Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-2475Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost vulnerable to Incorrect Implementation of Authentication AlgorithmCVE-2025-24358Mediumgithub.com/gorilla/csrf: gorilla/csrf CSRF vulnerability due to broken Referer validationCVE-2025-32093Mediumgithub.com/mattermost/mattermost-server: Mattermost Fails to Restrict Certain Operations on System AdminsCVE-2025-3445Highgithub.com/mholt/archiver: mholt/archiver Vulnerable to Path Traversal via Crafted ZIP FileCVE-2025-1386Mediumgithub.com/ClickHouse/ch-go: CVE-2025-1386- Query smuggling in ch-go libraryCVE-2025-22869Highgolang.org/x/crypto: golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key ExchangeCVE-2025-24866Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` EndpointCVE-2025-32387Mediumhelm.sh/helm/v3: Helm Allows A Specially Crafted JSON Schema To Cause A Stack OverflowCVE-2025-32386Mediumhelm.sh/helm/v3: Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory TerminationCVE-2025-32025Mediumgithub.com/bep/imagemeta: bep/imagemeta allows a potentially large memory allocation in PNG and WebP parsingCVE-2025-32024Mediumgithub.com/bep/imagemeta: bep/imagemeta allows excessively large EXIF data structuresCVE-2025-31489Highgithub.com/minio/minio: MinIO performs incomplete signature validation for unsigned-trailer uploadsCVE-2025-31483Mediumminiflux.app/v2: Miniflux Media Proxy vulnerable to Stored Cross-site Scripting due to improper Content-Security-Policy configurationCVE-2023-27592Mediumminiflux.app/v2: Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handlerCVE-2023-27591Highminiflux.app/v2: Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metricsCVE-2025-2786Mediumgithub.com/grafana/tempo-operator: Grafana Tempo Operator Vulnerable to Exposure of Sensitive Information to an Unauthorized ActorCVE-2025-2842Mediumgithub.com/grafana/tempo-operator: Grafana Tempo Operator Vulnerable to Exposure of Sensitive Information to an Unauthorized ActorCVE-2025-31135Mediumgithub.com/phires/go-guerrilla: Go-Guerrilla SMTP Daemon allows the PROXY command to be sent multiple timesCVE-2025-23391Criticalgithub.com/rancher/rancher: Rancher: Restricted Administrator can change Administrator's passwordsCVE-2025-29868Lowgithub.com/apache/answer: Apache Answer User Using External Images Potentially Discloses User InformationCVE-2025-30223Criticalgithub.com/beego/beego/v2: Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User InputGHSA-P799-Q2PR-6MXJMediumgo.rgst.io/stencil/v2: go.rgst.io/stencil/v2 vulnerable to Path TraversalCVE-2025-64346Mediumgithub.com/jaredallard/archives: github.com/jaredallard/archives Has Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CVE-2025-29072Highgithub.com/NethermindEth/juno: Nethermind Juno Potential Denial of Service (DoS) via Integer OverflowCVE-2025-1974Criticalk8s.io/ingress-nginx: ingress-nginx admission controller RCE escalation

Stop the waste.
Protect your environment with Kodem.