Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-M3RH-CVR5-X6Q4Mediumgithub.com/CosmWasm/wasmd: CosmWasm wasmd has large address count in ValidateBasicGHSA-RG2Q-2JH9-447QMediumcosmwasm-vm: Gas mispricing in cosmwasm-vmCVE-2024-41270Mediumgithub.com/appleboy/gorush: Gorush uses deprecated TLS versionsCVE-2024-6886Criticalcode.gitea.io/gitea: Gitea Cross-site Scripting VulnerabilityCVE-2023-37469Criticalgithub.com/IceWhaleTech/CasaOS: CasaOS Command Injection vulnerabilityCVE-2023-30625Criticalgithub.com/rudderlabs/rudder-server: rudder-server is vulnerable to SQL injectionCVE-2024-35182Mediumgithub.com/layer5io/meshery: Meshery SQL Injection vulnerabilityCVE-2024-35181Mediumgithub.com/layer5io/meshery: Meshery SQL Injection vulnerabilityCVE-2024-31450Mediumgithub.com/owncast/owncast: Owncast Path Traversal vulnerabilityCVE-2024-29192Highgithub.com/AlexxIT/go2rtc: gotortc vulnerable to Cross-Site Request ForgeryCVE-2024-29193Mediumgithub.com/AlexxIT/go2rtc: gotortc Cross-site Scripting vulnerabilityCVE-2024-29191Mediumgithub.com/AlexxIT/go2rtc: gotortc Cross-site Scripting vulnerabilityCVE-2024-29031Highgithub.com/layer5io/meshery: Meshery SQL Injection vulnerabilityCVE-2024-29030Mediumgithub.com/usememos/memos: memos vulnerable to Server-Side Request Forgery in /api/resourceCVE-2024-29029Mediumgithub.com/usememos/memos: memos vulnerable to Server-Side Request Forgery and Cross-site ScriptingCVE-2024-29028Mediumgithub.com/usememos/memos: memos vulnerable to Server-Side Request Forgery in /o/get/httpmetaCVE-2024-29026Highgithub.com/owncast/owncast: Owncast Cross-Site Request Forgery vulnerabilityCVE-2023-48703Highgithub.com/RobotsAndPencils/go-saml: RobotsAndPencils go-saml authentication bypass vulnerabilityCVE-2023-26494Mediumgo.thethings.network/lorawan-stack/v3: lorawan-stack Open Redirect vulnerabilityGHSA-6VJM-54VP-MXHXHighgithub.com/juju/juju: Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charmCVE-2024-41820Highgithub.com/kubean-io/kubean: Kubean vulnerable to cluster-level privilege escalationCVE-2025-24882Mediumgithub.com/regclient/regclient: In regclient, pinned manifest digests may be ignoredCVE-2024-37286Mediumgithub.com/elastic/apm-server: APM Server vulnerable to Insertion of Sensitive Information into Log FileCVE-2024-3056Highgithub.com/containers/podman/v5: Podman vulnerable to memory-based denial of serviceCVE-2024-41956Highgithub.com/charmbracelet/soft-serve: soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests

Stop the waste.
Protect your environment with Kodem.