17 Total advisories
17 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/containers/podman/v2 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-57231
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
MEDIUM 4.8
CVE-2024-3056
Podman vulnerable to memory-based denial of service
MEDIUM 4.7
CVE-2024-9407
Improper Input Validation in Buildah and Podman
UNKNOWN
CVE-2026-55686
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman
UNKNOWN
CVE-2026-33414
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman
UNKNOWN
CVE-2018-10856
Podman Elevated Container Privileges in github.com/containers/podman
UNKNOWN
CVE-2019-18466
Podman Symlink Vulnerability in github.com/containers/libpod
UNKNOWN
CVE-2022-4122
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman
UNKNOWN
CVE-2021-4024
Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman in github.com/containers/podman
UNKNOWN
CVE-2022-27649
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman
UNKNOWN
CVE-2025-9566
podman kube play symlink traversal vulnerability in github.com/containers/podman
UNKNOWN
CVE-2025-4953
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman
UNKNOWN
CVE-2024-3056
Podman vulnerable to memory-based denial of service in github.com/containers/podman
UNKNOWN
CVE-2024-9407
Improper Input Validation in Buildah and Podman in github.com/containers/buildah
UNKNOWN
CVE-2025-6032
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman
MEDIUM 5.9
CVE-2020-1726
Podman has Files or Directories Accessible to External Parties
MEDIUM 5.3
CVE-2020-14370
Information disclosure in podman
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes