StackRadar

CVE-2026-27139

Low

Advisory

Published 6 Mar 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,969
of 17,844 indexed, latest versions
Container images
4,471
deployed by those charts
Fix available
1 of 2
affected packages

FileInfo can escape from a Root in os

Carried by container images the latest versions of 3,969 of 17,844 indexed charts deploy, on 4,471 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+178 more1.25.84,471
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-27139GO-2026-4602
Also known as
BIT-golang-2026-27139

Charts affected

3,969 by stars
ChartLatestAffected imagesRadar Score
vals-operatorvals-operatorVerified publisher0.8.11 of 1See more

vals-operator vals-operator 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
stdlib@go1.25.7
1.25.8

Open the chart page →

737
vault-raft-snapshot-agentvault-raft-snapshot-agentVerified publisher0.6.91 of 1See more

vault-raft-snapshot-agent vault-raft-snapshot-agent 0.6.9

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
stdlib@go1.23.10
1.25.8

Open the chart page →

1,285
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
stdlib@go1.23.12
1.25.8

Open the chart page →

3,897
openldap-havcnngrVerified publisher1.0.01 of 3See more

openldap-ha vcnngr 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.25.8

Open the chart page →

5,521
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.25.8

Open the chart page →

5,064
velocityvelocity1.0.01 of 2See more

velocity velocity 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.8

Open the chart page →

1,043
doris-foundationdbvelodb25.8.01 of 4See more

doris-foundationdb velodb 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
stdlib@go1.23.7
1.25.8

Open the chart page →

3,253
doris-operatorvelodb25.8.01 of 1See more

doris-operator velodb 25.8.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
apache/doris:operator-latest3a4422656592
stdlib@go1.23.12
1.25.8

Open the chart page →

443
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
stdlib@go1.13.10
1.25.8

Open the chart page →

7,555
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
stdlib@go1.13.10
1.25.8

Open the chart page →

7,573
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
stdlib@go1.13.10
1.25.8

Open the chart page →

7,474
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
stdlib@go1.13.10
1.25.8

Open the chart page →

7,474
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
stdlib@go1.22.5
1.25.8

Open the chart page →

2,845
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
stdlib@go1.20.14
1.25.8

Open the chart page →

4,546
bugsinkvictorlane0.3.71 of 2See more

bugsink victorlane 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mariadb:12.0-noble607835cd628b
stdlib@go1.24.6
1.25.8

Open the chart page →

4,279
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
stdlib@go1.24.6
1.25.8

Open the chart page →

6,808
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
stdlib@go1.21.7
1.25.8

Open the chart page →

71,522
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,585
kube-monitoring-telegram-botviento-repository1.0.01 of 1See more

kube-monitoring-telegram-bot viento-repository 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
stdlib@go1.16.4
1.25.8

Open the chart page →

8,027
vineyard-operatorvineyardVerified publisher0.24.22 of 2See more

vineyard-operator vineyard 0.24.2

2 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
stdlib@go1.19.13
1.25.8
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
stdlib@go1.18.3
1.25.8

Open the chart page →

4,620
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
stdlib@go1.17.8
1.25.8

Open the chart page →

8,304
ciliumvks-helm-chartsVerified publisher1.17.141 of 3See more

cilium vks-helm-charts 1.17.14

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
stdlib@go1.25.4
1.25.8

Open the chart page →

4,433
corednsvks-helm-chartsVerified publisher1.45.01 of 1See more

coredns vks-helm-charts 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
stdlib@go1.25.2
1.25.8

Open the chart page →

929
vm-console-proxyvm-console-proxyVerified publisher0.2.01 of 1See more

vm-console-proxy vm-console-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/kubevirt/vm-console-proxy:v0.8.08d6b4b6e99bd
stdlib@go1.22.4
1.25.8

Open the chart page →

654
go-devvoid-xmh1.0.11 of 1See more

go-dev void-xmh 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
voidxmh/golang:1.19-alpine-dev423c6195fab2
stdlib@go1.19
1.25.8

Open the chart page →

1,155
volantmqvolantmq0.1.21 of 1See more

volantmq volantmq 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
stdlib@go1.13.6
1.25.8

Open the chart page →

2,544
volcanovolcano-sh1.15.23 of 3See more

volcano volcano-sh 1.15.2

3 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
volcanosh/vc-controller-manager:v1.15.26a6bc2560d51
stdlib@go1.25.0
1.25.8
volcanosh/vc-scheduler:v1.15.2afab36286a17
stdlib@go1.25.0
1.25.8
volcanosh/vc-webhook-manager:v1.15.22fff65aad011
stdlib@go1.25.0
1.25.8

Open the chart page →

1,585
postgresappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

postgresapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.8

Open the chart page →

1,319
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.8

Open the chart page →

7,639
postgresappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

postgresapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.8

Open the chart page →

1,319
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.8

Open the chart page →

7,639
vpa-managervpa-managerVerified publisher0.4.91 of 1See more

vpa-manager vpa-manager 0.4.9

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
quay.io/jcluppnow/vpa-manager:0.6.4e459d2fba277
stdlib@go1.22.7
1.25.8

Open the chart page →

494
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
mitre/vulcan:latest2bc4dfb8150f
stdlib@go1.25.5
1.25.8

Open the chart page →

1,559
cert-manager-webhook-vultrvultrVerified publisher1.0.01 of 1See more

cert-manager-webhook-vultr vultr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
stdlib@go1.16.3
1.25.8

Open the chart page →

2,510
vultr-csivultrVerified publisher2.0.01 of 4See more

vultr-csi vultr 2.0.0

1 of the 4 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
vultr/vultr-csi:v0.3.041d26735d437
stdlib@go1.16.8
1.25.8

Open the chart page →

2,362
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
stdlib@go1.20.2
1.25.8

Open the chart page →

3,517
gateway-control-planewallarmVerified publisher0.2.02 of 2See more

gateway-control-plane wallarm 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg17c79fa5891443
stdlib@go1.24.6
1.25.8
wallarm/gateway-control-plane:0.2.0a321bc974a19
stdlib@go1.24.13
1.25.8

Open the chart page →

1,233
kongwallarmVerified publisher4.6.33 of 7See more

kong wallarm 4.6.3

3 of the 7 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
wallarm/ingress-python:4.6.0-15cb2ae08b40f
stdlib@go1.18.2
1.25.8
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
stdlib@go1.18.3
1.25.8
wallarm/kong-kubernetes-ingress-controller:2.8b55ff6cecbd5
stdlib@go1.19.4
1.25.8

Open the chart page →

75,305
kong-previewwallarmVerified publisher4.2.32 of 5See more

kong-preview wallarm 4.2.3

2 of the 5 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
stdlib@go1.17.5
1.25.8
wallarm/ingress-ruby:4.2.1-195ea2632326c
stdlib@go1.18.3
1.25.8

Open the chart page →

2,913
wallarm-ingress-rcwallarmVerified publisher4.8.42 of 2See more

wallarm-ingress-rc wallarm 4.8.4

2 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
stdlib@go1.20.5
1.25.8
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.25.8

Open the chart page →

2,642
wallarm-node-nextwallarmVerified publisher0.5.32 of 2See more

wallarm-node-next wallarm 0.5.3

2 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
stdlib@go1.22.7
1.25.8
wallarm/node-next:0.5.24314f3d2b918
stdlib@go1.22.7
1.25.8

Open the chart page →

2,443
wallarm-oobwallarmVerified publisher0.23.03 of 3See more

wallarm-oob wallarm 0.23.0

3 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
stdlib@go1.22.1
1.25.8
wallarm/node-helpers:6.10.1aecd88b24c51
stdlib@go1.25.7
1.25.8
wallarm/node-native-processing:0.23.07db2da8fce0b
stdlib@go1.26.0
1.25.8

Open the chart page →

2,872
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.8

Open the chart page →

20,585
consulwarjiang1.3.02 of 2See more

consul warjiang 1.3.0

2 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
stdlib@go1.20.10
1.25.8
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
stdlib@go1.20.10
1.25.8

Open the chart page →

4,105
eth-validatorwateim1.4.51 of 3See more

eth-validator wateim 1.4.5

1 of the 3 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
wateim/lighthouse-launch:latest2520149ee574
stdlib@go1.23.8
1.25.8

Open the chart page →

5,111
prometheus-storage-adapterwavefront0.1.61 of 2See more

prometheus-storage-adapter wavefront 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
wavefronthq/prometheus-storage-adapter:latestded77b38c7c6
stdlib@go1.18
1.25.8

Open the chart page →

1,295
wavefront-hpa-adapterwavefront0.2.101 of 1See more

wavefront-hpa-adapter wavefront 0.2.10

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
stdlib@go1.18
1.25.8

Open the chart page →

1,694
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
stdlib@go1.14.12
1.25.8

Open the chart page →

5,798
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
stdlib@go1.14.12
1.25.8

Open the chart page →

11,472
anubiswbstack0.1.01 of 1See more

anubis wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27139.

Container imageDigestPackageFixed in
ghcr.io/techarohq/anubis:v1.21.3940ac71ef6fc
stdlib@go1.24.5
1.25.8

Open the chart page →

490

Container images carrying it

4,471 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.25.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.8
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.8
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.8
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.8
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.8
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.