Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-HRHF-2VCR-GHCHHighgithub.com/cometbft/cometbft: CometBFT's invalid BitArray handling can lead to network haltCVE-2025-62157Highgithub.com/argoproj/argo-workflows/v3: Argo Workflow may expose artifact repository credentialsCVE-2025-62156Highgithub.com/argoproj/argo-workflows/v3: Argo Workflow has a Zipslip VulnerabilityCVE-2025-61688Highgithub.com/siderolabs/omni: Omni vulnerable to information leak via APICVE-2025-59836Mediumgithub.com/siderolabs/omni: Omni is Vulnerable to DoS via Empty Create/Update Resource RequestsGHSA-XC79-566C-J4QXHighgithub.com/microstack-tech/parallax: Parallax is vulnerable to DoS via malicious p2p messageCVE-2025-61926Mediumgithub.com/ossf/allstar: Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook SecretCVE-2025-59530Highgithub.com/quic-go/quic-go: quic-go: Panic occurs when queuing undecryptable packets after handshake completionCVE-2025-11579Mediumgithub.com/nwaples/rardecode/v2: rardecode: DoS risk due to unrestricted RAR dictionary sizesCVE-2025-61524Highgithub.com/casdoor/casdoor: Casdoor is vulnerable to Improper AuthorizationCVE-2025-54286Highgithub.com/canonical/lxd: Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UICVE-2025-54287Highgithub.com/lxc/lxd: Canonical LXD Arbitrary File Read via Template Injection in Snapshot PatternsCVE-2025-54288Mediumgithub.com/canonical/lxd: Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD ServerCVE-2025-54289Highgithub.com/canonical/lxd: Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations APICVE-2025-54290Mediumgithub.com/canonical/lxd: Canonical LXD Project Existence Determination Through Error Handling in Image Export FunctionCVE-2025-54293Highgithub.com/canonical/lxd: Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval FunctionCVE-2025-54291Mediumgithub.com/canonical/lxd: Canonical LXD Project Existence Determination Through Error Handling in Image Get FunctionCVE-2025-61595Highgithub.com/MANTRA-Chain/mantrachain/v4: github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooksCVE-2025-59538Highgithub.com/argoproj/argo-cd/v2: Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhookCVE-2025-59537Highgithub.com/argoproj/argo-cd: argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payloadCVE-2025-59531Highgithub.com/argoproj/argo-cd: Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payloadCVE-2025-55191Mediumgithub.com/argoproj/argo-cd/v2: Repository Credentials Race Condition Crashes Argo CD ServerCVE-2025-59956Mediumgithub.com/coder/agentapi: Coder AgentAPI exposed user chat history via a DNS rebinding attackCVE-2025-59942Highgithub.com/filecoin-project/go-f3: go-f3 module vulnerable to integer overflow leading to panicCVE-2025-59941Mediumgithub.com/filecoin-project/go-f3: go-f3 Vulnerable to Cached Justification Verification Bypass

Stop the waste.
Protect your environment with Kodem.