Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-1942Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows attackers access to posts in channels they are not a member ofCVE-2024-24988Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost denial of service through long emoji valueCVE-2024-23493Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost leaks details of AD/LDAP groups of a teamsCVE-2024-1888Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to check the "invite_guest" permission CVE-2024-1887Highgithub.com/mattermost/mattermost/server/v8: Mattermost post fetching without auditing in compliance export CVE-2024-23488Lowgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly restrict the access of files attached to postsCVE-2024-25712Mediumgithub.com/swaggo/http-swagger: http-swagger XSS via PUT requestsCVE-2023-50658Mediumgithub.com/dvsekhvalnov/jose2go: jose2go vulnerable to denial of service via large p2c valueGHSA-555P-M4V6-CQXVLowgithub.com/cometbft/cometbft: ASA-2024-004: Default configuration param for Evidence may limit window of validityGHSA-86H5-XCPX-CFQCLowgithub.com/cosmos/cosmos-sdk: ASA-2024-005: Potential slashing evasion during re-delegationGHSA-X5R5-2QRX-RQJ8Criticalgithub.com/edgelesssys/marblerun: Transparent TLS may not be applied to Marbles with certain manifest configurationsCVE-2024-27093Mediumgithub.com/stacklok/minder: Minder trusts client-provided mapping from repo name to upstream IDGHSA-FVV5-H29G-F6W5Mediumgithub.com/treeverse/lakefs: User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repositoryCVE-2024-26147Highhelm.sh/helm/v3: Helm's Missing YAML Content Leads To PanicCVE-2024-25124Criticalgithub.com/gofiber/fiber/v2: Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with CredentialsCVE-2024-23349Mediumgithub.com/apache/incubator-answer: Apache Answer Cross-site Scripting vulnerabilityCVE-2024-26578Mediumgithub.com/apache/incubator-answer: Apache Answer Race Condition vulnerabilityCVE-2024-22393Highgithub.com/apache/incubator-answer: Apache Answer Unrestricted Upload of File with Dangerous Type vulnerabilityGHSA-2557-X9MG-76W8Mediumgithub.com/cosmos/cosmos-sdk: ASA-2024-002: Default `PrepareProposalHandler` may produce invalid proposals when used with default `SenderNonceMempool`GHSA-4J93-FM92-RP4MMediumgithub.com/cosmos/cosmos-sdk: ASA-2024-003: Missing `BlockedAddressed` Validation in Vesting ModuleCVE-2024-25631Mediumgithub.com/cilium/cilium: Unencrypted traffic between pods when using Wireguard and an external kvstoreCVE-2024-25630Mediumgithub.com/cilium/cilium: Unencrypted ingress/health traffic when using Wireguard transparent encryptionCVE-2024-21500Mediumgithub.com/greenpau/caddy-security: Improper Restriction of Excessive Authentication Attempts in github.com/greenpau/caddy-securityCVE-2024-21497Mediumgithub.com/greenpau/caddy-security: Open Redirect in github.com/greenpau/caddy-securityCVE-2024-21499Mediumgithub.com/greenpau/caddy-security: Improper Neutralization of HTTP Headers in github.com/greenpau/caddy-security

Stop the waste.
Protect your environment with Kodem.