An open API service providing security vulnerability metadata for many open source software ecosystems.

go

go

2,022,662 packages · proxy.golang.org

High
about 13 hours ago

Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced GSA_kwCzR0hTQS04YzM5LXhwcGctNDc5Y84ABQvN

go, packagist github.com/pterodactyl/wings, pterodactyl/panel
High
1 day ago

flagd: Multiple Go Runtime CVEs Impact Security and Availability GSA_kwCzR0hTQS00YzVmLTltajQtbTI0N84ABQr_

go github.com/open-feature/flagd/flagd, github.com/open-feature/flagd/flagd-proxy, github.com/open-feature/flagd/core
Moderate
14 days ago

Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues GSA_kwCzR0hTQS1mbXFmLXBtY20tOGN4Oc4ABQHm

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
16 days ago

Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm GSA_kwCzR0hTQS1xdm1jLTkydmctNnIzNc4ABQDD

go github.com/mattermost/mattermost-plugin-jira, github.com/mattermost/mattermost/server/v8
Moderate
19 days ago

Amazon S3 Encryption Client has a Key Commitment Issue GSA_kwCzR0hTQS0zZzc1LXEyNjgtcjlyNs4ABP88

go github.com/aws/amazon-s3-encryption-client-go/v3
Moderate
20 days ago

Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation GSA_kwCzR0hTQS14M3I4LTJobWgtODlmNc4ABP22

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost
Low
21 days ago

Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection GSA_kwCzR0hTQS1qZjVoLXhmdzQtcDhncM4ABP2N

go github.com/mattermost/mattermost-plugin-github, github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Low
21 days ago

Mattermost has missing redirect URL validation GSA_kwCzR0hTQS1xNjZnLXE5OGMtcTQ1NM4ABP2Q

go github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
21 days ago

Mattermost has CSRF vulnerability via Calls Widget page GSA_kwCzR0hTQS1nbXg1LWZydjktOW05Zs4ABP2S

go github.com/mattermost/mattermost-plugin-calls
Moderate
22 days ago

ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay GSA_kwCzR0hTQS02Z3ZxLWpjbXAtODk1Oc4ABPvn

hex, pypi, rubygems, maven, go, packagist, npm altcha, org.altcha:altcha, github.com/altcha-org/altcha-lib-go, altcha-org/altcha, altcha-lib
High
29 days ago

RCE via ZipSlip and symbolic links in argoproj/argo-workflows GSA_kwCzR0hTQS14cnFjLTd4Z3gtYzl2aM4ABPVz

go github.com/argoproj/argo-workflows, github.com/argoproj/argo-workflows/v3
Moderate
29 days ago

Babylon Incorrect FP inactive accounting in costaking creates “phantom stake” that earns rewards after BTC unbond GSA_kwCzR0hTQS00cm1xLW1jMmMtcjQ5Nc4ABPVt

go github.com/babylonlabs-io/babylon, github.com/babylonlabs-io/babylon/v2, github.com/babylonlabs-io/babylon/v3, github.com/babylonlabs-io/babylon/v4
High
29 days ago

Babylon Nil BlockHash in BLS vote extensions triggers panics in consensus handlers GSA_kwCzR0hTQS1tNndxLTY2cDItYzhwY84ABPUa

go github.com/babylonlabs-io/babylon, github.com/babylonlabs-io/babylon/v2, github.com/babylonlabs-io/babylon/v3, github.com/babylonlabs-io/babylon/v4
Critical
29 days ago

ZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 Login GSA_kwCzR0hTQS03d2ZjLTQ3OTYtZ21nNc4ABPUX

go github.com/zitadel/zitadel/v2, github.com/zitadel/zitadel
Moderate
30 days ago

1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers GSA_kwCzR0hTQS03Y3F2LXFjcTItcjc2Nc4ABPS2

go github.com/1Panel-dev/1Panel/agent, github.com/1Panel-dev/1Panel
High
30 days ago

1Panel – CAPTCHA Bypass via Client-Controlled Flag GSA_kwCzR0hTQS1xbWc1LXY0MngtcXFocc4ABPS1

go github.com/1Panel-dev/1Panel/core, github.com/1Panel-dev/1Panel
Low
about 1 month ago

Mattermost fails to validate user permissions in Boards GSA_kwCzR0hTQS01OHc2LXc1NXgtNndxOM4ABPG0

go github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
about 1 month ago

Mattermost fails to validate user permissions when deleting comments in Boards GSA_kwCzR0hTQS1wNmdqLWpjMzgteDJtN84ABPEk

go github.com/mattermost/mattermost, github.com/mattermost/mattermost/server/v8
Moderate
about 1 month ago

Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic GSA_kwCzR0hTQS0zOHBwLTZnY3AtcnF2bc4ABPEe

go github.com/cilium/cilium, Ciliumgithub.com/cilium/cilium
Critical
about 1 month ago

Mattermost fails to to verify the token used during code exchange GSA_kwCzR0hTQS1tcDZ4LTk3eGotOXg2Ms4ABPBl

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Critical
about 1 month ago

Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication GSA_kwCzR0hTQS0zeDM5LTYyaDQtZjhqNs4ABPBh

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
about 1 month ago

Mattermost fails to sanitize team email addresses GSA_kwCzR0hTQS00Zzg3LTl4NDUtY3gyaM4ABPBk

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8

Filter by Severity

Filter by Package

github.com/mattermost/mattermost/server/v8 154 github.com/mattermost/mattermost-server 97 github.com/usememos/memos 74 github.com/grafana/grafana 57 github.com/hashicorp/vault 51 github.com/rancher/rancher 50 k8s.io/kubernetes 42 github.com/mattermost/mattermost-server/v6 38 github.com/argoproj/argo-cd/v2 36 github.com/answerdev/answer 34 gogs.io/gogs 33 github.com/cilium/cilium 32 github.com/hashicorp/nomad 32 github.com/hashicorp/consul 31 code.gitea.io/gitea 30 github.com/argoproj/argo-cd 30 github.com/docker/docker 29 github.com/zitadel/zitadel 27 github.com/traefik/traefik/v2 24 github.com/ethereum/go-ethereum 21 github.com/goharbor/harbor 21 helm.sh/helm/v3 20 golang.org/x/net 18 github.com/openfga/openfga 18 github.com/traefik/traefik/v3 18 github.com/1Panel-dev/1Panel 17 github.com/containerd/containerd 17 github.com/opencontainers/runc 16 github.com/ollama/ollama 14 kubevirt.io/kubevirt 13 github.com/nats-io/nats-server/v2 13 github.com/cosmos/cosmos-sdk 13 github.com/cri-o/cri-o 13 github.com/mattermost/mattermost-plugin-confluence 13 github.com/traefik/traefik 13 k8s.io/ingress-nginx 12 github.com/go-gitea/gitea 12 golang.org/x/crypto 12 github.com/openbao/openbao 12 github.com/authzed/spicedb 12 github.com/dragonflyoss/dragonfly 11 github.com/filebrowser/filebrowser/v2 11 github.com/cloudflare/cfrpki 11 github.com/pomerium/pomerium 11 github.com/kyverno/kyverno 11 github.com/zitadel/zitadel/v2 11 github.com/cometbft/cometbft 10 github.com/greenpau/caddy-security 10 github.com/filebrowser/filebrowser 10 github.com/containers/podman/v4 10 github.com/canonical/lxd 10 github.com/beego/beego/v2 10 github.com/navidrome/navidrome 9 github.com/hashicorp/go-getter 9 github.com/pterodactyl/wings 9 github.com/treeverse/lakefs 9 github.com/juju/juju 9 github.com/sylabs/singularity 9 github.com/kubernetes/kubernetes 9 github.com/apache/incubator-answer 9 github.com/argoproj/argo-workflows/v3 9 github.com/casdoor/casdoor 9 github.com/coredns/coredns 8 github.com/consensys/gnark 8 github.com/mattermost/mattermost-server/v5 8 github.com/stacklok/minder 8 github.com/containers/buildah 8 go.etcd.io/etcd/v3 8 github.com/moby/moby 8 github.com/beego/beego 8 istio.io/istio 8 github.com/kubeedge/kubeedge 8 github.com/neuvector/neuvector 8 github.com/minio/minio 8 github.com/quic-go/quic-go 7 github.com/siyuan-note/siyuan/kernel 7 github.com/hyperledger/fabric 7 github.com/mattermost/mattermost 7 github.com/gofiber/fiber/v2 7 github.com/google/fscrypt 7 github.com/gravitl/netmaker 6 github.com/argoproj/argo-cd/v3 6 github.com/gophish/gophish 6 github.com/apache/trafficcontrol 6 github.com/git-lfs/git-lfs 6 github.com/charmbracelet/soft-serve 6 github.com/containers/podman/v5 6 github.com/cubefs/cubefs 6 helm.sh/helm 6 github.com/envoyproxy/envoy 6 github.com/lf-edge/ekuiper/v2 6 github.com/containers/podman/v3 5 github.com/osrg/gobgp/v3 5 github.com/bishopfox/sliver 5 github.com/snapcore/snapd 5 github.com/KubeOperator/kubepi 5 github.com/pion/dtls/v2 5 github.com/kiali/kiali 5 github.com/foxcpp/maddy 5 github.com/0xJacky/Nginx-UI 5 github.com/owncast/owncast 5 github.com/tendermint/tendermint 5 github.com/coder/coder/v2 5 github.com/IBAX-io/go-ibax 5 cosmwasm-vm 5 github.com/open-policy-agent/opa 5 github.com/alist-org/alist/v3 5 github.com/fluxcd/flux2 5 goauthentik.io 5 github.com/gin-gonic/gin 5 github.com/drakkan/sftpgo/v2 5 github.com/containerd/containerd/v2 5 github.com/fluxcd/kustomize-controller 5 github.com/moby/buildkit 5 github.com/CosmWasm/wasmd 5 github.com/bnb-chain/tss-lib 5 go.etcd.io/etcd 5 github.com/sigstore/cosign 5 github.com/edgelesssys/contrast 5 github.com/schollz/croc/v9 5 github.com/CosmWasm/wasmvm/v2 5 github.com/russellhaering/goxmldsig 5 github.com/cheqd/cheqd-node 5 github.com/ipfs/go-ipfs 5 github.com/lf-edge/ekuiper 5 github.com/CosmWasm/wasmvm 5 github.com/t2bot/matrix-media-repo 5 vitess.io/vitess 4 github.com/arduino/arduino-create-agent 4 github.com/cosmos/ibc-go/v2 4 github.com/hashicorp/boundary 4 github.com/cosmos/ibc-go/v3 4 github.com/pion/dtls 4 github.com/projectcalico/calico 4 github.com/cosmos/ibc-go/v5 4 golang.org/x/image 4 github.com/aws/aws-sdk-go 4 github.com/babylonlabs-io/babylon/v4 4 github.com/babylonlabs-io/babylon 4 github.com/evmos/evmos/v16 4 github.com/authelia/authelia/v4 4 github.com/notaryproject/notation-go 4 github.com/evmos/evmos/v7 4 github.com/lightningnetwork/lnd 4 github.com/cosmos/ibc-go 4 github.com/dexidp/dex 4 github.com/tidwall/gjson 4 github.com/osrg/gobgp 4 github.com/crossplane/crossplane 4 github.com/layer5io/meshery 4 github.com/oauth2-proxy/oauth2-proxy 4 github.com/elastic/beats 4 github.com/ory/fosite 4 github.com/crewjam/saml 4 github.com/cosmos/ibc-go/v4 4 github.com/IceWhaleTech/CasaOS-UserService 4 github.com/russellhaering/gosaml2 4 github.com/dhowden/tag 4 github.com/chaos-mesh/chaos-mesh 4 github.com/babylonlabs-io/babylon/v2 4 github.com/karmada-io/karmada 4 github.com/lestrrat-go/jwx 4 github.com/NVIDIA/nvidia-container-toolkit 4 github.com/mholt/archiver 4 github.com/go-git/go-git/v5 4 github.com/lestrrat-go/jwx/v2 4 github.com/edgelesssys/constellation/v2 4 github.com/containers/podman 4 github.com/oauth2-proxy/oauth2-proxy/v7 4 github.com/cortexproject/cortex 4 github.com/go-vela/server 4 github.com/evmos/evmos/v13 4 github.com/cli/cli/v2 4 golang.org/x/net/http2 4 miniflux.app/v2 4 github.com/evmos/evmos/v11 4 github.com/free5gc/free5gc 4 go.temporal.io/server 4 github.com/concourse/concourse 4 github.com/esm-dev/esm.sh 4 github.com/evmos/evmos/v6 4 github.com/binance-chain/tss-lib 4 github.com/sigstore/cosign/v2 3 github.com/knadh/listmonk 3 github.com/AlexxIT/go2rtc 3 github.com/lxc/incus/v6 3 k8s.io/client-go 3 github.com/openshift/hive 3 github.com/projectcapsule/capsule 3 github.com/cosmos/ibc-go/v6 3 go.etcd.io/etcd/client/v3 3 github.com/docker/distribution 3 github.com/cloudflare/circl 3 github.com/artifacthub/hub 3 github.com/gofiber/fiber 3 github.com/miekg/dns 3 gopkg.in/src-d/go-git.v4 3 github.com/evmos/evmos/v15 3 github.com/libp2p/go-libp2p 3 github.com/AdguardTeam/AdGuardHome 3

Filter by Repository

https://github.com/usememos/memos 68 https://github.com/kubernetes/kubernetes 65 https://github.com/mattermost/mattermost 59 https://github.com/argoproj/argo-cd 50 https://github.com/rancher/rancher 46 https://github.com/grafana/grafana 46 https://github.com/answerdev/answer 34 https://github.com/go-gitea/gitea 32 https://github.com/cilium/cilium 31 https://github.com/gogs/gogs 28 https://github.com/zitadel/zitadel 26 https://github.com/traefik/traefik 25 https://github.com/hashicorp/consul 24 https://github.com/moby/moby 23 https://github.com/helm/helm 22 https://github.com/goharbor/harbor 21 https://github.com/hashicorp/vault 21 https://github.com/containerd/containerd 19 https://github.com/openfga/openfga 17 https://github.com/ethereum/go-ethereum 17 https://github.com/etcd-io/etcd 16 https://github.com/hashicorp/nomad 16 https://github.com/opencontainers/runc 15 https://github.com/golang/go 14 https://github.com/cosmos/cosmos-sdk 14 https://github.com/containers/podman 14 https://github.com/1Panel-dev/1Panel 13 https://github.com/openbao/openbao 13 https://github.com/nats-io/nats-server 12 https://github.com/kubevirt/kubevirt 11 https://github.com/pomerium/pomerium 11 https://github.com/cometbft/cometbft 11 https://github.com/cloudflare/cfrpki 11 https://github.com/filebrowser/filebrowser 11 https://github.com/cri-o/cri-o 11 https://github.com/beego/beego 11 https://github.com/dragonflyoss/dragonfly 11 https://github.com/greenpau/caddy-security 10 https://github.com/authzed/spicedb 10 https://github.com/canonical/lxd 10 https://github.com/kyverno/kyverno 10 https://github.com/argoproj/argo-workflows 9 https://github.com/casdoor/casdoor 9 https://github.com/juju/juju 9 https://github.com/treeverse/lakeFS 9 https://github.com/hashicorp/go-getter 9 https://github.com/navidrome/navidrome 8 https://github.com/kubeedge/kubeedge 8 https://github.com/stacklok/minder 8 https://github.com/minio/minio 8 https://github.com/Consensys/gnark 8 https://github.com/docker/docker 8 https://github.com/pterodactyl/wings 8 https://github.com/containers/buildah 8 https://github.com/istio/istio 8 https://github.com/gofiber/fiber 8 https://github.com/ollama/ollama 7 https://github.com/google/fscrypt 7 https://github.com/kubernetes/ingress-nginx 7 https://github.com/evmos/evmos 7 https://github.com/neuvector/neuvector 7 https://github.com/hpcng/singularity 7 https://github.com/hyperledger/fabric 7 https://github.com/quic-go/quic-go 6 https://github.com/cubefs/cubefs 6 https://github.com/moby/buildkit 6 https://github.com/gravitl/netmaker 6 https://github.com/open-policy-agent/opa 6 https://github.com/charmbracelet/soft-serve 6 https://github.com/lf-edge/ekuiper 6 https://github.com/git-lfs/git-lfs 6 https://github.com/pion/dtls 6 https://github.com/fluxcd/flux2 6 https://github.com/drakkan/sftpgo 6 https://github.com/schollz/croc 6 https://github.com/oauth2-proxy/oauth2-proxy 6 https://github.com/sigstore/cosign 6 https://github.com/coredns/coredns 6 https://github.com/CosmWasm/wasmvm 5 https://github.com/crewjam/saml 5 https://github.com/free5gc/free5gc 5 https://github.com/tendermint/tendermint 5 https://github.com/edgelesssys/contrast 5 https://github.com/0xJacky/nginx-ui 5 https://github.com/CosmWasm/wasmd 5 https://github.com/IBAX-io/go-ibax 5 https://github.com/ipfs/go-ipfs 5 https://github.com/cli/cli 5 https://github.com/t2bot/matrix-media-repo 5 https://github.com/siyuan-note/siyuan 5 https://github.com/gophish/gophish 5 https://github.com/osrg/gobgp 5 https://github.com/cheqd/cheqd-node 5 https://github.com/foxcpp/maddy 5 https://github.com/IceWhaleTech/CasaOS-UserService 4 https://github.com/golang/crypto 4 https://github.com/lestrrat-go/jwx 4 https://github.com/woodpecker-ci/woodpecker 4 https://github.com/ory/fosite 4 https://github.com/BishopFox/sliver 4 https://github.com/crossplane/crossplane 4 https://github.com/containous/traefik 4 https://github.com/notaryproject/notation-go 4 https://github.com/russellhaering/gosaml2 4 https://github.com/projectdiscovery/nuclei 4 https://github.com/authelia/authelia 4 https://github.com/arduino/arduino-create-agent 4 https://github.com/dexidp/dex 4 https://github.com/go-vela/server 4 https://github.com/snapcore/snapd 4 https://github.com/concourse/concourse 4 https://github.com/meshery/meshery 4 https://github.com/owncast/owncast 4 https://github.com/go-git/go-git 4 https://github.com/apache/trafficcontrol 4 https://github.com/cosmos/ibc-go 4 https://github.com/edgelesssys/constellation 4 https://github.com/siderolabs/talos 4 https://github.com/dhowden/tag 4 https://github.com/aws/aws-sdk-go 4 https://github.com/envoyproxy/envoy 4 https://github.com/vitessio/vitess 4 https://github.com/coder/coder 4 https://github.com/gin-gonic/gin 4 https://github.com/Consensys/gnark-crypto 4 https://github.com/grafana/bugbounty 4 https://github.com/alist-org/alist 4 https://github.com/chaos-mesh/chaos-mesh 4 https://github.com/tidwall/gjson 4 https://github.com/babylonlabs-io/babylon 4 https://github.com/syncthing/syncthing 3 https://github.com/apache/incubator-answer 3 https://github.com/kiali/kiali 3 https://github.com/KubeOperator/KubePi 3 https://github.com/runatlantis/atlantis 3 https://github.com/mudler/localai 3 https://github.com/artifacthub/hub 3 https://github.com/phachon/mm-wiki 3 https://github.com/mholt/archiver 3 https://github.com/moby/libnetwork 3 https://github.com/plentico/plenti 3 https://github.com/project-zot/zot 3 https://github.com/ctfer-io/chall-manager 3 https://github.com/gogits/gogs 3 https://github.com/kcp-dev/kcp 3 https://github.com/NVIDIA/gpu-operator 3 https://github.com/openshift/origin 3 https://github.com/imgproxy/imgproxy 3 https://github.com/ory/oathkeeper 3 https://github.com/mattermost/mattermost-plugin-boards 3 https://github.com/weaveworks/weave-gitops 3 https://github.com/AlexxIT/go2rtc 3 https://github.com/heketi/heketi 3 https://github.com/temporalio/temporal 3 https://github.com/dutchcoders/transfer.sh 3 https://github.com/caddyserver/caddy 3 https://github.com/go-yaml/yaml 3 https://github.com/open-telemetry/opentelemetry-go-contrib 3 https://github.com/distribution/distribution 3 https://github.com/fleetdm/fleet 3 https://github.com/goauthentik/authentik 3 https://github.com/libp2p/go-libp2p 3 https://github.com/sylabs/singularity 3 https://github.com/edgelesssys/marblerun 3 https://github.com/flyteorg/flyteadmin 3 https://github.com/cloudflare/circl 3 https://github.com/argoproj/argo-events 3 https://github.com/square/go-jose 3 https://github.com/lightningnetwork/lnd 3 https://github.com/tailscale/tailscale 3 https://github.com/tiagorlampert/CHAOS 3 https://github.com/cortexproject/cortex 3 https://github.com/ubuntu/authd 3 https://github.com/go-jose/go-jose 3 https://github.com/ElrondNetwork/elrond-go 3 https://github.com/karmada-io/karmada 3 https://github.com/pingcap/tidb 3 https://github.com/ipfs/boxo 3 https://github.com/kubernetes-sigs/secrets-store-csi-driver 3 https://github.com/SpectoLabs/hoverfly 3 https://github.com/nats-io/jwt 3 https://github.com/u-root/u-root 3 https://github.com/miniflux/v2 3 https://github.com/clidey/whodb 3 https://github.com/siderolabs/omni 3 https://github.com/mattermost/mattermost-plugin-playbooks 3 https://github.com/theupdateframework/go-tuf 3 https://github.com/flipped-aurora/gin-vue-admin 3 https://github.com/IoFinnet/tss-lib 3 https://github.com/metal3-io/baremetal-operator 3 https://github.com/gohugoio/hugo 3 https://github.com/projectcapsule/capsule-proxy 2 https://github.com/btcsuite/btcd 2 https://github.com/jackc/pgx 2 https://github.com/gravitational/teleport 2 https://github.com/goreleaser/goreleaser 2 https://github.com/codenotary/immudb 2 https://github.com/labring/sealos 2 https://github.com/gotify/server 2