StackRadar

CVE-2026-32282

Medium

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.4
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,152
of 17,926 indexed, latest versions
Container images
4,655
deployed by those charts
Fix available
1 of 2
affected packages

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

Carried by container images the latest versions of 4,152 of 17,926 indexed charts deploy, on 4,655 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.94,655
OSV records
DEBIAN-CVE-2026-32282GO-2026-4864
Also known as
BIT-golang-2026-32282

Charts affected

4,152 by stars
ChartLatestAffected imagesRadar Score
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.25.9

Open the chart page →

12,296
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
stdlib@go1.18.4
1.25.9

Open the chart page →

10,792
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.25.9

Open the chart page →

7,950
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
stdlib@go1.18.1
1.25.9

Open the chart page →

3,617
searxgeek-cookbookVerified publisher5.6.23 of 4See more

searx geek-cookbook 5.6.2

3 of the 4 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.25.9
dalf/morty:latest248a4849c350
stdlib@go1.18.2
1.25.9
library/caddy:2.2.0-alpine7367adca165f
stdlib@go1.15.2
1.25.9

Open the chart page →

7,534
skypilotgeek-cookbookVerified publisher0.0.13 of 3See more

skypilot geek-cookbook 0.0.1

3 of the 3 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
stdlib@go1.23.5
1.25.9
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
stdlib@go1.24.4
1.25.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
stdlib@go1.24.4
1.25.9

Open the chart page →

9,501
torrservergeek-cookbookVerified publisher1.2.21 of 1See more

torrserver geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
smailkoz/torrserver:1.0.1117b52d15de8f0
stdlib@go1.17.5
1.25.9

Open the chart page →

3,163
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
stdlib@go1.18.4
1.25.9

Open the chart page →

12,378
vikunjageek-cookbookVerified publisher6.2.02 of 4See more

vikunja geek-cookbook 6.2.0

2 of the 4 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/caddy:2.4.2-alpinefbc51bcf1ab0
stdlib@go1.16.5
1.25.9
vikunja/api:0.17.18cba0520bf8c
stdlib@go1.16.5
1.25.9

Open the chart page →

6,923
webhook-receivergeek-cookbookVerified publisher0.0.11 of 1See more

webhook-receiver geek-cookbook 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
stdlib@go1.21.3
1.25.9

Open the chart page →

1,368
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.25.9

Open the chart page →

18,629
asynqmongeneral-helm-chartsVerified publisher0.0.11 of 1See more

asynqmon general-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
hibiken/asynqmon:latestac80bcffd2f9
stdlib@go1.18.10
1.25.9

Open the chart page →

753
cbtgeneral-helm-chartsVerified publisher0.0.51 of 1See more

cbt general-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ethpandaops/cbt:latest5377ffb3091a
stdlib@go1.26.1
1.25.9

Open the chart page →

568
chproxygeneral-helm-chartsVerified publisher0.0.21 of 1See more

chproxy general-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
contentsquareplatform/chproxy:v1.26.524555f22d4be
stdlib@go1.22.7
1.25.9

Open the chart page →

3,872
dispatchoor-apigeneral-helm-chartsVerified publisher0.1.11 of 1See more

dispatchoor-api general-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
stdlib@go1.24.13
1.25.9

Open the chart page →

798
panda-pulsegeneral-helm-chartsVerified publisher1.0.61 of 1See more

panda-pulse general-helm-charts 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ethpandaops/panda-pulse:latestad6fc3b3e6b8
stdlib@go1.26.1
1.25.9

Open the chart page →

642
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
stdlib@go1.17.10
1.25.9

Open the chart page →

4,620
mongogengxiankun-charts0.1.01 of 1See more

mongo gengxiankun-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
stdlib@go1.24.6
1.25.9

Open the chart page →

4,144
mysqlgengxiankun-charts0.2.01 of 1See more

mysql gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.9

Open the chart page →

476
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
stdlib@go1.19.8
1.25.9

Open the chart page →

4,469
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.82 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

2 of the 5 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
stdlib@go1.19.11
1.25.9
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.25.9

Open the chart page →

35,617
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
stdlib@go1.16.7
1.25.9
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
stdlib@go1.16.7
1.25.9

Open the chart page →

17,133
ghostghostVerified publisher0.1.02 of 4See more

ghost ghost 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
stdlib@go1.18.2
1.25.9
litestream/litestream:0.3c5a1e1b01916
stdlib@go1.21.3
1.25.9

Open the chart page →

9,115
rabbitmqginger-society0.1.02 of 2See more

rabbitmq ginger-society 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
kbudde/rabbitmq-exporter:latest12f27d6d84e6
stdlib@go1.21.8
1.25.9
library/rabbitmq:4-managementddc75301edf5
stdlib@go1.22.2
1.25.9

Open the chart page →

1,352
gitanagitana1.4.01 of 1See more

gitana gitana 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ntakashi/gitana:1.4.04171ec641120
stdlib@go1.17.7
1.25.9

Open the chart page →

4,079
github-rate-limits-prometheus-exportergithub-rate-limit-prometheus-exporterVerified publisher0.2.151 of 1See more

github-rate-limits-prometheus-exporter github-rate-limit-prometheus-exporter 0.2.15

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/kalgurn/grl-exporter:v3.2.0bd109b2bda38
stdlib@go1.23.5
1.25.9

Open the chart page →

888
gitlab-goproxygitlab-goproxy0.2.21 of 1See more

gitlab-goproxy gitlab-goproxy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
stdlib@go1.21.0
1.25.9

Open the chart page →

1,332
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
stdlib@go1.19.12
1.25.9

Open the chart page →

2,621
prometheus-container-resource-exportergkarthiks0.3.11 of 1See more

prometheus-container-resource-exporter gkarthiks 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
gkarthics/container-resource-exporter:latest6799af333e8a
stdlib@go1.14.7
1.25.9

Open the chart page →

2,213
prometheus-couchdb-exportergkarthiks0.1.31 of 1See more

prometheus-couchdb-exporter gkarthiks 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
gesellix/couchdb-prometheus-exporter:v27.2.05b891f1fc2b9
stdlib@go1.13.10
1.25.9

Open the chart page →

1,286
glassflow-etlglassflowVerified publisher0.5.2110 of 16See more

glassflow-etl glassflow 0.5.21

10 of the 16 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/nats:2.12.3-alpine88fe8e0e09d6
stdlib@go1.25.5
1.25.9
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.25.9
natsio/nats-box:0.19.28031d190c7ee
stdlib@go1.25.2
1.25.9
natsio/nats-server-config-reloader:0.21.110ff229eaf52
stdlib@go1.25.5
1.25.9
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.25.9
otel/opentelemetry-collector-contrib:0.108.0923eb1cfae32
stdlib@go1.23.0
1.25.9
ghcr.io/glassflow/glassflow-etl-be:v3.2.020f066d0f631
stdlib@go1.25.0
1.25.9
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
stdlib@go1.25.0
1.25.9
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
stdlib@go1.25.4
1.25.9
ghcr.io/glassflow/kafka-kerberos-gateway:latest2ae01c524a6e
stdlib@go1.21.13
1.25.9

Open the chart page →

12,354
pgbouncerglassflowVerified publisher0.1.01 of 1See more

pgbouncer glassflow 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
bitnamilegacy/pgbouncer:1.23.192356da09704
stdlib@go1.22.10
1.25.9

Open the chart page →

3,455
postgresqlglassflowVerified publisher0.1.91 of 1See more

postgresql glassflow 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.25.9

Open the chart page →

312
glassflow-operatorglassflow-operatorVerified publisher0.8.51 of 3See more

glassflow-operator glassflow-operator 0.8.5

1 of the 3 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
stdlib@go1.25.0
1.25.9

Open the chart page →

771
glauthglauthVerified publisher0.3.171 of 2See more

glauth glauth 0.3.17

1 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
stdlib@go1.24.5
1.25.9

Open the chart page →

2,785
glidergliderVerified publisher0.1.51 of 1See more

glider glider 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
nadoo/glider:0.1638aadefbd607
stdlib@go1.20.14
1.25.9

Open the chart page →

889
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/mariadb:latestd4fdec0510ad
stdlib@go1.24.6
1.25.9

Open the chart page →

11,892
gnp-stackgnp-stack0.0.511 of 14See more

gnp-stack gnp-stack 0.0.5

11 of the 14 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
grafana/grafana:12.2.135c41e0fd029
stdlib@go1.25.3
1.25.9
library/nats:2.12.1-alpineb3f2bd84176a
stdlib@go1.25.3
1.25.9
natsio/nats-box:0.19.28031d190c7ee
stdlib@go1.25.2
1.25.9
natsio/nats-server-config-reloader:0.20.147094fcae2f4
stdlib@go1.24.8
1.25.9
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.25.9
rancher/local-path-provisioner:v0.0.329289da488b07
stdlib@go1.24.4
1.25.9
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
stdlib@go1.24.12
1.25.9
quay.io/prometheus-operator/prometheus-operator:v0.85.0890b3bb05cf4
stdlib@go1.24.6
1.25.9
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
stdlib@go1.23.7
1.25.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.33d671cf20a35
stdlib@go1.25.1
1.25.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
stdlib@go1.24.6
1.25.9

Open the chart page →

13,639
go-app-helmgo-app-helm0.1.01 of 1See more

go-app-helm go-app-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
manojchaulagain/go-k8s:0.1.0f237b5f637ae
stdlib@go1.20.1
1.25.9

Open the chart page →

1,976
go-file-servergo-file-server1.0.01 of 2See more

go-file-server go-file-server 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
goccx/go-file-server:latestf4b3ebea0303
stdlib@go1.21.10
1.25.9

Open the chart page →

2,268
gofitgofit0.0.11 of 1See more

gofit gofit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/bamaas/gofit:0.0.132b6a174b419
stdlib@go1.22.11
1.25.9

Open the chart page →

643
googly-logingoogly-login0.1.01 of 2See more

googly-login googly-login 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
stdlib@go1.24.6
1.25.9

Open the chart page →

1,316
gorsegorse-io0.4.23 of 4See more

gorse gorse-io 0.4.2

3 of the 4 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
stdlib@go1.20.1
1.25.9
zhenghaoz/gorse-server:0.4.1239c565685b01
stdlib@go1.20.1
1.25.9
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
stdlib@go1.20.1
1.25.9

Open the chart page →

4,440
gotwaygotwayVerified publisher0.8.01 of 1See more

gotway gotway 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
stdlib@go1.18.3
1.25.9

Open the chart page →

1,831
Governify-Bluejaygovernify0.1.02 of 12See more

Governify-Bluejay governify 0.1.0

2 of the 12 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
stdlib@go1.17
1.25.9
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.9

Open the chart page →

22,167
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
stdlib@go1.17
1.25.9
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.9

Open the chart page →

24,385
goweeklygoweekly2.0.01 of 1See more

goweekly goweekly 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
zufardhiyaulhaq/goweekly:v2.0.008dcc130fbea
stdlib@go1.17.12
1.25.9

Open the chart page →

1,233
harborgpg-dev1.18.35 of 8See more

harbor gpg-dev 1.18.3

5 of the 8 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.14.3a30e5a8be3d9
stdlib@go1.24.13
1.25.9
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
stdlib@go1.24.13
1.25.9
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
stdlib@go1.24.13
1.25.9
goharbor/registry-photon:v2.14.36533fc396cbc
stdlib@go1.24.13
1.25.9
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
stdlib@go1.25.7
1.25.9

Open the chart page →

3,492
ingress-nginxgpg-dev4.9.02 of 2See more

ingress-nginx gpg-dev 4.9.0

2 of the 2 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
stdlib@go1.21.5
1.25.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
stdlib@go1.21.3
1.25.9

Open the chart page →

2,322
jaegergpg-dev3.3.34 of 5See more

jaeger gpg-dev 3.3.3

4 of the 5 container images this version deploys carry CVE-2026-32282.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
stdlib@go1.21.5
1.25.9
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.25.9
jaegertracing/jaeger-collector:1.53.07f1269222903
stdlib@go1.21.5
1.25.9
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
stdlib@go1.21.5
1.25.9

Open the chart page →

19,806

Container images carrying it

4,655 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.9
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.9
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.9
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.9
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.9
1

syft 1.42.1 · advisories as of 28 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.