Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-WPFR-6297-9V57Mediumgithub.com/netlify/gotrue: User object created with invalid provider data in GoTrueCVE-2022-23628Mediumgithub.com/open-policy-agent/opa: Incorrect Calculation in github.com/open-policy-agent/opaCVE-2020-14359Highgithub.com/keycloak/keycloak-gatekeeper: Keycloak Gatekeeper vulnerable to bypass on using lower case HTTP headersCVE-2021-45325Mediumgithub.com/go-gitea/gitea: Gitea displaying raw OpenID error in UICVE-2021-45326Highgithub.com/go-gitea/gitea: Cross Site Request Forgery in GiteaCVE-2021-45327Criticalgithub.com/go-gitea/gitea: Capture-replay in GiteaCVE-2021-45328Mediumgithub.com/go-gitea/gitea: Open redirect in GiteaCVE-2020-8554Mediumk8s.io/kubernetes: Unverified Ownership in KubernetesGHSA-QQ97-VM5H-RRHGLowgithub.com/docker/distribution: OCI Manifest Type Confusion IssueCVE-2022-24450Highgithub.com/nats-io/nats-streaming-server: Incorrect Authorization in NATS nats-serverCVE-2022-23600Mediumgithub.com/fleetdm/fleet/v4: Limited ability to spoof SAML authentication with missing audience verification in FleetCVE-2022-24348Highgithub.com/argoproj/argo-cd/v2: Path traversal and dereference of symlinks in Argo CDCVE-2022-23206Highgithub.com/apache/trafficcontrol: Server-Side Request Forgery in Apache Traffic ControlCVE-2021-46398Highgithub.com/filebrowser/filebrowser/v2: Cross-Site Request Forgery in FilebrowserCVE-2020-8562Lowk8s.io/kubernetes: Potential proxy IP restriction bypass in KubernetesCVE-2022-24124Highgithub.com/casdoor/casdoor: SQL Injection in CasdoorCVE-2022-21687Mediumgithub.com/github/gh-ost: Command injection in gh-ostCVE-2022-0317Mediumgithub.com/google/go-attestation: Go-Attestation Improper Input Validation with attacker-controlled TPM QuoteCVE-2022-23857Mediumgithub.com/navidrome/navidrome: SQL injection in github.com/navidrome/navidromeCVE-2022-21708Mediumgithub.com/graph-gophers/graphql-go: Denial of Service in graphql-goCVE-2023-36474Mediumgithub.com/projectdiscovery/interactsh: Subdomain Takeover in Interactsh serverCVE-2022-21646Highgithub.com/authzed/spicedb: Lookup operations do not take into account wildcards in SpiceDBGHSA-M7VP-HQWV-7M5XHighgithub.com/spiffe/spire: Unbounded memory usage on exposed HTTP/2 (non-gRPC) endpointsCVE-2021-25743Lowk8s.io/kubernetes: kubectl ANSI escape characters not filteredCVE-2021-42583Highgithub.com/foxcpp/maddy: Use of a Broken or Risky Cryptographic Algorithm in Max Mazurov Maddy

Stop the waste.
Protect your environment with Kodem.