StackRadar

CVE-2026-32282

Medium

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.4
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,119
of 17,926 indexed, latest versions
Container images
4,603
deployed by those charts
Fix available
1 of 2
affected packages

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

Carried by container images the latest versions of 4,119 of 17,926 indexed charts deploy, on 4,603 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.94,603
OSV records
DEBIAN-CVE-2026-32282GO-2026-4864
Also known as
BIT-golang-2026-32282

Charts affected

4,119 by stars
ChartLatestAffected imagesRadar Score
flyte-depsflyte1.16.81 of 3See more

flyte-deps flyte 1.16.8

1 of the 3 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
stdlib@go1.15.1
1.25.9

Open the chart page →

2,240
flyte-devboxflyte0.1.07 of 14See more

flyte-devbox flyte 0.1.0

7 of the 14 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
stdlib@go1.24.6
1.25.9
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
stdlib@go1.24.6
1.25.9
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
stdlib@go1.24.3
1.25.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
stdlib@go1.24.3
1.25.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
stdlib@go1.24.3
1.25.9
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
stdlib@go1.24.3
1.25.9
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
stdlib@go1.24.3
1.25.9

Open the chart page →

8,580
gobackupfmjstudios0.2.21 of 1See more

gobackup fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
huacnlee/gobackup:v2.11.2d9c693e99576
stdlib@go1.20.3
1.25.9

Open the chart page →

2,939
gotenbergfmjstudios0.2.21 of 1See more

gotenberg fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.7.0437b9cd3c351
stdlib@go1.22.4
1.25.9

Open the chart page →

10,030
ntfyfmjstudios0.2.21 of 1See more

ntfy fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
stdlib@go1.22.2
1.25.9

Open the chart page →

1,284
popeyefmjstudios0.1.21 of 1See more

popeye fmjstudios 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
derailed/popeye:v0.21.363b2d2a8f674
stdlib@go1.21.8
1.25.9

Open the chart page →

1,202
uptime-kumafmjstudios0.2.21See more

uptime-kuma fmjstudios 0.2.2

1 container image this version deploys carries CVE-2026-32282.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
stdlib@go1.19.6
1.25.9

Open the chart page →

—
csp-reporterfoomoVerified publisher2.2.01 of 1See more

csp-reporter foomo 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
foomo/csp-reporter:1.3.0e436da524785
stdlib@go1.18
1.25.9

Open the chart page →

1,410
forkliftforklift0.1.42 of 2See more

forklift forklift 0.1.4

2 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
wuhan005/forklift:daemon4e6da210e449
stdlib@go1.19.8
1.25.9
wuhan005/forklift:controllerbfbe82d59850
stdlib@go1.19.8
1.25.9

Open the chart page →

1,822
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
stdlib@go1.18.10
1.25.9

Open the chart page →

4,824
forwardforward1.3.11 of 1See more

forward forward 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
udhos/forward:1.1.312e120d39fdb
stdlib@go1.20.5
1.25.9

Open the chart page →

2,208
cloudflaredfossa0.1.11 of 1See more

cloudflared fossa 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2022.1.361f608cd1123
stdlib@go1.17.1
1.25.9

Open the chart page →

2,478
maxscalefour-allportalVerified publisher4.1.162 of 3See more

maxscale four-allportal 4.1.16

2 of the 3 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:10.6.12-debian-11-r1643a70df0e7c6
stdlib@go1.19.7
1.25.9
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
stdlib@go1.17.8
1.25.9

Open the chart page →

6,676
readium-lcpserverfpetr0.0.51 of 3See more

readium-lcpserver fpetr 0.0.5

1 of the 3 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
stdlib@go1.22.0
1.25.9

Open the chart page →

1,366
readium-lsdserverfpetr0.0.11 of 2See more

readium-lsdserver fpetr 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
stdlib@go1.22.0
1.25.9

Open the chart page →

1,366
ff-testfrankframework0.7.61 of 2See more

ff-test frankframework 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/postgres:17-bookworm639ab7ceb90e
stdlib@go1.24.6
1.25.9

Open the chart page →

1,826
frank2examplefrankframework0.7.41 of 2See more

frank2example frankframework 0.7.4

1 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/postgres:17-bookworm639ab7ceb90e
stdlib@go1.24.6
1.25.9

Open the chart page →

1,826
free5gc-amffree5gc-amfVerified publisher0.1.31 of 1See more

free5gc-amf free5gc-amf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
stdlib@go1.21.8
1.25.9

Open the chart page →

897
free5gc-ausffree5gc-ausfVerified publisher0.1.31 of 1See more

free5gc-ausf free5gc-ausf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/ausf:v3.4.3687ff4daf5da
stdlib@go1.21.8
1.25.9

Open the chart page →

906
free5gc-chffree5gc-chfVerified publisher0.1.31 of 1See more

free5gc-chf free5gc-chf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/chf:v3.4.3e2a4dd98a4ed
stdlib@go1.21.8
1.25.9

Open the chart page →

1,003
free5gc-nrffree5gc-nrfVerified publisher0.1.31 of 1See more

free5gc-nrf free5gc-nrf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/nrf:v3.4.399e46b860efb
stdlib@go1.21.8
1.25.9

Open the chart page →

914
free5gc-nssffree5gc-nssfVerified publisher0.1.31 of 1See more

free5gc-nssf free5gc-nssf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/nssf:v3.4.3dfe8c68c04b4
stdlib@go1.21.8
1.25.9

Open the chart page →

906
free5gc-pcffree5gc-pcfVerified publisher0.1.31 of 1See more

free5gc-pcf free5gc-pcf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/pcf:v3.4.3f712e8ecd927
stdlib@go1.21.8
1.25.9

Open the chart page →

898
free5gc-smffree5gc-smfVerified publisher0.1.31 of 1See more

free5gc-smf free5gc-smf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/smf:v3.4.360e38baa4b10
stdlib@go1.21.8
1.25.9

Open the chart page →

913
free5gc-udmfree5gc-udmVerified publisher0.1.31 of 1See more

free5gc-udm free5gc-udm 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/udm:v3.4.32f68df062a50
stdlib@go1.21.8
1.25.9

Open the chart page →

906
free5gc-udrfree5gc-udrVerified publisher0.1.31 of 1See more

free5gc-udr free5gc-udr 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/udr:v3.4.3c0783bcdcbdc
stdlib@go1.21.8
1.25.9

Open the chart page →

914
free5gc-upffree5gc-upfVerified publisher0.1.31 of 1See more

free5gc-upf free5gc-upf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/upf:v3.4.3b6b362a39fdd
stdlib@go1.21.8
1.25.9

Open the chart page →

1,070
free5gc-webuifree5gc-webuiVerified publisher0.1.31 of 1See more

free5gc-webui free5gc-webui 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
free5gc/webui:v3.4.39adeb18492cb
stdlib@go1.21.8
1.25.9

Open the chart page →

1,265
dbmatefrinx-helm-charts1.0.01 of 1See more

dbmate frinx-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
amacneil/dbmate:2.6.03fdce58cc189
stdlib@go1.21.0
1.25.9

Open the chart page →

1,440
frinx-machinefrinx-helm-charts11.0.010 of 26See more

frinx-machine frinx-helm-charts 11.0.0

10 of the 26 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
frinx/krakend:7.0.0bf8edd4f52f3
stdlib@go1.22.7
1.25.9
frinx/resource-manager:6.1.09cd0147a09bd
stdlib@go1.21.7
1.25.9
frinx/schellar:6.1.04693dc627d32
stdlib@go1.21.11
1.25.9
grafana/grafana:11.0.00dc5a246ab16
stdlib@go1.21.10
1.25.9
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.25.9
grafana/promtail:2.9.3b338a29de45e
stdlib@go1.21.3
1.25.9
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
stdlib@go1.22.3
1.25.9
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
stdlib@go1.22.2
1.25.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
stdlib@go1.19.4
1.25.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.9

Open the chart page →

44,148
frinx-machine-monitoringfrinx-helm-charts0.1.27 of 8See more

frinx-machine-monitoring frinx-helm-charts 0.1.2

7 of the 8 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
stdlib@go1.21.10
1.25.9
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.25.9
grafana/promtail:2.9.3b338a29de45e
stdlib@go1.21.3
1.25.9
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
stdlib@go1.22.3
1.25.9
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
stdlib@go1.22.2
1.25.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
stdlib@go1.19.4
1.25.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.9

Open the chart page →

10,720
frinx-machine-operatorsfrinx-helm-charts0.3.02 of 2See more

frinx-machine-operators frinx-helm-charts 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
arangodb/kube-arangodb:1.2.4108d1720cec3b
stdlib@go1.22.3
1.25.9
ghcr.io/cloudnative-pg/cloudnative-pg:1.23.2f1f3c20f3637
stdlib@go1.22.4
1.25.9

Open the chart page →

1,927
krakendfrinx-helm-charts5.0.21 of 1See more

krakend frinx-helm-charts 5.0.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
frinx/krakend:7.0.0bf8edd4f52f3
stdlib@go1.22.7
1.25.9

Open the chart page →

1,398
resource-managerfrinx-helm-charts2.3.11 of 4See more

resource-manager frinx-helm-charts 2.3.1

1 of the 4 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
frinx/resource-manager:6.1.09cd0147a09bd
stdlib@go1.21.7
1.25.9

Open the chart page →

9,805
uniresourcefrinx-helm-charts1.1.11See more

uniresource frinx-helm-charts 1.1.1

1 container image this version deploys carries CVE-2026-32282.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.25.9

Open the chart page →

—
workflow-managerfrinx-helm-charts3.2.11See more

workflow-manager frinx-helm-charts 3.2.1

1 container image this version deploys carries CVE-2026-32282.

Container imageDigestPackageFixed in
frinx/schellar:6.1.04693dc627d32
stdlib@go1.21.11
1.25.9

Open the chart page →

—
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
pschiffe/pdns-mysql:alpinea7d2d021c788
stdlib@go1.21.5
1.25.9

Open the chart page →

1,973
aptlyg0dscookie0.4.01 of 2See more

aptly g0dscookie 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
stdlib@go1.18.3
1.25.9

Open the chart page →

3,970
icinga2g0dscookie0.2.01 of 1See more

icinga2 g0dscookie 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
stdlib@go1.18.1
1.25.9

Open the chart page →

4,445
passboltg0dscookie0.5.22 of 2See more

passbolt g0dscookie 0.5.2

2 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/mariadb:10.79a48ac9f196f
stdlib@go1.16.7
1.25.9
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
stdlib@go1.14.4
1.25.9

Open the chart page →

8,209
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
stdlib@go1.23.5
1.25.9

Open the chart page →

2,636
castsponsorskipgabe565Verified publisher0.8.11 of 1See more

castsponsorskip gabe565 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
stdlib@go1.23.4
1.25.9

Open the chart page →

1,410
gotifygabe565Verified publisher0.4.01 of 1See more

gotify gabe565 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/gotify/server:2.6.104f4c4bb7cdd
stdlib@go1.23.3
1.25.9

Open the chart page →

758
hammondgabe565Verified publisher0.6.41 of 1See more

hammond gabe565 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
stdlib@go1.20.6
1.25.9

Open the chart page →

1,801
limogabe565Verified publisher0.8.01 of 1See more

limo gabe565 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/gabe565/limo:latest6dfdbc9853bb
stdlib@go1.20.12
1.25.9

Open the chart page →

1,329
matrimonygabe565Verified publisher0.7.01 of 1See more

matrimony gabe565 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/gabe565/matrimony:latestd39a9d7c3e1b
stdlib@go1.22.0
1.25.9

Open the chart page →

1,129
podgrabgabe565Verified publisher0.5.21 of 1See more

podgrab gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
stdlib@go1.15.2
1.25.9

Open the chart page →

2,397
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
stdlib@go1.19.8
1.25.9

Open the chart page →

13,861
smarter-device-managergabe565Verified publisher0.5.21 of 1See more

smarter-device-manager gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
stdlib@go1.19.1
1.25.9

Open the chart page →

1,234
transsmutegabe565Verified publisher1.1.01 of 1See more

transsmute gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
stdlib@go1.24.1
1.25.9

Open the chart page →

802

Container images carrying it

4,603 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.9
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.9
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.9
1

syft 1.42.1 · advisories as of 27 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.