Go Vulnerability Database
Data about new vulnerabilities come directly from Go package maintainers or sources such as MITRE and GitHub. Reports are curated by the Go Security team. Learn more at go.dev/security/vuln.
Search
Recent Reports
GO-2025-3828
- CVE-2025-4674, CVE-2025-4674
- Affects: cmd/go
- Published: Jul 29, 2025
The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.
GO-2025-3827
- CVE-2025-54379, GHSA-526j-mv3p-f4vv
- Affects: github.com/lf-edge/ekuiper, github.com/lf-edge/ekuiper/v2
- Published: Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper
GO-2025-3826
- CVE-2025-30086, GHSA-h27m-3qw8-3pw8
- Affects: github.com/goharbor/harbor
- Published: Jul 29, 2025
Possible ORM Leak Vulnerability in the Harbor in github.com/goharbor/harbor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/goharbor/harbor before v2.4.0-rc1.0.20250331071157-dce7d9f5cffb.
GO-2025-3825
- CVE-2025-32019, GHSA-f9vc-vf3r-pqqq
- Affects: github.com/goharbor/harbor, github.com/goharbor/harbor, and 2 more
- Published: Jul 29, 2025
Harbor repository description page has Cross-site Scripting vulnerability in github.com/goharbor/harbor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/goharbor/harbor before v2.4.0-rc1.0.20250421072404-a13a16383a41.
GO-2025-3824
- CVE-2025-51471, GHSA-x9hg-5q6g-q3jr
- Affects: github.com/ollama/ollama
- Published: Jul 30, 2025
Ollama vulnerable to Cross-Domain Token Exposure in github.com/ollama/ollama
If you don't see an existing, public Go vulnerability in a publicly importable package in our database, please let us know.