Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-30428Highgithub.com/gphper/ginadmin: Arbitrary file read in ginadminCVE-2022-1706Mediumgithub.com/coreos/ignition/v2: Ignition config accessible to unprivileged software on VMwareCVE-2022-29222Mediumgithub.com/pion/dtls: Pion/DLTS Accepts Client Certificates Without CertificateVerifyCVE-2021-43667Highgithub.com/hyperledger/fabric: NULL Pointer Dereference in HyperLedger FabricCVE-2020-35381Highgithub.com/buger/jsonparser: Denial of Service in jsonparserCVE-2022-29190Highgithub.com/pion/dtls: Pion DTLS Header reconstruction method can be thrown into an infinite loopCVE-2022-29189Mediumgithub.com/pion/dtls: Pion/DTLS contains buffer for inbound DTLS fragments with no limitCVE-2022-29188Mediumgithub.com/stripe/smokescreen: Smokescreen SSRF via deny list bypass (square brackets)CVE-2021-29417Criticalgithub.com/liamg/gitjacker: gitjacker arbitrary code executionCVE-2021-27940Mediumgithub.com/openark/orchestrator: openark/orchestrator cross-site scripting vulnerabilityCVE-2020-29652Highgolang.org/x/crypto: golang.org/x/crypto/ssh NULL Pointer Dereference vulnerabilityCVE-2020-25816Criticalgithub.com/hashicorp/vault: Token leases could outlive their TTL in HashiCorp VaultCVE-2018-17572Mediumgithub.com/influxdata/influxdb: InfluxDB Reflected Cross-site Scripting CVE-2019-18817Highistio.io/istio: Istio vulnerable to denial of serviceCVE-2019-18658Criticalhelm.sh/helm: Helm Unsafe Link FollowingCVE-2019-16355Mediumgithub.com/beego/beego: Incorrect Default Permissions in BeegoCVE-2022-29179Highgithub.com/cilium/cilium: Improper Privilege Management in CiliumCVE-2022-29178Highgithub.com/cilium/cilium: Access to Unix domain socket can lead to privileges escalation in CiliumCVE-2022-29180Criticalgithub.com/charmbracelet/charm: Server-Side Request Forgery in charmCVE-2022-29177Mediumgithub.com/ethereum/go-ethereum: DoS via malicious p2p message in Go EthereumCVE-2022-29173Highgithub.com/theupdateframework/go-tuf: Improper Validation of Integrity Check Value in go-tufCVE-2022-1464Mediumgogs.io/gogs: Cross-site Scripting in GogsCVE-2022-29165Criticalgithub.com/argoproj/argo-cd/v2: Argo CD will blindly trust JWT claims if anonymous access is enabledCVE-2021-43350Criticalgithub.com/apache/trafficcontrol: Apache Traffic Control Traffic Ops Vulnerable to LDAP InjectionCVE-2021-31525Mediumgolang.org/x/net: golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

Stop the waste.
Protect your environment with Kodem.