CVE-2026-10722
LowAdvisory
Published 3 Jun 2026In the index since 5 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 3.3
- base score, highest
- EPSS
- 0.002
- 8th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 173
- of 17,781 indexed, latest versions
- Container images
- 156
- deployed by those charts
- Fix available
- 1 of 1
- affected package
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
Carried by container images the latest versions of 173 of 17,781 indexed charts deploy, on 156 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v0.0.0-20191113100448-d9fb101ca1fb, v0.4.0, v0.5.0, v0.6.1+22 more | 0.22.0 | 156 |
- OSV records
- GHSA-xhgw-qwwf-pg32
- Also known as
- GO-2026-6238
Charts affected
173 by stars
Container images carrying it
156 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 4ec6df40fdb9 | github.com/ | 0.22.0 | 7 |
| registry.k8s.io/ | 37d841299325 | github.com/ | 0.22.0 | 6 |
| registry.k8s.io/ | 639a1e2da549 | github.com/ | 0.22.0 | 6 |
| rancher/ | 5f6c4dc52a05 | github.com/ | 0.22.0 | 4 |
| ghcr.io/ | 6d4c9fe66e4f | github.com/ | 0.22.0 | 4 |
| ghcr.io/ | 824d6d78d451 | github.com/ | 0.22.0 | 4 |
| derailed/ | 8e68e22c7663 | github.com/ | 0.22.0 | 3 |
| prom/ | 565ee8650122 | github.com/ | 0.22.0 | 3 |
| quay.io/ | 378f4e037035 | github.com/ | 0.22.0 | 3 |
| grafana/ | 7790f6f7fbd8 | github.com/ | 0.22.0 | 2 |
| grafana/ | f94b1c82957a | github.com/ | 0.22.0 | 2 |
| k0sproject/ | f04635825d51 | github.com/ | 0.22.0 | 2 |
| library/ | 5efed980cba3 | github.com/ | 0.22.0 | 2 |
| moby/ | 504731e577c2 | github.com/ | 0.22.0 | 2 |
| otel/ | 125bdbeb7590 | github.com/ | 0.22.0 | 2 |
| otel/ | 7ef2a2ff46b9 | github.com/ | 0.22.0 | 2 |
| prom/ | 5c435642ca4d | github.com/ | 0.22.0 | 2 |
| rancher/ | 9380f5dbae9a | github.com/ | 0.22.0 | 2 |
| uselagoon/ | 2c89ed939b8b | github.com/ | 0.22.0 | 2 |
| ghcr.io/ | 2659f4c2ebb7 | github.com/ | 0.22.0 | 2 |
| ghcr.io/ | 56f8617363b4 | github.com/ | 0.22.0 | 2 |
| quay.io/ | afc9458ba4bc | github.com/ | 0.22.0 | 2 |
| quay.io/ | 193280a33bc1 | github.com/ | 0.22.0 | 2 |
| quay.io/ | 944b2c67345c | github.com/ | 0.22.0 | 2 |
| quay.io/ | c96d4fb1d57f | github.com/ | 0.22.0 | 2 |
| quay.io/ | af92db7eac86 | github.com/ | 0.22.0 | 2 |
| quay.io/ | dde69a8b6f4b | github.com/ | 0.22.0 | 2 |
| quay.io/ | 075b1ba2c4eb | github.com/ | 0.22.0 | 2 |
| quay.io/ | 6559acbd5d77 | github.com/ | 0.22.0 | 2 |
| quay.io/ | f6639335d34a | github.com/ | 0.22.0 | 2 |
| amazon/ | d8ab0eef5074 | github.com/ | 0.22.0 | 1 |
| amazon/ | 73b79b02f03a | github.com/ | 0.22.0 | 1 |
| amazon/ | e745d1783c93 | github.com/ | 0.22.0 | 1 |
| bitnamilegacy/ | 08b1b7cb6a5b | github.com/ | 0.22.0 | 1 |
| bitnamilegacy/ | 5bf82b98c82c | github.com/ | 0.22.0 | 1 |
| concourse/ | 40a143ce5873 | github.com/ | 0.22.0 | 1 |
| coordimap/ | 7748fd0fae9f | github.com/ | 0.22.0 | 1 |
| datadog/ | aad9994de6a7 | github.com/ | 0.22.0 | 1 |
| datasaker/ | 08b52999f67b | github.com/ | 0.22.0 | 1 |
| ddosify/ | ea602056d9ce | github.com/ | 0.22.0 | 1 |
| erigontech/ | 2252efdf9abe | github.com/ | 0.22.0 | 1 |
| erigontech/ | 88706754b627 | github.com/ | 0.22.0 | 1 |
| falcosecurity/ | 0eeb79adc580 | github.com/ | 0.22.0 | 1 |
| falcosecurity/ | 7df783d5269a | github.com/ | 0.22.0 | 1 |
| galaxy/ | e50a890e24c9 | github.com/ | 0.22.0 | 1 |
| gitea/ | 6120b1165f3a | github.com/ | 0.22.0 | 1 |
| gocrane/ | a1400909118c | github.com/ | 0.22.0 | 1 |
| grafana/ | 3364714a2f64 | github.com/ | 0.22.0 | 1 |
| grafana/ | f6cbec9409be | github.com/ | 0.22.0 | 1 |
| grafana/ | 01a63f4e032c | github.com/ | 0.22.0 | 1 |