Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-39315Mediumgithub.com/pomerium/pomerium: Pomerium exposed OAuth2 access and ID tokens in user info endpoint responseCVE-2024-6284Mediumgithub.com/google/nftables: github.com/google/nftable IP addresses were encoded in the wrong byte orderCVE-2024-39223Criticalgithub.com/ginuerzh/gost: Missing key verification in gostCVE-2024-37298Highgithub.com/gorilla/schema: Potential memory exhaustion attack due to sparse slice deserializationCVE-2024-38513Criticalgithub.com/gofiber/fiber: Session Middleware Token Injection VulnerabilityCVE-2019-25211Criticalgithub.com/gin-gonic/gin: Gin mishandles a wildcard at the end of an origin stringGHSA-HG58-RF2H-6RR7Mediumgithub.com/cometbft/cometbft: CometBFT is unstability during blocksync when syncing from malicious peerCVE-2024-24792Highgolang.org/x/image: Panic when parsing invalid palette-color images in golang.org/x/imageCVE-2024-37820Mediumgithub.com/pingcap/tidb: PingCAP TiDB nil pointer dereferenceCVE-2024-6257Highgithub.com/hashicorp/go-getter: HashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config ManipulationCVE-2024-6104Mediumgithub.com/hashicorp/go-retryablehttp: go-retryablehttp can leak basic auth credentials to log filesCVE-2024-38359Highgithub.com/lightningnetwork/lnd: Lightning Network Daemon (LND)'s onion processing logic leads to a denial of serviceCVE-2024-38361Mediumgithub.com/authzed/spicedb: SpiceDB exclusions can result in no permission returned when permission expectedGHSA-RVJ4-Q8Q5-8GRFMediumgithub.com/traefik/traefik/v3: ACME DNS: Azure Identity Libraries Elevation of Privilege VulnerabilityCVE-2024-37897Mediumgithub.com/drakkan/sftpgo/v2: SFTPGo has insufficient access control for password resetCVE-2024-5182Highgithub.com/go-skynet/LocalAI: LocalAI path traversal vulnerabilityCVE-2024-38351Mediumgithub.com/pocketbase/pocketbase: PocketBase performs password auth and OAuth2 unverified email linkingCVE-2024-37904Mediumgithub.com/stacklok/minder: Minder affected by denial of service from maliciously configured Git repositoryCVE-2024-22032Highgithub.com/rancher/rancher: Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpecCVE-2023-32196Highgithub.com/rancher/rancher: Rancher's External RoleTemplates can lead to privilege escalationCVE-2023-32191Criticalgithub.com/rancher/rke: rke's credentials are stored in the RKE1 Cluster state ConfigMapCVE-2023-22650Highgithub.com/rancher/rancher: Rancher does not automatically clean up a user deleted or disabled from the configured Authentication ProviderCVE-2024-36586Highgithub.com/AdguardTeam/AdGuardHome: AdGuardHome privilege escalation vulnerabilityGHSA-85RG-8M6H-825PHighgithub.com/k8sgpt-ai/k8sgpt: Vulnerabilities with the k8sGPTCVE-2024-37307Highgithub.com/cilium/cilium: Cilium leaks sensitive information in cilium-bugtool

Stop the waste.
Protect your environment with Kodem.