StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,912
of 17,797 indexed, latest versions
Container images
4,506
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 3,912 of 17,797 indexed charts deploy, on 4,506 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,506
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

3,912 by stars
ChartLatestAffected imagesRadar Score
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
stdlib@go1.25.3
1.25.10

Open the chart page →

7,266
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
stdlib@go1.23.11
1.25.10

Open the chart page →

5,138
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
stdlib@go1.25.3
1.25.10

Open the chart page →

7,266
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
stdlib@go1.21.6
1.25.10

Open the chart page →

2,926
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
stdlib@go1.21.8
1.25.10

Open the chart page →

1,630
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
stdlib@go1.13.10
1.25.10

Open the chart page →

7,840
btrfs-nfs-csibtrfs-nfs-csi0.4.06 of 7See more

btrfs-nfs-csi btrfs-nfs-csi 0.4.0

6 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
stdlib@go1.25.7
1.25.10

Open the chart page →

3,226
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
stdlib@go1.21.4
1.25.10

Open the chart page →

2,049
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
stdlib@go1.14.7
1.25.10

Open the chart page →

2,670
buildkite-agent-metricsbuildkite-agent-metrics0.1.01 of 1See more

buildkite-agent-metrics buildkite-agent-metrics 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
stdlib@go1.25.1
1.25.10

Open the chart page →

1,541
buildkit-fleetbuildkit-fleetVerified publisher0.1.21 of 1See more

buildkit-fleet buildkit-fleet 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
moby/buildkit:v0.33.0-rootless80b15f0735e8
stdlib@go1.25.7
1.25.10

Open the chart page →

903
static-httpserverbyjgVerified publisher0.2.01 of 1See more

static-httpserver byjg 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
byjg/static-httpserver:latest562cc8b9c40b
stdlib@go1.26.1
1.25.10

Open the chart page →

677
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
stdlib@go1.24.2
1.25.10

Open the chart page →

1,490
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
stdlib@go1.24.2
1.25.10

Open the chart page →

1,490
pgcagriekinVerified publisher2.1.01 of 2See more

pg cagriekin 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.10

Open the chart page →

2,407
pgvectorcagriekinVerified publisher2.1.02 of 3See more

pgvector cagriekin 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.10
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
stdlib@go1.24.6
1.25.10

Open the chart page →

4,172
camel-dashboard-operatorcamel-dashboardVerified publisher0.1.01 of 1See more

camel-dashboard-operator camel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
stdlib@go1.25.9
1.25.10

Open the chart page →

520
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
stdlib@go1.22.2
1.25.10

Open the chart page →

913
capsulecapsuleOfficialVerified publisher0.14.61 of 2See more

capsule capsule 0.14.6

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.25.10

Open the chart page →

1,238
capsule-proxycapsule-proxyOfficialVerified publisher0.14.11 of 2See more

capsule-proxy capsule-proxy 0.14.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.25.10

Open the chart page →

1,226
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
stdlib@go1.16.2
1.25.10

Open the chart page →

3,511
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
stdlib@go1.23.0
1.25.10

Open the chart page →

1,810
cert-estuarycert-estuaryVerified publisher0.2.11 of 1See more

cert-estuary cert-estuary 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/hsn723/cert-estuary:0.2.00c4b6132b0ad
stdlib@go1.26.2
1.25.10

Open the chart page →

268
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
stdlib@go1.22.4
1.25.10
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
stdlib@go1.21.12
1.25.10
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
stdlib@go1.21.12
1.25.10
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
stdlib@go1.21.12
1.25.10
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
stdlib@go1.21.12
1.25.10
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
stdlib@go1.21.12
1.25.10
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
stdlib@go1.21.12
1.25.10

Open the chart page →

12,611
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
stdlib@go1.24.4
1.25.10

Open the chart page →

1,074
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
stdlib@go1.22.0
1.25.10

Open the chart page →

1,031
cert-vaultcert-vaultOfficialVerified publisher2.12.04 of 7See more

cert-vault cert-vault 2.12.0

4 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
stdlib@go1.23.7
1.25.10
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
stdlib@go1.23.7
1.25.10
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.25.10
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.10

Open the chart page →

16,124
chatclichatcliVerified publisher1.205.01 of 2See more

chatcli chatcli 1.205.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
stdlib@go1.23.10
1.25.10

Open the chart page →

1,028
passbolt-hachristianhuthVerified publisher6.0.13 of 4See more

passbolt-ha christianhuth 6.0.1

3 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.10
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
stdlib@go1.24.6
1.25.10
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.25.10

Open the chart page →

10,964
typo3christianhuthVerified publisher7.7.11 of 2See more

typo3 christianhuth 7.7.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.10

Open the chart page →

8,651
challengerchronicleVerified publisher0.1.11 of 1See more

challenger chronicle 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
stdlib@go1.22.12
1.25.10

Open the chart page →

978
spectrechronicleVerified publisher0.3.81 of 1See more

spectre chronicle 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
stdlib@go1.25.5
1.25.10

Open the chart page →

1,543
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
stdlib@go1.22.1
1.25.10

Open the chart page →

643
clamav-restclamav-rest-apiVerified publisher0.1.01 of 1See more

clamav-rest clamav-rest-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ajilaag/clamav-rest:latestad689c7b75b1
stdlib@go1.26.0
1.25.10

Open the chart page →

515
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
stdlib@go1.24.6
1.25.10

Open the chart page →

2,197
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
stdlib@go1.20.1
1.25.10
cloudbees/sidecar-injector:2.3.38f102ef0383a
stdlib@go1.20.1
1.25.10

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.25.10
prom/prometheus:v2.21.0d43417c260e5
stdlib@go1.15.2
1.25.10

Open the chart page →

4,265
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
stdlib@go1.17.6
1.25.10
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
stdlib@go1.18.6
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
stdlib@go1.17.6
1.25.10

Open the chart page →

7,597
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.25.10

Open the chart page →

2,714
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.25.10

Open the chart page →

1,579
grafanacloudposse0.2.61 of 1See more

grafana cloudposse 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
stdlib@go1.25.7
1.25.10

Open the chart page →

728
openstack-manila-csicloud-provider-openstack2.36.35 of 5See more

openstack-manila-csi cloud-provider-openstack 2.36.3

5 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
stdlib@go1.26.2
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
stdlib@go1.24.6
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
stdlib@go1.24.2
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
stdlib@go1.24.6
1.25.10

Open the chart page →

3,778
cloudttycloudtty0.8.92 of 2See more

cloudtty cloudtty 0.8.9

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell:v0.8.900984ba0f0eb
stdlib@go1.24.9
1.25.10
ghcr.io/cloudtty/cloudshell-operator:v0.8.9e43ad91f0684
stdlib@go1.21.11
1.25.10

Open the chart page →

3,994
cluster-api-visualizercluster-api-visualizer1.5.01 of 1See more

cluster-api-visualizer cluster-api-visualizer 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
stdlib@go1.24.11
1.25.10

Open the chart page →

558
clustereye-stackclustereyeVerified publisher0.1.11 of 5See more

clustereye-stack clustereye 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10

Open the chart page →

4,913
clusternet-hubclusternet1.0.01 of 1See more

clusternet-hub clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-hub:v1.0.059f75504c5d4
stdlib@go1.23.8
1.25.10

Open the chart page →

1,403
clusternet-schedulerclusternet1.0.01 of 1See more

clusternet-scheduler clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-scheduler:v1.0.0a6ae5aff81ce
stdlib@go1.23.8
1.25.10

Open the chart page →

1,403
cluster-setupcluster-setup1.5.07 of 8See more

cluster-setup cluster-setup 1.5.0

7 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
stdlib@go1.24.3
1.25.10
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.10
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
stdlib@go1.22.7
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.17.2ec56edb1161d
stdlib@go1.23.8
1.25.10
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
stdlib@go1.23.8
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.17.2e18989b4f912
stdlib@go1.23.8
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
stdlib@go1.23.8
1.25.10

Open the chart page →

10,121
cockroachdb-chartcockroachdbv226.3.11 of 1See more

cockroachdb-chart cockroachdbv2 26.3.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
stdlib@go1.23.12
1.25.10

Open the chart page →

703
istio-allcode4devsVerified publisher1.2.04 of 6See more

istio-all code4devs 1.2.0

4 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
stdlib@go1.23.2
1.25.10
istio/pilot:1.24.2-distroless137e44e3d1d2
stdlib@go1.23.2
1.25.10
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
stdlib@go1.22.5
1.25.10
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
stdlib@go1.22.6
1.25.10

Open the chart page →

4,812

Container images carrying it

4,506 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
stdlib@go1.17.10
1.25.10
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
stdlib@go1.25.3
1.25.10
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
stdlib@go1.22.5
1.25.10
1
ofekmeister/csi-gcs:v0.9.030d70fa9211b
stdlib@go1.18.2
1.25.10
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
stdlib@go1.24.5
1.25.10
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
stdlib@go1.21.10
1.25.10
1
okgolove/asprom:1.10.1974d2e5eb150
stdlib@go1.14.11
1.25.10
1
okteto/civo-webhook:0.5.357cd51176538
stdlib@go1.21.3
1.25.10
1
oliver006/redis_exporter:v1.11.104d958d209ab
stdlib@go1.15
1.25.10
1
oliver006/redis_exporter:v1.67.0120f7ec77293
stdlib@go1.23.4
1.25.10
1
oliver006/redis_exporter:v1.14.0d55e056987af
stdlib@go1.15.6
1.25.10
1
oliver006/redis_exporter:v1.66.0d98e6db8094f
stdlib@go1.23.2
1.25.10
1
oliver006/redis_exporter:v1.82.0-alpineda9e89ee4e75
stdlib@go1.26.1
1.25.10
1
olliai/exposecontroller:1.0.5a470d96525e4
stdlib@go1.16.3
1.25.10
1
olliai/k8s-replicator:1.3.05716f2a8bd4c
stdlib@go1.17.2
1.25.10
1
ondrejsika/counter:latestd95eaeee2172
stdlib@go1.26.2
1.25.10
1
opea/codegen-ui:1.02bee4eb66f3e
stdlib@go1.20.7
1.25.10
1
opea/codetrans-ui:1.03ef121f34610
stdlib@go1.20.12
1.25.10
1
opea/docsum-ui:1.07f854e9bffaf
stdlib@go1.20.12
1.25.10
1
opea/gmcmanager:1.0514af17c495c
stdlib@go1.21.13
1.25.10
1
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
stdlib@go1.19.8
no fix listed
1.25.10
1
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
stdlib@go1.16.5
1.25.10
1
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
stdlib@go1.19.8
1.25.10
1
opencsghq/csgbot:v0.6.9-ee7d0271e26521
stdlib@go1.24.4
1.25.10
1
opencsghq/csghub-portal:v2.5.0-ee1cb36b49151e
stdlib@go1.23.3
1.25.10
1
opencsghq/csghub-server:v2.5.0-ee587046575c2c
stdlib@go1.26.0
1.25.10
1
opencsghq/csghub-xnet:v2.5.0-ee86ea22f495c7
stdlib@go1.24.10
1.25.10
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
stdlib@go1.22.7
1.25.10
1
opencsghq/lws:v0.6.1de15437db41b
stdlib@go1.24.0
1.25.10
1
opendatacube/explorer:latest120457ffcd69
stdlib@go1.22.2
1.25.10
1
openebs/lvm-driver:1.10.141f73aba7f31
stdlib@go1.24.7
1.25.10
1
openebs/provisioner-nfs:0.11.04f41dd782761
stdlib@go1.19.13
1.25.10
1
openebs/zfs-driver:2.11.116f1a74bb249
stdlib@go1.26.2
1.25.10
1
openenergyprojects/modbus_exporter:20230617_a14455158990f24fb25
stdlib@go1.20.5
1.25.10
1
openfga/openfga:v1.9.25e94966c11df
stdlib@go1.24.5
1.25.10
1
openkruise/kruise-game-manager:v1.1.0d3c6d69d2c39
stdlib@go1.23.4
1.25.10
1
openkruise/kruise-manager:v1.8.30482722b4e56
stdlib@go1.22.11
1.25.10
1
openkruise/kruise-manager:v1.9.1f81ae78a36a4
stdlib@go1.23.9
1.25.10
1
openkruise/kruise-rollout:v0.6.2a75e6739ea7d
stdlib@go1.19.13
1.25.10
1
openkruise/kruise-state-metrics:v0.2.0a8108f771287
stdlib@go1.18.10
1.25.10
1
openmined/syft-frontend:0.9.5d11524a3854a
stdlib@go1.20.5
1.25.10
1
openmined/syft-seaweedfs:0.9.53a4144c0bb82
stdlib@go1.22.1
1.25.10
1
opennms/sentinel:36.0.288869082a14f
stdlib@go1.22.2
1.25.10
1
openpolicyagent/gatekeeper:v3.17.1b7b4d7cfdd52
stdlib@go1.22.7
1.25.10
1
openpolicyagent/gatekeeper-crds:v3.17.177bc9bf3d163
stdlib@go1.22.5
1.25.10
1
openpolicyagent/kube-mgmt:11.0.123a8b1bacbcd8
stdlib@go1.25.0
1.25.10
1
openpolicyagent/opa:0.53.16a58dea59933
stdlib@go1.20.4
1.25.10
1
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.25.10
1
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.25.10
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
stdlib@go1.20.6
1.25.10
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.