17 Total advisories
17 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/containers/podman/v5 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-57231
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
MEDIUM 4.2
CVE-2026-19730
podman quadlet install --replace does not fully replace the old file
HIGH 8.1
CVE-2025-9566
podman kube play symlink traversal vulnerability
HIGH 7.8
CVE-2026-33414
PowerShell Command Injection in Podman HyperV Machine
MEDIUM 4.8
CVE-2024-3056
Podman vulnerable to memory-based denial of service
HIGH 7.4
CVE-2025-4953
Podman Creates Temporary File with Insecure Permissions
HIGH 8.3
CVE-2025-6032
Podman Improper Certificate Validation; machine missing TLS verification
MEDIUM 4.7
CVE-2024-9407
Improper Input Validation in Buildah and Podman
HIGH 8.6
CVE-2024-1753
Podman affected by CVE-2024-1753 container escape at build time
MEDIUM 5.3
CVE-2026-55686
Podman: WORKDIR symlink traversal vulnerability
UNKNOWN
CVE-2026-55686
Podman: WORKDIR symlink traversal vulnerability in github.com/containers/podman
UNKNOWN
CVE-2026-33414
PowerShell Command Injection in Podman HyperV Machine in github.com/containers/podman
UNKNOWN
CVE-2025-9566
podman kube play symlink traversal vulnerability in github.com/containers/podman
UNKNOWN
CVE-2025-4953
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman
UNKNOWN
CVE-2024-3056
Podman vulnerable to memory-based denial of service in github.com/containers/podman
UNKNOWN
CVE-2024-9407
Improper Input Validation in Buildah and Podman in github.com/containers/buildah
UNKNOWN
CVE-2025-6032
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes