StackRadar

CVE-2020-15586

Unscored

Advisory

Published 17 Feb 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.029
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
231
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
1 of 1
affected package

Data race and crash in net/http

Carried by container images the latest versions of 231 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+13 more1.13.13206
OSV records
GO-2021-0224
Also known as
BIT-golang-2020-15586

Charts affected

231 by stars
ChartLatestAffected imagesRadar Score
prometheusprometheus-worawutchan13.0.03 of 6See more

prometheus prometheus-worawutchan 13.0.0

3 of the 6 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.13.13
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.13.13
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.13.13

Open the chart page →

9,939
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
stdlib@go1.14.2
1.13.13

Open the chart page →

23,964
prometheus-webhook-dingtalkrlex0.0.31 of 1See more

prometheus-webhook-dingtalk rlex 0.0.3

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.13.13

Open the chart page →

1,852
gcp-quota-exportersoftonic2.0.21 of 1See more

gcp-quota-exporter softonic 2.0.2

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
stdlib@go1.13.12
1.13.13

Open the chart page →

2,637
go-ratelimitsoftonic1.0.72 of 3See more

go-ratelimit softonic 1.0.7

2 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:v1.4.071081616da3e
stdlib@go1.14
1.13.13
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.13.13

Open the chart page →

5,098
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.13.13

Open the chart page →

2,307
gitwebhookproxystakaterVerified publisher0.2.791 of 1See more

gitwebhookproxy stakater 0.2.79

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
stakater/gitwebhookproxy:v0.2.79c1226e5270cd
stdlib@go1.13.1
1.13.13

Open the chart page →

1,503
Grafanasurajwarbhe-grafana0.1.01 of 1See more

Grafana surajwarbhe-grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
surajwarbhe/grafana:v185248611e9f1
stdlib@go1.14.3
1.13.13

Open the chart page →

2,597
atlantistrozz3.12.111 of 1See more

atlantis trozz 3.12.11

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.16.145fbaf7e207c
stdlib@go1.13.11
1.13.13

Open the chart page →

5,280
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
stdlib@go1.13.10
1.13.13

Open the chart page →

7,303
vearchvearch3.3.41 of 4See more

vearch vearch 3.3.4

1 of the 4 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.13.13

Open the chart page →

5,008
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
stdlib@go1.13.10
1.13.13

Open the chart page →

8,079
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
stdlib@go1.13.10
1.13.13

Open the chart page →

7,871
waardepapieren-registerwaardepapieren-register1.1.01 of 4See more

waardepapieren-register waardepapieren-register 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
stdlib@go1.13.10
1.13.13

Open the chart page →

7,429
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
stdlib@go1.13.10
1.13.13

Open the chart page →

7,447
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
stdlib@go1.13.10
1.13.13

Open the chart page →

7,209
smartorchestratorassist-iot-smart-orchestrator4.0.01 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

1 of the 14 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.13
1.13.13

Open the chart page →

45,363
hcloud-csi-driveratem181.5.11 of 6See more

hcloud-csi-driver atem18 1.5.1

1 of the 6 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.13.13

Open the chart page →

6,491
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
stdlib@go1.13.10
1.13.13

Open the chart page →

7,561
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.13.13

Open the chart page →

2,939
keptn-addonsazureorkestra0.1.01 of 4See more

keptn-addons azureorkestra 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
keptncontrib/prometheus-service:0.6.029969dd547de
stdlib@go1.13.7
1.13.13

Open the chart page →

10,621
prometheusazureorkestra14.8.01 of 6See more

prometheus azureorkestra 14.8.0

1 of the 6 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.13.13

Open the chart page →

9,661
webserverazureorkestra1.0.01 of 1See more

webserver azureorkestra 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
nmalhotr/webserver:v1.0.03419361fb0dd
stdlib@go1.13.10
1.13.13

Open the chart page →

3,037
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
stdlib@go1.13.10
1.13.13

Open the chart page →

8,408
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
stdlib@go1.13.10
1.13.13

Open the chart page →

7,342
openldapccowleyVerified publisher2.0.41 of 3See more

openldap ccowley 2.0.4

1 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
stdlib@go1.13.4
1.13.13

Open the chart page →

6,219
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
stdlib@go1.13.10
1.13.13

Open the chart page →

8,408
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
stdlib@go1.13.11
1.13.13

Open the chart page →

2,869
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
stdlib@go1.13.11
1.13.13

Open the chart page →

2,821
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.13.13

Open the chart page →

3,595
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.13.13

Open the chart page →

2,814
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.13.13

Open the chart page →

14,270
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.13.13

Open the chart page →

2,853
lgtmcmacraeVerified publisher0.1.01 of 1See more

lgtm cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
cmacrae/lgtm:0.1.0dec8d490fe40
stdlib@go1.14.1
1.13.13

Open the chart page →

1,909
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
stdlib@go1.13.12
1.13.13

Open the chart page →

2,234
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
stdlib@go1.13.10
1.13.13

Open the chart page →

7,572
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
stdlib@go1.13.10
1.13.13

Open the chart page →

12,907
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
stdlib@go1.13.10
1.13.13

Open the chart page →

7,209
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
stdlib@go1.13.10
1.13.13

Open the chart page →

8,408
katibcowboysysopVerified publisher2.4.21 of 4See more

katib cowboysysop 2.4.2

1 of the 4 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
stdlib@go1.13.3
1.13.13

Open the chart page →

6,542
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
stdlib@go1.13.1
1.13.13

Open the chart page →

5,488
crossplane-controllerscrossplane0.12.01 of 1See more

crossplane-controllers crossplane 0.12.0

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
crossplane/crossplane:v0.12.066666e6963af
stdlib@go1.14.4
1.13.13

Open the chart page →

2,312
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
stdlib@go1.14.2
1.13.13

Open the chart page →

4,624
nfs-provisionerdasmeta1.0.31 of 1See more

nfs-provisioner dasmeta 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.13.13

Open the chart page →

2,806
aws-s3-proxydeliveryheroVerified publisher0.1.71 of 1See more

aws-s3-proxy deliveryhero 0.1.7

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
pottava/s3-proxy:2.020a0bcb15f76
stdlib@go1.13.7
1.13.13

Open the chart page →

1,323
prometheus-soti-mobicontrol-exporterdeliveryheroVerified publisher1.0.31 of 1See more

prometheus-soti-mobicontrol-exporter deliveryhero 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.13.13

Open the chart page →

1,644
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
stdlib@go1.14.4
1.13.13

Open the chart page →

10,466
argocddevtron-labs1.8.11 of 3See more

argocd devtron-labs 1.8.1

1 of the 3 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
stdlib@go1.14.4
1.13.13

Open the chart page →

10,466
whoamidniel0.8.11 of 1See more

whoami dniel 0.8.1

1 of the 1 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.13.13

Open the chart page →

1,279
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-15586.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
stdlib@go1.13.10
1.13.13

Open the chart page →

8,408

Container images carrying it

206 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.13.13
8
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.13.13
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.13.13
6
containous/whoami:latest:v1.5.07d6a3c8f9147
stdlib@go1.14
1.13.13
5
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.13.13
5
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.13.13
5
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.13.13
5
grafana/grafana:6.7.11ff3999e0fc0
stdlib@go1.13.4
1.13.13
4
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.13.13
4
argoproj/argocd:v1.8.1830e86cacefd
stdlib@go1.14.4
1.13.13
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
stdlib@go1.13.11
1.13.13
3
prom/prometheus:v2.19.0bfad037f95e5
stdlib@go1.14.4
1.13.13
3
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.13.13
3
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.13.13
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.13.13
3
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.13.13
2
cesanta/docker_auth:1.6.04d16885f3d4c
stdlib@go1.13.7
1.13.13
2
grafana/loki:1.5.0922b3f412fdd
stdlib@go1.13.11
1.13.13
2
grafana/promtail:1.5.046e88d390cd6
stdlib@go1.13.11
1.13.13
2
honestica/kube-iptables-tailer:master-91a393242fb939
stdlib@go1.13.8
1.13.13
2
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
stdlib@go1.13.1
1.13.13
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
stdlib@go1.13.11
1.13.13
2
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.13.13
2
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.13.13
2
osixia/openldap:1.4.0ccd95cc6e61e
stdlib@go1.13.4
1.13.13
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.13.13
2
place1/wg-access-server:v0.4.62b2f3ea80ed6
stdlib@go1.13.8
1.13.13
2
pottava/s3-proxy:2.020a0bcb15f76
stdlib@go1.13.7
1.13.13
2
prom/prometheus:v2.17.242d2395cd719
stdlib@go1.13.10
1.13.13
2
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.13.13
2
squareup/ghostunnel:v1.5.270f4cf270425
stdlib@go1.13.4
1.13.13
2
thesisrobot/loop:v0.11.1-beta89ae07e787ca
stdlib@go1.13.12
1.13.13
2
weblate/weblate:4.2.2-169c160d37a3c
stdlib@go1.13.5
1.13.13
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
stdlib@go1.13.10
1.13.13
2
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
stdlib@go1.14.3
1.13.13
2
alpine/k8s:1.18.16a41efe02a041
stdlib@go1.13.4
1.13.13
1
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
stdlib@go1.13.4
1.13.13
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
stdlib@go1.13.8
1.13.13
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
stdlib@go1.13.3
1.13.13
1
apache/skywalking-ui:8.1.067d50e4deff4
stdlib@go1.13.3
1.13.13
1
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.13
1.13.13
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.13.13
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
stdlib@go1.13.3
1.13.13
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
stdlib@go1.13.4
1.13.13
1
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
stdlib@go1.13
1.13.13
1
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.13.13
1
cmacrae/lgtm:0.1.0dec8d490fe40
stdlib@go1.14.1
1.13.13
1
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.13.13
1
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.13.13
1
conduction/agendaservice-php:latest9cfeeb6c7c20
stdlib@go1.13.10
1.13.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.