StackRadar

CVE-2026-27145

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,204
of 17,828 indexed, latest versions
Container images
4,808
deployed by those charts
Fix available
1 of 2
affected packages

Inefficient candidate hostname parsing in crypto/x509

Carried by container images the latest versions of 4,204 of 17,828 indexed charts deploy, on 4,808 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+185 more1.25.114,808
OSV records
DEBIAN-CVE-2026-27145GO-2026-5037
Also known as
BIT-golang-2026-27145

Charts affected

4,204 by stars
ChartLatestAffected imagesRadar Score
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-27145.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
stdlib@go1.20.5
1.25.11

Open the chart page →

2,482
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-27145.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
stdlib@go1.17.13
1.25.11

Open the chart page →

3,702
zookeeper-exporterzookeeper-exporter0.1.01 of 1See more

zookeeper-exporter zookeeper-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27145.

Container imageDigestPackageFixed in
dabealu/zookeeper-exporter:latest86106fec315f
stdlib@go1.14.15
1.25.11

Open the chart page →

1,249
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-27145.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
stdlib@go1.24.6
1.25.11

Open the chart page →

8,105

Container images carrying it

4,808 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
stdlib@go1.23.6
1.25.11
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
stdlib@go1.23.6
1.25.11
1
ghcr.io/fluxerapp/fluxer-static:2026.812.125337cfe98ae544df
stdlib@go1.25.0
1.25.11
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
stdlib@go1.20.12
1.25.11
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
stdlib@go1.23.8
1.25.11
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
stdlib@go1.19.1
1.25.11
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
stdlib@go1.18.10
1.25.11
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
stdlib@go1.24.6
1.25.11
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
stdlib@go1.23.8
1.25.11
1
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
stdlib@go1.23.12
1.25.11
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
stdlib@go1.22.0
1.25.11
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
stdlib@go1.22.0
1.25.11
1
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
stdlib@go1.18.3
1.25.11
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
stdlib@go1.18.1
1.25.11
1
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
stdlib@go1.24.0
1.25.11
1
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
stdlib@go1.23.4
1.25.11
1
ghcr.io/gabe565/domain-watch:latest34c5a1e351d6
stdlib@go1.24.1
1.25.11
1
ghcr.io/gabe565/limo:latest6dfdbc9853bb
stdlib@go1.20.12
1.25.11
1
ghcr.io/gabe565/matrimony:latestd39a9d7c3e1b
stdlib@go1.22.0
1.25.11
1
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
stdlib@go1.24.1
1.25.11
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
stdlib@go1.21.3
1.25.11
1
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
stdlib@go1.24.4
1.25.11
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
stdlib@go1.19.8
1.25.11
1
ghcr.io/gijsvandulmen/k8qu:1.4e897b18db13d
stdlib@go1.22.6
1.25.11
1
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
stdlib@go1.25.4
1.25.11
1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
stdlib@go1.25.4
1.25.11
1
ghcr.io/glassflow/glassflow-etl-be:v3.2.020f066d0f631
stdlib@go1.25.0
1.25.11
1
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
stdlib@go1.25.4
1.25.11
1
ghcr.io/glassflow/kafka-kerberos-gateway:latest2ae01c524a6e
stdlib@go1.21.13
1.25.11
1
ghcr.io/glauth/glauth:v2.5.209c782ca5984
stdlib@go1.25.0
1.25.11
1
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
stdlib@go1.26.2
1.25.11
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
stdlib@go1.25.5
1.25.11
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
stdlib@go1.26.2
1.25.11
1
ghcr.io/gochain/rpc-proxy/rpc-proxy:latestca01f5ab95f7
stdlib@go1.23.11
1.25.11
1
ghcr.io/gomenhashai/gomenhashai:v1.3.36f031172a5ec
stdlib@go1.26.0
1.25.11
1
ghcr.io/gotify/server:2.6.104f4c4bb7cdd
stdlib@go1.23.3
1.25.11
1
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
stdlib@go1.18.3
1.25.11
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
stdlib@go1.24.5
1.25.11
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
stdlib@go1.24.10
1.25.11
1
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
stdlib@go1.25.8
1.25.11
1
ghcr.io/grafana/grafana-operator:v5.18.00af2faec9d6f
stdlib@go1.24.2
1.25.11
1
ghcr.io/grafana/grafana-operator:v5.22.2d45fc24e8f43
stdlib@go1.26.1
1.25.11
1
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
stdlib@go1.24.9
1.25.11
1
ghcr.io/grafana/tempo-operator/tempo-operator:v0.4.02627be646391
stdlib@go1.21.0
1.25.11
1
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
stdlib@go1.25.8
1.25.11
1
ghcr.io/haedalwang/kubescout:0.1.107d51f838f0d
stdlib@go1.25.5
1.25.11
1
ghcr.io/haydercyber/secrets-bridge:0.2.04709f1bb3039
stdlib@go1.24.13
1.25.11
1
ghcr.io/hay-kot/homebox:v0.9.2e6e0fbd7cca9
stdlib@go1.20.4
1.25.11
1
ghcr.io/headlamp-k8s/headlamp:v0.43.05d03caa26df7
stdlib@go1.26.3
1.25.11
1
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
stdlib@go1.24.13
1.25.11
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.