Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-XQ4H-WQM2-668WMediumgithub.com/babylonlabs-io/babylon/v4: Babylon's BIP322 signature implementation is not fully compliant to the specGHSA-2FCV-QWW3-9V6HHighgithub.com/babylonlabs-io/babylon/v4: Babylon's malformed vote extensions are not rejectedGHSA-RJ4J-2JPH-GG43Criticalgithub.com/lf-edge/ekuiper/v2: LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extractionCVE-2025-64761Highgithub.com/openbao/openbao: OpenBao is Vulnerable to Privileged Operator Identity Group Root EscalationCVE-2025-62155Highgithub.com/QuantumNous/new-api: new-api is vulnerable to SSRF BypassCVE-2025-60638Highgithub.com/free5gc/nssf: NSSF panic due to nil pointer dereference when expiry field is omitted in NSSAIAvailability POSTCVE-2025-60633Mediumgithub.com/free5gc/udm: Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement APICVE-2025-60632Mediumgithub.com/free5gc/pcf: Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST APICVE-2025-65111Lowgithub.com/authzed/spicedb: SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete ResultsCVE-2025-41115Criticalgithub.com/grafana/grafana: Grafana Incorrect Privilege Assignment vulnerabilityCVE-2025-13357Highgithub.com/hashicorp/terraform-provider-vault: Vault’s Terraform Provider incorrectly set default deny_null_bind parameter for LDAP auth method to false by defaultCVE-2025-64751Mediumgithub.com/openfga/openfga: OpenFGA Improper Policy EnforcementGHSA-6XVF-4VH9-MW47Highgithub.com/mindersec/minder: Minder does not sandbox http.send in Rego programsCVE-2025-13425Lowgithub.com/google/osv-scalibr: OSV-SCALIBR has NULL Pointer DereferenceCVE-2025-47914Mediumgolang.org/x/crypto: golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds readCVE-2025-58181Mediumgolang.org/x/crypto: golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumptionCVE-2025-65026Mediumgithub.com/esm-dev/esm.sh: esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScriptCVE-2025-65025Highgithub.com/esm-dev/esm.sh: esm.sh CDN service has arbitrary file write via tarslipCVE-2025-64708Mediumgoauthentik.io: authentik's invitation expiry is delayed by at least 5 minutesCVE-2025-64521Mediumgoauthentik.io: authentik allows a deactivated Service account to authenticate to OAuthCVE-2025-55074Lowgithub.com/mattermost/mattermost-server: Mattermost allows other users to determine when users had read channels via channel member objectsCVE-2024-21635Highgithub.com/usememos/memos: Memos' Access Tokens Stay Valid after User Password ChangeCVE-2025-64717Highgithub.com/zitadel/zitadel: ZITADEL is vulnerable to Account Takeover with deactivated Instance IdPCVE-2025-11794Mediumgithub.com/mattermost/mattermost-server: Mattermost allows system administrators to access password hashes and MFA secretsCVE-2025-55070Mediumgithub.com/mattermost/mattermost-server: Mattermost does not enforce MFA on WebSocket connections

Stop the waste.
Protect your environment with Kodem.