Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-44312Mediumgithub.com/apache/servicecomb-service-center: Apache ServiceComb Service-Center Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityCVE-2023-44313Highgithub.com/apache/servicecomb-service-center: Apache ServiceComb Service-Center Server-Side Request Forgery vulnerabilityCVE-2020-16251Highgithub.com/hashicorp/vault: HashiCorp Vault Authentication bypassCVE-2020-15136Mediumgo.etcd.io/etcd: Etcd Gateway TLS authentication only applies to endpoints detected in DNS SRV recordsCVE-2020-15114Highgo.etcd.io/etcd: Etcd Gateway can include itself as an endpoint resulting in resource exhaustionCVE-2020-15113Mediumgithub.com/etcd-io/etcd: Improper Preservation of Permissions in etcdCVE-2018-18625Mediumgithub.com/grafana/grafana: Grafana XSS via adding a link in General featureCVE-2018-18623Mediumgithub.com/grafana/grafana: Grafana XSS in Dashboard Text PanelCVE-2020-10660Mediumgithub.com/hashicorp/vault: HashiCorp Vault Improper Privilege ManagementCVE-2020-10661Criticalgithub.com/hashicorp/vault: HashiCorp Vault Improper Privilege ManagementCVE-2024-23840Mediumgithub.com/goreleaser/goreleaser: `goreleaser release --debug` shows secretsCVE-2024-23647Highgoauthentik.io: Authentik vulnerable to PKCE downgrade attackCVE-2024-23828Highgithub.com/0xJacky/Nginx-UI: Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLFCVE-2024-23827Criticalgithub.com/0xJacky/Nginx-UI: Nginx-UI vulnerable to arbitrary file write through the Import Certificate featureCVE-2024-23820Mediumgithub.com/openfga/openfga: OpenFGA denial of serviceCVE-2024-23656Highgithub.com/dexidp/dex: Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphersCVE-2023-52354Highgithub.com/albertito/chasquid: chasquid HTTP Request/Response Smuggling vulnerabilityCVE-2024-23332Mediumgithub.com/notaryproject/notation: Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from…CVE-2024-22424Highgithub.com/argoproj/argo-cd: github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerabilityGHSA-QR8R-M495-7HC4Highgithub.com/cometbft/cometbft: Validation of `VoteExtensionsEnableHeight` can cause chain halt in Go package github.com/cometbft/cometbftGHSA-F6JH-HVG2-9525Highgithub.com/kudelskisecurity/crystals-go: crystals-go vulnerable to KyberSlash (timing side-channel attack for Kyber)CVE-2024-22199Criticalgithub.com/gofiber/template/django/v3: Django Template Engine Vulnerable to XSSCVE-2024-22198Highgithub.com/0xJacky/Nginx-UI: Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)CVE-2024-22197Highgithub.com/0xJacky/Nginx-UI: Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)CVE-2024-22196Highgithub.com/0xJacky/Nginx-UI: Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)

Stop the waste.
Protect your environment with Kodem.