Go Getter
Vendor:
First CVE: Apr 27, 2022 · Active for 4 years
9
Total CVEs
More Total CVEs than 88% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Go Getter over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2022
4 years ago
Most Recent CVE
Aug 15, 2025
347 days ago
CVE Severity & Scoring
Go Getter9 CVEs
22%
56%
22%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26945CRITICAL go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1. | May 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-3817CRITICAL HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches.
This vulnerability does not affect the go-getter/v2 branch and p | Apr 17, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-30323HIGH go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0. | May 25, 2022 | 8.6 | 28 | NO | NO |
CVE-2022-30322HIGH go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0. | May 25, 2022 | 8.6 | 28 | NO | NO |
CVE-2022-30321HIGH go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0. | May 25, 2022 | 8.6 | 28 | NO | NO |
CVE-2025-8959HIGH HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vu | Aug 15, 2025 | 7.5 | 27 | NO | NO |
CVE-2024-6257HIGH HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution. | Jun 25, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-0475MEDIUM HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0. | Feb 16, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-29810MEDIUM The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter. | Apr 27, 2022 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Go Getter
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.1 | 1 | 6.5 | 0.4% | 0 | 0 |
| 2.0.2 | 4 | 8.9 | 1.9% | 0 | 0 |