Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-4953Highgithub.com/containers/podman/v5: Podman Creates Temporary File with Insecure PermissionsCVE-2025-54588Highgithub.com/envoyproxy/envoy: Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faultsCVE-2025-8396Mediumgo.temporal.io/server: Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or ThrottlingCVE-2025-59361Criticalgithub.com/chaos-mesh/chaos-mesh: Chaos Controller Manager is vulnerable to OS command injectionCVE-2025-59360Criticalgithub.com/chaos-mesh/chaos-mesh: Chaos Controller Manager is vulnerable to OS command injectionCVE-2025-9078Mediumgithub.com/mattermost/mattermost-server: Mattermost makes Use of Weak HashCVE-2025-59358Highgithub.com/chaos-mesh/chaos-mesh: Chaos Mesh's Chaos Controller Manager is Missing Authentication for Critical FunctionCVE-2025-59359Criticalgithub.com/chaos-mesh/chaos-mesh: Chaos Controller Manager is vulnerable to OS command injectionCVE-2025-9084Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Open Redirect vulnerabilityCVE-2025-9072Highgithub.com/mattermost/mattermost-server: Mattermost Open Redirect vulnerabilityCVE-2025-9076Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Missing Authorization vulnerabilityCVE-2025-54376Highgithub.com/SpectoLabs/hoverfly: WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabledCVE-2025-54123Criticalgithub.com/SpectoLabs/hoverfly: Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementationCVE-2025-58430Highgithub.com/knadh/listmonk: listmonk: CSRF to XSS Chain can Lead to Admin Account TakeoverCVE-2025-58063Highgithub.com/coredns/coredns: CoreDNS: DNS Cache Pinning via etcd Lease ID ConfusionCVE-2025-58450Criticalgithub.com/prest/prest/v2: pREST has a Systemic SQL Injection VulnerabilityCVE-2025-58445Lowgithub.com/runatlantis/atlantis: Atlantis Exposes Service Version Publicly on /status API EndpointCVE-2025-7445Mediumsigs.k8s.io/secrets-store-sync-controller: secrets-store-sync-controller discloses service account tokens in logsCVE-2025-58437Highgithub.com/coder/coder/v2: Coder vulnerable to privilege escalation could lead to a cross workspace compromiseCVE-2025-9566Highgithub.com/containers/podman/v5: podman kube play symlink traversal vulnerabilityCVE-2025-55190Criticalgithub.com/argoproj/argo-cd/v2: Argo CD's Project API Token Exposes Repository CredentialsCVE-2025-56760Mediumgithub.com/usememos/memos: Memos Vulnerable to Path Traversal via the CreateResource EndpointCVE-2025-56761Mediumgithub.com/usememos/memos: Memos Vulnerable to Stored Cross-Site ScriptingCVE-2025-58355Highgithub.com/charmbracelet/soft-serve: Soft Serve vulnerable to arbitrary file writing through SSH APICVE-2024-52284Highgithub.com/rancher/fleet: Rancher Fleet Helm Values are stored inside BundleDeployment in plain text

Stop the waste.
Protect your environment with Kodem.