Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-29164Highgithub.com/argoproj/argo-workflows/v3: Malicious HTML+XHR Artifact Privilege Escalation in Argo WorkflowsCVE-2022-31259Criticalgithub.com/beego/beego/v2: Access control bypass in beegoCVE-2022-24878Highgithub.com/fluxcd/kustomize-controller: Improper path handling in Kustomization files allows for denial of serviceCVE-2022-28946Highgithub.com/open-policy-agent/opa: Out of bounds memory access in github.com/open-policy-agent/opaCVE-2022-28948Highgopkg.in/yaml.v3: gopkg.in/yaml.v3 Denial of ServiceCVE-2022-30689Mediumgithub.com/hashicorp/vault: HashiCorp Vault improper configuration of multi factor authenticationCVE-2017-14992Mediumgithub.com/vbatts/tar-split: tar-split memory exhaustionCVE-2017-16539Mediumgithub.com/moby/moby: Docker Moby /proc/scsi Path Exposure Allows Host Data Loss (SCSI MICDROP)CVE-2022-30781Highcode.gitea.io/gitea: Shell command injection in giteaCVE-2022-24817Criticalgithub.com/fluxcd/flux2: Improper kubeconfig validation allows arbitrary code executionCVE-2017-1000420Highgithub.com/syncthing/syncthing: Syncthing vulnerable to symlink traversal and arbitrary file overwriteCVE-2018-9057Criticalgithub.com/hashicorp/terraform-provider-aws: HashiCorp Terraform Amazon Web Services (AWS) uses an insecure PRNG CVE-2015-9258Highgithub.com/docker/notary: Docker Notary Signature Algorithm Not Matched to Key vulnerabilityCVE-2018-12018Highgithub.com/ethereum/go-ethereum: Go Ethereum LES protocol implementation vulnerable to Denial of ServiceCVE-2018-15192Highcode.gitea.io/gitea: Gogs and Gitea SSRF VulnerabilityCVE-2018-17031Mediumgogs.io/gogs: Gogs XSS VulnerabilityCVE-2018-1000816Mediumgithub.com/grafana/grafana: Grafana XSS VulnerabilityCVE-2018-19295Highgithub.com/sylabs/singularity: Sylabs Singularity Improper Input ValidationCVE-2018-19148Lowgithub.com/caddyserver/caddy: Caddy allows enumeration of Certificates and HostnamesCVE-2018-20303Highgogs.io/gogs: Gogs Directory TraversalCVE-2018-19653Mediumgithub.com/hashicorp/consul: HashiCorp Consul can use cleartext agent-to-agent RPC communicationCVE-2019-1000008Mediumhelm.sh/helm: Helm Path TraversalCVE-2019-8400Mediumgithub.com/ory/hydra: Hydra has Reflected XSS via error_hint parameterCVE-2018-20744Mediumgithub.com/gofiber/fiber/v2: github.com/gofiber/fiber/v2 vulnerable to Origin Validation ErrorCVE-2018-12021Mediumgithub.com/hpcng/singularity: Singularity Incorrect Access Control

Stop the waste.
Protect your environment with Kodem.