
go
1,967,706 packages · proxy.golang.org
Low Security Advisories in go Clear Filters
Low
6 days ago
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
go
github.com/kcp-dev/kcp
Low
13 days ago
Mattermost boards plugin fails to restrict download access to files
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-boards
Low
15 days ago
Dragonfly's directories created via os.MkdirAll are not checked for permissions
go
d7y.io/dragonfly/v2
Low
17 days ago
Mattermost Open Redirect vulnerability
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
27 days ago
Atlantis Exposes Service Version Publicly on /status API Endpoint
go
github.com/runatlantis/atlantis
Low
about 1 month ago
Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token
go
github.com/coder/coder/v2
Low
about 1 month ago
Mattermost Lack of Access Control Validation
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
about 1 month ago
Mattermost Fails to Properly Validate Team Role Modification
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
about 1 month ago
Mattermost Server SSRF Vulnerability via the Agents Plugin
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
about 2 months ago
Mattermost Confluence Plugin has Missing Authorization vulnerability
go
github.com/mattermost/mattermost-plugin-confluence
Low
about 2 months ago
Mattermost Confluence Plugin has Missing Authorization vulnerability
go
github.com/mattermost/mattermost-plugin-confluence
Low
about 2 months ago
OpenBao has a Timing Side-Channel in the Userpass Auth Method
go
github.com/openbao/openbao
Low
about 2 months ago
github.com/go-acme/lego/v4/acme/api does not enforce HTTPS
go
github.com/go-acme/lego/v4, github.com/go-acme/lego/v3, github.com/go-acme/lego
Low
2 months ago
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
go
github.com/hashicorp/vault
Low
3 months ago
Mattermost has Insufficiently Protected Credentials
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-server
Low
3 months ago
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points
go
github.com/edgelesssys/contrast
Low
3 months ago
File Browser's password protection of links is bypassable
go
github.com/filebrowser/filebrowser
Low
3 months ago
Vault Community Edition rekey and recovery key operations can cause denial of service
go
github.com/hashicorp/vault
Low
3 months ago
Incus Allocation of Resources Without Limits allows firewall rule bypass on managed bridge networks
go
github.com/lxc/incus/v6
Low
3 months ago
Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE mode
go, npm
github.com/snyk/go-application-framework, snyk
Low
3 months ago
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
go
k8s.io/kubernetes
Low
4 months ago
Grafana long dashboard title or panel name causes unresponsives
go
github.com/grafana/grafana
Low
4 months ago
Mattermost allows guest users to view information about public teams they are not members of
go
github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
4 months ago
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
go
github.com/cloudflare/circl
Low
4 months ago
SpiceDB checks involving relations with caveats can result in no permission when permission is expected
go
github.com/authzed/spicedb
Low
4 months ago
Mattermost fails to properly enforce access control restrictions for System Manager roles
go
github.com/mattermost/mattermost/server/v8
Low
4 months ago
Mattermost fails to properly enforce access controls for guest users
go
github.com/mattermost/mattermost/server/v8
Low
4 months ago
Traefik allows path traversal using url encoding
go
github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
Low
4 months ago
Ackites KillWxapkg vulnerable to OS Command Injection
go
github.com/Ackites/KillWxapkg
Low
5 months ago
Mattermost Fails to Check User Access to `ExperimentalSettings`
go
github.com/mattermost/mattermost/server/v8
Low
5 months ago
Terraform WinDNS Provider improperly sanitizes input variables in `windns_record`
go
github.com/nrkno/terraform-provider-windns
Low
5 months ago
Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
go
github.com/snowflakedb/gosnowflake
Low
5 months ago
Mattermost Playbooks fails to properly validate permissions
go
github.com/mattermost/mattermost/server/v8, github.com/mattermost/mattermost-plugin-playbooks
Low
6 months ago
Mattermost doesn't restrict domains LLM can request to contact upstream
go
github.com/mattermost/mattermost/server/v8
Low
6 months ago
Mattermost Missing Authentication for Critical Function
go
github.com/mattermost/mattermost/server/v8
Low
6 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8
Low
6 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8
Low
6 months ago
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
go
github.com/mattermost/mattermost/server/v8
Low
6 months ago
Apache Answer User Using External Images Potentially Discloses User Information
go
github.com/apache/answer
Low
6 months ago
Cilium node based network policies may incorrectly allow workload traffic
go
Ciliumgithub.com/cilium/cilium, github.com/cilium/cilium
Low
6 months ago
Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
go
github.com/cilium/cilium
Low
6 months ago
Reflected XSS in go-httpbin due to unrestricted client control over Content-Type
go
github.com/mccutchen/go-httpbin/v2, github.com/mccutchen/go-httpbin
Low
7 months ago
Mattermost fail to prompt for explicit approval before adding a team admin to a private channel
go
github.com/mattermost/mattermost/server/v8
Low
7 months ago
go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
go
github.com/redis/go-redis/v9
Low
7 months ago
Kubernetes kube-apiserver Vulnerable to Race Condition
go
k8s.io/kubernetes/cmd/kube-apiserver
Low
7 months ago
Mattermost fails to invalidate all active sessions when converting a user to a bot
go
github.com/mattermost/mattermost/server/v8
Low
7 months ago
Authelia applies regulation separately to Username-based logins to Email-based logins
go
github.com/authelia/authelia/v4
Low
9 months ago
notation-go has an OS error when setting CRL cache leads to denial of signature verification
go
github.com/notaryproject/notation-go
Low
9 months ago
JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh
go
github.com/MicahParks/jwkset
Low
9 months ago
Mattermost has Improper Check for Unusual or Exceptional Conditions
go
github.com/mattermost/mattermost/server/v8
Low
9 months ago
Mattermost Incorrect Authorization vulnerability
go
github.com/mattermost/mattermost/server/v8
Low
10 months ago
lxd has a restricted TLS certificate privilege escalation when in PKI mode
go
github.com/canonical/lxd
Low
10 months ago
Apache Answer: Predictable Authorization Token Using UUIDv1
go
github.com/apache/incubator-answer
Low
11 months ago
gitsign may use incorrect Rekor entries during verification
go
github.com/sigstore/gitsign
Low
11 months ago
Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations
go
github.com/golang-jwt/jwt/v4
Low
11 months ago
Grafana org admin can delete pending invites in different org
go
github.com/grafana/grafana
Low
11 months ago
Mattermost incorrectly issues two sessions when using desktop SSO
go
github.com/mattermost/mattermost/server/v8
Low
11 months ago
AWS Load Balancer Controller automatically detaches externally associated web ACL from Application Load Balancers
go
sigs.k8s.io/aws-load-balancer-controller
Low
12 months ago
SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not
go
github.com/authzed/spicedb
Low
12 months ago
Go-Landlock in best-effort mode did not restrict TCP bind and connect operations correctly
go
github.com/landlock-lsm/go-landlock
Low
12 months ago
OpenTofu potential leaking of secret variable values when using static evaluation in v1.8
go
github.com/opentofu/opentofu
Low
about 1 year ago
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack
go
github.com/sigstore/sigstore-go
Low
about 1 year ago
CometBFT's state syncing validator from malicious node may lead to a chain split
go
github.com/cometbft/cometbft/light
Low
about 1 year ago
Trufflehog vulnerable to Blind SSRF in some Detectors
go
github.com/trufflesecurity/trufflehog/v3
Low
about 1 year ago
Mattermost did not properly restrict channel creation
go
github.com/mattermost/mattermost/server/v8
Low
about 1 year ago
snapd failed to properly check the destination of symbolic links when extracting a snap
go
github.com/snapcore/snapd
Low
about 1 year ago
Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go
go
google.golang.org/grpc
Low
over 1 year ago
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
go
github.com/hashicorp/vault
Low
over 1 year ago
`docker cp` allows unexpected chmod of host files in Moby Docker Engine
go
github.com/docker/docker
Low
over 1 year ago
evmos allows transferring unvested tokens after delegations
go
github.com/evmos/evmos/v6, github.com/evmos/evmos/v7, github.com/evmos/evmos/v8, github.com/evmos/evmos/v9, github.com/evmos/evmos/v10, github.com/evmos/evmos/v11, github.com/evmos/evmos/v12, github.com/evmos/evmos/v13, github.com/evmos/evmos/v14, github.com/evmos/evmos/v15, github.com/evmos/evmos/v16, github.com/evmos/evmos/v17
Low
over 1 year ago
github.com/huandu/facebook may expose access_token in error message.
go
github.com/huandu/facebook/v2
Low
over 1 year ago
github.com/bincyber/go-sqlcrypter vulnerable to IV collision
go
github.com/bincyber/go-sqlcrypter
Low
over 1 year ago
Grafana Forward OAuth Identity Token can allow users to access some data sources
go
github.com/grafana/grafana
Low
over 1 year ago
containerd started with non-empty inheritable Linux process capabilities
go
github.com/containerd/containerd
Low
over 1 year ago
NATS server TLS missing ciphersuite settings when CLI flags used
go
github.com/nats-io/nats-server/v2
Low
over 1 year ago
octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage
go
github.com/octo-sts/app
Low
over 1 year ago
Mattermost allows team admins to promote guests to team admins
go
github.com/mattermost/mattermost-server
Low
over 1 year ago
Mattermost fails to fully validate role changes
go
github.com/mattermost/mattermost-server
Low
over 1 year ago
Mattermost fails to limit the size of a request path
go
github.com/mattermost/mattermost-server
Low
over 1 year ago
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin
go
k8s.io/kubernetes
Low
over 1 year ago
Authelia's Group Changes may not have the expected results (YAML file backend)
go
github.com/authelia/authelia/v4
Low
over 1 year ago
1Panel's password verification is suspected to have a timing attack vulnerability
go
github.com/1Panel-dev/1Panel
Low
over 1 year ago
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used
go
github.com/authzed/spicedb
Low
over 1 year ago
Kopia: Storage connection credentials written to console on "repository status" CLI command with JSON output
go
github.com/kopia/kopia
Low
over 1 year ago
Mattermost Server Improper Access Control
go
github.com/mattermost/mattermost/server/v8
Low
over 1 year ago
Mattermost Server Resource Exhaustion
go
github.com/mattermost/mattermost/server/v8
Low
over 1 year ago
Mattermost incorrectly allows access individual posts
go
github.com/mattermost/mattermost/server/v8
Filter by Severity
Filter by Package
github.com/mattermost/mattermost/server/v8
33
github.com/mattermost/mattermost-server
10
github.com/cilium/cilium
6
k8s.io/kubernetes
6
helm.sh/helm/v3
5
github.com/authzed/spicedb
4
github.com/hashicorp/vault
4
github.com/mattermost/mattermost-server/v6
4
go.etcd.io/etcd/v3
3
github.com/grafana/grafana
3
github.com/cosmos/cosmos-sdk
3
helm.sh/helm
3
github.com/canonical/lxd
3
github.com/docker/docker
3
github.com/nats-io/nats-server/v2
2
github.com/1Panel-dev/1Panel
2
github.com/traefik/traefik/v2
2
github.com/authelia/authelia/v4
2
github.com/ntbosscher/gobase
2
github.com/containerd/containerd
2
github.com/mattermost/mattermost-plugin-confluence
2
github.com/cometbft/cometbft
2
github.com/opencontainers/runc
2
github.com/Ackites/KillWxapkg
2
github.com/hashicorp/nomad
2
github.com/answerdev/answer
2
go.etcd.io/etcd/client/v3
2
github.com/mutagen-io/mutagen
2
github.com/goharbor/harbor
2
github.com/apache/incubator-answer
2
github.com/docker/distribution
1
github.com/lxc/incus/v6
1
github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp
1
github.com/MicahParks/jwkset
1
github.com/CosmWasm/wasmd
1
github.com/argoproj/argo-workflows/v3
1
github.com/theupdateframework/go-tuf
1
github.com/notaryproject/notation-go
1
github.com/traefik/traefik/v3
1
github.com/evmos/evmos/v16
1
github.com/siderolabs/omni
1
github.com/redis/go-redis/v9
1
github.com/coder/coder/v2
1
github.com/evmos/evmos/v7
1
github.com/evmos/evmos/v13
1
github.com/tendermint/tendermint
1
go.etcd.io/etcd
1
go.etcd.io/etcd/client/pkg/v3
1
github.com/cloudflare/cfrpki
1
github.com/cloudflare/circl
1
github.com/Azure/secrets-store-csi-driver-provider-azure
1
github.com/opencontainers/distribution-spec
1
github.com/mattermost/mattermost-plugin-jira
1
github.com/aws/aws-sdk-go
1
github.com/syncthing/syncthing
1
github.com/landlock-lsm/go-landlock
1
github.com/etcd-io/etcd
1
github.com/slsa-framework/slsa-verifier/v2
1
github.com/hashicorp/vault-csi-provider
1
github.com/go-acme/lego/v3
1
github.com/sigstore/gitsign
1
github.com/go-acme/lego/v4
1
github.com/oauth2-proxy/oauth2-proxy
1
github.com/mutagen-io/mutagen-compose
1
github.com/edgelesssys/contrast
1
tailscale.com/cmd
1
knative.dev/eventing-gitlab
1
github.com/amir20/dozzle
1
github.com/crossplane/crossplane
1
github.com/mccutchen/go-httpbin/v2
1
sigs.k8s.io/aws-load-balancer-controller
1
github.com/evmos/evmos/v9
1
github.com/evmos/evmos/v12
1
github.com/opentofu/opentofu
1
github.com/ory/oathkeeper
1
github.com/bincyber/go-sqlcrypter
1
github.com/evmos/evmos/v17
1
github.com/trufflesecurity/trufflehog/v3
1
knative.dev/eventing-github
1
github.com/safedep/vet
1
github.com/cea-hpc/sshproxy
1
github.com/octo-sts/app
1
github.com/nrkno/terraform-provider-windns
1
github.com/flyteorg/flyteadmin
1
go.mozilla.org/sops/v3
1
k8s.io/kubernetes/cmd/kube-apiserver
1
github.com/argoproj/argo-cd
1
github.com/evmos/evmos/v6
1
github.com/mattermost/mattermost-plugin-playbooks
1
github.com/mudler/LocalAI
1
github.com/artifacthub/hub
1
gogs.io/gogs
1
github.com/stripe/stripe-cli
1
github.com/sigstore/cosign/v2
1
github.com/moov-io/customers
1
github.com/containers/podman/v4
1
snyk
1
go.temporal.io/server
1
github.com/evmos/evmos/v15
1
github.com/hashicorp/vagrant
1
github.com/traefik/traefik
1
google.golang.org/grpc
1
github.com/karmada-io/karmada
1
github.com/runatlantis/atlantis
1
github.com/snowflakedb/gosnowflake
1
github.com/evmos/evmos/v10
1
github.com/go-acme/lego
1
code.gitea.io/gitea
1
github.com/rancher/rancher
1
teler.app
1
github.com/evmos/evmos/v11
1
github.com/evmos/evmos/v14
1
github.com/apache/answer
1
github.com/foxcpp/maddy
1
github.com/snapcore/snapd
1
github.com/cloudflare/tableflip
1
go.elastic.co/apm
1
github.com/sigstore/cosign
1
github.com/Masterminds/goutils
1
github.com/tektoncd/pipeline
1
d7y.io/dragonfly/v2
1
github.com/huandu/facebook/v2
1
github.com/cometbft/cometbft/light
1
github.com/kcp-dev/kcp
1
github.com/snyk/go-application-framework
1
github.com/openbao/openbao
1
github.com/lima-vm/lima
1
github.com/evmos/evmos/v8
1
github.com/kopia/kopia
1
github.com/oauth2-proxy/oauth2-proxy/v7
1
github.com/consensys/gnark
1
github.com/personnummer/go
1
github.com/filebrowser/filebrowser
1
go.temporal.io/api
1
github.com/caddyserver/caddy
1
github.com/mattermost/mattermost-plugin-boards
1
github.com/disintegration/imaging
1
github.com/golang-jwt/jwt/v4
1
github.com/cheqd/cheqd-node
1
Ciliumgithub.com/cilium/cilium
1
github.com/slsa-framework/slsa-verifier
1
github.com/mccutchen/go-httpbin
1
github.com/consensys/gnark-crypto
1
github.com/sigstore/sigstore-go
1
github.com/opencontainers/image-spec
1
Filter by Repository
https://github.com/mattermost/mattermost
12
https://github.com/etcd-io/etcd
8
https://github.com/kubernetes/kubernetes
7
https://github.com/cilium/cilium
6
https://github.com/helm/helm
5
https://github.com/authzed/spicedb
4
https://github.com/cometbft/cometbft
3
https://github.com/canonical/lxd
3
https://github.com/cosmos/cosmos-sdk
3
https://github.com/moby/moby
3
https://github.com/goharbor/harbor
2
https://github.com/authelia/authelia
2
https://github.com/opencontainers/runc
2
https://github.com/ntbosscher/gobase
2
https://github.com/1Panel-dev/1Panel
2
https://github.com/Ackites/KillWxapkg
2
https://github.com/nats-io/nats-server
2
https://github.com/mutagen-io/mutagen
2
https://github.com/answerdev/answer
2
https://github.com/containerd/containerd
2
https://github.com/hashicorp/nomad
2
https://github.com/traefik/traefik
2
https://github.com/opencontainers/distribution-spec
2
https://github.com/sigstore/cosign
2
https://github.com/argoproj/argo-workflows
1
https://github.com/containers/podman
1
https://github.com/oauth2-proxy/oauth2-proxy
1
https://github.com/Consensys/gnark
1
https://github.com/coder/coder
1
https://github.com/apache/answer
1
https://github.com/temporalio/api-go
1
https://github.com/runatlantis/atlantis
1
https://github.com/personnummer/go
1
https://github.com/go-gitea/gitea
1
https://github.com/elastic/apm-agent-go
1
https://github.com/gogs/gogs
1
https://github.com/openbao/openbao
1
https://github.com/karmada-io/karmada
1
https://github.com/tendermint/tendermint
1
https://github.com/cloudflare/circl
1
https://github.com/lxc/incus
1
https://github.com/crossplane/crossplane
1
https://github.com/tailscale/tailscale
1
https://github.com/snyk/cli
1
https://github.com/mccutchen/go-httpbin
1
https://github.com/sigstore/sigstore-go
1
https://github.com/mattermost/mattermost-plugin-boards
1
https://github.com/lima-vm/lima
1
https://github.com/landlock-lsm/go-landlock
1
https://github.com/disintegration/imaging
1
https://github.com/nrkno/terraform-provider-windns
1
https://github.com/dragonflyoss/dragonfly
1
https://github.com/safedep/vet
1
https://github.com/artifacthub/hub
1
https://github.com/trufflesecurity/trufflehog
1
https://github.com/mattermost/mattermost-plugin-playbooks
1
https://github.com/argoproj/argo-cd
1
https://github.com/cloudflare/tableflip
1
https://github.com/cheqd/cheqd-node
1
https://github.com/temporalio/temporal
1
https://github.com/syncthing/syncthing
1
https://github.com/distribution/distribution
1
https://github.com/snowflakedb/gosnowflake
1
https://github.com/sigstore/gitsign
1
https://github.com/huandu/facebook
1
https://github.com/grpc/grpc-go
1
https://github.com/CosmWasm/wasmd
1
https://github.com/slsa-framework/slsa-verifier
1
https://github.com/notaryproject/notation-go
1
https://github.com/mudler/LocalAI
1
https://github.com/Masterminds/goutils
1
https://github.com/rancher/rancher
1
https://github.com/filebrowser/filebrowser
1
https://github.com/ory/oathkeeper
1
https://github.com/cea-hpc/sshproxy
1
https://github.com/stripe/stripe-cli
1
https://github.com/knative-extensions/eventing-gitlab
1
https://github.com/siderolabs/omni
1
https://github.com/kubernetes-sigs/secrets-store-csi-driver
1
https://github.com/snapcore/snapd
1
https://github.com/hashicorp/vault
1
https://github.com/mattermost/mattermost-plugin-jira
1
https://github.com/bincyber/go-sqlcrypter
1
https://github.com/octo-sts/app
1
https://github.com/mozilla/sops
1
https://github.com/evmos/evmos
1
https://github.com/Consensys/gnark-crypto
1
https://github.com/cloudflare/cfrpki
1
https://github.com/kcp-dev/kcp
1
https://github.com/edgelesssys/contrast
1
https://github.com/mholt/caddy
1
https://github.com/knative-extensions/eventing-github
1
https://github.com/tektoncd/pipeline
1
https://github.com/opentofu/opentofu
1
https://github.com/flyteorg/flyteadmin
1
https://github.com/MicahParks/jwkset
1
https://github.com/kopia/kopia
1
https://github.com/moov-io/customers
1
https://github.com/golang-jwt/jwt
1
https://github.com/kitabisa/teler
1
https://github.com/amir20/dozzle
1
https://github.com/grafana/grafana
1
https://github.com/aws/aws-sdk-go
1
https://github.com/kubernetes-sigs/aws-load-balancer-controller
1
https://github.com/go-acme/lego
1
https://github.com/redis/go-redis
1
https://github.com/theupdateframework/go-tuf
1
https://github.com/foxcpp/maddy
1