Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-47909Mediumgithub.com/gorilla/csrf: github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacksCVE-2025-58157Highgithub.com/consensys/gnark: gnark affected by denial of service when computing scalar multiplication using fake-GLV algorithmCVE-2025-58158Highgithub.com/harness/gitness: Harness Allows Arbitrary File Write in Gitness LFS serverGHSA-V2CH-C8V8-FGR7Highgithub.com/versity/versitygw: Versity panic induced by AWS chunked data sent to portCVE-2024-58259Highgithub.com/rancher/rancher: Rancher affected by unauthenticated Denial of ServiceCVE-2025-6203Highgithub.com/hashicorp/vault: HashiCorp Vault Community Edition Denial of Service Though Complex JSON PayloadsCVE-2025-58058Mediumgithub.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archivesGHSA-3RW9-WMC8-8948Lowgithub.com/coder/coder/v2: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh tokenGHSA-VXG3-W9RV-RHR2Highgithub.com/edgelesssys/contrast: Contrast leaks workload secrets to logs on INFO levelCVE-2025-8077Criticalgithub.com/neuvector/neuvector: NeuVector admin account has insecure default passwordCVE-2025-54467Mediumgithub.com/neuvector/neuvector: NeuVector process with sensitive arguments lead to leakageCVE-2025-53884Mediumgithub.com/neuvector/neuvector: NeuVector has an insecure password storage and is vulnerable to rainbow attackCVE-2025-51667Highgithub.com/suyuan32/simple-admin-core: simple-admin-core SQL Injection vulnerabilityCVE-2025-5187Mediumk8s.io/kubernetes: Kubernetes Nodes can delete themselves by adding an OwnerReferenceCVE-2025-57813Mediumgithub.com/traPtitech/traQ: traQ Allows Insertion of Sensitive Information into Log FileCVE-2025-57801Highgithub.com/consensys/gnark: gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checksCVE-2025-53363Mediumgithub.com/donknap/dpanel: Dpanel has an arbitrary file read vulnerabilityCVE-2025-6465Mediumgithub.com/mattermost/mattermost-server: Mattermost Fails to Sanitize File NamesCVE-2025-8402Mediumgithub.com/mattermost/mattermost-server: Mattermost has Potential Server Crash due to Unvalidated Import DataCVE-2025-11065Mediumgithub.com/go-viper/mapstructure/v2: go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed DataCVE-2025-8023Mediumgithub.com/mattermost/mattermost-server: Mattermost Fails to Sanitize Path Traversal SequencesCVE-2025-49810Lowgithub.com/mattermost/mattermost-server: Mattermost Lack of Access Control ValidationCVE-2025-49222Mediumgithub.com/mattermost/mattermost-server: Mattermost Fails to Validate Remote Cluster Upload SessionsCVE-2025-47870Mediumgithub.com/mattermost/mattermost-server: Mattermost Does Not Sanitize the Team Invite IDCVE-2025-47700Lowgithub.com/mattermost/mattermost-server: Mattermost Server SSRF Vulnerability via the Agents Plugin

Stop the waste.
Protect your environment with Kodem.