4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/google/go-attestation is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-12681
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation
MEDIUM 6.8
CVE-2026-12681
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
MEDIUM 4.0
CVE-2022-0317
Go-Attestation Improper Input Validation with attacker-controlled TPM Quote
UNKNOWN
CVE-2022-0317
Improper input validation in github.com/google/go-attestation
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes