gomplate

Direct Vulnerabilities

Known vulnerabilities in the gomplate package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-hrxh-6v49-42gf

<5.2.0-r1
  • L
Uncontrolled Memory Allocation

<5.2.0-r1
  • L
CVE-2026-46600

<5.2.0-r0
  • L
CVE-2026-56852

<5.2.0-r0
  • L
CVE-2026-42505

<5.1.0-r4
  • L
CVE-2026-39822

<5.1.0-r4
  • L
Uncontrolled Memory Allocation

<4.3.3-r17
  • L
GHSA-w5pp-99ch-qj29

<5.1.0-r3
  • C
Improper Encoding or Escaping of Output

<5.1.0-r3
  • L
Directory Traversal

<5.1.0-r3
  • L
Improper Verification of Cryptographic Signature

<5.1.0-r1
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<4.3.3-r4
  • M
CVE-2025-47911

<4.3.3-r4
  • L
Integer Overflow or Wraparound

<5.1.0-r1
  • L
CVE-2026-39824

<5.1.0-r1
  • L
Missing Authorization

<5.1.0-r1
  • L
Improper Certificate Validation

<5.1.0-r1
  • L
CVE-2026-46598

<5.1.0-r1
  • L
Deserialization of Untrusted Data

<5.1.0-r1
  • L
Improper Restriction of Rendered UI Layers or Frames

<5.1.0-r1
  • L
Improper Certificate Validation

<5.1.0-r1
  • L
Cross-site Scripting (XSS)

<5.1.0-r1
  • L
Incorrect Type Conversion or Cast

<5.1.0-r1
  • L
CVE-2026-39821

<5.1.0-r1
  • L
CVE-2026-27145

<5.1.0-r1
  • L
Out-of-Bounds

<5.1.0-r1
  • L
Resource Exhaustion

<5.1.0-r1
  • L
Improper Restriction of Rendered UI Layers or Frames

<5.1.0-r1
  • L
Missing Authorization

<5.1.0-r1
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<5.1.0-r1
  • L
Improper Certificate Validation

<5.1.0-r1
  • L
Reachable Assertion

<4.3.3-r4
  • L
CVE-2026-46595

<5.1.0-r1
  • L
CVE-2026-42504

<5.1.0-r1
  • L
CVE-2026-42507

<5.1.0-r1
  • L
Improper Restriction of Rendered UI Layers or Frames

<5.1.0-r1
  • L
GHSA-xmrv-pmrh-hhx2

<5.1.0-r0
  • H
Incorrect Behavior Order: Validate Before Canonicalize

<5.1.0-r3
  • L
Directory Traversal

<5.1.0-r3
  • L
Uncontrolled Recursion

<5.1.0-r3
  • L
Improper Encoding or Escaping of Output

<4.3.3-r19
  • H
NULL Pointer Dereference

<4.3.3-r19
  • M
Out-of-bounds Write

<4.3.3-r19
  • H
Double Free

<4.3.3-r19
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<4.3.3-r19
  • L
Cross-site Scripting (XSS)

<4.3.3-r19
  • L
CVE-2026-42501

<4.3.3-r19
  • L
CVE-2026-42499

<4.3.3-r19
  • L
CVE-2026-39825

<4.3.3-r19
  • M
Link Following

<4.3.3-r19
  • H
Allocation of Resources Without Limits or Throttling

<4.3.3-r19
  • L
Allocation of Resources Without Limits or Throttling

<4.3.3-r17
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<4.3.3-r16
  • C
CVE-2026-27143

<4.3.3-r16
  • L
GHSA-3xc5-wrhm-f963

<4.3.3-r18
  • M
Cross-site Scripting (XSS)

<4.3.3-r16
  • H
Allocation of Resources Without Limits or Throttling

<4.3.3-r16
  • M
Allocation of Resources Without Limits or Throttling

<4.3.3-r16
  • M
Link Following

<4.3.3-r16
  • H
Improper Certificate Validation

<4.3.3-r16
  • L
CVE-2026-32280

<4.3.3-r16
  • H
Incorrect Authorization

<4.3.3-r16
  • H
Improper Certificate Validation

<4.3.3-r16
  • H
Untrusted Search Path

<4.3.3-r17
  • L
Uncaught Exception

<4.3.3-r15
  • L
Integer Underflow

<4.3.3-r14
  • L
Improper Validation of Array Index

<4.3.3-r14
  • L
Improper Authorization

<4.3.3-r13
  • L
Improper Certificate Validation

<4.3.3-r12
  • L
Direct Request ('Forced Browsing')

<4.3.3-r12
  • L
Improper Certificate Validation

<4.3.3-r12
  • L
Directory Traversal

<4.3.3-r12
  • L
Cross-site Scripting (XSS)

<4.3.3-r12
  • L
Untrusted Search Path

<4.3.3-r11
  • C
CVE-2026-1229

<4.3.3-r10
  • C
CVE-2025-68121

<4.3.3-r8
  • M
Improper Validation of Integrity Check Value

<4.3.3-r9
  • L
CVE-2025-61732

<4.3.3-r8
  • L
Allocation of Resources Without Limits or Throttling

<4.3.3-r7
  • L
Allocation of Resources Without Limits or Throttling

<4.3.3-r7
  • L
CVE-2025-61731

<4.3.3-r7
  • L
Out-of-bounds Write

<4.3.3-r7
  • L
CVE-2025-61730

<4.3.3-r7
  • L
Improper Certificate Validation

<4.3.3-r5
  • L
Improper Certificate Validation

<4.3.3-r5
  • L
CVE-2025-47914

<4.3.3-r4
  • L
CVE-2025-58181

<4.3.3-r4
  • L
CVE-2025-47912

<4.3.3-r2
  • L
Allocation of Resources Without Limits or Throttling

<4.3.3-r2
  • L
CVE-2025-58183

<4.3.3-r2
  • L
Information Exposure Through Log Files

<4.3.3-r2
  • L
Algorithmic Complexity

<4.3.3-r2
  • L
CVE-2025-61725

<4.3.3-r2
  • L
Improper Certificate Validation

<4.3.3-r2
  • L
Allocation of Resources Without Limits or Throttling

<4.3.3-r2
  • L
CVE-2025-58186

<4.3.3-r2
  • L
Allocation of Resources Without Limits or Throttling

<4.3.3-r2
  • L
Link Following

<4.3.2-r2
  • L
CVE-2025-22874

<4.3.2-r2
  • L
CVE-2025-22872

<4.3.2-r1
  • L
Improper Validation of Specified Type of Input

<4.3.2-r2
  • L
Race Condition

<4.3.3-r1
  • L
CVE-2025-4673

<4.3.2-r2
  • L
CVE-2025-4674

<4.3.3-r0
  • L
CVE-2025-47906

<4.3.3-r1