Go Vulnerability Database

Data about new vulnerabilities come directly from Go package maintainers or sources such as MITRE and GitHub. Reports are curated by the Go Security team. Learn more at go.dev/security/vuln.

Search

Recent Reports

GO-2025-3665

Inspektor Gadget Security Policies Can be Bypassed in github.com/inspektor-gadget/inspektor-gadget

GO-2025-3663

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault

GO-2025-3662

Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault

GO-2025-3661

Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization in github.com/casdoor/casdoor

GO-2025-3660

OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa

View all reports

If you don't see an existing, public Go vulnerability in a publicly importable package in our database, please let us know.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL