Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-31989Criticalgithub.com/argoproj/argo-cd/v2: ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis CacheGHSA-2J6R-9VV4-6GF5Lowgithub.com/bincyber/go-sqlcrypter: github.com/bincyber/go-sqlcrypter vulnerable to IV collisionGHSA-QJCV-RX3V-7MVJMediumgithub.com/cosmos/ibc-go/v7: github.com/cosmos/ibc-go affected by IBC protocol "Huckleberry" vulnerabilityCVE-2024-35194Mediumgithub.com/stacklok/minder: Stacklok Minder vulnerable to denial of service from maliciously crafted templatesCVE-2024-35192Mediumgithub.com/aquasecurity/trivy: Trivy possibly leaks registry credential when scanning images from malicious registriesCVE-2024-5042Mediumgithub.com/submariner-io/submariner-operator: Submariner Operator sets unnecessary RBAC permissionsCVE-2024-35185Mediumgithub.com/stacklok/minder: Denial of service of Minder Server with attacker-controlled REST endpointCVE-2023-40297Highgithub.com/stakater/Forecastle: Stakater Forecastle has a directory traversal vulnerabilityCVE-2024-35183Mediumgithub.com/wolfi-dev/wolfictl: wolfictl leaks GitHub tokens to remote non-GitHub git serversGHSA-F6MM-5FC7-3G3CMediumgithub.com/goreleaser/goreleaser: goreleaser shows environment by defaultCVE-2024-31216Mediumgithub.com/fluxcd/source-controller: source-controller leaks Azure Storage SAS token into logsCVE-2024-3744Mediumsigs.k8s.io/azurefile-csi-driver: azure-file-csi-driver leaks service account tokens in the logsCVE-2024-35175Mediumgithub.com/tg123/sshpiper: sshpiper's enabling of proxy protocol without proper feature flagging allows faking source addressCVE-2022-36062Highgithub.com/grafana/grafana: Grafana folders admin only permission privilege escalationCVE-2022-39201Highgithub.com/grafana/grafana: Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination pluginsCVE-2022-39229Mediumgithub.com/grafana/grafana: Grafana when using email as a username can block other users from signing inCVE-2022-39306Highgithub.com/grafana/grafana: Grafana Email addresses and usernames can not be trustedCVE-2022-39307Highgithub.com/grafana/grafana: Grafana User enumeration via forget passwordCVE-2022-39324Mediumgithub.com/grafana/grafana: Grafana Spoofing originalUrl of snapshotsCVE-2022-39328Criticalgithub.com/grafana/grafana: Grafana Race condition allowing privilege escalationCVE-2022-35957Highgithub.com/grafana/grafana: Grafana Escalation from admin to server admin when auth proxy is usedCVE-2022-31130Mediumgithub.com/grafana/grafana: Grafana Data source and plugin proxy endpoints leaking authentication tokens to some destination pluginsCVE-2022-31123Highgithub.com/grafana/grafana: Grafana Plugin signature bypassCVE-2022-31107Highgithub.com/grafana/grafana: Grafana account takeover via OAuth vulnerabilityCVE-2022-21713Mediumgithub.com/grafana/grafana: Grafana API IDOR

Stop the waste.
Protect your environment with Kodem.