Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 4.3
Go

CVE-2026-100836

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

MEDIUM 5.7
Go

CVE-2025-71422

Contrast has insecure LUKS2 persistent storage partitions may be opened and used

MEDIUM 5.3
Go

CVE-2026-79778

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

MEDIUM 5.3
Go

CVE-2026-79779

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

MEDIUM 6.8
Go

CVE-2026-55770

OpenBao: LDAPi ldaputil (wrong escape func)

MEDIUM 6.5
Go

CVE-2026-79781

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

MEDIUM 6.5
Go

CVE-2026-55776

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types

MEDIUM 5.3
Go

CVE-2026-79780

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

MEDIUM 6.5
Go

CVE-2026-88016

rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

MEDIUM 5.9
Go

CVE-2026-56742

Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces

MEDIUM 6.8
Go

CVE-2026-10609

OpenShift Cluster Logging Operator missing authorization flaw

MEDIUM 4.3
Go

CVE-2026-62286

Dozzle label filters do not restrict container event and statistics streams

MEDIUM 4.2
Go

CVE-2026-19730

podman quadlet install --replace does not fully replace the old file

MEDIUM 4.3
Go

CVE-2026-56443

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

MEDIUM 6.2
Go

CVE-2026-56657

Gitea SSH Key Parser Denial of Service

MEDIUM 6.5
Go

CVE-2026-77281

Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass

MEDIUM 6.5
Go

CVE-2026-79913

Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses

MEDIUM 5.5
Go

CVE-2026-76804

Nuclei: Local File Read via Workflow File-Protocol Gate Bypass

MEDIUM 5.3
Go

CVE-2026-76805

Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode

MEDIUM 5.3
Go

CVE-2026-76803

Nuclei: Local File Read via MySQL Client Sandbox Bypass

MEDIUM 4.7
Go

CVE-2026-76802

Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass

MEDIUM 5.8
Go

CVE-2026-62987

Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header

MEDIUM 6.3
Go

CVE-2026-63342

Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check

MEDIUM 4.1
Go

CVE-2026-61681

Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler

MEDIUM 5.3
Go

CVE-2026-77561

Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service

MEDIUM 6.5
Go

CVE-2026-62370

KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub

MEDIUM 4.3
Go

CVE-2026-88978

Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter

MEDIUM 5.5
Go

CVE-2026-79767

Gardener: Authorization Bypass via Group Subject Injection

MEDIUM 6.2
Go

CVE-2026-59168

Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS

MEDIUM 6.2
Go

CVE-2026-62866

Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`

MEDIUM 5.4
Go

CVE-2026-10601

Grafana: Path traversal in the Tempo and Loki data source plugins

MEDIUM 4.2
Go

CVE-2026-61630

nginx ignition has TOTP Reuse During Validity Window

MEDIUM 4.3
Go

GHSA-jhjp-4c2q-xmx4

k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers

MEDIUM 6.5
Go

CVE-2024-9355

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

MEDIUM 6.5
Go

CVE-2026-53719

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

MEDIUM 6.5
Go

CVE-2026-53716

Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit

MEDIUM 6.4
Go

CVE-2026-53718

Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass

MEDIUM 6.5
Go

CVE-2026-53717

Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header

MEDIUM 5.3
Go

CVE-2026-53715

Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock

MEDIUM 5.3
Go

CVE-2026-88046

rclone: source object names can escape the configured root on upload

MEDIUM 6.3
Go

CVE-2026-88014

rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace

MEDIUM 5.3
Go

CVE-2026-88015

rclone local: crafted Range request against a translated symlink panics (DoS)

MEDIUM 5.3
Go

GHSA-pr6h-vr44-xq8j

Obot: MCP Registry API readable without authentication

MEDIUM 6.8
Go

CVE-2026-61795

Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation

MEDIUM 4.9
Go

CVE-2026-61794

Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic

MEDIUM 5.9
Go

CVE-2026-63405

AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body

MEDIUM 5.9
Go

CVE-2026-63406

AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets

MEDIUM 5.5
Go

CVE-2026-76081

ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions

MEDIUM 4.2
Go

CVE-2026-56665

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

MEDIUM 4.8
Go

CVE-2026-56666

ZITADEL: Auto-linking by email: IdP-side email verification is not checked

MEDIUM 5.5
Go

CVE-2025-58363

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

MEDIUM 5.3
Go

CVE-2026-88012

Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded

MEDIUM 6.5
Go

CVE-2026-59157

webhookd: Unrestricted HTTP Header to Shell Variable Injection

MEDIUM 5.5
Go

CVE-2025-24979

LF Edge eKuiper: SSRF in External Service

MEDIUM 4.7
Go

CVE-2026-85732

oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing

MEDIUM 5.3
Go

CVE-2026-61709

OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user

MEDIUM 6.4
Go

CVE-2026-6062

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

MEDIUM 5.4
Go

CVE-2026-5139

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

MEDIUM 6.4
Go

CVE-2026-6673

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret

MEDIUM 4.3
Go

CVE-2026-9162

Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation

Ready to move

Start Securing

Free, no credit card | First findings in minutes