Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-29482Highgithub.com/ulikunitz/xz: github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)CVE-2020-26213Mediumktbs.dev/teler: Denial-of-Service within Docker containerGHSA-G636-Q5FC-4PR7Lowgithub.com/moov-io/customers: accounts: Hash account number using SaltCVE-2020-15257Mediumgithub.com/containerd/containerd: containerd-shim API Exposed to Host Network ContainersCVE-2020-15233Mediumgithub.com/ory/fosite: OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addressesCVE-2020-15234Mediumgithub.com/ory/fosite: Redirect URL matching ignores character casingCVE-2020-15229Highgithub.com/sylabs/singularity: Path traversal and files overwrite with unsquashfs in singularityGHSA-5684-G483-2249Criticalgithub.com/russellhaering/gosaml2: Signature Validation BypassGHSA-RRFW-HG9M-J47HCriticalgithub.com/russellhaering/goxmldsig: Signature Validation BypassCVE-2020-13794Mediumgithub.com/goharbor/harbor: Authenticated users can exploit an enumeration vulnerability in HarborCVE-2020-15222Highgithub.com/ory/fosite: Token reuse in Ory fositeCVE-2020-15223Highgithub.com/ory/fosite: Ory fosite contains Improper Handling of Exceptional Conditions CVE-2020-15216Mediumgithub.com/russellhaering/goxmldsig: github.com/russellhaering/goxmldsig vulnerable to Signature Validation BypassCVE-2020-15187Lowhelm.sh/helm/v3: plugin.yaml file allows for duplicate entries in helmCVE-2020-15186Lowhelm.sh/helm/v3: Improper Sanitizing of plugin names in helmCVE-2020-15185Lowhelm.sh/helm/v3: Repository index file allows for duplicates of the same chart entry in helmCVE-2020-15184Lowhelm.sh/helm/v3: Aliases are never checked in helmCVE-2020-24356Highgithub.com/cloudflare/cloudflared: Local Privilege Escalation in cloudflaredCVE-2020-25040Highgithub.com/sylabs/singularity: Insecure permissions on build temporary rootfs in SingularityCVE-2021-4238Lowgithub.com/Masterminds/goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should beGHSA-GMQ2-39FF-F5QGLowgithub.com/cloudflare/tableflip: A failed upgrade may lead to hung goroutinesGHSA-3WXM-M9M4-CPRJMediumgithub.com/google/exposure-notifications-server: Import of incorrectly embargoed keys could cause early publicationCVE-2021-29651Mediumgithub.com/pomerium/pomerium: JWT leak via Open Redirect in Programmatic accessCVE-2021-29652Mediumgithub.com/pomerium/pomerium: pomerium_signature is not verified in middleware in github.com/pomerium/pomeriumCVE-2021-21405Mediumgithub.com/filecoin-project/lotus: BLS Signature "Malleability"

Stop the waste.
Protect your environment with Kodem.