Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-41259Mediumgithub.com/navidrome/navidrome: Navidrome uses MD5 hashing algorithmCVE-2024-41265Highgithub.com/cortexproject/cortex: cortex establishes TLS connections with `InsecureSkipVerify` set to `true`CVE-2024-41260Highgithub.com/netbirdio/netbird: NetBird uses a static initialization vector (IV)CVE-2024-41264Mediumgithub.com/casdoor/casdoor: casdoor's use of`ssh.InsecureIgnoreHostKey()` disables host key verificationCVE-2024-41926Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows remote actor to set arbitrary RemoteId values for synced usersCVE-2024-41144Highgithub.com/mattermost/mattermost/server/v8: Mattermost allows remote actor to create/update/delete posts in arbitrary channelsCVE-2024-39837Lowgithub.com/mattermost/mattermost/server/v8: Mattermost did not properly restrict channel creationCVE-2024-39839Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows a user on a remote to set their remote username prop to an arbitrary stringCVE-2024-39832Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handlingCVE-2024-39777Criticalgithub.com/mattermost/mattermost/server/v8: Mattermost allows unsolicited invites to expose access to local channelsCVE-2024-41162Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows a remote actor to make an arbitrary local channel read-onlyCVE-2024-39274Criticalgithub.com/mattermost/mattermost/server/v8: Mattermost failed to properly validate that the channel that comes from the sync message is a shared channelCVE-2024-29977Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost failed to properly validate synced reactionsCVE-2024-36492Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost failed to disallow the modification of local users when syncing users in shared channelsCVE-2024-41255Highgithub.com/mickael-kerjean/filestash: Filestash configured to skip TLS certificate verification when using the FTPS protocolCVE-2024-41256Highgithub.com/mickael-kerjean/filestash: Filestash skips TLS certificate verification process when sending out email verification codesCVE-2024-40464Highgithub.com/beego/beego/v2: Beego privilege escalation vulnerabilityCVE-2024-40465Highgithub.com/beego/beego/v2: Beego privilege escalation vulnerabilityCVE-2024-41952Mediumgithub.com/zitadel/zitadel: ZITADEL "ignoring unknown usernames" vulnerabilityCVE-2024-41953Mediumgithub.com/zitadel/zitadel: ZITADEL has improper HTML sanitization in emails and Console UICVE-2024-22278Highgithub.com/goharbor/harbor: Harbor fails to validate the user permissions when updating project configurationsGHSA-WM25-J4GW-6VR3Criticalgithub.com/prest/prest: pREST vulnerable to jwt bypass + sql injectionCVE-2024-41110Criticalgithub.com/docker/docker: Authz zero length regressionCVE-2024-29069Lowgithub.com/snapcore/snapd: snapd failed to properly check the destination of symbolic links when extracting a snapCVE-2024-29068Mediumgithub.com/snapcore/snapd: snapd failed to properly check the file type when extracting a snap

Stop the waste.
Protect your environment with Kodem.