Go Package Vulnerabilities
All 1,383 Go modules with known CVEs, ranked by live CVE volume — 6,238 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 1,301.github.com/yaklang/yaklang1 CVE
- 1,302.github.com/ydb-platform/ydb-go-sdk/v31 CVE
- 1,303.github.com/yi-ge/unzip1 CVE
- 1,304.github.com/Yubico/yubihsm-connector1 CVE
- 1,305.github.com/yuin/goldmark1 CVE
- 1,306.github.com/yuin/goldmark/renderer/html1 CVE
- 1,307.github.com/yusing/godoxy1 CVE
- 1,308.github.com/zarf-dev/zarf/src/pkg/archive1 CVE
- 1,309.github.com/zeromicro/go-zero1 CVE
- 1,310.github.com/zhaojh329/rttys1 CVE
- 1,311.github.com/zxh326/kite1 CVE
- 1,312.gitlab.com/uniget-org/cli1 CVE
- 1,313.goa.design/goa1 CVE
- 1,314.goa.design/goa/v31 CVE
- 1,315.go.elastic.co/apm1 CVE
- 1,316.go.etcd.io/etcd/client/v31 CVE
- 1,317.go.etcd.io/etcd/server/v31 CVE
- 1,318.go-gitea/gitea1 CVE
- 1,319.golang.org/x/crypto/ssh/agent1 CVE
- 1,320.golang.org/x/oauth21 CVE
- 1,321.go.mongodb.org/mongo-driver/v21 CVE
- 1,322.google.golang.org/grpc1 CVE
- 1,323.google.golang.org/protobuf/encoding/protojson1 CVE
- 1,324.google.golang.org/protobuf/internal/encoding/json1 CVE
- 1,325.go.opentelemetry.io/collector/config/configgrpc1 CVE
- 1,326.go.opentelemetry.io/collector/config/confighttp1 CVE
- 1,327.go.opentelemetry.io/contrib/instrumentation/github.com/astaxie/beego/otelbeego1 CVE
- 1,328.go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful1 CVE
- 1,329.go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin1 CVE
- 1,330.go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux1 CVE
- 1,331.go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho1 CVE
- 1,332.go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc1 CVE
- 1,333.go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron1 CVE
- 1,334.go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace1 CVE
- 1,335.go.opentelemetry.io/ebpf-profiler1 CVE
- 1,336.go.opentelemetry.io/otel/baggage1 CVE
- 1,337.go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp1 CVE
- 1,338.go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp1 CVE
- 1,339.go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp1 CVE
- 1,340.go.opentelemetry.io/otel/propagation1 CVE
- 1,341.go.opentelemetry.io/otel/schema1 CVE
- 1,342.go.opentelemetry.io/otel/schema/v1.01 CVE
- 1,343.go.opentelemetry.io/otel/schema/v1.11 CVE
- 1,344.go.pinniped.dev1 CVE
- 1,345.gopkg.in/go-jose/go-jose.v21 CVE
- 1,346.gopkg.in/macaron.v11 CVE
- 1,347.gopkg.in/square/go-jose.v21 CVE
- 1,348.gopkg.in/yaml.v31 CVE
- 1,349.go.probo.inc/probo1 CVE
- 1,350.go.qbee.io/transport1 CVE
Which Go packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →