Launch Week Day 1: Announcing Security Design Review

Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 5.0
Go

CVE-2026-48096

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

MEDIUM 6.1
Go

CVE-2026-41568

Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

MEDIUM 6.5
Go

CVE-2026-54092

File Browser has a DoS Vulnerability via Public Login API

MEDIUM 6.8
Go

CVE-2026-54094

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

MEDIUM 6.5
Go

CVE-2026-46371

Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint

MEDIUM 6.5
Go

CVE-2026-46370

Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint

MEDIUM 4.4
Go

CVE-2026-47190

IPAM controller service account granted unnecessary full access to Secrets

MEDIUM 5.9
Go

CVE-2026-48154

gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362)

MEDIUM 6.8
Go

GHSA-9r4w-jg96-92mv

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

MEDIUM 5.5
Go

CVE-2026-47768

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

MEDIUM 5.3
Go

CVE-2026-49397

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

MEDIUM 6.9
Go

CVE-2025-51471

Ollama vulnerable to Cross-Domain Token Exposure

MEDIUM 6.6
Go

CVE-2025-44779

Ollama allows deletion of arbitrary files

MEDIUM 6.1
Go

CVE-2026-44245

Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component

MEDIUM 5.3
Go

CVE-2026-40898

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

MEDIUM 5.3
Go

CVE-2026-41178

opentelemetry-go's baggage parsing no longer caps raw header length

MEDIUM 5.3
Go

CVE-2026-33221

Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload

MEDIUM 5.9
Go

CVE-2026-45680

OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU

MEDIUM 5.1
Go

CVE-2026-45682

OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals

MEDIUM 6.5
Go

CVE-2026-45679

OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages

MEDIUM 4.9
Go

CVE-2026-45684

OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers

MEDIUM 5.5
Go

CVE-2026-45676

OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent

MEDIUM 5.9
Go

CVE-2026-45681

OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size

MEDIUM 5.0
Go

CVE-2020-8554

Unverified Ownership in Kubernetes

MEDIUM 4.1
Go

CVE-2020-8561

Confused Deputy in Kubernetes

MEDIUM 6.5
Go

CVE-2026-44740

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

MEDIUM 6.3
Go

CVE-2026-45626

Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter

MEDIUM 6.5
Go

CVE-2026-44884

Portainer missing authorization on custom template file endpoint, which exposes template content

MEDIUM 5.5
Go

CVE-2026-44885

Portainer has a path traversal in backup archive extraction that allows arbitrary file write

MEDIUM 6.5
Go

CVE-2026-44317

free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference

MEDIUM 6.2
Go

CVE-2026-42328

go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth

MEDIUM 6.1
Go

CVE-2026-44475

Ella Core has a UE Security Capability bypass on NGAP PathSwitchRequest

MEDIUM 4.3
Go

CVE-2026-44323

free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)

MEDIUM 6.1
Go

CVE-2026-42081

Free5GC AMF Bypasses UE Security Capabilities on NGAP PathSwitchRequest

MEDIUM 6.5
Go

CVE-2026-44324

free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)

MEDIUM 5.5
Go

CVE-2026-45046

Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content

MEDIUM 5.4
Go

CVE-2026-45571

go-git: Crafted repositories may modify main and submodule .git directories

MEDIUM 6.8
Go

CVE-2026-44247

Volcano's webhook server vulnerable to OOM due to unbounded HTTP request body size

MEDIUM 6.1
Go

CVE-2026-44903

Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display

MEDIUM 4.4
Go

CVE-2026-41164

nuts-node has JWT type confusion in v1 access token introspection that allows VP replay as access token

MEDIUM 4.9
Go

CVE-2026-42600

MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint

MEDIUM 4.3
Go

CVE-2026-46431

Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *

MEDIUM 6.5
Go

CVE-2026-44318

free5GC's BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions

MEDIUM 5.3
Go

CVE-2026-42592

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

MEDIUM 5.5
Go

CVE-2026-41646

Nuclei: Local File Read via require() Module Loader Bypass

MEDIUM 4.1
Go

CVE-2026-35601

Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output

MEDIUM 5.3
Go

CVE-2025-31135

Go-Guerrilla SMTP Daemon allows the PROXY command to be sent multiple times

MEDIUM 6.5
Go

CVE-2024-34352

1Panel arbitrary file write vulnerability

MEDIUM 5.9
Go

CVE-2026-49343

Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS

MEDIUM 5.4
Go

CVE-2026-47671

Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets

MEDIUM 4.8
Go

CVE-2026-47215

Singluarity: Incorrect path matching for 'limit container paths' directive

MEDIUM 4.9
Go

CVE-2026-42876

ExternalSecrets vulnerable to privilege escalation with secret overwriting

MEDIUM 6.5
Go

GHSA-w5pp-99ch-qj29

go-git: Malformed Git object data may cause panics or resource exhaustion

MEDIUM 4.3
Go

CVE-2026-2325

Mattermost doesn't limit the size of the request body on the start meeting API endpoint

MEDIUM 4.3
Go

CVE-2026-28759

Mattermost does not verify remote cluster channel access when processing shared channel membership removals

MEDIUM 4.3
Go

CVE-2026-6343

Mattermost doesn't check public/private permissions

MEDIUM 6.5
Go

CVE-2026-6345

Mattermost doesn't prevent disclosure of created user password

MEDIUM 6.5
Go

CVE-2026-5163

Mattermost doesn't verify channel membership when processing AI-assisted message rewrites

MEDIUM 4.3
Go

CVE-2026-6339

Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint

MEDIUM 4.3
Go

CVE-2026-28732

Mattermost doesn't enforce slash command trigger-word uniqueness during command updates

Ready to move

Start Securing

Free, no credit card | First findings in minutes