Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-38817Highgithub.com/dapr/dashboard: Dapr Dashboard vulnerable to Incorrect Access ControlCVE-2022-39222Criticalgithub.com/dexidp/dex: Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization codeCVE-2022-2529Highgithub.com/cloudflare/goflow/v3: Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling packageCVE-2022-40931Mediumgithub.com/dutchcoders/transfer.sh: Dutchoders transfer.sh contains an XSS vulnerability via malicious file uploadCVE-2022-32169Mediumgithub.com/bytebase/bytebase: Bytebase does not restrict low privilege user to access admin issuesCVE-2022-32170Mediumgithub.com/bytebase/bytebase: Bytebase allows low-privilege users to view admin projectsCVE-2022-40083Criticalgithub.com/labstack/echo/v4: Labstack Echo Open Redirect vulnerabilityCVE-2022-40082Highgithub.com/cloudwego/hertz: Hertz contains path traversal via normalizePath functionCVE-2022-39219Highgithub.com/brokercap/Bifrost: Brokercap Bifrost subject to authentication bypass when using HTTP basic authenticationCVE-2022-40716Mediumgithub.com/hashicorp/consul: HashiCorp Consul vulnerable to authorization bypassCVE-2022-35253Highgithub.com/hyperledger/fabric: Hyperledger Fabric subject to Denial of Service via non-validated requestCVE-2022-3257Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost subject to Denial of Service via upload of special GIFCVE-2021-41803Highgithub.com/hashicorp/consul: HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertionsGHSA-GMHJ-XJFH-CF6MHighgithub.com/mohammed90/caddy-ssh: Caddy-SSH vulnerable to Authorization Bypass due to incorrect usage of PAM libraryCVE-2021-36782Criticalgithub.com/rancher/rancher: Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentialsGHSA-28Q9-9C3G-V3F9Highgithub.com/treeverse/lakefs: lakeFS vulnerable to authenticated users deleting files they are not authorized to deleteCVE-2022-40186Criticalgithub.com/hashicorp/vault: HashiCorp Vault vulnerable to incorrect metadata accessCVE-2022-32167Mediumgithub.com/HFO4/cloudreve: Cross site scripting in CloudreveCVE-2022-39220Mediumgithub.com/drakkan/sftpgo: SFTPGo WebClient vulnerable to Cross-site ScriptingCVE-2022-2995Highgithub.com/cri-o/cri-o: CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosureCVE-2022-36078Highgithub.com/gagliardetto/binary: Binary vulnerable to Slice Memory Allocation with Excessive Size ValueCVE-2022-36061Criticalgithub.com/ElrondNetwork/elrond-go: Elrond-go has improper initializationCVE-2022-36071Highgithub.com/drakkan/sftpgo/v2: SFTPGo vulnerable to recovery codes abuseCVE-2022-36109Mediumgithub.com/docker/docker: Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictionsCVE-2022-39213Highgithub.com/pandatix/go-cvss: Go-CVSS has Out-of-bounds Read vulnerability in ParseVector function

Stop the waste.
Protect your environment with Kodem.