StackRadar

CVE-2026-27139

Low

Advisory

Published 6 Mar 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,969
of 17,844 indexed, latest versions
Container images
4,471
deployed by those charts
Fix available
1 of 2
affected packages

FileInfo can escape from a Root in os

Carried by container images the latest versions of 3,969 of 17,844 indexed charts deploy, on 4,471 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+178 more1.25.84,471
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-27139GO-2026-4602
Also known as
BIT-golang-2026-27139

Charts affected

3,969 by stars
ChartLatestAffected imagesRadar Score
postgresself-hosters-by-nightVerified publisher0.14.31 of 1See more

postgres self-hosters-by-night 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
stdlib@go1.24.6
1.25.8

Open the chart page →

2,553
semaphoresemaphore-light1.0.01 of 1See more

semaphore semaphore-light 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
semaphoreui/semaphore:latest98ad9bc7a2a0
stdlib@go1.25.5
1.25.8

Open the chart page →

1,426
s3managersergeyshevch0.1.01 of 1See more

s3manager sergeyshevch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/sergeyshevch/s3manager:feature_refactoringff59fcdf44eb
stdlib@go1.18
1.25.8

Open the chart page →

2,159
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
stdlib@go1.21.8
1.25.8

Open the chart page →

3,381
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
stdlib@go1.24.1
1.25.8

Open the chart page →

3,498
miniosergiotocaliniVerified publisher1.0.01 of 1See more

minio sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
stdlib@go1.19.11
1.25.8

Open the chart page →

4,425
rdpgwsergiotocaliniVerified publisher1.0.01 of 1See more

rdpgw sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
bolkedebruin/rdpgw:masterc0dc0589373a
stdlib@go1.24.13
1.25.8

Open the chart page →

700
service-binding-operatorservice-binding-operator-helm-chart1.4.11 of 1See more

service-binding-operator service-binding-operator-helm-chart 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/redhat-developer/servicebinding-operatordigest-pinned16286ac84ddd
stdlib@go1.20.6
1.25.8

Open the chart page →

799
serviceexampleserviceexample0.1.03 of 5See more

serviceexample serviceexample 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/nats:2.9.20-alpined6c6ae7df4a0
stdlib@go1.19.11
1.25.8
natsio/nats-box:0.13.559cf2e949181
stdlib@go1.19.5
1.25.8
natsio/nats-server-config-reloader:0.11.0c3a755eab2cc
stdlib@go1.20.5
1.25.8

Open the chart page →

5,471
service-exampleservice-example-10.1.05 of 7See more

service-example service-example-1 0.1.0

5 of the 7 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.8
library/nats:2.9.11-alpineccbe811b8575
stdlib@go1.19.4
1.25.8
natsio/nats-box:0.13.3c507bd7e3831
stdlib@go1.19.4
1.25.8
natsio/nats-server-config-reloader:0.8.06bdaceb63aa5
stdlib@go1.19.4
1.25.8
natsio/prometheus-nats-exporter:0.10.1bce728062c4f
stdlib@go1.19.3
1.25.8

Open the chart page →

8,449
serviceexampleserviceexample-chart0.3.01 of 4See more

serviceexample serviceexample-chart 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.8

Open the chart page →

3,457
serviceexampleservice-example-helm-chart0.1.01 of 4See more

serviceexample service-example-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.8

Open the chart page →

1,613
service-exampleservice-example-jt0.1.14 of 9See more

service-example service-example-jt 0.1.1

4 of the 9 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/nats:2.12.2-alpine2d5fce3229ae
stdlib@go1.25.4
1.25.8
natsio/nats-box:0.19.28031d190c7ee
stdlib@go1.25.2
1.25.8
natsio/nats-server-config-reloader:0.20.147094fcae2f4
stdlib@go1.24.8
1.25.8
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.25.8

Open the chart page →

7,520
ccx-monitoringseveralnines0.6.215 of 7See more

ccx-monitoring severalnines 0.6.21

5 of the 7 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
grafana/grafana:12.3.12175aaa91c96
stdlib@go1.25.5
1.25.8
victoriametrics/victoria-metrics:v1.120.0a1cb2f3dfd45
stdlib@go1.24.4
1.25.8
victoriametrics/vmalert:v1.96.0150cd08fde94
stdlib@go1.21.5
1.25.8
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.25.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
stdlib@go1.20.10
1.25.8

Open the chart page →

7,823
apache-shardingsphere-operator-chartsshardingsphere0.3.01 of 2See more

apache-shardingsphere-operator-charts shardingsphere 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
stdlib@go1.19.10
1.25.8

Open the chart page →

1,701
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.8

Open the chart page →

3,230
bffshortlink0.2.11 of 1See more

bff shortlink 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
stdlib@go1.25.7
1.25.8

Open the chart page →

1,730
linkshortlink0.7.31 of 1See more

link shortlink 0.7.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
stdlib@go1.25.7
1.25.8

Open the chart page →

1,712
pagesshrutiujlan-pages1.0.01 of 3See more

pages shrutiujlan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,585
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:18.43a82e1f56c8f
stdlib@go1.24.6
1.25.8

Open the chart page →

2,869
backendsignalen4.25.02 of 4See more

backend signalen 4.25.0

2 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.25.8
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
stdlib@go1.16.7
1.25.8

Open the chart page →

11,388
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
stdlib@go1.14
1.25.8

Open the chart page →

2,177
postgresqlsignoz0.0.21 of 1See more

postgresql signoz 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
stdlib@go1.24.6
1.25.8

Open the chart page →

1,319
zookeepersignoz0.0.11 of 1See more

zookeeper signoz 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.25.8

Open the chart page →

2,978
local-static-provisionersig-storage-local-static-provisioner2.9.01 of 1See more

local-static-provisioner sig-storage-local-static-provisioner 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.8

Open the chart page →

1,353
ctlogsigstoreVerified publisher0.2.683 of 4See more

ctlog sigstore 0.2.68

3 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
stdlib@go1.25.0
1.25.8
ghcr.io/sigstore/scaffolding/createtree:v0.7.31e5232e8c9122
stdlib@go1.25.0
1.25.8
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
stdlib@go1.25.0
1.25.8

Open the chart page →

2,779
sigstore-probersigstoreVerified publisher0.3.11 of 1See more

sigstore-prober sigstore 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
stdlib@go1.26.0
1.25.8

Open the chart page →

450
trilliansigstoreVerified publisher0.3.204 of 5See more

trillian sigstore 0.3.20

4 of the 5 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.25.8
ghcr.io/sigstore/scaffolding/createdbdigest-pinned3cee6c78973b
stdlib@go1.25.0
1.25.8
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
stdlib@go1.26.0
1.25.8
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
stdlib@go1.26.0
1.25.8

Open the chart page →

2,789
tsasigstoreVerified publisher2.1.31 of 1See more

tsa sigstore 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/sigstore/timestamp-server:v2.1.08637f0482ed1
stdlib@go1.25.1
1.25.8

Open the chart page →

610
tufsigstoreVerified publisher0.1.321 of 1See more

tuf sigstore 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/serverdigest-pinnedae8eb69c7b70
stdlib@go1.25.0
1.25.8

Open the chart page →

773
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
stdlib@go1.19.6
1.25.8

Open the chart page →

2,873
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
stdlib@go1.21.4
1.25.8

Open the chart page →

2,345
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
stdlib@go1.17.6
1.25.8

Open the chart page →

2,383
olmsikalabs0.3.01 of 2See more

olm sikalabs 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned40d0363f4aa6
stdlib@go1.22.3
1.25.8

Open the chart page →

1,151
signpostsikalabs0.5.01 of 1See more

signpost sikalabs 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
sikalabs/signpost:v0.7.0c8b0e21d61b4
stdlib@go1.24.6
1.25.8

Open the chart page →

317
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
stdlib@go1.20.5
1.25.8

Open the chart page →

1,510
keydbsinextraVerified publisher0.31.01 of 1See more

keydb sinextra 0.31.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
stdlib@go1.18.10
1.25.8

Open the chart page →

2,173
mongosqldsinextraVerified publisher0.3.71 of 1See more

mongosqld sinextra 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
stdlib@go1.23.8
1.25.8

Open the chart page →

2,728
mongosyncsinextraVerified publisher0.4.01 of 1See more

mongosync sinextra 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
stdlib@go1.24.4
1.25.8

Open the chart page →

3,001
pgbouncersinextraVerified publisher0.17.01 of 1See more

pgbouncer sinextra 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
stdlib@go1.24.6
1.25.8

Open the chart page →

2,109
tailscalesinextraVerified publisher0.18.11 of 2See more

tailscale sinextra 0.18.1

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
stdlib@go1.25.5
1.25.8

Open the chart page →

1,109
talos-backupsinextraVerified publisher0.1.21 of 1See more

talos-backup sinextra 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/siderolabs/talos-backup:v0.1.0-beta.203a71e140f1d
stdlib@go1.23.0
1.25.8

Open the chart page →

909
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
stdlib@go1.21.11
1.25.8

Open the chart page →

2,471
mariadbsitepilot1.0.31 of 1See more

mariadb sitepilot 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mariadb:10.640153feb479c
stdlib@go1.24.6
1.25.8

Open the chart page →

2,897
skyhook-agentskyhookVerified publisher1.3.151 of 1See more

skyhook-agent skyhook 1.3.15

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/skyhook-io/skyhook-connector:v2.3.23deb8e4b1aaa
stdlib@go1.26.0
1.25.8

Open the chart page →

302
mimirskyloud-helm-chartsVerified publisher5.5.14 of 5See more

mimir skyloud-helm-charts 5.5.1

4 of the 5 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
grafana/mimir:r292-5f018727476e456c738
stdlib@go1.22.3
1.25.8
grafana/rollout-operator:v0.14.03409edfb45c7
stdlib@go1.22.1
1.25.8
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
stdlib@go1.21.1
1.25.8
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
stdlib@go1.21.1
1.25.8

Open the chart page →

10,961
tailscale-operatorskyloud-helm-chartsVerified publisher1.70.31 of 1See more

tailscale-operator skyloud-helm-charts 1.70.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
tailscale/k8s-operator:v1.70.08edd06cf5bac
stdlib@go1.22.5
1.25.8

Open the chart page →

1,042
skypilot-prometheus-serverskypilotVerified publisher0.11.13 of 3See more

skypilot-prometheus-server skypilot 0.11.1

3 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.83.078aec597d87a
stdlib@go1.24.3
1.25.8
quay.io/prometheus/prometheus:v3.4.19abc6cf6aea7
stdlib@go1.24.3
1.25.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0db384bf43222
stdlib@go1.23.5
1.25.8

Open the chart page →

2,344
pritunl-zerosky-sailVerified publisher0.3.31 of 1See more

pritunl-zero sky-sail 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
pritunl/pritunl-zero:1.0.3648.460f2943e0d41b
stdlib@go1.25.4
1.25.8

Open the chart page →

660
yopasssky-sailVerified publisher1.3.11 of 2See more

yopass sky-sail 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
jhaals/yopass:12.5.0916a1cf45d36
stdlib@go1.25.5
1.25.8

Open the chart page →

3,208

Container images carrying it

4,471 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.25.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.8
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.8
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.8
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.8
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.8
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.