Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-PFFG-92CG-XF5CLowgithub.com/consensys/gnark-crypto: gnark-crypto's exponentiation in the pairing target group GT using GLV can give incorrect resultsCVE-2023-44378Mediumgithub.com/consensys/gnark: gnark unsoundness in variable comparison / non-unique binary decompositionCVE-2023-43809Highgithub.com/charmbracelet/soft-serve: Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is EnabledGHSA-HQ58-P9MV-338CLowgithub.com/cometbft/cometbft: CometBFT's default for `BlockParams.MaxBytes` consensus parameter may increase block times and affect consensus participationCVE-2023-5193Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Incorrect Authorization vulnerabilityCVE-2023-5194Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Incorrect Authorization vulnerabilityCVE-2023-5159Lowgithub.com/mattermost/mattermost/server/v8: Mattermost Incorrect Authorization vulnerabilityCVE-2023-5195Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Incorrect Authorization vulnerabilityCVE-2023-5196Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Uncontrolled Resource Consumption vulnerabilityCVE-2023-5077Highgithub.com/hashicorp/vault: Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerabilityCVE-2023-43645Mediumgithub.com/openfga/openfga: OpenFGA Vulnerable to DoS from circular relationship definitionsCVE-2023-40026Mediumgithub.com/argoproj/argo-cd: Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-serverCVE-2023-41333Mediumgithub.com/cilium/cilium: Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy CVE-2023-41332Lowgithub.com/cilium/cilium: Specific Cilium configurations vulnerable to DoS via Kubernetes annotationsCVE-2023-43644Criticalgithub.com/sagernet/sing-box: sing-box vulnerable to improper authentication in the SOCKS inboundCVE-2023-39347Mediumgithub.com/cilium/cilium: Kubernetes users may update Pod labels to bypass network policyCVE-2018-17846Highgolang.org/x/net: x/net/html Vulnerable to DoS During HTML ParsingCVE-2023-1260Highgithub.com/openshift/apiserver-library-go: kube-apiserver authentication bypass vulnerabilityCVE-2022-3962Mediumgithub.com/kiali/kiali: Kiali content spoofing vulnerabilityCVE-2023-42821Highgithub.com/gomarkdown/markdown: Markdown vulnerable to Out-of-bounds Read while parsing citationsCVE-2023-37279Highgithub.com/contribsys/faktory: Faktory Web Dashboard can lead to denial of service(DOS) via malicious user inputCVE-2023-43621Mediumgithub.com/schollz/croc/v9: Croc may expose secret to local usersCVE-2023-43620Highgithub.com/schollz/croc/v9: Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal deviceCVE-2023-43616Mediumgithub.com/schollz/croc: Sender can cause a receiver to overwrite files during ZIP extraction in CrocCVE-2023-43619Highgithub.com/schollz/croc/v9: Croc sender may send dangerous new files to receiver

Stop the waste.
Protect your environment with Kodem.