Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-68476Highgithub.com/kedacore/keda/v2: KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account CredentialCVE-2025-14273Highgithub.com/mattermost/mattermost/server/v8: Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication AlgorithmCVE-2025-68383Mediumgithub.com/elastic/beats/v7: Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect ConfigurationCVE-2025-68388Highgithub.com/elastic/beats: Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 FragmentsCVE-2025-14764Mediumgithub.com/aws/amazon-s3-encryption-client-go/v3: Amazon S3 Encryption Client has a Key Commitment IssueCVE-2025-63389Criticalgithub.com/ollama/ollama: Ollama Platform has missing authentication enabling attackers to perform model management operationsCVE-2025-12689Mediumgithub.com/mattermost/mattermost-plugin-calls: Mattermost fails to check Websocket request for proper UTF-8 format potentially crashing Calls plug-inCVE-2025-13324Mediumgithub.com/mattermost/mattermost: Mattermost has an Invite Token Replay Vulnerability via Channel Membership ManipulationCVE-2025-62190Mediumgithub.com/mattermost/mattermost-plugin-calls: Mattermost has CSRF vulnerability via Calls Widget pageCVE-2025-62690Lowgithub.com/mattermost/mattermost/server/v8: Mattermost has missing redirect URL validationCVE-2025-13352Lowgithub.com/mattermost/mattermost/server/v8: Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction InjectionCVE-2025-68156Highgithub.com/expr-lang/expr: Expr has Denial of Service via Unbounded Recursion in Builtin FunctionsCVE-2025-68274Highgithub.com/emiago/sipgo: SIPGO is Vulnerable to Response DoS via Nil Pointer DereferenceCVE-2025-68927Highgithub.com/abhinavxd/libredesk: Libredesk has Improper Neutralization of HTML Tags in a Web PageCVE-2025-14443Highgithub.com/openshift/openshift-apiserver: openshift-apiserver: SSRF via Missing IP/Network-Range Validation in User-Supplied Image ReferencesCVE-2025-68113Mediumaltcha-lib: ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and ReplayCVE-2025-11393Highgithub.com/RedHatInsights/runtimes-inventory-operator: Misconfigured Internal Proxy in runtimes-inventory-rhel8-operator Grants Standard Users Full Cluster Administrator AccessCVE-2025-13888Criticalgithub.com/redhat-developer/gitops-operator: OpenShift GitOps authenticated attackers can obtain cluster root access through forged ArgoCD custom resourcesCVE-2025-13281Mediumk8s.io/kubernetes: kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClassGHSA-4JMP-X7MH-RGMRHighgithub.com/babylonlabs-io/finality-provider: Finality Provider vulnerable to anti-slashing bypassing due to misconfigurationCVE-2025-66001Highgithub.com/neuvector/neuvector: NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)CVE-2025-67818Highgithub.com/weaviate/weaviate: Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlipCVE-2025-67819Highgithub.com/weaviate/weaviate: Weaviate OSS has path traversal vulnerability via the Shard Movement APICVE-2025-67508Highgithub.com/gardener/gardenctl-v2: gardenctl is vulnerable to Command Injection when used with non‑POSIX shellsCVE-2025-64702Mediumgithub.com/quic-go/quic-go: quic-go HTTP/3 QPACK Header Expansion DoS

Stop the waste.
Protect your environment with Kodem.