Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-64329Mediumgithub.com/containerd/containerd: containerd CRI server: Host memory exhaustion through Attach goroutine leakGHSA-W2JF-268Q-MRVHLowgithub.com/opentofu/opentofu: OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responsesCVE-2024-25621Highgithub.com/containerd/containerd: containerd affected by a local privilege escalation via wide permissions on CRI directoryCVE-2025-64431Highgithub.com/zitadel/zitadel: IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data TemperingCVE-2025-52881Highgithub.com/opencontainers/runc: runc container escape and denial of service due to arbitrary write gadgets and procfs write redirectsCVE-2025-52565Highgithub.com/opencontainers/runc: runc container escape with malicious config due to /dev/console mount and related racesCVE-2025-31133Highgithub.com/opencontainers/runc: runc container escape via "masked path" abuse due to mount race conditionsGHSA-5PMX-7R6R-WFQQMediumgithub.com/kgateway-dev/kgateway/v2: Kgateway transformation policy template can emit files from the container CVE-2025-64323Mediumgithub.com/kgateway-dev/kgateway/v2: kgateway is missing xDS authorizationCVE-2025-64171Highgithub.com/3scale-sre/marin3r: MARIN3R: Cross-Namespace Vulnerability in the OperatorCVE-2025-64178Highgithub.com/jon4hz/jellysweep: Jellysweep uses uncontrolled data in image cache API endpointCVE-2025-64179Mediumgithub.com/treeverse/lakefs: lakeFS affected by unauthenticated access to API usage metricsCVE-2025-61141Highgithub.com/sqls-server/sqls: sqls-server/sqls is vulnerable to command injection in the config command GHSA-FJ2X-735W-74VQHighgithub.com/consensys/gnark-crypto: gnark-crypto allows unchecked memory allocation during vector deserializationCVE-2025-64716Mediumgithub.com/TecharoHQ/anubis: Anubis vulnerable to possible XSS via redir parameter when using subrequest auth modeCVE-2025-64103Highgithub.com/zitadel/zitadel/v2: Zitadel May Bypass Second Authentication FactorCVE-2025-64102Highgithub.com/zitadel/zitadel/v2: Zitadel allows brute-forcing authentication factorsCVE-2025-64101Highgithub.com/zitadel/zitadel/v2: ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header InjectionCVE-2025-11375Mediumgithub.com/hashicorp/consul: Consul event endpoint is vulnerable to denial of serviceCVE-2025-11374Mediumgithub.com/hashicorp/consul: Consul key/value endpoint is vulnerable to denial of serviceGHSA-F5P4-P5Q5-JV3HMediumgithub.com/edgelesssys/contrast: Contrast has insecure LUKS2 persistent storage partitions may be opened and usedCVE-2025-27093Mediumgithub.com/bishopfox/sliver: Silver has unrestricted traffic between Wireguard clientsCVE-2025-62725Highgithub.com/docker/compose/v2: Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer AnnotationsCVE-2025-58356Highgithub.com/edgelesssys/constellation/v2: Constellation has insecure LUKS2 persistent storage partitions which may be opened and usedCVE-2024-58269Mediumgithub.com/rancher/rancher: Rancher exposes sensitive information through audit logs

Stop the waste.
Protect your environment with Kodem.