Go Package Vulnerabilities
All 1,379 Go modules with known CVEs, ranked by live CVE volume — 6,214 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 601.github.com/zarf-dev/zarf2 CVEs
- 602.github.com/zhenorzz/goploy2 CVEs
- 603.github.com/zinclabs/zinc2 CVEs
- 604.github.com/zincsearch/zincsearch2 CVEs
- 605.golang.org/x/net/html2 CVEs
- 606.golang.org/x/sys2 CVEs
- 607.go.mongodb.org/mongo-driver2 CVEs
- 608.google.golang.org/protobuf2 CVEs
- 609.go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp2 CVEs
- 610.go.opentelemetry.io/otel2 CVEs
- 611.go.opentelemetry.io/otel/sdk2 CVEs
- 612.gopkg.in/square/go-jose.v12 CVEs
- 613.go.woodpecker-ci.org/woodpecker/v32 CVEs
- 614.mellium.im/xmpp2 CVEs
- 615.open-cluster-management.io/ocm2 CVEs
- 616.sigs.k8s.io/secrets-store-csi-driver2 CVEs
- 617.siyuan2 CVEs
- 618.aahframe.work1 CVE
- 619.blitiri.com.ar/go/chasquid1 CVE
- 620.charm.land/wish/v21 CVE
- 621.code.cloudfoundry.org/archiver1 CVE
- 622.code.cloudfoundry.org/gorouter1 CVE
- 623.code.vegaprotocol.io/vega1 CVE
- 624.ehang.io/nps1 CVE
- 625.filippo.io/edwards255191 CVE
- 626.filippo.io/nistec1 CVE
- 627.github.com/1Panel-dev/1Panel/agent1 CVE
- 628.github.com/3scale-sre/marin3r1 CVE
- 629.github.com/abhinavxd/libredesk1 CVE
- 630.github.com/actiontech/sqle1 CVE
- 631.github.com/AdguardTeam/dnsproxy1 CVE
- 632.github.com/agentgateway/agentgateway1 CVE
- 633.github.com/agnivade/easy-scrypt1 CVE
- 634.github.com/aiven/aiven-operator1 CVE
- 635.github.com/albertito/chasquid1 CVE
- 636.github.com/alexanderzobnin/grafana-zabbix1 CVE
- 637.github.com/altcha-org/altcha-lib-go1 CVE
- 638.github.com/anchore/grype1 CVE
- 639.github.com/anchore/stereoscope1 CVE
- 640.github.com/AndrewBurian/powermux1 CVE
- 641.github.com/Anipaleja/nginx-defender1 CVE
- 642.github.com/antchfx/xmlquery1 CVE
- 643.github.com/antchfx/xpath1 CVE
- 644.github.com/anyproto/anytype-cli1 CVE
- 645.github.com/anyproto/anytype-heart1 CVE
- 646.github.com/apache/age/drivers/golang1 CVE
- 647.github.com/apache/camel-k1 CVE
- 648.github.com/apache/camel-k/v21 CVE
- 649.github.com/apache/skywalking-mcp1 CVE
- 650.github.com/apache/solr-operator1 CVE
Which Go packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →