Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-24513Mediumk8s.io/ingress-nginx: ingress-nginx controller - auth secret file path traversal vulnerabilityCVE-2025-24514Highk8s.io/ingress-nginx: ingress-nginx controller - configuration injection via unsanitized auth-url annotationCVE-2025-1097Highk8s.io/ingress-nginx: ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotationCVE-2025-1098Highk8s.io/ingress-nginx: ingress-nginx controller - configuration injection via unsanitized mirror annotationsCVE-2025-30163Lowgithub.com/cilium/cilium: Cilium node based network policies may incorrectly allow workload trafficCVE-2025-29778Mediumgithub.com/kyverno/kyverno: Kyverno ignores subjectRegExp and IssuerRegExpCVE-2025-30162Lowgithub.com/cilium/cilium: Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancersCVE-2025-45286Lowgithub.com/mccutchen/go-httpbin: Reflected XSS in go-httpbin due to unrestricted client control over Content-TypeCVE-2025-30204Highgithub.com/golang-jwt/jwt/v5: jwt-go allows excessive memory allocation during header parsingCVE-2024-53351Highgithub.com/pipe-cd/pipecd: PipeCD Vulnerable to Privilege EscalationCVE-2025-30157Mediumgithub.com/envoyproxy/envoy: Envoy crashes when HTTP ext_proc processes local repliesCVE-2025-30179Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Fails to Enforce Certain Search APIsCVE-2025-27933Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows members with permission to convert public channels to private and convert private to publicCVE-2025-27715Lowgithub.com/mattermost/mattermost/server/v8: Mattermost fail to prompt for explicit approval before adding a team admin to a private channelCVE-2025-24920Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Fails to Restrict Bookmark Creation and Updates in Archived ChannelsCVE-2025-25068Highgithub.com/mattermost/mattermost/server/v8: Mattermost Fails to Enforce MFA on Plugin EndpointsCVE-2025-25274Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Fails to Restrict Command Execution in Archived ChannelsCVE-2025-29923Lowgithub.com/redis/go-redis/v9: go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishmentCVE-2025-29922Criticalgithub.com/kcp-dev/kcp: kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual WorkspaceCVE-2025-29914Mediumgithub.com/jptosso/coraza-waf: OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`CVE-2024-7598Lowk8s.io/kubernetes/cmd/kube-apiserver: Kubernetes kube-apiserver Vulnerable to Race ConditionCVE-2025-0312Highgithub.com/ollama/ollama: Ollama Denial of Service (DoS) via Null Pointer DereferenceCVE-2025-0315Highgithub.com/ollama/ollama: Ollama Allocation of Resources Without Limits or Throttling vulnerabilityCVE-2025-0317Highgithub.com/ollama/ollama: Ollama Divide By Zero vulnerabilityCVE-2024-9900Mediumgithub.com/mudler/LocalAI: LocalAI Cross-Site Scripting (XSS) vulnerability in its search functionality

Stop the waste.
Protect your environment with Kodem.