Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-49221Lowgithub.com/mattermost/mattermost-plugin-confluence: Mattermost Confluence Plugin has Missing Authorization vulnerabilityCVE-2025-44004Highgithub.com/mattermost/mattermost-plugin-confluence: Mattermost Confluence Plugin is Missing Authentication for Critical FunctionCVE-2025-44001Mediumgithub.com/mattermost/mattermost-plugin-confluence: Mattermost Confluence Plugin has Missing Authorization vulnerabilityCVE-2025-55001Mediumgithub.com/openbao/openbao: OpenBao LDAP MFA Enforcement Bypass When Using Username As AliasCVE-2025-55003Mediumgithub.com/openbao/openbao: OpenBao Login MFA Bypass of Rate Limiting and TOTP Token ReuseCVE-2025-55000Mediumgithub.com/openbao/openbao: OpenBao TOTP Secrets Engine Code ReuseCVE-2025-54999Lowgithub.com/openbao/openbao: OpenBao has a Timing Side-Channel in the Userpass Auth MethodCVE-2025-54998Mediumgithub.com/openbao/openbao: OpenBao Userpass and LDAP User Lockout BypassCVE-2025-54997Criticalgithub.com/openbao/openbao: Privileged OpenBao Operator May Execute Code on the Underlying HostCVE-2025-54996Highgithub.com/openbao/openbao: OpenBao Root Namespace Operator May Elevate Token PrivilegesCVE-2025-7195Mediumgithub.com/operator-framework/operator-sdk: operator-sdk: privilege escalation due to incorrect permissions of /etc/passwdCVE-2025-44779Mediumgithub.com/ollama/ollama: Ollama allows deletion of arbitrary filesCVE-2025-54799Lowgithub.com/go-acme/lego: github.com/go-acme/lego/v4/acme/api does not enforce HTTPSCVE-2025-6013Mediumgithub.com/hashicorp/vault: HashiCorp Vault ldap auth method may not have correctly enforced MFACVE-2025-54801Highgithub.com/gofiber/fiber/v2: Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in DecoderCVE-2025-53534Highgithub.com/tnborg/panel: RatPanel can perform remote command execution without authorizationCVE-2025-8341Mediumgithub.com/grafana/grafana-infinity-datasource: Grafana Infinity Datasource Plugin SSRF VulnerabilityCVE-2025-6015Mediumgithub.com/hashicorp/vault: Hashicorp Vault has Login MFA Rate Limit Bypass VulnerabilityCVE-2025-6011Lowgithub.com/hashicorp/vault: Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing UsersCVE-2025-6037Mediumgithub.com/hashicorp/vault: Hashicorp Vault has Incorrect Validation for Non-CA CertificatesCVE-2025-6004Mediumgithub.com/hashicorp/vault: Hashicorp Vault has Lockout Feature Authentication BypassCVE-2025-5999Highgithub.com/hashicorp/vault: Hashicorp Vault has Privilege Escalation VulnerabilityCVE-2025-6000Criticalgithub.com/hashicorp/vault: Hashicorp Vault has Code Execution Vulnerability via Plugin ConfigurationCVE-2025-6014Mediumgithub.com/hashicorp/vault: Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse CVE-2025-54424Highgithub.com/1Panel-dev/1Panel/core: 1Panel agent certificate verification bypass leading to arbitrary command execution

Stop the waste.
Protect your environment with Kodem.