Dependency scanning
Check whether github.com/cloudreve/Cloudreve/v4 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-77633
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
CVE-2026-79913
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
CVE-2026-77637
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope
GO-2026-6289
Cloudreve's remote download file paths can escape the selected destination directory
CVE-2026-54563
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
CVE-2026-54563
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve
GO-2026-6287
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
GHSA-vx2m-jpxr-xv7w
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve
GHSA-w8j7-39hp-8x59
Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve
GO-2026-6106
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
CVE-2026-55497
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
CVE-2026-55499
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
CVE-2026-55496
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
CVE-2026-55495
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
CVE-2026-55502
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
CVE-2026-62323
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
CVE-2026-55495
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve
CVE-2026-55502
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve
CVE-2026-55499
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve
CVE-2026-55496
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve
GHSA-v6w6-358x-2433
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
CVE-2026-55497
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve
CVE-2026-62323
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve
CVE-2026-54560
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
CVE-2026-54562
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
CVE-2026-54560
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve
CVE-2026-54562
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve
CVE-2026-25726
Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding)
CVE-2026-25726
Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) in github.com/cloudreve/Cloudreve
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes