Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-23772Highgithub.com/kataras/iris/v12: Link Following in IrisCVE-2021-4024Mediumgithub.com/containers/podman/v3: Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podmanCVE-2021-43839Highgithub.com/crypto-org-chain/cronos: Drainage of FeeCollector's Block Transaction Fees in cronosGHSA-GP6J-VX54-5PMFCriticalgithub.com/keep-network/keep-ecdsa: Incorrect validation of parties IDs leaks secret keys in Secret-sharing schemeCVE-2021-43816Highgithub.com/containerd/containerd: Unprivileged pod using `hostPath` can side-step active LSM when it is SELinuxCVE-2021-44716Highgolang.org/x/net/http2: golang.org/x/net/http2 allows uncontrolled memory consumptionCVE-2020-25039Highgithub.com/sylabs/singularity: Insecure permissions on user namespace / fakeroot temporary rootfs in SingularityCVE-2019-11328Highgithub.com/sylabs/singularity: Incorrect Permission Assignment for Critical Resource in SingularityCVE-2020-13846Highgithub.com/sylabs/singularity: "Verify All" Returns Success Despite Validation Failures in SingularityCVE-2020-13845Highgithub.com/sylabs/singularity: Execution Control List (ECL) Is Insecure in SingularityGHSA-G54H-M393-CPWQLowgithub.com/opencontainers/runc: devices resource list treated as a blacklist by defaultCVE-2016-9962Mediumgithub.com/opencontainers/runc: Information Exposure in RunCCVE-2016-3697Highgithub.com/opencontainers/runc: Privilege Elevation in runcGHSA-F3W5-V9XX-RP8PMediumgithub.com/tendermint/tendermint: Signature verification failure in TendermintCVE-2020-15091Mediumgithub.com/tendermint/tendermint: Denial of Service in TenderMintCVE-2020-12283Mediumgithub.com/sourcegraph/sourcegraph: Open redirect vulnerability in SourcegraphCVE-2017-1000069Highgithub.com/bitly/oauth2_proxy: Cross-site Request Forgery (CSRF)CVE-2017-1000070Mediumgithub.com/bitly/oauth2_proxy: Open Redirect in oauth2_proxyCVE-2020-5233Mediumgithub.com/oauth2-proxy/oauth2-proxy: The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirectCVE-2020-11053Highgithub.com/oauth2-proxy/oauth2-proxy: Open Redirect in OAuth2 ProxyCVE-2020-4037Mediumgithub.com/oauth2-proxy/oauth2-proxy: Open Redirect in OAuth2 ProxyCVE-2020-5415Highgithub.com/concourse/concourse: GitLab auth uses full name instead of username as user ID, allowing impersonationCVE-2020-26290Criticalgithub.com/dexidp/dex: Critical security issues in XML encoding in github.com/dexidp/dexCVE-2020-27847Criticalgithub.com/dexidp/dex: Authentication Bypass in dexCVE-2015-5250Mediumgithub.com/openshift/origin: Denial of Service in OpenShift Origin

Stop the waste.
Protect your environment with Kodem.