StackRadar

CVE-2026-27139

Low

Advisory

Published 6 Mar 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,843
of 17,813 indexed, latest versions
Container images
4,361
deployed by those charts
Fix available
1 of 2
affected packages

FileInfo can escape from a Root in os

Carried by container images the latest versions of 3,843 of 17,813 indexed charts deploy, on 4,361 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+177 more1.25.84,361
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-27139GO-2026-4602
Also known as
BIT-golang-2026-27139

Charts affected

3,843 by stars
ChartLatestAffected imagesRadar Score
vmot-container-kit0.0.34 of 7See more

vm ot-container-kit 0.0.3

4 of the 7 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
stdlib@go1.22.4
1.25.8
victoriametrics/operator:v0.47.271be93cfafb6
stdlib@go1.23.0
1.25.8
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.8

Open the chart page →

5,428
otel-add-onotel-add-onVerified publisher0.1.41 of 1See more

otel-add-on otel-add-on 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/kedify/otel-add-on:v0.1.4a6f2155bd822
stdlib@go1.24.3
1.25.8

Open the chart page →

734
adotowan-charts0.1.01 of 1See more

adot owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
stdlib@go1.24.3
1.25.8

Open the chart page →

1,033
httpbunowan-charts0.1.01 of 1See more

httpbun owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
sharat87/httpbun:latest405332d9050a
stdlib@go1.25.1
1.25.8

Open the chart page →

314
minioowan-charts0.1.21 of 2See more

minio owan-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
stdlib@go1.24.4
1.25.8

Open the chart page →

1,083
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
stdlib@go1.17
1.25.8

Open the chart page →

1,827
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
stdlib@go1.22.5
1.25.8

Open the chart page →

1,997
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
stdlib@go1.22.1
1.25.8

Open the chart page →

3,695
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
stdlib@go1.22.5
1.25.8

Open the chart page →

3,362
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
stdlib@go1.21.1
1.25.8
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
stdlib@go1.21.1
1.25.8

Open the chart page →

2,336
predicatep2p-avs0.1.41 of 1See more

predicate p2p-avs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
stdlib@go1.23.5
1.25.8

Open the chart page →

893
p4p40.1.03 of 7See more

p4 p4 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
stdlib@go1.18.10
1.25.8
library/mongo:5.0-focal5e15a3f014ed
stdlib@go1.24.6
1.25.8
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.8

Open the chart page →

27,879
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.8

Open the chart page →

19,768
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
stdlib@go1.24.0
1.25.8

Open the chart page →

3,627
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-andromeda1.0.01 of 3See more

pages pages-andromeda 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespagesbadami1.0.01 of 3See more

pages pagesbadami 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-blackburn1.0.01 of 3See more

pages pages-blackburn 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-botes1.0.01 of 3See more

pages pages-botes 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-brian1.0.01 of 3See more

pages pages-brian 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-buckll1.0.01 of 3See more

pages pages-buckll 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-camden1.0.01 of 3See more

pages pages-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-camden7711.0.01 of 3See more

pages pages-camden771 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-diarmuidkeane1.0.01 of 3See more

pages pages-diarmuidkeane 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-draco1.0.01 of 3See more

pages pages-draco 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-ellora1.0.01 of 3See more

pages pages-ellora 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-finchley1.0.01 of 3See more

pages pages-finchley 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-fornax1.0.01 of 3See more

pages pages-fornax 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-harsh1.0.01 of 3See more

pages pages-harsh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespagesk1.0.01 of 3See more

pages pagesk 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-microservice-ashim1.0.01 of 3See more

pages pages-microservice-ashim 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-mihai1.0.01 of 3See more

pages pages-mihai 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-nivesh1.0.01 of 3See more

pages pages-nivesh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespagessandeepgudu1.0.01 of 3See more

pages pagessandeepgudu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-shubhanker1.0.01 of 3See more

pages pages-shubhanker 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-ssharma09091.0.01 of 3See more

pages pages-ssharma0909 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-sucharitha1.0.01 of 3See more

pages pages-sucharitha 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-sudhir1.0.01 of 3See more

pages pages-sudhir 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-sushi1.0.01 of 3See more

pages pages-sushi 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-vasanth58141.0.01 of 3See more

pages pages-vasanth5814 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
pagespages-vjp1.0.01 of 3See more

pages pages-vjp 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,285
paperclippaperclip-helmVerified publisher0.1.01 of 3See more

paperclip paperclip-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.8

Open the chart page →

494
paperclip-operatorpaperclip-operatorVerified publisher0.19.11 of 1See more

paperclip-operator paperclip-operator 0.19.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/paperclipinc/paperclip-operator:v0.19.10984b890eb38
stdlib@go1.25.0
1.25.8

Open the chart page →

352

Container images carrying it

4,361 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
stdlib@go1.23.7
1.25.8
1
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
stdlib@go1.22.8
1.25.8
1
bitnamilegacy/postgresql:15.2.0-debian-11-r113e65a6b89e38
stdlib@go1.18.2
1.25.8
1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
stdlib@go1.22.7
1.25.8
1
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
stdlib@go1.16.7
1.25.8
1
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
stdlib@go1.16.7
1.25.8
1
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
stdlib@go1.17
1.25.8
1
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.25.8
1
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.25.8
1
bitnamilegacy/redis:7.2.5-debian-12-r05261cae9e407
stdlib@go1.21.10
1.25.8
1
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.25.8
1
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
stdlib@go1.23.7
1.25.8
1
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.25.8
1
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.25.8
1
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.25.8
1
bitnamilegacy/redis:7.0.8-debian-11-r0bf01d031ba8c
stdlib@go1.18.2
1.25.8
1
bitnamilegacy/redis:8.0.2-debian-12-r4cdc2efa9c306
stdlib@go1.24.4
1.25.8
1
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
stdlib@go1.19.12
1.25.8
1
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
stdlib@go1.23.8
1.25.8
1
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.25.8
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
stdlib@go1.17
1.25.8
1
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
stdlib@go1.24.1
1.25.8
1
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
stdlib@go1.23.4
1.25.8
1
bitnamilegacy/valkey:latest0384ca2eec63
stdlib@go1.23.10
1.25.8
1
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
stdlib@go1.24.6
1.25.8
1
bitnamilegacy/valkey:8.1.3-debian-12-r1a185655855b3
stdlib@go1.24.4
1.25.8
1
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
stdlib@go1.21.5
1.25.8
1
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
stdlib@go1.18.2
1.25.8
1
bitnami/mariadb:11.7.216a7dae804fb
stdlib@go1.22.12
1.25.8
1
bitnami/mongodb:8.0.8b3bd5b6be9a0
stdlib@go1.23.7
1.25.8
1
bitnami/redis:7.4.24e65bf641805
stdlib@go1.23.8
1.25.8
1
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
stdlib@go1.18.6
1.25.8
1
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
stdlib@go1.24.6
1.25.8
1
bitpoke/stack-default-backend:latestc5eed1ddf692
stdlib@go1.16.6
1.25.8
1
bitpoke/wordpress-operator:v0.12.421284d1df473
stdlib@go1.17.13
1.25.8
1
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
stdlib@go1.17.13
1.25.8
1
blackducksoftware/bdba-pgupgrader:2026.6.35c97f3a3f8b7
stdlib@go1.18.2
1.25.8
1
blackducksoftware/blackduck-alert-db:8.4.06310fac39d53
stdlib@go1.24.6
1.25.8
1
blipai/deckard:0.0.28737d5d19a312
stdlib@go1.18.10
1.25.8
1
bloomberg/goldpinger:3.10.08520120f5598
stdlib@go1.21.9
1.25.8
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
stdlib@go1.22.11
1.25.8
1
bolkedebruin/rdpgw:masterc0dc0589373a
stdlib@go1.24.13
1.25.8
1
bonovoo/secrethor:1.1.2bb93b68fcd17
stdlib@go1.24.2
1.25.8
1
breton/cool:dev41b1bb483aa2
stdlib@go1.19.2
1.25.8
1
bsgrigorov/helm-operator:latest45ab095f09c8
stdlib@go1.15.12
1.25.8
1
btcpayserver/tor:0.4.8.10e9585b68dc6b
stdlib@go1.16.5
1.25.8
1
buddyspencer/gickup:0.10.386b656f19b0c1
stdlib@go1.22.5
1.25.8
1
buddyspencer/gickup:0.10.309e7dbf923c12
stdlib@go1.21.9
1.25.8
1
buildkite/agent:3.25.0aec38cfaae0e
stdlib@go1.14.7
1.25.8
1
bulich/domain-exporter:latest6d0b780f7c7b
stdlib@go1.20.4
1.25.8
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.