Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-28236Highgithub.com/go-vela/worker: Insecure Variable Substitution in VelaGHSA-95RX-M9M5-M94VHighgithub.com/cosmos/cosmos-sdk: ASA-2024-006: ValidateVoteExtensions helper function in Cosmos SDK may allow incorrect voting power assumptionsCVE-2024-28197Highgithub.com/zitadel/zitadel: Account Takeover via Session Fixation in Zitadel [Bypassing MFA]CVE-2024-2352Mediumgithub.com/1Panel-dev/1Panel: 1Panel is vulnerable to command injection CVE-2024-28122Mediumgithub.com/lestrrat-go/jwx/v2: JWX vulnerable to a denial of service attack using compressed JWE messageCVE-2024-28180Mediumgithub.com/go-jose/go-jose/v4: Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)CVE-2024-1725Highgithub.com/kubevirt/csi-driver: kubevirt-csi: PersistentVolume allows access to HCP's root nodeCVE-2024-1442Highgithub.com/grafana/grafana: Grafana's users with permissions to create a data source can CRUD all data sourcesCVE-2024-28110Highgithub.com/cloudevents/sdk-go/v2: Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentialsCVE-2024-27288Mediumgithub.com/1Panel-dev/1Panel: 1Panel open source panel project has an unauthorized vulnerability.CVE-2024-24767Highgithub.com/IceWhaleTech/CasaOS-UserService: CasaOS Improper Restriction of Excessive Authentication Attempts vulnerabilityCVE-2024-24766Mediumgithub.com/IceWhaleTech/CasaOS-UserService: CasaOS Username EnumerationCVE-2024-24765Highgithub.com/IceWhaleTech/CasaOS-UserService: CasaOS-UserService allows unauthorized access to any file CVE-2024-24786Mediumgoogle.golang.org/protobuf: Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSONCVE-2024-27916Highgithub.com/stacklok/minder: `GetRepositoryByName`, `DeleteRepositoryByName` and `GetArtifactByName` allow access of arbitrary repositories in Minder by any…CVE-2024-2048Highgithub.com/hashicorp/vault: Incorrect TLS certificate auth method in VaultCVE-2024-27918Highgithub.com/coder/coder/v2: Coder's OIDC authentication allows email with partially matching domain to registerGHSA-7JWH-3VRQ-Q3M8Highgithub.com/jackc/pgproto3: pgproto3 SQL Injection via Protocol Message Size OverflowCVE-2024-27304Highgithub.com/jackc/pgx: pgx SQL Injection via Protocol Message Size OverflowCVE-2024-27302Criticalgithub.com/zeromicro/go-zero: Authorization Bypass Through User-Controlled Key in go-zeroCVE-2024-27289Highgithub.com/jackc/pgx: pgx SQL Injection via Line Comment CreationCVE-2024-27101Highgithub.com/authzed/spicedb: Integer overflow in chunking helper causes dispatching to miss elements or panicCVE-2024-1949Lowgithub.com/mattermost/mattermost/server/v8: Mattermost race conditionCVE-2024-1953Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to limit the number of role namesCVE-2024-1952Lowgithub.com/mattermost/mattermost/server/v8: Mattermost incorrectly allows access individual posts

Stop the waste.
Protect your environment with Kodem.