Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-27509Criticalgithub.com/fleetdm/fleet/v4: Fleet has SAML authentication vulnerability due to improper SAML response validationCVE-2025-25294Mediumgithub.com/envoyproxy/gateway: Envoy Gateway Log Injection VulnerabilityCVE-2025-27155Mediumgithub.com/matrix-org/pinecone: In-memory stored Cross-site scripting (XSS) vulnerability in pineconesimCVE-2025-27507Criticalgithub.com/zitadel/zitadel/v2: IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP ConfigurationsCVE-2025-27414Mediumgithub.com/minio/minio: MinIO allows an SFTP authentication bypass due to improperly trusted SSH keyCVE-2025-27421Highgithub.com/jasonlovesdoggo/abacus: Goroutine Leak in Abacus SSE ImplementationGHSA-JG6F-48FF-5XRWCriticalgithub.com/cosmos/ibc-go: IBC-Go has Non-deterministic JSON Unmarshalling of IBC AcknowledgementCVE-2025-22952Mediumgithub.com/usememos/memos: Memos Server-Side Request Forgery (SSRF)CVE-2025-23389Highgithub.com/rancher/rancher: Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First LoginCVE-2025-23388Highgithub.com/rancher/rancher: Rancher allows an unauthenticated stack overflow in /v3-public/authproviders APICVE-2025-23387Mediumgithub.com/rancher/rancher: Rancher's SAML-based login via CLI can be denied by unauthenticated usersCVE-2025-27112Mediumgithub.com/navidrome/navidrome: Navidrome allows an authentication bypass in Subsonic API with non-existent usernameCVE-2025-27144Mediumgithub.com/go-jose/go-jose/v4: DoS in go-jose ParsingCVE-2025-24526Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to restrict channel export of archived channelsCVE-2025-25279Criticalgithub.com/mattermost/mattermost/server/v8: Mattermost allows reading arbitrary files related to importing boardsCVE-2025-1412Lowgithub.com/mattermost/mattermost/server/v8: Mattermost fails to invalidate all active sessions when converting a user to a botCVE-2025-20051Criticalgithub.com/mattermost/mattermost/server/v8: Mattermost allows reading arbitrary filesCVE-2025-27100Mediumgithub.com/treeverse/lakefs: lakeFS allows an authenticated user to cause a crash by exhausting server memoryCVE-2025-27088Highgithub.com/oxyno-zeta/s3-proxy/cmd/s3-proxy: S3-Proxy allows Reflected Cross-site Scripting (XSS) in template implementationGHSA-X5VX-95H7-RV4PHighgithub.com/cosmos/cosmos-sdk: Cosmos SDK: Groups module can halt chain when handling a malicious proposalCVE-2025-1293Highgithub.com/hashicorp-forge/hermes: Hermes improperly validates a JWTCVE-2025-27090Mediumgithub.com/bishopfox/sliver: SSRF in sliver teamserverCVE-2025-25196Mediumgithub.com/openfga/openfga: OpenFGA Authorization BypassCVE-2025-24806Lowgithub.com/authelia/authelia/v4: Authelia applies regulation separately to Username-based logins to Email-based loginsCVE-2025-25204Mediumgithub.com/cli/cli/v2: `gh attestation verify` returns incorrect exit code during verification if no attestations are present

Stop the waste.
Protect your environment with Kodem.