Dependency scanning
Check whether kubevirt.io/kubevirt is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-9804
KubeVirt has a Link Following issue
CVE-2026-6383
KubeVirt's authorization mechanism improperly truncates subresource names
CVE-2025-64433
KubeVirt Arbitrary Container File Read
CVE-2026-7374
KubeVirt has a Link Following vulnerability
CVE-2025-64434
KubeVirt's Improper TLS Certificate Management Handling Allows API Identity Spoofing
CVE-2025-64435
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
CVE-2025-64436
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
CVE-2025-64324
KubeVirt Vulnerable to Arbitrary Host File Read and Write
CVE-2025-64437
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
CVE-2025-64432
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
CVE-2024-33394
kubevirt allows a local attacker to execute arbitrary code via a crafted command
CVE-2024-31420
KubeVirt NULL pointer dereference flaw
CVE-2022-1798
KubeVirt vulnerable to arbitrary file read on host
CVE-2022-1798
Duplicate Advisory: KubeVirt arbitrary host file read from the VM
CVE-2025-14525
KubeVirt Guest Agent DoS via Excessive Network Interface Reports
CVE-2026-7374
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt
CVE-2026-9804
KubeVirt has a Link Following issue in kubevirt.io/kubevirt
CVE-2026-6383
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt
CVE-2024-31420
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt
CVE-2025-64435
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt
CVE-2025-14525
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt
CVE-2024-33394
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt
CVE-2025-64437
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt
CVE-2025-64324
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt
CVE-2025-64433
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt
CVE-2025-64432
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt
CVE-2025-64434
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt
GHSA-qv98-3369-g364
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt
CVE-2020-14316
Privilege Escalation in kubevirt in kubevirt.io/kubevirt
CVE-2020-1701
Permissions bypass in KubeVirt in kubevirt.io/kubevirt
CVE-2020-14316
Privilege Escalation in kubevirt
CVE-2020-1701
Permissions bypass in KubeVirt
CVE-2023-26484
On a compromised node, the virt-handler service account can be used to modify all node specs
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes