Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
Echo OS
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
H
Allocation of Resources Without Limits or Throttling
CVE-2026-56150
Affects
github.com/elastic/fleet-server/v7/internal/pkg/file/uploader
| Versions
>=8.0.0 <8.19.1
>=9.0.0 <9.2.5
H
Allocation of Resources Without Limits or Throttling
CVE-2026-56150
Affects
github.com/elastic/fleet-server/internal/pkg/file/uploader
| Versions
>=8.0.0 <8.19.1
>=9.0.0 <9.2.5
H
Allocation of Resources Without Limits or Throttling
CVE-2026-56150
Affects
github.com/elastic/fleet-server/v7/internal/pkg/api
| Versions
>=8.0.0 <8.19.1
>=9.0.0 <9.2.5
H
Allocation of Resources Without Limits or Throttling
CVE-2026-56150
Affects
github.com/elastic/fleet-server/internal/pkg/api
| Versions
>=8.0.0 <8.19.1
>=9.0.0 <9.2.5
M
Relative Path Traversal
CVE-2026-44948
Affects
github.com/rancher/fleet/internal/cmd/controller/imagescan
| Versions
>=0.12.0-alpha.1 <0.12.16-rc.1
>=0.13.0-alpha.1 <0.13.12-rc.1
>=0.14.0-alpha.1 <0.14.7-rc.2
>=0.15.0-alpha.1 <0.15.3-rc.2
H
Incorrect Implementation of Authentication Algorithm
CVE-2026-41053
Affects
github.com/rancher/rancher/pkg/data/management
| Versions
>=2.13.0-alpha1 <2.13.6-alpha5
>=2.14.0-alpha1 <2.14.2-alpha5
>=2.15.0-alpha1 <2.15.0-alpha5
H
Incorrect Implementation of Authentication Algorithm
CVE-2026-41053
Affects
github.com/rancher/rancher/pkg/multiclustermanager
| Versions
>=2.13.0-alpha1 <2.13.6-alpha5
>=2.14.0-alpha1 <2.14.2-alpha5
>=2.15.0-alpha1 <2.15.0-alpha5
H
Incorrect Implementation of Authentication Algorithm
CVE-2026-41053
Affects
github.com/rancher/rancher/pkg/auth/providers/github
| Versions
>=2.13.0-alpha1 <2.13.6-alpha5
>=2.14.0-alpha1 <2.14.2-alpha5
>=2.15.0-alpha1 <2.15.0-alpha5
H
Incorrect Implementation of Authentication Algorithm
CVE-2026-41053
Affects
github.com/rancher/rancher/pkg/auth/providerrefresh
| Versions
>=2.13.0-alpha1 <2.13.6-alpha5
>=2.14.0-alpha1 <2.14.2-alpha5
>=2.15.0-alpha1 <2.15.0-alpha5
H
Incorrect Authorization
CVE-2026-44935
Affects
github.com/rancher/fleet/internal/cmd/controller/reconciler
| Versions
>=0.12.0-alpha.1 <0.12.15-rc.2
>=0.13.0-alpha.1 <0.13.11-rc.1
>=0.14.0-alpha.1 <0.14.6-rc.2
>=0.15.0-alpha.1 <0.15.2-rc.2
H
Incorrect Authorization
CVE-2026-44935
Affects
github.com/rancher/fleet/internal/cmd/controller/helmops/reconciler
| Versions
>=0.12.0-alpha.1 <0.12.15-rc.2
>=0.13.0-alpha.1 <0.13.11-rc.1
>=0.14.0-alpha.1 <0.14.6-rc.2
>=0.15.0-alpha.1 <0.15.2-rc.2
H
Incorrect Authorization
CVE-2026-44935
Affects
github.com/rancher/fleet/internal/cmd/controller/gitops/reconciler
| Versions
>=0.12.0-alpha.1 <0.12.15-rc.2
>=0.13.0-alpha.1 <0.13.11-rc.1
>=0.14.0-alpha.1 <0.14.6-rc.2
>=0.15.0-alpha.1 <0.15.2-rc.2
M
Server-side Request Forgery (SSRF)
CVE-2026-44936
Affects
github.com/rancher/fleet/internal/cmd/cli/migrate
| Versions
>=0.12.0-alpha.1 <0.12.15-rc.2
>=0.13.0-alpha.1 <0.13.11-rc.1
>=0.14.0-alpha.1 <0.14.6-rc.2
>=0.15.0-alpha.1 <0.15.2-rc.2
M
Server-side Request Forgery (SSRF)
CVE-2026-44936
Affects
github.com/rancher/fleet/internal/cmd/cli
| Versions
>=0.12.0-alpha.1 <0.12.15-rc.2
>=0.13.0-alpha.1 <0.13.11-rc.1
>=0.14.0-alpha.1 <0.14.6-rc.2
>=0.15.0-alpha.1 <0.15.2-rc.2
M
Server-side Request Forgery (SSRF)
CVE-2026-44936
Affects
github.com/rancher/fleet/internal/bundlereader
| Versions
>=0.12.0-alpha.1 <0.12.15-rc.2
>=0.13.0-alpha.1 <0.13.11-rc.1
>=0.14.0-alpha.1 <0.14.6-rc.2
>=0.15.0-alpha.1 <0.15.2-rc.2
H
Insufficiently Protected Credentials
CVE-2026-44938
Affects
github.com/rancher/fleet/internal/cmd/agent/deployer
| Versions
>=0.12.0-alpha.1 <0.12.15-rc.2
>=0.13.0-alpha.1 <0.13.11-rc.1
>=0.14.0-alpha.1 <0.14.6-rc.2
>=0.15.0-alpha.1 <0.15.2-rc.2
H
Insufficient Verification of Data Authenticity
CVE-2026-44937
Affects
github.com/rancher/fleet/pkg/webhook
| Versions
>=0.12.0-alpha.1 <0.12.15-rc.2
>=0.13.0-alpha.1 <0.13.11-rc.1
>=0.14.0-alpha.1 <0.14.6-rc.2
>=0.15.0-alpha.1 <0.15.2-rc.2
M
Allocation of Resources Without Limits or Throttling
CVE-2026-48824
Affects
github.com/axllent/mailpit/server/apiv1
| Versions
<1.30.1
M
Allocation of Resources Without Limits or Throttling
CVE-2026-48824
Affects
github.com/axllent/mailpit/server
| Versions
<1.30.1
H
Improper Verification of Cryptographic Signature
CVE-2026-49998
Affects
github.com/centrifugal/centrifugo/v6/internal/jwks
| Versions
<6.8.1
H
Improper Verification of Cryptographic Signature
CVE-2026-49998
Affects
github.com/centrifugal/centrifugo/v5/internal/jwks
| Versions
>=0.0.0
H
Improper Verification of Cryptographic Signature
CVE-2026-49998
Affects
github.com/centrifugal/centrifugo/v4/internal/jwks
| Versions
>=0.0.0
H
Improper Verification of Cryptographic Signature
CVE-2026-49998
Affects
github.com/centrifugal/centrifugo/v3/internal/jwks
| Versions
>=0.0.0
H
Improper Verification of Cryptographic Signature
CVE-2026-49998
Affects
github.com/centrifugal/centrifugo/v2/internal/jwks
| Versions
>=0.0.0
H
Improper Verification of Cryptographic Signature
CVE-2026-49998
Affects
github.com/centrifugal/centrifugo/internal/jwks
| Versions
>=0.0.0
H
Race Condition
CVE-2026-50139
Affects
github.com/patrickhener/goshs/v2/httpserver
| Versions
<2.1.0
H
Race Condition
CVE-2026-50139
Affects
github.com/patrickhener/goshs/httpserver
| Versions
>=0.0.0
H
Race Condition
CVE-2026-50139
Affects
github.com/goshs-labs/goshs/v2/httpserver
| Versions
<2.1.0
M
External Control of File Name or Path
CVE-2026-50162
Affects
github.com/oras-project/oras-go/v2/content/file
| Versions
<2.6.1
M
External Control of File Name or Path
CVE-2026-50162
Affects
github.com/oras-project/oras-go/content/file
| Versions
>=0.0.0