Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-28923Mediumgithub.com/caddyserver/caddy/v2: Open Redirect in CaddyCVE-2018-1103Mediumgithub.com/openshift/source-to-image: Openshift Enterprise source-to-image vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip)CVE-2020-36067Highgithub.com/tidwall/gjson: Improper Validation of Array Index in GJSONCVE-2020-8565Mediumk8s.io/client-go: Kubernetes client-go vulnerable to Sensitive Information Leak via Log FileCVE-2020-8564Mediumgithub.com/kubernetes/kubernetes: Kubernetes Sensitive Information leak via Log FileCVE-2020-29529Highgithub.com/hashicorp/go-slug: Unsafe tar unpacking in HashiCorp go-slugCVE-2022-45786Highgithub.com/apache/age/drivers/golang: Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injectionCVE-2022-47762Highgithub.com/flipped-aurora/gin-vue-admin: Path Traversal in gin-vue-adminCVE-2023-24623Highgithub.com/hakobe/paranoidhttp: Paranoidhttp Server-Side Request Forgery vulnerabilityGHSA-X477-FQ37-Q5WRMediumfortio.org/proxy: Initial debug-host handler implementation could leak information and facilitate denial of serviceCVE-2023-0229Mediumgithub.com/openshift/apiserver-library-go: github.com/openshift/apiserver-library-go Improper Input Validation vulnerabilityCVE-2023-22482Criticalgithub.com/argoproj/argo-cd: JWT audience claim is not verifiedCVE-2022-31249Highgithub.com/rancher/wrangler: Command injection in Git package in WranglerCVE-2022-43756Mediumgithub.com/rancher/wrangler: Denial of service (DoS) when processing Git credentialsCVE-2023-22736Highgithub.com/argoproj/argo-cd/v2: Controller reconciles apps outside configured namespaces when sharding is enabledGHSA-C45C-39F6-6GW9Highgithub.com/rancher/rancher: Rancher generated tokens not revoked after modifications made to authentication providerCVE-2022-43757Highgithub.com/rancher/rancher: Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objectsCVE-2022-43758Mediumgithub.com/rancher/rancher: Command injection in Rancher Git packageCVE-2022-21953Highgithub.com/rancher/rancher: Authenticated user can gain unauthorized shell pod and kubectl access in the local clusterCVE-2022-43759Highgithub.com/rancher/rancher: Privilege escalation in project role template binding (PRTB) and -promoted rolesCVE-2022-43755Highgithub.com/rancher/rancher: Rancher cattle-token is predictableCVE-2022-46959Mediumgithub.com/go-sonic/sonic: Path Traversal in github.com/go-sonic/sonicCVE-2022-23538Mediumgithub.com/sylabs/scs-library-client: scs-library-client may leak user credentials to third-party service via HTTP redirectCVE-2022-47747Highgithub.com/uber/kraken: Kraken has arbitrary file read vulnerability via component testfsCVE-2023-22726Highgithub.com/nektos/act: act vulnerable to arbitrary file upload in artifact server

Stop the waste.
Protect your environment with Kodem.