StackRadar

CVE-2026-27145

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,204
of 17,828 indexed, latest versions
Container images
4,808
deployed by those charts
Fix available
1 of 2
affected packages

Inefficient candidate hostname parsing in crypto/x509

Carried by container images the latest versions of 4,204 of 17,828 indexed charts deploy, on 4,808 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+185 more1.25.114,808
OSV records
DEBIAN-CVE-2026-27145GO-2026-5037
Also known as
BIT-golang-2026-27145

Charts affected

4,204 by stars
ChartLatestAffected imagesRadar Score
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-27145.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
stdlib@go1.20.5
1.25.11

Open the chart page →

2,482
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-27145.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
stdlib@go1.17.13
1.25.11

Open the chart page →

3,702
zookeeper-exporterzookeeper-exporter0.1.01 of 1See more

zookeeper-exporter zookeeper-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27145.

Container imageDigestPackageFixed in
dabealu/zookeeper-exporter:latest86106fec315f
stdlib@go1.14.15
1.25.11

Open the chart page →

1,249
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-27145.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
stdlib@go1.24.6
1.25.11

Open the chart page →

8,105

Container images carrying it

4,808 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
stdlib@go1.22.4
1.25.11
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
stdlib@go1.20.14
1.25.11
1
ghcr.io/syself/hetzner-cloud-controller-manager:v2.0.77d4a5e29c387
stdlib@go1.24.5
1.25.11
1
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
stdlib@go1.19.2-ts3fd24dee31
1.25.11
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
stdlib@go1.23.4
1.25.11
1
ghcr.io/tale/headplane:0.6.39476cc5adb12
stdlib@go1.25.1
1.25.11
1
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.25.11
1
ghcr.io/tarampampam/webhook-tester:2.3.085818267b450
stdlib@go1.26.2
1.25.11
1
ghcr.io/taskmedia/kubectl-gpg-ncftp:main0fb2b5584f7c
stdlib@go1.22.10
1.25.11
1
ghcr.io/techarohq/anubis:v1.21.3940ac71ef6fc
stdlib@go1.24.5
1.25.11
1
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
stdlib@go1.24.6
1.25.11
1
ghcr.io/terminus-io/enforcer:v1.1.0f21b905610d6
stdlib@go1.25.5
1.25.11
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
stdlib@go1.24.4
1.25.11
1
ghcr.io/thetredev/steamcmd:srcds-20240309dbb0f042cb31
stdlib@go1.18.2
1.25.11
1
ghcr.io/tikalk/resource-manager:latest7f21d50e69cb
stdlib@go1.19
1.25.11
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
stdlib@go1.24.3
1.25.11
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
stdlib@go1.22.8
1.25.11
1
ghcr.io/traefik/hub-manager:v0.45.1d1cff2560c67
stdlib@go1.26.0
1.25.11
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
stdlib@go1.21.8
1.25.11
1
ghcr.io/transparency-dev/tesseract/posix:v0.1.2b044edd23888
stdlib@go1.25.8
1.25.11
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
stdlib@go1.23.7
1.25.11
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
stdlib@go1.23.7
1.25.11
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
stdlib@go1.23.7
1.25.11
1
ghcr.io/tsouza/cerberus:1.21.1242b56dcb5c7
stdlib@go1.26.2
1.25.11
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
stdlib@go1.22.8
1.25.11
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
stdlib@go1.24.6
1.25.11
1
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
stdlib@go1.24.1
1.25.11
1
ghcr.io/twin/lighthouse:v0.0.45aeda2ea2ba2
stdlib@go1.22.3
1.25.11
1
ghcr.io/universal-backup-operator/backup-operator:1.2.306292b289dda
stdlib@go1.22.4
1.25.11
1
ghcr.io/upbothq/upbot-operator:v0.0.20e5da24947c91
stdlib@go1.24.9
1.25.11
1
ghcr.io/upcloudltd/upcloud-csi5af91c663788
stdlib@go1.24.13
1.25.11
1
ghcr.io/usememos/memos:0.24.04723d86e6797
stdlib@go1.23.6
1.25.11
1
ghcr.io/utkuozdemir/nvidia_gpu_exporter:1.5.0d75967a4dd72
stdlib@go1.26.3
1.25.11
1
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
stdlib@go1.18.3
1.25.11
1
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
stdlib@go1.19.3
1.25.11
1
ghcr.io/vojtechpastyrik/muthur:0.10.0b5a06a6e13b9
stdlib@go1.26.1
1.25.11
1
ghcr.io/vojtechpastyrik/muthur-collector:0.11.00a580fe3a032
stdlib@go1.26.1
1.25.11
1
ghcr.io/voyagermesh/crd-manager:v0.1.013fd0cccafe8
stdlib@go1.25.6
1.25.11
1
ghcr.io/voyagermesh/gateway:v1.6.223f4da194134
stdlib@go1.25.5
1.25.11
1
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
stdlib@go1.20.5
1.25.11
1
ghcr.io/voyagermesh/gateway-converter:v0.0.1b92123805584
stdlib@go1.23.1
1.25.11
1
ghcr.io/voyagermesh/voyager:v17.5.04964ceaf9d35
stdlib@go1.25.8
1.25.11
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
stdlib@go1.21.1
1.25.11
1
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
stdlib@go1.22.2
1.25.11
1
ghcr.io/vvanouytsel/jetspotter:1.48.1ec0e17a94f61
stdlib@go1.23.12
1.25.11
1
ghcr.io/wachd/wachd:0.4.1805b05c56da94
stdlib@go1.25.10
1.25.11
1
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
stdlib@go1.20.2
1.25.11
1
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
stdlib@go1.23.10
1.25.11
1
ghcr.io/wasilak/go-hello-world:1.8.366d353e7693f
stdlib@go1.25.4
1.25.11
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
stdlib@go1.20.12
1.25.11
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.