Dependency scanning
Check whether github.com/containers/podman/v4 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-57231
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
CVE-2025-9566
podman kube play symlink traversal vulnerability
CVE-2026-33414
PowerShell Command Injection in Podman HyperV Machine
CVE-2024-3056
Podman vulnerable to memory-based denial of service
CVE-2025-6032
Podman Improper Certificate Validation; machine missing TLS verification
CVE-2024-9407
Improper Input Validation in Buildah and Podman
CVE-2024-1753
Podman affected by CVE-2024-1753 container escape at build time
CVE-2022-27649
Podman's default inheritable capabilities for linux container not empty
CVE-2026-55686
Podman: WORKDIR symlink traversal vulnerability
CVE-2026-55686
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman
CVE-2026-33414
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman
CVE-2018-10856
Podman Elevated Container Privileges in github.com/containers/podman
CVE-2019-18466
Podman Symlink Vulnerability in github.com/containers/libpod
CVE-2022-4122
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman
CVE-2022-27649
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman
CVE-2025-9566
podman kube play symlink traversal vulnerability in github.com/containers/podman
CVE-2025-4953
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman
CVE-2022-2989
Podman's incorrect handling of the supplementary groups may lead to data disclosure, modification
CVE-2024-3056
Podman vulnerable to memory-based denial of service in github.com/containers/podman
CVE-2024-9407
Improper Input Validation in Buildah and Podman in github.com/containers/buildah
CVE-2025-6032
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman
CVE-2022-4122
Buildah (as part of Podman) vulnerable to Link Following
CVE-2019-18466
Podman Symlink Vulnerability
CVE-2023-0778
Podman Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2022-4123
Buildah (as part of Podman) vulnerable to Path Traversal
CVE-2023-0778
Time-of-check time-of-use race condition in github.com/containers/podman/v4
CVE-2022-4123
Path traversal in github.com/containers/podman/v4
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes