Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-21237Highgithub.com/git-lfs/git-lfs: Git LFS can execute a Git binary from the current directory on WindowsCVE-2020-26294Highgithub.com/go-vela/compiler: Exposure of server configuration in github.com/go-vela/serverCVE-2022-24686Mediumgithub.com/hashicorp/nomad: HashiCorp Nomad Artifact Download Race ConditionGHSA-8459-6RC9-8VF8Lowgithub.com/cloudflare/cfrpki: Path traversal in github.com/cloudflare/cfrpki/cmd/octorpkiCVE-2020-26277Mediumgithub.com/datacharmer/dbdeployer: Symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations in dbdeployerCVE-2020-29662Mediumgithub.com/goharbor/harbor: "catalog's registry v2 api exposed on unauthenticated path in Harbor"CVE-2020-26276Highgithub.com/fleetdm/fleet/v4: SAML authentication vulnerability due to stdlib XML parsingCVE-2020-29509Criticalgithub.com/russellhaering/gosaml2: Authentication Bypass in github.com/russellhaering/gosaml2CVE-2020-26521Highgithub.com/nats-io/jwt: Nil dereference in NATS JWT, DoS of nats-serverCVE-2020-26892Criticalgithub.com/nats-io/jwt: Incorrect handling of credential expiry by /nats-io/nats-serverGHSA-FQFH-778M-2V32Mediumgithub.com/cli/cli: GitHub CLI can execute a git binary from the current directoryCVE-2022-2583Lowgithub.com/ntbosscher/gobase: gobase subject to Incorrect routing of some HTTP requests when using httpauth due to a race conditionCVE-2020-27955Criticalgithub.com/git-lfs/git-lfs: Git LFS can execute a Git binary from the current directoryGHSA-HV53-VF5M-8Q94Lowgithub.com/personnummer/go: personnummer/go vulnerable to Improper Input ValidationCVE-2020-15157Mediumgithub.com/containerd/containerd: containerd v1.2.x can be coerced into leaking credentials during image pullCVE-2020-8911Mediumgithub.com/aws/aws-sdk-go: CBC padding oracle issue in AWS S3 Crypto SDK for golangCVE-2020-8912Lowgithub.com/aws/aws-sdk-go: In-band key negotiation issue in AWS S3 Crypto SDK for golangCVE-2020-15129Mediumgithub.com/traefik/traefik: Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix headerCVE-2020-8918Highgithub.com/google/go-tpm: TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpmCVE-2019-19030Mediumgithub.com/goharbor/harbor: Unauthenticated users can exploit an enumeration vulnerability in Harbor (CVE-2019-19030)CVE-2020-13788Lowgithub.com/goharbor/harbor: Harbor is vulnerable to a limited Server-Side Request Forgery (SSRF) (CVE-2020-13788)CVE-2022-0532Mediumgithub.com/cri-o/cri-o: Incorrect Permission Assignment for Critical Resource in CRI-OCVE-2021-45329Mediumgithub.com/go-gitea/gitea: Cross-site Scripting in GiteaCVE-2021-45331Criticalcode.gitea.io/gitea: Reuse of one time passwords allowed in GiteaCVE-2021-45330Criticalcode.gitea.io/gitea: Improper Privilege Management in Gitea

Stop the waste.
Protect your environment with Kodem.