An open API service providing security vulnerability metadata for many open source software ecosystems.

go

go

1,993,475 packages · proxy.golang.org

Moderate
8 months ago

LF Edge eKuiper allows Stored XSS in Rules Functionality GSA_kwCzR0hTQS02aHJ3LXg3cHItNG1wOM4ABFPf

go github.com/lf-edge/ekuiper, github.com/lf-edge/ekuiper/v2
Moderate
9 months ago

DoS in go-jose Parsing GSA_kwCzR0hTQS1jNmd3LXczOTgtaHY3OM4ABEvX

go github.com/go-jose/go-jose, github.com/go-jose/go-jose/v3, github.com/go-jose/go-jose/v4
Moderate
9 months ago

SSRF in sliver teamserver GSA_kwCzR0hTQS1maDR2LXY3NzktNGcyd84ABEo5

go github.com/bishopfox/sliver
Moderate
9 months ago

OpenFGA Authorization Bypass GSA_kwCzR0hTQS1nNHY1LTZmNXAtbTM4as4ABEo4

go github.com/openfga/openfga
Moderate
9 months ago

Missing rate limit in MaysWind ezBookkeeping GSA_kwCzR0hTQS03NzJtLTc3M2ctcW1oY84ABEbF

go github.com/mayswind/ezbookkeeping
Moderate
9 months ago

Potential Denial-of-Service condition leading to temporary disability in IBC transfers to the native chain GSA_kwCzR0hTQS02ZmdtLXg2ZmYtdzc4Zs4ABEaJ

go github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v8, github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v7
Moderate
10 months ago

wasmvm: Malicious smart contract can slow down block production GSA_kwCzR0hTQS1teDJqLTdjbXYtMzUzY84ABEI_

go, cargo github.com/CosmWasm/wasmvm/v2, cosmwasm-vm
Moderate
10 months ago

wasmvm: Malicious smart contract can crash the chain GSA_kwCzR0hTQS0yM3FwLTNjMm0teHg2d84ABEI-

go github.com/CosmWasm/wasmvm/v2, github.com/CosmWasm/wasmvm
Moderate
10 months ago

Mattermost webapp crash via a crafted post GSA_kwCzR0hTQS13NnhoLWM4MnctaDk5N84ABDca

go github.com/mattermost/mattermost/server/v8
Moderate
10 months ago

Mattermost fails to properly validate post props GSA_kwCzR0hTQS00NXY5LXc5ZmgtMzNqNs4ABDao

go github.com/mattermost/mattermost/server/v8
Moderate
10 months ago

Mattermost fails to properly validate post props GSA_kwCzR0hTQS01bTdqLTZnYzQtZmY1Z84ABDah

go github.com/mattermost/mattermost/server/v8
Moderate
10 months ago

Mattermost Incorrect Type Conversion or Cast GSA_kwCzR0hTQS04ajNxLWdjOXgtNzk3Ms4ABDZg

go github.com/mattermost/mattermost/server/v8
Moderate
10 months ago

OpenFGA Authorization Bypass GSA_kwCzR0hTQS0zMnE2LXJyOTgtY2pxds4ABDO8

go github.com/openfga/openfga
Moderate
10 months ago

Soft Serve vulnerable to path traversal attacks GSA_kwCzR0hTQS1qNGp3LW02eHItZnY2Y84ABDGD

go github.com/charmbracelet/soft-serve
Moderate
11 months ago

Traefik affected by CVE-2024-53259 GSA_kwCzR0hTQS1oeHI2LTJwMjQtaGY5OM4ABChW

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Moderate
11 months ago

Mattermost Data Amplification vulnerability GSA_kwCzR0hTQS12NjQ3LWg4amotZnc1cs4ABCdp

go github.com/mattermost/mattermost/server/v8
Moderate
11 months ago

Mattermost Race Condition vulnerability GSA_kwCzR0hTQS04MjZoLXA0YzMtNDc3cM4ABCdm

go github.com/mattermost/mattermost/server/v8
Moderate
11 months ago

SiYuan has an SSTI via /api/template/renderSprig GSA_kwCzR0hTQS00cGpjLXB3Z3EtcTlqcM4ABCSY

go github.com/siyuan-note/siyuan/kernel
Moderate
11 months ago

CosmWasm VM Incorrect metering GSA_kwCzR0hTQS0ycTk3LW01cmMtcDNncM4ABCOg

cargo, go cosmwasm-vm, github.com/CosmWasm/wasmvm, github.com/CosmWasm/wasmvm/v2
Moderate
11 months ago

Panic in wasmvm can slow down block production GSA_kwCzR0hTQS12bXFoLTUyMzItdjQzcs4ABCOf

cargo, go cosmwasm-vm, github.com/CosmWasm/wasmvm, github.com/CosmWasm/wasmvm/v2
Moderate
12 months ago

Traefik's X-Forwarded-Prefix Header still allows for Open Redirect GSA_kwCzR0hTQS1oOTI0LThnNjUtajl3Z84ABB_B

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Moderate
about 1 year ago

Safearchive Path Traversal vulnerability GSA_kwCzR0hTQS1xM3JwLXZ2bTctajhqZ84ABA7y

go github.com/google/safearchive
Moderate
about 1 year ago

Mattermost Server allows user to get private channel names GSA_kwCzR0hTQS02bXZwLWdoNzctN3Z3aM4ABAwn

go github.com/mattermost/mattermost/server/v8
Moderate
about 1 year ago

Infinite loop in github.com/gomarkdown/markdown GSA_kwCzR0hTQS14aHIzLXdmN2otaDI1Nc4ABATH

go github.com/gomarkdown/markdown

Filter by Severity

Filter by Package

github.com/mattermost/mattermost/server/v8 89 github.com/usememos/memos 50 github.com/mattermost/mattermost-server 50 github.com/grafana/grafana 31 github.com/mattermost/mattermost-server/v6 30 k8s.io/kubernetes 24 github.com/answerdev/answer 21 github.com/hashicorp/vault 21 github.com/cilium/cilium 19 github.com/argoproj/argo-cd/v2 17 github.com/hashicorp/consul 16 github.com/docker/docker 16 github.com/hashicorp/nomad 15 github.com/openfga/openfga 13 github.com/goharbor/harbor 13 helm.sh/helm/v3 12 github.com/containerd/containerd 12 github.com/rancher/rancher 11 github.com/ethereum/go-ethereum 11 github.com/traefik/traefik/v2 11 github.com/argoproj/argo-cd 10 github.com/greenpau/caddy-security 10 gogs.io/gogs 9 code.gitea.io/gitea 9 kubevirt.io/kubevirt 9 github.com/mattermost/mattermost-plugin-confluence 8 github.com/traefik/traefik/v3 8 github.com/kubeedge/kubeedge 8 github.com/cri-o/cri-o 8 github.com/zitadel/zitadel 7 github.com/google/fscrypt 7 github.com/mattermost/mattermost-server/v5 7 github.com/openbao/openbao 7 github.com/dragonflyoss/dragonfly 7 github.com/treeverse/lakefs 7 github.com/pomerium/pomerium 6 github.com/1Panel-dev/1Panel 6 github.com/stacklok/minder 6 github.com/traefik/traefik 6 github.com/kubernetes/kubernetes 6 github.com/apache/incubator-answer 6 github.com/moby/moby 6 github.com/opencontainers/runc 6 github.com/CosmWasm/wasmvm 5 github.com/cloudflare/cfrpki 5 github.com/cosmos/cosmos-sdk 5 github.com/CosmWasm/wasmvm/v2 5 cosmwasm-vm 5 github.com/t2bot/matrix-media-repo 5 github.com/juju/juju 5 github.com/containers/podman/v4 5 github.com/coredns/coredns 5 golang.org/x/net 5 k8s.io/ingress-nginx 4 github.com/go-gitea/gitea 4 github.com/argoproj/argo-workflows/v3 4 github.com/dhowden/tag 4 github.com/lestrrat-go/jwx 4 github.com/navidrome/navidrome 4 github.com/gophish/gophish 4 github.com/casdoor/casdoor 4 github.com/containers/buildah 4 github.com/lestrrat-go/jwx/v2 4 github.com/pion/dtls/v2 4 github.com/kyverno/kyverno 4 k8s.io/client-go 3 github.com/drakkan/sftpgo/v2 3 github.com/pterodactyl/wings 3 github.com/authzed/spicedb 3 github.com/ollama/ollama 3 github.com/consensys/gnark 3 github.com/snapcore/snapd 3 github.com/containerd/containerd/v2 3 github.com/cubefs/cubefs 3 github.com/aws/aws-sdk-go 3 golang.org/x/image 3 github.com/ipfs/go-ipfs 3 github.com/neuvector/neuvector 3 github.com/cometbft/cometbft 3 github.com/cli/cli/v2 3 github.com/canonical/lxd 3 github.com/schollz/croc/v9 3 github.com/cortexproject/cortex 3 github.com/mholt/archiver 3 github.com/tendermint/tendermint 3 github.com/filebrowser/filebrowser/v2 3 github.com/notaryproject/notation 3 github.com/openshift/console 3 vitess.io/vitess 3 github.com/osrg/gobgp 3 github.com/containers/podman/v3 3 github.com/go-jose/go-jose/v3 3 github.com/filebrowser/filebrowser 3 github.com/osrg/gobgp/v3 3 github.com/containers/podman/v2 3 github.com/sigstore/cosign 3 github.com/goreleaser/goreleaser 2 github.com/kitabisa/teler-waf 2 github.com/bytebase/bytebase 2 github.com/minio/minio 2 github.com/beego/beego/v2 2 zotregistry.dev/zot 2 github.com/kiali/kiali 2 go.etcd.io/etcd/v3 2 github.com/openshift/origin 2 github.com/quic-go/quic-go 2 github.com/gin-gonic/gin 2 github.com/stripe/smokescreen 2 golang.org/x/crypto 2 github.com/bep/imagemeta 2 github.com/dutchcoders/transfer.sh 2 github.com/kgateway-dev/kgateway/v2 2 github.com/mattermost/mattermost-plugin-playbooks 2 github.com/gotify/server 2 github.com/sigstore/cosign/v2 2 github.com/edgexfoundry/app-functions-sdk-go/v2 2 github.com/charmbracelet/soft-serve 2 github.com/caddyserver/caddy/v2 2 github.com/alist-org/alist/v3 2 gopkg.in/yaml.v2 2 github.com/imgproxy/imgproxy/v3 2 github.com/hashicorp/boundary 2 github.com/containers/podman 2 github.com/IceWhaleTech/CasaOS-UserService 2 github.com/jaegertracing/jaeger 2 github.com/CosmWasm/wasmd 2 github.com/kuadrant/authorino 2 github.com/owncast/owncast 2 github.com/go-jose/go-jose/v4 2 github.com/AlexxIT/go2rtc 2 github.com/gitpod-io/gitpod 2 istio.io/istio 2 sigs.k8s.io/secrets-store-csi-driver 2 github.com/gohugoio/hugo 2 github.com/layer5io/meshery 2 github.com/gofiber/fiber 2 github.com/open-policy-agent/opa 2 github.com/supranational/blst 2 golang.org/x/net/http2 2 github.com/fluxcd/source-controller 2 github.com/containers/podman/v5 2 github.com/go-viper/mapstructure/v2 2 github.com/evmos/evmos/v13 2 github.com/cli/cli 2 github.com/hpcng/singularity 2 github.com/hashicorp/go-getter 2 github.com/bishopfox/sliver 2 github.com/zinclabs/zinc 2 github.com/concourse/concourse 2 github.com/forceu/gokapi 2 github.com/kubewarden/kubewarden-controller 2 github.com/zincsearch/zincsearch 2 github.com/dvsekhvalnov/jose2go 2 github.com/ory/fosite 2 www.velocidex.com/golang/velociraptor 2 github.com/ubuntu/authd 2 github.com/arduino/arduino-create-agent 2 github.com/gorilla/csrf 2 github.com/phachon/mm-wiki 2 github.com/codenotary/immudb 2 github.com/fluid-cloudnative/fluid 2 miniflux.app/v2 2 github.com/pion/dtls 2 github.com/lf-edge/ekuiper 2 github.com/moby/buildkit 2 github.com/cli/go-gh/v2 2 github.com/projectcalico/calico 2 go.etcd.io/etcd 2 github.com/lf-edge/ekuiper/v2 2 github.com/oauth2-proxy/oauth2-proxy 2 github.com/grafana/agent 2 github.com/beego/beego 2 github.com/apache/trafficcontrol 2 github.com/metal3-io/baremetal-operator 2 github.com/pydio/cells 2 github.com/dapr/dapr 2 github.com/nyaruka/phonenumbers 1 github.com/russellhaering/gosaml2 1 github.com/codeclysm/extract/v3 1 github.com/anchore/stereoscope 1 github.com/kro-run/kro 1 github.com/cosmos/ibc-go/v4 1 github.com/openshift/openshift-controller-manager 1 github.com/operator-framework/operator-sdk 1 google.golang.org/protobuf 1 github.com/temporalio/temporal 1 github.com/argoproj/argo-cd/v2/server 1 github.com/ory/hydra 1 ktbs.dev/teler 1 github.com/zitadel/zitadel-go/v3 1 github.com/containous/traefik/api 1 github.com/rancher/fleet 1 github.com/devfile/registry-support/registry-library 1 github.com/containous/traefik 1 github.com/cloudflare/circl 1 github.com/deis/workflow-manager 1 github.com/ovn-org/ovn-kubernetes 1 github.com/go-pg/pg/v9 1 github.com/mattermost/mattermost-plugin-jira 1 github.com/astaxie/beego 1

Filter by Repository

https://github.com/usememos/memos 50 https://github.com/kubernetes/kubernetes 39 https://github.com/mattermost/mattermost 36 https://github.com/grafana/grafana 26 https://github.com/argoproj/argo-cd 24 https://github.com/answerdev/answer 21 https://github.com/cilium/cilium 19 https://github.com/moby/moby 14 https://github.com/go-gitea/gitea 13 https://github.com/openfga/openfga 13 https://github.com/goharbor/harbor 13 https://github.com/containerd/containerd 13 https://github.com/traefik/traefik 12 https://github.com/helm/helm 12 https://github.com/hashicorp/consul 12 https://github.com/rancher/rancher 11 https://github.com/ethereum/go-ethereum 11 https://github.com/greenpau/caddy-security 10 https://github.com/hashicorp/nomad 8 https://github.com/kubeedge/kubeedge 8 https://github.com/openbao/openbao 8 https://github.com/gogs/gogs 8 https://github.com/dragonflyoss/dragonfly 7 https://github.com/treeverse/lakeFS 7 https://github.com/zitadel/zitadel 7 https://github.com/hashicorp/vault 7 https://github.com/containers/podman 7 https://github.com/google/fscrypt 7 https://github.com/kubevirt/kubevirt 7 https://github.com/stacklok/minder 6 https://github.com/pomerium/pomerium 6 https://github.com/cri-o/cri-o 6 https://github.com/1Panel-dev/1Panel 6 https://github.com/opencontainers/runc 6 https://github.com/cloudflare/cfrpki 5 https://github.com/etcd-io/etcd 5 https://github.com/t2bot/matrix-media-repo 5 https://github.com/CosmWasm/wasmvm 5 https://github.com/cosmos/cosmos-sdk 5 https://github.com/argoproj/argo-workflows 5 https://github.com/juju/juju 5 https://github.com/casdoor/casdoor 4 https://github.com/lestrrat-go/jwx 4 https://github.com/dhowden/tag 4 https://github.com/vitessio/vitess 4 https://github.com/containers/buildah 4 https://github.com/golang/go 4 https://github.com/drakkan/sftpgo 4 https://github.com/pion/dtls 4 https://github.com/gophish/gophish 4 https://github.com/schollz/croc 4 https://github.com/cli/cli 4 https://github.com/kyverno/kyverno 4 https://github.com/go-jose/go-jose 3 https://github.com/cortexproject/cortex 3 https://github.com/sigstore/cosign 3 https://github.com/moby/buildkit 3 https://github.com/canonical/lxd 3 https://github.com/cubefs/cubefs 3 https://github.com/cometbft/cometbft 3 https://github.com/grafana/bugbounty 3 https://github.com/docker/docker 3 https://github.com/beego/beego 3 https://github.com/ollama/ollama 3 https://github.com/Consensys/gnark 3 https://github.com/authzed/spicedb 3 https://github.com/neuvector/neuvector 3 https://github.com/metal3-io/baremetal-operator 3 https://github.com/pterodactyl/wings 3 https://github.com/filebrowser/filebrowser 3 https://github.com/aws/aws-sdk-go 3 https://github.com/kubernetes/ingress-nginx 3 https://github.com/oauth2-proxy/oauth2-proxy 3 https://github.com/tendermint/tendermint 3 https://github.com/osrg/gobgp 3 https://github.com/navidrome/navidrome 3 https://github.com/coredns/coredns 3 https://github.com/imgproxy/imgproxy 3 https://github.com/ipfs/go-ipfs 3 https://github.com/apache/incubator-answer 3 https://github.com/mholt/archiver 2 https://github.com/jaredallard/archives 2 https://github.com/open-telemetry/opentelemetry-collector-contrib 2 https://github.com/lf-edge/ekuiper 2 https://github.com/gohugoio/hugo 2 https://github.com/gin-gonic/gin 2 https://github.com/CosmWasm/wasmd 2 https://github.com/zinclabs/zinc 2 https://github.com/dapr/dapr 2 https://github.com/gitpod-io/gitpod 2 https://github.com/evmos/evmos 2 https://github.com/moby/libnetwork 2 https://github.com/hashicorp/go-getter 2 https://github.com/notaryproject/notation 2 https://github.com/stripe/smokescreen 2 https://github.com/supranational/blst 2 https://github.com/dvsekhvalnov/jose2go 2 https://github.com/snapcore/snapd 2 https://github.com/ubuntu/authd 2 https://github.com/mattermost/mattermost-plugin-channel-export 2 https://github.com/mattermost/mattermost-plugin-playbooks 2 https://github.com/meshery/meshery 2 https://github.com/open-policy-agent/opa 2 https://github.com/cli/go-gh 2 https://github.com/AlexxIT/go2rtc 2 https://github.com/bytebase/bytebase 2 https://github.com/kgateway-dev/kgateway 2 https://github.com/gofiber/fiber 2 https://github.com/concourse/concourse 2 https://github.com/woodpecker-ci/woodpecker 2 https://github.com/rs/cors 2 https://github.com/temporalio/temporal 2 https://github.com/fluid-cloudnative/fluid 2 https://github.com/kubewarden/kubewarden-controller 2 https://github.com/arduino/arduino-create-agent 2 https://github.com/gotify/server 2 https://github.com/go-viper/mapstructure 2 https://github.com/goreleaser/goreleaser 2 https://github.com/bep/imagemeta 2 https://github.com/istio/istio 2 https://github.com/dutchcoders/transfer.sh 2 https://github.com/project-zot/zot 2 https://github.com/codenotary/immudb 2 https://github.com/BishopFox/sliver 2 https://github.com/quic-go/quic-go 2 https://github.com/caddyserver/caddy 2 https://github.com/hpcng/singularity 2 https://github.com/openshift/origin 2 https://github.com/ory/fosite 2 https://github.com/gogits/gogs 2 https://github.com/miniflux/v2 2 https://github.com/Forceu/Gokapi 2 https://github.com/grafana/agent 2 https://github.com/kitabisa/teler-waf 2 https://github.com/Velocidex/velociraptor 2 https://github.com/charmbracelet/soft-serve 2 https://github.com/IceWhaleTech/CasaOS-UserService 2 https://github.com/matrix-org/gomatrixserverlib 2 https://github.com/kubernetes-sigs/secrets-store-csi-driver 2 https://github.com/minio/minio 2 https://github.com/alist-org/alist 2 https://github.com/phachon/mm-wiki 2 https://github.com/knative/serving 1 https://github.com/ipfs/go-unixfs 1 https://github.com/pion/webrtc 1 https://github.com/shift72/caddy-geo-ip 1 https://github.com/appleboy/gorush 1 https://github.com/artifacthub/hub 1 https://github.com/hyperledger/fabric 1 https://github.com/influxdata/influxdb 1 https://github.com/justinas/nosurf 1 https://github.com/containers/libpod 1 https://github.com/astaxie/beego 1 https://github.com/go-sonic/sonic 1 https://github.com/refraction-networking/utls 1 https://github.com/codeclysm/extract 1 https://github.com/aws/amazon-ecs-agent 1 https://github.com/crossplane/crossplane 1 https://github.com/jaegertracing/jaeger 1 https://github.com/github/git-sizer 1 https://github.com/fortio/proxy 1 https://github.com/SimonWaldherr/zplgfa 1 https://github.com/netlify/gotrue 1 https://github.com/openshift/osin 1 https://github.com/jumpserver/jumpserver 1 https://github.com/kubernetes-csi/external-snapshotter 1 https://github.com/submariner-io/submariner-operator 1 https://github.com/bitly/oauth2_proxy 1 https://github.com/protocolbuffers/protobuf-go 1 https://github.com/ouqiang/gocron 1 https://github.com/fluxcd/source-controller 1 https://github.com/heketi/heketi 1 https://github.com/appc/docker2aci 1 https://github.com/aquasecurity/trivy 1 https://github.com/jessfraz/pastebinit 1 https://github.com/f1veT/BUG 1 https://github.com/russellhaering/goxmldsig 1 https://github.com/crossplane/crossplane-runtime 1 https://github.com/containers/storage 1 https://github.com/CosmWasm/advisories 1 https://github.com/projectcapsule/capsule-proxy 1 https://github.com/cloudflare/circl 1 https://github.com/go-yaml/yaml 1 https://github.com/csaf-poc/csaf_distribution 1 https://github.com/anchore/syft 1 https://github.com/minio/console 1 https://github.com/authelia/authelia 1 https://github.com/Consensys/gnark-crypto 1 https://github.com/fleetdm/fleet 1 https://github.com/github/hub 1 https://github.com/corazawaf/coraza 1 https://github.com/traPtitech/traQ 1 https://github.com/containers/image 1 https://github.com/projectdiscovery/nuclei 1 https://github.com/mongodb/mongo-go-driver 1 https://github.com/Xhofe/alist 1 https://github.com/go-macaron/i18n 1 https://github.com/sigstore/rekor 1 https://github.com/ecnepsnai/web 1