Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-62714Criticalgithub.com/karmada-io/dashboard: Karmada Dashboard API Unauthorized Access Vulnerability CVE-2023-32199Mediumgithub.com/rancher/rancher: Rancher user retains access to clusters despite Global Role removalCVE-2025-12044Highgithub.com/hashicorp/vault: Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSONCVE-2025-11621Highgithub.com/hashicorp/vault: HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypassCVE-2025-59048Highgithub.com/openbao/openbao-plugins: OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth MethodCVE-2025-62820Mediumgithub.com/slackhq/nebula: Slack Nebula may accept arbitrary source IP addresses CVE-2025-62705Mediumgithub.com/openbao/openbao: OpenBao and Vault Leak []byte Fields in Audit Logs CVE-2025-62513Mediumgithub.com/openbao/openbao: OpenBao leaks HTTPRawBody in Audit LogsCVE-2025-54471Mediumgithub.com/neuvector/neuvector: NeuVector is shipping cryptographic material into its binaryCVE-2025-54470Highgithub.com/neuvector/neuvector: NeuVector telemetry sender is vulnerable to MITM and DoSCVE-2025-54469Criticalgithub.com/neuvector/neuvector: NeuVector Enforcer is vulnerable to Command Injection and Buffer overflowGHSA-8PFH-J44R-F654Criticalgithub.com/cosmos/evm: Cosmos EVM VulnerabilityCVE-2025-10678Criticalgithub.com/netbirdio/netbird: NetBird VPN does not remove the default password of an admin accountCVE-2025-59043Highgithub.com/openbao/openbao: OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requestsCVE-2025-26625Highgithub.com/git-lfs/git-lfs: Git LFS may write to arbitrary files via crafted symlinksCVE-2025-62506Highgithub.com/minio/minio: MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STSCVE-2025-61581Lowgithub.com/apache/trafficcontrol/v8: Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerabilityCVE-2025-58073Highgithub.com/mattermost/mattermost/server/v8: Mattermost has a Missing Authorization vulnerabilityCVE-2025-10545Lowgithub.com/mattermost/mattermost/server/v8: Mattermost has an Incorrect Authorization vulnerabilityCVE-2025-41410Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost has a Missing Authorization vulnerabilityCVE-2025-58075Highgithub.com/mattermost/mattermost/server/v8: Mattermost has a Missing Authorization vulnerabilityCVE-2025-41443Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost has a Missing Authorization vulnerabilityCVE-2025-54499Lowgithub.com/mattermost/mattermost/server/v8: Mattermost has an Observable Timing Discrepancy vulnerabilityCVE-2025-62375Mediumgithub.com/in-toto/go-witness: go-witness is Vulnerable to Improper Verification of AWS EC2 Identity DocumentsCVE-2023-44273Mediumgithub.com/consensys/gnark-crypto: gnark-crypto doesn't range check input values during ECDSA and EdDSA signature deserialization

Stop the waste.
Protect your environment with Kodem.