Go Package Vulnerabilities
All 1,317 Go modules with known CVEs, ranked by live CVE volume — 5,626 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 401.github.com/apache/answer2 CVEs
- 402.github.com/apache/trafficcontrol/v82 CVEs
- 403.github.com/aquasecurity/trivy2 CVEs
- 404.github.com/aws/amazon-ecs-agent2 CVEs
- 405.github.com/basekick-labs/arc2 CVEs
- 406.github.com/beam-cloud/beta92 CVEs
- 407.github.com/bep/imagemeta2 CVEs
- 408.github.com/bettercap/bettercap/v22 CVEs
- 409.github.com/bitly/oauth2_proxy2 CVEs
- 410.github.com/boxlite-ai/boxlite/sdks/go2 CVEs
- 411.github.com/brokercap/Bifrost2 CVEs
- 412.github.com/buildkite/elastic-ci-stack-for-aws/v62 CVEs
- 413.github.com/bytebase/bytebase2 CVEs
- 414.github.com/cert-manager/cert-manager2 CVEs
- 415.github.com/clastix/capsule-proxy2 CVEs
- 416.github.com/clidey/whodb/core2 CVEs
- 417.github.com/cli/go-gh/v22 CVEs
- 418.github.com/cloudflare/circl2 CVEs
- 419.github.com/cloudflare/cloudflared2 CVEs
- 420.github.com/codenotary/immudb2 CVEs
- 421.github.com/containernetworking/plugins2 CVEs
- 422.github.com/containers/image2 CVEs
- 423.github.com/containers/libpod/v22 CVEs
- 424.github.com/corazawaf/coraza/v22 CVEs
- 425.github.com/corazawaf/coraza/v32 CVEs
- 426.github.com/cosmos/ethermint2 CVEs
- 427.github.com/couchbase/sync_gateway2 CVEs
- 428.github.com/crowdsecurity/crowdsec2 CVEs
- 429.github.com/crypto-org-chain/cronos2 CVEs
- 430.github.com/ctfer-io/monitoring2 CVEs
- 431.github.com/daptin/daptin2 CVEs
- 432.github.com/devtron-labs/devtron2 CVEs
- 433.github.com/docker/cli2 CVEs
- 434.github.com/docker/compose2 CVEs
- 435.github.com/docker/compose/v22 CVEs
- 436.github.com/docker/distribution2 CVEs
- 437.github.com/docker/mcp-gateway2 CVEs
- 438.github.com/dvsekhvalnov/jose2go2 CVEs
- 439.github.com/edgexfoundry/app-functions-sdk-go2 CVEs
- 440.github.com/edgexfoundry/app-functions-sdk-go/v22 CVEs
- 441.github.com/elastic/apm-server2 CVEs
- 442.github.com/etcd-io/etcd2 CVEs
- 443.github.com/expr-lang/expr2 CVEs
- 444.github.com/facebook/fbthrift2 CVEs
- 445.github.com/filecoin-project/go-f32 CVEs
- 446.github.com/flipped-aurora/gin-vue-admin/server2 CVEs
- 447.github.com/fluid-cloudnative/fluid2 CVEs
- 448.github.com/fluxcd/notification-controller2 CVEs
- 449.github.com/forceu/gokapi2 CVEs
- 450.github.com/free5gc/nrf2 CVEs
Which Go packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →