StackRadar

CVE-2026-33813

Unscored

Advisory

Published 21 Apr 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
121
of 17,781 indexed, latest versions
Container images
117
deployed by those charts
Fix available
1 of 1
affected package

Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image

Carried by container images the latest versions of 121 of 17,781 indexed charts deploy, on 117 images.

Affected packageAffected versionsFixed inImages
golang.org/x/imagegolangv0.0.0-20190802002840-cff245a6509b, v0.0.0-20191009234506-e7c1f5e7dbb8, v0.0.0-20201208152932-35266b937fa6, v0.0.0-20210216034530-4410531fe030+38 more0.42.0117
OSV records
GO-2026-4961

Charts affected

121 by stars
ChartLatestAffected imagesRadar Score
syncoor-serverethereum-helm-chartsVerified publisher0.0.11 of 1See more

syncoor-server ethereum-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/syncoor:master233aa9808fc7
golang.org/x/image@v0.41.0
0.42.0

Open the chart page →

952
testnet-homepageethereum-helm-chartsVerified publisher0.2.31 of 1See more

testnet-homepage ethereum-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0

Open the chart page →

2,681
siyuanextrim-helm-chartsVerified publisher0.1.11 of 2See more

siyuan extrim-helm-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
b3log/siyuan:v3.1.2595c0d129bc19
golang.org/x/image@v0.24.0
0.42.0

Open the chart page →

1,247
mission-controlflanksourceVerified publisher0.1.3361 of 8See more

mission-control flanksource 0.1.336

1 of the 8 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
golang.org/x/image@v0.32.0
0.42.0

Open the chart page →

8,902
dendritegeek-cookbookVerified publisher6.4.01 of 1See more

dendrite geek-cookbook 6.4.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.42.0

Open the chart page →

2,143
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.42.0

Open the chart page →

1,881
gonicgeek-cookbookVerified publisher6.4.21 of 1See more

gonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.42.0

Open the chart page →

3,525
navidromegeek-cookbookVerified publisher6.4.21 of 1See more

navidrome geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.42.0

Open the chart page →

3,597
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.42.0

Open the chart page →

3,236
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/image@v0.0.0-20220617043117-41969df76e82
0.42.0

Open the chart page →

19,503
vikunjageek-cookbookVerified publisher6.2.01 of 4See more

vikunja geek-cookbook 6.2.0

1 of the 4 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
vikunja/api:0.17.18cba0520bf8c
golang.org/x/image@v0.0.0-20210504121937-7319ad40d33e
0.42.0

Open the chart page →

6,893
goldpingergoldpinger1.1.21 of 1See more

goldpinger goldpinger 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.11.2a1fb87c2e9d9
golang.org/x/image@v0.35.0
0.42.0

Open the chart page →

280
minifluxhajowielandVerified publisher1.0.01 of 1See more

miniflux hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/image@v0.26.0
0.42.0

Open the chart page →

1,112
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0

Open the chart page →

4,455
headcniheadcni1.0.101 of 1See more

headcni headcni 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
binrc/headcni:1.0.10e199c334b957
golang.org/x/image@v0.27.0
0.42.0

Open the chart page →

724
listmonkhelm-charts-nr0.1.121 of 1See more

listmonk helm-charts-nr 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.42.0

Open the chart page →

2,537
answerhelmforgeVerified publisher1.5.21 of 1See more

answer helmforge 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
apache/answer:2.0.2a0d71b0e30a5
golang.org/x/image@v0.20.0
0.42.0

Open the chart page →

556
listmonkhelmforgeVerified publisher1.1.141 of 3See more

listmonk helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
listmonk/listmonk:v6.2.0f535d59e1499
golang.org/x/image@v0.38.0
0.42.0

Open the chart page →

2,839
memoshelmforgeVerified publisher2.0.01 of 2See more

memos helmforge 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
neosmemo/memos:0.30.071a5b4738d1b
golang.org/x/image@v0.39.0
0.42.0

Open the chart page →

792
opencloudhelmforgeVerified publisher1.0.01 of 1See more

opencloud helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
opencloudeu/opencloud:7.2.46d992ccc5f1c
golang.org/x/image@v0.40.0
0.42.0

Open the chart page →

663
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.42.0

Open the chart page →

2,140
paperlesshpVerified publisher0.1.11 of 5See more

paperless hp 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.3467097317623a
golang.org/x/image@v0.39.0
0.42.0

Open the chart page →

26,612
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/image@v0.25.0
0.42.0

Open the chart page →

45,239
giteak8s-home-lab-repo2.6.01 of 1See more

gitea k8s-home-lab-repo 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
gitea/gitea:1.26.27d13848af126
golang.org/x/image@v0.38.0
0.42.0

Open the chart page →

2,139
photoprismk8s-home-lab-repo10.0.11 of 1See more

photoprism k8s-home-lab-repo 10.0.1

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
photoprism/photoprism:231128-ce284de9cc4f9c
golang.org/x/image@v0.14.0
0.42.0

Open the chart page →

1,140
kbot-self-hostedkbot-self-hostedVerified publisher0.1.81 of 7See more

kbot-self-hosted kbot-self-hosted 0.1.8

1 of the 7 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.30206a6c708fc6
golang.org/x/image@v0.32.0
0.42.0

Open the chart page →

32,509
casdoor-helm-chartskubeblocksVerified publisher1.753.01 of 1See more

casdoor-helm-charts kubeblocks 1.753.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.42.0

Open the chart page →

2,299
navidromekubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

navidrome kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
deluan/navidrome:0.61.29fa40b3d8dec
golang.org/x/image@v0.38.0
0.42.0

Open the chart page →

901
pocket-idkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

pocket-id kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
golang.org/x/image@v0.39.0
0.42.0

Open the chart page →

1,513
metadockvalitetsitVerified publisher0.0.71 of 2See more

metadoc kvalitetsit 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0

Open the chart page →

4,026
listmonklbenicio-communityVerified publisher0.1.01 of 1See more

listmonk lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
listmonk/listmonk:latestf535d59e1499
golang.org/x/image@v0.38.0
0.42.0

Open the chart page →

720
listmonklistmonk-chartVerified publisher2.0.11 of 2See more

listmonk listmonk-chart 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
listmonk/listmonk:v6.0.0bf3903d54a46
golang.org/x/image@v0.29.0
0.42.0

Open the chart page →

3,067
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
golang.org/x/image@v0.14.0
0.42.0

Open the chart page →

10,716
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
golang.org/x/image@v0.22.0
0.42.0

Open the chart page →

12,036
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
golang.org/x/image@v0.18.0
0.42.0

Open the chart page →

8,938
focalboardmattermostVerified publisher0.5.01 of 1See more

focalboard mattermost 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0

Open the chart page →

4,014
mattermost-chaos-enginemattermostVerified publisher0.2.01 of 1See more

mattermost-chaos-engine mattermost 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.42.0

Open the chart page →

4,067
mattermost-team-editionmattermost-team-edition6.6.831 of 4See more

mattermost-team-edition mattermost-team-edition 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
golang.org/x/image@v0.27.0
0.42.0

Open the chart page →

4,089
memosmt1905027.3.21 of 3See more

memos mt190502 7.3.2

1 of the 3 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
neosmemo/memos:0.26.23eefcc231141
golang.org/x/image@v0.30.0
0.42.0

Open the chart page →

2,443
minifluxmt1905021.1.61 of 3See more

miniflux mt190502 1.1.6

1 of the 3 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
miniflux/miniflux:2.2.18a3ca6bbc1f74
golang.org/x/image@v0.37.0
0.42.0

Open the chart page →

2,669
vikunjamt1905027.1.21 of 3See more

vikunja mt190502 7.1.2

1 of the 3 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/image@v0.20.0
0.42.0

Open the chart page →

2,968
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
golang.org/x/image@v0.13.0
0.42.0

Open the chart page →

3,430
ocisocis-community0.1.01 of 1See more

ocis ocis-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
owncloud/ocis:8.0.1b38fd8fdd58f
golang.org/x/image@v0.32.0
0.42.0

Open the chart page →

2,346
mattermost-team-editionopenshift6.6.831 of 4See more

mattermost-team-edition openshift 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
golang.org/x/image@v0.27.0
0.42.0

Open the chart page →

4,089
vikunjapascaliskeVerified publisher5.1.01 of 1See more

vikunja pascaliske 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/image@v0.20.0
0.42.0

Open the chart page →

1,342
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.42.0

Open the chart page →

4,158
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
golang.org/x/image@v0.20.0
0.42.0

Open the chart page →

1,837
istio-fortiorgnu1.0.31 of 1See more

istio-fortio rgnu 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
fortio/fortio:latest_releasefc8221136fe2
golang.org/x/image@v0.27.0
0.42.0

Open the chart page →

540
memosrm3lVerified publisher0.1.11 of 1See more

memos rm3l 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
neosmemo/memos:0.24c6defc2dfb98
golang.org/x/image@v0.27.0
0.42.0

Open the chart page →

1,614
imgproxyrock8sVerified publisher0.8.301 of 1See more

imgproxy rock8s 0.8.30

1 of the 1 container images this version deploys carry CVE-2026-33813.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/image@v0.5.0
0.42.0

Open the chart page →

2,022

Container images carrying it

117 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
golang.org/x/image@v0.27.0
0.42.0
1
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
golang.org/x/image@v0.39.0
0.42.0
1
ghcr.io/sergelogvinov/tailscale:1.102.3d91287e83d1a
golang.org/x/image@v0.41.0
0.42.0
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.42.0
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
golang.org/x/image@v0.6.0
0.42.0
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.42.0
1
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
golang.org/x/image@v0.6.0
0.42.0
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.42.0
1
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/image@v0.29.0
0.42.0
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
golang.org/x/image@v0.0.0-20210607152325-775e3b0c77b9
0.42.0
1
ghcr.io/usememos/memos:0.24.04723d86e6797
golang.org/x/image@v0.21.0
0.42.0
1
ghcr.io/zoriya/kyoo_transcoder:4.7.12dadea51a91e
golang.org/x/image@v0.23.0
0.42.0
1
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/image@v0.41.0
0.42.0
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/image@v0.21.0
0.42.0
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.42.0
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
golang.org/x/image@v0.20.0
0.42.0
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
golang.org/x/image@v0.20.0
0.42.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.