Go Package Vulnerabilities
All 1,329 Go modules with known CVEs, ranked by live CVE volume — 5,708 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 1,251.github.com/yi-ge/unzip1 CVE
- 1,252.github.com/Yubico/yubihsm-connector1 CVE
- 1,253.github.com/yuin/goldmark1 CVE
- 1,254.github.com/yuin/goldmark/renderer/html1 CVE
- 1,255.github.com/yusing/godoxy1 CVE
- 1,256.github.com/zarf-dev/zarf1 CVE
- 1,257.github.com/zeromicro/go-zero1 CVE
- 1,258.github.com/zhaojh329/rttys1 CVE
- 1,259.github.com/zxh326/kite1 CVE
- 1,260.gitlab.com/uniget-org/cli1 CVE
- 1,261.goa.design/goa1 CVE
- 1,262.goa.design/goa/v31 CVE
- 1,263.go.elastic.co/apm1 CVE
- 1,264.go.etcd.io/etcd/client/v31 CVE
- 1,265.go-gitea/gitea1 CVE
- 1,266.golang.org/x/crypto/ssh/agent1 CVE
- 1,267.golang.org/x/oauth21 CVE
- 1,268.go.mongodb.org/mongo-driver/v21 CVE
- 1,269.google.golang.org/grpc1 CVE
- 1,270.google.golang.org/protobuf/encoding/protojson1 CVE
- 1,271.google.golang.org/protobuf/internal/encoding/json1 CVE
- 1,272.go.opentelemetry.io/collector/config/configgrpc1 CVE
- 1,273.go.opentelemetry.io/collector/config/confighttp1 CVE
- 1,274.go.opentelemetry.io/contrib/instrumentation/github.com/astaxie/beego/otelbeego1 CVE
- 1,275.go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful1 CVE
- 1,276.go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin1 CVE
- 1,277.go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux1 CVE
- 1,278.go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho1 CVE
- 1,279.go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc1 CVE
- 1,280.go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron1 CVE
- 1,281.go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace1 CVE
- 1,282.go.opentelemetry.io/ebpf-profiler1 CVE
- 1,283.go.opentelemetry.io/otel1 CVE
- 1,284.go.opentelemetry.io/otel/baggage1 CVE
- 1,285.go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp1 CVE
- 1,286.go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp1 CVE
- 1,287.go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp1 CVE
- 1,288.go.opentelemetry.io/otel/propagation1 CVE
- 1,289.go.opentelemetry.io/otel/schema1 CVE
- 1,290.go.opentelemetry.io/otel/schema/v1.01 CVE
- 1,291.go.opentelemetry.io/otel/schema/v1.11 CVE
- 1,292.go.pinniped.dev1 CVE
- 1,293.gopkg.in/go-jose/go-jose.v21 CVE
- 1,294.gopkg.in/macaron.v11 CVE
- 1,295.gopkg.in/square/go-jose.v21 CVE
- 1,296.gopkg.in/yaml.v31 CVE
- 1,297.go.probo.inc/probo1 CVE
- 1,298.go.qbee.io/transport1 CVE
- 1,299.go.temporal.io/api1 CVE
- 1,300.go.thethings.network/lorawan-stack1 CVE
Which Go packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →