Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-55196Highgithub.com/gophish/gophish: GoPhish sends cleartext passwordsCVE-2024-25131Highgithub.com/openshift/must-gather: OpenShift Must Gather Operator Improper Input Validation vulnerabilityGHSA-5PF6-CQ2V-23WWHighgithub.com/clidey/whodb/core: WhoDB Allows Unbounded Memory Consumption in Authentication Middleware Can Lead to Denial of ServiceCVE-2024-45338Highgolang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/htmlGHSA-32GQ-X56H-299CMediumfilippo.io/age: age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary executionCVE-2024-9779Highopen-cluster-management.io/ocm: Open Cluster Management vulnerable to Trust Boundary ViolationGHSA-HXR6-2P24-HF98Mediumgithub.com/traefik/traefik/v2: Traefik affected by CVE-2024-53259GHSA-8WCC-M6J2-QXVMHighgithub.com/cosmos/cosmos-sdk: ASA-2024-0012, ASA-2024-0013: CosmosSDK: Transaction decoding may result in a stack overflow or resource exhaustion CVE-2024-55949Highgithub.com/minio/minio: MinIO vulnerable to privilege escalation in IAM import APICVE-2024-54682Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Data Amplification vulnerabilityCVE-2024-54083Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Improper Validation of Specified Type of Input vulnerabilityCVE-2024-48872Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Race Condition vulnerabilityCVE-2024-12289Mediumgithub.com/hashicorp/boundary: Boundary Community Edition Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of ServiceCVE-2024-55885Mediumgithub.com/beego/beego/v2: Beego has Collision Hazards of MD5 in Cache Key FilenamesGHSA-7PRJ-HGX4-2XC3Highgithub.com/ryanbekhen/nanoproxy: Potential Vulnerabilities Due to Outdated golang.org/x/crypto Dependency in NanoProxyCVE-2024-45337Criticalgolang.org/x/crypto: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/cryptoCVE-2024-55657Highgithub.com/siyuan-note/siyuan/kernel: SiYuan has an arbitrary file read via /api/template/renderCVE-2024-55658Highgithub.com/siyuan-note/siyuan/kernel: SiYuan has an arbitrary file read and path traversal via /api/export/exportResourcesCVE-2024-55659Highgithub.com/siyuan-note/siyuan/kernel: SiYuan has an arbitrary file write in the host via /api/asset/uploadCVE-2024-55660Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan has an SSTI via /api/template/renderSprigGHSA-C7XH-GJV4-4JGVMediumgithub.com/kcp-dev/kcp: kcp's impersonation allows access to global administrative groupsGHSA-2Q97-M5RC-P3GPMediumgithub.com/CosmWasm/wasmvm/v2: CosmWasm VM Incorrect meteringGHSA-VMQH-5232-V43RMediumgithub.com/CosmWasm/wasmvm/v2: Panic in wasmvm can slow down block productionGHSA-VMG2-R3XV-R3XFLowgithub.com/CosmWasm/wasmd: Simulation of Wasmd message can cause crashingCVE-2024-6156Lowgithub.com/canonical/lxd: lxd CA certificate sign check bypass

Stop the waste.
Protect your environment with Kodem.