Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-38867Highgithub.com/zhaojh329/rttys: rttys SQL Injection vulnerabilityCVE-2022-25978Mediumgithub.com/usememos/memos: Cross Site Scripting in usememos/memosCVE-2023-25168Criticalgithub.com/pterodactyl/wings: Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host systemCVE-2023-23625Mediumgithub.com/ipfs/go-unixfs: Denial of service via HAMT Decoding PanicsCVE-2023-23631Highgithub.com/ipfs/go-unixfsnode: IPFS go-unixfsnode subject to DOS via HAMT Decoding PanicsCVE-2023-23626Mediumgithub.com/ipfs/go-bitfield: IPFS go-bitfield vulnerable to DoS via malformed size argumentsCVE-2023-25163Mediumgithub.com/argoproj/argo-cd/v2: Argo CD leaks repository credentials in user-facing error messages and in logsCVE-2023-25165Mediumhelm.sh/helm/v3: Helm vulnerable to information disclosure via getHostByName Function CVE-2023-25151Highgo.opentelemetry.io/contrib/instrumentation/net/http/otelhttp: otelhttp and otelbeego have DoS vulnerability for high cardinality metricsCVE-2023-24827Mediumgithub.com/anchore/syft: Credential disclosure in syft when SYFT_ATTEST_PASSWORD environment variable setCVE-2023-25152Highgithub.com/pterodactyl/wings: Pterodactyl Wings contains UNIX Symbolic Link (Symlink) FollowingCVE-2023-25307Highgithub.com/nothub/mrpack-install: mrpack-install vulnerable to path traversal with dependencyCVE-2023-0740Criticalgithub.com/answerdev/answer: Cross-site scripting vulnerability found in answerdev/answerCVE-2023-0743Criticalgithub.com/answerdev/answer: Answer subject to Cross-site Scripting vulnerabilityCVE-2023-0744Criticalgithub.com/answerdev/answer: Answer contains Improper Access Control vulnerabilityCVE-2023-0742Criticalgithub.com/answerdev/answer: Answer contains Cross-site Scripting vulnerabilityCVE-2023-0741Criticalgithub.com/answerdev/answer: Answer has Cross-site Scripting vulnerabilityCVE-2023-0739Mediumgithub.com/answerdev/answer: Answer vulnerable to Race ConditionGHSA-74FP-R6JW-H4MPHighk8s.io/apimachinery: Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsingCVE-2020-15106Lowgo.etcd.io/etcd: Panic due to malformed WALs in go.etcd.io/etcdCVE-2021-3538Criticalgithub.com/satori/go.uuid: go.uuid has Predictable UUID IdentifiersCVE-2020-29242Mediumgithub.com/dhowden/tag: Denial of Service in dhowden/tagCVE-2017-3204Highgolang.org/x/crypto: golang.org/x/crypto/ssh Man-in-the-Middle attackGHSA-4XGV-J62Q-H3RJMediumgithub.com/pion/dtls/v2: Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2GHSA-HXP2-XQF3-V83HMediumgithub.com/pion/dtls/v2: Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2

Stop the waste.
Protect your environment with Kodem.