Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

UNKNOWN
Go

CVE-2026-100836

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2025-71422

Contrast has insecure LUKS2 persistent storage partitions may be opened and used in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2025-71426

Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2025-71424

Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2025-71423

Contrast leaks workload secrets to logs on INFO level in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2025-71425

Contrast workload secrets leak to logs on INFO level in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2026-100838

Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2026-100837

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2026-100839

Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast

UNKNOWN
Go

CVE-2026-53493

Containerd has image-pull DoS via crafted OCI index graph amplification

UNKNOWN
Go

CVE-2026-84445

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

HIGH 8.2
Go

CVE-2026-65838

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

MEDIUM 5.3
Go

CVE-2026-79778

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

MEDIUM 5.3
Go

CVE-2026-79779

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

UNKNOWN
Go

CVE-2026-40575

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy

UNKNOWN
Go

CVE-2026-55770

OpenBao: LDAPi ldaputil (wrong escape func) in github.com/openbao/openbao

LOW 3.6
Go

CVE-2026-79783

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

LOW 3.1
Go

CVE-2026-79782

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

MEDIUM 6.5
Go

CVE-2026-79781

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

UNKNOWN
Go

CVE-2026-55776

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types in github.com/openbao/openbao

UNKNOWN
Go

CVE-2026-79777

Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone

UNKNOWN
Go

CVE-2026-84195

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno

MEDIUM 5.3
Go

CVE-2026-79780

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

UNKNOWN
Go

CVE-2026-55774

OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808 in github.com/openbao/openbao

UNKNOWN
Go

CVE-2026-84196

Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno

UNKNOWN
Go

CVE-2026-84200

Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno

UNKNOWN
Go

CVE-2026-55775

OpenBao's System Backend allows Unauthorized Management of the containing Namespace in github.com/openbao/openbao

UNKNOWN
Go

CVE-2026-54917

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs

UNKNOWN
Go

CVE-2026-56859

Add recursion depth guard during decode in encoding/xml

UNKNOWN
Go

CVE-2026-56860

Avoid quadratic complexity in resolvePath in net/url

UNKNOWN
Go

CVE-2026-42504

Quadratic complexity in WordDecoder.DecodeHeader in mime

UNKNOWN
Go

CVE-2026-33818

Enforce maximum recursion depth in encoding/asn1

UNKNOWN
Go

CVE-2026-56858

Fix Javascript regexp context tracking in html/template

UNKNOWN
Go

CVE-2026-56862

Limit handshake messages we are willing to accept post-handshake in crypto/tls

MEDIUM 6.5
Go

CVE-2026-88016

rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

Ready to move

Start Securing

Free, no credit card | First findings in minutes