Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-56323Mediumgithub.com/openfga/openfga: OpenFGA Authorization BypassCVE-2024-56138Mediumgithub.com/notaryproject/notation-go: notation-go's timestamp signature generation lacks certificate revocation checkCVE-2024-51491Lowgithub.com/notaryproject/notation-go: notation-go has an OS error when setting CRL cache leads to denial of signature verificationCVE-2025-22149Lowgithub.com/MicahParks/jwkset: JWK Set's HTTP client only overwrites and appends JWK to local cache during refreshCVE-2025-22449Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Incorrect Authorization vulnerabilityCVE-2025-20033Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Improper Validation of Specified Type of Input vulnerabilityCVE-2025-22445Lowgithub.com/mattermost/mattermost/server/v8: Mattermost has Improper Check for Unusual or Exceptional ConditionsCVE-2025-22130Mediumgithub.com/charmbracelet/soft-serve: Soft Serve vulnerable to path traversal attacksGHSA-2R2V-9PF8-6342Highgithub.com/h44z/wg-portal: WireGuard Portal v2 Vulnerable to OAuth Insecure Redirect URI / Account TakeoverCVE-2025-21614Highgopkg.in/src-d/go-git.v4: go-git clients vulnerable to DoS via maliciously crafted Git server repliesCVE-2025-21613Criticalgopkg.in/src-d/go-git.v4: go-git has an Argument Injection via the URL fieldCVE-2025-21609Highgithub.com/siyuan-note/siyuan/kernel: SiYuan has an arbitrary file deletion vulnerabilityCVE-2024-56514Mediumgithub.com/karmada-io/karmada: Karmada Tar Slips in CRDs archive extractionCVE-2024-56513Highgithub.com/karmada-io/karmada: Karmada PULL Mode Cluster Privilege EscalationCVE-2024-25133Highgithub.com/openshift/hive: OpenShift Hive RCE through AWS/Kubernetes client configuration leads to privilege escalationCVE-2024-39930Criticalgogs.io/gogs: Gogs has an argument Injection in the built-in SSH serverCVE-2024-39932Criticalgogs.io/gogs: Gogs allows argument injection during the previewing of changesCVE-2024-39931Criticalgogs.io/gogs: Gogs allows deletion of internal filesCVE-2024-39933Highgogs.io/gogs: Gogs allows argument Injection when tagging new releasesCVE-2024-56362Highgithub.com/navidrome/navidrome: Navidrome Stores JWT Secret in Plaintext in navidrome.dbCVE-2024-45387Highgithub.com/apache/trafficcontrol/v8: SQL injection in Apache Traffic ControlCVE-2024-55947Highgogs.io/gogs: Path Traversal in file update API in gogsCVE-2024-54148Highgogs.io/gogs: Remote Command Execution in file editing in gogsCVE-2024-28892Criticalgithub.com/mayuresh82/gocast: GoCast OS Command Injection vulnerabilityCVE-2024-12678Mediumgithub.com/hashicorp/nomad: Hashicorp Nomad Incorrect Privilege Assignment vulnerability

Stop the waste.
Protect your environment with Kodem.