9 Total advisories
9 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/kcp-dev/kcp is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.9
CVE-2026-61682
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
HIGH 8.2
CVE-2026-39429
kcp's cache server is accessible without authentication or authorization checks
UNKNOWN
CVE-2026-39429
kcp's cache server is accessible without authentication or authorization checks in github.com/kcp-dev/kcp
UNKNOWN
GHSA-q6hv-wcjr-wp8h
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace in github.com/kcp-dev/kcp
UNKNOWN
CVE-2025-29922
kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/kcp
UNKNOWN
GHSA-c7xh-gjv4-4jgv
kcp's impersonation allows access to global administrative groups in github.com/kcp-dev/kcp
UNKNOWN
GO-2025-3985
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
CRITICAL 9.6
CVE-2025-29922
kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace
MEDIUM 6.4
GO-2024-3325
kcp's impersonation allows access to global administrative groups
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes