StackRadar

CVE-2026-33812

Unscored

Advisory

Published 21 Apr 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
108
of 17,781 indexed, latest versions
Container images
106
deployed by those charts
Fix available
1 of 1
affected package

Excessive memory allocation when decoding malicious SFNT in golang.org/x/image

Carried by container images the latest versions of 108 of 17,781 indexed charts deploy, on 106 images.

Affected packageAffected versionsFixed inImages
golang.org/x/imagegolangv0.0.0-20190802002840-cff245a6509b, v0.0.0-20191009234506-e7c1f5e7dbb8, v0.0.0-20201208152932-35266b937fa6, v0.0.0-20210216034530-4410531fe030+35 more0.39.0106
OSV records
GO-2026-4962

Charts affected

108 by stars
ChartLatestAffected imagesRadar Score
agentssynapse0.1.302 of 9See more

agents synapse 0.1.30

2 of the 9 container images this version deploys carry CVE-2026-33812.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.39.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.39.0

Open the chart page →

7,244
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-33812.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
golang.org/x/image@v0.6.0
0.39.0

Open the chart page →

8,518
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2026-33812.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
golang.org/x/image@v0.6.0
0.39.0

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-33812.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.39.0

Open the chart page →

1,955
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-33812.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/image@v0.25.0
0.39.0

Open the chart page →

45,239
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33812.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.39.0

Open the chart page →

3,174
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-33812.

Container imageDigestPackageFixed in
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/image@v0.5.0
0.39.0

Open the chart page →

16,083
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33812.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.39.0

Open the chart page →

1,960

Container images carrying it

106 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/usememos/memos:0.24.04723d86e6797
golang.org/x/image@v0.21.0
0.39.0
1
ghcr.io/zoriya/kyoo_transcoder:4.7.12dadea51a91e
golang.org/x/image@v0.23.0
0.39.0
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/image@v0.21.0
0.39.0
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.39.0
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
golang.org/x/image@v0.20.0
0.39.0
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
golang.org/x/image@v0.20.0
0.39.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.