An open API service providing security vulnerability metadata for many open source software ecosystems.

go

go

1,967,706 packages · proxy.golang.org

Moderate
4 months ago

uptrace pgdriver SQL injection vulnerability GSA_kwCzR0hTQS1oNGg2LXZjY3ItNDRoMs4ABJAj

go github.com/uptrace/bun/driver/pgdriver
Low
4 months ago

Mattermost allows guest users to view information about public teams they are not members of GSA_kwCzR0hTQS1qd2h3LXhmNXYtcWd4Y84ABI-z

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago

Mattermost allows authenticated administrator to execute LDAP search filter injection GSA_kwCzR0hTQS00cjY3LTR4NHAtZnByZ84ABI-v

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
4 months ago

Mattermost fails to clear Google OAuth credentials GSA_kwCzR0hTQS04Y2d4LTljY2otM2d3cs4ABIhX

go github.com/mattermost/mattermost/server/v8
Critical
4 months ago

Argo CD allows cross-site scripting on repositories page GSA_kwCzR0hTQS0yaGo1LWc2NGctZnA2cM4ABIbo

go github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Low
4 months ago

Traefik allows path traversal using url encoding GSA_kwCzR0hTQS12cmNoLTg2OGctOWp4Nc4ABIbb

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
Moderate
4 months ago

ActiveMQ Artemis AMQ Broker Operator Starting Credentials Reuse GSA_kwCzR0hTQS1xNXE3LTh4NngtaGNnMs4ABIXI

go github.com/arkmq-org/activemq-artemis-operator
Moderate
4 months ago

OpenFGA Authorization Bypass GSA_kwCzR0hTQS1jNzJnLTUzaHctODJxN84ABIVQ

go github.com/openfga/openfga
Moderate
4 months ago

zot logs secrets GSA_kwCzR0hTQS1jMzd2LTNjOHctY3JxOM4ABIPq

go zotregistry.dev/zot
Moderate
4 months ago

Insufficient input sanitization in ejson2env GSA_kwCzR0hTQS0yYzQ3LW03NTctMzJnNs4ABIMs

go, rubygems github.com/Shopify/ejson2env, ejson2env, github.com/Shopify/ejson2env/v2
Critical
5 months ago

Gardener External DNS Management allows malicious google credential in DNS secret to lead to privilege escalation GSA_kwCzR0hTQS14d2dnLW03ZngtODN3eM4ABIG2

go github.com/gardener/gardener-extension-shoot-dns-service, github.com/gardener/external-dns-management
Moderate
5 months ago

SeaweedFS Vulnerable to SQL Injection GSA_kwCzR0hTQS1xOTdtLTg4NTMtcHE3Ns4ABH_X

go github.com/seaweedfs/seaweedfs
Moderate
5 months ago

Mattermost Fails to Validate Team Invite Permissions GSA_kwCzR0hTQS1yN3IyLW0zdnItYzhxY84ABH4U

go github.com/mattermost/mattermost/server/v8
Moderate
5 months ago

LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality GSA_kwCzR0hTQS05Y3d2LXB4Y3ItaGZqY84ABH2w

go github.com/lf-edge/ekuiper/v2, github.com/lf-edge/ekuiper
Moderate
5 months ago

Inspektor Gadget Security Policies Can be Bypassed GSA_kwCzR0hTQS1wdjIyLWZxY2otN3h3aM4ABHfN

go github.com/inspektor-gadget/inspektor-gadget
High
5 months ago

OPA server Data API HTTP path injection of Rego GSA_kwCzR0hTQS02bTh3LWpjODctNmNyN84ABHYV

go github.com/open-policy-agent/opa, github.com/open-policy-agent/opa/server, github.com/open-policy-agent/opa/v1/server
Moderate
5 months ago

OpenFGA Authorization Bypass GSA_kwCzR0hTQS13MjIyLW00NmMtbWdoNs4ABHSg

go github.com/openfga/openfga
Moderate
5 months ago

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions GSA_kwCzR0hTQS02ODljLXhxN3gteGp3Zs4ABHIK

go github.com/mattermost/mattermost-plugin-playbooks, github.com/mattermost/mattermost/server/v8
Low
5 months ago

Mattermost Playbooks fails to properly validate permissions GSA_kwCzR0hTQS1mcjIyLTUzNzctZjNwN84ABHIO

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-playbooks
Moderate
5 months ago

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type GSA_kwCzR0hTQS0zZzM2LWdmN2MtNzVxd84ABHIQ

go github.com/mattermost/mattermost-plugin-playbooks, github.com/mattermost/mattermost/server/v8
High
5 months ago

Traefik has a possible vulnerability with the path matchers GSA_kwCzR0hTQS02cDY4LXc0NWctNDhqN84ABHEL

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2, github.com/traefik/traefik
Moderate
5 months ago

GoBGP crashes in the flowspec parser GSA_kwCzR0hTQS1tZnZ2LW1nZjYtcTI1cs4ABHDt

go github.com/osrg/gobgp/v3, github.com/osrg/gobgp
Moderate
5 months ago

GoBGP does not verify that the input length GSA_kwCzR0hTQS1jNWpnLXdyNXYtMndwMs4ABHDv

go github.com/osrg/gobgp/v3, github.com/osrg/gobgp
High
5 months ago

GoBGP panics due to a zero value for softwareVersionLen GSA_kwCzR0hTQS03bTM1LXZ3MmMtNjk2ds4ABHDs

go github.com/osrg/gobgp/v3, github.com/osrg/gobgp
Moderate
5 months ago

GoBGP does not properly check the input length GSA_kwCzR0hTQS1ocWhxLWhwNXgteHAzd84ABHDu

go github.com/osrg/gobgp/v3, github.com/osrg/gobgp
Moderate
6 months ago

one-api Cross-site Scripting vulnerability GSA_kwCzR0hTQS13dmN4LWo2MnEtNDVxd84ABHDA

go github.com/songquanpeng/one-api
Critical
6 months ago

Traefik affected by Go HTTP Request Smuggling Vulnerability GSA_kwCzR0hTQS01NDIzLWpjam0tMmdwds4ABHCP

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Moderate
6 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1tajJwLXYyYzItdmg0ds4ABG5Q

go github.com/mattermost/mattermost/server/v8
Moderate
6 months ago

Mattermost vulnerable to Observable Timing Discrepancy GSA_kwCzR0hTQS0yajg3LXA2MjMtOGNjMs4ABG1v

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-msteams
Moderate
6 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1oNHJyLWYzN2otNGhoN84ABG1q

go github.com/mattermost/mattermost/server/v8
Low
6 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1qNjM5LW0zNjctNzVjZs4ABG1o

go github.com/mattermost/mattermost/server/v8

Filter by Severity

Filter by Package

github.com/mattermost/mattermost/server/v8 128 github.com/usememos/memos 68 github.com/grafana/grafana 56 github.com/hashicorp/vault 49 github.com/rancher/rancher 48 k8s.io/kubernetes 41 github.com/mattermost/mattermost-server 41 github.com/argoproj/argo-cd/v2 36 github.com/mattermost/mattermost-server/v6 36 github.com/answerdev/answer 34 gogs.io/gogs 32 github.com/cilium/cilium 31 github.com/hashicorp/nomad 31 github.com/argoproj/argo-cd 30 github.com/docker/docker 29 github.com/hashicorp/consul 29 github.com/traefik/traefik/v2 25 github.com/goharbor/harbor 21 github.com/ethereum/go-ethereum 21 helm.sh/helm/v3 20 code.gitea.io/gitea 20 github.com/zitadel/zitadel 19 golang.org/x/net 18 github.com/traefik/traefik/v3 17 github.com/openfga/openfga 17 github.com/containerd/containerd 15 github.com/nats-io/nats-server/v2 14 github.com/cri-o/cri-o 13 github.com/mattermost/mattermost-plugin-confluence 13 github.com/cosmos/cosmos-sdk 13 github.com/ollama/ollama 13 github.com/opencontainers/runc 13 k8s.io/ingress-nginx 12 github.com/traefik/traefik 12 github.com/1Panel-dev/1Panel 12 github.com/go-gitea/gitea 12 github.com/dragonflyoss/dragonfly 11 github.com/cloudflare/cfrpki 11 github.com/pomerium/pomerium 11 github.com/kyverno/kyverno 10 github.com/authzed/spicedb 10 github.com/beego/beego/v2 10 golang.org/x/crypto 10 github.com/greenpau/caddy-security 10 github.com/sylabs/singularity 9 github.com/juju/juju 9 github.com/containers/podman/v4 9 github.com/apache/incubator-answer 9 github.com/kubernetes/kubernetes 9 github.com/cometbft/cometbft 9 github.com/navidrome/navidrome 9 github.com/hashicorp/go-getter 9 github.com/filebrowser/filebrowser/v2 9 github.com/filebrowser/filebrowser 9 github.com/moby/moby 8 github.com/coredns/coredns 8 github.com/containers/buildah 8 github.com/consensys/gnark 8 github.com/kubeedge/kubeedge 8 istio.io/istio 8 github.com/pterodactyl/wings 8 github.com/treeverse/lakefs 8 github.com/beego/beego 8 go.etcd.io/etcd/v3 8 github.com/casdoor/casdoor 8 github.com/openbao/openbao 8 github.com/stacklok/minder 8 github.com/gofiber/fiber/v2 7 github.com/minio/minio 7 github.com/google/fscrypt 7 github.com/hyperledger/fabric 7 helm.sh/helm 6 github.com/fluxcd/flux2 6 github.com/gophish/gophish 6 github.com/argoproj/argo-cd/v3 6 github.com/apache/trafficcontrol 6 kubevirt.io/kubevirt 6 github.com/mattermost/mattermost-server/v5 6 github.com/argoproj/argo-workflows/v3 6 github.com/containers/podman/v5 6 github.com/gravitl/netmaker 6 github.com/cubefs/cubefs 6 github.com/open-policy-agent/opa 6 github.com/snapcore/snapd 5 github.com/alist-org/alist/v3 5 cosmwasm-vm 5 github.com/git-lfs/git-lfs 5 github.com/zitadel/zitadel/v2 5 github.com/ipfs/go-ipfs 5 github.com/CosmWasm/wasmvm/v2 5 github.com/russellhaering/goxmldsig 5 github.com/moby/buildkit 5 github.com/foxcpp/maddy 5 github.com/drakkan/sftpgo/v2 5 go.etcd.io/etcd 5 github.com/siyuan-note/siyuan/kernel 5 github.com/pion/dtls/v2 5 github.com/quic-go/quic-go 5 github.com/osrg/gobgp/v3 5 github.com/t2bot/matrix-media-repo 5 github.com/tendermint/tendermint 5 github.com/CosmWasm/wasmvm 5 github.com/CosmWasm/wasmd 5 github.com/0xJacky/Nginx-UI 5 github.com/sigstore/cosign 5 github.com/lf-edge/ekuiper 5 github.com/cheqd/cheqd-node 5 github.com/KubeOperator/kubepi 5 github.com/kiali/kiali 5 github.com/IBAX-io/go-ibax 5 github.com/owncast/owncast 5 github.com/lf-edge/ekuiper/v2 5 github.com/gin-gonic/gin 5 github.com/bnb-chain/tss-lib 5 github.com/containers/podman/v3 5 github.com/schollz/croc/v9 5 github.com/go-vela/server 4 github.com/chaos-mesh/chaos-mesh 4 github.com/cli/cli/v2 4 github.com/concourse/concourse 4 github.com/hashicorp/boundary 4 github.com/cosmos/ibc-go/v5 4 golang.org/x/image 4 github.com/evmos/evmos/v11 4 github.com/cortexproject/cortex 4 github.com/cosmos/ibc-go 4 golang.org/x/net/http2 4 github.com/karmada-io/karmada 4 github.com/cosmos/ibc-go/v3 4 github.com/evmos/evmos/v13 4 github.com/ory/fosite 4 github.com/notaryproject/notation-go 4 github.com/authelia/authelia/v4 4 github.com/coder/coder/v2 4 github.com/aws/aws-sdk-go 4 github.com/evmos/evmos/v6 4 github.com/evmos/evmos/v7 4 github.com/neuvector/neuvector 4 github.com/lestrrat-go/jwx/v2 4 github.com/cosmos/ibc-go/v7 4 github.com/free5gc/free5gc 4 github.com/nats-io/jwt 4 github.com/dexidp/dex 4 github.com/dhowden/tag 4 github.com/osrg/gobgp 4 github.com/tidwall/gjson 4 github.com/crossplane/crossplane 4 github.com/oauth2-proxy/oauth2-proxy 4 github.com/go-git/go-git/v5 4 github.com/binance-chain/tss-lib 4 github.com/crewjam/saml 4 github.com/IceWhaleTech/CasaOS-UserService 4 github.com/cosmos/ibc-go/v4 4 github.com/russellhaering/gosaml2 4 github.com/cosmos/ibc-go/v6 4 github.com/charmbracelet/soft-serve 4 github.com/arduino/arduino-create-agent 4 github.com/fluxcd/kustomize-controller 4 github.com/mholt/archiver 4 github.com/lestrrat-go/jwx 4 github.com/containers/podman 4 github.com/cosmos/ibc-go/v2 4 github.com/projectcalico/calico 4 github.com/lightningnetwork/lnd 4 github.com/edgelesssys/contrast 4 github.com/evmos/evmos/v16 4 github.com/layer5io/meshery 4 github.com/pion/dtls 4 github.com/crypto-org-chain/cronos 3 github.com/AlexxIT/go2rtc 3 github.com/notaryproject/notation 3 golang.org/x/text 3 github.com/tiagorlampert/CHAOS 3 github.com/evmos/evmos/v9 3 vitess.io/vitess 3 github.com/evmos/evmos/v14 3 github.com/plentico/plenti 3 gopkg.in/yaml.v2 3 github.com/syncthing/syncthing 3 github.com/libp2p/go-libp2p 3 github.com/go-jose/go-jose/v3 3 github.com/sigstore/cosign/v2 3 github.com/openshift/origin 3 github.com/go-skynet/LocalAI 3 github.com/evmos/evmos/v12 3 github.com/btcsuite/btcd 3 github.com/edgelesssys/marblerun 3 github.com/argoproj/argo-events 3 github.com/evmos/evmos/v10 3 github.com/clidey/whodb/core 3 github.com/evmos/evmos/v15 3 github.com/kcp-dev/kcp 3 goauthentik.io 3 github.com/gofiber/fiber 3 github.com/caddyserver/caddy 3 github.com/miekg/dns 3 github.com/openshift/console 3 github.com/mattermost/mattermost-plugin-playbooks 3 github.com/projectcapsule/capsule 3 github.com/apache/servicecomb-service-center 3

Filter by Repository

https://github.com/usememos/memos 68 https://github.com/kubernetes/kubernetes 65 https://github.com/argoproj/argo-cd 50 https://github.com/grafana/grafana 46 https://github.com/rancher/rancher 44 https://github.com/mattermost/mattermost 39 https://github.com/answerdev/answer 34 https://github.com/go-gitea/gitea 32 https://github.com/cilium/cilium 31 https://github.com/gogs/gogs 28 https://github.com/traefik/traefik 25 https://github.com/moby/moby 23 https://github.com/hashicorp/consul 22 https://github.com/zitadel/zitadel 22 https://github.com/helm/helm 22 https://github.com/goharbor/harbor 21 https://github.com/hashicorp/vault 19 https://github.com/ethereum/go-ethereum 17 https://github.com/openfga/openfga 17 https://github.com/containerd/containerd 17 https://github.com/hashicorp/nomad 16 https://github.com/etcd-io/etcd 16 https://github.com/golang/go 14 https://github.com/containers/podman 14 https://github.com/cosmos/cosmos-sdk 14 https://github.com/1Panel-dev/1Panel 13 https://github.com/opencontainers/runc 12 https://github.com/nats-io/nats-server 12 https://github.com/cloudflare/cfrpki 11 https://github.com/pomerium/pomerium 11 https://github.com/filebrowser/filebrowser 11 https://github.com/beego/beego 11 https://github.com/cri-o/cri-o 11 https://github.com/dragonflyoss/dragonfly 11 https://github.com/openbao/openbao 10 https://github.com/greenpau/caddy-security 10 https://github.com/authzed/spicedb 10 https://github.com/kyverno/kyverno 10 https://github.com/cometbft/cometbft 10 https://github.com/hashicorp/go-getter 9 https://github.com/juju/juju 9 https://github.com/gofiber/fiber 8 https://github.com/containers/buildah 8 https://github.com/pterodactyl/wings 8 https://github.com/docker/docker 8 https://github.com/stacklok/minder 8 https://github.com/treeverse/lakeFS 8 https://github.com/istio/istio 8 https://github.com/kubeedge/kubeedge 8 https://github.com/casdoor/casdoor 8 https://github.com/Consensys/gnark 8 https://github.com/navidrome/navidrome 8 https://github.com/evmos/evmos 7 https://github.com/argoproj/argo-workflows 7 https://github.com/hyperledger/fabric 7 https://github.com/kubernetes/ingress-nginx 7 https://github.com/google/fscrypt 7 https://github.com/hpcng/singularity 7 https://github.com/minio/minio 7 https://github.com/ollama/ollama 7 https://github.com/pion/dtls 6 https://github.com/fluxcd/flux2 6 https://github.com/open-policy-agent/opa 6 https://github.com/lf-edge/ekuiper 6 https://github.com/coredns/coredns 6 https://github.com/cubefs/cubefs 6 https://github.com/gravitl/netmaker 6 https://github.com/oauth2-proxy/oauth2-proxy 6 https://github.com/schollz/croc 6 https://github.com/drakkan/sftpgo 6 https://github.com/sigstore/cosign 6 https://github.com/moby/buildkit 6 https://github.com/cli/cli 5 https://github.com/quic-go/quic-go 5 https://github.com/CosmWasm/wasmvm 5 https://github.com/crewjam/saml 5 https://github.com/git-lfs/git-lfs 5 https://github.com/free5gc/free5gc 5 https://github.com/0xJacky/nginx-ui 5 https://github.com/ipfs/go-ipfs 5 https://github.com/tendermint/tendermint 5 https://github.com/t2bot/matrix-media-repo 5 https://github.com/foxcpp/maddy 5 https://github.com/CosmWasm/wasmd 5 https://github.com/cheqd/cheqd-node 5 https://github.com/IBAX-io/go-ibax 5 https://github.com/osrg/gobgp 5 https://github.com/gophish/gophish 5 https://github.com/siyuan-note/siyuan 5 https://github.com/woodpecker-ci/woodpecker 4 https://github.com/kubevirt/kubevirt 4 https://github.com/authelia/authelia 4 https://github.com/tidwall/gjson 4 https://github.com/containous/traefik 4 https://github.com/notaryproject/notation-go 4 https://github.com/projectdiscovery/nuclei 4 https://github.com/crossplane/crossplane 4 https://github.com/russellhaering/gosaml2 4 https://github.com/babylonlabs-io/babylon 4 https://github.com/grafana/bugbounty 4 https://github.com/arduino/arduino-create-agent 4 https://github.com/coder/coder 4 https://github.com/siderolabs/talos 4 https://github.com/go-git/go-git 4 https://github.com/gin-gonic/gin 4 https://github.com/edgelesssys/contrast 4 https://github.com/apache/trafficcontrol 4 https://github.com/cosmos/ibc-go 4 https://github.com/IceWhaleTech/CasaOS-UserService 4 https://github.com/ory/fosite 4 https://github.com/lestrrat-go/jwx 4 https://github.com/snapcore/snapd 4 https://github.com/charmbracelet/soft-serve 4 https://github.com/aws/aws-sdk-go 4 https://github.com/alist-org/alist 4 https://github.com/neuvector/neuvector 4 https://github.com/envoyproxy/envoy 4 https://github.com/go-vela/server 4 https://github.com/chaos-mesh/chaos-mesh 4 https://github.com/meshery/meshery 4 https://github.com/golang/crypto 4 https://github.com/dexidp/dex 4 https://github.com/owncast/owncast 4 https://github.com/vitessio/vitess 4 https://github.com/concourse/concourse 4 https://github.com/dhowden/tag 4 https://github.com/openshift/origin 3 https://github.com/weaveworks/weave-gitops 3 https://github.com/sylabs/singularity 3 https://github.com/tiagorlampert/CHAOS 3 https://github.com/kcp-dev/kcp 3 https://github.com/ctfer-io/chall-manager 3 https://github.com/libp2p/go-libp2p 3 https://github.com/plentico/plenti 3 https://github.com/caddyserver/caddy 3 https://github.com/moby/libnetwork 3 https://github.com/KubeOperator/KubePi 3 https://github.com/go-yaml/yaml 3 https://github.com/syncthing/syncthing 3 https://github.com/runatlantis/atlantis 3 https://github.com/open-telemetry/opentelemetry-go-contrib 3 https://github.com/go-jose/go-jose 3 https://github.com/pingcap/tidb 3 https://github.com/cortexproject/cortex 3 https://github.com/ory/oathkeeper 3 https://github.com/AlexxIT/go2rtc 3 https://github.com/dutchcoders/transfer.sh 3 https://github.com/u-root/u-root 3 https://github.com/clidey/whodb 3 https://github.com/mholt/archiver 3 https://github.com/edgelesssys/constellation 3 https://github.com/distribution/distribution 3 https://github.com/imgproxy/imgproxy 3 https://github.com/temporalio/temporal 3 https://github.com/flyteorg/flyteadmin 3 https://github.com/kubernetes-sigs/secrets-store-csi-driver 3 https://github.com/goauthentik/authentik 3 https://github.com/SpectoLabs/hoverfly 3 https://github.com/IoFinnet/tss-lib 3 https://github.com/theupdateframework/go-tuf 3 https://github.com/canonical/lxd 3 https://github.com/gogits/gogs 3 https://github.com/heketi/heketi 3 https://github.com/cloudflare/circl 3 https://github.com/nats-io/jwt 3 https://github.com/gohugoio/hugo 3 https://github.com/mudler/localai 3 https://github.com/project-zot/zot 3 https://github.com/flipped-aurora/gin-vue-admin 3 https://github.com/ulikunitz/xz 3 https://github.com/tailscale/tailscale 3 https://github.com/metal3-io/baremetal-operator 3 https://github.com/miniflux/v2 3 https://github.com/artifacthub/hub 3 https://github.com/lightningnetwork/lnd 3 https://github.com/ElrondNetwork/elrond-go 3 https://github.com/mattermost/mattermost-plugin-boards 3 https://github.com/karmada-io/karmada 3 https://github.com/phachon/mm-wiki 3 https://github.com/ipfs/boxo 3 https://github.com/apache/incubator-answer 3 https://github.com/edgelesssys/marblerun 3 https://github.com/BishopFox/sliver 3 https://github.com/ubuntu/authd 3 https://github.com/fleetdm/fleet 3 https://github.com/mattermost/mattermost-plugin-playbooks 3 https://github.com/kiali/kiali 3 https://github.com/argoproj/argo-events 3 https://github.com/square/go-jose 3 https://github.com/netlify/gotrue 2 https://github.com/hashicorp/terraform 2 https://github.com/opencontainers/distribution-spec 2 https://github.com/fkie-cad/yapscan 2 https://github.com/bitly/oauth2_proxy 2 https://github.com/lxc/incus 2 https://github.com/go-viper/mapstructure 2 https://github.com/containers/libpod 2 https://github.com/kitabisa/teler-waf 2 https://github.com/spiffe/spire 2