Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-47933Criticalgithub.com/argoproj/argo-cd: Argo CD allows cross-site scripting on repositories pageGHSA-H5F8-CRRQ-4PW8Highgithub.com/edgelesssys/contrast: Contrast workload secrets leak to logs on INFO levelCVE-2025-47952Lowgithub.com/traefik/traefik/v3: Traefik allows path traversal using url encodingCVE-2025-4057Mediumgithub.com/arkmq-org/activemq-artemis-operator: ActiveMQ Artemis AMQ Broker Operator Starting Credentials ReuseCVE-2025-48371Mediumgithub.com/openfga/openfga: OpenFGA Authorization BypassCVE-2025-48374Mediumzotregistry.dev/zot: zot logs secretsCVE-2025-48075Highgithub.com/gofiber/fiber/v2: Fiber panics when fiber.Ctx.BodyParser parses invalid range indexCVE-2025-4123Highgithub.com/grafana/grafana: Grafana Cross-Site-Scripting (XSS) via custom loaded frontend pluginCVE-2025-5030Lowgithub.com/Ackites/KillWxapkg: Ackites KillWxapkg vulnerable to OS Command InjectionCVE-2025-5031Lowgithub.com/Ackites/KillWxapkg: Ackites KillWxapkg Zip Bomb Resource ExhaustionCVE-2025-48069Mediumgithub.com/Shopify/ejson2env/v2: Insufficient input sanitization in ejson2env CVE-2025-47291Mediumgithub.com/containerd/containerd/v2: containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods.CVE-2025-48056Mediumgithub.com/cilium/hubble: Character injection in Hubble CLICVE-2025-47290Highgithub.com/containerd/containerd/v2: containerd allows host filesystem access on pullCVE-2025-47284Criticalgithub.com/gardener/gardener: Gardener allows metadata injection for a project secret which can lead to privilege escalationCVE-2025-47283Criticalgithub.com/gardener/gardener: Gardener allows bypassing project secret validation which can lead to privilege escalationCVE-2025-47282Criticalgithub.com/gardener/external-dns-management: Gardener External DNS Management allows malicious google credential in DNS secret to lead to privilege escalationCVE-2024-40120Mediumgithub.com/seaweedfs/seaweedfs: SeaweedFS Vulnerable to SQL InjectionCVE-2025-1975Highgithub.com/ollama/ollama: Ollama Server Vulnerable to Denial of Service (DoS) AttackCVE-2025-2570Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Fails to Check User Access to `ExperimentalSettings`CVE-2025-2527Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Fails to Verify User's Permissions When Accessing GroupsGHSA-869W-47C6-FQ8QHighgithub.com/babylonlabs-io/babylon: Babylon Integer Overflow in Distribution Module CumulativeRewardRatio Calculation Leading to Chain HaltGHSA-7MM3-VFG8-7RG6Highgithub.com/babylonlabs-io/babylon: Babylon Finality Provider `MsgCommitPubRandList` replay attackCVE-2025-3446Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Fails to Validate Team Invite PermissionsCVE-2025-31947Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Fails to Lockout LDAP Users After Repeated Login Failures

Stop the waste.
Protect your environment with Kodem.