Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-44337Mediumgithub.com/gomarkdown/markdown: Infinite loop in github.com/gomarkdown/markdownCVE-2024-9594Mediumgithub.com/kubernetes-sigs/image-builder: VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builderCVE-2024-48909Lowgithub.com/authzed/spicedb: SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is notGHSA-VV6C-69R6-CHG9Lowgithub.com/landlock-lsm/go-landlock: Go-Landlock in best-effort mode did not restrict TCP bind and connect operations correctlyCVE-2024-46528Mediumgithub.com/kubesphere/kubesphere: KubeSphere IDOR vulnerabilityCVE-2024-47877Mediumgithub.com/codeclysm/extract/v3: Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory.CVE-2024-47832Criticalgithub.com/ssoready/ssoready: SSOReady has an XML Signature Bypass via differential XML parsingCVE-2024-9180Highgithub.com/hashicorp/vault: Vault Community Edition privilege escalation vulnerabilityCVE-2024-47067Mediumgithub.com/alist-org/alist/v3: Alist reflected Cross-Site Scripting vulnerabilityCVE-2024-9312Mediumgithub.com/ubuntu/authd: Authd allows attacker-controlled usernames to yield controllable UIDsCVE-2024-38365Highgithub.com/btcsuite/btcd: btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionalityCVE-2024-47182Lowgithub.com/amir20/dozzle: Dozzle uses unsafe hash for passwordsCVE-2024-9675Mediumgithub.com/containers/buildah: Buildah allows arbitrary directory mountCVE-2024-36814Highgithub.com/AdguardTeam/AdGuardHome: Adguard Home arbitrary file read vulnerabilityCVE-2024-8038Mediumgithub.com/juju/juju: Vulnerable juju introspection abstract UNIX domain socketCVE-2024-8037Mediumgithub.com/juju/juju: Vulnerable juju hook tool abstract UNIX domain socketCVE-2024-9313Highgithub.com/ubuntu/authd: PAM module may allow accessing with the credentials of another userGHSA-WPR2-J6GR-PJW9Lowgithub.com/opentofu/opentofu: OpenTofu potential leaking of secret variable values when using static evaluation in v1.8CVE-2024-7558Mediumgithub.com/juju/juju: JUJU_CONTEXT_ID is a predictable authentication secretCVE-2024-47616Highgithub.com/pomerium/pomerium: Pomerium service account access token may grant unintended access to databroker APICVE-2024-33662Highgithub.com/portainer/portainer: Portainer improperly uses an encryption algorithm in the AesEncrypt functionCVE-2024-9407Mediumgithub.com/containers/buildah: Improper Input Validation in Buildah and PodmanCVE-2024-9355Highgithub.com/golang-fips/openssl: Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerabilityCVE-2024-9341Mediumgithub.com/containers/common: Link Following in github.com/containers/commonCVE-2024-47534Highgithub.com/theupdateframework/go-tuf/v2: Incorrect delegation lookups can make go-tuf download the wrong artifact

Stop the waste.
Protect your environment with Kodem.