Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-1724Mediumgithub.com/snapcore/snapd: snapd failed to restrict writes to the $HOME/bin pathCVE-2024-36536Criticalgithub.com/fabedge/fabedge: fabedge has insecure permissionsCVE-2024-36533Criticalgithub.com/volcano-sh/volcano: Volcano has insecure permissionsCVE-2024-41666Mediumgithub.com/argoproj/argo-cd/v2: The Argo CD web terminal session does not handle the revocation of user permissions properlyCVE-2024-6717Highgithub.com/hashicorp/nomad: HashiCorp Nomad is vulnerable to path escape through archive unpacking during migrationCVE-2024-40634Highgithub.com/argoproj/argo-cd: Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook EndpointCVE-2024-41121Highgo.woodpecker-ci.org/woodpecker/v2: Woodpecker's custom workspace allow to overwrite plugin entrypoint executableCVE-2024-41122Mediumgo.woodpecker-ci.org/woodpecker/v2: Woodpecker's custom environment variables allow to alter execution flow of pluginsCVE-2024-21583Mediumgithub.com/gitpod-io/gitpod: github.com/gitpod-io/gitpod vulnerable to Cookie TossingCVE-2024-5321Highk8s.io/kubernetes: Kubernetes sets incorrect permissions on Windows containers logsCVE-2024-41111Highgithub.com/bishopfox/sliver: Sliver Allows Authenticated Operator-to-Server Remote Code ExecutionCVE-2024-39907Criticalgithub.com/1Panel-dev/1Panel: 1Panel has an SQL injection issue related to the orderBy clauseCVE-2024-40641Highgithub.com/projectdiscovery/nuclei/v3: projectdiscovery/nuclei allows unsigned code template execution through workflowsCVE-2024-6535Highgithub.com/skupperproject/skupper: Skupper uses a static cookie secret for the openshift oauth-proxyGHSA-QC6V-5G5M-8CW2Mediumgithub.com/zitadel/zitadel-go/v3: ZITADEL Go's GRPC example code vulnerability - GO-2024-2687 HTTP/2 CONTINUATION flood in net/httpCVE-2024-39909Highgithub.com/openclarity/kubeclarity/backend: SQL Injection in the KubeClarity REST APICVE-2024-6468Highgithub.com/hashicorp/vault: Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions CVE-2022-29946Highgithub.com/nats-io/nats-server/v2: NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjectsCVE-2024-39696Highgithub.com/evmos/evmos/v18: Evmos vulnerable to exploit of smart contract account and vestingCVE-2024-39897Mediumzotregistry.io/zot: Cache driver GetBlob() allows read access to any blob without access control checkCVE-2024-39321Highgithub.com/traefik/traefik/v2: Bypassing IP allow-lists in traefik via HTTP/3 early data requests in QUIC 0-RTT handshakesGHSA-FQPG-RQ76-99PQMediumgithub.com/jackc/pgx/v5: Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgxGHSA-XR7Q-JX4M-X55MLowgoogle.golang.org/grpc: Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-goCVE-2024-39683Mediumgithub.com/zitadel/zitadel: ZITADEL Vulnerable to Session Information LeakageCVE-2025-47908Mediumgithub.com/rs/cors: Denial of service via malicious preflight requests in github.com/rs/cors

Stop the waste.
Protect your environment with Kodem.