StackRadar

CVE-2026-27142

Medium

Advisory

Published 6 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,851
of 17,828 indexed, latest versions
Container images
4,357
deployed by those charts
Fix available
1 of 2
affected packages

URLs in meta content attribute actions are not escaped in html/template

Carried by container images the latest versions of 3,851 of 17,828 indexed charts deploy, on 4,357 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+178 more1.25.84,357
OSV records
DEBIAN-CVE-2026-27142GO-2026-4603
Also known as
BIT-golang-2026-27142

Charts affected

3,851 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-27142.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
stdlib@go1.24.6
1.25.8

Open the chart page →

7,966

Container images carrying it

4,357 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.