Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-66491Mediumgithub.com/traefik/traefik/v3: Traefik Inverted TLS Verification Logic in ingress-nginx ProviderCVE-2025-66490Mediumgithub.com/traefik/traefik: Path Normalization Bypass in Traefik Router + Middleware RulesCVE-2025-66564Highgithub.com/sigstore/timestamp-authority: Sigstore Timestamp Authority allocates excessive memory during request parsingCVE-2025-66506Highgithub.com/sigstore/fulcio: Fulcio allocates excessive memory during token parsingCVE-2025-66220Mediumgithub.com/envoyproxy/envoy: Envoy's TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byteCVE-2025-64763Lowgithub.com/envoyproxy/envoy: Envoy forwards early CONNECT data in TCP proxy modeCVE-2025-64527Mediumgithub.com/envoyproxy/envoy: Envoy crashes when JWT authentication is configured with the remote JWKS fetchingCVE-2025-65637Highgithub.com/sirupsen/logrus: Logrus is vulnerable to DoS when using Entry.Writer()CVE-2025-44005Criticalgithub.com/smallstep/certificates: Step CA Has Authorization Bypass in ACME and SCEP ProvisionersCVE-2025-66411Highgithub.com/coder/coder/v2: Coder logs sensitive objects unsanitizedCVE-2025-66406Mediumgithub.com/smallstep/certificates: step-ca Has Improper Authorization Check for SSH Certificate RevocationCVE-2025-64443Highgithub.com/docker/mcp-gateway: Docker MCP Plugin and Docker MCP Gateway have DNS Rebinding vulnerability when running in sse or streaming modeCVE-2025-65105Mediumgithub.com/apptainer/apptainer: Apptainer ineffectively applies selinux and apparmor --security optionsCVE-2025-64750Mediumgithub.com/sylabs/singularity/v4: Singluarity ineffectively applies selinux / apparmor LSM process labelsCVE-2025-13353Highgithub.com/cloudflare/gokey: gokey allows secret recovery from a seed file without the master passwordCVE-2025-13870Lowgithub.com/mattermost/mattermost/server/v8: Mattermost fails to validate user permissions in BoardsCVE-2025-10543Mediumgithub.com/eclipse/paho.mqtt.golang: Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytesCVE-2025-66410Highgithub.com/flipped-aurora/gin-vue-admin: Gin-vue-admin has an arbitrary file deletion vulnerabilityCVE-2025-12756Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to validate user permissions when deleting comments in BoardsCVE-2025-64715Mediumgithub.com/cilium/cilium: Cilium with misconfigured toGroups in policies can lead to unrestricted egress trafficCVE-2025-12421Criticalgithub.com/mattermost/mattermost/server/v8: Mattermost fails to to verify the token used during code exchangeCVE-2025-12559Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to sanitize team email addressesCVE-2025-12419Criticalgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly validate OAuth state tokens during OpenID Connect authenticationCVE-2025-65942Lowgithub.com/VictoriaMetrics/VictoriaMetrics: VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOMCVE-2025-65965Highgithub.com/anchore/grype: Grype has a credential disclosure vulnerability in its JSON output

Stop the waste.
Protect your environment with Kodem.