Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-21498Mediumgithub.com/greenpau/caddy-security: Server-Side Request Forgery in github.com/greenpau/caddy-securityCVE-2024-21492Mediumgithub.com/greenpau/caddy-security: Insufficient Session Expiration in github.com/greenpau/caddy-securityCVE-2024-21493Mediumgithub.com/greenpau/caddy-security: Improper Validation of Array Index in github.com/greenpau/caddy-securityCVE-2024-21494Mediumgithub.com/greenpau/caddy-security: Authentication Bypass by Spoofing in github.com/greenpau/caddy-securityCVE-2024-21495Mediumgithub.com/greenpau/caddy-security: Use of Insufficiently Random Values in github.com/greenpau/caddy-securityCVE-2024-21496Mediumgithub.com/greenpau/caddy-security: Cross-site Scripting in github.com/greenpau/caddy-securityCVE-2024-25620Mediumhelm.sh/helm/v3: Helm dependency management path traversalCVE-2024-1485Mediumgithub.com/devfile/registry-support/registry-library: registry-support: decompress can delete files outside scope via relative pathsCVE-2023-6152Mediumgithub.com/grafana/grafana: Email Validation Bypass And Preventing Sign Up From Email's OwnerCVE-2023-52430Mediumgithub.com/greenpau/caddy-security: caddy-security plugin for Caddy vulnerable to reflected Cross-site ScriptingCVE-2024-1402Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost vulnerable to denial of service via large number of emoji reactionsCVE-2024-24774Mediumgithub.com/mattermost/mattermost-plugin-jira: Mattermost Jira Plugin does not properly check security levelsCVE-2024-24776Lowgithub.com/mattermost/mattermost/server/v8: Mattermost fails to check the required permissionsCVE-2024-23319Lowgithub.com/mattermost/mattermost-plugin-jira: Mattermost Jira Plugin vulnerable to Cross-Site Request ForgeryCVE-2024-1329Highgithub.com/hashicorp/nomad: HashiCorp Nomad vulnerable to symlink attacksCVE-2023-32192Highgithub.com/rancher/apiserver: Rancher API Server Cross-site Scripting VulnerabilityCVE-2023-32193Highgithub.com/rancher/norman: Norman API Cross-site Scripting VulnerabilityCVE-2023-22649Highgithub.com/rancher/rancher: Rancher 'Audit Log' leaks sensitive informationCVE-2023-32194Highgithub.com/rancher/rancher: Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core'CVE-2024-23448Highgithub.com/elastic/apm-server: APM Server vulnerable to Insertion of Sensitive Information into Log FileCVE-2024-1052Highgithub.com/hashicorp/boundary: Boundary vulnerable to session hijacking through TLS certificate tamperingCVE-2024-24768Lowgithub.com/1Panel-dev/1Panel: 1Panel set-cookie is missing the Secure keywordGHSA-VJG6-93FV-QV64Lowgo.etcd.io/etcd/v3: Etcd auth Inaccurate logging of authentication attempts for users with CN-based auth onlyGHSA-PM3M-32R3-7MFHLowgo.etcd.io/etcd/v3: Etcd embed auto compaction retention negative value causing a compaction loop or a crashGHSA-J86V-2VJR-FG8FMediumgo.etcd.io/etcd/v3: Etcd Gateway TLS endpoint validation only confirms TCP reachability

Stop the waste.
Protect your environment with Kodem.