Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-39348Mediumgithub.com/spinnaker/spinnaker: Improper log output when using GitHub Status Notifications in spinnakerCVE-2023-39059Highgithub.com/ansible-semaphore/semaphore: Code injection in ansible semaphoreCVE-2023-40579Mediumgithub.com/openfga/openfga: OpenFGA Authorization BypassCVE-2023-32079Highgithub.com/gravitl/netmaker: Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin UserCVE-2023-32078Highgithub.com/gravitl/netmaker: Netmaker IDOR Allows User to Update Other User's PasswordCVE-2023-32077Highgithub.com/gravitl/netmaker: Netmaker has Hardcoded DNS Secret KeyCVE-2023-40583Highgithub.com/libp2p/go-libp2p: libp2p nodes vulnerable to OOM attackCVE-2023-40577Mediumgithub.com/prometheus/alertmanager: Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpointCVE-2023-40025Highgithub.com/argoproj/argo-cd/v2: Argo CD web terminal session doesn't expireCVE-2023-38976Highgithub.com/weaviate/weaviate: Weaviate denial of service vulnerabilityCVE-2023-40034Highgithub.com/woodpecker-ci/woodpecker: Woodpecker does not validate webhook before changing any dataCVE-2023-40023Highgithub.com/yaklang/yaklang: Yaklang Plugin's Fuzztag Component Allows Unauthorized Local File ReadingGHSA-9PHH-R37V-34WHMediumgithub.com/treeverse/lakefs: lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML FilesCVE-2023-4108Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost fails to sanitize post metadataCVE-2023-4107Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost does not validate requesting user permissions before updating admin detailsCVE-2023-4106Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost fails to check if user is a guest before performing actions on public playbooksCVE-2023-4105Lowgithub.com/mattermost/mattermost-server/v6: Mattermost fails to correctly delete attachmentsCVE-2023-39966Highgithub.com/1Panel-dev/1Panel: 1Panel arbitrary file write vulnerabilityCVE-2023-39965Mediumgithub.com/1Panel-dev/1Panel: 1Panel Arbitrary File Download vulnerabilityCVE-2023-39964Highgithub.com/1Panel-dev/1Panel: 1Panel O&M management panel has a background arbitrary file reading vulnerabilityGHSA-8C37-7QX3-4C4PMediumgithub.com/supranational/blst: Blst has logical error in SigValidate in Go bindingsCVE-2023-3518Highgithub.com/hashicorp/consul: Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT ProvidersCVE-2023-39533Highgithub.com/libp2p/go-libp2p: libp2p nodes vulnerable to attack using large RSA keysCVE-2022-38795Mediumcode.gitea.io/gitea: Gitea erroneous repo clonesCVE-2023-37896Highgithub.com/projectdiscovery/nuclei/v2: Nuclei Path Traversal vulnerability

Stop the waste.
Protect your environment with Kodem.