Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-1906Criticalgithub.com/openshift/origin: Authorization bypass in OpenshiftCVE-2021-32637Criticalgithub.com/authelia/authelia/v4: Authelia vulnerable to an authentication bypassed with malformed request URI on nginxCVE-2019-11254Mediumgopkg.in/yaml.v2: Excessive Platform Resource Consumption within a Loop in KubernetesCVE-2021-39183Highgithub.com/owncast/owncast: Unsafe inline XSS in pasting DOM element into chatCVE-2021-43415Highgithub.com/hashicorp/nomad: Improper Authentication in HashiCorp NomadCVE-2020-11576Mediumgithub.com/argoproj/argo-cd: Observable Discrepancy in ArgoCVE-2021-41090Mediumgithub.com/grafana/agent: Instance config inline secret exposure in GrafanaCVE-2021-43784Mediumgithub.com/opencontainers/runc: Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunCCVE-2021-43669Highgithub.com/hyperledger/fabric: HTTP Request Smuggling in github.com/hyperledger/fabricCVE-2021-43998Criticalgithub.com/hashicorp/vault: HashiCorp Vault Incorrect Permission Assignment for Critical ResourceCVE-2021-20848Mediumgithub.com/schollz/rwtxt: Cross-site Scripting in github.com/schollz/rwtxtCVE-2021-43668Mediumgithub.com/ethereum/go-ethereum: Denial of Service in Go-EthereumCVE-2021-41278Mediumgithub.com/edgexfoundry/app-functions-sdk-go/v2: Broken encryption in EdgeX FoundryCVE-2021-3978Highgithub.com/cloudflare/cfrpki: Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpkiCVE-2021-41190Lowgithub.com/opencontainers/distribution-spec: Clarify Content-Type handlingGHSA-5J5W-G665-5M35Lowgithub.com/containerd/containerd: Ambiguous OCI manifest parsingGHSA-77VH-XPMG-72QHLowgithub.com/opencontainers/image-spec: Clarify `mediaType` handlingCVE-2021-41266Highgithub.com/minio/console: Authentication bypass issue in the Operator ConsoleCVE-2021-41254Highgithub.com/fluxcd/kustomize-controller: Privilege escalation to cluster admin on multi-tenant environmentsCVE-2021-3912Mediumgithub.com/cloudflare/cfrpki: OctoRPKI crashes when processing GZIP bomb returned via malicious repositoryCVE-2021-3908Mediumgithub.com/cloudflare/cfrpki: Infinite certificate chain depth results in OctoRPKI running foreverCVE-2021-3909Mediumgithub.com/cloudflare/cfrpki: Infinite open connection causes OctoRPKI to hang foreverCVE-2021-3910Highgithub.com/cloudflare/cfrpki: NUL character in ROA causes OctoRPKI to crashCVE-2021-3907Highgithub.com/cloudflare/cfrpki: Arbitrary filepath traversal via URI injection CVE-2021-3911Mediumgithub.com/cloudflare/cfrpki: Misconfigured IP address field in ROA leads to OctoRPKI crash

Stop the waste.
Protect your environment with Kodem.