Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

LOW 3.5
Go

CVE-2025-71424

Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points

LOW 3.7
Go

CVE-2026-100837

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

LOW 3.6
Go

CVE-2026-79783

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

LOW 3.1
Go

CVE-2026-79782

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

LOW 2.7
Go

CVE-2026-79777

rclone: Verbose Stack Trace Disclosure in RC API Error Responses

LOW 3.8
Go

CVE-2026-77637

Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope

LOW 3.1
Go

CVE-2026-84298

Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher

LOW 3.8
Go

CVE-2026-8823

Mattermost has an Incorrect Authorization issue

LOW 3.7
Go

CVE-2026-88013

rclone: http backend forwards custom/auth headers to a different host on redirect

LOW 3.7
Go

CVE-2025-24978

LF Edge eKuiper: Self-XSS in External Service Creation

LOW 3.8
Go

CVE-2026-8074

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

LOW 3.7
Go

GO-2026-6265

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

LOW 2.6
Go

GO-2026-6262

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

LOW 3.1
Go

CVE-2026-54787

sigstore-go fails to check signature timestamps against a signing key's validity period

LOW 3.3
Go

CVE-2026-10722

ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader

LOW 3.3
Go

CVE-2026-41579

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

LOW 3.5
Go

CVE-2026-45781

MCP Registry: OCI validator skips ownership check on upstream rate limits

LOW 3.1
Go

CVE-2026-39396

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

LOW 3.1
Go

CVE-2026-74797

OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format

LOW 2.2
Go

CVE-2025-27538

Mattermost Missing Authentication for Critical Function

LOW 3.1
Go

CVE-2025-24839

Mattermost Incorrect Authorization vulnerability

LOW 3.3
Go

CVE-2025-46327

Go Snowflake Driver has race condition when checking access to Easy Logging configuration file

LOW 3.5
Go

CVE-2025-22445

Mattermost has Improper Check for Unusual or Exceptional Conditions

LOW 3.1
Go

GO-2026-5558

OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server

LOW 3.1
Go

CVE-2026-39388

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

LOW 2.8
Go

CVE-2026-33762

go-git missing validation decoding Index v4 files leads to panic

LOW 3.7
Go

CVE-2026-24122

Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped

LOW 3.1
Go

CVE-2026-24513

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

LOW 3.8
Go

CVE-2025-67860

NeuVector scanner insecurely handles passwords as command arguments

LOW 3.1
Go

GO-2025-4101

OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses

LOW 2.7
Go

CVE-2025-65942

VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM

LOW 3.7
Go

CVE-2025-6011

Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users

LOW 3.3
Go

CVE-2025-54410

Moby firewalld reload removes bridge network isolation

LOW 2.7
Go

CVE-2025-4563

kubernetes allows nodes to bypass dynamic resource allocation authorization checks

LOW 3.1
Go

CVE-2025-4656

Vault Community Edition rekey and recovery key operations can cause denial of service

LOW 2.7
Go

CVE-2025-1088

Grafana long dashboard title or panel name causes unresponsives

LOW 3.1
Go

CVE-2025-52996

File Browser's password protection of links is bypassable

LOW 3.7
Go

CVE-2025-8556

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

LOW 3.1
Go

CVE-2025-41423

Mattermost Playbooks fails to properly validate permissions

LOW 3.0
Go

CVE-2025-31363

Mattermost doesn't restrict domains LLM can request to contact upstream

LOW 3.1
Go

CVE-2024-7598

Kubernetes kube-apiserver Vulnerable to Race Condition

LOW 3.7
Go

CVE-2025-29923

go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment

LOW 3.8
Go

CVE-2025-22449

Mattermost Incorrect Authorization vulnerability

LOW 3.3
Go

CVE-2024-51491

notation-go has an OS error when setting CRL cache leads to denial of signature verification

LOW 3.1
Go

CVE-2024-51744

Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations

LOW 3.5
Go

CVE-2024-10214

Mattermost incorrectly issues two sessions when using desktop SSO

LOW 2.2
Go

CVE-2024-10452

Grafana org admin can delete pending invites in different org

LOW 3.1
Go

CVE-2024-45395

sigstore-go has an unbounded loop over untrusted input can lead to endless data attack

LOW 3.6
Go

CVE-2024-45310

runc can be confused to create empty files/directories on the host

LOW 3.7
Go

CVE-2023-30464

CoreDNS Cache Poisoning via a birthday attack

LOW 2.8
Go

CVE-2021-41089

`docker cp` allows unexpected chmod of host files in Moby Docker Engine

LOW 3.5
Go

CVE-2024-32873

evmos allows transferring unvested tokens after delegations

LOW 3.7
Go

CVE-2024-38361

SpiceDB exclusions can result in no permission returned when permission expected

LOW 3.5
Go

CVE-2024-34713

sshproxy vulnerable to SSH option injection

LOW 3.7
Go

CVE-2024-34079

octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage

LOW 3.1
Go

CVE-2024-21848

Mattermost Server Improper Access Control

LOW 2.7
Go

CVE-2024-3177

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

LOW 2.2
Go

CVE-2024-32001

SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used

LOW 3.7
Go

CVE-2024-35232

github.com/huandu/facebook may expose access_token in error message.

LOW 2.0
Go

GO-2024-2703

Kopia: Storage connection credentials written to console on "repository status" CLI command with JSON output

Ready to move

Start Securing

Free, no credit card | First findings in minutes