Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-36051Highgithub.com/zitadel/zitadel: Broken Authorization in ZITADEL ActionsCVE-2022-36055Mediumhelm.sh/helm/v3: Helm Vulnerable to denial of service through string value parsingGHSA-PFHR-PCCP-HWMHMediumgithub.com/cilium/cilium: Network Policies & (Clusterwide) Cilium Network Policies with namespace label selectors may unexpectedly select pods with maliciously…CVE-2022-36009Mediumgithub.com/matrix-org/dendrite: gomatrixserverlib and Dendrite vulnerable to incorrect parsing of the event default power level in event authCVE-2022-36633Highgithub.com/gravitational/teleport: Improper token validation leading to code execution in TeleportCVE-2022-35936Highgithub.com/evmos/ethermint: Ethermint vulnerable to DoS through unintended Contract SelfdestructCVE-2022-38149Highgithub.com/hashicorp/consul-template: HashiCorp Consul Template could reveal Vault secret contents in error messagesCVE-2022-38183Mediumcode.gitea.io/gitea: Gitea allowed assignment of private issuesGHSA-GWJ5-WP6R-5Q9FHighgithub.com/crypto-org-chain/cronos: Cronos vulnerable to DoS through unintended Contract SelfdestructCVE-2022-35929Highgithub.com/sigstore/cosign: cosign's `cosign verify-attestaton --type` can report a false positive if any attestation existsCVE-2022-35930Highgithub.com/sigstore/policy-controller: PolicyController before 0.2.1 may bypass attestation verificationCVE-2022-37450Mediumgithub.com/ethereum/go-ethereum: Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocksCVE-2022-37315Highgithub.com/graphql-go/graphql: graphql-go has infinite recursion in the type definition parserCVE-2022-24912Highgithub.com/runatlantis/atlantis: Atlantis Events vulnerable to Timing AttackCVE-2022-25891Highgithub.com/containrrr/shoutrrr: Shoutrrr util package DoS via sending 2000, 4000, or 6000 character messagesGHSA-WC5V-R48V-G4VHLowgithub.com/cilium/cilium: Cilium host policy bypass in endpoint-routes mode with dual-stackCVE-2022-31145Mediumgithub.com/flyteorg/flyteadmin: FlyteAdmin Insufficient AccessToken Expiration CheckCVE-2022-2401Mediumgithub.com/mattermost/mattermost-server/v6: Mattermost users could access some sensitive information via API callCVE-2022-2385Highsigs.k8s.io/aws-iam-authenticator: aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9CVE-2022-1025Highgithub.com/argoproj/argo-cd: Argo CD improper access control bug can allow malicious user to escalate privileges to admin levelCVE-2022-31102Lowgithub.com/argoproj/argo-cd: Argo CD SSO users vulnerable to Cross-site ScriptingCVE-2022-31105Highgithub.com/argoproj/argo-cd: Argo CD certificate verification is skipped for connections to OIDC providersCVE-2022-31080Mediumgithub.com/kubeedge/kubeedge: DoS in KubeEdge's Websocket Client in package ViaductCVE-2022-31079Mediumgithub.com/kubeedge/kubeedge: KubeEdge Cloud Stream and Edge Stream DoS from large stream messageCVE-2022-31078Mediumgithub.com/kubeedge/kubeedge: KubeEdge CloudCore Router memory exhaustion vulnerability

Stop the waste.
Protect your environment with Kodem.