Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 7.1
Go

CVE-2025-71426

Contrast's unauthenticated recovery allows Coordinator impersonation

HIGH 7.3
Go

CVE-2025-71423

Contrast leaks workload secrets to logs on INFO level

HIGH 7.3
Go

CVE-2025-71425

Contrast workload secrets leak to logs on INFO level

HIGH 8.1
Go

CVE-2026-100838

Contras Affected by CopyFile Policy Subversion via Symlinks

HIGH 8.4
Go

CVE-2026-100839

Contrast BadAML injection allows arbitrary code execution

HIGH 8.2
Go

CVE-2026-65838

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

HIGH 7.7
Go

CVE-2026-84195

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)

HIGH 7.7
Go

CVE-2026-84196

Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF

HIGH 7.5
Go

CVE-2026-57231

Podman: Malformed Image can trick podman run into leaking host environment variables into the container

HIGH 8.7
Go

CVE-2026-85057

ZITADEL: Actions V1 sandbox escape: host file read via require()

HIGH 8.2
Go

CVE-2026-85056

ZITADEL: MFA bypass via session reuse in Login V2

HIGH 7.7
Go

CVE-2026-58314

Gitea: Two SSRF findings

HIGH 7.5
Go

CVE-2026-34966

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

HIGH 7.5
Go

CVE-2026-86065

Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)

HIGH 8.6
Go

CVE-2026-86064

Klever-Go: /log controls global node logging

HIGH 7.1
Go

CVE-2026-77633

Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service

HIGH 8.6
Go

CVE-2026-76819

Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability

HIGH 8.8
Go

CVE-2026-62182

KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes

HIGH 8.1
Go

CVE-2026-62369

KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join

HIGH 8.8
Go

CVE-2026-62371

KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API

HIGH 8.1
Go

CVE-2026-77560

Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for

HIGH 7.5
Go

CVE-2026-77322

SIPGO: DoS via unvalidated WebSocket frame length

HIGH 7.5
Go

CVE-2026-58268

SIPGO: DoS via unvalidated Content-Length in the stream parser

HIGH 7.5
Go

CVE-2023-54365

Traefik vulnerable to HTTP/2 request causing denial of service

HIGH 7.5
Go

GHSA-pvrg-q6jw-42p7

Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service

HIGH 7.5
Go

CVE-2026-42127

Grafana: Pre-authentication denial of service in the public dashboard query handler

HIGH 7.3
Go

CVE-2026-9029

Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug

HIGH 7.7
Go

CVE-2026-42129

Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability.

HIGH 8.1
Go

CVE-2026-61628

nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition

HIGH 7.5
Go

CVE-2026-61629

nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware

HIGH 7.1
Go

CVE-2026-61687

Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState

HIGH 7.4
Go

CVE-2026-53714

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

HIGH 7.5
Go

CVE-2026-88045

rclone: S3 multipart declared-length memory exhaustion

HIGH 8.8
Go

GHSA-xwmw-prc4-v3cr

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

HIGH 7.6
Go

GHSA-jgh3-fggc-mcpm

Obot: Server-Side Request Forgery via remote MCP server URL

HIGH 8.8
Go

CVE-2026-58197

ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement

HIGH 7.1
Go

CVE-2026-61672

Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement

HIGH 8.1
Go

CVE-2026-61833

zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion

HIGH 7.5
Go

CVE-2026-82399

CoreDNS: Unauthenticated memory exhaustion in custom transports

HIGH 7.5
Go

CVE-2026-86003

CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP

HIGH 8.8
Go

GO-2026-6449

Komari: Management Interface CSRF

HIGH 7.8
Go

CVE-2026-59172

Joker linter executed project-local .jokerd/linter.* files during linting

HIGH 8.5
Go

CVE-2026-59185

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

HIGH 7.3
Go

CVE-2026-88017

rclone: FTP cross-session auth-proxy backend confusion

HIGH 8.1
Go

CVE-2026-56668

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange

HIGH 8.8
Go

CVE-2026-85731

oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)

HIGH 7.5
Go

CVE-2026-86043

Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)

HIGH 8.3
Go

CVE-2026-63443

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

HIGH 7.5
Go

CVE-2026-61554

emp3r0r has an unauthenticated HTTP Polling DoS

HIGH 8.5
Go

CVE-2026-55108

KubeVela Terraform remote loader DoS via unbounded file read

HIGH 8.6
Go

CVE-2026-72789

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

HIGH 8.6
Go

CVE-2026-68587

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

HIGH 7.5
Go

CVE-2026-27660

Gitea draft releases and attachments are exposed without write permission

HIGH 8.6
Go

CVE-2026-72810

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

HIGH 7.5
Go

CVE-2026-27779

Gitea forwarded-proto validation allows canonical URL spoofing

HIGH 7.7
Go

CVE-2026-59832

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

HIGH 8.6
Go

CVE-2026-72795

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

HIGH 8.0
Go

CVE-2026-72809

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy

HIGH 7.5
Go

CVE-2026-73232

ffuf denial of service (OOM) via HTTP response decompression bomb

HIGH 7.5
Go

CVE-2026-72801

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

Ready to move

Start Securing

Free, no credit card | First findings in minutes