Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-29193Highgithub.com/authzed/spicedb: SpiceDB binding metrics port to untrusted networks and can leak command-line flagsCVE-2023-29018Highgithub.com/open-feature/open-feature-operator: OpenFeature Operator vulnerable to Cluster-level Privilege EscalationCVE-2023-30512Mediumgithub.com/cubefs/cubefs: CubeFS allows Kubernetes cluster-level privilege escalationCVE-2023-29194Mediumvitess.io/vitess: vitess allows users to create keyspaces that can deny access to already existing keyspacesCVE-2023-29013Highgithub.com/traefik/traefik/v2: Traefik HTTP header parsing could cause a denial of service CVE-2023-1974Mediumgithub.com/answerdev/answer: Answer vulnerable to Exposure of Sensitive Information Through MetadataCVE-2023-1975Mediumgithub.com/answerdev/answer: Answer vulnerable to Insertion of Sensitive Information Into Sent DataCVE-2023-1976Highgithub.com/answerdev/answer: Answer vulnerable to account takeover because password reset links do not expireCVE-2023-1782Highgithub.com/hashicorp/nomad: HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalationCVE-2023-28840Highgithub.com/docker/docker: Docker Swarm encrypted overlay network may be unauthenticatedCVE-2023-28841Mediumgithub.com/docker/docker: Docker Swarm encrypted overlay network traffic may be unencryptedCVE-2023-28842Mediumgithub.com/docker/docker: Docker Swarm encrypted overlay network with a single endpoint is unauthenticatedCVE-2020-19277Mediumgithub.com/phachon/mm-wiki: Phachon mm-wiki vulnerable to stored cross-site scripting (XSS)CVE-2020-19278Highgithub.com/phachon/mm-wiki: Phachon mm-wiki Cross Site Request Forgery vulnerabilityCVE-2021-28235Criticalgo.etcd.io/etcd/v3: Etcd-io Improper Authentication vulnerabilityCVE-2023-1800Criticalgithub.com/sjqzhang/go-fastdfs: sjqzhang go-fastdfs vulnerable to path traversalCVE-2023-27163Mediumgithub.com/darklynx/request-baskets: request-baskets vulnerable to Server-Side Request ForgeryGHSA-3HWM-922R-47HWHighatomys.codes/stud42: Stud42 vulnerable to denial of serviceCVE-2023-1776Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost vulnerable to cross-site scripting (XSS)CVE-2023-1775Mediumgithub.com/mattermost/mattermost-server: Mattermost vulnerable to information disclosure CVE-2023-1774Mediumgithub.com/mattermost/mattermost-server: Mattermost fails to properly authentication inviter's permissions to private channelCVE-2023-1777Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost vulnerable to information disclosureCVE-2023-28642Mediumgithub.com/opencontainers/runc: runc AppArmor bypass with symlinked /procCVE-2023-25809Lowgithub.com/opencontainers/runc: rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runcCVE-2023-0620Mediumgithub.com/hashicorp/vault: HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File

Stop the waste.
Protect your environment with Kodem.