Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-24877Criticalgithub.com/fluxcd/kustomize-controller: Improper path handling in kustomization files allows path traversalCVE-2022-27313Highcode.gitea.io/gitea: Arbitrary file deletion in giteaCVE-2022-25850Highgithub.com/hoppscotch/proxyscotch: ProxyScotch is vulnerable to a server-side Request Forgery (SSRF)CVE-2021-36784Mediumgithub.com/rancher/rancher: Privilege escalation for users with create/update permissions in Global Roles in RancherCVE-2021-36778Highgithub.com/rancher/rancher: Exposure of repository credentials to external third-party sources in RancherCVE-2021-4200Highgithub.com/rancher/rancher: Write access to the catalog for any user when restricted-admin role is enabled in RancherCVE-2022-1227Highgithub.com/containers/psgo: Podman publishes a malicious image to public registriesCVE-2022-29947Mediumgithub.com/woodpecker-ci/woodpecker: Woodpecker allows cross-site scripting (XSS) via build logsCVE-2022-29810Mediumgithub.com/hashicorp/go-getter: Insertion of Sensitive Information into Log File in Hashicorp go-getterGHSA-WM2R-RP98-8PMHLowgithub.com/rancher/rancher: Exposure of SSH credentials in Rancher/FleetCVE-2022-24863Highgithub.com/swaggo/http-swagger: Denial of Service in http-swaggerCVE-2022-27652Mediumgithub.com/cri-o/cri-o: Incorrect Default Permissions in CRI-OCVE-2022-24826Criticalgithub.com/git-lfs/git-lfs/v3: Git LFS can execute a binary from the current directory on WindowsCVE-2022-29153Highgithub.com/hashicorp/consul: Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vectorCVE-2022-1384Highgithub.com/mattermost/mattermost-server/v6: Insecure plugin handling in MattermostCVE-2022-1385Mediumgithub.com/mattermost/mattermost-server/v6: Improper Control of a Resource Through its Lifetime in MattermostCVE-2022-1332Mediumgithub.com/mattermost/mattermost-server/v6: Improper Privilege Management in MattermostCVE-2022-1337Mediumgithub.com/mattermost/mattermost-server/v6: Resource exhaustion in MattermostCVE-2018-16886Highgo.etcd.io/etcd/v3: go.etcd.io/etcd Authentication BypassCVE-2015-7528Mediumgithub.com/kubernetes/kubernetes: Information Exposure in KubernetesGHSA-MCQ2-W56R-5W2WHighgithub.com/ipld/go-ipfs: Daemon panics when processing certain blocksCVE-2022-2584Highgithub.com/ipld/go-codec-dagpb: ipld/go-codec-dagpb panics when processing certain blocksCVE-2022-24825Mediumgithub.com/stripe/smokescreen: Smokescreen SSRF via deny list bypassCVE-2021-27117Highgithub.com/beego/beego/v2: Privilege escalation in beegoCVE-2021-27116Highgithub.com/beego/beego/v2: Privilege escalation in beego

Stop the waste.
Protect your environment with Kodem.