Goreleaser is a release-automation tool with a focused product portfolio centered on the core release orchestrator and its companion package-management utility NFPM, both widely used in CI/CD pipelines for Go-based projects. The observed vulnerability pattern reflects configuration and information-handling issues, with exposures centered on default-permission logic and accidental logging of sensitive data.
The number and severity of CVEs published that impact products developed by Goreleaser over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32698HIGH nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged
the files (without extra config for enforcing it’s own p | May 30, 2023 | 7.1 | 22 | NO | NO |
CVE-2024-23840MEDIUM GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret | Jan 30, 2024 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goreleaser.
Media articles that mention a CVE ID that affects a product developed by Goreleaser — matched by CVE ID, not by vendor name.