Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-46737Lowgithub.com/sigstore/cosign/v2: Cosign vulnerable to possible endless data attack from attacker-controlled registryCVE-2023-46254Mediumgithub.com/projectcapsule/capsule: capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount nameCVE-2023-5967Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost denial of service vulnerabilityCVE-2023-5969Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost vulnerable to excessive memory consumptionCVE-2023-5968Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost password hash disclosure vulnerabilityCVE-2023-41378Highgithub.com/projectcalico/calico: Calico Typha denial of service vulnerabilityCVE-2023-3893Highgithub.com/kubernetes-csi/csi-proxy/v2: Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validationCVE-2023-46255Mediumgithub.com/authzed/spicedb: SpiceDB leaks information in log files when URI cannot be parsedCVE-2023-3955Highk8s.io/kubernetes: Kubernetes privilege escalation vulnerabilityCVE-2023-3676Highk8s.io/kubernetes: Kubernetes privilege escalation vulnerabilityCVE-2023-46129Highgithub.com/nats-io/nkeys: xkeys seal encryption used fixed key for all encryptionGHSA-JQ35-85CJ-FJ4PMediumgithub.com/docker/docker: /sys/devices/virtual/powercap accessible by default to containersCVE-2023-46239Highgithub.com/quic-go/quic-go: quic-go vulnerable to pointer dereference that can lead to panicCVE-2021-25736Mediumk8s.io/kubernetes: Kube-proxy may unintentionally forward trafficCVE-2023-5834Lowgithub.com/hashicorp/vagrant: HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerabilityCVE-2023-41891Lowgithub.com/flyteorg/flyteadmin: Flyte Admin SQL Injection in List FiltersGHSA-W6RP-VXJ2-FJHRHighgithub.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4: Cosmos packet-forward-middleware vulnerable to chain-haltCVE-2023-5043Highk8s.io/ingress-nginx: Ingress nginx annotation injection causes arbitrary command executionCVE-2023-5044Highk8s.io/ingress-nginx: Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotationCVE-2022-4886Highk8s.io/ingress-nginx: Ingress-nginx path sanitization can be bypassedGHSA-M425-MQ94-257GHighgoogle.golang.org/grpc: gRPC-Go HTTP/2 Rapid Reset vulnerabilityCVE-2023-43651Mediumgithub.com/jumpserver/koko: Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell CVE-2023-46324Highgithub.com/free5gc/udm: free5GC udm vulnerable to Invalid Curve AttackCVE-2023-45825Mediumgithub.com/ydb-platform/ydb-go-sdk/v3: ydb-go-sdk token in custom credentials object can leak through logsCVE-2023-45823Highgithub.com/artifacthub/hub: Artifact Hub arbitrary file read vulnerability

Stop the waste.
Protect your environment with Kodem.