10 Total advisories
10 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/sigstore/rekor is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-48702
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic in github.com/sigstore/rekor
HIGH 7.5
CVE-2026-48702
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic
UNKNOWN
CVE-2023-33199
malformed proposed intoto entries can cause a panic in github.com/sigstore/rekor
MEDIUM 5.3
CVE-2026-23831
Rekor's COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty Message
MEDIUM 5.3
CVE-2023-33199
malformed proposed intoto entries can cause a panic
UNKNOWN
CVE-2023-30551
Rekor's compressed archives can result in OOM conditions in github.com/sigstore/rekor
UNKNOWN
CVE-2026-23831
Rekor's COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty Message in github.com/sigstore/rekor
UNKNOWN
CVE-2026-24117
Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL in github.com/sigstore/rekor
HIGH 7.5
CVE-2023-30551
Rekor's compressed archives can result in OOM conditions
MEDIUM 5.3
CVE-2026-24117
Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes