Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-8063Highgithub.com/ollama/ollama: Ollama Divide by Zero VulnerabilityCVE-2024-12886Highgithub.com/ollama/ollama: Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIPCVE-2024-12055Highgithub.com/ollama/ollama: Ollama Allows Out-of-Bounds ReadCVE-2024-7631Mediumgithub.com/openshift/console: OpenShift Console Has a Path Traversal VulnerabilityCVE-2024-25132Mediumgithub.com/openshift/hive: OpenShift Hive Has an Uncontrolled Resource Consumption VulnerabilityCVE-2025-30153Highgithub.com/getkin/kin-openapi: Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filterCVE-2025-1472Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Fails to Properly Perform Viewer Role AuthorizationCVE-2025-0495Mediumgithub.com/docker/buildx: buildx allows a possible credential leakage to telemetry endpointCVE-2025-29786Highgithub.com/expr-lang/expr: Memory Exhaustion in Expr Parser with Unrestricted InputCVE-2025-29781Mediumgithub.com/metal3-io/baremetal-operator/apis: Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRDCVE-2024-40635Mediumgithub.com/containerd/containerd/v2: containerd has an integer overflow in User ID handlingCVE-2025-2241Highgithub.com/openshift/hive: Openshift Hive Exposes VCenter Credentials via ClusterProvisionCVE-2025-30077Mediumgithub.com/onosproject/onos-lib-go: onos-lib-go allows an index out-of-range panicCVE-2025-1767Mediumk8s.io/kubernetes: Kubernetes GitRepo Volume Inadvertent Local Repository AccessCVE-2024-9042Mediumk8s.io/kubernetes: Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query APIGHSA-H2RP-8VPX-Q9R4Criticalgithub.com/cheqd/cheqd-node: cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002)CVE-2025-22870Mediumgolang.org/x/net: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/netGHSA-4WF3-5QJ9-368VCriticalgithub.com/cosmos/ibc-go: IBC-Go: Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain haltGHSA-47WW-FF84-4JRGHighgithub.com/cosmos/cosmos-sdk: Cosmos SDK: x/group can halt when erroring in EndBlockerGHSA-33CR-M232-XQCHCriticalgithub.com/cheqd/cheqd-node: cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC AcknowledgementCVE-2025-27403Highgithub.com/ratify-project/ratify: Ratify Azure authentication providers can leak authentication tokens to non-Azure container registriesCVE-2025-27616Highgithub.com/go-vela/server: Vela Server Has Insufficient Webhook Payload Data VerificationCVE-2024-52812Mediumgithub.com/lf-edge/ekuiper/v2: LF Edge eKuiper allows Stored XSS in Rules FunctionalityCVE-2025-1296Mediumgithub.com/hashicorp/nomad: Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logsGHSA-6WXF-7784-62FPHighgithub.com/strangelove-ventures/horcrux/v3: Horcrux Double Sign Possibility

Stop the waste.
Protect your environment with Kodem.