StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,903
of 17,787 indexed, latest versions
Container images
4,475
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 3,903 of 17,787 indexed charts deploy, on 4,475 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,475
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

3,903 by stars
ChartLatestAffected imagesRadar Score
oncallgrafana1.16.57 of 12See more

oncall grafana 1.16.5

7 of the 12 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
stdlib@go1.22.4
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
stdlib@go1.17.8
1.25.10
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
stdlib@go1.17.8
1.25.10
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
stdlib@go1.17.8
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
stdlib@go1.17.8
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
stdlib@go1.18.2
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
stdlib@go1.16.9
1.25.10

Open the chart page →

16,251
k8sgpt-operatork8sgptOfficialVerified publisher0.2.291 of 2See more

k8sgpt-operator k8sgpt 0.2.29

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
stdlib@go1.24.2
1.25.10

Open the chart page →

966
openbaoopenbaoVerified publisher0.29.41 of 2See more

openbao openbao 0.29.4

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:1.7.2ae3d307658b7
stdlib@go1.25.5
1.25.10

Open the chart page →

1,508
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.01 of 5See more

openproject openproject-helm-charts 13.11.0

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.10

Open the chart page →

19,926
kratosory0.64.01 of 1See more

kratos ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
oryd/kratos:v26.2.02a13bb8d362c
stdlib@go1.26.0
1.25.10

Open the chart page →

866
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
stdlib@go1.14.12
1.25.10

Open the chart page →

11,384
aws-cloudwatch-metricsaws0.0.111 of 1See more

aws-cloudwatch-metrics aws 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
stdlib@go1.21.5
1.25.10

Open the chart page →

1,556
zabbixcetic3.1.33 of 5See more

zabbix cetic 3.1.3

3 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.10
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
stdlib@go1.18.1
1.25.10
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
stdlib@go1.18.1
1.25.10

Open the chart page →

33,725
chatwootchatwootVerified publisher2.0.242 of 3See more

chatwoot chatwoot 2.0.24

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.25.10
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
stdlib@go1.16.7
1.25.10

Open the chart page →

9,203
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
stdlib@go1.15
1.25.10

Open the chart page →

4,918
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.25.10

Open the chart page →

7,705
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
stdlib@go1.19.8
1.25.10

Open the chart page →

6,543
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
stdlib@go1.25.1
1.25.10

Open the chart page →

2,321
cloudflaredkubitodevVerified publisher1.7.91 of 1See more

cloudflared kubitodev 1.7.9

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
stdlib@go1.24.13
1.25.10

Open the chart page →

1,437
argocdnicklasfrahm-argocdVerified publisher0.3.02 of 2See more

argocd nicklasfrahm-argocd 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.10
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
stdlib@go1.22.7
1.25.10

Open the chart page →

5,240
prometheus-snmp-exporterprometheus-communityOfficialVerified publisher9.18.01 of 1See more

prometheus-snmp-exporter prometheus-community 9.18.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
stdlib@go1.25.5
1.25.10

Open the chart page →

509
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
stdlib@go1.16.7
1.25.10

Open the chart page →

2,039
daskdask2024.1.11 of 2See more

dask dask 2024.1.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
stdlib@go1.21.5
1.25.10

Open the chart page →

12,746
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
stdlib@go1.22.12
1.25.10

Open the chart page →

2,993
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
stdlib@go1.13.4
1.25.10

Open the chart page →

6,219
netbirdjaconiVerified publisher0.15.13 of 4See more

netbird jaconi 0.15.1

3 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
stdlib@go1.23.9
1.25.10
netbirdio/relay:0.45.1872e3add0e1e
stdlib@go1.23.9
1.25.10
netbirdio/signal:0.45.146ce5a45538f
stdlib@go1.23.9
1.25.10

Open the chart page →

8,390
kube-starrockskube-starrocksOfficialVerified publisher1.11.71 of 1See more

kube-starrocks kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
stdlib@go1.22.12
1.25.10

Open the chart page →

556
linkerd-jaegerlinkerd2Verified publisher30.12.112 of 4See more

linkerd-jaeger linkerd2 30.12.11

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
stdlib@go1.17.6
1.25.10
otel/opentelemetry-collector:0.59.0ee9da0b08d83
stdlib@go1.18.5
1.25.10

Open the chart page →

4,405
oneuptimeoneuptimeOfficialVerified publisher13.0.41 of 7See more

oneuptime oneuptime 13.0.4

1 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

11,192
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.25.10

Open the chart page →

4,431
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
stdlib@go1.17.1
1.25.10

Open the chart page →

6,041
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
stdlib@go1.23.6
1.25.10

Open the chart page →

1,023
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
stdlib@go1.15.12
1.25.10

Open the chart page →

6,854
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
stdlib@go1.15
1.25.10

Open the chart page →

5,173
falcosidekickfalcosecurity0.14.01 of 1See more

falcosidekick falcosecurity 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
falcosecurity/falcosidekick:2.32.01976da721518
stdlib@go1.25.1
1.25.10

Open the chart page →

1,633
glasskube-operatorglasskubeOfficialVerified publisher0.12.23 of 3See more

glasskube-operator glasskube 0.12.2

3 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
stdlib@go1.20.8
1.25.10
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
stdlib@go1.21.1
1.25.10
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
stdlib@go1.21.1
1.25.10

Open the chart page →

11,933
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
stdlib@go1.20.12
1.25.10

Open the chart page →

5,352
linkerd-vizlinkerd2-edgeVerified publisher30.14.11-edge1 of 5See more

linkerd-viz linkerd2-edge 30.14.11-edge

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prom/prometheus:v2.48.1a67e5e402ff5
stdlib@go1.21.5
1.25.10

Open the chart page →

1,346
plane-cemakeplaneOfficialVerified publisher1.8.13 of 11See more

plane-ce makeplane 1.8.1

3 of the 11 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.25.10
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
stdlib@go1.24.6
1.25.10
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
stdlib@go1.24.6
1.25.10

Open the chart page →

4,854
milvusmilvus-helm5.0.282See more

milvus milvus-helm 5.0.28

2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.25-r1fededb2f2d63
stdlib@go1.24.10
1.25.10
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
stdlib@go1.23.4
1.25.10

Open the chart page →

mssqlmssqlVerified publisher1.10.31 of 1See more

mssql mssql 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.25.10

Open the chart page →

642
opa-kube-mgmtopa-kube-mgmtVerified publisher11.0.121 of 2See more

opa-kube-mgmt opa-kube-mgmt 11.0.12

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
openpolicyagent/kube-mgmt:11.0.123a8b1bacbcd8
stdlib@go1.25.0
1.25.10

Open the chart page →

601
spirespiffeVerified publisher0.30.23 of 10See more

spire spiffe 0.30.2

3 of the 10 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
stdlib@go1.24.0
1.25.10
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
stdlib@go1.25.3
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
stdlib@go1.24.6
1.25.10

Open the chart page →

1,640
ansible-semaphorecloudhippieVerified publisher15.2.101 of 1See more

ansible-semaphore cloudhippie 15.2.10

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.19.1498ad9bc7a2a0
stdlib@go1.25.5
1.25.10

Open the chart page →

1,235
zookeepercloudpirates-zookeeperVerified publisher0.13.111 of 1See more

zookeeper cloudpirates-zookeeper 0.13.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5cab8944a33a1
stdlib@go1.18.1
1.25.10

Open the chart page →

2,924
vertical-pod-autoscalercluster-autoscaler0.12.01 of 4See more

vertical-pod-autoscaler cluster-autoscaler 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
stdlib@go1.21.3
1.25.10

Open the chart page →

1,062
codefreshcodefresh-onpremOfficialVerified publisher2.12.134 of 42See more

codefresh codefresh-onprem 2.12.13

4 of the 42 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
stdlib@go1.25.0
1.25.10
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
stdlib@go1.21.12
1.25.10
bitnamilegacy/nats:2.11.8-debian-12-r0fa0cfba6034a
stdlib@go1.24.6
1.25.10
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
stdlib@go1.23.8
1.25.10

Open the chart page →

14,956
aws-ebs-csi-driverdeliveryheroVerified publisher2.17.46 of 6See more

aws-ebs-csi-driver deliveryhero 2.17.4

6 of the 6 container images this version deploys carry CVE-2026-39820.

Open the chart page →

6,483
loki-simple-scalablegrafana1.8.112 of 3See more

loki-simple-scalable grafana 1.8.11

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
stdlib@go1.18
1.25.10
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.25.10

Open the chart page →

6,470
kube-prometheus-stackkube-prometheus-stack-oci91.4.01See more

kube-prometheus-stack kube-prometheus-stack-oci 91.4.0

1 container image this version deploys carries CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:13.2.1-distroless3600073f45a9
stdlib@go1.25.7
1.25.10

Open the chart page →

kubernetes-replicatorkubernetes-replicator2.12.41 of 1See more

kubernetes-replicator kubernetes-replicator 2.12.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.12.45dc9fc5ff59a
stdlib@go1.24.13
1.25.10

Open the chart page →

273
adguard-homerm3lVerified publisher0.24.11 of 2See more

adguard-home rm3l 0.24.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.513a143e6c071c
stdlib@go1.22.4
1.25.10

Open the chart page →

1,149
supabasetokens-studioVerified publisher1.0.03 of 14See more

supabase tokens-studio 1.0.0

3 of the 14 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
stdlib@go1.23.2
1.25.10
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.10
supabase/gotrue:v2.163.0ba4ddc594b0b
stdlib@go1.22.3
1.25.10

Open the chart page →

23,123
prometheus-operatorarldkaVerified publisher13.0.12 of 2See more

prometheus-operator arldka 13.0.1

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.73.204f2b98d71ef
stdlib@go1.22.2
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
stdlib@go1.19.4
1.25.10

Open the chart page →

2,107
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
stdlib@go1.22.4
1.25.10
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
stdlib@go1.26.0
1.25.10

Open the chart page →

8,493

Container images carrying it

4,475 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/redis:7.0.8-debian-11-r0bf01d031ba8c
stdlib@go1.18.2
1.25.10
1
bitnamilegacy/redis:8.0.2-debian-12-r4cdc2efa9c306
stdlib@go1.24.4
1.25.10
1
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
stdlib@go1.19.12
1.25.10
1
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
stdlib@go1.23.8
1.25.10
1
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.25.10
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
stdlib@go1.17
1.25.10
1
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
stdlib@go1.24.1
1.25.10
1
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
stdlib@go1.23.4
1.25.10
1
bitnamilegacy/valkey:latest0384ca2eec63
stdlib@go1.23.10
1.25.10
1
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
stdlib@go1.24.6
1.25.10
1
bitnamilegacy/valkey:8.1.3-debian-12-r1a185655855b3
stdlib@go1.24.4
1.25.10
1
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
stdlib@go1.21.5
1.25.10
1
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
stdlib@go1.18.2
1.25.10
1
bitnami/mariadb:11.7.216a7dae804fb
stdlib@go1.22.12
1.25.10
1
bitnami/mongodb:8.0.8b3bd5b6be9a0
stdlib@go1.23.7
1.25.10
1
bitnami/redis:7.4.24e65bf641805
stdlib@go1.23.8
1.25.10
1
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
stdlib@go1.18.6
1.25.10
1
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
stdlib@go1.24.6
1.25.10
1
bitpoke/stack-default-backend:latestc5eed1ddf692
stdlib@go1.16.6
1.25.10
1
bitpoke/wordpress-operator:v0.12.421284d1df473
stdlib@go1.17.13
1.25.10
1
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
stdlib@go1.17.13
1.25.10
1
blackducksoftware/bdba-pgupgrader:2026.6.35c97f3a3f8b7
stdlib@go1.18.2
1.25.10
1
blackducksoftware/blackduck-alert-db:8.4.06310fac39d53
stdlib@go1.24.6
1.25.10
1
blipai/deckard:0.0.28737d5d19a312
stdlib@go1.18.10
1.25.10
1
bloomberg/goldpinger:3.10.08520120f5598
stdlib@go1.21.9
1.25.10
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
stdlib@go1.22.11
1.25.10
1
bluenviron/mediamtx:1.17.19e39256d1ba3
stdlib@go1.25.8
1.25.10
1
bolkedebruin/rdpgw:masterc0dc0589373a
stdlib@go1.24.13
1.25.10
1
bonovoo/secrethor:1.1.2bb93b68fcd17
stdlib@go1.24.2
1.25.10
1
breton/cool:dev41b1bb483aa2
stdlib@go1.19.2
1.25.10
1
bsgrigorov/helm-operator:latest45ab095f09c8
stdlib@go1.15.12
1.25.10
1
btcpayserver/tor:0.4.8.10e9585b68dc6b
stdlib@go1.16.5
1.25.10
1
buddyspencer/gickup:0.10.386b656f19b0c1
stdlib@go1.22.5
1.25.10
1
buddyspencer/gickup:0.10.309e7dbf923c12
stdlib@go1.21.9
1.25.10
1
buildkite/agent:3.25.0aec38cfaae0e
stdlib@go1.14.7
1.25.10
1
bulich/domain-exporter:latest6d0b780f7c7b
stdlib@go1.20.4
1.25.10
1
burganbank/vault-initializer:v19259c34e4037
stdlib@go1.22.2
1.25.10
1
burningalchemist/sql_exporter:0.16.0b8e4757c7def
stdlib@go1.23.2
1.25.10
1
byjg/static-httpserver:latest562cc8b9c40b
stdlib@go1.26.1
1.25.10
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
stdlib@go1.20.5
1.25.10
1
caarlos0/domain_exporter:v1.23.0d11dec138900
stdlib@go1.21.6
1.25.10
1
calico/cni:v3.28.0cef0c907b8f4
stdlib@go1.22.2
1.25.10
1
calico/cni:v3.28.1e486870cfde8
stdlib@go1.22.5
1.25.10
1
calico/kube-controllers:v3.28.08f04e4772a2b
stdlib@go1.22.3
1.25.10
1
calico/kube-controllers:v3.28.1eadb3a25109a
stdlib@go1.22.5
1.25.10
1
calico/node:v3.28.0385bf6391fea
stdlib@go1.22.3
1.25.10
1
calico/node:v3.28.1d8c644a8a3ee
stdlib@go1.22.5
1.25.10
1
camptocamp/bucket-cloner:latestacfafc308d88
stdlib@go1.16.5
1.25.10
1
captnbp/freebox-exporter:1.0.0-r01600c5a253e0
stdlib@go1.21.3
1.25.10
1
caroga/commentoplusplus:v1.8.7f3233882b3bd
stdlib@go1.15.15
1.25.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.