StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,940
of 17,790 indexed, latest versions
Container images
4,539
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 3,940 of 17,790 indexed charts deploy, on 4,539 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,539
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

3,940 by stars
ChartLatestAffected imagesRadar Score
cluster-api-visualizercluster-api-visualizer1.5.01 of 1See more

cluster-api-visualizer cluster-api-visualizer 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
stdlib@go1.24.11
1.25.10

Open the chart page →

558
clustereye-stackclustereyeVerified publisher0.1.11 of 5See more

clustereye-stack clustereye 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10

Open the chart page →

4,906
clusternet-hubclusternet1.0.01 of 1See more

clusternet-hub clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-hub:v1.0.059f75504c5d4
stdlib@go1.23.8
1.25.10

Open the chart page →

1,403
clusternet-schedulerclusternet1.0.01 of 1See more

clusternet-scheduler clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-scheduler:v1.0.0a6ae5aff81ce
stdlib@go1.23.8
1.25.10

Open the chart page →

1,403
cluster-setupcluster-setup1.5.07 of 8See more

cluster-setup cluster-setup 1.5.0

7 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
stdlib@go1.24.3
1.25.10
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.10
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
stdlib@go1.22.7
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.17.2ec56edb1161d
stdlib@go1.23.8
1.25.10
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
stdlib@go1.23.8
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.17.2e18989b4f912
stdlib@go1.23.8
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
stdlib@go1.23.8
1.25.10

Open the chart page →

10,111
cockroachdb-chartcockroachdbv226.3.11 of 1See more

cockroachdb-chart cockroachdbv2 26.3.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
stdlib@go1.23.12
1.25.10

Open the chart page →

703
istio-allcode4devsVerified publisher1.2.04 of 6See more

istio-all code4devs 1.2.0

4 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
stdlib@go1.23.2
1.25.10
istio/pilot:1.24.2-distroless137e44e3d1d2
stdlib@go1.23.2
1.25.10
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
stdlib@go1.22.5
1.25.10
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
stdlib@go1.22.6
1.25.10

Open the chart page →

4,811
istio-control-planecode4devsVerified publisher1.0.02 of 3See more

istio-control-plane code4devs 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
stdlib@go1.23.2
1.25.10
istio/pilot:1.24.2-distroless137e44e3d1d2
stdlib@go1.23.2
1.25.10

Open the chart page →

2,373
maintenancecodewithemadVerified publisher0.1.61 of 1See more

maintenance codewithemad 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/caddy:2.9-alpineb4e3952384eb
stdlib@go1.23.4
1.25.10

Open the chart page →

1,476
dawarichcogitriVerified publisher2.8.41 of 3See more

dawarich cogitri 2.8.4

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
freikin/dawarich:1.14.511826c67e4b1
stdlib@go1.24.4
1.25.10

Open the chart page →

5,823
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
stdlib@go1.13.10
1.25.10

Open the chart page →

7,313
cortex-tenantcortex-tenantVerified publisher0.8.11 of 1See more

cortex-tenant cortex-tenant 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/blind-oracle/cortex-tenant:v2.0.09f8896ffc15b
stdlib@go1.25.1
1.25.10

Open the chart page →

786
cosmo-controller-managercosmoVerified publisher0.9.01 of 2See more

cosmo-controller-manager cosmo 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-controller-manager:v0.9.08c7fa5552028
stdlib@go1.20.5
1.25.10

Open the chart page →

1,926
cosmo-dashboardcosmoVerified publisher0.9.11 of 1See more

cosmo-dashboard cosmo 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-dashboard:v0.9.16a1c4a81a924
stdlib@go1.20.5
1.25.10

Open the chart page →

1,938
cp-schema-registrycp-schema-registryVerified publisher1.0.01 of 1See more

cp-schema-registry cp-schema-registry 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
stdlib@go1.25.4
1.25.10

Open the chart page →

1,883
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
stdlib@go1.16.5
1.25.10

Open the chart page →

6,480
chalk-operatorcrashoverride-helm-chartsVerified publisher0.1.11 of 1See more

chalk-operator crashoverride-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/chalk-operator:v0.1.128eee62e9bfa
stdlib@go1.24.13
1.25.10

Open the chart page →

375
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.25.10

Open the chart page →

3,026
cronjob-scale-down-operatorcronschedules0.4.41 of 1See more

cronjob-scale-down-operator cronschedules 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cronschedules/cronjob-scale-down-operator:0.4.41c4e803d7169
stdlib@go1.25.0
1.25.10

Open the chart page →

444
cruisekubecruisekubeOfficialVerified publisher0.3.41 of 5See more

cruisekube cruisekube 0.3.4

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
stdlib@go1.24.1
1.25.10

Open the chart page →

440
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
stdlib@go1.19.8
1.25.10

Open the chart page →

13,792
revadcs3orgOfficialVerified publisher1.6.11 of 1See more

revad cs3org 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
stdlib@go1.20.4
1.25.10

Open the chart page →

1,711
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.25.10
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
stdlib@go1.18.4
1.25.10
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
stdlib@go1.17.3
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
stdlib@go1.17.3
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
stdlib@go1.16.2
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.25.10

Open the chart page →

15,931
CubeUniversecubeuniverseVerified publisher0.1.01 of 1See more

CubeUniverse cubeuniverse 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
tksky1/cubeuniverse:0.1alphaec7b889f380f
stdlib@go1.20.3
1.25.10

Open the chart page →

1,837
cyphernetes-operatorcyphernetes-operatorVerified publisher0.1.01 of 1See more

cyphernetes-operator cyphernetes-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
stdlib@go1.24.4
1.25.10

Open the chart page →

504
dagrondagron-workflowVerified publisher0.9.21 of 3See more

dagron dagron-workflow 0.9.2

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10

Open the chart page →

1,192
dagster-cloud-agentdagster-cloudVerified publisher1.13.221 of 1See more

dagster-cloud-agent dagster-cloud 1.13.22

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
dagster/dagster-cloud-agent:1.13.229674f3b94a3b
stdlib@go1.25.7
1.25.10

Open the chart page →

1,109
aibrixdanchevVerified publisher0.7.02 of 5See more

aibrix danchev 0.7.0

2 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
aibrix/controller-manager:v0.7.076aabbbfda79
stdlib@go1.22.12
1.25.10
aibrix/gateway-plugins:v0.7.05b93ea4c753a
stdlib@go1.22.12
1.25.10

Open the chart page →

5,343
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.25.10

Open the chart page →

38,441
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
stdlib@go1.22.2
1.25.10

Open the chart page →

4,915
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
stdlib@go1.15.15
1.25.10

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
stdlib@go1.13.11
1.25.10

Open the chart page →

4,570
dbrepodbrepo1.13.311 of 25See more

dbrepo dbrepo 1.13.3

11 of the 25 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
stdlib@go1.23.4
1.25.10
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
stdlib@go1.23.8
1.25.10
bitnamilegacy/mariadb-galera:11.3.2-debian-12-r9aee9c668098f
stdlib@go1.22.5
1.25.10
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
stdlib@go1.21.12
1.25.10
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
stdlib@go1.23.8
1.25.10
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
stdlib@go1.22.8
1.25.10
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
stdlib@go1.22.8
1.25.10
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
stdlib@go1.22.8
1.25.10
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
stdlib@go1.22.7
1.25.10
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
stdlib@go1.24.1
1.25.10
bitnamilegacy/valkey:latest0384ca2eec63
stdlib@go1.23.10
1.25.10

Open the chart page →

53,108
mealiedeimosfr-charts1.0.151 of 1See more

mealie deimosfr-charts 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
stdlib@go1.24.4
1.25.10

Open the chart page →

4,059
dregsydeliveryheroVerified publisher0.1.51 of 1See more

dregsy deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
stdlib@go1.18.3
1.25.10

Open the chart page →

2,977
gripmockdeliveryheroVerified publisher1.1.31 of 1See more

gripmock deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
stdlib@go1.14.6
1.25.10

Open the chart page →

2,793
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
stdlib@go1.13.15
1.25.10

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
stdlib@go1.13.5
1.25.10

Open the chart page →

7,987
snapshot-controllerdemocratic-csiVerified publisher0.3.01 of 1See more

snapshot-controller democratic-csi 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.10

Open the chart page →

467
developer-operatordeveloper-operatorVerified publisher2.1.21 of 1See more

developer-operator developer-operator 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
stdlib@go1.24.5
1.25.10

Open the chart page →

1,862
kube-bench-metricsdevopstalesVerified publisher0.1.01 of 1See more

kube-bench-metrics devopstales 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.25.10

Open the chart page →

2,111
kubedashdevopstalesOfficialVerified publisher4.0.05 of 8See more

kubedash devopstales 4.0.0

5 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:18.3a9abf4275f9e
stdlib@go1.24.6
1.25.10
oliver006/redis_exporter:v1.82.0-alpineda9e89ee4e75
stdlib@go1.26.1
1.25.10
prom/statsd-exporter:v0.22.48be660470961
stdlib@go1.17.3
1.25.10
sosedoff/pgweb:latesta5256d416e2e
stdlib@go1.24.6
1.25.10
quay.io/prometheuscommunity/postgres-exporter:v0.19.1e96064f87622
stdlib@go1.25.7
1.25.10

Open the chart page →

9,271
permission-managerdevopstalesVerified publisher1.8.01 of 1See more

permission-manager devopstales 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
stdlib@go1.16.8
1.25.10

Open the chart page →

2,266
trivy-operatordevopstalesVerified publisher2.5.01 of 1See more

trivy-operator devopstales 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
devopstales/trivy-operator:2.575136aa7a26e
stdlib@go1.18.10
1.25.10

Open the chart page →

5,607
dnsmasqdevplayer0Verified publisher0.1.51 of 2See more

dnsmasq devplayer0 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
stdlib@go1.16.5
1.25.10

Open the chart page →

3,392
whoamidevplayer0Verified publisher0.1.21 of 1See more

whoami devplayer0 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
traefik/whoami:v1.6.12c52bb2c8480
stdlib@go1.15.6
1.25.10

Open the chart page →

1,216
calicodevtron0.1.14 of 4See more

calico devtron 0.1.1

4 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
stdlib@go1.15.2
1.25.10
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
stdlib@go1.15.2
1.25.10
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
stdlib@go1.15.2
1.25.10
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.25.10

Open the chart page →

10,094
clairdevtron0.1.141 of 2See more

clair devtron 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
stdlib@go1.17.6
1.25.10

Open the chart page →

6,237
discord-alertmanagerdevtron-labs0.10.01 of 1See more

discord-alertmanager devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.25.10

Open the chart page →

951
dex-serverdex-server1.19.12 of 3See more

dex-server dex-server 1.19.1

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
dexidp/dex:v2.39.1-distroless43655afd1a8f
stdlib@go1.21.6
1.25.10
public.ecr.aws/cloudnatix/llmariner/database-creator:1.19.162375abc3c56
stdlib@go1.23.12
1.25.10

Open the chart page →

2,245

Container images carrying it

4,539 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/telegraf:1.27507a3eecf809
stdlib@go1.20.7
1.25.10
1
library/telegraf:1.19.0-alpine794079a7f241
stdlib@go1.16.5
1.25.10
1
library/telegraf:1.19-alpineaddb86c0c520
stdlib@go1.16.6
1.25.10
1
library/traefik:v2.11.00a5157f742d2
stdlib@go1.22.0
1.25.10
1
library/traefik:3.3.5104204dadedf
stdlib@go1.23.7
1.25.10
1
library/traefik:v2.10.11489caffaedb
stdlib@go1.20.3
1.25.10
1
library/traefik:2.10.61957e3314f43
stdlib@go1.21.4
1.25.10
1
library/traefik:2.5.62f603f8d3abe
stdlib@go1.17.5
1.25.10
1
library/traefik:v3.6.1334d5089d0b41
stdlib@go1.25.8
1.25.10
1
library/traefik:v1.7.345d47b7bb2546
stdlib@go1.16.12
1.25.10
1
library/traefik:2.5.47d0228d19042
stdlib@go1.17.3
1.25.10
1
library/traefik:2.4.8eda951fd29a8
stdlib@go1.16.2
1.25.10
1
library/traefik:2.2.8f5af5a5ce17f
stdlib@go1.14.6
1.25.10
1
library/vault:1.13.3f98ac9dd97b0
stdlib@go1.20.4
1.25.10
1
library/zookeeper:3.9.5cab8944a33a1
stdlib@go1.18.1
1.25.10
1
library/zookeeper:3.9.4dfa9ba46d14b
stdlib@go1.18.1
1.25.10
1
librenms/librenms:24.11.00920bc9117a8
stdlib@go1.21.5
1.25.10
1
librenms/librenms:22.4.14f1f3d667cc7
stdlib@go1.16.12
1.25.10
1
librenms/librenms:26.8.28194a4a9ff49
stdlib@go1.24.6
1.25.10
1
lifailon/openrouter-bot:latestea37e4b6b952
stdlib@go1.25.0
1.25.10
1
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
stdlib@go1.22.1
1.25.10
1
linuxserver/calibre-web:0.6.24241009026e6f
stdlib@go1.17.8
1.25.10
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
stdlib@go1.16.7
1.25.10
1
linuxserver/cloud9:latest45c5fe102ff3
stdlib@go1.17.11
1.25.10
1
linuxserver/smokeping:2.9.02f4488c9afcd
stdlib@go1.24.12
1.25.10
1
linuxserver/smokeping:2.8.2b7f906899cd3
stdlib@go1.22.5
1.25.10
1
lishimeng/hufu:v1.2.13d5752dac834
stdlib@go1.20.7
1.25.10
1
lishimeng/owl-console:v0.11.2c79a67657baf
stdlib@go1.21.3
1.25.10
1
lishimeng/owl-messager:v0.11.23d00485e64dc
stdlib@go1.21.3
1.25.10
1
lishimeng/passport:v0.2.163e7d05ded625
stdlib@go1.20.7
1.25.10
1
lishimeng/passport-profile:v0.2.160970dfe5dc8f
stdlib@go1.20.7
1.25.10
1
lishimeng/tabby:v1.0.48145c3dc83c8
stdlib@go1.20.6
1.25.10
1
lishimeng/tree:v0.2.89b2f8be6c7d3
stdlib@go1.20.6
1.25.10
1
lishimeng/zoo:v0.4.0e0b8d2d8ca28
stdlib@go1.20.8
1.25.10
1
listmonk/listmonk:v6.0.0bf3903d54a46
stdlib@go1.24.1
1.25.10
1
litestream/litestream:0.3c5a1e1b01916
stdlib@go1.21.3
1.25.10
1
livekit/ingress:v1.2.21ab01641b366
stdlib@go1.20.7
1.25.10
1
livekit/livekit-recorder:v0.3.13ecf1409c75e0
stdlib@go1.16.2
1.25.10
1
livekit/livekit-server:v1.9.03602a85840d5
stdlib@go1.24.3
1.25.10
1
livekit/livekit-server:v1.0.08391fd1b834f
stdlib@go1.17.10
1.25.10
1
lmierzwa/karma:v0.503751e5eed656
stdlib@go1.13.4
1.25.10
1
lmierzwa/karma:v0.70d417abe7ddb5
stdlib@go1.15.2
1.25.10
1
localstack/localstack:3.19d278167f2b7
stdlib@go1.18.10
1.25.10
1
loeken/home-assistant:2026.5.14ce6abc553b3
stdlib@go1.23.3
1.25.10
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
stdlib@go1.16.6
1.25.10
1
loftsh/jspolicy:0.2.225deb9bd2683
stdlib@go1.17.13
1.25.10
1
loftsh/virtual-cluster:0.0.28023b13bf5898
stdlib@go1.15.11
1.25.10
1
logiqai/flash:v3.10.265b996bc7bdc
stdlib@go1.21.13
1.25.10
1
logiqai/flash-discovery:v2.0.3f5b551bca98e
stdlib@go1.18.9
1.25.10
1
logiqai/logiqctl:2.0.4798306811f2d
stdlib@go1.13.7
1.25.10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.