Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-31667Mediumgithub.com/goharbor/harbor: Harbor fails to validate the user permissions when updating a robot accountCVE-2022-31669Mediumgithub.com/goharbor/harbor: Harbor fails to validate the user permissions when updating tag immutability policiesCVE-2022-31666Highgithub.com/goharbor/harbor: Harbor fails to validate the user permissions when viewing Webhook policiesCVE-2022-31670Highgithub.com/goharbor/harbor: Harbor fails to validate the user permissions when updating tag retention policiesCVE-2022-36056Mediumgithub.com/sigstore/cosign: Cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signatureCVE-2022-36049Highgithub.com/fluxcd/helm-controller: Helm Controller denial of serviceCVE-2022-36085Highgithub.com/open-policy-agent/opa: OPA Compiler: Bypass of WithUnsafeBuiltins using "with" keyword to mock functionsCVE-2022-36103Highgithub.com/talos-systems/talos: Talos worker join token can be used to get elevated access level to the Talos APIGHSA-JR8J-2JHP-M67VMediumgithub.com/siderolabs/talos: nftables binding to an already bound chainGHSA-34VW-M4RH-R36PHighgithub.com/talos-systems/talos: Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRMGHSA-3633-5H82-39PQLowgithub.com/theupdateframework/go-tuf: Go-tuf Improperly handles multiple key IDs for the same public keys in attacker-controlled metadataCVE-2022-36110Highgithub.com/gravitl/netmaker: Netmaker vulnerable to Insufficient Granularity of Access ControlCVE-2022-39200Highgithub.com/matrix-org/dendrite: Dendrite signature checks not applied to some retrieved missing eventsGHSA-QV98-3369-G364Highkubevirt.io/kubevirt: KubeVirt vulnerable to arbitrary file read on hostCVE-2022-40365Mediumgithub.com/ouqiang/gocron: ouqiang gocron Cross-site scripting vulnerabilityCVE-2022-2990Highgithub.com/containers/buildah: Buildah's incorrect handling of the supplementary groups may lead to data disclosure, modificationCVE-2022-2989Highgithub.com/containers/podman/v4: Podman's incorrect handling of the supplementary groups may lead to data disclosure, modificationCVE-2022-25295Mediumgithub.com/gophish/gophish: Gophish before 0.12.0 vulnerable to Open RedirectCVE-2022-38638Criticalgithub.com/casdoor/casdoor: Casdoor arbitrary file write vulnerabilityCVE-2022-31671Mediumgithub.com/goharbor/harbor: Harbor fails to validate the user permissions when reading job execution logs through the P2P preheat execution logsCVE-2021-43565Highgolang.org/x/crypto: x/crypto/ssh vulnerable to panic via malformed packetsCVE-2022-27664Highgolang.org/x/net: golang.org/x/net/http2 Denial of Service vulnerabilityCVE-2022-36058Highgithub.com/ElrondNetwork/elrond-go: elrond-go MultiESDTNFTTransfer call on a SC address with missing function nameCVE-2022-31677Mediumgo.pinniped.dev: Pinniped Supervisor Insufficient Session Expiration vulnerabilityCVE-2022-36035Highgithub.com/fluxcd/flux2: Flux CLI Workload Injection

Stop the waste.
Protect your environment with Kodem.