Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-21885Mediumminiflux.app/v2: Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resourcesCVE-2026-0650Criticalgithub.com/openflagr/flagr: OpenFlagr contains an authentication bypass vulnerability in the HTTP middlewareGHSA-GG4X-FGG2-H9W9Criticalgithub.com/kyverno/kyverno: Bypassing Kyverno Policies via Double Policy ExceptionsCVE-2026-21859Mediumgithub.com/axllent/mailpit: Mailpit Proxy Endpoint has Server-Side Request Forgery (SSRF) vulnerabilityCVE-2025-68954Highpterodactyl/panel: Pterodactyl does not revoke SFTP access when server is deleted or permissions reducedCVE-2025-62877Criticalgithub.com/harvester/harvester-installer: Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive InstallerGHSA-HJR9-WJ7V-7HV8Mediumgithub.com/bishopfox/sliver: Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder BypassGHSA-4C5F-9MJ4-M247Highgithub.com/open-feature/flagd/core: flagd: Multiple Go Runtime CVEs Impact Security and AvailabilityCVE-2026-21483Mediumgithub.com/knadh/listmonk: listmonk Vulnerable to Stored XSS Leading to Admin Account TakeoverCVE-2025-69413Mediumcode.gitea.io/gitea: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username existsCVE-2025-14986Lowgo.temporal.io/server: Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contextsCVE-2025-14987Mediumgo.temporal.io/server: Temporal has an Incorrect Authorization vulnerabilityCVE-2025-68120Mediumgithub.com/golang/vscode-go: Visual Studio Code Go extension has unexpected untrusted code executionCVE-2025-15107Lowgithub.com/actiontech/sqle: SQLE's JWT Secret Handler can be manipulated to use hard-coded cryptographic keyCVE-2025-68945Mediumcode.gitea.io/gitea: Gitea: anonymous user can visit private user's projectCVE-2025-68946Mediumcode.gitea.io/gitea: Gitea vulnerable to Cross-site ScriptingCVE-2025-68943Mediumcode.gitea.io/gitea: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort orderCVE-2025-68944Mediumcode.gitea.io/gitea: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registriesCVE-2025-68942Mediumcode.gitea.io/gitea: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-textCVE-2025-68940Lowcode.gitea.io/gitea: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request.CVE-2025-68941Mediumcode.gitea.io/gitea: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resourcesCVE-2025-68939Highcode.gitea.io/gitea: Gitea allows attackers to add attachments with forbidden file extensionsCVE-2025-68938Mediumcode.gitea.io/gitea: Gitea mishandles authorization for deletion of releasesCVE-2025-13767Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issuesCVE-2025-64641Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin

Stop the waste.
Protect your environment with Kodem.