Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.6
Go

CVE-2026-53649

Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

CRITICAL 10.0
Go

CVE-2026-50197

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

CRITICAL 10.0
Go

CVE-2026-52831

Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE

CRITICAL 9.1
Go

CVE-2026-42508

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

CRITICAL 10.0
Go

CVE-2026-46595

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

CRITICAL 9.1
Go

CVE-2026-39830

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

CRITICAL 9.1
Go

CVE-2026-39832

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

CRITICAL 9.3
Go

CVE-2026-40280

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

CRITICAL 9.6
Go

CVE-2026-42880

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

CRITICAL 9.9
Go

CVE-2023-22647

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

CRITICAL 9.8
Go

CVE-2023-49569

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

CRITICAL 9.4
Go

CVE-2023-3128

Grafana vulnerable to Authentication Bypass by Spoofing

CRITICAL 9.1
Go

CVE-2021-23365

Authentication Bypass in tyk-identity-broker

CRITICAL 9.3
Go

CVE-2020-26290

Critical security issues in XML encoding in github.com/dexidp/dex

CRITICAL 9.1
Go

CVE-2023-50422

Improper Privilege Management in github.com/sap/cloud-security-client-go

CRITICAL 9.9
Go

CVE-2022-1025

Improper access control allows admin privilege escalation in Argo CD

CRITICAL 9.1
Go

CVE-2021-41244

Grafana Fine-grained access control vulnerability

CRITICAL 9.9
Go

CVE-2021-36782

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

CRITICAL 9.8
Go

CVE-2021-28955

Arbitrary code execution due to an uncontrolled search path for the git binary

CRITICAL 9.1
Go

CVE-2022-31247

Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

CRITICAL 9.9
Go

CVE-2021-36783

Rancher doesn't properly sanitize credentials in cluster template answers

CRITICAL 9.8
Go

CVE-2022-31836

Path Traversal in Beego

CRITICAL 10.0
Go

CVE-2021-32637

Authelia vulnerable to an authentication bypassed with malformed request URI on nginx

CRITICAL 9.8
Go

CVE-2022-31259

Access control bypass in beego

CRITICAL 9.9
Go

CVE-2023-22651

Rancher Webhook is misconfigured during upgrade process

CRITICAL 9.1
Go

CVE-2026-41328

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

CRITICAL 9.6
Go

CVE-2026-53552

Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers

CRITICAL 9.9
Go

CVE-2026-48752

Incus has arbitrary file read+write on host via templates/ symlink in malicious image

CRITICAL 9.9
Go

CVE-2026-48750

Incus has an arbitrary file write on host via `exec-output` symlink in crafted image

CRITICAL 9.9
Go

CVE-2026-48749

Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image

CRITICAL 9.9
Go

CVE-2026-48755

Incus has an argument injection in backup compression algorithm leading to AFW and ACE

CRITICAL 9.9
Go

CVE-2026-48751

Incus has a restricted project bypass leading to arbitrary command execution

CRITICAL 9.9
Go

CVE-2026-48769

Incus has an arbitrary file write on its client due to trusted image hash

CRITICAL 9.1
Go

CVE-2025-66719

Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value

CRITICAL 9.9
Go

CVE-2026-48753

Incus has an arbitrary file write via path traversal in S3 multipart upload

CRITICAL 9.6
Go

CVE-2026-41589

Wish has SCP Path Traversal that allows arbitrary file read/write

CRITICAL 9.9
Go

GO-2026-5821

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

CRITICAL 9.9
Go

CVE-2026-7374

KubeVirt has a Link Following vulnerability

CRITICAL 9.9
Go

CVE-2026-50545

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

CRITICAL 9.9
Go

CVE-2026-50563

Fission Container Executor Function PodSpec Injection Leading to Node Escape

CRITICAL 9.1
Go

CVE-2026-53519

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

CRITICAL 9.9
Go

CVE-2026-50564

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

CRITICAL 9.1
Go

CVE-2026-9098

Casdoor SAML callback handler accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest

CRITICAL 9.6
Go

CVE-2026-44939

Rancher vulnerable to command injection through unsanitized YAML parameter

CRITICAL 9.1
Go

CVE-2026-9090

Casdoor has an authentication bypass

CRITICAL 9.8
Go

CVE-2026-9097

Casdoor doesn't verify that a JWT used for token exchange is still active

CRITICAL 9.2
Go

CVE-2026-49445

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

CRITICAL 9.9
Go

CVE-2026-44935

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

CRITICAL 9.9
Go

CVE-2026-50566

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

CRITICAL 9.8
Go

CVE-2026-9093

Casdoor does not validate the AudienceRestriction element in SAML assertions

CRITICAL 9.1
Go

CVE-2026-39834

golang.org/x/crypto vulnerable to infinite loop on large channel writes

CRITICAL 9.1
Go

CVE-2026-39833

golang.org/x/crypto doesn't enforce invoking key constraints

CRITICAL 9.1
Go

CVE-2026-39831

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

CRITICAL 9.8
Go

CVE-2024-23827

Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature

CRITICAL 9.8
Go

CVE-2026-26190

Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise

CRITICAL 9.8
Go

CVE-2020-36645

Squalor SQL Injection vulnerability

CRITICAL 9.8
Go

CVE-2025-8077

NeuVector admin account has insecure default password

CRITICAL 9.1
Go

CVE-2024-22036

Rancher Remote Code Execution via Cluster/Node Drivers

Ready to move

Start Securing

Free, no credit card | First findings in minutes