StackRadar

CVE-2026-33813

Unscored

Advisory

Published 21 Apr 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
121
of 17,781 indexed, latest versions
Container images
117
deployed by those charts
Fix available
1 of 1
affected package

Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image

Carried by container images the latest versions of 121 of 17,781 indexed charts deploy, on 117 images.

Affected packageAffected versionsFixed inImages
golang.org/x/imagegolangv0.0.0-20190802002840-cff245a6509b, v0.0.0-20191009234506-e7c1f5e7dbb8, v0.0.0-20201208152932-35266b937fa6, v0.0.0-20210216034530-4410531fe030+38 more0.42.0117
OSV records
GO-2026-4961

Charts affected

121 by stars
ChartLatestAffected imagesRadar Score
recipyartomik-helm-chartsVerified publisher0.0.21 of 2See more

recipya rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
reaper99/recipya:v1.2.27f7ec3aeb88c
golang.org/x/image@v0.18.0
0.42.0

Open the chart page →

2,066
memorubxkubeVerified publisher1.2.11 of 1See more

memo rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
neosmemo/memos:0.293e1253477066
golang.org/x/image@v0.39.0
0.42.0

Open the chart page →

555
rmfakecloudrubxkubeVerified publisher0.1.11 of 1See more

rmfakecloud rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ddvk/rmfakecloud:latest2f5c45cbf0c5
golang.org/x/image@v0.18.0
0.42.0

Open the chart page →

498
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.42.0

Open the chart page →

5,582
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/image@v0.20.0
0.42.0

Open the chart page →

4,070
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
golang.org/x/image@v0.41.0
0.42.0

Open the chart page →

10,348
seaweedfs-operatorseaweedfs-operatorVerified publisher1.5.81 of 3See more

seaweedfs-operator seaweedfs-operator 1.5.8

1 of the 3 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/nnstd/seaweedfs-operator:1.43ebe2fd253f6
golang.org/x/image@v0.29.0
0.42.0

Open the chart page →

2,092
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
golang.org/x/image@v0.18.0
0.42.0

Open the chart page →

3,286
tailscalesinextraVerified publisher0.18.11 of 2See more

tailscale sinextra 0.18.1

1 of the 2 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/tailscale:1.102.3d91287e83d1a
golang.org/x/image@v0.41.0
0.42.0

Open the chart page →

1,047
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.42.0

Open the chart page →

3,073
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/image@v0.28.0
0.42.0

Open the chart page →

2,540
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
golang.org/x/image@v0.18.0
0.42.0

Open the chart page →

2,396
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
golang.org/x/image@v0.22.0
0.42.0

Open the chart page →

8,193
agentssynapse0.1.302 of 9See more

agents synapse 0.1.30

2 of the 9 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.42.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.42.0

Open the chart page →

7,244
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
golang.org/x/image@v0.6.0
0.42.0

Open the chart page →

8,518
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
golang.org/x/image@v0.6.0
0.42.0

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.42.0

Open the chart page →

1,955
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/image@v0.25.0
0.42.0

Open the chart page →

45,239
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.42.0

Open the chart page →

3,174
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/image@v0.5.0
0.42.0

Open the chart page →

16,083
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0

Open the chart page →

1,960

Container images carrying it

117 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
instill/model-backend:611f0f2e980125e5ba5
golang.org/x/image@v0.19.0
0.42.0
1
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0
1
listmonk/listmonk:v6.0.0bf3903d54a46
golang.org/x/image@v0.29.0
0.42.0
1
livekit/ingress:v1.2.21ab01641b366
golang.org/x/image@v0.14.0
0.42.0
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.42.0
1
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0
1
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0
1
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/image@v0.5.0
0.42.0
1
miniflux/miniflux:2.2.18a3ca6bbc1f74
golang.org/x/image@v0.37.0
0.42.0
1
neosmemo/memos:0.293e1253477066
golang.org/x/image@v0.39.0
0.42.0
1
neosmemo/memos:0.26.23eefcc231141
golang.org/x/image@v0.30.0
0.42.0
1
neosmemo/memos:0.24c6defc2dfb98
golang.org/x/image@v0.27.0
0.42.0
1
opencloudeu/opencloud:7.2.46d992ccc5f1c
golang.org/x/image@v0.40.0
0.42.0
1
opencsghq/csghub-portal:v2.4.0-ee93ad59164d87
golang.org/x/image@v0.28.0
0.42.0
1
openmined/syft-seaweedfs:0.9.53a4144c0bb82
golang.org/x/image@v0.15.0
0.42.0
1
owncloud/ocis:7.1.388e7c854517d
golang.org/x/image@v0.22.0
0.42.0
1
owncloud/ocis:8.0.1b38fd8fdd58f
golang.org/x/image@v0.32.0
0.42.0
1
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.42.0
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/image@v0.8.0
0.42.0
1
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.42.0
1
photoprism/photoprism:231128-ce284de9cc4f9c
golang.org/x/image@v0.14.0
0.42.0
1
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/image@v0.0.0-20220617043117-41969df76e82
0.42.0
1
photoprism/photoprism:260601650c6ad5a651
golang.org/x/image@v0.41.0
0.42.0
1
photoprism/photoprism:251130db16ee6b1ba3
golang.org/x/image@v0.33.0
0.42.0
1
photoprism/photoprism:240711-cefc6fd632ca74
golang.org/x/image@v0.18.0
0.42.0
1
reaper99/recipya:v1.2.27f7ec3aeb88c
golang.org/x/image@v0.18.0
0.42.0
1
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.42.0
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0
1
stashapp/stash:latest24dbd7607174
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.42.0
1
stashapp/stash:v0.31.1df744af5a0c9
golang.org/x/image@v0.18.0
0.42.0
1
stashapp/stash-box:latesta534c8afdf39
golang.org/x/image@v0.22.0
0.42.0
1
tailscale/tailscale:stable8c42c4574ab0
golang.org/x/image@v0.41.0
0.42.0
1
tailscale/tailscale:v1.96.5dbeff02d2337
golang.org/x/image@v0.27.0
0.42.0
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0
1
twinproduction/gatus:v5.34.03fff895e77d3
golang.org/x/image@v0.18.0
0.42.0
1
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.42.0
1
vikunja/api:0.17.18cba0520bf8c
golang.org/x/image@v0.0.0-20210504121937-7319ad40d33e
0.42.0
1
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.42.0
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.42.0
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
golang.org/x/image@v0.32.0
0.42.0
1
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
golang.org/x/image@v0.35.0
0.42.0
1
ghcr.io/ethpandaops/syncoor:master233aa9808fc7
golang.org/x/image@v0.41.0
0.42.0
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
golang.org/x/image@v0.32.0
0.42.0
1
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
golang.org/x/image@v0.31.0
0.42.0
1
ghcr.io/marmotdata/marmot:0.10.0bd2a49f86486
golang.org/x/image@v0.41.0
0.42.0
1
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.42.0
1
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/image@v0.26.0
0.42.0
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/image@v0.23.0
0.42.0
1
ghcr.io/nnstd/seaweedfs-operator:1.43ebe2fd253f6
golang.org/x/image@v0.29.0
0.42.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.