Go Vulnerability Database
Data about new vulnerabilities come directly from Go package maintainers or sources such as MITRE and GitHub. Reports are curated by the Go Security team. Learn more at go.dev/security/vuln.
Search
Recent Reports
- CVE-2024-10975, GHSA-2w5v-x29g-jw7j
- Affects: github.com/hashicorp/nomad
- Published: Nov 08, 2024
- Unreviewed
Hashicorp Nomad Incorrect Authorization vulnerability in github.com/hashicorp/nomad
- CVE-2024-45794, GHSA-q78v-cv36-8fxj
- Affects: github.com/devtron-labs/devtron
- Published: Nov 08, 2024
- Unreviewed
Devtron has SQL Injection in CreateUser API in github.com/devtron-labs/devtron
- CVE-2024-51735, GHSA-wvv7-wm5v-w2gv
- Affects: github.com/j3ssie/osmedeus
- Published: Nov 06, 2024
- Unreviewed
Osmedeus Web Server Vulnerable to Stored XSS, Leading to RCE in github.com/j3ssie/osmedeus
- CVE-2024-48057, GHSA-ghx4-cgxw-7h9p
- Affects: github.com/mudler/LocalAI
- Published: Nov 06, 2024
- Unreviewed
LocalAI Cross-site Scripting vulnerability in github.com/mudler/LocalAI
- CVE-2024-51746, GHSA-8pmp-678w-c8xx
- Affects: github.com/sigstore/gitsign
- Published: Nov 06, 2024
- Unreviewed
gitsign may use incorrect Rekor entries during verification in github.com/sigstore/gitsign
If you don't see an existing, public Go vulnerability in a publicly importable package in our database, please let us know.