Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
585849
AlmaLinux
4142
Alpaquita
7076
Alpine
3908
Android
2912
BellSoft Hardened Containers
249
Bitnami
6210
Chainguard
28710
CRAN
11
crates.io
1885
Debian
50272
Echo
2172
GHC
3
GIT
73412
GitHub Actions
37
Go
5021
Hackage
25
Hex
44
Julia
332
Linux
21749
Mageia
5751
Maven
6046
MinimOS
7739
npm
213007
NuGet
1494
openEuler
5462
openSUSE
10280
OSS-Fuzz
3671
Packagist
5500
Pub
10
PyPI
17310
Red Hat
17588
Rocky Linux
2424
RubyGems
1797
SUSE
17024
SwiftURL
42
Ubuntu
48074
VSCode
14
Wolfi
14446
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-h8cp-697h-8c8p
Go/github.com/smallstep/certificates
Step CA Has Authorization Bypass in ACME and SCEP Provisioners
10 hours ago
Fix available
Severity - 10.0 (Critical)
GHSA-jf75-p25m-pw74
Go/github.com/coder/coder/v2
Coder logs sensitive objects unsanitized
10 hours ago
Fix available
Severity - 7.8 (High)
GHSA-j7c9-79x7-8hpr
Go/github.com/smallstep/certificates
step-ca Has Improper Authorization Check for SSH Certificate Revocation
10 hours ago
Fix available
Severity - 5.0 (Medium)
GHSA-46gc-mwh4-cc5r
Go/github.com/docker/mcp-gateway
Docker MCP Plugin and Docker MCP Gateway have DNS Rebinding vulnerability when running in sse or streaming mode
10 hours ago
Fix available
Severity - 7.3 (High)
GHSA-j3rw-fx6g-q46j
Go/github.com/apptainer/apptainer
Apptainer ineffectively applies selinux and apparmor --security options
yesterday
Fix available
Severity - 4.5 (Medium)
GHSA-wwrx-w7c9-rf87
Go/github.com/sylabs/singularity/v4
Singluarity ineffectively applies selinux / apparmor LSM process labels
yesterday
Fix available
Severity - 4.5 (Medium)
GO-2025-4175
Go/stdlib
Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509
yesterday
Fix available
GO-2025-4163
Go/github.com/free5gc/nssf
NSSF panic due to nil pointer dereference when expiry field is omitted in NSSAIAvailability POST in github.com/free5gc/nssf
yesterday
Fix available
GO-2025-4164
Go/github.com/free5gc/pcf
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API in github.com/free5gc/pcf
yesterday
Fix available
GO-2025-4171
Go/github.com/flipped-aurora/gin-vue-admin
Gin-vue-admin has an arbitrary file deletion vulnerability in github.com/flipped-aurora/gin-vue-admin
yesterday
Fix available
GO-2025-4172
Go/github.com/mattermost/mattermost
Go/github.com/mattermost/mattermost-server
Go/github.com/mattermost/mattermost-server/v5
Go/github.com/mattermost/mattermost-server/v6
Go/github.com/mattermost/mattermost/server/v8
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost
yesterday
No fix available
GO-2025-4174
Go/github.com/cloudflare/gokey
gokey allows secret recovery from a seed file without the master password in github.com/cloudflare/gokey
yesterday
Fix available
GO-2025-4155
Go/stdlib
Excessive resource consumption when printing error string for host certificate validation in crypto/x509
yesterday
Fix available
GHSA-69jw-4jj8-fcxm
Go/github.com/cloudflare/gokey
gokey allows secret recovery from a seed file without the master password
yesterday
Fix available
Severity - 7.1 (High)
GHSA-58w6-w55x-6wq8
Go/github.com/mattermost/mattermost/server/v8
Go/github.com/mattermost/mattermost
Mattermost fails to validate user permissions in Boards
yesterday
Fix available
Severity - 3.1 (Low)
GHSA-32fw-gq77-f2f2
Go/github.com/eclipse/paho.mqtt.golang
Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes
yesterday
Fix available
Severity - 6.3 (Medium)
Load more...
Go - OSV