Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-10086Mediumgithub.com/hashicorp/consul: Hashicorp Consul Cross-site Scripting vulnerabilityCVE-2024-0133Mediumgithub.com/NVIDIA/nvidia-container-toolkit: NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file systemCVE-2024-0132Criticalgithub.com/NVIDIA/nvidia-container-toolkit: NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerabilityCVE-2024-10452Lowgithub.com/grafana/grafana: Grafana org admin can delete pending invites in different orgCVE-2024-48921Highgithub.com/kyverno/kyverno: Kyverno's PolicyException objects can be created in any namespace by defaultCVE-2024-47401Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Server vulnerable to application crash from attacker-generated large responseCVE-2024-50052Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost server allows authenticated user to delete arbitrary postCVE-2024-46872Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request ForgeryCVE-2024-10241Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost Server allows user to get private channel namesGHSA-WCX9-CCPJ-HX3CMediumgithub.com/coder/coder/v2: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect')CVE-2024-47827Mediumgithub.com/argoproj/argo-workflows/v3: Argo Workflows Controller: Denial of Service via malicious daemon WorkflowsCVE-2024-10214Lowgithub.com/mattermost/mattermost/server/v8: Mattermost incorrectly issues two sessions when using desktop SSOGHSA-7H65-4P22-39J6Criticalgithub.com/crossplane/crossplane: github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addressesGHSA-X7XJ-JVWP-97RVCriticalgithub.com/rancher/rke2: RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control ListsCVE-2024-22036Criticalgithub.com/rancher/rancher: Rancher Remote Code Execution via Cluster/Node DriversCVE-2022-45157Highgithub.com/rancher/rancher: Exposure of vSphere's CPI and CSI credentials in RancherCVE-2023-32197Criticalgithub.com/rancher/rancher: Rancher allows privilege escalation in Windows nodes due to Insecure Access Control ListsCVE-2024-49757Highgithub.com/zitadel/zitadel: User Registration Bypass in ZitadelCVE-2024-49753Mediumgithub.com/zitadel/zitadel: Denied Host Validation Bypass in Zitadel ActionsCVE-2023-26248Mediumgithub.com/libp2p/go-libp2p-kad-dht: Content Censorship in the InterPlanetary File System (IPFS) via Kademlia DHT abuseGHSA-RJFV-PJVX-MJGVLowsigs.k8s.io/aws-load-balancer-controller: AWS Load Balancer Controller automatically detaches externally associated web ACL from Application Load BalancersCVE-2024-47825Mediumgithub.com/cilium/cilium: Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is presentGHSA-P5WF-CMR4-XRWRHighgithub.com/facebookincubator/tacquito: Permissive Regular Expression in tacquitoCVE-2024-9264Criticalgithub.com/grafana/grafana: Grafana Command Injection And Local File Inclusion Via Sql ExpressionsCVE-2024-9486Criticalgithub.com/kubernetes-sigs/image-builder: VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder

Stop the waste.
Protect your environment with Kodem.