Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-4128Lowgithub.com/mattermost/mattermost/server/v8: Mattermost allows guest users to view information about public teams they are not members ofCVE-2025-4573Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows authenticated administrator to execute LDAP search filter injectionCVE-2025-8556Lowgithub.com/cloudflare/circl: CIRCL-Fourq: Missing and wrong validation can lead to incorrect resultsCVE-2025-49140Highgithub.com/pion/interceptor: Pion Interceptor's improper RTP padding handling allows remote crash for SFU users (DoS)CVE-2025-49136Criticalgithub.com/knadh/listmonk: listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege userCVE-2025-25208Mediumgithub.com/kuadrant/authorino: Authorino Uncontrolled Resource Consumption vulnerabilityCVE-2025-25207Mediumgithub.com/kuadrant/authorino: Authorino Uncontrolled Resource Consumption vulnerabilityCVE-2025-49011Lowgithub.com/authzed/spicedb: SpiceDB checks involving relations with caveats can result in no permission when permission is expectedCVE-2025-47950Highgithub.com/coredns/coredns: CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream AmplificationCVE-2025-48710Mediumgithub.com/kro-run/kro: kro Confused Deputy vulnerabilityCVE-2025-48494Mediumgithub.com/forceu/gokapi: Gokapi vulnerable to stored XSS via uploading file with malicious file nameCVE-2025-48495Mediumgithub.com/forceu/gokapi: Gokapi has stored XSS vulnerability in friendly name for API keysCVE-2025-29785Highgithub.com/quic-go/quic-go: quic-go Has Panic in Path Probe Loss Recovery HandlingCVE-2025-3454Mediumgithub.com/grafana/grafana: Grafana's datasource proxy API allows authorization checks to be bypassedCVE-2025-3260Highgithub.com/grafana/grafana: Grafana vulnerable to authenticated users bypassing dashboard, folder permissionsCVE-2025-48938Mediumgithub.com/cli/go-gh/v2: Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise ServerCVE-2025-3230Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly invalidate personal access tokens upon user deactivationCVE-2025-3611Lowgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly enforce access control restrictions for System Manager rolesCVE-2025-2571Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to clear Google OAuth credentialsCVE-2025-1792Lowgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly enforce access controls for guest usersCVE-2025-48948Highgithub.com/navidrome/navidrome: Navidrome Transcoding Permission Bypass Vulnerability ReportCVE-2025-3913Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost improperly allows team administrators to modify team invitesCVE-2025-48949Highgithub.com/navidrome/navidrome: Navidrome allows SQL Injection via role parameterCVE-2025-48865Criticalgithub.com/fabiolb/fabio: Fabio allows HTTP clients to manipulate custom headers it addsCVE-2025-48936Highgithub.com/zitadel/zitadel: ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection

Stop the waste.
Protect your environment with Kodem.