Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-20146Criticalgithub.com/gorilla/handlers: gorilla/handlers may allow requester to bypass expected behavior of the Same Origin PolicyCVE-2016-15005Highgithub.com/dinever/golf: Golf may allow attacker to bypass CSRF protections due to weak PRNGCVE-2020-36561Criticalgithub.com/yi-ge/unzip: Unzip vulnerable to path traversalCVE-2020-36560Criticalgithub.com/artdarek/go-unzip: go-unzip vulnerable to Path TraversalCVE-2019-25072Highgithub.com/tendermint/tendermint: Tendermint Client package vulnerable to Uncontrolled Resource ConsumptionCVE-2020-36564Highgithub.com/justinas/nosurf: nosurf vulnerable to improper input validationCVE-2021-4239Highgithub.com/flynn/noise: Noise vulnerable to denial of serviceCVE-2021-4235Mediumgopkg.in/yaml.v2: YAML Go package vulnerable to denial of serviceCVE-2020-36566Criticalgithub.com/whyrusleeping/tar-utils: tar-utils Path Traversal vulnerabilityCVE-2020-36568Mediumgithub.com/revel/revel: revel is vulnerable to resource exhaustionCVE-2020-36569Criticalgithub.com/nanobox-io/golang-nanoauth: golang-nanoauth authentication bypass vulnerabilityCVE-2022-3064Highgopkg.in/yaml.v2: yaml package for Go can consume excessive amounts of CPU or memoryCVE-2020-36567Highgithub.com/gin-gonic/gin: Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log linesCVE-2022-4734Mediumgithub.com/usememos/memos: usememos/memos may leak user information to an authenticated userCVE-2022-4695Mediumgithub.com/usememos/memos: usememos/memos vulnerable to stored Cross-site ScriptingCVE-2022-4691Mediumgithub.com/usememos/memos: usememos/memos vulnerable to stored Cross-site ScriptingCVE-2022-4694Mediumgithub.com/usememos/memos: usememos/memos vulnerable to stored Cross-site ScriptingCVE-2022-4767Highgithub.com/usememos/memos: usememos/memos Denial of Service vulnerabilityCVE-2021-38561Highgolang.org/x/text: golang.org/x/text/language Out-of-bounds Read vulnerabilityCVE-2022-4741Mediumgithub.com/sajari/docconv: docconv vulnerable to Memory Allocation with Excessive Size ValueCVE-2020-36627Mediumgithub.com/go-macaron/i18n: Macaron i18n Open Redirect vulnerabilityCVE-2022-4692Mediumgithub.com/usememos/memos: usememos/memos vulnerable to stored Cross-site ScriptingCVE-2022-4686Criticalgithub.com/usememos/memos: usememos/memos Authorization Bypass Through User-Controlled Key vulnerabilityCVE-2022-4684Highgithub.com/usememos/memos: usememos/memos Improper Access Control vulnerabilityCVE-2022-4688Highgithub.com/usememos/memos: usememos/memos vulnerable to improper authorization

Stop the waste.
Protect your environment with Kodem.