Known vulnerabilities in Go programming language - page 3

Vendor: Google
Software CPE: cpe:2.3:a:google:golang:*:*:*:*:*:*:*:*
Total vulnerabilities: 177
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Go programming language Go programming language is affected by 177 known vulnerabilities: 16 high, 125 medium, 36 low Critical High Medium Low

Vulnerabilities (177)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118190 - Resource exhaustion
CVE-2025-58183
CWE-400 Medium
No
No
1.24.8, 1.25.2 07.11.2025 SB2025110705
SB2025110725
SB2025110726
and 172 more
#VU118189 - Improper input validation
CVE-2025-58188
CWE-20 Medium
No
No
1.24.8, 1.25.2 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 108 more
#VU118188 - Allocation of Resources Without Limits or Throttling
CVE-2025-58186
CWE-770 Medium
No
No
1.24.8, 1.25.2 07.11.2025 SB2025110705
SB2025110731
SB2025120304
and 19 more
#VU118187 - Resource exhaustion
CVE-2025-58185
CWE-400 Medium
No
No
1.24.8, 1.25.2 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 110 more
#VU118186 - Improper input validation
CVE-2025-47912
CWE-20 Low
No
No
1.24.8, 1.25.2 07.11.2025 SB2025110705
SB2025110731
SB2025120304
and 19 more
#VU118184 - Resource exhaustion
CVE-2025-61723
CWE-400 Medium
No
No
1.24.8, 1.25.2 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 116 more
#VU118183 - Improper Encoding or Escaping of Output
CVE-2025-58189
CWE-116 Low
No
No
1.24.8, 1.25.2 07.11.2025 SB2025110705
SB2025110711
SB2025110712
and 118 more
#VU118179 - Resource exhaustion
CVE-2025-61725
CWE-400 Medium
No
No
1.24.8, 1.25.2 07.11.2025 SB2025110705
SB2025110714
SB2025110715
and 74 more
#VU114341 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-4674
CWE-78 High
No
No
1.23.11, 1.24.5 21.08.2025 SB2025082138
SB2025082164
SB2025082165
and 18 more
#VU114080 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-47907
CWE-362 Low
No
No
1.23.12, 1.24.6 14.08.2025 SB2025081423
SB2025081424
SB2025081425
and 48 more
#VU114079 - Improper input validation
CVE-2025-47906
CWE-20 Low
No
No
1.23.12, 1.24.6 14.08.2025 SB2025081423
SB2025081424
SB2025081425
and 130 more
#VU110253 - Protection Mechanism Failure
CVE-2025-22874
CWE-693 Low
No
No
1.24.4 07.06.2025 SB2025060702
SB2025061002
SB2025081114
and 16 more
#VU110252 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-0913
CWE-59 Low
No
No
1.23.10, 1.24.4 07.06.2025 SB2025060702
SB2025061002
SB2025061003
and 8 more
#VU110251 - Exposure of sensitive information to an unauthorized actor
CVE-2025-4673
CWE-200 Low
No
No
1.23.10, 1.24.4 07.06.2025 SB2025060701
SB2025060702
SB2025061002
and 35 more
#VU109823 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-22873
CWE-22 Medium
No
No
1.23.9, 1.24.3 26.05.2025 SB2025052631
SB2025052636
SB2025052637
and 3 more
#VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-22871
CWE-444 Medium
No
No
1.23.8, 1.24.2 05.04.2025 SB2025040507
SB2025040508
SB2025040739
and 109 more
#VU103933 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-22867
CWE-94 Low
No
No
1.24 rc.3 12.02.2025 SB20250212100
SB20250212103
#VU103932 - Missing release of memory after effective lifetime
CVE-2025-22866
CWE-401 Low
No
No
1.22.12, 1.23.6, 1.24 rc.3 12.02.2025 SB20250212100
SB20250212101
SB20250212102
and 27 more
#VU103458 - Improper input validation
CVE-2025-22865
CWE-20 Medium
No
No
1.24 rc2 30.01.2025 SB2025013039
SB2025013045
SB2025072441
and 2 more
#VU103457 - Improper input validation
CVE-2024-45341
CWE-20 Low
No
No
1.22.11, 1.23.5, 1.24 rc2 30.01.2025 SB2025013039
SB2025013043
SB2025013044
and 23 more


Showing elements 41 - 60 out of 177