StackRadar

CVE-2026-27139

Low

Advisory

Published 6 Mar 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,718
of 17,781 indexed, latest versions
Container images
4,229
deployed by those charts
Fix available
1 of 2
affected packages

FileInfo can escape from a Root in os

Carried by container images the latest versions of 3,718 of 17,781 indexed charts deploy, on 4,229 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+175 more1.25.84,229
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-27139GO-2026-4602
Also known as
BIT-golang-2026-27139

Charts affected

3,718 by stars
ChartLatestAffected imagesRadar Score
veleromesosphere3.2.51 of 1See more

velero mesosphere 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
stdlib@go1.19.8
1.25.8

Open the chart page →

1,869
kubecostmesosphere-stable0.37.57 of 9See more

kubecost mesosphere-stable 0.37.5

7 of the 9 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
stdlib@go1.22.7
1.25.8
grafana/grafana:9.4.71a359d92f40e
stdlib@go1.20.1
1.25.8
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
stdlib@go1.21.5
1.25.8
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
stdlib@go1.21.4
1.25.8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.8
quay.io/prometheus/prometheus:v2.55.0378f4e037035
stdlib@go1.23.2
1.25.8
quay.io/thanos/thanos:v0.36.1e542959e1b36
stdlib@go1.21.13
1.25.8

Open the chart page →

17,693
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
stdlib@go1.17.2
1.25.8

Open the chart page →

2,743
helm-ai-kernelmindburn-labsOfficialVerified publisher0.8.51 of 2See more

helm-ai-kernel mindburn-labs 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
stdlib@go1.22.5
1.25.8

Open the chart page →

2,160
mortalgpumortalgpuOfficialVerified publisher1.3.71 of 1See more

mortalgpu mortalgpu 1.3.7

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/maxiv/mortalgpu:1.3.7e1c5c194bbf0
stdlib@go1.26.0
1.25.8

Open the chart page →

372
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
stdlib@go1.19
1.25.8

Open the chart page →

3,793
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
stdlib@go1.24.13
1.25.8

Open the chart page →

4,060
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
stdlib@go1.13.8
1.25.8

Open the chart page →

5,067
gateway-apinicklasfrahm-gateway-apiVerified publisher0.2.01 of 1See more

gateway-api nicklasfrahm-gateway-api 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
alpine/kubectl:1.33.32c59a3f0726c
stdlib@go1.24.4
1.25.8

Open the chart page →

1,257
observalobservalVerified publisher1.13.11 of 8See more

observal observal 1.13.1

1 of the 8 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.8

Open the chart page →

5,828
aws-xrayokgoloveVerified publisher5.0.01 of 1See more

aws-xray okgolove 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
public.ecr.aws/xray/aws-xray-daemon:3.6.243d051eed000
stdlib@go1.25.7
1.25.8

Open the chart page →

273
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
stdlib@go1.25.5
1.25.8

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
stdlib@go1.17.1
1.25.8
jwilder/dockerize:latestf94fb59fb4f6
stdlib@go1.25.5
1.25.8

Open the chart page →

18,517
secrets-injectoronepassword-connect1.2.01 of 1See more

secrets-injector onepassword-connect 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
1password/kubernetes-secrets-injector:1.0.25884757f7879
stdlib@go1.20.5
1.25.8

Open the chart page →

890
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
alpine/git:2.47.2062a01ad7a0e
stdlib@go1.23.9
1.25.8

Open the chart page →

5,218
opentelemetry-ebpfopentelemetry-helmVerified publisher0.1.71 of 4See more

opentelemetry-ebpf opentelemetry-helm 0.1.7

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
stdlib@go1.20
1.25.8

Open the chart page →

2,573
oesopsmxVerified publisher4.0.3210 of 25See more

oes opsmx 4.0.32

10 of the 25 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
stdlib@go1.15.5
1.25.8
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
stdlib@go1.15.5
1.25.8
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
stdlib@go1.17.2
1.25.8
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
stdlib@go1.16.15
1.25.8
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
stdlib@go1.20.3
1.25.8
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
stdlib@go1.19.1
1.25.8
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
stdlib@go1.24.11
1.25.8
quay.io/opsmxpublic/opa:1.12.084fb1af7401c
stdlib@go1.25.5
1.25.8
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
stdlib@go1.22.2
1.25.8
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
stdlib@go1.13.1
1.25.8

Open the chart page →

107,811
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
stdlib@go1.18.3
1.25.8
ipfs/ipfs-cluster:1.0.21511f6d57994
stdlib@go1.18.3
1.25.8

Open the chart page →

3,757
permifypermifyVerified publisher0.5.01 of 1See more

permify permify 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/permify/permify:v1.3.5f0c6f7d7daa6
stdlib@go1.22.4
1.25.8

Open the chart page →

997
platzioplatz-ioVerified publisher0.6.51 of 2See more

platzio platz-io 0.6.5

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
platzio/backend:v0.6.5d5e5972f344b
stdlib@go1.24.3
1.25.8

Open the chart page →

2,866
plecopleco0.24.01 of 1See more

pleco pleco 0.24.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
stdlib@go1.21.6
1.25.8

Open the chart page →

1,346
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
stdlib@go1.13.10
1.25.8

Open the chart page →

2,995
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
stdlib@go1.20.3
1.25.8

Open the chart page →

1,942
prometheus-systemd-exporterprometheus-communityVerified publisher0.5.21 of 1See more

prometheus-systemd-exporter prometheus-community 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/systemd-exporter:v0.7.078c03f875dfb
stdlib@go1.24.1
1.25.8

Open the chart page →

725
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
stdlib@go1.15.1
1.25.8
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
stdlib@go1.15.3
1.25.8
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
stdlib@go1.14.12
1.25.8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.25.8

Open the chart page →

12,125
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
stdlib@go1.24.0
1.25.8

Open the chart page →

5,435
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
stdlib@go1.15
1.25.8

Open the chart page →

2,730
repoflowrepoflow-helm-public0.9.12 of 8See more

repoflow repoflow-helm-public 0.9.1

2 of the 8 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.25.8
minio/minio:RELEASE.2025-07-23T15-54-02Zd249d1fb6966
stdlib@go1.24.5
1.25.8

Open the chart page →

13,521
backrestrobertobochetVerified publisher0.7.01 of 1See more

backrest robertobochet 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
garethgeorge/backrest:v1.14.1b85297975428
stdlib@go1.26.0
1.25.8

Open the chart page →

859
supabaserock8sVerified publisher0.0.61 of 1See more

supabase rock8s 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.8

Open the chart page →

493
rqliterqliteOfficialVerified publisher2.0.01 of 1See more

rqlite rqlite 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
rqlite/rqlite:9.1.37b992a526eee
stdlib@go1.25.3
1.25.8

Open the chart page →

1,311
qbittorrent-vpnrtomik-helm-chartsVerified publisher0.0.21 of 2See more

qbittorrent-vpn rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.40.02b42bfa04675
stdlib@go1.23.4
1.25.8

Open the chart page →

1,218
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
stdlib@go1.18.1
1.25.8

Open the chart page →

3,427
seaweedfs-csi-driverseaweedfs-csi-driver0.2.385 of 7See more

seaweedfs-csi-driver seaweedfs-csi-driver 0.2.38

5 of the 7 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
stdlib@go1.20.3
1.25.8
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
stdlib@go1.20.3
1.25.8
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
stdlib@go1.20.3
1.25.8
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
stdlib@go1.20.3
1.25.8
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
stdlib@go1.20.3
1.25.8

Open the chart page →

5,270
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
stdlib@go1.24.11
1.25.8

Open the chart page →

841
bentoself-hosters-by-nightVerified publisher0.9.11 of 1See more

bento self-hosters-by-night 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
stdlib@go1.23.10
1.25.8

Open the chart page →

1,046
lldapself-hosters-by-nightVerified publisher0.5.22 of 2See more

lldap self-hosters-by-night 0.5.2

2 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
stdlib@go1.24.6
1.25.8
ghcr.io/lldap/lldap:2025-05-193de697c3ba57
stdlib@go1.18.2
1.25.8

Open the chart page →

3,400
appshini4iVerified publisher0.4.01 of 1See more

app shini4i 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
traefik/whoami:v1.10.21474027c3166
stdlib@go1.22.2
1.25.8

Open the chart page →

537
skypilotskypilotOfficialVerified publisher0.13.03 of 3See more

skypilot skypilot 0.13.0

3 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
stdlib@go1.24.11
1.25.8
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
stdlib@go1.24.4
1.25.8
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
stdlib@go1.24.4
1.25.8

Open the chart page →

5,852
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
stdlib@go1.20
1.25.8

Open the chart page →

1,663
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
stdlib@go1.14.2
1.25.8
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
stdlib@go1.14.2
1.25.8
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
stdlib@go1.14.2
1.25.8
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
stdlib@go1.14.2
1.25.8
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
stdlib@go1.14.2
1.25.8

Open the chart page →

12,502
miniosolidchartsVerified publisher0.5.01 of 1See more

minio solidcharts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
stdlib@go1.24.6
1.25.8

Open the chart page →

1,055
ingressmonitorcontrollerstakaterVerified publisher2.2.131 of 1See more

ingressmonitorcontroller stakater 2.2.13

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
stdlib@go1.24.13
1.25.8

Open the chart page →

576
sn-platformstreamnative1.11.446 of 9See more

sn-platform streamnative 1.11.44

6 of the 9 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.8
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
stdlib@go1.20.4
1.25.8
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
stdlib@go1.17.11
1.25.8
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
stdlib@go1.19.4
1.25.8
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.25.8
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.8

Open the chart page →

15,477
pocketbasetechwolf12Verified publisher0.29.31 of 1See more

pocketbase techwolf12 0.29.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
stdlib@go1.24.6
1.25.8

Open the chart page →

1,446
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.8

Open the chart page →

9,770
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
stdlib@go1.24.4
1.25.8

Open the chart page →

3,804
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.263 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

3 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
stdlib@go1.20.5
1.25.8
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
stdlib@go1.19.12
1.25.8
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.25.8

Open the chart page →

14,566
feedbacksystemthm-mni-iiVerified publisher0.47.16 of 10See more

feedbacksystem thm-mni-ii 0.47.1

6 of the 10 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
stdlib@go1.21.5
1.25.8
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
stdlib@go1.19.12
1.25.8
bitnamilegacy/mysql:8.0.35-debian-11-r2be03e8ea6129
stdlib@go1.21.5
1.25.8
library/docker:20.10.21-dind3153fa63f546
stdlib@go1.18.7
1.25.8
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
stdlib@go1.20.12
1.25.8
thmmniii/fbs-runner:v1.27.186105349c1a3
stdlib@go1.20.11
1.25.8

Open the chart page →

28,534
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
stdlib@go1.24.2
1.25.8

Open the chart page →

1,494

Container images carrying it

4,229 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
stdlib@go1.25.7
1.25.8
3
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
stdlib@go1.23.12
1.25.8
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
stdlib@go1.16
1.25.8
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
stdlib@go1.15
1.25.8
3
derailed/popeye:v0.22.18e68e22c7663
stdlib@go1.23.5
1.25.8
3
dgraph/dgraph:v21.12.03b55ea83fffe
stdlib@go1.17.3
1.25.8
3
ethpandaops/tracoor:latestd8514b9f4c59
stdlib@go1.24.13
1.25.8
3
grafana/grafana:8.2.500568d89c4f8
stdlib@go1.17
1.25.8
3
grafana/grafana:11.0.00dc5a246ab16
stdlib@go1.21.10
1.25.8
3
grafana/grafana:11.3.0a0f881232a6f
stdlib@go1.23.1
1.25.8
3
grafana/loki:3.4.258a6c186ce78
stdlib@go1.23.6
1.25.8
3
grafana/loki-canary:3.6.70dac7d5cb383
stdlib@go1.24.13
1.25.8
3
grafana/promtail:2.4.2626900031c4e
stdlib@go1.17.2
1.25.8
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.25.8
3
hashicorp/http-echo:1.0.0:latestfcb75f691c8b
stdlib@go1.21.1
1.25.8
3
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.8
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
stdlib@go1.25.4
1.25.8
3
library/docker:20.10-dind:20-dindaf96c680a7e1
stdlib@go1.19.7
1.25.8
3
library/mysql:latest66aec17cd21a
stdlib@go1.24.6
1.25.8
3
library/nats:2.10-alpineb83efabe3e7d
stdlib@go1.24.2
1.25.8
3
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.25.8
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.25.8
3
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.8
3
library/postgres:14-alpine727876d27466
stdlib@go1.24.6
1.25.8
3
library/rabbitmq:4.3.5-management:4-management:managementffd1b50c522a
stdlib@go1.22.2
1.25.8
3
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.8
3
migrate/migrate:latestcc4ad8e19d66
stdlib@go1.25.4
1.25.8
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
stdlib@go1.15.7
1.25.8
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
stdlib@go1.13.11
1.25.8
3
natsio/nats-box:0.19.28031d190c7ee
stdlib@go1.25.2
1.25.8
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.25.8
3
oryd/hydra:v2.2.02c93beb5e5f2
stdlib@go1.21.5
1.25.8
3
prom/alertmanager:v0.28.0d5155cfac40a
stdlib@go1.23.4
1.25.8
3
prom/prometheus:v3.0.1565ee8650122
stdlib@go1.23.3
1.25.8
3
prom/prometheus:v2.19.0bfad037f95e5
stdlib@go1.14.4
1.25.8
3
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.25.8
3
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.8
3
prom/statsd-exporter:v0.28.04e7a1f00b9b2
stdlib@go1.23.2
1.25.8
3
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.25.8
3
rancher/kubectl:v1.34.1090bef429ed1
stdlib@go1.24.6
1.25.8
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.25.8
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
stdlib@go1.21.3
1.25.8
3
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.25.8
3
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.25.8
3
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.25.8
3
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
stdlib@go1.22.7
1.25.8
3
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
stdlib@go1.22.7
1.25.8
3
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.25.8
3
vikunja/vikunja:0.24.6ed1f3ed467fe
stdlib@go1.23.4
1.25.8
3
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.25.8
3

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.