Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-6558Mediumgithub.com/google/fscrypt: Privilege Escalation in fscryptCVE-2016-9121Criticalgopkg.in/square/go-jose.v1: Elliptic Curve Key Disclosure in go-joseCVE-2016-9123Highgithub.com/square/go-jose: Integer Overflow in go-joseCVE-2020-7667Highgithub.com/sassoftware/go-rpmutils: github.com/sassoftware/go-rpmutils Arbitrary File Write via Archive Extraction (Zip Slip)CVE-2020-17522Mediumgithub.com/apache/trafficcontrol: Cache Manipulation Attack in Apache Traffic ControlCVE-2021-20329Mediumgo.mongodb.org/mongo-driver: go.mongodb.org/mongo-driver improperly validates cstrings when marshalling Go objects into BSONCVE-2020-28924Highgithub.com/rclone/rclone: Use of Cryptographically Weak Pseudo-Random Number Generator in RcloneCVE-2021-3499Mediumgithub.com/ovn-org/ovn-kubernetes: Improper Input ValidationCVE-2021-3495Highgithub.com/kiali/kiali: Access control flaw in KialiCVE-2021-32923Highgithub.com/hashicorp/vault: Invalid session token expiration CVE-2021-20278Mediumgithub.com/kiali/kiali: Kiali Authentication Bypass vulnerabilityCVE-2021-32635Mediumgithub.com/sylabs/singularity: Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote EndpointGHSA-JQ42-HFCH-42F3Mediumgithub.com/hpcng/singularity: Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote EndpointCVE-2020-1701Mediumkubevirt.io/kubevirt: Permissions bypass in KubeVirtCVE-2021-25735Mediumk8s.io/kubernetes: Access Restriction Bypass in kube-apiserverCVE-2020-11091Mediumgithub.com/weaveworks/weave: Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisementsCVE-2020-11013Highhelm.sh/helm/v3: Lookup function information discolosure in helmCVE-2020-5303Lowgithub.com/tendermint/tendermint: Denial of service in TendermintCVE-2020-5300Mediumgithub.com/ory/hydra: Authentication Bypass in hydraCVE-2019-19921Mediumgithub.com/opencontainers/runc: opencontainers runc contains procfs race condition with a shared volume mountGHSA-QMFX-75FF-8MW6Highgithub.com/ThomasLeister/prosody-filer: Listing of upload directory contents possibleCVE-2021-30465Highgithub.com/opencontainers/runc: mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfsCVE-2021-28955Criticalgithub.com/MichaelMure/git-bug: Arbitrary code execution due to an uncontrolled search path for the git binaryCVE-2021-28681Mediumgithub.com/pion/webrtc/v3: In github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communicationCVE-2021-21291Lowgithub.com/oauth2-proxy/oauth2-proxy/v7: Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy

Stop the waste.
Protect your environment with Kodem.