Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-29902Mediumgithub.com/sigstore/cosign: Cosign malicious attachments can cause system-wide denial of serviceCVE-2024-32001Lowgithub.com/authzed/spicedb: SpiceDB: LookupSubjects may return partial results if a specific kind of relation is usedCVE-2024-32644Criticalgithub.com/evmos/evmos/v16: Evmos transaction execution not accounting for all state transition after interaction with precompilesCVE-2024-2029Criticalgithub.com/go-skynet/LocalAI: LocalAI Command Injection in audioToWavGHSA-J5VM-7QCC-2WWGLowgithub.com/kopia/kopia: Kopia: Storage connection credentials written to console on "repository status" CLI command with JSON outputCVE-2024-31457Highgithub.com/flipped-aurora/gin-vue-admin/server: gin-vue-admin background arbitrary code coverage vulnerabilityCVE-2024-31455Mediumgithub.com/stacklok/minder: Minder GetRepositoryByName data leakCVE-2024-28224Highgithub.com/ollama/ollama: Ollama DNS rebinding vulnerabilityCVE-2024-0406Mediumgithub.com/mholt/archiver/v3: Archiver Path Traversal vulnerabilityCVE-2024-1313Highgithub.com/grafana/grafana: Grafana: Users outside an organization can delete a snapshot with its keyGHSA-J496-CRGH-34MXCriticalgithub.com/cosmos/ibc-go/v4: ibc-go: Potential Reentrancy using Timeout Callbacks in ibc-hooksCVE-2024-3250Mediumgithub.com/canonical/pebble: Pebble service manager's file pull API allows access by any userCVE-2024-2447Highgithub.com/mattermost/mattermost/server/v8: Mattermost fails to authenticate the source of certain types of post actionsCVE-2024-28949Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Server doesn't limit the number of user preferencesCVE-2024-29221Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Server Improper Access Control CVE-2024-21848Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Server Improper Access ControlCVE-2023-45288Mediumnet/http: net/http, x/net/http2: close connections when receiving too many headersCVE-2024-2660Mediumgithub.com/hashicorp/vault: HashiCorpVault does not correctly validate OCSP responsesCVE-2024-2689Mediumgithub.com/temporalio/temporal: Temporal Server Denial of ServiceCVE-2024-31420Mediumkubevirt.io/kubevirt: KubeVirt NULL pointer dereference flawCVE-2024-2435Mediumgithub.com/temporalio/ui-server/v2: Temporal UI Server cross-site scripting vulnerabilityCVE-2024-22780Mediumgithub.com/ca17/teamsacs: CA17 TeamsACS Cross Site Scripting vulnerabilityCVE-2024-22189Highgithub.com/quic-go/quic-go: QUIC's Connection ID Mechanism vulnerable to Memory Exhaustion AttackCVE-2024-3135Mediumgithub.com/go-skynet/LocalAI: LocalAI cross-site request forgery vulnerabilityCVE-2024-28232Mediumgithub.com/IceWhaleTech/CasaOS-UserService: CasaOS Username Enumeration - Bypass of CVE-2024-24766

Stop the waste.
Protect your environment with Kodem.