Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-39162Highgithub.com/pomerium/pomerium: Incorrect handling of H2 GOAWAY + SETTINGS framesCVE-2021-38698Mediumgithub.com/hashicorp/consul: HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access…CVE-2021-37219Highgithub.com/hashicorp/consul: HashiCorp Consul Privilege Escalation VulnerabilityCVE-2021-37218Highgithub.com/hashicorp/nomad: Privilege escalation in Hashicorp NomadCVE-2021-25737Mediumk8s.io/kubernetes: Incomplete List of Disallowed Inputs in KubernetesCVE-2021-3761Highgithub.com/cloudflare/cfrpki: OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength valuesCVE-2021-36156Mediumgithub.com/grafana/loki: Path traversal in Grafana LokiCVE-2019-20894Highgithub.com/traefik/traefik/v2: Improper AuthenticationCVE-2020-9321Mediumgithub.com/traefik/traefik: Traefik has an Improper Certificate Handling issueCVE-2021-36157Mediumgithub.com/cortexproject/cortex: Path traversal in Grafana CortexCVE-2021-38599Highgithub.com/wal-g/wal-g: Improper use of cryptographic key in wal-gCVE-2021-21501Highgithub.com/apache/servicecomb-service-center: Path traversal in ServiceCenterCVE-2021-38197Criticalgithub.com/gen2brain/go-unarr: Tarslip in go-unarrCVE-2021-38553Criticalgithub.com/hashicorp/vault: HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0CVE-2021-38554Mediumgithub.com/hashicorp/vault: Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp VaultCVE-2021-32783Highgithub.com/projectcontour/contour: ExternalName Services can be used to gain access to Envoy's admin interfaceCVE-2021-39156Highistio.io/istio: Istio Fragments in Path May Lead to Authorization Policy BypassCVE-2021-39155Highistio.io/istio: Authorization Policy Bypass Due to Case Insensitive Host ComparisonCVE-2021-39137Mediumgithub.com/ethereum/go-ethereum: Ethereum Contains Consensus Flaw During Block ProcessingGHSA-PRQF-XR2J-XF65Lowgithub.com/argoproj/argo-workflows/v3: Potential privilege escalation on Kubernetes >= v1.19 when the Argo Sever is run with `--auth-mode=client`GHSA-6C73-2V8X-QPVMMediumgithub.com/argoproj/argo-workflows/v3: Argo Server TLS requests could be forged by attacker with network accessCVE-2021-37914Mediumgithub.com/argoproj/argo-workflows/v3: Workflow re-write vulnerability using input parameterCVE-2021-32813Mediumgithub.com/traefik/traefik/v2: Header dropping in traefikGHSA-RC7P-GMVH-XFX2Mediumgithub.com/argoproj/argo-workflows: Attack on Kubernetes via Misconfigured Argo WorkflowsCVE-2019-16354Mediumgithub.com/beego/beego: Beego has a file creation race condition

Stop the waste.
Protect your environment with Kodem.