StackRadar

CVE-2025-61726

High

Advisory

Published 28 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,608
of 17,805 indexed, latest versions
Container images
4,070
deployed by those charts
Fix available
2 of 3
affected packages

Red Hat Security Advisory: go-rpm-macros security update

Carried by container images the latest versions of 3,608 of 17,805 indexed charts deploy, on 4,070 images.

Affected packageAffected versionsFixed inImages
go-rpm-macrosrpm3.2.0-3.el90:3.6.0-13.el9_73
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+171 more1.24.124,068
OSV records
DEBIAN-CVE-2025-61726RHSA-2026:3668RLSA-2026:3668GO-2026-4341
Also known as
BIT-golang-2025-61726

Charts affected

3,608 by stars
ChartLatestAffected imagesRadar Score
prometheus-locust-exporterdeliveryheroVerified publisher1.2.31 of 1See more

prometheus-locust-exporter deliveryhero 1.2.3

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.24.12

Open the chart page →

1,277
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.24.12

Open the chart page →

4,236
bscdysnixVerified publisher0.6.591 of 4See more

bsc dysnix 0.6.59

1 of the 4 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
stdlib@go1.24.9
1.24.12

Open the chart page →

2,316
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
stdlib@go1.13.15
1.24.12

Open the chart page →

2,272
postgres-pgdump-backupeugen0.7.61 of 1See more

postgres-pgdump-backup eugen 0.7.6

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.24.12

Open the chart page →

353
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.24.12

Open the chart page →

12,059
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.24.12

Open the chart page →

14,562
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.24.12

Open the chart page →

13,891
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.24.12

Open the chart page →

5,324
flyte-binaryflyte2.0.491 of 4See more

flyte-binary flyte 2.0.49

1 of the 4 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
library/postgres:15-alpinea46e076249ce
stdlib@go1.24.6
1.24.12

Open the chart page →

4,004
flyte-coreflyte2.0.491 of 3See more

flyte-core flyte 2.0.49

1 of the 3 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
library/postgres:15-alpinea46e076249ce
stdlib@go1.24.6
1.24.12

Open the chart page →

416
frp-operatorfrp-operator1.9.01 of 1See more

frp-operator frp-operator 1.9.0

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
stdlib@go1.23.12
1.24.12

Open the chart page →

542
ascii-moviegabe565Verified publisher0.16.41 of 1See more

ascii-movie gabe565 0.16.4

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
stdlib@go1.24.0
1.24.12

Open the chart page →

1,133
domain-watchgabe565Verified publisher1.1.01 of 1See more

domain-watch gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/gabe565/domain-watch:latest34c5a1e351d6
stdlib@go1.24.1
1.24.12

Open the chart page →

935
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
stdlib@go1.17.7
1.24.12

Open the chart page →

3,036
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.24.12

Open the chart page →

1,111
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
stdlib@go1.15.10
1.24.12

Open the chart page →

1,745
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
stdlib@go1.17.10
1.24.12

Open the chart page →

7,636
multusgeek-cookbookVerified publisher3.5.22 of 3See more

multus geek-cookbook 3.5.2

2 of the 3 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.24.12
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
stdlib@go1.13.10
1.24.12

Open the chart page →

4,916
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
stdlib@go1.18.4
1.24.12

Open the chart page →

9,849
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
stdlib@go1.17.8
1.24.12

Open the chart page →

10,295
smarter-device-managergeek-cookbookVerified publisher6.5.21 of 1See more

smarter-device-manager geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
stdlib@go1.16.4
1.24.12

Open the chart page →

2,337
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
stdlib@go1.14.13
1.24.12

Open the chart page →

3,379
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
stdlib@go1.17
1.24.12

Open the chart page →

2,611
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.24.12

Open the chart page →

10,865
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
stdlib@go1.13.12
1.24.12

Open the chart page →

2,235
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.24.12

Open the chart page →

11,977
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher1.1.21 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 1.1.2

1 of the 3 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
library/mysql:8.4b3b90af2a655
stdlib@go1.24.6
1.24.12

Open the chart page →

1,489
gitvotegitvoteVerified publisher1.5.02 of 6See more

gitvote gitvote 1.5.0

2 of the 6 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.24.12
ghcr.io/cncf/gitvote/dbmigrator:v1.5.0f1e7efe440da
stdlib@go1.25.3
1.24.12

Open the chart page →

5,683
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.24.12

Open the chart page →

6,702
unifi-pollerhalkeye0.1.21 of 1See more

unifi-poller halkeye 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
golift/unifi-poller:2.0.0cafac968b540
stdlib@go1.13.7
1.24.12

Open the chart page →

1,655
whoamiharrytangVerified publisher0.2.01 of 1See more

whoami harrytang 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.24.12

Open the chart page →

353
monitoring-stackhaukitechVerified publisher0.1.113 of 3See more

monitoring-stack haukitech 0.1.11

3 of the 3 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
stdlib@go1.23.1
1.24.12
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.24.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
stdlib@go1.23.3
1.24.12

Open the chart page →

2,166
prometheus-operatorhaukitechVerified publisher0.1.41 of 1See more

prometheus-operator haukitech 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
stdlib@go1.23.1
1.24.12

Open the chart page →

562
headscaleheadscaleVerified publisher1.0.191 of 3See more

headscale headscale 1.0.19

1 of the 3 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
alpine/k8s:1.36.244ef4942e171
stdlib@go1.24.0
1.24.12

Open the chart page →

3,492
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
stdlib@go1.17.2
1.24.12

Open the chart page →

1,559
netbirdhelmforgeVerified publisher1.0.101 of 4See more

netbird helmforge 1.0.10

1 of the 4 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
stdlib@go1.24.6
1.24.12

Open the chart page →

3,099
helm-watchdog-pod-deletehelm-watchdog-pod-delete0.3.01 of 1See more

helm-watchdog-pod-delete helm-watchdog-pod-delete 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
stdlib@go1.24.6
1.24.12

Open the chart page →

1,154
home-assistanthome-assistantVerified publisher0.5.101 of 3See more

home-assistant home-assistant 0.5.10

1 of the 3 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
stdlib@go1.23.3
1.24.12

Open the chart page →

2,360
hpe-cosi-driverhpe-storageVerified publisher2.0.02 of 2See more

hpe-cosi-driver hpe-storage 2.0.0

2 of the 2 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
stdlib@go1.25.0
1.24.12
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.24.12

Open the chart page →

1,696
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
stdlib@go1.19.5
1.24.12

Open the chart page →

2,623
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.21 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

1 of the 5 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.24.12

Open the chart page →

10,752
coreinstill-aiOfficialVerified publisher0.1.756 of 15See more

core instill-ai 0.1.75

6 of the 15 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.24.12
instill/console:0.68.54cd70e2df5c6
stdlib@go1.23.10
1.24.12
library/influxdb:2.3.0-alpined7f5dd5f70e2
stdlib@go1.18.3
1.24.12
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.24.12
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.24.12
openfga/openfga:v1.9.25e94966c11df
stdlib@go1.24.5
1.24.12

Open the chart page →

31,479
intel-gpu-resource-driverintelVerified publisher0.7.01 of 1See more

intel-gpu-resource-driver intel 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
stdlib@go1.23.4
1.24.12

Open the chart page →

566
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
stdlib@go1.15.6
1.24.12

Open the chart page →

2,212
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.24.12

Open the chart page →

4,592
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
stdlib@go1.23.3
1.24.12

Open the chart page →

4,694
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.24.12

Open the chart page →

7,554
k8s-sftp-gcsk8s-sftp-gcsVerified publisher0.1.41 of 1See more

k8s-sftp-gcs k8s-sftp-gcs 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.24.12

Open the chart page →

1,607
k8statusk8statusOfficialVerified publisher0.17.01 of 1See more

k8status k8status 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-61726.

Container imageDigestPackageFixed in
ghcr.io/stenic/k8status:0.17.093298e03089e
stdlib@go1.23.12
1.24.12

Open the chart page →

712

Container images carrying it

4,070 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.24.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.24.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.24.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.24.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.24.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.24.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.24.12
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.24.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.24.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.24.12
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.24.12
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.24.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.24.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.24.12
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.24.12
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.24.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.24.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.24.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.24.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.24.12
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.