Go Vulnerability Database
Data about new vulnerabilities come directly from Go package maintainers or sources such as MITRE and GitHub. Reports are curated by the Go Security team. Learn more at go.dev/security/vuln.
Search
Recent Reports
- CVE-2017-18883, GHSA-w8cc-3h7q-jhc3
- Affects: github.com/mattermost/mattermost-server
- Published: Dec 08, 2025
- Unreviewed
Mattermost Server has low entropy for authorization data as an OAuth 2.0 Service Provider in github.com/mattermost/mattermost-server
- CVE-2017-18884, GHSA-876j-jfqf-m7j7
- Affects: github.com/mattermost/mattermost-server
- Published: Dec 08, 2025
- Unreviewed
Mattermost Server exposes OAuth personal access tokens to attackers in github.com/mattermost/mattermost-server
- CVE-2025-66506, GHSA-f83f-xpx7-ffpw
- Affects: github.com/sigstore/fulcio
- Published: Dec 08, 2025
- Unreviewed
Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio
- CVE-2025-66564, GHSA-4qg8-fj49-pxjh
- Affects: github.com/sigstore/timestamp-authority, github.com/sigstore/timestamp-authority/v2
- Published: Dec 08, 2025
- Unreviewed
Sigstore Timestamp Authority allocates excessive memory during request parsing in github.com/sigstore/timestamp-authority
- CVE-2017-18877, GHSA-9x8x-w6g5-hx4w
- Affects: github.com/mattermost/mattermost-server
- Published: Dec 08, 2025
- Unreviewed
Mattermost Server is vulnerable to XSS attacks against an OAuth 2.0 allow/deny page in github.com/mattermost/mattermost-server
If you don't see an existing, public Go vulnerability in a publicly importable package in our database, please let us know.