Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
UNKNOWN
CVE-2026-100836
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast
UNKNOWN
CVE-2025-71422
Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast
UNKNOWN
CVE-2025-71426
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast
UNKNOWN
CVE-2025-71424
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast
UNKNOWN
CVE-2025-71423
Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast
UNKNOWN
CVE-2025-71425
Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast
UNKNOWN
CVE-2026-100838
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast
UNKNOWN
CVE-2026-100837
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast
UNKNOWN
CVE-2026-100839
Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast
UNKNOWN
CVE-2026-53493
Containerd has image-pull DoS via crafted OCI index graph amplification
UNKNOWN
CVE-2026-84445
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
HIGH 8.2
CVE-2026-65838
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
MEDIUM 5.3
CVE-2026-79778
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
MEDIUM 5.3
CVE-2026-79779
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
UNKNOWN
CVE-2026-40575
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy
UNKNOWN
CVE-2026-55770
OpenBao: LDAPi ldaputil (wrong escape func) in github.com/openbao/openbao
LOW 3.6
CVE-2026-79783
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
LOW 3.1
CVE-2026-79782
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
MEDIUM 6.5
CVE-2026-79781
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
UNKNOWN
CVE-2026-55776
OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types in github.com/openbao/openbao
UNKNOWN
CVE-2026-79777
Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
UNKNOWN
CVE-2026-84195
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
MEDIUM 5.3
CVE-2026-79780
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
UNKNOWN
CVE-2026-55774
OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808 in github.com/openbao/openbao
UNKNOWN
CVE-2026-84196
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
UNKNOWN
CVE-2026-84200
Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
UNKNOWN
CVE-2026-55775
OpenBao's System Backend allows Unauthorized Management of the containing Namespace in github.com/openbao/openbao
UNKNOWN
CVE-2026-54917
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs
UNKNOWN
CVE-2026-56859
Add recursion depth guard during decode in encoding/xml
UNKNOWN
CVE-2026-56860
Avoid quadratic complexity in resolvePath in net/url
UNKNOWN
CVE-2026-42504
Quadratic complexity in WordDecoder.DecodeHeader in mime
UNKNOWN
CVE-2026-33818
Enforce maximum recursion depth in encoding/asn1
UNKNOWN
CVE-2026-56858
Fix Javascript regexp context tracking in html/template
UNKNOWN
CVE-2026-56862
Limit handshake messages we are willing to accept post-handshake in crypto/tls
MEDIUM 6.5
CVE-2026-88016
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
Ready to move
Start Securing
Free, no credit card | First findings in minutes