Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-49569Criticalgithub.com/go-git/go-git/v5: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clientsCVE-2023-6476Mediumgithub.com/cri-o/cri-o: CRI-O's pods can break out of resource confinement on cgroupv2CVE-2023-49295Mediumgithub.com/quic-go/quic-go: quic-go's path validation mechanism can be exploited to cause denial of serviceCVE-2023-49619Lowgithub.com/apache/incubator-answer: Apache Answer Race Condition vulnerabilityCVE-2024-21664Mediumgithub.com/lestrrat-go/jwx/v2: Parsing JSON serialized payload without protected field can lead to segfaultCVE-2022-3328Criticalgithub.com/snapcore/snapd: snapd Race Condition vulnerabilityGHSA-9763-4F94-GFCHHighgithub.com/cloudflare/circl: CIRCL's Kyber: timing side-channel (kyberslash2)CVE-2023-30617Mediumgithub.com/openkruise/kruise: Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire clusterGHSA-7XG2-83F8-39MRLowgithub.com/karmada-io/karmada: The DES/3DES cipher was used as part of the TLS protocol by installation toolsCVE-2023-46742Mediumgithub.com/cubefs/cubefs: CubeFS leaks users key in logsCVE-2023-46741Mediumgithub.com/cubefs/cubefs: CubeFS leaks magic secret key when starting Blobstore access serviceCVE-2023-46740Highgithub.com/cubefs/cubefs: Insecure random string generator used for sensitive dataCVE-2023-46739Highgithub.com/cubefs/cubefs: CubeFS timing attack can leak user passwordsCVE-2023-46738Highgithub.com/cubefs/cubefs: Authenticated users can crash the CubeFS servers with maliciously crafted requestsCVE-2023-50333Lowgithub.com/mattermost/mattermost/server/v8: Mattermost allows demoted guests to change group namesCVE-2023-48732Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost notified all users in the channel when using WebSockets to respond individuallyCVE-2023-47858Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost viewing archived public channels permissions vulnerabilityCVE-2023-7113Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Cross-site Scripting vulnerabilityCVE-2023-52081Mediumgithub.com/ewen-lbh/ffcss: ewen-lbh/ffcss Late-Unicode normalization vulnerabilityCVE-2023-49568Highgithub.com/go-git/go-git/v5: Maliciously crafted Git server replies can cause DoS on go-git clientsCVE-2016-15036Mediumgithub.com/deis/workflow-manager: Deis Workflow Manager race condition vulnerabilityCVE-2023-49391Highgithub.com/free5gc/amf: free5GC AMF denial of service vulnerabilityCVE-2023-43116Highgithub.com/buildkite/elastic-ci-stack-for-aws/v6: Buildkite Elastic CI for AWS symbolic link following vulnerabilityCVE-2023-43741Highgithub.com/buildkite/elastic-ci-stack-for-aws/v6: Buildkite Elastic CI for AWS time-of-check-time-of-use race condition vulnerabilityCVE-2023-51442Highgithub.com/navidrome/navidrome: Authentication bypass vulnerability in navidrome's subsonic endpoint

Stop the waste.
Protect your environment with Kodem.