An open API service providing security vulnerability metadata for many open source software ecosystems.

go

go

1,967,706 packages · proxy.golang.org

Low
13 days ago

Mattermost boards plugin fails to restrict download access to files GSA_kwCzR0hTQS1mNzJnLTUydjctbWczcM4ABMZr

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-boards
Low
17 days ago

Mattermost Open Redirect vulnerability GSA_kwCzR0hTQS1obTk1LWp4NjYtZzJnaM4ABMER

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
about 1 month ago

Mattermost Lack of Access Control Validation GSA_kwCzR0hTQS1wd3ZyLWdycWctN3ZwMs4ABLTo

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
about 1 month ago

Mattermost Fails to Properly Validate Team Role Modification GSA_kwCzR0hTQS00Mjc2LWNtOGMtNzg4aM4ABLTj

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
about 1 month ago

Mattermost Server SSRF Vulnerability via the Agents Plugin GSA_kwCzR0hTQS12cXdoLTVqaGgtdmM5cM4ABLTk

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
about 2 months ago

Mattermost Confluence Plugin has Missing Authorization vulnerability GSA_kwCzR0hTQS00Mm02LTV2bTctZmp2Ms4ABK7J

go github.com/mattermost/mattermost-plugin-confluence
Low
about 2 months ago

Mattermost Confluence Plugin has Missing Authorization vulnerability GSA_kwCzR0hTQS1yZmc0LTJtNjMtZncycc4ABK7C

go github.com/mattermost/mattermost-plugin-confluence
Low
about 2 months ago

github.com/go-acme/lego/v4/acme/api does not enforce HTTPS GSA_kwCzR0hTQS1xODJyLTJqN20tOXJ2NM4ABK1r

go github.com/go-acme/lego/v4, github.com/go-acme/lego/v3, github.com/go-acme/lego
Low
3 months ago

Mattermost has Insufficiently Protected Credentials GSA_kwCzR0hTQS00ZndqLTg1OTUtd3AyNc4ABKRo

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
4 months ago

Mattermost allows guest users to view information about public teams they are not members of GSA_kwCzR0hTQS1qd2h3LXhmNXYtcWd4Y84ABI-z

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
4 months ago

Traefik allows path traversal using url encoding GSA_kwCzR0hTQS12cmNoLTg2OGctOWp4Nc4ABIbb

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
Low
5 months ago

Mattermost Playbooks fails to properly validate permissions GSA_kwCzR0hTQS1mcjIyLTUzNzctZjNwN84ABHIO

go github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-playbooks
Low
6 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1qNjM5LW0zNjctNzVjZs4ABG1o

go github.com/mattermost/mattermost/server/v8
Low
6 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS13d2hqLXB3NmgtZjhod84ABGv_

go github.com/mattermost/mattermost/server/v8
Low
6 months ago

Reflected XSS in go-httpbin due to unrestricted client control over Content-Type GSA_kwCzR0hTQS01MjhxLTRwZ20td3ZnMs4ABFxs

go github.com/mccutchen/go-httpbin/v2, github.com/mccutchen/go-httpbin
Low
9 months ago

Mattermost Incorrect Authorization vulnerability GSA_kwCzR0hTQS1xOGZnLWNwM3EtNWp3bc4ABDHt

go github.com/mattermost/mattermost/server/v8
Low
about 1 year ago

Trufflehog vulnerable to Blind SSRF in some Detectors GSA_kwCzR0hTQS0zcjc0LXY4M3AtZjRmNM4AA-xT

go github.com/trufflesecurity/trufflehog/v3
Low
about 1 year ago

Mattermost did not properly restrict channel creation GSA_kwCzR0hTQS12dnBnLTU1cDctNWg4d84AA-UY

go github.com/mattermost/mattermost/server/v8
Low
over 1 year ago

evmos allows transferring unvested tokens after delegations GSA_kwCzR0hTQS1weHY4LXFocmgtamM3ds4AA8wK

go github.com/evmos/evmos/v6, github.com/evmos/evmos/v7, github.com/evmos/evmos/v8, github.com/evmos/evmos/v9, github.com/evmos/evmos/v10, github.com/evmos/evmos/v11, github.com/evmos/evmos/v12, github.com/evmos/evmos/v13, github.com/evmos/evmos/v14, github.com/evmos/evmos/v15, github.com/evmos/evmos/v16, github.com/evmos/evmos/v17
Low
over 1 year ago

Mattermost fails to fully validate role changes GSA_kwCzR0hTQS01cXg5LTlmZmotNXI4Zs4AA7VE

go github.com/mattermost/mattermost-server
Low
over 1 year ago

Mattermost Server Improper Access Control GSA_kwCzR0hTQS14cDlqLThwNjgtOXE5M84AA6p2

go github.com/mattermost/mattermost/server/v8
Low
over 1 year ago

Mattermost Server Resource Exhaustion GSA_kwCzR0hTQS1xcWM4LXJ2MzctNzlxNc4AA6BG

go github.com/mattermost/mattermost/server/v8
Low
over 1 year ago

Mattermost incorrectly allows access individual posts GSA_kwCzR0hTQS1yNGZtLWc2NWgtY3I1NM4AA5qG

go github.com/mattermost/mattermost/server/v8
Low
over 1 year ago

Mattermost race condition GSA_kwCzR0hTQS0zZzM1LXY1M3ItZ3B4Y84AA5qJ

go github.com/mattermost/mattermost/server/v8

Filter by Severity

Filter by Package

github.com/mattermost/mattermost/server/v8 33 github.com/mattermost/mattermost-server 10 github.com/cilium/cilium 6 k8s.io/kubernetes 6 helm.sh/helm/v3 5 github.com/authzed/spicedb 4 github.com/hashicorp/vault 4 github.com/mattermost/mattermost-server/v6 4 go.etcd.io/etcd/v3 3 github.com/grafana/grafana 3 github.com/cosmos/cosmos-sdk 3 helm.sh/helm 3 github.com/canonical/lxd 3 github.com/docker/docker 3 github.com/nats-io/nats-server/v2 2 github.com/1Panel-dev/1Panel 2 github.com/traefik/traefik/v2 2 github.com/authelia/authelia/v4 2 github.com/ntbosscher/gobase 2 github.com/containerd/containerd 2 github.com/mattermost/mattermost-plugin-confluence 2 github.com/cometbft/cometbft 2 github.com/opencontainers/runc 2 github.com/Ackites/KillWxapkg 2 github.com/hashicorp/nomad 2 github.com/answerdev/answer 2 go.etcd.io/etcd/client/v3 2 github.com/mutagen-io/mutagen 2 github.com/goharbor/harbor 2 github.com/apache/incubator-answer 2 github.com/docker/distribution 1 github.com/lxc/incus/v6 1 github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp 1 github.com/MicahParks/jwkset 1 github.com/CosmWasm/wasmd 1 github.com/argoproj/argo-workflows/v3 1 github.com/theupdateframework/go-tuf 1 github.com/notaryproject/notation-go 1 github.com/traefik/traefik/v3 1 github.com/evmos/evmos/v16 1 github.com/siderolabs/omni 1 github.com/redis/go-redis/v9 1 github.com/coder/coder/v2 1 github.com/evmos/evmos/v7 1 github.com/evmos/evmos/v13 1 github.com/tendermint/tendermint 1 go.etcd.io/etcd 1 go.etcd.io/etcd/client/pkg/v3 1 github.com/cloudflare/cfrpki 1 github.com/cloudflare/circl 1 github.com/Azure/secrets-store-csi-driver-provider-azure 1 github.com/opencontainers/distribution-spec 1 github.com/mattermost/mattermost-plugin-jira 1 github.com/aws/aws-sdk-go 1 github.com/syncthing/syncthing 1 github.com/landlock-lsm/go-landlock 1 github.com/etcd-io/etcd 1 github.com/slsa-framework/slsa-verifier/v2 1 github.com/hashicorp/vault-csi-provider 1 github.com/go-acme/lego/v3 1 github.com/sigstore/gitsign 1 github.com/go-acme/lego/v4 1 github.com/oauth2-proxy/oauth2-proxy 1 github.com/mutagen-io/mutagen-compose 1 github.com/edgelesssys/contrast 1 tailscale.com/cmd 1 knative.dev/eventing-gitlab 1 github.com/amir20/dozzle 1 github.com/crossplane/crossplane 1 github.com/mccutchen/go-httpbin/v2 1 sigs.k8s.io/aws-load-balancer-controller 1 github.com/evmos/evmos/v9 1 github.com/evmos/evmos/v12 1 github.com/opentofu/opentofu 1 github.com/ory/oathkeeper 1 github.com/bincyber/go-sqlcrypter 1 github.com/evmos/evmos/v17 1 github.com/trufflesecurity/trufflehog/v3 1 knative.dev/eventing-github 1 github.com/safedep/vet 1 github.com/cea-hpc/sshproxy 1 github.com/octo-sts/app 1 github.com/nrkno/terraform-provider-windns 1 github.com/flyteorg/flyteadmin 1 go.mozilla.org/sops/v3 1 k8s.io/kubernetes/cmd/kube-apiserver 1 github.com/argoproj/argo-cd 1 github.com/evmos/evmos/v6 1 github.com/mattermost/mattermost-plugin-playbooks 1 github.com/mudler/LocalAI 1 github.com/artifacthub/hub 1 gogs.io/gogs 1 github.com/stripe/stripe-cli 1 github.com/sigstore/cosign/v2 1 github.com/moov-io/customers 1 github.com/containers/podman/v4 1 snyk 1 go.temporal.io/server 1 github.com/evmos/evmos/v15 1 github.com/hashicorp/vagrant 1 github.com/traefik/traefik 1 google.golang.org/grpc 1 github.com/karmada-io/karmada 1 github.com/runatlantis/atlantis 1 github.com/snowflakedb/gosnowflake 1 github.com/evmos/evmos/v10 1 github.com/go-acme/lego 1 code.gitea.io/gitea 1 github.com/rancher/rancher 1 teler.app 1 github.com/evmos/evmos/v11 1 github.com/evmos/evmos/v14 1 github.com/apache/answer 1 github.com/foxcpp/maddy 1 github.com/snapcore/snapd 1 github.com/cloudflare/tableflip 1 go.elastic.co/apm 1 github.com/sigstore/cosign 1 github.com/Masterminds/goutils 1 github.com/tektoncd/pipeline 1 d7y.io/dragonfly/v2 1 github.com/huandu/facebook/v2 1 github.com/cometbft/cometbft/light 1 github.com/kcp-dev/kcp 1 github.com/snyk/go-application-framework 1 github.com/openbao/openbao 1 github.com/lima-vm/lima 1 github.com/evmos/evmos/v8 1 github.com/kopia/kopia 1 github.com/oauth2-proxy/oauth2-proxy/v7 1 github.com/consensys/gnark 1 github.com/personnummer/go 1 github.com/filebrowser/filebrowser 1 go.temporal.io/api 1 github.com/caddyserver/caddy 1 github.com/mattermost/mattermost-plugin-boards 1 github.com/disintegration/imaging 1 github.com/golang-jwt/jwt/v4 1 github.com/cheqd/cheqd-node 1 Ciliumgithub.com/cilium/cilium 1 github.com/slsa-framework/slsa-verifier 1 github.com/mccutchen/go-httpbin 1 github.com/consensys/gnark-crypto 1 github.com/sigstore/sigstore-go 1 github.com/opencontainers/image-spec 1

Filter by Repository

https://github.com/mattermost/mattermost 12 https://github.com/etcd-io/etcd 8 https://github.com/kubernetes/kubernetes 7 https://github.com/cilium/cilium 6 https://github.com/helm/helm 5 https://github.com/authzed/spicedb 4 https://github.com/cometbft/cometbft 3 https://github.com/canonical/lxd 3 https://github.com/cosmos/cosmos-sdk 3 https://github.com/moby/moby 3 https://github.com/goharbor/harbor 2 https://github.com/authelia/authelia 2 https://github.com/opencontainers/runc 2 https://github.com/ntbosscher/gobase 2 https://github.com/1Panel-dev/1Panel 2 https://github.com/Ackites/KillWxapkg 2 https://github.com/nats-io/nats-server 2 https://github.com/mutagen-io/mutagen 2 https://github.com/answerdev/answer 2 https://github.com/containerd/containerd 2 https://github.com/hashicorp/nomad 2 https://github.com/traefik/traefik 2 https://github.com/opencontainers/distribution-spec 2 https://github.com/sigstore/cosign 2 https://github.com/argoproj/argo-workflows 1 https://github.com/containers/podman 1 https://github.com/oauth2-proxy/oauth2-proxy 1 https://github.com/Consensys/gnark 1 https://github.com/coder/coder 1 https://github.com/apache/answer 1 https://github.com/temporalio/api-go 1 https://github.com/runatlantis/atlantis 1 https://github.com/personnummer/go 1 https://github.com/go-gitea/gitea 1 https://github.com/elastic/apm-agent-go 1 https://github.com/gogs/gogs 1 https://github.com/openbao/openbao 1 https://github.com/karmada-io/karmada 1 https://github.com/tendermint/tendermint 1 https://github.com/cloudflare/circl 1 https://github.com/lxc/incus 1 https://github.com/crossplane/crossplane 1 https://github.com/tailscale/tailscale 1 https://github.com/snyk/cli 1 https://github.com/mccutchen/go-httpbin 1 https://github.com/sigstore/sigstore-go 1 https://github.com/mattermost/mattermost-plugin-boards 1 https://github.com/lima-vm/lima 1 https://github.com/landlock-lsm/go-landlock 1 https://github.com/disintegration/imaging 1 https://github.com/nrkno/terraform-provider-windns 1 https://github.com/dragonflyoss/dragonfly 1 https://github.com/safedep/vet 1 https://github.com/artifacthub/hub 1 https://github.com/trufflesecurity/trufflehog 1 https://github.com/mattermost/mattermost-plugin-playbooks 1 https://github.com/argoproj/argo-cd 1 https://github.com/cloudflare/tableflip 1 https://github.com/cheqd/cheqd-node 1 https://github.com/temporalio/temporal 1 https://github.com/syncthing/syncthing 1 https://github.com/distribution/distribution 1 https://github.com/snowflakedb/gosnowflake 1 https://github.com/sigstore/gitsign 1 https://github.com/huandu/facebook 1 https://github.com/grpc/grpc-go 1 https://github.com/CosmWasm/wasmd 1 https://github.com/slsa-framework/slsa-verifier 1 https://github.com/notaryproject/notation-go 1 https://github.com/mudler/LocalAI 1 https://github.com/Masterminds/goutils 1 https://github.com/rancher/rancher 1 https://github.com/filebrowser/filebrowser 1 https://github.com/ory/oathkeeper 1 https://github.com/cea-hpc/sshproxy 1 https://github.com/stripe/stripe-cli 1 https://github.com/knative-extensions/eventing-gitlab 1 https://github.com/siderolabs/omni 1 https://github.com/kubernetes-sigs/secrets-store-csi-driver 1 https://github.com/snapcore/snapd 1 https://github.com/hashicorp/vault 1 https://github.com/mattermost/mattermost-plugin-jira 1 https://github.com/bincyber/go-sqlcrypter 1 https://github.com/octo-sts/app 1 https://github.com/mozilla/sops 1 https://github.com/evmos/evmos 1 https://github.com/Consensys/gnark-crypto 1 https://github.com/cloudflare/cfrpki 1 https://github.com/kcp-dev/kcp 1 https://github.com/edgelesssys/contrast 1 https://github.com/mholt/caddy 1 https://github.com/knative-extensions/eventing-github 1 https://github.com/tektoncd/pipeline 1 https://github.com/opentofu/opentofu 1 https://github.com/flyteorg/flyteadmin 1 https://github.com/MicahParks/jwkset 1 https://github.com/kopia/kopia 1 https://github.com/moov-io/customers 1 https://github.com/golang-jwt/jwt 1 https://github.com/kitabisa/teler 1 https://github.com/amir20/dozzle 1 https://github.com/grafana/grafana 1 https://github.com/aws/aws-sdk-go 1 https://github.com/kubernetes-sigs/aws-load-balancer-controller 1 https://github.com/go-acme/lego 1 https://github.com/redis/go-redis 1 https://github.com/theupdateframework/go-tuf 1 https://github.com/foxcpp/maddy 1