An open API service providing security vulnerability metadata for many open source software ecosystems.

go

go

1,983,772 packages · proxy.golang.org

Moderate
17 days ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS03Y3IzLTM4am0tNnA0Nc4ABNex

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
17 days ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS0zcTRxLXdxbTYtaHZmM84ABNe5

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
about 1 month ago

Repository Credentials Race Condition Crashes Argo CD Server GSA_kwCzR0hTQS1nODhwLXI0MnItcHBwOc4ABMyV

go github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2
Moderate
about 1 month ago

Grafana-Zabbix ReDoS vulnerability GSA_kwCzR0hTQS1nNHJyLTg4ZmMtMjZmas4ABMYk

go github.com/alexanderzobnin/grafana-zabbix
Moderate
about 2 months ago

Mattermost makes Use of Weak Hash GSA_kwCzR0hTQS05cDkyLXg3N3ctOWZ3Ms4ABMEa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
about 2 months ago

Mattermost Missing Authorization vulnerability GSA_kwCzR0hTQS0zdmNtLWM0MnAtM2hoZs4ABMEP

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
2 months ago

Mattermost Fails to Sanitize File Names GSA_kwCzR0hTQS1wajZmLXJjOTQtZ3c1M84ABLUh

go github.com/mattermost/mattermost-server
Moderate
2 months ago

Mattermost has Potential Server Crash due to Unvalidated Import Data GSA_kwCzR0hTQS1oNDY5LTRmY2YtcDIzaM4ABLUR

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
2 months ago

Mattermost Fails to Sanitize Path Traversal Sequences GSA_kwCzR0hTQS14NjdjLXY4anItcDI5cs4ABLTm

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
2 months ago

Mattermost Fails to Validate File Paths GSA_kwCzR0hTQS1ncTNyLTU4MzMtNTUzMs4ABLTi

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
2 months ago

Mattermost Fails to Validate Remote Cluster Upload Sessions GSA_kwCzR0hTQS1xNDUzLTYzOGMtaDRtcs4ABLTn

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
2 months ago

Mattermost Does Not Sanitize the Team Invite ID GSA_kwCzR0hTQS1xajQ3LXc5ZjItcWc0NM4ABLTl

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
3 months ago

OpenFGA Authorization Bypass GSA_kwCzR0hTQS1tZ2g5LTRtd3AtZmc1Nc4ABLLo

go github.com/openfga/openfga
Moderate
3 months ago

Mattermost Confluence Plugin has Missing Authorization vulnerability GSA_kwCzR0hTQS12NmM4LWc1M2gtbWMyaM4ABK7P

go github.com/mattermost/mattermost-plugin-confluence
Moderate
3 months ago

Mattermost Confluence Plugin has Missing Authorization vulnerability GSA_kwCzR0hTQS1xanJ4LWo4d20teGY4M84ABK7T

go github.com/mattermost/mattermost-plugin-confluence
Moderate
3 months ago

Mattermost Confluence Plugin has Missing Authorization vulnerability GSA_kwCzR0hTQS1qNjZoLXhocHItN3E1Z84ABK7F

go github.com/mattermost/mattermost-plugin-confluence
Moderate
3 months ago

Mattermost Confluence Plugin has Missing Authorization vulnerability GSA_kwCzR0hTQS1jbXByLThwcnEtdzVwNc4ABK7I

go github.com/mattermost/mattermost-plugin-confluence
Moderate
3 months ago

Mattermost Confluence Plugin has Missing Authorization vulnerability GSA_kwCzR0hTQS12cGNyLWZxcGMtMzg2aM4ABK7R

go github.com/mattermost/mattermost-plugin-confluence
Moderate
3 months ago

Grafana Infinity Datasource Plugin SSRF Vulnerability GSA_kwCzR0hTQS0zYzkzLTkycjctajkzNM4ABKv2

go github.com/grafana/grafana-infinity-datasource
Moderate
4 months ago

Mattermost Path Traversal vulnerability GSA_kwCzR0hTQS13dncyLTNqaDQtNGMzOc4ABKRq

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago

Mattermost Missing Authentication for Critical Function GSA_kwCzR0hTQS03aDM0LTljaHItNThxaM4ABKRa

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago

juju/utils leaks private key in certs GSA_kwCzR0hTQS1oMzRyLWp4cW0tcWdwcs4ABJmf

go github.com/juju/utils/v4/cert
Moderate
4 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS12OGZyLXZ4bXctNm1mNs4ABJkm

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS13Z3ZwLWpqNHctODhoZs4ABJkw

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Moderate
4 months ago

File Browser vulnerable to insecure password handling GSA_kwCzR0hTQS1jbTJyLXJnN3ItcDdnZ84ABJkh

go github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
Moderate
4 months ago

File Browser allows sensitive data to be transferred in URL GSA_kwCzR0hTQS1ybXdoLWczNjctbWo0eM4ABJkd

go github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
Moderate
4 months ago

filebrowser Sets Insecure File Permissions GSA_kwCzR0hTQS1qajJyLTQ1NXAtNWd2Zs4ABJfk

go github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2

Filter by Severity

Filter by Package

github.com/mattermost/mattermost/server/v8 85 github.com/usememos/memos 50 github.com/mattermost/mattermost-server 47 github.com/grafana/grafana 31 github.com/mattermost/mattermost-server/v6 30 k8s.io/kubernetes 24 github.com/hashicorp/vault 21 github.com/answerdev/answer 21 github.com/cilium/cilium 19 github.com/argoproj/argo-cd/v2 17 github.com/hashicorp/consul 16 github.com/docker/docker 16 github.com/hashicorp/nomad 15 github.com/goharbor/harbor 13 github.com/openfga/openfga 13 helm.sh/helm/v3 12 github.com/containerd/containerd 11 github.com/traefik/traefik/v2 11 github.com/rancher/rancher 11 github.com/argoproj/argo-cd 11 github.com/ethereum/go-ethereum 11 github.com/greenpau/caddy-security 10 gogs.io/gogs 9 code.gitea.io/gitea 9 github.com/mattermost/mattermost-plugin-confluence 8 github.com/kubeedge/kubeedge 8 github.com/traefik/traefik/v3 8 github.com/cri-o/cri-o 8 github.com/dragonflyoss/dragonfly 7 github.com/google/fscrypt 7 github.com/openbao/openbao 7 github.com/mattermost/mattermost-server/v5 7 github.com/zitadel/zitadel 7 github.com/treeverse/lakefs 6 github.com/kubernetes/kubernetes 6 github.com/traefik/traefik 6 github.com/1Panel-dev/1Panel 6 github.com/moby/moby 6 github.com/stacklok/minder 6 github.com/opencontainers/runc 6 github.com/apache/incubator-answer 6 github.com/pomerium/pomerium 6 github.com/cosmos/cosmos-sdk 5 github.com/CosmWasm/wasmvm 5 golang.org/x/net 5 github.com/t2bot/matrix-media-repo 5 github.com/CosmWasm/wasmvm/v2 5 github.com/cloudflare/cfrpki 5 github.com/juju/juju 5 github.com/containers/podman/v4 5 cosmwasm-vm 5 github.com/coredns/coredns 5 github.com/lestrrat-go/jwx 4 github.com/gophish/gophish 4 github.com/casdoor/casdoor 4 github.com/lestrrat-go/jwx/v2 4 github.com/argoproj/argo-workflows/v3 4 github.com/containers/buildah 4 vitess.io/vitess 4 github.com/pion/dtls/v2 4 github.com/dhowden/tag 4 github.com/navidrome/navidrome 4 github.com/kyverno/kyverno 4 k8s.io/ingress-nginx 4 github.com/go-gitea/gitea 4 github.com/schollz/croc/v9 3 github.com/neuvector/neuvector 3 github.com/tendermint/tendermint 3 github.com/containers/podman/v3 3 github.com/sigstore/cosign 3 github.com/cli/cli/v2 3 github.com/notaryproject/notation 3 github.com/filebrowser/filebrowser/v2 3 github.com/openshift/console 3 github.com/aws/aws-sdk-go 3 github.com/canonical/lxd 3 k8s.io/client-go 3 github.com/snapcore/snapd 3 golang.org/x/image 3 github.com/cubefs/cubefs 3 github.com/pterodactyl/wings 3 github.com/cometbft/cometbft 3 github.com/containers/podman/v2 3 golang.org/x/crypto 3 github.com/ollama/ollama 3 github.com/osrg/gobgp 3 github.com/consensys/gnark 3 github.com/osrg/gobgp/v3 3 github.com/cortexproject/cortex 3 github.com/ipfs/go-ipfs 3 github.com/mholt/archiver 3 github.com/go-jose/go-jose/v3 3 github.com/drakkan/sftpgo/v2 3 github.com/filebrowser/filebrowser 3 kubevirt.io/kubevirt 3 github.com/authzed/spicedb 3 github.com/pydio/cells 2 github.com/dvsekhvalnov/jose2go 2 github.com/containers/podman 2 github.com/gohugoio/hugo 2 github.com/IceWhaleTech/CasaOS-UserService 2 github.com/layer5io/meshery 2 github.com/ory/fosite 2 www.velocidex.com/golang/velociraptor 2 github.com/ubuntu/authd 2 github.com/arduino/arduino-create-agent 2 github.com/gofiber/fiber 2 github.com/sigstore/cosign/v2 2 github.com/gorilla/csrf 2 github.com/phachon/mm-wiki 2 github.com/quic-go/quic-go 2 github.com/jaegertracing/jaeger 2 github.com/open-policy-agent/opa 2 github.com/codenotary/immudb 2 github.com/fluid-cloudnative/fluid 2 miniflux.app/v2 2 github.com/pion/dtls 2 github.com/CosmWasm/wasmd 2 github.com/kitabisa/teler-waf 2 github.com/lf-edge/ekuiper 2 github.com/moby/buildkit 2 github.com/edgexfoundry/app-functions-sdk-go/v2 2 github.com/stripe/smokescreen 2 github.com/caddyserver/caddy/v2 2 github.com/gin-gonic/gin 2 github.com/supranational/blst 2 github.com/cli/go-gh/v2 2 github.com/kuadrant/authorino 2 github.com/projectcalico/calico 2 github.com/alist-org/alist/v3 2 golang.org/x/net/http2 2 github.com/owncast/owncast 2 github.com/containerd/containerd/v2 2 github.com/fluxcd/source-controller 2 go.etcd.io/etcd 2 zotregistry.dev/zot 2 github.com/lf-edge/ekuiper/v2 2 github.com/containers/podman/v5 2 github.com/bytebase/bytebase 2 github.com/go-viper/mapstructure/v2 2 github.com/go-jose/go-jose/v4 2 github.com/evmos/evmos/v13 2 github.com/oauth2-proxy/oauth2-proxy 2 github.com/cli/cli 2 github.com/hpcng/singularity 2 gopkg.in/yaml.v2 2 github.com/kiali/kiali 2 github.com/hashicorp/go-getter 2 github.com/grafana/agent 2 github.com/bep/imagemeta 2 github.com/beego/beego 2 github.com/dutchcoders/transfer.sh 2 github.com/beego/beego/v2 2 github.com/imgproxy/imgproxy/v3 2 github.com/goreleaser/goreleaser 2 github.com/bishopfox/sliver 2 github.com/AlexxIT/go2rtc 2 go.etcd.io/etcd/v3 2 github.com/apache/trafficcontrol 2 github.com/zinclabs/zinc 2 github.com/concourse/concourse 2 github.com/gitpod-io/gitpod 2 github.com/metal3-io/baremetal-operator 2 github.com/hashicorp/boundary 2 github.com/forceu/gokapi 2 github.com/minio/minio 2 github.com/openshift/origin 2 github.com/mattermost/mattermost-plugin-playbooks 2 istio.io/istio 2 github.com/kubewarden/kubewarden-controller 2 github.com/gotify/server 2 github.com/zincsearch/zincsearch 2 github.com/dapr/dapr 2 sigs.k8s.io/secrets-store-csi-driver 2 github.com/openshift/hive 1 github.com/appleboy/gorush 1 github.com/RobotsAndPencils/go-saml 1 github.com/coder/agentapi 1 github.com/turt2live/matrix-media-repo 1 github.com/ipfs/kubo 1 github.com/evmos/evmos/v13/x/vesting 1 github.com/superfly/tokenizer 1 github.com/leanote/leanote 1 github.com/coreos/ignition 1 github.com/minio/console 1 github.com/Xhofe/alist 1 github.com/evmos/evmos/v8 1 github.com/songquanpeng/one-api 1 github.com/influxdata/influxdb 1 github.com/heketi/heketi 1 github.com/seaweedfs/seaweedfs 1 github.com/Shopify/ejson2env/v2 1 github.com/netlify/gotrue 1 github.com/argoproj/gitops-engine 1 github.com/pires/go-proxyproto 1 github.com/fluxcd/image-automation-controller 1 github.com/consensys/gnark-crypto 1 github.com/jackc/pgx/v5 1 github.com/canonical/pebble 1 github.com/Anipaleja/nginx-defender 1

Filter by Repository

https://github.com/usememos/memos 50 https://github.com/kubernetes/kubernetes 39 https://github.com/mattermost/mattermost 36 https://github.com/grafana/grafana 26 https://github.com/argoproj/argo-cd 24 https://github.com/answerdev/answer 21 https://github.com/cilium/cilium 19 https://github.com/moby/moby 14 https://github.com/goharbor/harbor 13 https://github.com/go-gitea/gitea 13 https://github.com/openfga/openfga 13 https://github.com/hashicorp/consul 12 https://github.com/helm/helm 12 https://github.com/traefik/traefik 12 https://github.com/containerd/containerd 12 https://github.com/ethereum/go-ethereum 11 https://github.com/rancher/rancher 11 https://github.com/greenpau/caddy-security 10 https://github.com/openbao/openbao 8 https://github.com/hashicorp/nomad 8 https://github.com/gogs/gogs 8 https://github.com/kubeedge/kubeedge 8 https://github.com/containers/podman 7 https://github.com/hashicorp/vault 7 https://github.com/google/fscrypt 7 https://github.com/dragonflyoss/dragonfly 7 https://github.com/zitadel/zitadel 7 https://github.com/pomerium/pomerium 6 https://github.com/treeverse/lakeFS 6 https://github.com/1Panel-dev/1Panel 6 https://github.com/cri-o/cri-o 6 https://github.com/stacklok/minder 6 https://github.com/opencontainers/runc 6 https://github.com/cloudflare/cfrpki 5 https://github.com/CosmWasm/wasmvm 5 https://github.com/argoproj/argo-workflows 5 https://github.com/cosmos/cosmos-sdk 5 https://github.com/juju/juju 5 https://github.com/t2bot/matrix-media-repo 5 https://github.com/etcd-io/etcd 5 https://github.com/golang/go 4 https://github.com/drakkan/sftpgo 4 https://github.com/schollz/croc 4 https://github.com/vitessio/vitess 4 https://github.com/pion/dtls 4 https://github.com/gophish/gophish 4 https://github.com/kyverno/kyverno 4 https://github.com/cli/cli 4 https://github.com/lestrrat-go/jwx 4 https://github.com/containers/buildah 4 https://github.com/dhowden/tag 4 https://github.com/casdoor/casdoor 4 https://github.com/filebrowser/filebrowser 3 https://github.com/moby/buildkit 3 https://github.com/cubefs/cubefs 3 https://github.com/pterodactyl/wings 3 https://github.com/kubernetes/ingress-nginx 3 https://github.com/go-jose/go-jose 3 https://github.com/cortexproject/cortex 3 https://github.com/cometbft/cometbft 3 https://github.com/canonical/lxd 3 https://github.com/coredns/coredns 3 https://github.com/sigstore/cosign 3 https://github.com/apache/incubator-answer 3 https://github.com/imgproxy/imgproxy 3 https://github.com/beego/beego 3 https://github.com/Consensys/gnark 3 https://github.com/tendermint/tendermint 3 https://github.com/docker/docker 3 https://github.com/grafana/bugbounty 3 https://github.com/ipfs/go-ipfs 3 https://github.com/metal3-io/baremetal-operator 3 https://github.com/ollama/ollama 3 https://github.com/authzed/spicedb 3 https://github.com/oauth2-proxy/oauth2-proxy 3 https://github.com/aws/aws-sdk-go 3 https://github.com/osrg/gobgp 3 https://github.com/navidrome/navidrome 3 https://github.com/neuvector/neuvector 3 https://github.com/gotify/server 2 https://github.com/goreleaser/goreleaser 2 https://github.com/bep/imagemeta 2 https://github.com/kitabisa/teler-waf 2 https://github.com/go-viper/mapstructure 2 https://github.com/grafana/agent 2 https://github.com/mattermost/mattermost-plugin-channel-export 2 https://github.com/meshery/meshery 2 https://github.com/concourse/concourse 2 https://github.com/kubernetes-sigs/secrets-store-csi-driver 2 https://github.com/gin-gonic/gin 2 https://github.com/caddyserver/caddy 2 https://github.com/CosmWasm/wasmd 2 https://github.com/cli/go-gh 2 https://github.com/rs/cors 2 https://github.com/gofiber/fiber 2 https://github.com/codenotary/immudb 2 https://github.com/supranational/blst 2 https://github.com/quic-go/quic-go 2 https://github.com/snapcore/snapd 2 https://github.com/jaredallard/archives 2 https://github.com/temporalio/temporal 2 https://github.com/open-telemetry/opentelemetry-collector-contrib 2 https://github.com/ory/fosite 2 https://github.com/mholt/archiver 2 https://github.com/lf-edge/ekuiper 2 https://github.com/matrix-org/gomatrixserverlib 2 https://github.com/gohugoio/hugo 2 https://github.com/BishopFox/sliver 2 https://github.com/stripe/smokescreen 2 https://github.com/AlexxIT/go2rtc 2 https://github.com/phachon/mm-wiki 2 https://github.com/bytebase/bytebase 2 https://github.com/woodpecker-ci/woodpecker 2 https://github.com/dutchcoders/transfer.sh 2 https://github.com/zinclabs/zinc 2 https://github.com/fluid-cloudnative/fluid 2 https://github.com/dvsekhvalnov/jose2go 2 https://github.com/kubewarden/kubewarden-controller 2 https://github.com/moby/libnetwork 2 https://github.com/miniflux/v2 2 https://github.com/notaryproject/notation 2 https://github.com/evmos/evmos 2 https://github.com/Velocidex/velociraptor 2 https://github.com/gitpod-io/gitpod 2 https://github.com/dapr/dapr 2 https://github.com/minio/minio 2 https://github.com/ubuntu/authd 2 https://github.com/hashicorp/go-getter 2 https://github.com/project-zot/zot 2 https://github.com/open-policy-agent/opa 2 https://github.com/openshift/origin 2 https://github.com/gogits/gogs 2 https://github.com/IceWhaleTech/CasaOS-UserService 2 https://github.com/alist-org/alist 2 https://github.com/mattermost/mattermost-plugin-playbooks 2 https://github.com/hpcng/singularity 2 https://github.com/Forceu/Gokapi 2 https://github.com/arduino/arduino-create-agent 2 https://github.com/istio/istio 2 https://github.com/free5gc/free5gc 1 https://github.com/golang/crypto 1 https://github.com/cilium/hubble 1 https://github.com/mongodb/mongo-go-driver 1 https://github.com/Azure/azure-sdk-for-go 1 https://github.com/containers/image 1 https://github.com/turt2live/matrix-media-repo 1 https://github.com/projectdiscovery/nuclei 1 https://github.com/jackc/pgx 1 https://github.com/singularityware/singularity 1 https://github.com/grafana/grafana-zabbix 1 https://github.com/cloudevents/sdk-go 1 https://github.com/google/go-attestation 1 https://github.com/kitabisa/teler 1 https://github.com/aws/efs-utils 1 https://github.com/google/osv-scalibr 1 https://github.com/filecoin-project/go-f3 1 https://github.com/ory/hydra 1 https://github.com/revel/revel 1 https://github.com/crowdsecurity/cs-firewall-bouncer 1 https://github.com/yaowenxiao721/Poc 1 https://github.com/gomarkdown/markdown 1 https://github.com/mittwald/kube-httpcache 1 https://github.com/grafana/grafana-infinity-datasource 1 https://github.com/sylabs/scs-library-client 1 https://github.com/deis/workflow-manager 1 https://github.com/1Panel-dev/KubePi 1 https://github.com/filecoin-project/lotus 1 https://github.com/btcsuite/btcd 1 https://github.com/russellhaering/gosaml2 1 https://github.com/ossf/allstar 1 https://github.com/sourcegraph/sourcegraph 1 https://github.com/Anipaleja/nginx-defender 1 https://github.com/schollz/rwtxt 1 https://github.com/google/exposure-notifications-verification-server 1 https://github.com/windmill-labs/windmill 1 https://github.com/AndrewBurian/powermux 1 https://github.com/CA17/TeamsACS 1 https://github.com/hashicorp/terraform 1 https://github.com/AdguardTeam/AdGuardHome 1 https://github.com/siderolabs/talos 1 https://github.com/play-with-docker/play-with-docker 1 https://github.com/anchore/stereoscope 1 https://github.com/coreos/etcd 1 https://github.com/coder/agentapi 1 https://github.com/onosproject/onos-lib-go 1 https://github.com/xyproto/algernon 1 https://github.com/matrix-org/pinecone 1 https://github.com/github/gh-ost 1 https://github.com/ipld/go-car 1 https://github.com/temporalio/ui-server 1 https://github.com/documize/community 1 https://github.com/kubevela/kubevela 1 https://github.com/99designs/gqlgen 1 https://github.com/Xhofe/alist 1 https://github.com/go-macaron/i18n 1 https://github.com/ipld/go-ipld-prime 1 https://github.com/tiagorlampert/CHAOS 1 https://github.com/envoyproxy/gateway 1 https://github.com/sigstore/rekor 1