Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-59937Highgithub.com/wneessen/go-mail: go-mail has insufficient address encoding when passing mail addresses to the SMTP clientCVE-2025-59163Lowgithub.com/safedep/vet: vet MCP Server SSE Transport DNS Rebinding VulnerabilityCVE-2025-10954Mediumgithub.com/nyaruka/phonenumbers: github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of InputGHSA-Q6HV-WCJR-WP8HLowgithub.com/kcp-dev/kcp: kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual WorkspaceCVE-2024-58260Highgithub.com/rancher/rancher: Rancher update on users can deny the service to the adminCVE-2024-58267Highgithub.com/rancher/rancher: Rancher CLI SAML authentication is vulnerable to phishing attacksCVE-2025-54468Mediumgithub.com/rancher/rancher: Rancher sends sensitive information to external services through the `/meta/proxy` endpointCVE-2025-59823Criticalgithub.com/gardener/gardener-extension-provider-aws: Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioningCVE-2025-59824Lowgithub.com/siderolabs/omni: Omni Wireguard SideroLink potential escapeCVE-2025-9079Highgithub.com/mattermost/mattermost-server: Mattermost Path Traversal vulnerabilityCVE-2025-9081Lowgithub.com/mattermost/mattermost-plugin-boards: Mattermost boards plugin fails to restrict download access to filesCVE-2025-10630Mediumgithub.com/alexanderzobnin/grafana-zabbix: Grafana-Zabbix ReDoS vulnerabilityCVE-2025-59410Mediumgithub.com/dragonflyoss/dragonfly: DragonFly's tiny file download uses hard coded HTTP protocolCVE-2025-59354Mediumgithub.com/dragonflyoss/dragonfly: DragonFly has weak integrity checks for downloaded filesCVE-2025-59353Highgithub.com/dragonflyoss/dragonfly: DragonFly's manager generates mTLS certificates for arbitrary IP addressesCVE-2025-59352Mediumgithub.com/dragonflyoss/dragonfly: DragonFly vulnerable to arbitrary file read and write on a peer machineCVE-2025-59351Mediumgithub.com/dragonflyoss/dragonfly: DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an errorCVE-2025-59350Mediumgithub.com/dragonflyoss/dragonfly: Dragonfly vulnerable to timing attacks against Proxy’s basic authenticationCVE-2025-59349Lowgithub.com/dragonflyoss/dragonfly: Dragonfly's directories created via os.MkdirAll are not checked for permissionsCVE-2025-59348Mediumgithub.com/dragonflyoss/dragonfly: Dragonfly incorrectly handles a task structure’s usedTrac fieldCVE-2025-59347Mediumgithub.com/dragonflyoss/dragonfly: Dragonfly's manager makes requests to external endpoints with disabled TLS authenticationCVE-2025-59346Highgithub.com/dragonflyoss/dragonfly: Dragonfly vulnerable to server-side request forgeryCVE-2025-59345Highgithub.com/dragonflyoss/dragonfly: Dragonfly doesn't have authentication enabled for some Manager’s endpointsCVE-2025-59342Mediumgithub.com/esm-dev/esm.sh: esm.sh has arbitrary file write via path traversal in `X-Zone-Id` headerCVE-2025-59341Highgithub.com/esm-dev/esm.sh: esm.sh has File Inclusion issue

Stop the waste.
Protect your environment with Kodem.