Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-54386Highgithub.com/traefik/traefik/v2: Traefik Client Plugin's Path Traversal Vulnerability Allows Arbitrary File Overwrite and Remote Code ExecutionCVE-2025-54576Criticalgithub.com/oauth2-proxy/oauth2-proxy/v7: OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusionCVE-2021-21411Mediumgithub.com/oauth2-proxy/oauth2-proxy/v7: OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0CVE-2025-52490Highgithub.com/couchbase/sync_gateway: Couchbase Sync Gateway shows cleartext passwords in redacted and unredacted outputCVE-2025-54410Lowgithub.com/docker/docker: Moby firewalld reload removes bridge network isolationCVE-2025-54388Mediumgithub.com/docker/docker: Moby firewalld reload makes published container ports accessible from remote hosts CVE-2025-50738Mediumgithub.com/usememos/memos: Memos has Cross-Site Scripting (XSS) Vulnerability in Image URLsCVE-2025-54379Highgithub.com/lf-edge/ekuiper/v2: eKuiper API endpoints handling SQL queries with user-controlled table names. CVE-2025-30086Mediumgithub.com/goharbor/harbor: Possible ORM Leak Vulnerability in the HarborCVE-2025-32019Mediumgithub.com/goharbor/harbor: Harbor repository description page has Cross-site Scripting vulnerabilityCVE-2025-51471Mediumgithub.com/ollama/ollama: Ollama vulnerable to Cross-Domain Token ExposureCVE-2025-53942Highgoauthentik.io: Authentik has insufficient check for account active status when authenticating with OAuth/SAML SourcesCVE-2025-47281Highgithub.com/kyverno/kyverno: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of ServiceCVE-2025-54059Mediumchainguard.dev/melange: melange's world-writable permissions expose SBOM files to potential image tamperingCVE-2025-53945Highchainguard.dev/apko: apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other filesCVE-2025-22868Highgolang.org/x/oauth2: golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerabilityCVE-2025-6233Mediumgithub.com/mattermost/mattermost-server: Mattermost Path Traversal vulnerabilityCVE-2025-6227Lowgithub.com/mattermost/mattermost-server: Mattermost has Insufficiently Protected CredentialsCVE-2025-6226Mediumgithub.com/mattermost/mattermost-server: Mattermost Missing Authentication for Critical FunctionCVE-2025-6023Highgithub.com/grafana/grafana: Grafana is vulnerable to XSS attacks through open redirects and path traversalCVE-2025-23266Criticalgithub.com/NVIDIA/nvidia-container-toolkit: NVIDIA Container Toolkit for all platforms contains an Untrusted Search PathCVE-2025-23267Highgithub.com/NVIDIA/nvidia-container-toolkit: NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hookCVE-2025-3415Mediumgithub.com/grafana/grafana: Grafana's insecure DingDing Alert integration exposes sensitive informationCVE-2025-53893Highgithub.com/filebrowser/filebrowser/v2: File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processingCVE-2025-53826Highgithub.com/filebrowser/filebrowser: File Browser’s insecure JWT handling can lead to session replay attacks after logout

Stop the waste.
Protect your environment with Kodem.