Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-6219Lowgithub.com/canonical/lxd: lxd has a restricted TLS certificate privilege escalation when in PKI modeCVE-2024-55601Mediumgithub.com/gohugoio/hugo: Hugo does not escape some attributes in internal templatesCVE-2024-54132Mediumgithub.com/cli/cli/v2: Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerabilityCVE-2024-54131Highgithub.com/kolide/launcher: Kolide Agent Privilege Escalation (Windows, Versions >= 1.5.3, < 1.12.3)CVE-2024-53257Mediumvitess.io/vitess: Vitess allows HTML injection in /debug/querylogz & /debug/envCVE-2024-53862Mediumgithub.com/argoproj/argo-workflows/v3: Access to Archived Argo Workflows with Fake Token in `client` modeCVE-2024-53264Mediumgithub.com/bunkerity/bunkerweb: BunkerWeb has Open Redirect Vulnerability in Loading PageCVE-2024-53259Mediumgithub.com/quic-go/quic-go: quic-go affected by an ICMP Packet Too Large Injection Attack on LinuxCVE-2024-52801Mediumgithub.com/drakkan/sftpgo/v2: sftpgo vulnerable to brute force takeover of OpenID Connect session cookiesCVE-2024-52003Mediumgithub.com/traefik/traefik/v2: Traefik's X-Forwarded-Prefix Header still allows for Open RedirectCVE-2024-36623Highgithub.com/moby/moby: Moby Race Condition vulnerabilityCVE-2024-36621Highgithub.com/moby/moby: Moby Race Condition vulnerabilityCVE-2024-36620Mediumgithub.com/moby/moby: NULL Pointer Dereference on moby image historyCVE-2024-53858Mediumgithub.com/cli/cli/v2: Recursive repository cloning can leak authentication tokens to non-GitHub submodule hostsCVE-2024-53859Mediumgithub.com/cli/go-gh/v2: `auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespaceCVE-2024-8676Mediumgithub.com/cri-o/cri-o: CRI-O: Maliciously structured checkpoint file can gain arbitrary node accessCVE-2024-43784Mediumgithub.com/treeverse/lakefs: Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletionCVE-2024-52529Mediumgithub.com/cilium/cilium: Cilium's Layer 7 policy enforcement may not occur in policies with wildcarded port rangesGHSA-7F6P-PHW2-8253Highgithub.com/taurusgroup/multi-party-sig: Taurus multi-party-sig has OT-based ECDSA protocol implementation flawsCVE-2024-6538Mediumgithub.com/openshift/console: OpenShift Console Server Side Request Forgery vulnerabilityCVE-2024-10220Highk8s.io/kubernetes: Kubernetes kubelet arbitrary command executionCVE-2024-45719Lowgithub.com/apache/incubator-answer: Apache Answer: Predictable Authorization Token Using UUIDv1CVE-2024-52309Mediumgithub.com/drakkan/sftpgo/v2: SFTPGo allows administrators to restrict command execution from the EventManagerGHSA-R4PG-VG54-WXX4Mediumgithub.com/cert-manager/cert-manager: cert-manager ha a potential slowdown / DoS when parsing specially crafted PEM inputsCVE-2024-52282Mediumgithub.com/rancher/rancher: Rancher Helm Applications may have sensitive values leaked

Stop the waste.
Protect your environment with Kodem.