Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-43618Mediumgithub.com/schollz/croc/v9: Croc requires senders to provide local IP addresses in cleartextCVE-2023-43617Mediumgithub.com/schollz/croc/v9: Cros secrets may be disclosed to untrusted relayCVE-2022-28357Criticalgithub.com/nats-io/nats-server: NATS nats-server allows directory traversal via unintended path to a management action CVE-2023-5036Highgithub.com/usememos/memos: Cross-Site Request Forgery (CSRF) in usememos/memosCVE-2023-4680Mediumgithub.com/hashicorp/vault: HashiCorp Vault Improper Input Validation vulnerabilityCVE-2023-4863Highlibwebp-sys2: libwebp: OOB write in BuildHuffmanTableCVE-2023-32186Highgithub.com/rancher/rke2: RKE2 supervisor port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attackCVE-2023-32187Highgithub.com/k3s-io/k3s: K3s apiserver port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attackCVE-2023-40584Mediumgithub.com/argoproj/argo-cd/v2: Argo CD repo-server Denial of Service vulnerabilityCVE-2023-40029Criticalgithub.com/argoproj/argo-cd/v2: Argo CD cluster secret might leak in cluster details pageCVE-2023-4782Mediumgithub.com/hashicorp/terraform: Terraform allows arbitrary file write during the `init` operationCVE-2023-41338Mediumgithub.com/gofiber/fiber: Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`CVE-2023-41318Mediumgithub.com/turt2live/matrix-media-repo: matrix-media-repo: Unsafe media served inline on download endpointsGHSA-6XV5-86Q9-7XR8Mediumgithub.com/cyphar/filepath-securejoin: SecureJoin: on windows, paths outside of the rootfs could be inadvertently producedCVE-2023-4815Highgithub.com/answerdev/answer: Answer Missing Authentication for Critical FunctionGHSA-23PX-MW2P-46QMMediumgithub.com/cosmos/cosmos-sdk: Cosmos-SDK Cosmovisor component may be vulnerable to denial of serviceCVE-2023-40591Highgithub.com/ethereum/go-ethereum: Go-Ethereum vulnerable to denial of service via malicious p2p messageCVE-2023-28433Highgithub.com/minio/minio: Minio vulnerable to Privilege Escalation on Windows via Path separator manipulationCVE-2023-28434Highgithub.com/minio/minio: Privilege Escalation on Linux/MacOSCVE-2023-36307Mediumsimonwaldherr.de/go/zplgfa: Index out of bounds leading to crashCVE-2023-36308Lowgithub.com/disintegration/imaging: Crash when processing crafted TIFF filesGHSA-H24C-6P6P-M3VXCriticalgithub.com/bnb-chain/tss-lib: tss-lib leaks secret keys in response to incorrectly constructed Paillier moduliCVE-2023-4698Highgithub.com/usememos/memos: usememos/memos vulnerable to improper input validationCVE-2023-4697Highgithub.com/usememos/memos: usememos/memos vulnerable to privilege escalationCVE-2023-4696Criticalgithub.com/usememos/memos: Account TakeOver Due to Improper Handling of JWT Tokens in usememos/memos

Stop the waste.
Protect your environment with Kodem.