Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-30080Highgithub.com/beego/beego/v2: Access control bypass in BeegoGHSA-FX5P-F64H-93XCMediumgithub.com/ipfs/go-ipfs: Opened exploitable ports in default docker-compose.yaml in go-ipfsCVE-2022-27649Highgithub.com/containers/podman/v4: Podman's default inheritable capabilities for linux container not emptyCVE-2022-21235Criticalgithub.com/Masterminds/vcs: Command Injection Vulnerability with Mercurial in VCSCVE-2022-27651Mediumgithub.com/containers/buildah: Non-empty default inheritable capabilities for linux container in BuildahCVE-2021-3121Highgithub.com/gogo/protobuf: Improper Input Validation in GoGo ProtobufCVE-2022-24778Highgithub.com/containerd/imgcrypt: Incorrect Authorization in imgcryptCVE-2022-0415Highgogs.io/gogs: Unrestricted Upload of File with Dangerous Type in GogsCVE-2022-26245Criticalgithub.com/open-falcon/falcon-plus: SQLinjection in falcon-plusCVE-2022-1058Mediumcode.gitea.io/gitea: Gitea Open RedirectCVE-2022-24768Criticalgithub.com/argoproj/argo-cd: Improper access control allows admin privilege escalation in Argo CDCVE-2022-24731Mediumgithub.com/argoproj/argo-cd: Path traversal allows leaking out-of-bound files from Argo CD repo-serverCVE-2022-24730Highgithub.com/argoproj/argo-cd: Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-serverCVE-2022-27191Highgolang.org/x/crypto: golang.org/x/crypto/ssh Denial of service via crafted SignerCVE-2021-42219Highgithub.com/ethereum/go-ethereum: Denial of service in go-ethereumCVE-2022-21221Highgithub.com/valyala/fasthttp: Path traversal in github.com/valyala/fasthttpCVE-2021-29134Mediumcode.gitea.io/gitea: Path Traversal in GiteaCVE-2022-0811Highgithub.com/cri-o/cri-o: Code Injection in CRI-OGHSA-W2J5-3RCX-VX7XMediumgithub.com/cri-o/cri-o: Sysctls applied to containers with host IPC or host network namespaces can affect the hostCVE-2022-0871Highgogs.io/gogs: Gogs vulnerable to improper PAM authorization handlingGHSA-Q347-CG56-PCQ4Mediumgogs.io/gogs: SSRF in repository migrationCVE-2022-26533Mediumgithub.com/Xhofe/alist: Cross-site Scripting in AlistCVE-2022-0870Mediumgogs.io/gogs: SSRF in repository migrationCVE-2022-0905Highcode.gitea.io/gitea: Gitea Missing Authorization vulnerabilityCVE-2022-24193Criticalgithub.com/IceWhaleTech/CasaOS: Command Injection in CasaOS

Stop the waste.
Protect your environment with Kodem.