Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-45822Lowgithub.com/artifacthub/hub: Artifact Hub allows unsafe rego built-inCVE-2023-45821Mediumgithub.com/artifacthub/hub: Artifact Hub has Incorrect Docker Hub registry checkCVE-2023-47090Highgithub.com/nats-io/nats-server/v2: NATS.io: Adding accounts for just the system account adds auth bypassCVE-2023-45810Highgithub.com/openfga/openfga: OpenFGA DoS vulnerabilityCVE-2023-43803Mediumgithub.com/arduino/arduino-create-agent: Arduino Create Agent path traversal - arbitrary file deletion vulnerabilityCVE-2023-43802Highgithub.com/arduino/arduino-create-agent: Arduino Create Agent path traversal - local privilege escalation vulnerabilityCVE-2023-43801Mediumgithub.com/arduino/arduino-create-agent: Arduino Create Agent path traversal - arbitrary file deletion vulnerabilityCVE-2023-43800Highgithub.com/arduino/arduino-create-agent: Arduino Create Agent Insufficient Verification of Data Authenticity vulnerabilityCVE-2023-42319Highgithub.com/ethereum/go-ethereum: go-ethereum vulnerable to denial of service via crafted GraphQL queryGHSA-7P92-X423-VWJ6Criticalgithub.com/consensys/gnark: Plonk verifier KZG multi point verificationCVE-2023-45683Highgithub.com/crewjam/saml: Cross-site Scripting via missing Binding syntax validationGHSA-9WMC-RG4H-28WVHighgithub.com/kumahq/kuma: github.com/kumahq/kuma affected by CVE-2023-44487CVE-2023-45141Highgithub.com/gofiber/fiber/v2: Go Fiber CSRF Token Validation VulnerabilityCVE-2023-45128Criticalgithub.com/gofiber/fiber/v2: CSRF Token Reuse VulnerabilityGHSA-7V4P-328V-8V5GMediumgithub.com/traefik/traefik: Traefik vulnerable to HTTP/2 request causing denial of service CVE-2023-45142Highgo.opentelemetry.io/contrib/instrumentation/net/http/otelhttp: OpenTelemetry-Go Contrib vulnerable to denial of service in otelhttp due to unbound cardinality metricsCVE-2023-4457Mediumgithub.com/grafana/google-sheets-datasource: Google Sheets data source plugin for Grafana information disclosure vulnerabilityCVE-2023-4822Mediumgithub.com/grafana/grafana: Grafana privilege escalation vulnerabilityCVE-2023-1943Highk8s.io/kops: kOps privilege escalation vulnerabilityCVE-2023-39325Highgolang.org/x/net: HTTP/2 rapid reset can cause excessive work in net/httpCVE-2023-44399Mediumgithub.com/zitadel/zitadel: ZITADEL's password reset does not respect the "Ignoring unknown usernames" settingCVE-2023-20902Mediumgithub.com/goharbor/harbor: Harbor timing attack riskCVE-2023-44487Mediumgolang.org/x/net: HTTP/2 Stream Cancellation AttackGHSA-VX74-F528-FXQGHighgithub.com/nghttp2/nghttp2: github.com/nghttp2/nghttp2 has HTTP/2 Rapid ResetCVE-2023-32188Criticalgithub.com/neuvector/neuvector: JWT token compromise can allow malicious actions including Remote Code Execution (RCE)

Stop the waste.
Protect your environment with Kodem.