Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-100836
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
CVE-2025-71422
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
CVE-2026-79778
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
CVE-2026-79779
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
CVE-2026-55770
OpenBao: LDAPi ldaputil (wrong escape func)
CVE-2026-79781
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
CVE-2026-55776
OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types
CVE-2026-79780
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
CVE-2026-88016
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
CVE-2026-56742
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
CVE-2026-10609
OpenShift Cluster Logging Operator missing authorization flaw
CVE-2026-62286
Dozzle label filters do not restrict container event and statistics streams
CVE-2026-19730
podman quadlet install --replace does not fully replace the old file
CVE-2026-56443
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-56657
Gitea SSH Key Parser Denial of Service
CVE-2026-77281
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
CVE-2026-79913
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
CVE-2026-76804
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
CVE-2026-76805
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode
CVE-2026-76803
Nuclei: Local File Read via MySQL Client Sandbox Bypass
CVE-2026-76802
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
CVE-2026-62987
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header
CVE-2026-63342
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check
CVE-2026-61681
Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler
CVE-2026-77561
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service
CVE-2026-62370
KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub
CVE-2026-88978
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
CVE-2026-79767
Gardener: Authorization Bypass via Group Subject Injection
CVE-2026-59168
Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS
CVE-2026-62866
Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`
CVE-2026-10601
Grafana: Path traversal in the Tempo and Loki data source plugins
CVE-2026-61630
nginx ignition has TOTP Reuse During Validity Window
GHSA-jhjp-4c2q-xmx4
k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers
CVE-2024-9355
Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability
CVE-2026-53719
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
CVE-2026-53716
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
CVE-2026-53718
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
CVE-2026-53717
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
CVE-2026-53715
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
CVE-2026-88046
rclone: source object names can escape the configured root on upload
CVE-2026-88014
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
CVE-2026-88015
rclone local: crafted Range request against a translated symlink panics (DoS)
GHSA-pr6h-vr44-xq8j
Obot: MCP Registry API readable without authentication
CVE-2026-61795
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
CVE-2026-61794
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic
CVE-2026-63405
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
CVE-2026-63406
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
CVE-2026-76081
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
CVE-2026-56665
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
CVE-2026-56666
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
CVE-2025-58363
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
CVE-2026-88012
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
CVE-2026-59157
webhookd: Unrestricted HTTP Header to Shell Variable Injection
CVE-2025-24979
LF Edge eKuiper: SSRF in External Service
CVE-2026-85732
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
CVE-2026-61709
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
CVE-2026-6062
Mattermost doesn't validate channel ownership of an existing subscription before applying edits
CVE-2026-5139
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
CVE-2026-6673
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret
CVE-2026-9162
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
Ready to move
Start Securing
Free, no credit card | First findings in minutes