Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-35965Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Playbooks fails to validate the uniqueness and quantity of task actionsCVE-2026-26994Mediumgithub.com/refraction-networking/utls: uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canariesCVE-2025-24016Criticalgithub.com/wazuh/wazuh: Wazuh server vulnerable to remote code executionCVE-2025-32963Mediumgithub.com/minio/operator: Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STSCVE-2025-32793Mediumgithub.com/cilium/cilium: In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clustersCVE-2025-32431Highgithub.com/traefik/traefik: Traefik has a possible vulnerability with its path matchersCVE-2025-43973Mediumgithub.com/osrg/gobgp: GoBGP does not verify that the input lengthCVE-2025-43972Mediumgithub.com/osrg/gobgp: GoBGP crashes in the flowspec parserCVE-2025-43970Mediumgithub.com/osrg/gobgp: GoBGP does not properly check the input lengthCVE-2025-43971Highgithub.com/osrg/gobgp/v3: GoBGP panics due to a zero value for softwareVersionLenCVE-2025-3801Mediumgithub.com/songquanpeng/one-api: one-api Cross-site Scripting vulnerabilityGHSA-5423-JCJM-2GPVCriticalgithub.com/traefik/traefik/v2: Traefik affected by Go HTTP Request Smuggling VulnerabilityGHSA-3WQC-MWFX-672PHighgithub.com/traefik/traefik/v3: Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerabilityCVE-2025-22872Mediumgolang.org/x/net: golang.org/x/net vulnerable to Cross-site ScriptingCVE-2025-2564Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Incorrect Authorization vulnerabilityCVE-2025-27936Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost vulnerable to Observable Timing DiscrepancyCVE-2025-31363Lowgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't restrict domains LLM can request to contact upstreamCVE-2025-27571Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Incorrect Authorization vulnerabilityCVE-2025-24839Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Incorrect Authorization vulnerabilityCVE-2025-27538Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Missing Authentication for Critical FunctionCVE-2025-30215Criticalgithub.com/nats-io/nats-server/v2: NATS Server may fail to authorize certain Jetstream admin APIsGHSA-459X-Q9HG-4GPQHighgithub.com/kyverno/kyverno: Kyverno vulnerable to SSRF via Service CallsCVE-2025-30206Criticalgithub.com/donknap/dpanel: Dpanel's hard-coded JWT secret leads to remote code executionCVE-2025-32445Criticalgithub.com/argoproj/argo-events: Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR CVE-2025-2424Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Incorrect Authorization vulnerability

Stop the waste.
Protect your environment with Kodem.