StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,934
of 17,803 indexed, latest versions
Container images
4,529
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 3,934 of 17,803 indexed charts deploy, on 4,529 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,529
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

3,934 by stars
ChartLatestAffected imagesRadar Score
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
stdlib@go1.13.10
1.25.10

Open the chart page →

7,266
echoappechoapp0.1.01 of 1See more

echoapp echoapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
hashicorp/http-echo:1.0.0fcb75f691c8b
stdlib@go1.21.1
1.25.10

Open the chart page →

550
aeros-orchestrator-overlayeclipse-aeriosVerified publisher2.0.01 of 2See more

aeros-orchestrator-overlay eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
masipcat/wireguard-go:latest696206e5954d
stdlib@go1.20.14
1.25.10

Open the chart page →

1,195
api-gatewayeclipse-aeriosVerified publisher1.7.01 of 1See more

api-gateway eclipse-aerios 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
devopsfaith/krakend:2.6.34c678c224f67
stdlib@go1.22.3
1.25.10

Open the chart page →

1,427
federatoreclipse-aeriosVerified publisher1.1.01 of 1See more

federator eclipse-aerios 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
eclipseaerios/federator:1.1.018c7f0d101c0
stdlib@go1.22.12
1.25.10

Open the chart page →

743
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.25.10

Open the chart page →

4,647
iotaeclipse-aeriosVerified publisher1.0.23 of 4See more

iota eclipse-aerios 1.0.2

3 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
eclipseaerios/iota-tangle-peerer:latest99d7ff18d416
stdlib@go1.22.12
1.25.10
iotaledger/hornet:2.001206f1ba89c
stdlib@go1.21.10
1.25.10
iotaledger/inx-dashboard:1.012c669cb8748
stdlib@go1.21.1
1.25.10

Open the chart page →

13,638
llo-apieclipse-aeriosVerified publisher1.0.01 of 1See more

llo-api eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
eclipseaerios/llo-api:1.2.0ab7a04182191
stdlib@go1.21.13
1.25.10

Open the chart page →

931
llo-docker-operatoreclipse-aeriosVerified publisher1.0.02 of 2See more

llo-docker-operator eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
stdlib@go1.23.12
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
stdlib@go1.19.4
1.25.10

Open the chart page →

2,194
llo-k8seclipse-aeriosVerified publisher1.1.02 of 2See more

llo-k8s eclipse-aerios 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
stdlib@go1.21.13
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
stdlib@go1.19.4
1.25.10

Open the chart page →

2,165
llo-natseclipse-aeriosVerified publisher1.0.01 of 1See more

llo-nats eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/nats:2.11.4c8cd23806eef
stdlib@go1.24.3
1.25.10

Open the chart page →

837
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
timescale/timescaledb-postgis:latest-pg127758704d4a14
stdlib@go1.14
1.25.10

Open the chart page →

11,485
openfaas2eclipse-aeriosVerified publisher12.0.56 of 6See more

openfaas2 eclipse-aerios 12.0.5

6 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/nats-streaming:0.25.5ced93c701875
stdlib@go1.19.10
1.25.10
prom/prometheus:v2.51.24f6c47e39a90
stdlib@go1.22.2
1.25.10
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
stdlib@go1.23.4
1.25.10
ghcr.io/openfaas/gateway:0.27.1382b15393116e
stdlib@go1.24.6
1.25.10
ghcr.io/openfaasltd/jetstream-queue-worker:0.3.37d96366e208b1
stdlib@go1.22.1
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.10

Open the chart page →

6,842
openldap-stack-haeclipse-aeriosVerified publisher4.1.21 of 4See more

openldap-stack-ha eclipse-aerios 4.1.2

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
eclipseaerios/openldap:2.6.30208743f315e
stdlib@go1.18.2
1.25.10

Open the chart page →

7,539
orion-ldeclipse-aeriosVerified publisher1.0.01 of 2See more

orion-ld eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.21.12
1.25.10

Open the chart page →

9,819
chartecr-toke-renew0.1.51 of 1See more

chart ecr-toke-renew 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
itzmanish/ecr-token-renew:latest02154d1c05b5
stdlib@go1.16.6
1.25.10

Open the chart page →

2,818
edge-accessedge-accessVerified publisher0.1.01 of 1See more

edge-access edge-access 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.13.056e3daedf765
stdlib@go1.25.4
1.25.10

Open the chart page →

677
continuum-proxyedgelesssysVerified publisher1.5.11 of 1See more

continuum-proxy edgelesssys 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/continuum/continuum-proxydigest-pinned24c76f294a80
stdlib@go1.23.3
1.25.10

Open the chart page →

859
marblerunedgelesssysVerified publisher1.9.21 of 1See more

marblerun edgelesssys 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
stdlib@go1.26.1
1.25.10

Open the chart page →

1,864
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
stdlib@go1.16.7
1.25.10

Open the chart page →

11,025
pagesedgwarepages1.0.01 of 3See more

pages edgwarepages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,261
grafanaedu5.3.01 of 1See more

grafana edu 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.10

Open the chart page →

3,199
prometheusedu11.6.04 of 6See more

prometheus edu 11.6.0

4 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.25.10
prom/prometheus:v2.19.0bfad037f95e5
stdlib@go1.14.4
1.25.10
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.25.10
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.25.10

Open the chart page →

8,492
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
stdlib@go1.13.10
1.25.10

Open the chart page →

7,338
cert-manager-cpanel-dns-webhookegebackVerified publisher1.0.61 of 1See more

cert-manager-cpanel-dns-webhook egeback 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
stdlib@go1.22.8
1.25.10

Open the chart page →

1,299
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
stdlib@go1.23.3
1.25.10

Open the chart page →

2,185
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.10

Open the chart page →

7,445
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.25.10

Open the chart page →

30,645
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
stdlib@go1.24.4
1.25.10
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
stdlib@go1.24.4
1.25.10

Open the chart page →

3,986
eg-universal-agent-operatoreg-universal-agent-operatorVerified publisher0.0.51 of 1See more

eg-universal-agent-operator eg-universal-agent-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
stdlib@go1.24.6
1.25.10

Open the chart page →

581
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
stdlib@go1.13.10
1.25.10

Open the chart page →

7,520
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
stdlib@go1.23.6
1.25.10

Open the chart page →

903
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.10

Open the chart page →

8,060
postgresqleks-storageclass0.1.01 of 1See more

postgresql eks-storageclass 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.10

Open the chart page →

1,686
elastic-agentelasticVerified publisher9.5.41 of 2See more

elastic-agent elastic 9.5.4

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
stdlib@go1.24.4
1.25.10

Open the chart page →

768
kube-state-metricselasticVerified publisher6.1.01 of 1See more

kube-state-metrics elastic 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
stdlib@go1.24.4
1.25.10

Open the chart page →

768
seafileeleksbai0.1.12 of 3See more

seafile eleksbai 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mariadb:10.692e50059ea0a
stdlib@go1.24.6
1.25.10
seafileltd/seafile-mc:9.0.106693911bcc40
stdlib@go1.19
1.25.10

Open the chart page →

88,064
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
stdlib@go1.23.12
1.25.10

Open the chart page →

3,146
elsaelsa0.1.01 of 4See more

elsa elsa 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/stakater/reloader:v1.4.4a571c5b32c0f
stdlib@go1.24.4
1.25.10

Open the chart page →

398
rabbitmqemberstackVerified publisher1.0.211 of 1See more

rabbitmq emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/rabbitmq:managementffd1b50c522a
stdlib@go1.22.2
1.25.10

Open the chart page →

1,060
emissary-ingressemissary-ingress4.1.01 of 1See more

emissary-ingress emissary-ingress 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
stdlib@go1.24.13
1.25.10

Open the chart page →

968
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
stdlib@go1.19.5
1.25.10

Open the chart page →

2,838
parrot-mirroremmas-chartsVerified publisher1.0.01 of 1See more

parrot-mirror emmas-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
stdlib@go1.21.0
1.25.10

Open the chart page →

2,251
cost-reportempathyco0.7.81 of 1See more

cost-report empathyco 0.7.8

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
empathyco/cost-report:0.0.124f1e26eaacbf
stdlib@go1.15.15
1.25.10

Open the chart page →

1,168
deadman-switchempathyco0.0.21 of 1See more

deadman-switch empathyco 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
stdlib@go1.16.3
1.25.10

Open the chart page →

1,259
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.25.10

Open the chart page →

10,623
yace-exporterempathyco0.1.01 of 1See more

yace-exporter empathyco 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
stdlib@go1.17.3
1.25.10

Open the chart page →

1,642
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
stdlib@go1.19.10
1.25.10

Open the chart page →

1,329
kube-ecp-stackemqx-operator2.5.111 of 16See more

kube-ecp-stack emqx-operator 2.5.1

11 of the 16 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
stdlib@go1.23.3
1.25.10
emqx/ecp-main:2.5.1fa876f71e5d6
stdlib@go1.22.0
1.25.10
emqxecp/otelcol:2.5.04c31d9bec846
stdlib@go1.22.12
1.25.10
library/telegraf:1.27507a3eecf809
stdlib@go1.20.7
1.25.10
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
stdlib@go1.23.2
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
stdlib@go1.23.2
1.25.10
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
stdlib@go1.23.2
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
stdlib@go1.23.2
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
stdlib@go1.23.2
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.1e2dc5623bcdd
stdlib@go1.23.2
1.25.10
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
stdlib@go1.23.1
1.25.10

Open the chart page →

23,974
cnpg-monitoringenixVerified publisher0.3.01 of 1See more

cnpg-monitoring enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.10

Open the chart page →

824

Container images carrying it

4,529 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/telegraf:1.20.428e98eece020
stdlib@go1.17.3
1.25.10
1
library/telegraf:1.27507a3eecf809
stdlib@go1.20.7
1.25.10
1
library/telegraf:1.19.0-alpine794079a7f241
stdlib@go1.16.5
1.25.10
1
library/telegraf:1.19-alpineaddb86c0c520
stdlib@go1.16.6
1.25.10
1
library/traefik:v2.11.00a5157f742d2
stdlib@go1.22.0
1.25.10
1
library/traefik:3.3.5104204dadedf
stdlib@go1.23.7
1.25.10
1
library/traefik:v2.10.11489caffaedb
stdlib@go1.20.3
1.25.10
1
library/traefik:2.10.61957e3314f43
stdlib@go1.21.4
1.25.10
1
library/traefik:2.5.62f603f8d3abe
stdlib@go1.17.5
1.25.10
1
library/traefik:v3.6.1334d5089d0b41
stdlib@go1.25.8
1.25.10
1
library/traefik:v1.7.345d47b7bb2546
stdlib@go1.16.12
1.25.10
1
library/traefik:2.5.47d0228d19042
stdlib@go1.17.3
1.25.10
1
library/traefik:2.4.8eda951fd29a8
stdlib@go1.16.2
1.25.10
1
library/traefik:2.2.8f5af5a5ce17f
stdlib@go1.14.6
1.25.10
1
library/vault:1.13.3f98ac9dd97b0
stdlib@go1.20.4
1.25.10
1
library/zookeeper:3.9.5cab8944a33a1
stdlib@go1.18.1
1.25.10
1
library/zookeeper:3.9.4dfa9ba46d14b
stdlib@go1.18.1
1.25.10
1
librenms/librenms:24.11.00920bc9117a8
stdlib@go1.21.5
1.25.10
1
librenms/librenms:22.4.14f1f3d667cc7
stdlib@go1.16.12
1.25.10
1
librenms/librenms:26.8.28194a4a9ff49
stdlib@go1.24.6
1.25.10
1
lifailon/openrouter-bot:latestea37e4b6b952
stdlib@go1.25.0
1.25.10
1
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
stdlib@go1.22.1
1.25.10
1
linuxserver/calibre-web:0.6.24241009026e6f
stdlib@go1.17.8
1.25.10
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
stdlib@go1.16.7
1.25.10
1
linuxserver/cloud9:latest45c5fe102ff3
stdlib@go1.17.11
1.25.10
1
linuxserver/smokeping:2.9.02f4488c9afcd
stdlib@go1.24.12
1.25.10
1
linuxserver/smokeping:2.8.2b7f906899cd3
stdlib@go1.22.5
1.25.10
1
lishimeng/hufu:v1.2.13d5752dac834
stdlib@go1.20.7
1.25.10
1
lishimeng/owl-console:v0.11.2c79a67657baf
stdlib@go1.21.3
1.25.10
1
lishimeng/owl-messager:v0.11.23d00485e64dc
stdlib@go1.21.3
1.25.10
1
lishimeng/passport:v0.2.163e7d05ded625
stdlib@go1.20.7
1.25.10
1
lishimeng/passport-profile:v0.2.160970dfe5dc8f
stdlib@go1.20.7
1.25.10
1
lishimeng/tabby:v1.0.48145c3dc83c8
stdlib@go1.20.6
1.25.10
1
lishimeng/tree:v0.2.89b2f8be6c7d3
stdlib@go1.20.6
1.25.10
1
lishimeng/zoo:v0.4.0e0b8d2d8ca28
stdlib@go1.20.8
1.25.10
1
listmonk/listmonk:v6.0.0bf3903d54a46
stdlib@go1.24.1
1.25.10
1
litestream/litestream:0.3c5a1e1b01916
stdlib@go1.21.3
1.25.10
1
livekit/ingress:v1.2.21ab01641b366
stdlib@go1.20.7
1.25.10
1
livekit/livekit-recorder:v0.3.13ecf1409c75e0
stdlib@go1.16.2
1.25.10
1
livekit/livekit-server:v1.9.03602a85840d5
stdlib@go1.24.3
1.25.10
1
livekit/livekit-server:v1.0.08391fd1b834f
stdlib@go1.17.10
1.25.10
1
lmierzwa/karma:v0.503751e5eed656
stdlib@go1.13.4
1.25.10
1
lmierzwa/karma:v0.70d417abe7ddb5
stdlib@go1.15.2
1.25.10
1
localstack/localstack:3.19d278167f2b7
stdlib@go1.18.10
1.25.10
1
loeken/home-assistant:2026.5.14ce6abc553b3
stdlib@go1.23.3
1.25.10
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
stdlib@go1.16.6
1.25.10
1
loftsh/jspolicy:0.2.225deb9bd2683
stdlib@go1.17.13
1.25.10
1
loftsh/virtual-cluster:0.0.28023b13bf5898
stdlib@go1.15.11
1.25.10
1
logiqai/flash:v3.10.265b996bc7bdc
stdlib@go1.21.13
1.25.10
1
logiqai/flash-discovery:v2.0.3f5b551bca98e
stdlib@go1.18.9
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.