Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-9122Highgopkg.in/square/go-jose.v1: Go JOSE Signature Validation BypassCVE-2018-16733Highgithub.com/ethereum/go-ethereum: Go Ethereum Improper Input ValidationCVE-2020-10750Mediumgithub.com/jaegertracing/jaeger: Information Exposure in jaegerCVE-2020-14040Mediumgolang.org/x/text: golang.org/x/text Infinite loopCVE-2018-17419Highgithub.com/miekg/dns: miekg/dns parsing error leads to nil pointer dereference and DoSCVE-2021-22133Lowgo.elastic.co/apm: Information Disclosure in go.elastic.co/apmCVE-2021-20188Highgithub.com/containers/libpod: Improper Authorization in github.com/containers/libpodCVE-2020-10696Highgithub.com/containers/buildah: Path Traversal in BuildahCVE-2021-29499Highgithub.com/sylabs/sif: Predictable SIF UUID Identifiers in github.com/sylabs/sifCVE-2020-1764Highgithub.com/kiali/kiali: Hard coded cryptographic key in KialiCVE-2020-7669Highgithub.com/u-root/u-root: github.com/u-root/u-root/pkg/tarutil Arbitrary File Write via Archive Extraction (Zip Slip)CVE-2019-19025Highgithub.com/goharbor/harbor: Cross-site Request Forgery (CSRF) in Cloud Native Computing Foundation HarborCVE-2019-19026Mediumgithub.com/goharbor/harbor: SQL Injection in Cloud Native Computing Foundation HarborCVE-2019-19029Highgithub.com/goharbor/harbor: SQL Injection in Cloud Native Computing Foundation HarborCVE-2019-19023Mediumgithub.com/goharbor/harbor: Privilege Escalation in Cloud Native Computing Foundation HarborCVE-2020-10675Highgithub.com/buger/jsonparser: Infinite Loop in jsonparserCVE-2019-20933Criticalgithub.com/influxdata/influxdb: Improper Authentication in InfluxDBCVE-2020-13250Highgithub.com/hashicorp/consul: Allocation of Resources Without Limits or Throttling in Hashicorp ConsulCVE-2020-13170Mediumgithub.com/hashicorp/consul: Improper Input Validation in HashiCorp ConsulCVE-2020-13223Highgithub.com/hashicorp/vault: Information Disclosure in HashiCorp VaultCVE-2020-12757Criticalgithub.com/hashicorp/vault-plugin-secrets-gcp: Improper Input Validation in HashiCorp VaultCVE-2020-7956Highgithub.com/hashicorp/nomad: Improper Certificate Validation in HashiCorp NomadCVE-2020-7218Highgithub.com/hashicorp/nomad: Allocation of Resources Without Limits or Throttling in HashiCorp NomadCVE-2020-7219Highgithub.com/hashicorp/consul: Denial of Service (DoS) in HashiCorp ConsulCVE-2019-19316Highgithub.com/hashicorp/terraform: Use of a Broken or Risky Cryptographic Algorithm in Terraform

Stop the waste.
Protect your environment with Kodem.