4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/golang-jwt/jwt/v4 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2025-30204
jwt-go allows excessive memory allocation during header parsing
LOW 3.1
CVE-2024-51744
Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations
UNKNOWN
CVE-2025-30204
Excessive memory allocation during header parsing in github.com/golang-jwt/jwt
UNKNOWN
CVE-2024-51744
Improper error handling in ParseWithClaims and bad documentation may cause dangerous situations in github.com/golang-jwt/jwt
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes