Go Package Vulnerabilities
All 1,317 Go modules with known CVEs, ranked by live CVE volume — 5,619 package-to-CVE mappings with affected ranges and fixed versions. Updated continuously as new vulnerabilities publish.
- 1,251.go.elastic.co/apm1 CVE
- 1,252.go.etcd.io/etcd/client/v31 CVE
- 1,253.go-gitea/gitea1 CVE
- 1,254.golang.org/x/crypto/ssh/agent1 CVE
- 1,255.golang.org/x/oauth21 CVE
- 1,256.go.mongodb.org/mongo-driver/v21 CVE
- 1,257.google.golang.org/grpc1 CVE
- 1,258.google.golang.org/protobuf/encoding/protojson1 CVE
- 1,259.google.golang.org/protobuf/internal/encoding/json1 CVE
- 1,260.go.opentelemetry.io/collector/config/configgrpc1 CVE
- 1,261.go.opentelemetry.io/collector/config/confighttp1 CVE
- 1,262.go.opentelemetry.io/contrib/instrumentation/github.com/astaxie/beego/otelbeego1 CVE
- 1,263.go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful1 CVE
- 1,264.go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin1 CVE
- 1,265.go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux1 CVE
- 1,266.go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho1 CVE
- 1,267.go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc1 CVE
- 1,268.go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron1 CVE
- 1,269.go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace1 CVE
- 1,270.go.opentelemetry.io/ebpf-profiler1 CVE
- 1,271.go.opentelemetry.io/otel1 CVE
- 1,272.go.opentelemetry.io/otel/baggage1 CVE
- 1,273.go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp1 CVE
- 1,274.go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp1 CVE
- 1,275.go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp1 CVE
- 1,276.go.opentelemetry.io/otel/propagation1 CVE
- 1,277.go.opentelemetry.io/otel/schema1 CVE
- 1,278.go.opentelemetry.io/otel/schema/v1.01 CVE
- 1,279.go.opentelemetry.io/otel/schema/v1.11 CVE
- 1,280.go.pinniped.dev1 CVE
- 1,281.gopkg.in/go-jose/go-jose.v21 CVE
- 1,282.gopkg.in/macaron.v11 CVE
- 1,283.gopkg.in/square/go-jose.v21 CVE
- 1,284.gopkg.in/yaml.v31 CVE
- 1,285.go.probo.inc/probo1 CVE
- 1,286.go.qbee.io/transport1 CVE
- 1,287.go.temporal.io/api1 CVE
- 1,288.go.thethings.network/lorawan-stack1 CVE
- 1,289.go.thethings.network/lorawan-stack/v31 CVE
- 1,290.heckel.io/ntfy1 CVE
- 1,291.heckel.io/ntfy/v21 CVE
- 1,292.https://github.com/dadrus/heimdall1 CVE
- 1,293.k8s.io/apiextensions-apiserver1 CVE
- 1,294.k8s.io/apimachinery1 CVE
- 1,295.k8s.io/apiserver1 CVE
- 1,296.k8s.io/kops1 CVE
- 1,297.k8s.io/kubernetes/cmd/kube-apiserver1 CVE
- 1,298.k8s.io/kubernetes/cmd/kubelet1 CVE
- 1,299.k8s.io/kubernetes/pkg/kubelet1 CVE
- 1,300.k8s.io/kube-state-metrics1 CVE
Which Go packages run in YOUR stack?
EchelonGraph inventories your dependencies and correlates them against live CVE intelligence — affected ranges, fixed versions, and blast radius in one graph.
Start Free Scan →