Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-34927Mediumgithub.com/casdoor/casdoor: Casdoor Cross-Site Request Forgery vulnerabilityCVE-2023-34758Criticalgithub.com/bishopfox/sliver: Silver vulnerable to MitM attack against implants due to a cryptography vulnerabilityCVE-2023-35163Mediumcode.vegaprotocol.io/vega: Vega's validators able to submit duplicate transactions CVE-2023-34242Lowgithub.com/cilium/cilium: Cilium vulnerable to information leakage via incorrect ReferenceGrant handlingCVE-2023-2783Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost Server Missing Authorization vulnerabilityCVE-2023-2431Mediumk8s.io/kubernetes: Kubelet vulnerable to bypass of seccomp profile enforcementGHSA-RM8V-MXJ3-5RMQMediumgithub.com/lestrrat-go/jwx/v2: github.com/lestrrat-go/jwx vulnerable to Potential Padding Oracle AttackCVE-2023-34620Highorg.hjson:hjson: hjson stack exhaustion vulnerabilityCVE-2023-2183Mediumgithub.com/grafana/grafana: Grafana has Broken Access Control in Alert manager: Viewer can send test alertsGHSA-8QXH-2GH8-R923Highgithub.com/cheqd/cheqd-node: cheqd-node subject to Cosmos SDK "Barberry" vulnerabilityCVE-2019-12291Highgithub.com/hashicorp/consul: HashiCorp Consul Incorrect Access Control vulnerabilityCVE-2023-34231Highgithub.com/snowflakedb/gosnowflake: Snowflake Golang Driver vulnerable to Command InjectionCVE-2023-2121Mediumgithub.com/hashicorp/vault: Hashicorp Vault vulnerable to Cross-site ScriptingCVE-2023-33498Highgithub.com/alist-org/alist/v3: alist Incorrect Access Control vulnerabilityCVE-2023-2801Highgithub.com/grafana/grafana: Grafana Missing Synchronization vulnerabilityCVE-2023-33959Highgithub.com/notaryproject/notation-go: notation-go's verification bypass can cause users to verify the wrong artifactCVE-2023-33958Mediumgithub.com/notaryproject/notation: Notation's default `maxSignatureAttempts` in `notation verify` enables an endless data attackCVE-2023-33957Mediumgithub.com/notaryproject/notation: Notation vulnerable to denial of service from high number of artifact signaturesCVE-2022-46165Mediumgithub.com/syncthing/syncthing: syncthing vulnerable to Cross-site Scripting (XSS) in Web GUICVE-2023-22647Criticalgithub.com/rancher/rancher: Rancher vulnerable to Privilege Escalation via manipulation of SecretsCVE-2022-43760Mediumgithub.com/rancher/rancher: Rancher UI has multiple Cross-Site Scripting (XSS) issuesCVE-2020-10676Highgithub.com/rancher/rancher: Rancher users retain access after moving namespaces into projects they don't have access toCVE-2023-33967Highgithub.com/megaease/easeprobe: SQL injection when using MySQL/PostgreSQL data checkingCVE-2023-33965Criticalgithub.com/txthinking/brook: Brook's tproxy server is vulnerable to a drive-by command injection.GHSA-7C94-GVVJ-R3MGLowgithub.com/cheqd/cheqd-node: cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability

Stop the waste.
Protect your environment with Kodem.