Go Package Vulnerabilities
All 1,382 Go modules with known CVEs, ranked by live CVE volume — 6,217 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 1,101.github.com/nwaples/rardecode1 CVE
- 1,102.github.com/nwaples/rardecode/v21 CVE
- 1,103.github.com/nyaruka/phonenumbers1 CVE
- 1,104.github.com/oam-dev/kubevela1 CVE
- 1,105.github.com/oasdiff/oasdiff1 CVE
- 1,106.github.com/onosproject/onos-lib-go1 CVE
- 1,107.github.com/openark/orchestrator1 CVE
- 1,108.github.com/openbao/openbao-plugins1 CVE
- 1,109.github.com/openbao/openbao/sdk1 CVE
- 1,110.github.com/openbao/openbao/sdk/v21 CVE
- 1,111.github.com/openclarity/kubeclarity/backend1 CVE
- 1,112.github.com/opencloud-eu/reva1 CVE
- 1,113.github.com/opencloud-eu/reva/v21 CVE
- 1,114.github.com/opencontainers/distribution-spec1 CVE
- 1,115.github.com/opencontainers/umoci1 CVE
- 1,116.github.com/opencost/opencost1 CVE
- 1,117.github.com/open-falcon/falcon-plus1 CVE
- 1,118.github.com/open-feature/flagd/flagd1 CVE
- 1,119.github.com/openflagr/flagr1 CVE
- 1,120.github.com/openmeterio/openmeter1 CVE
- 1,121.github.com/open-policy-agent/opa-envoy-plugin1 CVE
- 1,122.github.com/open-policy-agent/opa/server1 CVE
- 1,123.github.com/open-policy-agent/opa/v1/server1 CVE
- 1,124.github.com/openpubkey/openpubkey1 CVE
- 1,125.github.com/openpubkey/opkssh1 CVE
- 1,126.github.com/openrundev/openrun1 CVE
- 1,127.github.com/openshift/assisted-installer1 CVE
- 1,128.github.com/openshift/builder1 CVE
- 1,129.github.com/openshift/cluster-monitoring-operator1 CVE
- 1,130.github.com/openshift/must-gather1 CVE
- 1,131.github.com/openshift/openshift-apiserver1 CVE
- 1,132.github.com/openshift/openshift-controller-manager1 CVE
- 1,133.github.com/openshift/osin1 CVE
- 1,134.github.com/openshift/source-to-image1 CVE
- 1,135.github.com/openshift/telemeter1 CVE
- 1,136.github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter1 CVE
- 1,137.github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension1 CVE
- 1,138.github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension1 CVE
- 1,139.github.com/open-telemetry/opentelemetry-collector-contrib/receiver/awsfirehosereceiver1 CVE
- 1,140.github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver1 CVE
- 1,141.github.com/open-telemetry/opentelemetry-operator1 CVE
- 1,142.github.com/operator-framework/operator-sdk1 CVE
- 1,143.github.com/orneryd/nornicdb1 CVE
- 1,144.github.com/ory/hydra/v21 CVE
- 1,145.github.com/ory/keto1 CVE
- 1,146.github.com/ossf/allstar1 CVE
- 1,147.github.com/ouqiang/gocron1 CVE
- 1,148.github.com/ovn-org/ovn-kubernetes1 CVE
- 1,149.github.com/oxyno-zeta/s3-proxy/cmd/s3-proxy1 CVE
- 1,150.github.com/pandatix/go-cvss1 CVE
Which Go packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →