Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-7453Lowgithub.com/saltbo/zpan: ZPan Uses Hard-Coded PasswordCVE-2025-53634Highgithub.com/ctfer-io/chall-manager: Chall-Manager's HTTP Gateway is vulnerable to DoS due to missing header timeoutCVE-2025-53633Highgithub.com/ctfer-io/chall-manager: Chall-Manager's scenario decoding process does not check for zip bombsCVE-2025-53632Highgithub.com/ctfer-io/chall-manager: Chall-Manager is vulnerable to Path Traversal when extracting/decoding a zip archiveGHSA-PHHQ-63JG-FP7RLowgithub.com/edgelesssys/contrast: Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount pointsCVE-2025-0928Highgithub.com/juju/juju: Juju allows arbitrary executable uploads via authenticated endpoint without authorizationCVE-2025-53512Mediumgithub.com/juju/juju: Juju vulnerable to sensitive log retrieval via authenticated endpoint without authorizationCVE-2025-53513Highgithub.com/juju/juju: Juju zip slip vulnerability via authenticated endpointGHSA-P22H-3M2V-CMGHHighgithub.com/cosmos/cosmos-sdk: Cosmos SDK's Integer Overflow vulnerability in its Validator Rewards pool can cause a chain haltCVE-2025-53547Highhelm.sh/helm/v3: Helm vulnerable to Code Injection through malicious chart.yaml contentGHSA-RJ53-J6JW-7F7GHighgithub.com/babylonlabs-io/babylon/v2: Babylon vulnerable to chain halt when a message modifies the validator set at the epoch boundaryGHSA-GJ54-GWJ9-X2C6Highgithub.com/lf-edge/ekuiper/v2: eKuiper /config/uploads API arbitrary file writing may lead to RCEGHSA-FV2P-QJ5P-WQQ4Highgithub.com/lf-edge/ekuiper/v2: LF Edge eKuiper vulnerable to File Path Traversal leading to file replacementCVE-2025-6224Mediumgithub.com/juju/utils/v4/cert: juju/utils leaks private key in certsCVE-2025-47871Mediumgithub.com/mattermost/mattermost-server: Mattermost Incorrect Authorization vulnerabilityCVE-2025-46702Mediumgithub.com/mattermost/mattermost-server: Mattermost Incorrect Authorization vulnerabilityGHSA-56J4-446M-QRF6Highgithub.com/babylonlabs-io/babylon/v2: Babylon vulnerable to chain half when transaction has fees different than `ubbn`CVE-2025-52997Mediumgithub.com/filebrowser/filebrowser/v2: File Browser vulnerable to insecure password handlingCVE-2025-52996Lowgithub.com/filebrowser/filebrowser: File Browser's password protection of links is bypassableCVE-2025-52995Highgithub.com/filebrowser/filebrowser/v2: File Browser vulnerable to command execution allowlist bypassCVE-2025-52904Highgithub.com/filebrowser/filebrowser/v2: File Browser: Command Execution not Limited to ScopeCVE-2025-52901Mediumgithub.com/filebrowser/filebrowser/v2: File Browser allows sensitive data to be transferred in URLGHSA-FV92-FJC5-JJ9HMediumgithub.com/go-viper/mapstructure/v2: mapstructure May Leak Sensitive Information in Logs When Processing Malformed DataCVE-2025-52903Highgithub.com/filebrowser/filebrowser/v2: filebrowser Allows Shell Commands to Spawn Other CommandsCVE-2025-52902Highgithub.com/filebrowser/filebrowser/v2: filebrowser allows Stored Cross-Site Scripting through the Markdown preview function

Stop the waste.
Protect your environment with Kodem.