Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 5.9
Go

CVE-2026-6815

Casdoor: Arbitrary file write possible through Local File System storage provider

CRITICAL 9.6
Go

CVE-2026-53649

Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

CRITICAL 10.0
Go

CVE-2026-50197

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

CRITICAL 10.0
Go

CVE-2026-52831

Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE

UNKNOWN
Go

CVE-2026-39822

Root escape via symlink plus trailing slash in os

UNKNOWN
Go

CVE-2026-42505

Invoking Encrypted Client Hello privacy leak in crypto/tls

UNKNOWN
Go

CVE-2026-40179

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

UNKNOWN
Go

CVE-2026-54685

FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel in github.com/gtsteffaniak/filebrowser/backend

HIGH 8.6
Go

CVE-2025-71261

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

MEDIUM 5.3
Go

CVE-2026-39835

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

CRITICAL 9.1
Go

CVE-2026-42508

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

CRITICAL 10.0
Go

CVE-2026-46595

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

CRITICAL 9.1
Go

CVE-2026-39830

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

CRITICAL 9.1
Go

CVE-2026-39832

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

MEDIUM 6.3
Go

CVE-2026-39828

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

HIGH 7.5
Go

CVE-2026-39829

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

UNKNOWN
Go

GO-2026-5932

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

UNKNOWN
Go

CVE-2026-49835

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality in github.com/sigstore/timestamp-authority

UNKNOWN
Go

CVE-2026-21728

Grafana Tempo has an Uncontrolled Resource Consumption issue in github.com/grafana/tempo

UNKNOWN
Go

CVE-2026-41579

Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2026-48702

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic in github.com/sigstore/rekor

UNKNOWN
Go

CVE-2026-53935

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation in github.com/cilium/cilium

UNKNOWN
Go

CVE-2026-33811

Crash when handling long CNAME response in net

UNKNOWN
Go

CVE-2025-21613

Argument Injection via the URL field in github.com/go-git/go-git

UNKNOWN
Go

CVE-2026-27145

Inefficient candidate hostname parsing in crypto/x509

UNKNOWN
Go

CVE-2026-39821

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

UNKNOWN
Go

CVE-2026-25679

Incorrect parsing of IPv6 host literals in net/url

UNKNOWN
Go

CVE-2026-27018

Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)

CRITICAL 9.3
Go

CVE-2026-40280

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

MEDIUM 5.3
Go

CVE-2026-39882

opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies

UNKNOWN
Go

CVE-2026-58403

Hugo: Symlink confinement bypass in os.ReadFile

UNKNOWN
Go

CVE-2026-56395

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

UNKNOWN
Go

CVE-2026-7461

Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure in github.com/aws/amazon-ecs-agent

UNKNOWN
Go

CVE-2026-41282

Nuclei: Environment variable disclosure via Response-Derived DSL Expressions in github.com/projectdiscovery/nuclei

HIGH 8.8
Go

CVE-2026-52800

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

HIGH 7.8
Go

CVE-2026-45152

uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution

UNKNOWN
Go

CVE-2026-58404

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

UNKNOWN
Go

CVE-2026-58402

Hugo: XSS via unescaped code-fence language in default code block renderer

UNKNOWN
Go

CVE-2026-12681

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation

UNKNOWN
Go

CVE-2026-42880

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction in github.com/argoproj/argo-cd

MEDIUM 4.1
Go

CVE-2025-54288

Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server

MEDIUM 6.5
Go

CVE-2025-54287

Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns

HIGH 8.3
Go

CVE-2025-54286

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

MEDIUM 6.8
Go

CVE-2025-54289

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

MEDIUM 6.5
Go

CVE-2025-26260

Plenti - Code Injection - Denial of Services

MEDIUM 6.5
Go

CVE-2024-3250

Pebble service manager's file pull API allows access by any user

MEDIUM 4.0
Go

CVE-2024-5138

CVE-2024-5138: snapd snapctl auth bypass

HIGH 8.8
Go

CVE-2025-53513

Juju zip slip vulnerability via authenticated endpoint

HIGH 8.1
Go

CVE-2024-5154

malicious container creates symlink "mtab" on the host External

UNKNOWN
Go

CVE-2025-45286

Reflected XSS in go-httpbin due to unrestricted client control over Content-Type

MEDIUM 6.5
Go

CVE-2025-54293

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

Ready to move

Start Securing

Free, no credit card | First findings in minutes