Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-7WW5-4WQC-M92CMediumgithub.com/containerd/containerd: containerd allows RAPL to be accessible to a containerCVE-2023-48795Mediumrussh: Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka TerrapinCVE-2023-50424Criticalgithub.com/sap/cloud-security-client-go: Improper Privilege Management in github.com/sap/cloud-security-client-goCVE-2023-49922Mediumgithub.com/elastic/beats: Elastic Beats inserts sensitive information into log fileGHSA-4RGC-5G6R-2RJFHighgithub.com/treeverse/lakefs: lakeFS logs S3 credentials in plain textGHSA-26HR-Q2WP-RVC5Mediumgithub.com/treeverse/lakefs: User with permission to write actions can impersonate another user when auth token is configured in environment variableCVE-2023-45292Mediumgithub.com/mojocn/base64Captcha: Always incorrect control flow in github.com/mojocn/base64CaptchaCVE-2023-50463Mediumgithub.com/shift72/caddy-geo-ip: Header spoofing in caddy-geo-ipCVE-2023-6337Highgithub.com/hashicorp/vault: Memory exhaustion in HashiCorp VaultGHSA-99JV-8292-2HPMLowknative.dev/eventing-gitlab: eventing-gitlab vulnerable to denial of service, caused by improper enforcement of the timeout on individual read operationsGHSA-V7HC-87JC-QRRRLowknative.dev/eventing-github: eventing-github vulnerable to denial of service caused by improper enforcement of the timeout on individual read operationsCVE-2023-6459Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityCVE-2023-6458Highgithub.com/mattermost/mattermost-server/v6: Mattermost Injection vulnerabilityCVE-2023-26154Mediumpubnub: pubnub Insufficient Entropy vulnerabilityGHSA-X9QQ-236J-GJ97Lowgithub.com/canonical/lxd: Canonical LXD documentation improvement to make clear restricted.devices.disk=allow without restricted.devices.disk.paths also allows…CVE-2023-49292Highgithub.com/ecies/go/v2: github.com/ecies/go vulnerable to possible private key restorationCVE-2023-49290Mediumgithub.com/lestrrat-go/jwx: lestrrat-go/jwx's malicious parameters in JWE can cause a DOSCVE-2023-47633Highgithub.com/traefik/traefik/v2: Traefik docker container using 100% CPUCVE-2023-47124Mediumgithub.com/traefik/traefik/v2: Traefik vulnerable to potential DDoS via ACME HTTPChallengeCVE-2023-47106Mediumgithub.com/traefik/traefik/v2: Traefik incorrectly processes fragment in the URL, leads to Authorization BypassGHSA-J3RQ-4XJW-XG63Highgithub.com/edgelesssys/marblerun: Go package github.com/edgelesssys/marblerun CLI commands susceptible to MITM attacksCVE-2023-49097Highgithub.com/zitadel/zitadel: ZITADEL Account Takeover via Malicious Host Header InjectionCVE-2023-45286Mediumgithub.com/go-resty/resty/v2: github.com/go-resty/resty/v2 HTTP request body disclosureCVE-2023-46480Mediumgithub.com/owncast/owncast: OwnCast remote code execution vulnerabilityCVE-2023-48713Mediumknative.dev/serving: Knative Serving vulnerable to attacker-controlled pod causing denial of service of autoscaler

Stop the waste.
Protect your environment with Kodem.