Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-5798Lowgithub.com/hashicorp/vault: HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience ClaimsCVE-2023-49559Mediumgithub.com/vektah/gqlparser/v2: gqlparser denial of service vulnerability via the parserDirectives functionGHSA-7JMW-8259-Q9JXMediumgithub.com/traefik/traefik/v3: Traefik has unexpected behavior with IPv4-mapped IPv6 addressesCVE-2024-35255Mediumazure-identity: Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege VulnerabilityGHSA-XMMX-7JPF-FX42Mediumgithub.com/docker/docker: Moby (Docker Engine) is vulnerable to Ambiguous OCI manifest parsingCVE-2021-41092Mediumgithub.com/docker/cli: Docker CLI leaks private registry credentials to registry-1.docker.ioCVE-2021-41089Lowgithub.com/docker/docker: `docker cp` allows unexpected chmod of host files in Moby Docker EngineGHSA-87M9-RV8P-RGMGHighgithub.com/mostynb/go-grpc-compression: go-grpc-compression has a zstd decompression bombing vulnerabilityCVE-2024-37152Mediumgithub.com/argoproj/argo-cd/v2/server: Unauthenticated Access to sensitive settings in Argo CDCVE-2024-37154Mediumgithub.com/evmos/evmos/v18: Evmos allows unvested token delegationsCVE-2024-36106Mediumgithub.com/argoproj/argo-cd: Argo-cd authenticated users can enumerate clusters by nameCVE-2024-37153Highgithub.com/evmos/evmos/v18: Contract balance not updating correctly after interchain transactionCVE-2024-32873Lowgithub.com/evmos/evmos/v17: evmos allows transferring unvested tokens after delegationsCVE-2024-36129Highgo.opentelemetry.io/collector/config/confighttp: Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPCCVE-2024-5262Criticalgithub.com/projectdiscovery/interactsh: Files or Directories Accessible to External Parties in ProjectDiscoveryCVE-2024-5154Highgithub.com/cri-o/cri-o: malicious container creates symlink "mtab" on the host ExternalCVE-2024-36127Highchainguard.dev/apko: apko Exposure of HTTP basic auth credentials in log outputCVE-2024-22261Lowgithub.com/goharbor/harbor: SQL Injection in Harbor scan log APICVE-2024-22244Mediumgithub.com/goharbor/harbor: Open Redirect URL in HarborCVE-2024-37032Mediumgithub.com/ollama/ollama: Ollama does not validate the format of the digest (sha256 with 64 hex digits)CVE-2024-36107Mediumgithub.com/minio/minio: MinIO information disclosure vulnerabilityCVE-2024-35238Mediumgithub.com/stacklok/minder: Denial of service of Minder Server from maliciously crafted GitHub attestationsCVE-2024-35232Lowgithub.com/huandu/facebook/v2: github.com/huandu/facebook may expose access_token in error message.GHSA-F7CQ-5V43-8PWPMediumgithub.com/traefik/traefik/v2: Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loopCVE-2024-35223Mediumgithub.com/dapr/dapr: Dapr API Token Exposure

Stop the waste.
Protect your environment with Kodem.