Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-29893Mediumgithub.com/argoproj/argo-cd/v2: ArgoCD's repo server has Uncontrolled Resource Consumption vulnerabilityCVE-2024-1753Mediumgithub.com/containers/podman/v4: Podman affected by CVE-2024-1753 container escape at build time CVE-2024-28860Highgithub.com/cilium/cilium: Cilium has insecure IPsec transport encryptionCVE-2024-29891Highgithub.com/zitadel/zitadel: ZITADEL's Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP BypassCVE-2024-29892Highgithub.com/zitadel/zitadel: ZITADEL's actions can overload reserved claimsCVE-2024-1394Highgithub.com/golang-fips/go: Memory leaks in code encrypting and verifying RSA payloadsCVE-2024-29018Mediumgithub.com/docker/docker: Moby's external DNS requests from 'internal' networks could lead to data exfiltrationGHSA-PMF3-C36M-G5CFHighgithub.com/containers/buildah: Container escape at build timeCVE-2024-28855Highgithub.com/zitadel/zitadel: Improper HTML sanitization in ZITADELCVE-2024-28250Mediumgithub.com/cilium/cilium: Unencrypted traffic between nodes when using WireGuard and L7 policiesCVE-2024-28249Mediumgithub.com/cilium/cilium: Unencrypted traffic between nodes when using IPsec and L7 policiesCVE-2024-28248Highgithub.com/cilium/cilium: Intermittent HTTP policy bypassCVE-2024-21662Mediumgithub.com/argoproj/argo-cd/v2: Bypassing Rate Limit and Brute Force Protection Using Cache OverflowCVE-2024-21661Highgithub.com/argoproj/argo-cd: Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded EnvironmentCVE-2024-21652Criticalgithub.com/argoproj/argo-cd/v2: Bypassing Brute Force Protection via Application Crash and In-Memory Data LossGHSA-4JHJ-3GV3-C3GRHighgithub.com/go-vela/cli: CLI for Vela Insecure Variable SubstitutionGHSA-V8MX-HP2Q-GW85Highgithub.com/go-vela/sdk-go: Golang SDK for Vela Insecure Variable SubstitutionGHSA-69P4-J5V5-X234Highgithub.com/go-vela/server: Server/API for Vela Insecure Variable SubstitutionGHSA-7V38-W32M-WX4MHighgithub.com/go-vela/types: Types for Vela Insecure Variable SubstitutionCVE-2024-28175Criticalgithub.com/argoproj/argo-cd/v2: Cross-site scripting on application summary componentCVE-2024-27920Highgithub.com/projectdiscovery/nuclei/v3: Nuclei allows unsigned code template execution through workflowsCVE-2024-27102Criticalgithub.com/pterodactyl/wings: Pterodactyl Wings vulnerable to improper isolation of server file accessCVE-2023-51699Mediumgithub.com/fluid-cloudnative/fluid: Fluid vulnerable to OS Command Injection for Fluid Users with JuicefsRuntimeCVE-2023-50726Mediumgithub.com/argoproj/argo-cd: Users with `create` but not `override` privileges can perform local syncCVE-2024-28053Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Server Resource Exhaustion

Stop the waste.
Protect your environment with Kodem.