Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 8.6
Go

CVE-2025-71261

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

HIGH 7.5
Go

CVE-2026-39829

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

HIGH 7.2
Go

CVE-2026-7461

Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure

HIGH 8.8
Go

CVE-2026-52800

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

HIGH 7.8
Go

CVE-2026-45152

uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution

HIGH 8.3
Go

CVE-2025-54286

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

HIGH 8.8
Go

CVE-2025-53513

Juju zip slip vulnerability via authenticated endpoint

HIGH 8.1
Go

CVE-2024-5154

malicious container creates symlink "mtab" on the host External

HIGH 8.0
Go

CVE-2023-22648

Rancher's Azure AD permission changes are not reflected on active sessions

HIGH 8.8
Go

CVE-2023-25307

mrpack-install vulnerable to path traversal with dependency

HIGH 8.8
Go

CVE-2024-6984

Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm

HIGH 7.5
Go

CVE-2023-49568

Maliciously crafted Git server replies can cause DoS on go-git clients

HIGH 8.0
Go

CVE-2024-1485

registry-support: decompress can delete files outside scope via relative paths

HIGH 7.5
Go

GHSA-vfvf-6gx5-mqv6

Incorrect Authorization in ORY Oathkeeper

HIGH 7.5
Go

CVE-2022-25856

Insecure path traversal in Git Trigger Source can lead to arbitrary file read

HIGH 7.5
Go

CVE-2020-7711

goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures

HIGH 7.5
Go

CVE-2020-7667

github.com/sassoftware/go-rpmutils Arbitrary File Write via Archive Extraction (Zip Slip)

HIGH 7.5
Go

CVE-2020-26160

Authorization bypass in github.com/dgrijalva/jwt-go

HIGH 7.5
Go

CVE-2022-21221

Path traversal in github.com/valyala/fasthttp

HIGH 7.5
Go

CVE-2020-28466

Denial of service in github.com/nats-io/nats-server/server

HIGH 7.5
Go

CVE-2022-25891

Shoutrrr util package DoS via sending 2000, 4000, or 6000 character messages

HIGH 8.8
Go

CVE-2022-1025

Argo CD improper access control bug can allow malicious user to escalate privileges to admin level

HIGH 7.5
Go

CVE-2022-2529

Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package

HIGH 7.5
Go

CVE-2021-21404

Crash due to malformed relay protocol message

HIGH 7.7
Go

CVE-2022-24348

Path traversal and dereference of symlinks in Argo CD

HIGH 7.5
Go

CVE-2022-27649

Podman's default inheritable capabilities for linux container not empty

HIGH 7.3
Go KEV

CVE-2021-39226

Authentication bypass for viewing and deletions of snapshots

HIGH 8.8
Go

CVE-2021-22538

Privilege escalation in rbac

HIGH 7.5
Go

CVE-2024-1394

Memory leaks in code encrypting and verifying RSA payloads

HIGH 7.7
Go

CVE-2021-21272

Zip slip directory exploit in github.com/deislabs/oras

HIGH 7.1
Go

CVE-2020-8918

TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm

HIGH 7.5
Go

CVE-2021-21403

Authentication Bypass by Primary Weakness in github.com/kongchuanhujiao/server

HIGH 7.5
Go

CVE-2021-43839

Drainage of FeeCollector's Block Transaction Fees in cronos

HIGH 7.2
Go

CVE-2021-21237

Git LFS can execute a Git binary from the current directory on Windows

HIGH 8.0
Go

CVE-2021-41088

Elvish vulnerable to remote code execution via the web UI backend

HIGH 8.1
Go

CVE-2020-15222

Token reuse in Ory fosite

HIGH 8.4
Go

CVE-2022-43760

Rancher UI has multiple Cross-Site Scripting (XSS) issues

HIGH 8.1
Go

CVE-2022-47633

kyverno verifyImages rule bypass possible with malicious proxy/registry

HIGH 8.0
Go

CVE-2021-43816

Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux

HIGH 7.5
Go

CVE-2021-29499

Predictable SIF UUID Identifiers in github.com/sylabs/sif

HIGH 7.5
Go

CVE-2021-3910

NUL character in ROA causes OctoRPKI to crash

HIGH 7.5
Go

CVE-2022-1708

Node DOS by way of memory exhaustion through ExecSync request in CRI-O

HIGH 8.1
Go

CVE-2021-41232

Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker

HIGH 7.5
Go

CVE-2021-21432

Reject unauthorized access with GitHub PATs

HIGH 7.5
Go KEV

CVE-2021-43798

Grafana path traversal

HIGH 7.5
Go

GO-2022-0406

Possible bypass of token claim validation when OAuth2 Introspection caching is enabled

HIGH 8.1
Go

CVE-2023-34758

Silver vulnerable to MitM attack against implants due to a cryptography vulnerability

HIGH 7.5
Go

CVE-2020-13846

"Verify All" Returns Success Despite Validation Failures in Singularity

HIGH 7.5
Go

CVE-2021-3761

OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values

HIGH 8.8
Go

CVE-2022-0811

Code Injection in CRI-O

HIGH 7.5
Go

CVE-2021-29482

github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

HIGH 8.5
Go

CVE-2021-32783

ExternalName Services can be used to gain access to Envoy's admin interface

HIGH 8.1
Go

CVE-2021-27098

Legacy Node API Allows Impersonation in github.com/spiffe/spire/pkg/server/endpoints/node

HIGH 7.5
Go

CVE-2023-1314

cloudflared's Installer has Local Privilege Escalation Vulnerability

HIGH 8.2
Go

CVE-2021-39183

Unsafe inline XSS in pasting DOM element into chat

HIGH 8.8
Go

CVE-2021-41254

Privilege escalation to cluster admin on multi-tenant environments

HIGH 8.1
Go

CVE-2021-39156

Istio Fragments in Path May Lead to Authorization Policy Bypass

HIGH 8.3
Go

CVE-2021-39155

Authorization Policy Bypass Due to Case Insensitive Host Comparison

Ready to move

Start Securing

Free, no credit card | First findings in minutes