Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-45039Mediumgithub.com/consensys/gnark: gnark's Groth16 commitment extension unsound for more than one commitmentCVE-2024-45040Highgithub.com/consensys/gnark: gnark commitments to private witnesses in Groth16 as implemented break zero-knowledge propertyGHSA-7Q74-G774-7X3GHighgithub.com/cosmos/interchain-security/v5: Interchain Security: The signers of ICS messages do not need to match the provider address CVE-2024-45401Lowgithub.com/stripe/stripe-cli: Path traversal vulnerability in stripe-cli CVE-2024-8462Mediumgithub.com/windmill-labs/windmill: Windmill HTTP Request users.rs excessive authentication in github.com/windmill-labs/windmillCVE-2024-45395Lowgithub.com/sigstore/sigstore-go: sigstore-go has an unbounded loop over untrusted input can lead to endless data attackCVE-2024-43405Mediumgithub.com/projectdiscovery/nuclei/v3: Nuclei Template Signature Verification BypassCVE-2024-45388Highgithub.com/spectolabs/hoverfly: Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`)CVE-2024-43803Mediumgithub.com/metal3-io/baremetal-operator: The Bare Metal Operator (BMO) can expose particularly named secrets from other namespaces via BMH CRDGHSA-G5XX-C4HV-9CCCLowgithub.com/cometbft/cometbft/light: CometBFT's state syncing validator from malicious node may lead to a chain splitCVE-2024-45310Mediumgithub.com/opencontainers/runc: runc can be confused to create empty files/directories on the hostCVE-2024-8365Mediumgithub.com/hashicorp/vault: Vault Leaks Client Token and Token Accessor in Audit DevicesCVE-2024-8260Mediumgithub.com/open-policy-agent/opa: OPA for Windows has an SMB force-authentication vulnerabilityCVE-2024-45054Mediumgithub.com/hwameistor/hwameistor: Hwameistor Potential Permission Leakage of Cluster Level CVE-2024-45043Mediumgithub.com/open-telemetry/opentelemetry-collector-contrib/receiver/awsfirehosereceiver: OpenTelemetry Collector module AWS Firehose Receiver Authentication Bypass VulnerabilityCVE-2024-45436Highgithub.com/ollama/ollama: Ollama can extract members of a ZIP archive outside of the parent directoryGHSA-75QH-GG76-P2W4Mediumcosmwasm-vm: CWA-2023-004: Excessive number of function parameters in compiled WasmCVE-2024-43798Highgithub.com/jpillora/chisel: Chisel's AUTH environment variable not respected in server entrypointCVE-2024-45258Mediumgithub.com/imroc/req/v3: req may send an unintended request when a malformed URL is providedCVE-2024-45244Mediumgithub.com/hyperledger/fabric: Hyperledger Fabric does not verify request has a timestamp within the expected time windowCVE-2024-43105Mediumgithub.com/mattermost/mattermost-plugin-channel-export: Mattermost Plugin Channel Export excessive resource consumptionCVE-2024-43780Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows guest user with read access to upload files to a channelCVE-2024-42497Highgithub.com/mattermost/mattermost/server/v8: Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teamsCVE-2024-40884Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows team admin user without "Add Team Members" permission to disable invite URLCVE-2024-41659Highgithub.com/usememos/memos: memos CORS Misconfiguration in server.go (GHSL-2024-034)

Stop the waste.
Protect your environment with Kodem.