Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-41658Mediumgithub.com/casdoor/casdoor: Casdoor has reflected XSS in QrCodePage.js (GHSL-2024-036)CVE-2024-41657Highgithub.com/casdoor/casdoor: Casdoor CORS misconfiguration (GHSL-2024-035)CVE-2024-42490Criticalgoauthentik.io: GoAuthentik vulnerable to Insufficient Authorization for several API endpointsCVE-2024-39836Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows remote/synthetic users to create sessions, reset passwordsCVE-2024-32939Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't redact remote users' original email addressesCVE-2024-40886Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Cross-Site Request Forgery vulnerabilityCVE-2024-8071Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't restrict which roles can promote a user as system adminGHSA-FPGJ-CR28-FVPXMediumgithub.com/CosmWasm/wasmd: CWA-2024-006: wasmd non-deterministic module_query_safe queryGHSA-G8W7-7VGG-X7XGHighgithub.com/CosmWasm/wasmd: CWA-2024-005: Stackoverflow in wasmdCVE-2024-6508Mediumgithub.com/openshift/console: Openshift Console insufficient entropy vulnerabilityCVE-2024-43406Highgithub.com/lf-edge/ekuiper: LF Edge eKuiper has a SQL Injection in sqlKvStoreCVE-2024-39690Highgithub.com/projectcapsule/capsule: Capsule tenant owner with "patch namespace" permission can hijack system namespacesCVE-2024-6322Mediumgithub.com/grafana/grafana: Grafana plugin data sources vulnerable to access control bypassCVE-2024-43379Lowgithub.com/trufflesecurity/trufflehog/v3: Trufflehog vulnerable to Blind SSRF in some DetectorsCVE-2024-42486Mediumgithub.com/cilium/cilium: Cilium leaks information via incorrect ReferenceGrant update logic in Gateway APICVE-2024-42487Mediumgithub.com/cilium/cilium: Gateway API route matching order contradicts specificationCVE-2024-42488Mediumgithub.com/cilium/cilium: Policy bypass for Host Firewall policy due to race condition in Cilium agentCVE-2024-32231Criticalgithub.com/stashapp/stash: SQL injection in github.com/stashapp/stashCVE-2024-7625Mediumgithub.com/hashicorp/nomad: Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive UnpackingGHSA-83QR-9V2H-QXP4Mediumgithub.com/cosmos/gaia: Cosmos Hub (Gaia): The check for the height of cryptographic equivocation evidence is missingCVE-2024-42368Mediumgithub.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension: open-telemetry has an Observable Timing DiscrepancyCVE-2024-42480Criticalgithub.com/clastix/kamaji: RBAC Roles for `etcd` created by Kamaji are not disjunctCVE-2024-41890Mediumgithub.com/apache/incubator-answer: Apache Answer: The link to reset the user's password will remain valid after sending a new linkCVE-2024-41888Mediumgithub.com/apache/incubator-answer: Apache Answer: The link for resetting user password is not Single-UseCVE-2024-42473Highgithub.com/openfga/openfga: OpenFGA Authorization Bypass

Stop the waste.
Protect your environment with Kodem.