Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

LOW 2.7
Go

CVE-2024-22261

SQL Injection in Harbor scan log API

LOW 3.0
Go

CVE-2021-41190

Clarify Content-Type handling

LOW 3.1
Go

CVE-2020-5303

Denial of service in Tendermint

LOW 3.7
Go

CVE-2020-15184

Aliases are never checked in helm

LOW 3.4
Go

CVE-2020-15186

Improper Sanitizing of plugin names in helm

LOW 2.2
Go

CVE-2020-15185

Repository index file allows for duplicates of the same chart entry in helm

LOW 2.8
Go

CVE-2021-41089

`docker cp` allows unexpected chmod of host files in Moby Docker Engine

LOW 3.0
Go

CVE-2020-15187

plugin.yaml file allows for duplicate entries in helm

LOW 3.7
Go

CVE-2020-4053

Plugin archive directory traversal in Helm

LOW 3.7
Go

CVE-2020-15106

Panic due to malformed WALs in go.etcd.io/etcd

LOW 3.3
Go

CVE-2026-41579

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

LOW 3.7
Go

GO-2026-5865

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

LOW 3.7
Go

CVE-2026-49245

SFTPGo has stored XSS via inline parameter on public shares and user file download

LOW 3.7
Go

GO-2024-3059

CosmWasm wasmd has large address count in ValidateBasic

LOW 3.4
Go

CVE-2025-30163

Cilium node based network policies may incorrectly allow workload traffic

LOW 3.8
Go

CVE-2024-6219

lxd has a restricted TLS certificate privilege escalation when in PKI mode

LOW 3.1
Go

GO-2026-5441

OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency responses

LOW 2.8
Go

GO-2026-5614

arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS

LOW 3.1
Go

GO-2026-5558

OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server

LOW 3.3
Go

CVE-2026-29051

melange has Path Traversal via .PKGINFO in --persist-lint-results

LOW 3.1
Go

CVE-2026-6334

Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow

LOW 3.1
Go

CVE-2026-4053

Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields

LOW 3.7
Go

CVE-2026-21388

Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint

LOW 3.8
Go

CVE-2026-3495

Mattermost doesn't escape some variables that could contain malicious content during error page composition

LOW 3.7
Go

CVE-2026-40263

Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel

LOW 2.7
Go

CVE-2026-27769

Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace

LOW 3.7
Go

CVE-2026-4273

Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation

LOW 3.1
Go

CVE-2026-40109

Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering

LOW 3.7
Go

CVE-2026-44474

Ella Core has handover failures during concurrent Security Mode Command

LOW 3.1
Go

CVE-2026-39396

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

LOW 3.7
Go

CVE-2026-42082

Free5GC AMF has Missing Concurrent NAS SMC Validation During NGAP Handover

LOW 3.5
Go

CVE-2026-6333

Mattermost doesn't validate the Host header when constructing response URLs for custom slash command

LOW 2.7
Go

CVE-2026-34762

Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber

LOW 3.5
Go

CVE-2026-5468

Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml

LOW 3.1
Go

CVE-2026-4286

Mattermost doesn't check if {{team_id}} was being changed when updating playbooks

LOW 3.7
Go

CVE-2026-41263

Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware

LOW 3.5
Go

CVE-2026-45803

GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injection

LOW 3.1
Go

CVE-2026-39388

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

LOW 2.3
Go

CVE-2026-40243

Incus has an OVN TLS Verification that Accepts Peer-Supplied Roots

LOW 3.7
Go

CVE-2026-40097

Step CA affected by an index out of bounds panic in TPM attestation EKU validation

LOW 3.5
Go

CVE-2026-34454

OAuth2 Proxy's session cookies are not cleared when rendering sign-in page

LOW 3.7
Go

CVE-2026-48709

OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration

LOW 2.7
Go

CVE-2026-45723

Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic

LOW 3.8
Go

CVE-2026-45683

OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure

LOW 3.7
Go

CVE-2026-8275

bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function

LOW 3.5
Go

CVE-2026-52796

Gogs has DoS in rendering issue index pattern

LOW 3.7
Go

CVE-2026-55866

SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected

LOW 3.5
Go

CVE-2026-40077

Beszel has an IDOR in hub API endpoints that read system ID from URL parameter

LOW 3.1
Go

CVE-2026-24513

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

LOW 3.1
Go

CVE-2024-7598

Kubernetes kube-apiserver Vulnerable to Race Condition

LOW 3.9
Go

CVE-2026-30963

Capsule Namespace Hijacking via subresource

LOW 3.7
Go

CVE-2026-24122

Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped

LOW 3.1
Go

CVE-2020-8562

Potential proxy IP restriction bypass in Kubernetes

LOW 3.1
Go

CVE-2021-25740

Confused Deputy in Kubernetes

LOW 3.7
Go

CVE-2023-30464

CoreDNS Cache Poisoning via a birthday attack

LOW 3.5
Go

CVE-2026-45781

MCP Registry: OCI validator skips ownership check on upstream rate limits

LOW 3.7
Go

CVE-2026-8276

bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go

LOW 2.0
Go

GO-2024-2703

Kopia: Storage connection credentials written to console on "repository status" CLI command with JSON output

LOW 2.5
Go

CVE-2020-8912

In-band key negotiation issue in AWS S3 Crypto SDK for golang

LOW 2.8
Go

CVE-2026-33762

go-git missing validation decoding Index v4 files leads to panic

Ready to move

Start Securing

Free, no credit card | First findings in minutes