Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-34429Highgithub.com/1Panel-dev/1Panel: 1Panel contains a cross-site request forgery (CSRF) vulnerability in the web port configuration functionalityCVE-2025-34430Mediumgithub.com/1Panel-dev/1Panel: 1Panel contains a cross-site request forgery (CSRF) vulnerability in the panel name management functionalityCVE-2025-65754Mediumgithub.com/xyproto/algernon: Algernon Cross-Site Scripting vulnerabilityCVE-2025-34410Highgithub.com/1Panel-dev/1Panel: 1Panel contains a cross-site request forgery (CSRF) vulnerability in the Change Username functionalityCVE-2025-67717Mediumgithub.com/zitadel/zitadel: Zitadel Discloses the Total Number of Instance UsersCVE-2025-67713Mediumminiflux.app/v2: Miniflux has an Open Redirect via protocol-relative redirect_urlCVE-2025-8110Highgogs.io/gogs: Gogs vulnerable to a bypass of CVE-2024-55947GHSA-MJCP-GPGX-GGCGMediumgithub.com/opentofu/opentofu: OpenTofu incorrectly validates excluded subdomain constraint in conjunction with TLS certificates containing wildcard SANsCVE-2025-67499Mediumgithub.com/containernetworking/plugins: CNA Plugins Portmap nftables backend can intercept non-local trafficGHSA-4R66-7RCV-X46XHighgithub.com/siyuan-note/siyuan/kernel: SiYuan vulnerable to RCE via zip slip and Command Injection via PandocBinCVE-2025-67488Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCECVE-2025-66626Highgithub.com/argoproj/argo-workflows/v3: RCE via ZipSlip and symbolic links in argoproj/argo-workflowsGHSA-4RMQ-MC2C-R495Mediumgithub.com/babylonlabs-io/babylon/v4: Babylon Incorrect FP inactive accounting in costaking creates “phantom stake” that earns rewards after BTC unbondGHSA-M6WQ-66P2-C8PCHighgithub.com/babylonlabs-io/babylon/v4: Babylon Nil BlockHash in BLS vote extensions triggers panics in consensus handlersCVE-2025-67495Highgithub.com/zitadel/zitadel: ZITADEL Vulnerable to Account Takeover via DOM-Based XSS in Zitadel V2 LoginCVE-2026-29067Highgithub.com/zitadel/zitadel: ZITADEL Vulnerable to Account Takeover Due to Improper Instance Validation in V2 LoginCVE-2025-67494Criticalgithub.com/zitadel/zitadel: ZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 LoginCVE-2025-65795Highgithub.com/usememos/memos: memos vulnerability allows the creation of arbitrary accountsCVE-2025-65799Mediumgithub.com/usememos/memos: memos lacks file name validation or verificationCVE-2025-65797Mediumgithub.com/usememos/memos: memos vulnerability allows arbitrarily modification or deletion registered identity providersCVE-2025-65796Mediumgithub.com/usememos/memos: memos vulnerability allows arbitrarily reactions deletionCVE-2025-65798Mediumgithub.com/usememos/memos: memos vulnerability allows arbitrarily modification or deletion of attachmentsCVE-2025-66565Criticalgithub.com/gofiber/utils/v2: Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable ValuesCVE-2025-66508Mediumgithub.com/1Panel-dev/1Panel: 1Panel IP Access Control Bypass via Untrusted X-Forwarded-For HeadersCVE-2025-66507Highgithub.com/1Panel-dev/1Panel: 1Panel – CAPTCHA Bypass via Client-Controlled Flag

Stop the waste.
Protect your environment with Kodem.