Launch Week Day 1: Announcing Security Design Review

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

LOW 3.8
Go

CVE-2026-45683

OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure

LOW 3.1
Go

CVE-2020-8562

Potential proxy IP restriction bypass in Kubernetes

LOW 3.1
Go

CVE-2021-25740

Confused Deputy in Kubernetes

LOW 3.9
Go

CVE-2026-30963

Capsule Namespace Hijacking via subresource

LOW 2.8
Go

GHSA-rc6v-5rmx-w5mv

arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS

LOW 3.7
Go

CVE-2026-42082

Free5GC AMF has Missing Concurrent NAS SMC Validation During NGAP Handover

LOW 3.7
Go

CVE-2026-44474

Ella Core has handover failures during concurrent Security Mode Command

LOW 3.1
Go

GHSA-pxh5-6rrc-8rjv

OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server

LOW 3.7
Go

CVE-2023-30464

CoreDNS Cache Poisoning via a birthday attack

LOW 2.7
Go

CVE-2026-45723

Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic

LOW 3.7
Go

CVE-2026-4273

Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation

LOW 3.5
Go

CVE-2026-6333

Mattermost doesn't validate the Host header when constructing response URLs for custom slash command

LOW 3.1
Go

CVE-2026-4286

Mattermost doesn't check if {{team_id}} was being changed when updating playbooks

LOW 3.8
Go

CVE-2026-3495

Mattermost doesn't escape some variables that could contain malicious content during error page composition

LOW 3.1
Go

CVE-2026-6334

Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow

LOW 3.1
Go

CVE-2026-4053

Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields

LOW 3.5
Go

CVE-2026-45781

MCP Registry: OCI validator skips ownership check on upstream rate limits

LOW 3.1
Go

CVE-2026-24513

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

LOW 3.5
Go

CVE-2026-45803

GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injection

LOW 3.7
Go

CVE-2026-8276

bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go

LOW 3.7
Go

CVE-2026-8275

bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function

LOW 2.3
Go

CVE-2026-40243

Incus has an OVN TLS Verification that Accepts Peer-Supplied Roots

LOW 3.7
Go

CVE-2026-41263

Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware

LOW 3.7
Go

CVE-2026-40263

Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel

LOW 3.7
Go

CVE-2026-21388

Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint

LOW 3.3
Go

CVE-2026-29051

melange has Path Traversal via .PKGINFO in --persist-lint-results

LOW 2.7
Go

CVE-2026-27769

Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace

LOW 3.1
Go

CVE-2026-39388

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

LOW 2.0
Go

GO-2024-2703

Kopia: Storage connection credentials written to console on "repository status" CLI command with JSON output

LOW 2.5
Go

CVE-2020-8912

In-band key negotiation issue in AWS S3 Crypto SDK for golang

LOW 3.1
Go

CVE-2026-39396

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

LOW 3.5
Go

CVE-2026-34454

OAuth2 Proxy's session cookies are not cleared when rendering sign-in page

LOW 3.1
Go

GHSA-hw5x-4r37-72w7

OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency responses

LOW 3.1
Go

CVE-2026-40109

Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering

LOW 3.7
Go

CVE-2026-40097

Step CA affected by an index out of bounds panic in TPM attestation EKU validation

LOW 3.5
Go

CVE-2026-40077

Beszel has an IDOR in hub API endpoints that read system ID from URL parameter

LOW 3.5
Go

CVE-2026-5468

Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml

LOW 2.8
Go

CVE-2026-33762

go-git missing validation decoding Index v4 files leads to panic

LOW 2.7
Go

CVE-2026-34762

Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber

LOW 3.8
Go

CVE-2025-14573

Mattermost fails to enforce invite permissions when updating team settings

LOW 3.1
Go

CVE-2025-41423

Mattermost Playbooks fails to properly validate permissions

LOW 3.4
Go

CVE-2025-52889

Incus Allocation of Resources Without Limits allows firewall rule bypass on managed bridge networks

LOW 3.3
Go

CVE-2026-33529

Zoraxy: Authenticated Path Traversal in Config Import leads to RCE

LOW 3.3
Go

CVE-2025-54410

Moby firewalld reload removes bridge network isolation

LOW 3.6
Go

CVE-2026-31863

Anytype Heart's gRPC API client challenge verification can be bypassed on localhost

LOW 3.1
Go

CVE-2026-22545

Mattermost fails to validate user's authentication method when processing account auth type switch

LOW 3.0
Go

CVE-2021-41190

Clarify Content-Type handling

LOW 3.7
Go

CVE-2020-15106

Panic due to malformed WALs in go.etcd.io/etcd

LOW 3.4
Go

CVE-2020-15186

Improper Sanitizing of plugin names in helm

LOW 2.2
Go

CVE-2020-15185

Repository index file allows for duplicates of the same chart entry in helm

LOW 2.8
Go

CVE-2021-41089

`docker cp` allows unexpected chmod of host files in Moby Docker Engine

LOW 3.7
Go

CVE-2020-15184

Aliases are never checked in helm

LOW 3.7
Go

CVE-2020-4053

Plugin archive directory traversal in Helm

LOW 3.1
Go

CVE-2020-5303

Denial of service in Tendermint

LOW 2.7
Go

CVE-2024-22261

SQL Injection in Harbor scan log API

LOW 3.0
Go

CVE-2020-15187

plugin.yaml file allows for duplicate entries in helm

LOW 3.8
Go

CVE-2025-67860

NeuVector scanner insecurely handles passwords as command arguments

LOW 3.1
Go

CVE-2025-14822

Mattermost is vulnerable to CPU exhaustion via crafted HTTP request

LOW 3.1
Go

CVE-2026-20796

Mattermost doesn't properly validate channel membership at the time of data retrieval

LOW 3.7
Go

CVE-2026-24122

Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped

Ready to move

Start Securing

Free, no credit card | First findings in minutes