Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-2515Highgithub.com/mattermost/mattermost-server/v6: Mattermost Incorrect Authorization vulnerabilityCVE-2023-1732Mediumgithub.com/cloudflare/circl: Improper random reading in CIRCLGHSA-QVQG-6RP8-4P9HMediumgithub.com/ipfs/kubo: github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leakGHSA-Q3J6-22WF-3JH9Highgithub.com/ipfs/go-bitswap: github.com/ipfs/go-bitswap vulnerable to DOS unbounded persistent memory leakCVE-2023-2253Highgithub.com/docker/distribution: distribution catalog API endpoint can lead to OOM via malicious user inputCVE-2023-25568Highgithub.com/ipfs/go-libipfs: Boxo bitswap/server: DOS unbounded persistent memory leakCVE-2023-32080Criticalgithub.com/pterodactyl/wings: Wings vulnerable to escape to host from installation containerCVE-2023-29195Mediumvitess.io/vitess: VTAdmin users that can create shards can deny access to other functionsCVE-2023-30840Mediumgithub.com/fluid-cloudnative/fluid: On a compromised node, the fluid-csi service account can be used to modify node specsCVE-2023-2590Lowgithub.com/answerdev/answer: Answer Missing Authorization vulnerabilityCVE-2023-30019Mediumgithub.com/imgproxy/imgproxy/v3: imgproxy is vulnerable to Server-Side Request ForgeryCVE-2023-29659Mediumgithub.com/strukturag/libheif: libheif vulnerable to segmentation fault via floating point exceptionCVE-2023-30844Lowgithub.com/mutagen-io/mutagen: Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpointsGHSA-FWJ4-72FM-C93GLowgithub.com/mutagen-io/mutagen: Under-validated ComSpec and cmd.exe resolution in Mutagen projectsCVE-2023-26125Mediumgithub.com/gin-gonic/gin: Improper input validation in github.com/gin-gonic/ginCVE-2023-30551Highgithub.com/sigstore/rekor: Rekor's compressed archives can result in OOM conditionsCVE-2023-30841Mediumgithub.com/metal3-io/baremetal-operator: Ironic and ironic-inspector may expose as ConfigMapsGHSA-W9MR-28MW-J8HGLowgithub.com/ory/oathkeeper: Hop-by-hop abuse to malform header mutatorCVE-2023-30549Highgithub.com/apptainer/apptainer: Unpatched extfs vulnerabilities are exploitable through suid-mode ApptainerCVE-2023-22651Criticalgithub.com/rancher/rancher: Rancher Webhook is misconfigured during upgrade processCVE-2023-30622Mediumgithub.com/clusternet/clusternet: A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalationCVE-2023-26556Criticalgithub.com/bnb-chain/tss-lib: IO FinNet tss-lib vulnerable to timing attack from non-constant time scalar multiplicationCVE-2023-26557Highgithub.com/bnb-chain/tss-lib: IO FinNet tss-lib vulnerable to timing attack from non-constant time scalar arithmeticCVE-2022-47930Mediumgithub.com/bnb-chain/tss-lib: IO FinNet tss-lib vulnerable to replay attacks involving proofsCVE-2023-29002Highgithub.com/cilium/cilium: Debug mode leaks confidential data in Cilium

Stop the waste.
Protect your environment with Kodem.