StackRadar

CVE-2026-27139

Low

Advisory

Published 6 Mar 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,897
of 17,828 indexed, latest versions
Container images
4,417
deployed by those charts
Fix available
1 of 2
affected packages

FileInfo can escape from a Root in os

Carried by container images the latest versions of 3,897 of 17,828 indexed charts deploy, on 4,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+178 more1.25.84,417
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-27139GO-2026-4602
Also known as
BIT-golang-2026-27139

Charts affected

3,897 by stars
ChartLatestAffected imagesRadar Score
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.8

Open the chart page →

4,261
apimicroslacVerified publisher0.1.01 of 2See more

api microslac 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.1999213b98257
stdlib@go1.21.9
1.25.8

Open the chart page →

3,428
argomicroslacVerified publisher0.1.03 of 4See more

argo microslac 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.8
ghcr.io/dexidp/dex:v2.38.0b1d793440a98
stdlib@go1.21.6
1.25.8
quay.io/argoproj/argocd:v2.10.783c86003b781
stdlib@go1.20.10
1.25.8

Open the chart page →

10,009
streamsmicroslacVerified publisher0.1.01 of 6See more

streams microslac 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
microslac/kafka-connect:latesta90091a1f524
stdlib@go1.20.4
1.25.8

Open the chart page →

19,868
kube-agent-chartmiddleware-labsVerified publisher0.1.21 of 1See more

kube-agent-chart middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
stdlib@go1.18.9
1.25.8

Open the chart page →

1,809
middleware-odigosmiddleware-labsVerified publisher0.2.414 of 6See more

middleware-odigos middleware-labs 0.2.41

4 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
stdlib@go1.18.10
1.25.8
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
stdlib@go1.18.10
1.25.8
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
stdlib@go1.19.6
1.25.8
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
stdlib@go1.18.10
1.25.8

Open the chart page →

8,386
middleware-visionmiddleware-labsVerified publisher0.2.654 of 6See more

middleware-vision middleware-labs 0.2.65

4 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
stdlib@go1.18.10
1.25.8
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
stdlib@go1.18.10
1.25.8
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
stdlib@go1.19.7
1.25.8
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
stdlib@go1.18.10
1.25.8

Open the chart page →

8,378
mw-autoinstrumentationmiddleware-labsVerified publisher1.2.65 of 6See more

mw-autoinstrumentation middleware-labs 1.2.6

5 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-auto-injector:0.1.18512248e17e8
stdlib@go1.23.12
1.25.8
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
stdlib@go1.24.0
1.25.8
ghcr.io/middleware-labs/mw-lang-detector:0.1.2a4776aa2a56b
stdlib@go1.23.12
1.25.8
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.132.05e331c925091
stdlib@go1.24.6
1.25.8
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
stdlib@go1.24.2
1.25.8

Open the chart page →

3,756
mw-kube-agentmiddleware-labsVerified publisher0.1.21 of 1See more

mw-kube-agent middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
stdlib@go1.20.14
1.25.8

Open the chart page →

1,612
mw-kube-agent-v3middleware-labsVerified publisher1.8.52 of 2See more

mw-kube-agent-v3 middleware-labs 1.8.5

2 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
stdlib@go1.25.6
1.25.8
ghcr.io/middleware-labs/mw-kube-agent-config-updater:1.21.0d4edc3f244f4
stdlib@go1.25.6
1.25.8

Open the chart page →

2,124
sshportalmidokura-communityVerified publisher0.1.41 of 2See more

sshportal midokura-community 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
moul/sshportal:v1.19.3332b603727c3
stdlib@go1.17.6
1.25.8

Open the chart page →

2,339
argocd-extra-app-info-exportermikejohVerified publisher0.1.121 of 1See more

argocd-extra-app-info-exporter mikejoh 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
stdlib@go1.23.4
1.25.8

Open the chart page →

1,365
imaginemikejohVerified publisher0.2.01 of 1See more

imagine mikejoh 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
mikejoh/imagine:0.1.078737d7345f9
stdlib@go1.23.3
1.25.8

Open the chart page →

559
local-path-provisionermikejohVerified publisher0.0.291 of 1See more

local-path-provisioner mikejoh 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.299bebefa0b908
stdlib@go1.22.5
1.25.8

Open the chart page →

1,301
miniomilvus-helm8.0.201 of 1See more

minio milvus-helm 8.0.20

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
stdlib@go1.22.3
1.25.8

Open the chart page →

1,685
pulsarv2milvus-helm2.7.82 of 4See more

pulsarv2 milvus-helm 2.7.8

2 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
stdlib@go1.13.10
1.25.8
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
stdlib@go1.13.4
1.25.8

Open the chart page →

15,886
mimirmimir0.1.101 of 1See more

mimir mimir 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
stdlib@go1.24.13
1.25.8

Open the chart page →

382
zkapps-dashboardminaVerified publisher0.1.21 of 2See more

zkapps-dashboard mina 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.25.8

Open the chart page →

1,672
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
stdlib@go1.24.6
1.25.8

Open the chart page →

12,890
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
stdlib@go1.17.4
1.25.8

Open the chart page →

6,090
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:13-alpinefb9065b6e3e2
stdlib@go1.24.6
1.25.8

Open the chart page →

112,546
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
stdlib@go1.19.7
1.25.8

Open the chart page →

10,708
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
stdlib@go1.19.7
1.25.8

Open the chart page →

10,708
helmmirasys-chart0.1.01 of 4See more

helm mirasys-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.24.6
1.25.8

Open the chart page →

4,488
jupyterhubmizzoukube0.0.1-set.by.chartpress1 of 7See more

jupyterhub mizzoukube 0.0.1-set.by.chartpress

1 of the 7 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
stdlib@go1.21.7
1.25.8

Open the chart page →

1,897
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
stdlib@go1.15.13
1.25.8

Open the chart page →

2,856
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
stdlib@go1.13.14
1.25.8

Open the chart page →

7,812
echoperatormmontesVerified publisher0.0.21 of 1See more

echoperator mmontes 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
stdlib@go1.18.3
1.25.8

Open the chart page →

1,828
mariadbmmontesVerified publisher0.3.01 of 1See more

mariadb mmontes 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mariadb:10.7.307e06f2e7ae9
stdlib@go1.16.7
1.25.8

Open the chart page →

10,171
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.25.8

Open the chart page →

7,193
basic-git-servermoikot0.0.21 of 1See more

basic-git-server moikot 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
moikot/basic-git-server:0.0.20d941bd30ffa
stdlib@go1.14.9
1.25.8

Open the chart page →

2,955
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
stdlib@go1.14.4
1.25.8

Open the chart page →

2,556
smartthings-metricsmoikot0.1.01 of 1See more

smartthings-metrics moikot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:0.1.08625f53aa9b7
stdlib@go1.14.13
1.25.8

Open the chart page →

1,745
smartthings-metrics-feat-log-detailsmoikot0.0.921 of 1See more

smartthings-metrics-feat-log-details moikot 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:feat-log-detailsfb8565140106
stdlib@go1.14.15
1.25.8

Open the chart page →

1,733
docker-registrymoinologics0.1.11 of 1See more

docker-registry moinologics 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/registry:2a3d8aaa63ed8
stdlib@go1.20.8
1.25.8

Open the chart page →

550
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
stdlib@go1.18.7
1.25.8

Open the chart page →

2,472
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:latest4b40b165f348
stdlib@go1.24.6
1.25.8

Open the chart page →

11,884
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:latest4b40b165f348
stdlib@go1.24.6
1.25.8

Open the chart page →

11,884
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:latest4b40b165f348
stdlib@go1.24.6
1.25.8

Open the chart page →

12,299
backendmojaloop0.1.05 of 6See more

backend mojaloop 0.1.0

5 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
stdlib@go1.18.2
1.25.8
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
stdlib@go1.17
1.25.8
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
stdlib@go1.23.8
1.25.8
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
stdlib@go1.16.4
1.25.8
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
stdlib@go1.21.5
1.25.8

Open the chart page →

16,356
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:latest4b40b165f348
stdlib@go1.24.6
1.25.8

Open the chart page →

19,443
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.25.8

Open the chart page →

6,265
mollysocketmollysocket-wrenixVerified publisher0.1.141 of 2See more

mollysocket mollysocket-wrenix 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.3c4a11ae9a1cb
stdlib@go1.25.7
1.25.8

Open the chart page →

2,551
gar-credential-providermondu-aiVerified publisher0.2.11 of 1See more

gar-credential-provider mondu-ai 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
stdlib@go1.26.0
1.25.8

Open the chart page →

710
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
stdlib@go1.24.6
1.25.8

Open the chart page →

5,265
enterprise-operatormongodb-helm-charts1.33.01 of 1See more

enterprise-operator mongodb-helm-charts 1.33.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
stdlib@go1.24.2
1.25.8

Open the chart page →

1,578
mongodb-query-exportermongodb-query-exporterVerified publisher5.1.01 of 1See more

mongodb-query-exporter mongodb-query-exporter 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/raffis/mongodb-query-exporter:v5.1.0ca6ac8a5b329
stdlib@go1.20.5
1.25.8

Open the chart page →

989
mongodb-secure-backupmongodb-secure-backup1.0.01 of 2See more

mongodb-secure-backup mongodb-secure-backup 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
stdlib@go1.22.10
1.25.8

Open the chart page →

1,034
mongopingmongoping1.3.11 of 1See more

mongoping mongoping 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
udhos/mongoping:1.3.103b08b63f524
stdlib@go1.24.2
1.25.8

Open the chart page →

1,283
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
stdlib@go1.17.10
1.25.8

Open the chart page →

11,826

Container images carrying it

4,417 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.8
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.8
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.8
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.8
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.8
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.