Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.1
Go

CVE-2026-40575

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

CRITICAL 9.0
Go

CVE-2026-84200

Bypassing Kyverno Policies via Double Policy Exceptions

CRITICAL 9.0
Go

CVE-2026-12249

Canonical ADSys Uses a Less Trusted Source

CRITICAL 9.1
Go

CVE-2026-53713

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure

CRITICAL 9.1
Go

CVE-2026-88044

rclone: RC per-server auth-proxy bypass

CRITICAL 9.9
Go

CVE-2026-61682

kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace

CRITICAL 9.8
Go

CVE-2026-88018

rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

CRITICAL 9.1
Go

CVE-2026-71485

Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends

CRITICAL 9.1
Go

CVE-2026-39830

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

CRITICAL 9.6
Go

GHSA-24r3-p3x6-cqvx

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

CRITICAL 9.8
Go

CVE-2026-72920

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

CRITICAL 9.8
Go

CVE-2026-27780

Gitea pre-receive hook scanner errors allow branch-protection bypass

CRITICAL 9.6
Go

CVE-2026-73843

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

CRITICAL 9.8
Go KEV

CVE-2026-60004

Gitea: Remote Code Execution via diffpatch Git Hook Installation

CRITICAL 10.0
Go

CVE-2026-69084

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

CRITICAL 9.0
Go

CVE-2026-73842

OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

CRITICAL 9.1
Go

CVE-2026-11720

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints

CRITICAL 9.8
Go

CVE-2026-26292

Gitea LFS mirror operations bypass migration HTTP transport protections

CRITICAL 10.0
Go

CVE-2026-69083

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

CRITICAL 9.9
Go

CVE-2026-73294

Semaphore U: OS Command Injection

CRITICAL 10.0
Go

CVE-2026-72811

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

CRITICAL 9.1
Go

CVE-2026-7482

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

CRITICAL 9.1
Go

CVE-2026-41328

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

CRITICAL 9.8
Go

CVE-2026-41492

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

CRITICAL 9.1
Go

CVE-2025-41118

Pyroscope Exposes Storage Secret

CRITICAL 9.4
Go

CVE-2026-40173

Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints

CRITICAL 9.8
Go

CVE-2025-8077

NeuVector admin account has insecure default password

CRITICAL 9.0
Go

CVE-2025-49136

listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user

CRITICAL 9.9
Go

CVE-2025-32445

Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR

CRITICAL 9.8
Go

CVE-2025-1974

ingress-nginx admission controller RCE escalation

CRITICAL 9.1
Go

CVE-2024-45337

Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto

CRITICAL 9.1
Go

CVE-2026-54061

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

CRITICAL 9.1
Go

CVE-2026-73501

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

CRITICAL 9.9
Go

CVE-2026-54680

Logging operator has Fluentd configuration injection that allows remote code execution

CRITICAL 9.6
Go

CVE-2026-44939

Rancher vulnerable to command injection through unsanitized YAML parameter

CRITICAL 10.0
Go

CVE-2026-46595

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

CRITICAL 9.0
Go

GO-2026-5709

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

CRITICAL 9.1
Go

CVE-2026-39834

golang.org/x/crypto vulnerable to infinite loop on large channel writes

CRITICAL 9.8
Go

CVE-2026-49980

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

CRITICAL 9.1
Go

CVE-2026-39833

golang.org/x/crypto doesn't enforce invoking key constraints

CRITICAL 9.9
Go

CVE-2026-50195

containerd: CRI checkpoint import allows local image tag poisoning

CRITICAL 9.1
Go

CVE-2026-39832

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

CRITICAL 10.0
Go

CVE-2026-53622

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

CRITICAL 9.1
Go

CVE-2026-39831

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

CRITICAL 9.1
Go

CVE-2026-42508

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

CRITICAL 9.9
Go

CVE-2026-7374

KubeVirt has a Link Following vulnerability

CRITICAL 9.9
Go

CVE-2026-44477

CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

CRITICAL 9.6
Go

CVE-2026-42880

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

CRITICAL 9.8
Go

CVE-2026-33815

pgx contains memory-safety vulnerability

CRITICAL 10.0
Go

CVE-2026-34976

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

CRITICAL 9.1
Go

CVE-2026-41327

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

CRITICAL 9.8
Go

CVE-2026-41179

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

CRITICAL 9.8
Go

CVE-2026-33816

Memory-safety vulnerability in github.com/jackc/pgx/v5.

CRITICAL 9.8
Go

CVE-2026-41176

Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution

CRITICAL 10.0
Go

CVE-2026-30836

step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)

CRITICAL 9.1
Go

CVE-2026-33186

gRPC-Go has an authorization bypass via missing leading slash in :path

CRITICAL 9.6
Go

CVE-2026-33211

Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod

CRITICAL 9.8
Go

CVE-2026-33032

nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

CRITICAL 9.9
Go

CVE-2021-25320

Rancher cloud credentials can be used through proxy API by users without access

CRITICAL 9.9
Go

CVE-2026-22039

Kyverno Cross-Namespace Privilege Escalation via Policy apiCall

Ready to move

Start Securing

Free, no credit card | First findings in minutes