StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,940
of 17,790 indexed, latest versions
Container images
4,539
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 3,940 of 17,790 indexed charts deploy, on 4,539 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,539
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

3,940 by stars
ChartLatestAffected imagesRadar Score
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
stdlib@go1.13.8
1.25.10

Open the chart page →

4,713
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
stdlib@go1.18.4
1.25.10

Open the chart page →

4,049
yet-another-cloudwatch-exporteryet-another-cloudwatch-exporter0.38.01 of 1See more

yet-another-cloudwatch-exporter yet-another-cloudwatch-exporter 0.38.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
stdlib@go1.22.4
1.25.10

Open the chart page →

923
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
stdlib@go1.23.12
1.25.10

Open the chart page →

4,017
paperlesszekker6Verified publisher11.8.01 of 1See more

paperless zekker6 11.8.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10

Open the chart page →

4,651
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
stdlib@go1.22.6
1.25.10

Open the chart page →

829
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
stdlib@go1.23.7
1.25.10

Open the chart page →

1,851
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10

Open the chart page →

19,828
agentareaagentareaVerified publisher0.0.187 of 16See more

agentarea agentarea 0.0.18

7 of the 16 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-manager:latestefe23cef3727
stdlib@go1.22.5
1.25.10
agentarea/agentarea-mcp-runner:latestd3c209a5d531
stdlib@go1.19.8
1.25.10
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10
library/postgres:alpined3e1620b530c
stdlib@go1.24.6
1.25.10
oryd/kratos:v1.3.1fe2428f103a6
stdlib@go1.23.2
1.25.10
temporalio/auto-setup:1.29.15b3502a3b685
stdlib@go1.25.0
1.25.10
temporalio/ui:2.39.0b768f87f18b5
stdlib@go1.23.4
1.25.10

Open the chart page →

15,049
alertmanager-discordalertmanagerdiscordVerified publisher0.3.21 of 1See more

alertmanager-discord alertmanagerdiscord 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
speckle/alertmanager-discord:latestf6221ff308e9
stdlib@go1.22.4
1.25.10

Open the chart page →

419
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
stdlib@go1.24.4
1.25.10

Open the chart page →

12,092
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.25.10

Open the chart page →

12,081
clearml-servingallegroaiVerified publisher1.6.26 of 9See more

clearml-serving allegroai 1.6.2

6 of the 9 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
stdlib@go1.19.6
1.25.10
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
stdlib@go1.18.2
1.25.10
grafana/grafana:9.4.376dcf36e7d2a
stdlib@go1.19.4
1.25.10
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.10
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
stdlib@go1.19.4
1.25.10
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.25.10

Open the chart page →

17,897
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.25.10

Open the chart page →

4,997
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.25.10

Open the chart page →

8,387
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
stdlib@go1.18.5
1.25.10

Open the chart page →

3,119
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
stdlib@go1.18.10
1.25.10

Open the chart page →

2,173
cloudflare-operatorankra-chartsVerified publisher0.2.01 of 1See more

cloudflare-operator ankra-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
adyanth/cloudflare-operatordigest-pinned6b168dc237d5
stdlib@go1.24.4
1.25.10

Open the chart page →

499
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
stdlib@go1.24.4
1.25.10

Open the chart page →

5,971
upcloud-csiankra-chartsVerified publisher0.4.08 of 8See more

upcloud-csi ankra-charts 0.4.0

8 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
stdlib@go1.23.12
1.25.10
ghcr.io/upcloudltd/upcloud-csidigest-pinned5af91c663788
stdlib@go1.24.13
1.25.10
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
stdlib@go1.17.3
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
stdlib@go1.17.3
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
stdlib@go1.17.3
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
stdlib@go1.17.3
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.10
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.10

Open the chart page →

14,969
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
stdlib@go1.19.3
1.25.10

Open the chart page →

1,149
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
stdlib@go1.22.5
1.25.10

Open the chart page →

3,395
anteonanteonVerified publisher2.6.45 of 13See more

anteon anteon 2.6.4

5 of the 13 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.64634b094b2183
stdlib@go1.22.1
1.25.10
ddosify/selfhosted_hammer:2.0.0181965edb12e
stdlib@go1.18.1
1.25.10
library/influxdb:2.6.1-alpine44a366dd7724
stdlib@go1.19.4
1.25.10
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.10
prom/prometheus:v2.37.98176adea328e
stdlib@go1.19.11
1.25.10

Open the chart page →

22,304
antreaantreaVerified publisher2.7.01 of 2See more

antrea antrea 2.7.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
stdlib@go1.25.7
1.25.10

Open the chart page →

3,539
api-usage-serverapi-usage-server1.16.01 of 1See more

api-usage-server api-usage-server 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
stdlib@go1.23.12
1.25.10

Open the chart page →

740
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
stdlib@go1.20.5
1.25.10

Open the chart page →

1,096
scannerappscodeVerified publisher2026.1.153 of 3See more

scanner appscode 2026.1.15

3 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
stdlib@go1.21.5
1.25.10
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
stdlib@go1.25.5
1.25.10
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
stdlib@go1.20.2
1.25.10

Open the chart page →

5,315
smtprelayappscodeVerified publisher2026.9.111 of 1See more

smtprelay appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
stdlib@go1.23.2
1.25.10

Open the chart page →

872
stash-enterpriseappscodeVerified publisher0.42.04 of 4See more

stash-enterprise appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.25.10
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
stdlib@go1.24.9
1.25.10
ghcr.io/stashed/stash-crd-installer:v0.42.1d6c9b7a1f7b8
stdlib@go1.25.5
1.25.10
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
stdlib@go1.25.5
1.25.10

Open the chart page →

3,628
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
stdlib@go1.24.6
1.25.10

Open the chart page →

5,249
argocd-rbac-operatorargocd-rbac-operator0.4.51 of 1See more

argocd-rbac-operator argocd-rbac-operator 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-rbac-operator:v0.2.451dded00137a
stdlib@go1.24.9
1.25.10

Open the chart page →

961
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
stdlib@go1.23.3
1.25.10
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
stdlib@go1.23.3
1.25.10

Open the chart page →

2,290
s3dartur9010Verified publisher1.0.11 of 1See more

s3d artur9010 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
stdlib@go1.26.2
1.25.10

Open the chart page →

1,736
arvancloud-webhookarvancloud-webhookVerified publisher1.0.01 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
stdlib@go1.25.4
1.25.10

Open the chart page →

2,327
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
stdlib@go1.14.15
1.25.10

Open the chart page →

2,819
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
stdlib@go1.18.2
1.25.10

Open the chart page →

17,951
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
stdlib@go1.14.12
1.25.10

Open the chart page →

10,740
dltbrokerassist-iot-distributed-broker0.2.04 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
stdlib@go1.17.13
1.25.10
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.25.10
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.25.10
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.25.10

Open the chart page →

77,883
dltloggingassist-iot-logging-auditing0.2.04 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
stdlib@go1.17.13
1.25.10
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.25.10
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.25.10
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.25.10

Open the chart page →

77,863
astradnsastradnsVerified publisher0.2.92 of 2See more

astradns astradns 0.2.9

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
stdlib@go1.26.1
1.25.10
ghcr.io/astradns/astradns-operator:v0.2.909e58b62416a
stdlib@go1.26.1
1.25.10

Open the chart page →

2,649
deployautoml0.1.02 of 3See more

deploy automl 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.25.10
muonsoft/openapi-mock:latestc9afe1295484
stdlib@go1.20.2
1.25.10

Open the chart page →

2,947
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
stdlib@go1.17.5
1.25.10

Open the chart page →

4,308
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
stdlib@go1.16.2
1.25.10

Open the chart page →

3,398
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
stdlib@go1.18.1
1.25.10

Open the chart page →

3,731
prismav1o-chartsVerified publisher0.3.11 of 1See more

prism av1o-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.25.10

Open the chart page →

1,276
kubebrowseravistoOfficialVerified publisher1.4.01 of 1See more

kubebrowser avisto 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/kubebrowser:0.10.0a354b8dc7e6a
stdlib@go1.24.1
1.25.10

Open the chart page →

677
generic-appb3oVerified publisher0.1.61 of 1See more

generic-app b3o 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.25.10

Open the chart page →

1,280
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
stdlib@go1.13.10
1.25.10

Open the chart page →

4,821
music-assistantbdclark-helm-chartsVerified publisher0.4.131 of 1See more

music-assistant bdclark-helm-charts 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.3885872224fa5
stdlib@go1.25.5
1.25.10

Open the chart page →

3,702
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
stdlib@go1.17.8
1.25.10
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
stdlib@go1.17.5
1.25.10
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
stdlib@go1.17.8
1.25.10

Open the chart page →

7,821

Container images carrying it

4,539 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
istio/operator:1.18.270f9d1fe5fff
stdlib@go1.20.6
1.25.10
1
istio/pilot:1.10.0294ca55bd1cc
stdlib@go1.16.4
1.25.10
1
istio/pilot:1.29.0325156535773
stdlib@go1.25.7
1.25.10
1
istio/pilot:1.23.69c3d6a218181
stdlib@go1.23.7
1.25.10
1
istio/pilot:1.16.0ac0284d75ec9
stdlib@go1.19.3
1.25.10
1
istio/pilot:1.17.1ce9d87606701
stdlib@go1.20.1
1.25.10
1
istio/pilot:1.15.2db08d6963975
stdlib@go1.19.2
1.25.10
1
istio/pilot:1.10.3e7e110a421c2
stdlib@go1.16.6
1.25.10
1
istio/pilot:1.29.1f8b0e412ac4a
stdlib@go1.25.8
1.25.10
1
istio/proxyv2:1.9.687a9db561d2e
stdlib@go1.15.13
1.25.10
1
istio/proxyv2:1.10.088c6c693e67a
stdlib@go1.16.4
1.25.10
1
istio/proxyv2:1.14.1df69c1a7af7c
stdlib@go1.18.2
1.25.10
1
itzg/bungeecord:latest1c59f9631f3b
stdlib@go1.24.6
1.25.10
1
itzg/mc-router:1.16.1bb552b59fb53
stdlib@go1.18.4
1.25.10
1
itzg/minecraft-server:latest8672e335dbef
stdlib@go1.24.6
1.25.10
1
itzg/minecraft-server:2026.9.1e8640538dac5
stdlib@go1.22.2
1.25.10
1
itzmanish/ecr-token-renew:latest02154d1c05b5
stdlib@go1.16.6
1.25.10
1
ixsystems/truecommand:3.2.019c218455cd2
stdlib@go1.25.0
1.25.10
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
stdlib@go1.17.2
1.25.10
1
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.25.10
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.25.10
1
jaegertracing/all-in-one:1.2942822be7888b
stdlib@go1.17.3
1.25.10
1
jaegertracing/all-in-one:1.53.060e65bfffe1f
stdlib@go1.21.5
1.25.10
1
jaegertracing/all-in-one:1.42.07d32a4eddec7
stdlib@go1.19.5
1.25.10
1
jaegertracing/all-in-one:1.22.0ca6b73330616
stdlib@go1.15.8
1.25.10
1
jaegertracing/all-in-one:1.18db45c07f2e1b
stdlib@go1.14.4
1.25.10
1
jaegertracing/all-in-one:1.55f6b5d09073f1
stdlib@go1.22.0
1.25.10
1
jaegertracing/jaeger:2.9.0e128b9adbb29
stdlib@go1.24.5
1.25.10
1
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
stdlib@go1.19.4
1.25.10
1
jaegertracing/jaeger-operator:1.61.03f036ec60e61
stdlib@go1.22.3
1.25.10
1
jaegertracing/jaeger-query:1.41.0b636f0f464bc
stdlib@go1.19.4
1.25.10
1
jakuboskera/todo-operator:v0.1.0a305b8ce5bff
stdlib@go1.25.3
1.25.10
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
stdlib@go1.22.8
1.25.10
1
jamesread/olivetin:3000.20.0f3066e207efd
stdlib@go1.26.0
1.25.10
1
jdvalencia422/observabilitysec:latesta80b6e47a7b8
stdlib@go1.18.4
1.25.10
1
jeboehm/mailserver-filter:5.0.92e756949e537d
stdlib@go1.24.1
1.25.10
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
stdlib@go1.24.1
1.25.10
1
jeboehm/mailserver-mta:5.0.925fb2f31c940d
stdlib@go1.24.1
1.25.10
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
stdlib@go1.24.1
1.25.10
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
stdlib@go1.21.8
1.25.10
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
stdlib@go1.21.8
1.25.10
1
jfwenisch/alpine-tor:latest9e6c229f953c
stdlib@go1.14.6
1.25.10
1
jhaals/yopass:11.17.026873480863b
stdlib@go1.20.5
1.25.10
1
jhaals/yopass:11.15.16bca8d5a4914
stdlib@go1.20.5
1.25.10
1
jhaals/yopass:12.5.0916a1cf45d36
stdlib@go1.25.5
1.25.10
1
jhaals/yopass:11.4.69516e3b3e88c
stdlib@go1.19.1
1.25.10
1
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
stdlib@go1.17.13
1.25.10
1
jhonbrownn/elchi-discovery:latest8f6551ecc98c
stdlib@go1.23.1
1.25.10
1
jkremser/log2rbac:v0.0.5e35cf56ef183
stdlib@go1.17.6
1.25.10
1
jmferrer/azure-devops-agent:latest030f68ec6998
stdlib@go1.13.5
1.25.10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.