Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-45339Mediumgithub.com/golang/glog: Insecure Temporary File usage in github.com/golang/glogCVE-2025-0750Mediumgithub.com/cri-o/cri-o: CRI-O Path Traversal vulnerabilityCVE-2025-24354Mediumgithub.com/imgproxy/imgproxy: imgproxy is vulnerable to SSRF against 0.0.0.0CVE-2025-24355Highgithub.com/updatecli/updatecli: Updatecli exposes Maven credentials in console outputCVE-2025-24030Highgithub.com/envoyproxy/gateway: Envoy Admin Interface Exposed through prometheus metrics endpointCVE-2025-23047Mediumgithub.com/cilium/cilium: Cilium has an information leakage via insecure default Hubble UI CORS headerCVE-2025-23028Mediumgithub.com/cilium/cilium: DoS in Cilium agent DNS proxy from crafted DNS responsesCVE-2024-11218Highgithub.com/containers/buildah: Buildah allows build breakout using malicious Containerfiles and concurrent buildsCVE-2024-10846Mediumgithub.com/compose-spec/compose-go/v2: Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loopCVE-2025-0377Highgithub.com/hashicorp/go-slug: HashiCorp go-slug Vulnerable to Zip Slip AttackCVE-2025-24337Highgithub.com/writefreely/writefreely: Insecure default config access in WriteFreelyCVE-2025-23208Highzotregistry.dev/zot: Zot IdP group membership revocation ignoredCVE-2024-52594Mediumgithub.com/matrix-org/gomatrixserverlib: Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federationCVE-2025-20621Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost webapp crash via a crafted postCVE-2024-56515Mediumgithub.com/t2bot/matrix-media-repo: Matrix Media Repo (MMR) allows untrusted file formats can be thumbnailed, invoking potentially further untrusted decodersCVE-2024-52602Mediumgithub.com/t2bot/matrix-media-repo: Matrix Media Repo (MMR) allows Server-Side Request Forgery (SSRF) on redirects and federationCVE-2024-52791Mediumgithub.com/t2bot/matrix-media-repo: matrix-media-repo (MMR) allows a denial of service through memory exhaustionCVE-2024-36403Mediumgithub.com/t2bot/matrix-media-repo: matrix-media-repo (MMR) allows denial of service/high operating costs through unauthenticated downloadsCVE-2024-36402Mediumgithub.com/t2bot/matrix-media-repo: matrix-media-repo (MMR) allows unauthenticated writes to the media repository, which may allow planting of problematic contentCVE-2024-5138Mediumgithub.com/snapcore/snapd: CVE-2024-5138: snapd snapctl auth bypassCVE-2025-20088Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly validate post propsCVE-2025-20086Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly validate post propsCVE-2025-21088Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Incorrect Type Conversion or CastCVE-2024-52281Highgithub.com/rancher/rancher: Rancher UI has Stored Cross-site Scripting vulnerabilityCVE-2024-53263Highgithub.com/git-lfs/git-lfs/v3: Git LFS permits exfiltration of credentials via crafted HTTP URLs

Stop the waste.
Protect your environment with Kodem.