Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Go Number Of NVD 138 CRITICAL 16 HIGH 83 MEDIUM 37 LOW 2
URL https://golang.org/
Explanation It is a programming language developed by Google.
It has a simple syntax and can be coded by anyone to look the same.
It has been adopted by many companies because it is good at parallel processing and can perform well on multi-core systems.
Since it is cross-compatible, it can be run in a variety of environments including Windows, Linux, Mac, and Android.

As a result of prioritizing simplicity, there are some disadvantages such as the lack of exception handling (there are alternative functions), which is common in other languages.
This may be implemented in the future.

A major release is made about every 6 months.
If a critical bug or security issue is fixed during the major release, a minor release is made.

The last two major releases are supported and covered.
Since major releases are made about every six months, the major version a year ago will no longer be supported.
Tag
  • オープンソース
  • BSD License

Add Information URL
No Type Name URL
1 https://github.com/golang/go/wiki/Go-Release-Cycle
2 https://golang.org/doc/devel/release.html
3 https://github.com/golang/go/wiki/MinorReleases
4 https://golang.org/security
5 https://golang.org/doc/copyright.html

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
51 go 1.21 1.21.13 Aug. 6, 2024 June 16, 2023 2 14 12 1
52 go 1.20 1.20.7 Aug. 1, 2023 Feb. 1, 2023 6 22 14 1
53 go 1.19 1.19.13 Sept. 6, 2023 Aug. 2, 2022 6 29 15 1
54 Go 1.18 1.18.10 Jan. 10, 2023 March 15, 2022 6 41 19 2
55 Go 1.17 1.17.13 Aug. 1, 2022 Aug. 16, 2021 8 47 20 2
56 Go 1.16 1.16.15 March 3, 2022 Feb. 16, 2021 8 53 27 2
57 Go 1.15 1.15.15 Aug. 4, 2021 Aug. 11, 2020 8 58 29 2
58 Go 1.14 1.14.15 Feb. 4, 2021 Feb. 25, 2020 8 58 31 2
59 Go 1.13 1.13.15 Aug. 6, 2020 Sept. 3, 2019 8 62 31 2
60 Go 1.12 1.12.17 Feb. 12, 2020 Feb. 25, 2019 10 63 31 2
61 go 1.9 1.9.7 11 66 32 2
62 go 1.8 1.8.7 11 66 33 2
63 go 1.7 1.7.6 11 69 33 2
64 go 1.6 1.6.4 11 71 33 2
65 go 1.5 1.5.4 11 72 33 2
66 go 1.4 1.4.3 14 70 33 2
67 go 1.3 1.3.3 14 70 34 2
68 go 1.2 1.20.7 Aug. 1, 2023 14 71 35 2
69 go 1.12 1.12.9 10 63 31 2
70 go 1.11 1.11.9 10 63 32 2
71 go 1.10 1.10.8 10 66 31 2
72 go 1.1 1.19.13 Sept. 6, 2023 14 72 35 2
73 go 1.0 1.0.3 15 70 33 2
74 go 0.0 0.0.0-20201203163018-be400aefbc4c 14 69 33 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
51 5.3
-
MEDIUM
Network
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of ent… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2022-41717 cpe:2.3:a:golang:go:*:* 1.19.0


1.19.4
1.18.9
2024-11-21 16:23
2022-12-9
Show GitHub Exploit DB Packet Storm
52 7.5
-
HIGH
Network
On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit a… CWE-22
Path Traversal
CVE-2022-41720 cpe:2.3:a:golang:go:*:*
1.19.0


1.18.9
1.19.4
2024-11-21 16:23
2022-12-8
Show GitHub Exploit DB Packet Storm
53 7.5
-
HIGH
Network
Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL v… NVD-CWE-Other
CVE-2022-41716 cpe:2.3:a:golang:go:*:*
1.19.0


1.18.8
1.19.3
2024-11-21 16:23
2022-11-3
Show GitHub Exploit DB Packet Storm
54 7.5
-
HIGH
Network
Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but… NVD-CWE-Other
CVE-2022-41715 cpe:2.3:a:golang:go:*:* 1.19.0


1.19.2
1.18.7
2024-11-21 16:23
2022-10-15
Show GitHub Exploit DB Packet Storm
55 7.5
-
HIGH
Network
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a … CWE-444
HTTP Request Smuggling
CVE-2022-2880 cpe:2.3:a:golang:go:*:* 1.19.0


1.19.2
1.18.7
2024-11-21 16:01
2022-10-15
Show GitHub Exploit DB Packet Storm
56 7.5
-
HIGH
Network
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion o… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2022-2879 cpe:2.3:a:golang:go:*:* 1.19.0


1.19.2
1.18.7
2024-11-21 16:01
2022-10-15
Show GitHub Exploit DB Packet Storm
57 7.5
-
HIGH
Network
JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath do… CWE-22
Path Traversal
CVE-2022-32190 cpe:2.3:a:golang:go:1.19.0:rc2
cpe:2.3:a:golang:go:1.19.0:rc1
cpe:2.3:a:golang:go:1.19.0:beta1
cpe:2.3:a:golan…
2024-11-21 16:05
2022-09-14
Show GitHub Exploit DB Packet Storm
58 7.5
-
HIGH
Network
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. NVD-CWE-noinfo
CVE-2022-27664 cpe:2.3:a:golang:go:1.19.0:*
cpe:2.3:a:golang:go:*:*
1.18.6 2024-11-21 15:56
2022-09-7
Show GitHub Exploit DB Packet Storm
59 7.5
-
HIGH
Network
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service. NVD-CWE-noinfo
CVE-2022-32189 cpe:2.3:a:golang:go:*:* 1.18.0


1.18.5
1.17.13
2024-11-21 16:05
2022-08-11
Show GitHub Exploit DB Packet Storm
60 6.5
-
MEDIUM
Network
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for t… NVD-CWE-noinfo
CVE-2022-32148 cpe:2.3:a:golang:go:*:*
1.18.0


1.17.12
1.18.4
2024-11-21 16:05
2022-08-11
Show GitHub Exploit DB Packet Storm