Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-31097Mediumgithub.com/grafana/grafana: Grafana Stored Cross-site Scripting in Unified AlertingCVE-2022-21702Mediumgithub.com/grafana/grafana: Grafana proxy Cross-site ScriptingCVE-2022-21673Lowgithub.com/grafana/grafana: Grafana Forward OAuth Identity Token can allow users to access some data sourcesCVE-2021-43815Mediumgithub.com/grafana/grafana: Grafana directory traversal for .cvs filesCVE-2021-41244Criticalgithub.com/grafana/grafana: Grafana Fine-grained access control vulnerabilityGHSA-C9CP-9C75-9V8CLowgithub.com/containerd/containerd: containerd started with non-empty inheritable Linux process capabilitiesCVE-2021-32026Lowgithub.com/nats-io/nats-server/v2: NATS server TLS missing ciphersuite settings when CLI flags usedCVE-2020-26312Highgithub.com/dotmesh-io/dotmesh: dotmesh arbitrary file read and/or writeCVE-2024-34713Lowgithub.com/cea-hpc/sshproxy: sshproxy vulnerable to SSH option injectionCVE-2024-3727Highgithub.com/containers/image: github.com/containers/image allows unexpected authenticated registry accessesCVE-2024-34079Lowgithub.com/octo-sts/app: octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usageCVE-2024-34360Highgithub.com/spacemeshos/go-spacemesh: Previous ATX is not checked to be the newest valid ATX by Smesher when validating incoming ATXCVE-2024-34352Mediumgithub.com/1Panel-dev/1Panel: 1Panel arbitrary file write vulnerabilityCVE-2024-32886Mediumgithub.com/vitessio/vitess: Vitess vulnerable to infinite memory consumption and vtgate crashCVE-2024-33434Criticalgithub.com/tiagorlampert/CHAOS: tiagorlampert CHAOS vulnerable to arbitrary code executionCVE-2024-34084Highgithub.com/stacklok/minder: Minder's GitHub Webhook Handler vulnerable to DoS from un-validated requestsCVE-2024-32972Highgithub.com/ethereum/go-ethereum: go-ethereum vulnerable to DoS via malicious p2p messageCVE-2024-34478Mediumgithub.com/btcsuite/btcd: btcd susceptible to consensus failuresCVE-2024-34068Mediumgithub.com/pterodactyl/wings: Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pullCVE-2024-34066Highgithub.com/pterodactyl/wings: Pterodactyl Wings vulnerable to Arbitrary File Write/ReadCVE-2024-33398Highgithub.com/piraeusdatastore/piraeus-operator/v2: piraeus-operator allows attacker to impersonate service accountGHSA-V84H-653V-4PQ9Criticalgithub.com/jub0bs/fcors: Some CORS middleware allow untrusted originsGHSA-VHXV-FG4M-P2W8Criticalgithub.com/jub0bs/cors: Some CORS middleware allow untrusted originsCVE-2024-33396Highgithub.com/karmada-io/karmada: karmada vulnerable to arbitrary code execution via a crafted command CVE-2024-33394Mediumkubevirt.io/kubevirt: kubevirt allows a local attacker to execute arbitrary code via a crafted command

Stop the waste.
Protect your environment with Kodem.