Go Vulnerability Database
Data about new vulnerabilities come directly from Go package maintainers or sources such as MITRE and GitHub. Reports are curated by the Go Security team. Learn more at go.dev/security/vuln.
Search
Recent Reports
GO-2025-3665
- GHSA-pv22-fqcj-7xwh
- Affects: github.com/inspektor-gadget/inspektor-gadget
- Published: May 06, 2025
Inspektor Gadget Security Policies Can be Bypassed in github.com/inspektor-gadget/inspektor-gadget
GO-2025-3663
- CVE-2025-4166, GHSA-gcqf-f89c-68hv
- Affects: github.com/hashicorp/vault
- Published: May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault
GO-2025-3662
- CVE-2025-3879, GHSA-f9ch-h8j7-8jwg
- Affects: github.com/hashicorp/vault
- Published: May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault
GO-2025-3661
- CVE-2025-4210
- Affects: github.com/casdoor/casdoor
- Published: May 06, 2025
Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization in github.com/casdoor/casdoor
GO-2025-3660
- CVE-2025-46569, GHSA-6m8w-jc87-6cr7
- Affects: github.com/open-policy-agent/opa
- Published: May 05, 2025
OPA server Data API HTTP path injection of Rego in github.com/open-policy-agent/opa
If you don't see an existing, public Go vulnerability in a publicly importable package in our database, please let us know.