CVE-2026-33818
HighAdvisory
Published 13 Aug 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.006
- 46th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 4,667
- of 17,837 indexed, latest versions
- Container images
- 5,368
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Enforce maximum recursion depth in encoding/asn1
Carried by container images the latest versions of 4,667 of 17,837 indexed charts deploy, on 5,368 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+193 more | 1.25.13 | 5,368 |
- OSV records
- DEBIAN-CVE-2026-33818GO-2026-5972
- Also known as
- BIT-golang-2026-33818
Charts affected
4,667 by stars
Container images carrying it
5,368 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ethpandaops/ | c0e6cc6542c1 | stdlib | 1.25.13 | 1 |
| ethpandaops/ | 1edd4074fd79 | stdlib | 1.25.13 | 1 |
| ethpandaops/ | e261d1734e9f | stdlib | 1.25.13 | 1 |
| ethpandaops/ | 431cd3790ed2 | stdlib | 1.25.13 | 1 |
| ethpandaops/ | fb84b718500f | stdlib | 1.25.13 | 1 |
| ethpandaops/ | d1780db2e286 | stdlib | 1.25.13 | 1 |
| ethpandaops/ | 38448e9d4aef | stdlib | 1.25.13 | 1 |
| ethpandaops/ | 5c4832e9588f | stdlib | 1.25.13 | 1 |
| ethpandaops/ | c937f4ba737c | stdlib | 1.25.13 | 1 |
| ethpandaops/ | ad6fc3b3e6b8 | stdlib | 1.25.13 | 1 |
| ethpandaops/ | c0b30fcf64bc | stdlib | 1.25.13 | 1 |
| ethpandaops/ | 27b8e5ea3125 | stdlib | 1.25.13 | 1 |
| ethpandaops/ | a71967db581f | stdlib | 1.25.13 | 1 |
| ethpandaops/ | 989da6bea4bd | stdlib | 1.25.13 | 1 |
| ethpandaops/ | 9f1d6aec0d04 | stdlib | 1.25.13 | 1 |
| ethpandaops/ | f7dec2e07091 | stdlib | 1.25.13 | 1 |
| evcc/ | ddf2a25afce5 | stdlib | 1.25.13 | 1 |
| everpcpc/ | b378d137ae8b | stdlib | 1.25.13 | 1 |
| evoapicloud/ | 966625532d90 | stdlib | 1.25.13 | 1 |
| expediagroup/ | 193a00ec8dd4 | stdlib | 1.25.13 | 1 |
| factly/ | 66fafc7b0a17 | stdlib | 1.25.13 | 1 |
| factly/ | 94d21479382e | stdlib | 1.25.13 | 1 |
| factly/ | be85ff1b9bd3 | stdlib | 1.25.13 | 1 |
| factly/ | 384d384310ef | stdlib | 1.25.13 | 1 |
| factly/ | 87064eb0463c | stdlib | 1.25.13 | 1 |
| falcosecurity/ | 932956d86c99 | stdlib | 1.25.13 | 1 |
| falcosecurity/ | 8a99fcc57a57 | stdlib | 1.25.13 | 1 |
| falcosecurity/ | 1976da721518 | stdlib | 1.25.13 | 1 |
| falcosecurity/ | 828ee36cb13a | stdlib | 1.25.13 | 1 |
| farmer1992/ | e0064b824403 | stdlib | 1.25.13 | 1 |
| fatliverfreddy/ | e79f24ca7371 | stdlib | 1.25.13 | 1 |
| featureformcom/ | 82396f8fb5e8 | stdlib | 1.25.13 | 1 |
| federid/ | fbfb7c6510a7 | stdlib | 1.25.13 | 1 |
| feiyu563/ | 224cfa68cbd9 | stdlib | 1.25.13 | 1 |
| feiyu563/ | 8192368b0578 | stdlib | 1.25.13 | 1 |
| felipecs8/ | f945423be36d | stdlib | 1.25.13 | 1 |
| filebrowser/ | 4fcd47af573c | stdlib | 1.25.13 | 1 |
| filebrowser/ | dbac07403040 | stdlib | 1.25.13 | 1 |
| fission/ | 3fcfd8a0fa5d | stdlib | 1.25.13 | 1 |
| fission/ | fa0f24cdb9cd | stdlib | 1.25.13 | 1 |
| fission/ | 04c6e06af175 | stdlib | 1.25.13 | 1 |
| flanksource/ | 1dacc3195bf9 | stdlib | 1.25.13 | 1 |
| flanksource/ | 689687a7cf95 | stdlib | 1.25.13 | 1 |
| flanksource/ | 764c84e550db | stdlib | 1.25.13 | 1 |
| flanksource/ | 953948a194c9 | stdlib | 1.25.13 | 1 |
| flanksource/ | bd3294c20a60 | stdlib | 1.25.13 | 1 |
| flashbots/ | 7c486b5789da | stdlib | 1.25.13 | 1 |
| flashcatcloud/ | 421acb36181b | stdlib | 1.25.13 | 1 |
| flashcatcloud/ | ea1b0aaabe09 | stdlib | 1.25.13 | 1 |
| fleetdm/ | 12e644b7f40e | stdlib | 1.25.13 | 1 |