Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-31075Mediumgithub.com/kubeedge/kubeedge: KubeEdge DoS when signing the CSR from EdgeCoreCVE-2022-31074Mediumgithub.com/kubeedge/kubeedge: KubeEdge Cloud AdmissionController component DoSCVE-2022-31073Mediumgithub.com/kubeedge/kubeedge: KubeEdge Edge ServiceBus module DoSCVE-2022-31121Highgithub.com/hyperledger/fabric: Hyperledger Fabric vulnerable to Improper Input Validation in orderer/common/cluster consensus requestCVE-2015-3207Mediumgithub.com/openshift/origin: Insecure cookies in Openshift OriginGHSA-F2GR-7299-487HMediumgithub.com/ipfs/go-ipfs: DOS and excessive memory usage when passing untrusted user input to to dag importGHSA-9X4H-8WGM-8XFGMediumgithub.com/ipld/go-car: Malformed CAR panics and excessive memory usageCVE-2022-2306Highgithub.com/heroiclabs/nakama: Insufficient Session Expiration in NakamaCVE-2022-31836Criticalgithub.com/beego/beego: Path Traversal in BeegoCVE-2022-2321Criticalgithub.com/heroiclabs/nakama/v3: Improper Restriction of Excessive Authentication AttemptsCVE-2022-33082Highgithub.com/open-policy-agent/opa: Denial of service in Open Policy Agent CVE-2022-31076Mediumgithub.com/kubeedge/kubeedge: CloudCore UDS Server: Malicious Message can crash CloudCoreGHSA-3JHM-87M6-X959Highgithub.com/cloudflare/cfrpki: Path traversal mitigation bypass in OctoRPKICVE-2022-31077Mediumgithub.com/kubeedge/kubeedge: CloudCore CSI Driver: Malicious response from KubeEdge can crash CSI Driver controller serverCVE-2022-34296Highgithub.com/zalando/skipper: Query predicate bypass in Zalando SkipperCVE-2022-29526Mediumgolang.org/x/sys: golang.org/x/sys/unix has Incorrect privilege reporting in syscallCVE-2022-31098Criticalgithub.com/weaveworks/weave-gitops: Weave GitOps leaked cluster credentials into logs on connection errorsCVE-2022-31016Mediumgithub.com/argoproj/argo-cd: DoS through large manifest files in Argo CDCVE-2022-31036Mediumgithub.com/argoproj/argo-cd: Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-serverCVE-2022-31035Criticalgithub.com/argoproj/argo-cd: Argo CD's external URLs for Deployments can include JavaScriptCVE-2022-31034Highgithub.com/argoproj/argo-cd: Insecure entropy in Argo CD's PKCE/Oauth2/OIDC paramsCVE-2022-31066Mediumgithub.com/edgexfoundry/device-sdk-go/v2: Configuration API in EdgeXFoundry 2.1.0 and earlier exposes message bus credentials to local unauthenticated usersCVE-2022-25856Highgithub.com/argoproj/argo-events: Insecure path traversal in Git Trigger Source can lead to arbitrary file readCVE-2022-31054Highgithub.com/argoproj/argo-events: Uses of deprecated API can be used to cause DoS in user-facing endpointsCVE-2022-31053Criticalbiscuit-auth: Signature forgery in Biscuit

Stop the waste.
Protect your environment with Kodem.