Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-8566Mediumgithub.com/kubernetes/kubernetes: Sensitive Information leak via Log File in KubernetesCVE-2020-10937Highgithub.com/ipfs/go-ipfs: Access Restriction Bypass in go-ipfsCVE-2020-8557Mediumk8s.io/kubernetes/pkg/kubelet: Denial of service in KubernetesCVE-2020-8559Mediumk8s.io/apimachinery: Privilege Escalation in KubernetesCVE-2020-7666Highgithub.com/u-root/u-root/pkg/cpio: github.com/u-root/u-root/pkg/cpio Arbitrary File Write via Archive Extraction (Zip Slip)CVE-2024-32875Mediumgithub.com/gohugoio/hugo: Hugo Markdown titles do not escaped in internal render hooksCVE-2024-3177Lowk8s.io/kubernetes: Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission pluginCVE-2020-14144Highcode.gitea.io/gitea: Arbitrary Code Execution in GiteaCVE-2022-24769Mediumgithub.com/moby/moby: Moby (Docker Engine) started with non-empty inheritable Linux process capabilitiesGHSA-X883-2VMG-XWF7Lowgithub.com/authelia/authelia/v4: Authelia's Group Changes may not have the expected results (YAML file backend)CVE-2024-29217Mediumgithub.com/apache/incubator-answer: Apache Answer: XSS vulnerability when changing personal websiteCVE-2024-32473Mediumgithub.com/docker/docker: IPv6 enabled on IPv4-only network interfacesCVE-2024-30257Lowgithub.com/1Panel-dev/1Panel: 1Panel's password verification is suspected to have a timing attack vulnerabilityCVE-2024-3817Criticalgithub.com/hashicorp/go-getter: HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git BranchesGHSA-M99C-Q26R-M7M7Mediumgithub.com/evmos/evmos/v13/x/vesting: Evmos vulnerable to unauthorized account creation with vesting moduleGHSA-V6RW-HHGG-WC4XCriticalgithub.com/evmos/evmos/v11: Evmos vulnerable to DOS and transaction fee expropiation through Authz exploitCVE-2024-31452Highgithub.com/openfga/openfga: OpenFGA Authorization BypassCVE-2024-31990Mediumgithub.com/argoproj/argo-cd/v2: Argo CD's API server does not enforce project sourceNamespacesGHSA-7F4J-64P6-5H5VMediumgithub.com/traefik/traefik/v2: Traefik affected by HTTP/2 CONTINUATION flood in net/httpGHSA-G8FC-VRCG-8VJGHighgithub.com/edgelesssys/constellation/v2: Constallation has pods exposed to peers in VPCCVE-2024-28869Highgithub.com/traefik/traefik/v3: Traefik vulnerable to denial of service with Content-length headerCVE-2024-31391Mediumgithub.com/apache/solr-operator: Apache Solr Operator liveness and readiness probes may leak basic auth credentialsCVE-2024-31839Mediumgithub.com/tiagorlampert/CHAOS: tiagorlampert CHAOS vulnerable to Cross Site ScriptingCVE-2024-30850Highgithub.com/tiagorlampert/CHAOS: tiagorlampert CHAOS vulnerable to command injectionsCVE-2024-29903Mediumgithub.com/sigstore/cosign: Cosign malicious artifacts can cause machine-wide DoS

Stop the waste.
Protect your environment with Kodem.