Go Package Vulnerabilities
All 1,379 Go modules with known CVEs, ranked by live CVE volume — 6,214 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 851.github.com/github/hub1 CVE
- 852.github.com/gitpod-io/gitpod/components/server/go1 CVE
- 853.github.com/gitpod-io/gitpod/components/ws-proxy1 CVE
- 854.github.com/gitpod-io/gitpod/install/installer1 CVE
- 855.github.com/gittuf/gittuf1 CVE
- 856.github.com/gmrtd/gmrtd1 CVE
- 857.github.com/go-aah/aah1 CVE
- 858.github.com/goadesign/goa1 CVE
- 859.github.com/go-chi/chi1 CVE
- 860.github.com/go-chi/chi/v21 CVE
- 861.github.com/go-chi/chi/v31 CVE
- 862.github.com/go-chi/chi/v41 CVE
- 863.github.com/gofiber/fiber/v2/middleware/session1 CVE
- 864.github.com/gofiber/template/django/v31 CVE
- 865.github.com/gofiber/utils1 CVE
- 866.github.com/gofiber/utils/v21 CVE
- 867.github.com/gogits/gogs1 CVE
- 868.github.com/gogo/protobuf1 CVE
- 869.github.com/goharbor/harbor/src1 CVE
- 870.github.com/go-kratos/kratos/v21 CVE
- 871.github.com/golang-fips/go1 CVE
- 872.github.com/golang-fips/openssl1 CVE
- 873.github.com/golang-fips/openssl/v21 CVE
- 874.github.com/golang/glog1 CVE
- 875.github.com/golang-jwt/jwt1 CVE
- 876.github.com/golang-jwt/jwt/v51 CVE
- 877.github.com/golang/vscode-go1 CVE
- 878.github.com/go-ldap/ldap1 CVE
- 879.github.com/go-macaron/csrf1 CVE
- 880.github.com/go-macaron/i18n1 CVE
- 881.github.com/GoogleCloudPlatform/secrets-store-csi-driver-provider-gcp1 CVE
- 882.github.com/google/go-tpm1 CVE
- 883.github.com/google/nftables1 CVE
- 884.github.com/google/safearchive1 CVE
- 885.github.com/gookit/goutil1 CVE
- 886.github.com/go-pg/pg1 CVE
- 887.github.com/go-pg/pg/v101 CVE
- 888.github.com/go-pg/pg/v91 CVE
- 889.github.com/gopistolet/gopistolet1 CVE
- 890.github.com/go-pkgz/auth1 CVE
- 891.github.com/go-pkgz/auth/v21 CVE
- 892.github.com/goreleaser/goreleaser1 CVE
- 893.github.com/goreleaser/nfpm1 CVE
- 894.github.com/goreleaser/nfpm/v21 CVE
- 895.github.com/go-resty/resty/v21 CVE
- 896.github.com/gorilla/handlers1 CVE
- 897.github.com/gorilla/schema1 CVE
- 898.github.com/gorilla/websocket1 CVE
- 899.github.com/go-shiori/shiori1 CVE
- 900.github.com/go-sonic/sonic1 CVE
Which Go packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →