Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-52900Mediumgithub.com/filebrowser/filebrowser/v2: filebrowser Sets Insecure File PermissionsCVE-2025-4656Lowgithub.com/hashicorp/vault: Vault Community Edition rekey and recovery key operations can cause denial of serviceCVE-2025-52894Mediumgithub.com/openbao/openbao: OpenBao allows cancellation of root rekey and recovery rekey operations without authenticationCVE-2025-52893Mediumgithub.com/openbao/openbao/sdk/v2: OpenBao Inserts Sensitive Information into Log File when processing malformed dataCVE-2025-52890Highgithub.com/lxc/incus/v6: Incus creates nftables rules that partially bypass security optionsCVE-2025-52889Lowgithub.com/lxc/incus/v6: Incus Allocation of Resources Without Limits allows firewall rule bypass on managed bridge networksCVE-2025-52477Highgithub.com/octo-sts/app: Octo STS Unauthenticated SSRF by abusing fields in OpenID Connect tokensCVE-2025-47943Mediumgithub.com/gogs/gogs: Gogs XSS allowed by stored call in PDF rendererCVE-2025-6624Lowsnyk: Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE modeCVE-2025-6032Highgithub.com/containers/podman/v5: Podman Improper Certificate Validation; machine missing TLS verificationCVE-2024-56731Criticalgogs.io/gogs: Gogs allows deletion of internal files which leads to remote command executionCVE-2025-4563Lowk8s.io/kubernetes: kubernetes allows nodes to bypass dynamic resource allocation authorization checksGHSA-VRW8-FXC6-2R93Mediumgithub.com/go-chi/chi/v5: chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashesCVE-2025-3227Mediumgithub.com/mattermost/mattermost-server: Mattermost allows unauthorized channel member management through playbook runsCVE-2025-3228Mediumgithub.com/mattermost/mattermost-server: Mattermost allows an unauthorized Guest user access to PlaybookCVE-2025-4981Criticalgithub.com/mattermost/mattermost-server: Mattermost allows authenticated users to write files to arbitrary locationsCVE-2025-6264Mediumwww.velocidex.com/golang/velociraptor: Velociraptor vulnerable to privilege escalation via UpdateConfig artifactCVE-2025-1088Lowgithub.com/grafana/grafana: Grafana long dashboard title or panel name causes unresponsivesCVE-2025-5981Mediumgithub.com/google/osv-scalibr: OSV-SCALIBR's Container Image Unpacking Vulnerable to Arbitrary File Write via Path TraversalCVE-2025-49825Criticalgithub.com/gravitational/teleport: Teleport allows remote authentication bypassCVE-2025-5689Mediumgithub.com/ubuntu/authd: New authd users logging in via SSH are members of the root groupCVE-2024-44906Mediumgithub.com/uptrace/bun/driver/pgdriver: uptrace pgdriver SQL injection vulnerabilityCVE-2024-44905Mediumgithub.com/go-pg/pg/v9: go-pg SQL injection vulnerability via the component /types/append_value.goCVE-2025-4922Highgithub.com/hashicorp/nomad: Hashicorp Nomad Incorrect Privilege Assignment vulnerabilityGHSA-79XG-Q4QM-7V9WHighgithub.com/CosmWasm/wasmd: CWA-2025-006: wasmd's improper error handling may lead to IBC channel opening despite error

Stop the waste.
Protect your environment with Kodem.