StackRadar

CVE-2026-27137

Unscored

Advisory

Published 6 Mar 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
72
of 17,781 indexed, latest versions
Container images
67
deployed by those charts
Fix available
1 of 1
affected package

Incorrect enforcement of email constraints in crypto/x509

Carried by container images the latest versions of 72 of 17,781 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.26.01.26.167
OSV records
GO-2026-4599
Also known as
BIT-golang-2026-27137

Charts affected

72 by stars
ChartLatestAffected imagesRadar Score
castopodhelmforgeVerified publisher1.2.71 of 3See more

castopod helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
stdlib@go1.26.0
1.26.1

Open the chart page →

9,342
blockyk8s-home-lab-repo11.2.11 of 1See more

blocky k8s-home-lab-repo 11.2.1

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.29.0a6d99f323d30
stdlib@go1.26.0
1.26.1

Open the chart page →

580
kbot-self-hostedkbot-self-hostedVerified publisher0.1.81 of 7See more

kbot-self-hosted kbot-self-hosted 0.1.8

1 of the 7 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.30206a6c708fc6
stdlib@go1.26.0
1.26.1

Open the chart page →

32,509
pocket-idkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

pocket-id kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
stdlib@go1.26.0
1.26.1

Open the chart page →

1,513
kubernetes-nmstatekubernetes-nmstateVerified publisher0.87.01 of 1See more

kubernetes-nmstate kubernetes-nmstate 0.87.0

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
quay.io/nmstate/kubernetes-nmstate-operator:v0.87.04dce694f01ea
stdlib@go1.26.0
1.26.1

Open the chart page →

354
gar-credential-providermondu-aiVerified publisher0.2.11 of 1See more

gar-credential-provider mondu-ai 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
stdlib@go1.26.0
1.26.1

Open the chart page →

708
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-backend:2.0.0f80349eb018b
stdlib@go1.26.0
1.26.1

Open the chart page →

3,798
nri-memory-policynri-pluginsVerified publisher0.14.01 of 1See more

nri-memory-policy nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memory-policy:v0.14.0531d21ec4ba2
stdlib@go1.26.0
1.26.1

Open the chart page →

265
nri-memory-qosnri-pluginsOfficialVerified publisher0.14.01 of 1See more

nri-memory-qos nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memory-qos:v0.14.0c7c5c24ed894
stdlib@go1.26.0
1.26.1

Open the chart page →

265
nri-resctrl-monnri-pluginsVerified publisher0.14.01 of 1See more

nri-resctrl-mon nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resctrl-mon:v0.14.0a9c9775fab70
stdlib@go1.26.0
1.26.1

Open the chart page →

265
nri-resource-annotatornri-pluginsVerified publisher0.14.01 of 1See more

nri-resource-annotator nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resource-annotator:v0.14.08100a19e85f7
stdlib@go1.26.0
1.26.1

Open the chart page →

235
nri-resource-policy-templatenri-pluginsVerified publisher0.14.01 of 1See more

nri-resource-policy-template nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resource-policy-template:v0.14.00edfc075277b
stdlib@go1.26.0
1.26.1

Open the chart page →

279
nri-sgx-epcnri-pluginsVerified publisher0.14.01 of 1See more

nri-sgx-epc nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-sgx-epc:v0.14.0b4c4d0d83c14
stdlib@go1.26.0
1.26.1

Open the chart page →

265
picoclawpicoclawVerified publisher0.1.261 of 1See more

picoclaw picoclaw 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/mattn/picoclaw:latest517556c8b144
stdlib@go1.26.0
1.26.1

Open the chart page →

1,556
gotifyrubxkubeVerified publisher1.3.31 of 1See more

gotify rubxkube 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
gotify/server:3.1.0be44495e4609
stdlib@go1.26.0
1.26.1

Open the chart page →

320
operatorshopware-storeVerified publisher1.8.11 of 1See more

operator shopware-store 1.8.1

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/shopware/shopware-operator:1.8.187db0eda7a03
stdlib@go1.26.0
1.26.1

Open the chart page →

571
sigstore-probersigstoreVerified publisher0.3.11 of 1See more

sigstore-prober sigstore 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
stdlib@go1.26.0
1.26.1

Open the chart page →

424
trilliansigstoreVerified publisher0.3.172 of 5See more

trillian sigstore 0.3.17

2 of the 5 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
stdlib@go1.26.0
1.26.1
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
stdlib@go1.26.0
1.26.1

Open the chart page →

2,808
skyhook-agentskyhookVerified publisher1.3.151 of 1See more

skyhook-agent skyhook 1.3.15

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/skyhook-io/skyhook-connector:v2.3.23deb8e4b1aaa
stdlib@go1.26.0
1.26.1

Open the chart page →

299
spire-identity-exchangespiffeVerified publisher0.2.21 of 3See more

spire-identity-exchange spiffe 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-identity-exchange-server:v0.5.0239bc70c1988
stdlib@go1.26.0
1.26.1

Open the chart page →

1,427
hub-managertraefikVerified publisher1.0.01 of 1See more

hub-manager traefik 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
ghcr.io/traefik/hub-manager:v0.45.1d1cff2560c67
stdlib@go1.26.0
1.26.1

Open the chart page →

634
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-27137.

Container imageDigestPackageFixed in
wallarm/node-native-processing:0.23.07db2da8fce0b
stdlib@go1.26.0
1.26.1

Open the chart page →

2,824

Container images carrying it

67 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/hsn723/dkim-manager:1.4.00312232b31a2
stdlib@go1.26.0
1.26.1
1
ghcr.io/lexfrei/extractedprism:v0.3.0d10417753727
stdlib@go1.26.0
1.26.1
1
ghcr.io/mattn/picoclaw:latest517556c8b144
stdlib@go1.26.0
1.26.1
1
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
stdlib@go1.26.0
1.26.1
1
ghcr.io/naval-group/butane-operator:v0.1.1-rc285818b510780
stdlib@go1.26.0
1.26.1
1
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
stdlib@go1.26.0
1.26.1
1
ghcr.io/shopware/shopware-operator:1.8.187db0eda7a03
stdlib@go1.26.0
1.26.1
1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
stdlib@go1.26.0
1.26.1
1
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
stdlib@go1.26.0
1.26.1
1
ghcr.io/skyhook-io/skyhook-connector:v2.3.23deb8e4b1aaa
stdlib@go1.26.0
1.26.1
1
ghcr.io/spiffe/spire-identity-exchange-server:v0.5.0239bc70c1988
stdlib@go1.26.0
1.26.1
1
ghcr.io/traefik/hub-manager:v0.45.1d1cff2560c67
stdlib@go1.26.0
1.26.1
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
stdlib@go1.26.0
1.26.1
1
quay.io/maxiv/mortalgpu:1.3.7e1c5c194bbf0
stdlib@go1.26.0
1.26.1
1
quay.io/nmstate/kubernetes-nmstate-operator:v0.87.04dce694f01ea
stdlib@go1.26.0
1.26.1
1
registry.k8s.io/descheduler/descheduler:v0.36.07ca92c0a7b4f
stdlib@go1.26.0
1.26.1
1
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
stdlib@go1.26.0
1.26.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.