StackRadar

CVE-2026-32282

Medium

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.4
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,143
of 17,966 indexed, latest versions
Container images
4,641
deployed by those charts
Fix available
1 of 2
affected packages

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

Carried by container images the latest versions of 4,143 of 17,966 indexed charts deploy, on 4,641 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.94,641
OSV records
DEBIAN-CVE-2026-32282GO-2026-4864
Also known as
BIT-golang-2026-32282

Charts affected

4,143 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

4,641 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
inaccel/reef:latestc967218739f3
stdlib@go1.21.6
1.25.9
2
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
stdlib@go1.17.3
1.25.9
2
iomesh/csi-provisioner:v3.0.0f9508460b273
stdlib@go1.16.2
1.25.9
2
iomesh/csi-snapshotter:v6.2.2becc53e25b96
stdlib@go1.19
1.25.9
2
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
stdlib@go1.13.1
1.25.9
2
iomesh/livenessprobe:v2.8.0560f01510f99
stdlib@go1.18
1.25.9
2
iomesh/localpv-manager:v0.2.0f13deacac3f4
stdlib@go1.20.3
1.25.9
2
iomesh/node-disk-exporter:1.8.0f03148764f38
stdlib@go1.14.7
1.25.9
2
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
stdlib@go1.19
1.25.9
2
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
stdlib@go1.19.7
1.25.9
2
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.9
2
istio/install-cni:1.24.2-distrolessaef4825e110f
stdlib@go1.23.2
1.25.9
2
istio/pilot:1.24.2-distroless137e44e3d1d2
stdlib@go1.23.2
1.25.9
2
istio/pilot:1.10.0294ca55bd1cc
stdlib@go1.16.4
1.25.9
2
istio/proxyv2:1.18.0757d28c24100
stdlib@go1.20.4
1.25.9
2
istio/proxyv2:1.9.687a9db561d2e
stdlib@go1.15.13
1.25.9
2
istio/proxyv2:1.10.088c6c693e67a
stdlib@go1.16.4
1.25.9
2
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.25.9
2
jaegertracing/all-in-one:1.3104d224a9999b
stdlib@go1.17.6
1.25.9
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
stdlib@go1.20.6
1.25.9
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
stdlib@go1.25.3
1.25.9
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
stdlib@go1.13.11
1.25.9
2
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
stdlib@go1.15.3
1.25.9
2
jmalloc/echo-server:0.3.1e4eaee2c7998
stdlib@go1.17
1.25.9
2
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
stdlib@go1.19.4
1.25.9
2
kbudde/rabbitmq-exporter:1.0.0:latest12f27d6d84e6
stdlib@go1.21.8
1.25.9
2
kubernetesui/dashboard:v2.2.0148991563e37
stdlib@go1.15.1
1.25.9
2
kubesphere/openelb:v0.4.4ed7311a0f9e4
stdlib@go1.15.15
1.25.9
2
kubesphere/porter:v0.4.38d1ed5ee1d2e
stdlib@go1.15.15
1.25.9
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
stdlib@go1.19.3
1.25.9
2
langgenius/dify-sandbox:0.2.009b7e8705673
stdlib@go1.20.6
1.25.9
2
library/arangodb:3.11.81e75d74954a4
stdlib@go1.21.5
1.25.9
2
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.25.9
2
library/ghost:6.65.090592b712b6b
stdlib@go1.24.6
1.25.9
2
library/influxdb:2.6.1-alpine44a366dd7724
stdlib@go1.19.4
1.25.9
2
library/influxdb:2.7b8d940ca9376
stdlib@go1.18.2
1.25.9
2
library/mariadb:10.8.30abf60f81588
stdlib@go1.16.7
1.25.9
2
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.25.9
2
library/mariadb:10.640153feb479c
stdlib@go1.24.6
1.25.9
2
library/mariadb:12.0.2:12.0-noble607835cd628b
stdlib@go1.24.6
1.25.9
2
library/mariadb:11.470cc072b29b4
stdlib@go1.24.6
1.25.9
2
library/mariadb:11.3.2e101f9db3191
stdlib@go1.18.2
1.25.9
2
library/mongo:8.0.20098862b1339f
stdlib@go1.25.7
1.25.9
2
library/mongo:5.041108d183e97
stdlib@go1.24.6
1.25.9
2
library/mongo:7.0-jammy:7-jammy84c4a18b60a0
stdlib@go1.24.6
1.25.9
2
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.25.9
2
library/mysql:9.7.230a0abfa7b50
stdlib@go1.24.6
1.25.9
2
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.25.9
2
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.25.9
2
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.25.9
2

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.