Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-39389Highgithub.com/lightningnetwork/lnd: Witness Block Parsing DoS Vulnerability CVE-2022-39383Mediumgithub.com/oam-dev/kubevela: KubeVela VelaUX APIserver has SSRF vulnerability CVE-2022-3920Highgithub.com/hashicorp/consul: Missing Authorization in HashiCorp ConsulCVE-2020-7731Highgithub.com/russellhaering/gosaml2: github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer DereferenceCVE-2022-41719Highgithub.com/shamaton/msgpack/v2: MessagePack for Golang subject to DoS via Unmarshal panicGHSA-VP35-85Q5-9F25Lowgithub.com/docker/docker: Container build can leak any path on the host into the containerCVE-2021-40289Mediumgithub.com/phachon/mm-wiki: mm-wiki is vulnerable to Cross-Site Scripting (XSS)CVE-2022-3866Mediumgithub.com/hashicorp/nomad: HashiCorp Nomad vulnerable to non-sensitive metadata exposureCVE-2022-3867Lowgithub.com/hashicorp/nomad: HashiCorp Nomad vulnerable to Insufficient Session ExpirationCVE-2022-39388Highgithub.com/istio/istio: Istio may allow identity impersonation if user has localhost accessCVE-2022-39395Criticalgithub.com/go-vela/server: Vela Insecure DefaultsCVE-2022-39352Mediumgithub.com/openfga/openfga: OpenFGA Authorization BypassCVE-2022-44797Criticalgithub.com/lightningnetwork/lnd: btcd mishandles witness size checkingCVE-2022-3023Criticalgithub.com/pingcap/tidb: TiDB vulnerable to Use of Externally-Controlled Format StringCVE-2022-3802Highgithub.com/IBAX-io/go-ibax: IBAX go-ibax vulnerable to SQL injectionCVE-2022-3799Highgithub.com/IBAX-io/go-ibax: IBAX go-ibax vulnerable to SQL injectionCVE-2022-3800Highgithub.com/IBAX-io/go-ibax: IBAX go-ibax vulnerable to SQL injectionCVE-2022-3798Highgithub.com/IBAX-io/go-ibax: IBAX go-ibax vulnerable to SQL injectionCVE-2022-3801Highgithub.com/IBAX-io/go-ibax: IBAX go-ibax vulnerable to SQL injectionCVE-2022-3616Mediumgithub.com/cloudflare/cfrpki: OctoRPKI crashes when max iterations is reachedCVE-2022-36182Mediumgithub.com/hashicorp/boundary: Hashicorp Boundary vulnerable to clickjackingCVE-2022-39345Criticalgithub.com/flipped-aurora/gin-vue-admin/server: Gin-vue-admin subject to Remote Code Execution via file upload vulnerabilityCVE-2022-38580Criticalgithub.com/zalando/skipper: Skipper vulnerable to SSRF via X-Skipper-ProxyCVE-2022-39341Mediumgithub.com/openfga/openfga: OpenFGA Authorization Bypass via tupleset wildcardCVE-2022-39342Mediumgithub.com/openfga/openfga: OpenFGA Authorization Bypass

Stop the waste.
Protect your environment with Kodem.