CVE-2026-10722
LowAdvisory
Published 3 Jun 2026In the index since 5 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 3.3
- base score, highest
- EPSS
- 0.002
- 8th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 173
- of 17,781 indexed, latest versions
- Container images
- 156
- deployed by those charts
- Fix available
- 1 of 1
- affected package
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
Carried by container images the latest versions of 173 of 17,781 indexed charts deploy, on 156 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v0.0.0-20191113100448-d9fb101ca1fb, v0.4.0, v0.5.0, v0.6.1+22 more | 0.22.0 | 156 |
- OSV records
- GHSA-xhgw-qwwf-pg32
- Also known as
- GO-2026-6238
Charts affected
173 by stars
Container images carrying it
156 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| webdevops/ | f333704ecd60 | github.com/ | 0.22.0 | 1 |
| webdevops/ | 381136dda026 | github.com/ | 0.22.0 | 1 |
| webdevops/ | 7acd46a8a972 | github.com/ | 0.22.0 | 1 |
| webdevops/ | 4fad7e14ad67 | github.com/ | 0.22.0 | 1 |
| gcr.io/ | 135327c978de | github.com/ | 0.22.0 | 1 |
| gcr.io/ | e6c562b5e983 | github.com/ | 0.22.0 | 1 |
| gcr.io/ | 6efe04ba4e06 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 657a2c9f6e6d | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 269d0e55ea97 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | a43323732181 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | c90ca8389c87 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 50b431281d3e | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | c8882543f693 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 5dfa86b6451f | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 45e744fc623f | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | b065ec5a5239 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 14527ca5d2a9 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | a89958921526 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 2434560e8f0e | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 165efd4469ea | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 26f82b148dfe | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 6d6794f45f3e | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | adc0eeb4dd05 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | aab0c99d313f | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | dd31d4713ef6 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | a198ac7bc8c1 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 22f84e3615c8 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 89969b78fb07 | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | d7bdfa7b41da | github.com/ | 0.22.0 | 1 |
| ghcr.io/ | 5afcab98d9d7 | github.com/ | 0.22.0 | 1 |
| public.ecr.aws/ | d94ce715f051 | github.com/ | 0.22.0 | 1 |
| public.ecr.aws/ | 8aa9ea5f67b8 | github.com/ | 0.22.0 | 1 |
| public.ecr.aws/ | f4925b15ce94 | github.com/ | 0.22.0 | 1 |
| public.ecr.aws/ | dc5a516c2333 | github.com/ | 0.22.0 | 1 |
| public.ecr.aws/ | e97e0e7a2088 | github.com/ | 0.22.0 | 1 |
| public.ecr.aws/ | 86380a01587d | github.com/ | 0.22.0 | 1 |
| public.ecr.aws/ | efcecf98b912 | github.com/ | 0.22.0 | 1 |
| quay.io/ | 351d6685dc6f | github.com/ | 0.22.0 | 1 |
| quay.io/ | 858f807ea4e2 | github.com/ | 0.22.0 | 1 |
| quay.io/ | cdcfab5b4466 | github.com/ | 0.22.0 | 1 |
| quay.io/ | 6079308ee15e | github.com/ | 0.22.0 | 1 |
| quay.io/ | db1454e45dc3 | github.com/ | 0.22.0 | 1 |
| quay.io/ | 773886ec9337 | github.com/ | 0.22.0 | 1 |
| quay.io/ | 819c7281f5a4 | github.com/ | 0.22.0 | 1 |
| quay.io/ | cb4e4ffc5789 | github.com/ | 0.22.0 | 1 |
| quay.io/ | 96fac2482898 | github.com/ | 0.22.0 | 1 |
| quay.io/ | 5efd991d218b | github.com/ | 0.22.0 | 1 |
| quay.io/ | 0885ab519dac | github.com/ | 0.22.0 | 1 |
| quay.io/ | 63baf86a49ac | github.com/ | 0.22.0 | 1 |
| quay.io/ | ed8f5118e3a4 | github.com/ | 0.22.0 | 1 |