Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-F99H-W337-MV56Mediumgithub.com/malfunkt/iprange: iprange may panic when parsing ranges with invalid masksGHSA-2W8W-QHG4-F78JMediumgithub.com/jaegertracing/jaeger: A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queriesCVE-2023-37264Lowgithub.com/tektoncd/pipeline: Pipelines do not validate child UIDsGHSA-J2CR-JC39-WPX5Mediumgithub.com/cosmos/cosmos-sdk: Barberry Security Advisory - regarding x/auth periodic vesting accountsCVE-2023-24999Highgithub.com/hashicorp/vault: Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy OperationCVE-2023-1296Mediumgithub.com/hashicorp/nomad: Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own VariablesCVE-2023-0690Highgithub.com/hashicorp/boundary: HashiCorp Boundary Workers Store Rotated Credentials in Plaintext Even When Key Management Service ConfiguredCVE-2022-41316Mediumgithub.com/hashicorp/vault: HashiCorp Vault's revocation list not respectedCVE-2022-32171Mediumgithub.com/zincsearch/zincsearch: Zinc Cross-site Scripting vulnerabilityCVE-2022-32172Mediumgithub.com/zincsearch/zincsearch: Zinc Cross-site Scripting vulnerabilityCVE-2023-36458Mediumgithub.com/1Panel-dev/1Panel: 1Panel vulnerable to command injection when entering the container terminalCVE-2023-36457Mediumgithub.com/1Panel-dev/1Panel: 1Panel vulnerable to command injection when adding container repositoriesCVE-2023-34451Highgithub.com/cometbft/cometbft: CometBFT may duplicate transactions in the mempool's data structuresCVE-2023-34450Mediumgithub.com/cometbft/cometbft: CometBFT PeerState JSON serialization deadlockCVE-2023-3515Lowcode.gitea.io/gitea: code.gitea.io/gitea Open Redirect vulnerabilityCVE-2023-2728Mediumk8s.io/kubernetes: Kubernetes mountable secrets policy bypassCVE-2023-2727Mediumk8s.io/kubernetes: kube-apiserver vulnerable to policy bypassGHSA-W5W5-2882-47PCLowgithub.com/cosmos/cosmos-sdk: github.com/cosmos/cosmos-sdk's x/crisis does not charge ConstantFeeCVE-2023-36815Highgithub.com/labring/sealos: Sealos billing system permission control defectCVE-2023-33190Criticalgithub.com/labring/sealos: Improper configuration of RBAC permissions obtaining cluster control permissionsCVE-2023-3485Lowgo.temporal.io/server: Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of ResourceCVE-2023-35933Mediumgithub.com/openfga/openfga: OpenFGA vulnerable to denial of service due to circular relationshipCVE-2023-35930Lowgithub.com/authzed/spicedb: SpiceDB's LookupResources may return partial resultsCVE-2023-40586Highgithub.com/corazawaf/coraza/v3: Coraza has potential denial of service vulnerabilityCVE-2023-3128Criticalgithub.com/grafana/grafana: Grafana vulnerable to Authentication Bypass by Spoofing

Stop the waste.
Protect your environment with Kodem.