Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-39340Mediumgithub.com/openfga/openfga: OpenFGA subject to Information Disclosure via streamed-list-objects endpointCVE-2022-43677Mediumgithub.com/free5gc/free5gc: free5GC vulnerable to malformed NGAP message crashing the AMF and NGAP decodersCVE-2022-31683Mediumgithub.com/concourse/concourse: Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution CVE-2022-39272Mediumgithub.com/fluxcd/flux2: Improper use of metav1.Duration allows for Denial of ServiceCVE-2022-39267Highgithub.com/brokercap/Bifrost: Bifrost vulnerable to authentication check flaw that leads to authentication bypassGHSA-J92C-MMF7-J5X5Highgithub.com/cheqd/cheqd-node: Potential inter-blockchain communication (IBC) protocol compromise via "Dragonberry" vulnerability in cheqdCVE-2022-42968Criticalgithub.com/go-gitea/gitea: Gitea vulnerable to Argument InjectionCVE-2022-32149Highgolang.org/x/text: golang.org/x/text/language Denial of service via crafted Accept-Language headerCVE-2022-36023Highgithub.com/hyperledger/fabric: Remote denial of service in Hyperledger Fabric GatewayCVE-2022-41606Mediumgithub.com/hashicorp/nomad: Nomad Panics On Job Submission With Bad Artifact Stanza Source URLCVE-2022-32174Criticalgogs.io/gogs: Gogs vulnerable to Cross-site ScriptingCVE-2022-32175Mediumgithub.com/AdguardTeam/AdGuardHome: AdGuardHome vulnerable to Cross-Site Request ForgeryCVE-2022-39271Highgithub.com/traefik/traefik/v2: Traefik HTTP/2 connections management could cause a denial of serviceGHSA-X279-68RR-JP4PMediumgithub.com/supranational/blst: Blst vulnerable to incorrect results for some inputs in blst_fp_eucl_inverse functionCVE-2021-21271Mediumgithub.com/tendermint/tendermint: Tendermint Core vulnerable to Uncontrolled Resource ConsumptionCVE-2020-25614Highgithub.com/antchfx/xmlquery: xmlquery lacks check for whether LoadURL response is in XML format, causing denial of serviceCVE-2020-7711Highgithub.com/russellhaering/goxmldsig: goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signaturesGHSA-9GP7-6833-WV89Lowgo.etcd.io/etcd/client/v3: etcd having a negative value for cluster node size results in an index out-of-bound panic during service discoveryGHSA-528J-9R78-WFFXLowgo.etcd.io/etcd/client/v3: etcd user credentials are stored in WAL logs in plaintextCVE-2020-15115Mediumgo.etcd.io/etcd/client/v3: etcd has no minimum password lengthGHSA-H8G9-6GVH-5MRCLowgo.etcd.io/etcd/v3: etcd vulnerable to TOCTOU of gateway endpoint authenticationCVE-2020-15112Mediumgo.etcd.io/etcd/v3: etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panicCVE-2018-21246Criticalgithub.com/caddyserver/caddy: Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authenticationCVE-2022-39237Mediumgithub.com/sylabs/sif/v2: SIF's Digital Signature Hash Algorithms Not ValidatedCVE-2022-39273Highgithub.com/flyteorg/flyteadmin: FlyteAdmin's Default OAuth Authorization Server secret must be rotated

Stop the waste.
Protect your environment with Kodem.