Go Getter

Vendor:

First CVE: Apr 27, 2022 · Active for 4 years

9
Total CVEs
More Total CVEs than 88% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Go Getter over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2022
4 years ago
Most Recent CVE
Aug 15, 2025
347 days ago

CVE Severity & Scoring

Go Getter9 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.
May 25, 20229.831NONO
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and p
Apr 17, 20249.829NONO
go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
May 25, 20228.628NONO
go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.
May 25, 20228.628NONO
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
May 25, 20228.628NONO
HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vu
Aug 15, 20257.527NONO
HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
Jun 25, 20248.826NONO
HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
Feb 16, 20236.521NONO
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
Apr 27, 20225.520NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Go Getter

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.1.116.50.4%00
2.0.248.91.9%00