Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-55073Mediumgithub.com/mattermost/mattermost-server: Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URLCVE-2025-11776Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly restrict access to archived channel search APICVE-2025-41436Lowgithub.com/mattermost/mattermost-server: Mattermost allows regular users to access archived channel content and filesCVE-2025-47913Highgolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent has a potential denial of serviceGHSA-3G2J-VM47-X4MJHighgithub.com/canonical/lxd: LXD vulnerable to a local privilege escalation through custom storage volumesCVE-2025-64529Lowgithub.com/authzed/spicedb: SpiceDB WriteRelationships fails silently if payload is too bigGHSA-6JQF-MV7M-3Q7PCriticalgithub.com/filebrowser/filebrowser/v2: File Browser has risk of HTTP Request/Response smuggling through vulnerable dependencyCVE-2025-64523Highgithub.com/filebrowser/filebrowser/v2: File Browser is Vulnerable to Insecure Direct Object Reference (IDOR) in Share Deletion FunctionGHSA-7WQ2-32H4-9HC9Highgithub.com/aws/aws-advanced-go-wrapper/awssql: AWS Advanced Go Wrapper: Privilege Escalation in Aurora PostgreSQL InstanceCVE-2025-11777Lowgithub.com/mattermost/mattermost-server: Mattermost Incorrect Authorization vulnerabilityCVE-2025-64507Highgithub.com/lxc/incus/v6: Incus vulnerable to local privilege escalation through custom storage volumesCVE-2025-64513Criticalgithub.com/milvus-io/milvus: Milvus Proxy has a Critical Authentication Bypass VulnerabilityCVE-2025-64186Highgithub.com/evervault/evervault-go: Evervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted EnclavesCVE-2025-64484Highgithub.com/oauth2-proxy/oauth2-proxy/v7: OAuth2-Proxy is vulnerable to header smuggling via underscore leading to potential privilege escalationCVE-2025-63811Highgithub.com/dvsekhvalnov/jose2go: jose2go is vulnerable to a JWT bomb attack through its decode functionCVE-2025-2843Highgithub.com/rhobs/observability-operator: Observability Operator is vulnerable to Incorrect Privilege Assignment through its Custom Resource MonitorStackCVE-2025-64522Criticalgithub.com/charmbracelet/soft-serve: Soft Serve is vulnerable to SSRF through its WebhooksCVE-2025-64324Highkubevirt.io/kubevirt: KubeVirt Vulnerable to Arbitrary Host File Read and WriteCVE-2025-64494Mediumgithub.com/charmbracelet/soft-serve: Soft Serve does not sanitize ANSI escape sequences in user inputCVE-2025-64437Mediumkubevirt.io/kubevirt: KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission ChangesCVE-2025-64436Mediumkubevirt.io/kubevirt: KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between NodesCVE-2025-64435Mediumkubevirt.io/kubevirt: KubeVirt VMI Denial-of-Service (DoS) Using Pod ImpersonationCVE-2025-64434Mediumkubevirt.io/kubevirt: KubeVirt's Improper TLS Certificate Management Handling Allows API Identity SpoofingCVE-2025-64433Mediumkubevirt.io/kubevirt: KubeVirt Arbitrary Container File Read CVE-2025-64432Mediumkubevirt.io/kubevirt: KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer

Stop the waste.
Protect your environment with Kodem.