Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-0426Mediumk8s.io/kubernetes: Node Denial of Service via kubelet Checkpoint APICVE-2024-57604Criticalgithub.com/mayswind/ezbookkeeping: MaysWind ezBookkeeping has Improper Privilege ManagementCVE-2024-57603Mediumgithub.com/mayswind/ezbookkeeping: Missing rate limit in MaysWind ezBookkeepingGHSA-6FGM-X6FF-W78FMediumgithub.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v7: Potential Denial-of-Service condition leading to temporary disability in IBC transfers to the native chainCVE-2025-25199Highgithub.com/microsoft/go-crypto-winnative: go-crypto-winnative BCryptGenerateSymmetricKey memory leakCVE-2025-1243Lowgo.temporal.io/api: Unencrypted transmission in Temporal api-go libraryCVE-2025-24976Highgithub.com/distribution/distribution/v3: Distribution's token authentication allows to inject an untrusted signing key in a JWTCVE-2025-24366Highgithub.com/drakkan/sftpgo/v2: SFTPGo has insufficient sanitization of user provided rsync commandCVE-2025-24787Highgithub.com/clidey/whodb/core: WhoDB allows parameter injection in DB connection URIs leading to local file inclusionCVE-2025-24786Criticalgithub.com/clidey/whodb/core: WhoDB has a path traversal opening Sqlite3 databaseCVE-2025-26260Mediumgithub.com/plentico/plenti: Plenti - Code Injection - Denial of ServicesGHSA-VQV5-385R-2HF8Highgithub.com/edgelesssys/contrast: Contrast's unauthenticated recovery allows Coordinator impersonationGHSA-W7WM-2425-7P2HHighgithub.com/edgelesssys/marblerun: MarbleRun unauthenticated recovery allows Coordinator impersonationGHSA-MX2J-7CMV-353CMediumcosmwasm-vm: wasmvm: Malicious smart contract can slow down block productionGHSA-23QP-3C2M-XX6WMediumgithub.com/CosmWasm/wasmvm: wasmvm: Malicious smart contract can crash the chainGHSA-R3R4-G7HQ-PQ4FHighgithub.com/cometbft/cometbft: CometBFT allows a malicious peer to stall the network by disseminating seemingly valid block partsCVE-2025-24371Mediumgithub.com/cometbft/cometbft: CometBFT allows a malicious peer to make node stuck in blocksyncCVE-2024-11741Mediumgithub.com/grafana/grafana: Grafana Alerting VictorOps integration could be exposed to users with Viewer permissionCVE-2025-23216Mediumgithub.com/argoproj/argo-cd/v2: Argo CD does not scrub secret values from patch errorsCVE-2025-24376Mediumgithub.com/kubewarden/kubewarden-controller: KubeWarden's AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resourcesCVE-2025-24784Mediumgithub.com/kubewarden/kubewarden-controller: Kubewarden-Controller information leak via AdmissionPolicyGroup ResourceCVE-2025-24883Mediumgithub.com/ethereum/go-ethereum: Go Ethereum vulnerable to DoS via malicious p2p messageGHSA-274V-MGCV-CM8JMediumgithub.com/argoproj/gitops-engine: Argo CD GitOps Engine does not scrub secret values from patch errorsCVE-2025-24884Mediumgithub.com/RichardoC/kube-audit-rest: kube-audit-rest's example logging configuration could disclose secret values in the audit logCVE-2024-13484Highgithub.com/redhat-developer/gitops-operator: OpenShift GitOps Operator Namespace Isolation Break

Stop the waste.
Protect your environment with Kodem.