Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-4127Mediumgithub.com/answerdev/answer: Answer has Race Condition within a ThreadCVE-2023-4125Highgithub.com/answerdev/answer: Answer has Weak Password RequirementsCVE-2023-4126Mediumgithub.com/answerdev/answer: Answer Insufficient Session Expiration vulnerabilityCVE-2023-4124Highgithub.com/answerdev/answer: Answer Missing Authorization vulnerabilityCVE-2023-3978Mediumgolang.org/x/net: Improper rendering of text nodes in golang.org/x/net/htmlCVE-2023-29408Mediumgolang.org/x/image: Golang TIFF decoder does not place a limit on the size of compressed tile dataCVE-2023-29407Mediumgolang.org/x/image: Golang TIFF decoder vulnerable to excessive CPU consumptionCVE-2023-3462Mediumgithub.com/hashicorp/vault: HashiCorp Vault and Vault Enterprise vulnerable to user enumerationCVE-2023-37900Lowgithub.com/crossplane/crossplane: Denial of service from large imageCVE-2023-38495Highgithub.com/crossplane/crossplane: Possible image tampering from missing image validation for PackagesCVE-2023-38496Mediumgithub.com/apptainer/apptainer: Ineffective privileges drop when requesting container networkCVE-2023-37916Mediumgithub.com/KubeOperator/kubepi: KubePi may leak password hash of any userCVE-2023-37917Criticalgithub.com/KubeOperator/kubepi: KubePi Privilege Escalation vulnerabilityCVE-2023-37918Mediumgithub.com/dapr/dapr: Dapr API token authentication bypass in HTTP endpointsCVE-2023-3300Mediumgithub.com/hashicorp/nomad: Nomad Search API Leaks Information About CSI PluginsCVE-2023-3299Lowgithub.com/hashicorp/nomad: Nomad Caller ACL Token’s Secret ID is Exposed to SentinelCVE-2023-3072Mediumgithub.com/hashicorp/nomad: Nomad ACL Policies without Label are Applied to Unexpected ResourcesCVE-2023-37788Highgithub.com/elazarl/goproxy: goproxy Denial of Service vulnerabilityCVE-2023-37477Highgithub.com/1Panel-dev/1Panel: 1Panel command injection vulnerability in Firewall ip functionalityCVE-2023-37266Criticalgithub.com/IceWhaleTech/CasaOS: CasaOS contains weak JWT secretsCVE-2023-37265Criticalgithub.com/IceWhaleTech/CasaOS-Gateway: CasaOS Gateway vulnerable to incorrect identification of source IP addressesCVE-2023-37475Highgithub.com/hamba/avro: avro vulnerable to denial of service via attacker-controlled parameterCVE-2023-34236Highgithub.com/weaveworks/tf-controller: Weave GitOps Terraform Controller Information Disclosure VulnerabilityGHSA-F28G-86HC-823QMediumgithub.com/superfly/tokenizer: Tokenizer vulnerable to client brute-force of token secretsCVE-2023-34458Highgithub.com/multiversx/mx-chain-go: mx-chain-go's relayed transactions always increment nonce

Stop the waste.
Protect your environment with Kodem.