An open API service providing security vulnerability metadata for many open source software ecosystems.

go

go

1,969,065 packages · proxy.golang.org

Critical
8 days ago

Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning GSA_kwCzR0hTQS0yMjd4LTdtaDgtM2NmNs4ABMpW

go github.com/gardener/gardener-extension-provider-openstack, github.com/gardener/gardener-extension-provider-azure, github.com/gardener/gardener-extension-provider-gcp, github.com/gardener/gardener-extension-provider-aws
Critical
29 days ago

Argo CD's Project API Token Exposes Repository Credentials GSA_kwCzR0hTQS03ODZxLTloY2ctdjlmZs4ABLqo

go github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2
Critical
about 2 months ago

HydrAIDE Authentication Bypass Vulnerability GSA_kwCzR0hTQS1xcDdqLXg3MjUtZzY3Zs4ABLM0

go github.com/hydraide/hydraide
Critical
3 months ago

NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path GSA_kwCzR0hTQS12bWczLTd2NDMtOWcyM84ABKQS

go github.com/NVIDIA/mig-parted, github.com/NVIDIA/gpu-operator, github.com/NVIDIA/k8s-device-plugin, github.com/NVIDIA/nvidia-container-toolkit
Critical
4 months ago

Mattermost allows authenticated users to write files to arbitrary locations GSA_kwCzR0hTQS1xaDU4LTl2M2otd2NqY84ABJSQ

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Critical
4 months ago

Teleport allows remote authentication bypass GSA_kwCzR0hTQS04Y3F2LXBqN2YtcHdwY84ABJEa

go github.com/gravitational/teleport
Critical
4 months ago

Argo CD allows cross-site scripting on repositories page GSA_kwCzR0hTQS0yaGo1LWc2NGctZnA2cM4ABIbo

go github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Critical
5 months ago

Gardener External DNS Management allows malicious google credential in DNS secret to lead to privilege escalation GSA_kwCzR0hTQS14d2dnLW03ZngtODN3eM4ABIG2

go github.com/gardener/gardener-extension-shoot-dns-service, github.com/gardener/external-dns-management
Critical
6 months ago

Traefik affected by Go HTTP Request Smuggling Vulnerability GSA_kwCzR0hTQS01NDIzLWpjam0tMmdwds4ABHCP

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Critical
7 months ago

IBC-Go: Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt GSA_kwCzR0hTQS00d2YzLTVxajktMzY4ds4ABFZ8

go github.com/cosmos/ibc-go/v7, github.com/cosmos/ibc-go/v6, github.com/cosmos/ibc-go/v5, github.com/cosmos/ibc-go/v4, github.com/cosmos/ibc-go/v3, github.com/cosmos/ibc-go/v2, github.com/cosmos/ibc-go/v8, github.com/cosmos/ibc-go
Critical
7 months ago

IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement GSA_kwCzR0hTQS1qZzZmLTQ4ZmYtNXhyd84ABE50

go github.com/cosmos/ibc-go/v8, github.com/cosmos/ibc-go/v7, github.com/cosmos/ibc-go/v6, github.com/cosmos/ibc-go/v5, github.com/cosmos/ibc-go/v4, github.com/cosmos/ibc-go/v3, github.com/cosmos/ibc-go/v2, github.com/cosmos/ibc-go
Critical
7 months ago

Mattermost allows reading arbitrary files GSA_kwCzR0hTQS12NDY5LTd3cDYtN2N2cM4ABEuB

go github.com/mattermost/mattermost/server/v8
Critical
9 months ago

go-git has an Argument Injection via the URL field GSA_kwCzR0hTQS12NzI1LTk1NDYtN3E3bc4ABC-k

go github.com/go-git/go-git/v5, gopkg.in/src-d/go-git.v4
Critical
about 1 year ago

HTTP client can manipulate custom HTTP headers that are added by Traefik GSA_kwCzR0hTQS02MmM4LW1oNTMtNGNxds4AA_sN

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
Critical
about 1 year ago

Grafana plugin SDK Information Leakage GSA_kwCzR0hTQS14eHh3LTNqNmgtcTdoNs4AA_sL

go github.com/grafana/grafana-plugin-sdk-go
Critical
about 1 year ago

Chaosblade vulnerable to OS command execution GSA_kwCzR0hTQS03MjNoLXgzN2ctZjhxbc4AA_rL

go github.com/chaosblade-io/chaosblade
Critical
about 1 year ago

CasaOS Command Injection vulnerability GSA_kwCzR0hTQS05MnZjLTRmY3ctZzY4cc4AA-ZD

go github.com/IceWhaleTech/CasaOS
Critical
about 1 year ago

rudder-server is vulnerable to SQL injection GSA_kwCzR0hTQS0zam1tLWY2amotcmNjM84AA-ZC

go github.com/rudderlabs/rudder-server
Critical
about 1 year ago

Authz zero length regression GSA_kwCzR0hTQS12MjN2LTZqdzItOThmcc4AA-Q4

go github.com/docker/docker
Critical
about 1 year ago

Volcano has insecure permissions GSA_kwCzR0hTQS01ZzN4LThnMnYtcjh4OM4AA-HK

go github.com/volcano-sh/volcano
Critical
about 1 year ago

fabedge has insecure permissions GSA_kwCzR0hTQS1jOWNtLTVqODItbTZwas4AA-HP

go github.com/fabedge/fabedge
Critical
over 1 year ago

Missing key verification in gost GSA_kwCzR0hTQS04d3h4LTM1cWMtdnA2cs4AA9f9

go github.com/ginuerzh/gost
Critical
over 1 year ago

Session Middleware Token Injection Vulnerability GSA_kwCzR0hTQS05OGoyLTNqM3AtZncyds4AA9cs

go github.com/gofiber/fiber/v2/middleware/session, github.com/gofiber/fiber/v2, github.com/gofiber/fiber
Critical
over 1 year ago

ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache GSA_kwCzR0hTQS05NzY2LTUyNzctajVocs4AA8aY

go github.com/argoproj/argo-cd, github.com/argoproj/argo-cd/v2
Critical
over 1 year ago

Improper Access Control in Gitea GSA_kwCzR0hTQS1yN2g3LWNoaDQtNXJ2bc4AA7Sn

go github.com/go-gitea/gitea
Critical
over 1 year ago

Evmos transaction execution not accounting for all state transition after interaction with precompiles GSA_kwCzR0hTQS0zZnA1LTJ4d2gtZnhtNs4AA657

go github.com/tharsis/evmos/v5, github.com/tharsis/evmos/v4, github.com/tharsis/evmos/v3, github.com/tharsis/evmos/v2, github.com/tharsis/evmos, github.com/evmos/evmos/v5, github.com/evmos/evmos/v6, github.com/evmos/evmos/v7, github.com/evmos/evmos/v16
Critical
over 1 year ago

LocalAI Command Injection in audioToWav GSA_kwCzR0hTQS13eDQzLWc1NWctMmpmNM4AA64K

go github.com/go-skynet/LocalAI
Critical
over 1 year ago

ibc-go: Potential Reentrancy using Timeout Callbacks in ibc-hooks GSA_kwCzR0hTQS1qNDk2LWNyZ2gtMzRteM4AA6qW

go github.com/cosmos/ibc-go, github.com/cosmos/ibc-go/v2, github.com/cosmos/ibc-go/v3, github.com/cosmos/ibc-go/v8, github.com/cosmos/ibc-go/v7, github.com/cosmos/ibc-go/v6, github.com/cosmos/ibc-go/v5, github.com/cosmos/ibc-go/v4

Filter by Severity

Filter by Package

gogs.io/gogs 11 github.com/argoproj/argo-cd/v2 8 github.com/rancher/rancher 7 github.com/argoproj/argo-cd 7 github.com/answerdev/answer 6 github.com/hashicorp/vault 6 github.com/grafana/grafana 5 code.gitea.io/gitea 5 github.com/mattermost/mattermost/server/v8 5 github.com/usememos/memos 4 github.com/cosmos/ibc-go/v5 3 github.com/pterodactyl/wings 3 github.com/go-gitea/gitea 3 github.com/cosmos/ibc-go 3 github.com/cosmos/ibc-go/v8 3 github.com/beego/beego/v2 3 github.com/cosmos/ibc-go/v2 3 github.com/cosmos/ibc-go/v7 3 github.com/hashicorp/nomad 3 github.com/cosmos/ibc-go/v6 3 github.com/bnb-chain/tss-lib 3 github.com/gofiber/fiber/v2 3 github.com/cosmos/ibc-go/v4 3 github.com/IceWhaleTech/CasaOS 3 github.com/cosmos/ibc-go/v3 3 github.com/beego/beego 3 github.com/chaos-mesh/chaos-mesh 3 github.com/dexidp/dex 3 github.com/go-git/go-git/v5 2 helm.sh/helm 2 github.com/nats-io/nats-server/v2 2 github.com/apache/trafficcontrol 2 github.com/russellhaering/gosaml2 2 github.com/crewjam/saml 2 github.com/NVIDIA/nvidia-container-toolkit 2 github.com/moby/buildkit 2 github.com/docker/docker 2 github.com/hashicorp/go-getter 2 github.com/git-lfs/git-lfs 2 github.com/traefik/traefik/v2 2 github.com/neuvector/neuvector 2 github.com/fluxcd/kustomize-controller 2 github.com/KubeOperator/kubepi 2 github.com/gardener/gardener 2 github.com/fluxcd/flux2 2 github.com/argoproj/argo-cd/v3 2 github.com/russellhaering/goxmldsig 2 github.com/traefik/traefik/v3 2 github.com/cheqd/cheqd-node 2 github.com/ElrondNetwork/elrond-go 1 github.com/ginuerzh/gost 1 github.com/gofiber/fiber/v2/middleware/session 1 github.com/gardener/gardener-extension-shoot-dns-service 1 github.com/NVIDIA/k8s-device-plugin 1 github.com/influxdata/influxdb 1 github.com/caddyserver/caddy 1 github.com/flipped-aurora/gin-vue-admin/server 1 github.com/tharsis/evmos/v2 1 github.com/argoproj/argo-events 1 github.com/netlify/gotrue 1 github.com/hashicorp/vault-plugin-secrets-gcp 1 github.com/gofiber/template/django/v3 1 kubevirt.io/kubevirt 1 github.com/fluxcd/helm-controller 1 github.com/projectdiscovery/interactsh 1 github.com/volcano-sh/volcano 1 github.com/git-lfs/git-lfs/v3 1 github.com/gardener/external-dns-management 1 mosn.io/mosn 1 github.com/zitadel/zitadel 1 github.com/fleetdm/fleet/v4 1 code.cloudfoundry.org/archiver 1 github.com/authelia/authelia/v4 1 github.com/evmos/evmos/v16 1 github.com/satori/go.uuid 1 github.com/txthinking/brook 1 github.com/zitadel/zitadel/v2 1 github.com/labstack/echo/v4 1 github.com/evmos/evmos/v7 1 k8s.io/ingress-nginx 1 github.com/kubernetes/kubernetes 1 github.com/gorilla/handlers 1 github.com/cloudflare/golz4 1 go.etcd.io/etcd/v3 1 github.com/hydraide/hydraide 1 github.com/openshift/origin 1 github.com/yi-ge/unzip 1 github.com/loft-sh/devspace 1 mellium.im/xmpp 1 github.com/openpubkey/openpubkey 1 k8s.io/kubernetes 1 github.com/ansible-semaphore/semaphore 1 github.com/chaosblade-io/chaosblade 1 github.com/prasmussen/glot-code-runner 1 github.com/tiagorlampert/CHAOS 1 github.com/gin-gonic/gin 1 github.com/grafana/grafana-plugin-sdk-go 1 github.com/navidrome/navidrome 1 github.com/owncast/owncast 1 github.com/pingcap/tidb 1 github.com/donknap/dpanel 1 github.com/edgelesssys/marblerun 1 goauthentik.io 1 github.com/layer5io/meshery 1 github.com/bishopfox/sliver 1 github.com/nats-io/jwt/v2 1 github.com/clidey/whodb/core 1 github.com/sagernet/sing-box 1 github.com/NVIDIA/mig-parted 1 github.com/rancher/rke2 1 github.com/crossplane/crossplane 1 github.com/go-vela/worker 1 github.com/tyktechnologies/tyk-identity-broker 1 golang.org/x/crypto 1 github.com/ssoready/ssoready 1 github.com/rudderlabs/rudder-server 1 github.com/projectcapsule/capsule-proxy 1 github.com/hashicorp/terraform-provider-aws 1 github.com/gen2brain/go-unarr 1 github.com/wazuh/wazuh 1 github.com/elgs/gosqljson 1 github.com/moov-io/signedxml 1 github.com/zalando/skipper 1 github.com/nanobox-io/golang-nanoauth 1 github.com/dutchcoders/transfer.sh 1 github.com/fabedge/fabedge 1 github.com/pomerium/pomerium 1 github.com/weaveworks/weave-gitops 1 github.com/go-skynet/LocalAI 1 github.com/go-vela/server 1 github.com/clastix/kamaji 1 github.com/openpubkey/opkssh 1 github.com/ethereum/go-ethereum 1 github.com/open-falcon/falcon-plus 1 gopkg.in/src-d/go-git.v4 1 github.com/evmos/evmos/v6 1 github.com/keep-network/keep-ecdsa 1 github.com/mayswind/ezbookkeeping 1 github.com/sajari/docconv 1 github.com/cloudfoundry/archiver 1 github.com/whyrusleeping/tar-utils 1 github.com/MichaelMure/git-bug 1 github.com/clastix/capsule-proxy 1 github.com/gardener/gardener-extension-provider-aws 1 github.com/knadh/listmonk 1 github.com/envoyproxy/envoy 1 github.com/binance-chain/tss-lib 1 github.com/0xJacky/Nginx-UI 1 github.com/sjqzhang/go-fastdfs 1 github.com/benc-uk/kubeview 1 github.com/lightningnetwork/lnd 1 github.com/jub0bs/fcors 1 github.com/juju/juju 1 github.com/kubernetes-sigs/image-builder 1 github.com/ecnepsnai/web 1 github.com/evmos/evmos/v5 1 github.com/IceWhaleTech/CasaOS-Gateway 1 github.com/traefik/traefik 1 github.com/charmbracelet/charm 1 github.com/casdoor/casdoor 1 github.com/stashapp/stash 1 github.com/alist-org/alist/v3 1 github.com/nats-io/jwt 1 github.com/btcsuite/btcd 1 github.com/tharsis/evmos/v3 1 github.com/square/squalor 1 github.com/fabiolb/fabio 1 github.com/gofiber/fiber 1 github.com/labring/sealos 1 github.com/couchbase/sync_gateway 1 github.com/evmos/evmos/v11 1 gopkg.in/square/go-jose.v1 1 github.com/Masterminds/vcs 1 github.com/foxcpp/maddy 1 github.com/patrickhener/goshs 1 github.com/snapcore/snapd 1 github.com/prest/prest 1 github.com/NVIDIA/gpu-operator 1 github.com/sap/cloud-security-client-go 1 github.com/tharsis/evmos/v5 1 github.com/prest/prest/v2 1 github.com/j3ssie/osmedeus 1 github.com/tharsis/evmos/v4 1 github.com/Masterminds/goutils 1 github.com/gardener/gardener-extension-provider-gcp 1 github.com/nats-io/nats-server 1 github.com/mayuresh82/gocast 1 github.com/emicklei/go-restful/v3 1 github.com/heroiclabs/nakama/v3 1 github.com/gardener/gardener-extension-provider-azure 1 d7y.io/dragonfly/v2 1 github.com/v2fly/v2ray-core/v4 1 github.com/liamg/gitjacker 1 code.sajari.com/docconv 1 github.com/gravitational/teleport 1 github.com/tharsis/evmos 1 github.com/Consensys/gnark-crypto 1 github.com/mattermost/mattermost-server 1 github.com/kcp-dev/kcp 1 github.com/zeromicro/go-zero 1

Filter by Repository

https://github.com/gogs/gogs 11 https://github.com/argoproj/argo-cd 11 https://github.com/go-gitea/gitea 8 https://github.com/rancher/rancher 7 https://github.com/answerdev/answer 6 https://github.com/grafana/grafana 5 https://github.com/usememos/memos 4 https://github.com/kubernetes/kubernetes 4 https://github.com/gofiber/fiber 3 https://github.com/dexidp/dex 3 https://github.com/beego/beego 3 https://github.com/pterodactyl/wings 3 https://github.com/crewjam/saml 3 https://github.com/chaos-mesh/chaos-mesh 3 https://github.com/cosmos/ibc-go 3 https://github.com/neuvector/neuvector 2 https://github.com/russellhaering/gosaml2 2 https://github.com/fluxcd/flux2 2 https://github.com/mattermost/mattermost-plugin-boards 2 https://github.com/evmos/evmos 2 https://github.com/cheqd/cheqd-node 2 https://github.com/moby/buildkit 2 https://github.com/gardener/gardener 2 https://github.com/hashicorp/nomad 2 https://github.com/NVIDIA/gpu-operator 2 https://github.com/hashicorp/go-getter 2 https://github.com/prest/prest 2 https://github.com/traefik/traefik 2 https://github.com/moby/moby 2 https://github.com/go-git/go-git 2 https://github.com/IceWhaleTech/CasaOS 2 https://github.com/nats-io/jwt 2 https://github.com/hashicorp/vault 2 https://github.com/git-lfs/git-lfs 2 https://github.com/nats-io/nats-server 2 https://github.com/fleetdm/fleet 1 https://github.com/authelia/authelia 1 https://github.com/MichaelMure/git-bug 1 https://github.com/Consensys/gnark-crypto 1 https://github.com/couchbase/sync_gateway 1 https://github.com/projectcapsule/capsule 1 https://github.com/gorilla/handlers 1 https://github.com/yangyanglo/ForCVE 1 https://github.com/openpubkey/opkssh 1 https://github.com/goauthentik/authentik 1 https://github.com/patrickhener/goshs 1 https://github.com/edgelesssys/marblerun 1 https://github.com/juju/juju 1 https://github.com/wazuh/wazuh 1 https://github.com/stashapp/stash 1 https://github.com/zeromicro/go-zero 1 https://github.com/SpectoLabs/hoverfly 1 https://github.com/1Panel-dev/KubePi 1 https://github.com/golang/crypto 1 https://github.com/square/go-jose 1 https://github.com/hpcng/sif 1 https://github.com/pomerium/pomerium 1 https://github.com/openpubkey/openpubkey 1 https://github.com/0xJacky/nginx-ui 1 https://github.com/yi-ge/unzip 1 https://github.com/bnb-chain/tss-lib 1 https://github.com/tailscale/tailscale 1 https://github.com/apache/trafficcontrol 1 https://github.com/zitadel/zitadel 1 https://github.com/go-vela/server 1 https://github.com/keep-network/keep-ecdsa 1 https://github.com/ecnepsnai/web 1 https://github.com/oauth2-proxy/oauth2-proxy 1 https://github.com/meshery/meshery 1 https://github.com/square/squalor 1 https://github.com/tiagorlampert/CHAOS 1 https://github.com/ethereum/go-ethereum 1 https://github.com/openbao/openbao 1 https://github.com/heroiclabs/nakama 1 https://github.com/projectdiscovery/interactsh 1 https://github.com/txthinking/brook 1 https://github.com/mosn/mosn 1 https://github.com/devspace-cloud/devspace 1 https://github.com/projectcapsule/capsule-proxy 1 https://github.com/threshold-network/tss-lib 1 https://github.com/ElrondNetwork/elrond-go 1 https://github.com/labstack/echo 1 https://github.com/kubevirt/kubevirt 1 https://github.com/sajari/docconv 1 https://github.com/chaosblade-io/chaosblade 1 https://github.com/benc-uk/kubeview 1 https://github.com/gen2brain/go-unarr 1 https://github.com/caddyserver/caddy 1 https://github.com/j3ssie/osmedeus 1 https://github.com/alist-org/alist 1 https://github.com/labring/sealos 1 https://github.com/gravitational/teleport 1 https://github.com/hydraide/hydraide 1 https://github.com/rudderlabs/rudder-server 1 https://github.com/KubeOperator/KubePi 1 https://github.com/SagerNet/sing-box 1 https://github.com/v2fly/v2ray-core 1 https://github.com/jub0bs/fcors 1 https://github.com/pion/dtls 1 https://github.com/nanobox-io/golang-nanoauth 1 https://github.com/liamg/gitjacker 1 https://github.com/navidrome/navidrome 1 https://github.com/kcp-dev/kcp 1 https://github.com/helm/helm 1 https://github.com/gofiber/template 1 https://github.com/lightningnetwork/lnd 1 https://github.com/argoproj/argo-events 1 https://github.com/owncast/owncast 1 https://github.com/terraform-providers/terraform-provider-aws 1 https://github.com/grafana/grafana-plugin-sdk-go 1 https://github.com/foxcpp/maddy 1 https://github.com/mudler/localai 1 https://github.com/flipped-aurora/gin-vue-admin 1 https://github.com/jub0bs/cors 1 https://github.com/snapcore/snapd 1 https://github.com/gardener/external-dns-management 1 https://github.com/elgs/gosqljson 1 https://github.com/SAP/cloud-security-client-go 1 https://github.com/ssoready/ssoready 1 https://github.com/rancher/rke 1 https://github.com/Masterminds/vcs 1 https://github.com/emicklei/go-restful 1 https://github.com/whyrusleeping/tar-utils 1 https://github.com/prasmussen/glot-code-runner 1 https://github.com/fabiolb/fabio 1 https://github.com/openshift/origin 1 https://github.com/github/pe-security-lab 1 https://github.com/knadh/listmonk 1 https://github.com/BishopFox/sliver 1 https://github.com/volcano-sh/volcano 1 https://github.com/artdarek/go-unzip 1 https://github.com/zalando/skipper 1 https://github.com/crossplane/crossplane 1 https://github.com/IoFinnet/tss-lib 1 https://github.com/clastix/kamaji 1 https://github.com/cloudflare/golz4 1 https://github.com/etcd-io/etcd 1 https://github.com/Consensys/gnark 1 https://github.com/ginuerzh/gost 1 https://github.com/1Panel-dev/1Panel 1 https://github.com/dragonflyoss/Dragonfly2 1 https://github.com/cloudfoundry/archiver 1 https://github.com/donknap/dpanel 1 https://github.com/Masterminds/goutils 1 https://github.com/mattermost/mattermost 1 https://github.com/IceWhaleTech/CasaOS-Gateway 1 https://github.com/gin-contrib/cors 1 https://github.com/TykTechnologies/tyk-identity-broker 1 https://github.com/influxdata/influxdb 1 https://github.com/gardener/gardener-extension-provider-aws 1 https://github.com/pingcap/tidb 1 https://github.com/mayswind/ezbookkeeping 1 https://github.com/casdoor/casdoor 1 https://github.com/open-falcon/falcon-plus 1 https://github.com/netlify/gotrue 1 https://github.com/envoyproxy/envoy 1 https://github.com/dutchcoders/transfer.sh 1 https://github.com/clidey/whodb 1 https://github.com/charmbracelet/charm 1 https://github.com/moov-io/signedxml 1 https://github.com/weaveworks/weave-gitops 1 https://github.com/ansible-semaphore/semaphore 1 https://github.com/hashicorp/vault-plugin-secrets-gcp 1