Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-4123Lowgithub.com/containers/podman/v4: Buildah (as part of Podman) vulnerable to Path TraversalCVE-2022-4122Mediumgithub.com/containers/podman/v4: Buildah (as part of Podman) vulnerable to Link FollowingCVE-2022-23495Highgithub.com/ipfs/go-merkledag: go-merkledag's ProtoNode may be modified such that common method calls may panicCVE-2022-23469Lowgithub.com/traefik/traefik/v2: Traefik may display authorization header in the debug logsCVE-2022-46153Mediumgithub.com/traefik/traefik/v2: Traefik routes exposed with an empty TLSOptionCVE-2022-23471Mediumgithub.com/containerd/containerd: containerd CRI stream server vulnerable to host memory exhaustion via terminalCVE-2022-23492Highgithub.com/libp2p/go-libp2p: libp2p DoS vulnerability from lack of resource managementCVE-2020-36565Mediumgithub.com/labstack/echo/v4: Echo vulnerable to directory traversalCVE-2022-44942Highgithub.com/casdoor/casdoor: Casdoor arbitrary file deletion vulnerability via uploadFile functionCVE-2022-23466Lowteler.app: teler dashboard vulnerable to DOM-based cross-site scripting (XSS)CVE-2022-46167Highgithub.com/clastix/capsule: Capsule vulnerable to privilege escalation by ServiceAccount deployed in a Tenant NamespaceGHSA-4V48-4Q5M-8VX4Highgithub.com/prometheus/prometheus: Prometheus vulnerable to basic authentication bypassCVE-2022-46146Mediumgithub.com/prometheus/exporter-toolkit: Prometheus Exporter-Toolkit is vulnerable to authentication bypassGHSA-47XH-QXQV-MGVGMediumgithub.com/mittwald/kube-httpcache: kube-httpcache is vulnerable to Cross-Site Request Forgery (CSRF)CVE-2022-41912Criticalgithub.com/crewjam/saml: crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authenticationCVE-2022-3751Criticalgithub.com/owncast/owncast: owncast is vulnerable to SQL InjectionCVE-2022-45933Criticalgithub.com/benc-uk/kubeview: KubeView vulnerable to full cluster takeover due to improper authenticationCVE-2022-4045Mediumgithub.com/mattermost/mattermost-server: Denial of service in MattermostCVE-2022-4044Mediumgithub.com/mattermost/mattermost-server: Denial of service in MattermostCVE-2022-41925Lowtailscale.com/cmd: Tailscale daemon is vulnerable to information disclosure via CSRFCVE-2022-41924Criticaltailscale.com: Tailscale Windows daemon is vulnerable to RCE via CSRFCVE-2022-41920Highgithub.com/duke-git/lancet/v2: Lancet vulnerable to path traversal when unzipping filesCVE-2022-39199Mediumgithub.com/codenotary/immudb: Lack of proper validation of server UUID can be used by the server to trick the client to accept invalid proofsCVE-2022-36111Mediumgithub.com/codenotary/immudb: Insufficient Verification of Proofs generated by the immudb server in client SDK.CVE-2022-38871Highgithub.com/free5gc/free5gc: Free5gc vulnerable to uncontrolled resource consumption

Stop the waste.
Protect your environment with Kodem.