CVE-2026-32282
MediumAdvisory
Published 7 Apr 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.4
- base score, highest
- EPSS
- 0.003
- 22nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,834
- of 17,803 indexed, latest versions
- Container images
- 4,379
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
Carried by container images the latest versions of 3,834 of 17,803 indexed charts deploy, on 4,379 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+177 more | 1.25.9 | 4,379 |
- OSV records
- DEBIAN-CVE-2026-32282GO-2026-4864
- Also known as
- BIT-golang-2026-32282
Charts affected
3,834 by stars
Container images carrying it
4,379 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| bitnami/ | 16a7dae804fb | stdlib | 1.25.9 | 1 |
| bitnami/ | b3bd5b6be9a0 | stdlib | 1.25.9 | 1 |
| bitnami/ | 4e65bf641805 | stdlib | 1.25.9 | 1 |
| bitnami/ | 0516f987fae2 | stdlib | 1.25.9 | 1 |
| bitnami/ | 74eaff41382b | stdlib | 1.25.9 | 1 |
| bitpoke/ | c5eed1ddf692 | stdlib | 1.25.9 | 1 |
| bitpoke/ | 21284d1df473 | stdlib | 1.25.9 | 1 |
| bitpoke/ | 7fb3aad37b5f | stdlib | 1.25.9 | 1 |
| blackducksoftware/ | 5c97f3a3f8b7 | stdlib | 1.25.9 | 1 |
| blackducksoftware/ | 6310fac39d53 | stdlib | 1.25.9 | 1 |
| blipai/ | 737d5d19a312 | stdlib | 1.25.9 | 1 |
| bloomberg/ | 8520120f5598 | stdlib | 1.25.9 | 1 |
| bloxstaking/ | bf6d7d2fdc93 | stdlib | 1.25.9 | 1 |
| bluenviron/ | 9e39256d1ba3 | stdlib | 1.25.9 | 1 |
| bolkedebruin/ | c0dc0589373a | stdlib | 1.25.9 | 1 |
| bonovoo/ | bb93b68fcd17 | stdlib | 1.25.9 | 1 |
| breton/ | 41b1bb483aa2 | stdlib | 1.25.9 | 1 |
| bsgrigorov/ | 45ab095f09c8 | stdlib | 1.25.9 | 1 |
| btcpayserver/ | e9585b68dc6b | stdlib | 1.25.9 | 1 |
| buddyspencer/ | 6b656f19b0c1 | stdlib | 1.25.9 | 1 |
| buddyspencer/ | 9e7dbf923c12 | stdlib | 1.25.9 | 1 |
| buildkite/ | aec38cfaae0e | stdlib | 1.25.9 | 1 |
| bulich/ | 6d0b780f7c7b | stdlib | 1.25.9 | 1 |
| burganbank/ | 9259c34e4037 | stdlib | 1.25.9 | 1 |
| burningalchemist/ | b8e4757c7def | stdlib | 1.25.9 | 1 |
| bytesafe/ | ee287384c005 | stdlib | 1.25.9 | 1 |
| caarlos0/ | d11dec138900 | stdlib | 1.25.9 | 1 |
| calico/ | cef0c907b8f4 | stdlib | 1.25.9 | 1 |
| calico/ | e486870cfde8 | stdlib | 1.25.9 | 1 |
| calico/ | 8f04e4772a2b | stdlib | 1.25.9 | 1 |
| calico/ | eadb3a25109a | stdlib | 1.25.9 | 1 |
| calico/ | 385bf6391fea | stdlib | 1.25.9 | 1 |
| calico/ | d8c644a8a3ee | stdlib | 1.25.9 | 1 |
| camptocamp/ | acfafc308d88 | stdlib | 1.25.9 | 1 |
| captnbp/ | 1600c5a253e0 | stdlib | 1.25.9 | 1 |
| caroga/ | f3233882b3bd | stdlib | 1.25.9 | 1 |
| casbin/ | 66f836ef778b | stdlib | 1.25.9 | 1 |
| casbin/ | 770ad9ec3190 | stdlib | 1.25.9 | 1 |
| castopod/ | 1fd37280cbb2 | stdlib | 1.25.9 | 1 |
| castopod/ | 4e4f0440520f | stdlib | 1.25.9 | 1 |
| cbeneke/ | dc658078d7ba | stdlib | 1.25.9 | 1 |
| censedata/ | ebfffb9dd4c0 | stdlib | 1.25.9 | 1 |
| cesanta/ | 98e0307e0d2d | stdlib | 1.25.9 | 1 |
| cfcontainerization/ | 82fa261c18a8 | stdlib | 1.25.9 | 1 |
| cfcontainerization/ | 58fb1c173a46 | stdlib | 1.25.9 | 1 |
| cgtysylr/ | aec0f8a38a77 | stdlib | 1.25.9 | 1 |
| chaerr/ | 66833deec017 | stdlib | 1.25.9 | 1 |
| chainflag/ | ac642796bcb6 | stdlib | 1.25.9 | 1 |
| chainsafe/ | 5593f6e97912 | stdlib | 1.25.9 | 1 |
| chainsafe/ | 7b9fe4aa8073 | stdlib | 1.25.9 | 1 |