StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,937
of 17,792 indexed, latest versions
Container images
4,529
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 3,937 of 17,792 indexed charts deploy, on 4,529 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,529
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

3,937 by stars
ChartLatestAffected imagesRadar Score
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
stdlib@go1.22.3
1.25.10

Open the chart page →

2,486
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
stdlib@go1.18.10
1.25.10
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
stdlib@go1.18.10
1.25.10

Open the chart page →

4,816
traceetrivy-operator0.24.11 of 1See more

tracee trivy-operator 0.24.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
aquasec/tracee:0.24.1cfbbfee972e6
stdlib@go1.24.9
1.25.10

Open the chart page →

1,083
trivy-webhook-aws-security-hubtrivy-webhook-aws-security-hubVerified publisher0.1.201 of 1See more

trivy-webhook-aws-security-hub trivy-webhook-aws-security-hub 0.1.20

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/csepulveda/trivy-webhook-aws-security-hub:v0.1.206836b779b060
stdlib@go1.26.2
1.25.10

Open the chart page →

617
trivy-webhook-elasticsearchtrivy-webhook-elasticsearch0.1.41 of 1See more

trivy-webhook-elasticsearch trivy-webhook-elasticsearch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/lbi22/trivy-webhook-elasticsearch:v0.1.4b51b824e4f19
stdlib@go1.22.8
1.25.10

Open the chart page →

755
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
stdlib@go1.13.10
1.25.10

Open the chart page →

7,519
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
stdlib@go1.14.6
1.25.10

Open the chart page →

3,110
clickhouse-operatortruefoundryVerified publisher0.1.12 of 3See more

clickhouse-operator truefoundry 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.34baec90b20cd
stdlib@go1.20.14
1.25.10
altinity/metrics-exporter:0.23.32912a6c15b44
stdlib@go1.20.14
1.25.10

Open the chart page →

1,430
tfy-agenttruefoundryVerified publisher0.2.1041 of 5See more

tfy-agent truefoundry 0.2.104

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v2.4.19440a40b3947
stdlib@go1.26.2
1.25.10

Open the chart page →

688
tfy-cloudflaredtruefoundryVerified publisher0.6.01 of 2See more

tfy-cloudflared truefoundry 0.6.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
stdlib@go1.20
1.25.10

Open the chart page →

2,022
tfy-distributortruefoundryVerified publisher0.0.13 of 4See more

tfy-distributor truefoundry 0.0.1

3 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.25.10
natsio/nats-server-config-reloader:0.14.08c28b75bc416
stdlib@go1.20.5
1.25.10
natsio/prometheus-nats-exporter:0.13.02adf791d9f9f
stdlib@go1.21.3
1.25.10

Open the chart page →

17,403
tfy-inferentia-operatortruefoundryVerified publisher0.2.83 of 3See more

tfy-inferentia-operator truefoundry 0.2.8

3 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/kubernetes/kube-scheduler:v1.29.14-eks-1-29-lateste7e1db003e6a
stdlib@go1.22.12
1.25.10
public.ecr.aws/neuron/neuron-device-plugin:2.23.30.075a6d5ce3bd3
stdlib@go1.20.4
1.25.10
public.ecr.aws/neuron/neuron-scheduler:2.23.30.04cd274463e6b
stdlib@go1.20.4
1.25.10

Open the chart page →

2,918
tfy-karpentertruefoundryVerified publisher0.5.112 of 3See more

tfy-karpenter truefoundry 0.5.11

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:1.9.030a506c64fbb
stdlib@go1.25.7
1.25.10
public.ecr.aws/truefoundrycloud/eks/eks-node-monitoring-agent:v1.5.1-eksbuild.1988c8e1a273a
stdlib@go1.25.6
1.25.10

Open the chart page →

654
tfy-kservetruefoundryVerified publisher0.1.11 of 2See more

tfy-kserve truefoundry 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
kserve/kserve-controller:v0.10.022ff858b57c1
stdlib@go1.18.10
1.25.10

Open the chart page →

1,178
tfy-llm-gateway-infratruefoundryVerified publisher0.2.102 of 3See more

tfy-llm-gateway-infra truefoundry 0.2.10

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.774315beb57db
stdlib@go1.21.13
1.25.10
altinity/metrics-exporter:0.23.7a4d7ff0c727e
stdlib@go1.21.13
1.25.10

Open the chart page →

1,206
tfy-lokitruefoundryVerified publisher0.1.62 of 2See more

tfy-loki truefoundry 0.1.6

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/loki:2.9.1035b02acc6765
stdlib@go1.22.5
1.25.10
grafana/promtail:2.9.1063a2e57a5b14
stdlib@go1.22.5
1.25.10

Open the chart page →

2,827
truefoundry-monitoringtruefoundryVerified publisher0.1.64 of 8See more

truefoundry-monitoring truefoundry 0.1.6

4 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
stdlib@go1.25.3
1.25.10
ghcr.io/jkroepke/kube-webhook-certgen:1.7.47a62bba56a7c
stdlib@go1.25.5
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.88.0b4f51de53357
stdlib@go1.25.5
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.10

Open the chart page →

4,549
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10

Open the chart page →

5,616
aws-eks-asg-rolling-update-handlertwin1.5.01 of 1See more

aws-eks-asg-rolling-update-handler twin 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
stdlib@go1.19.3
1.25.10

Open the chart page →

1,119
lighthousetwin1.0.21 of 1See more

lighthouse twin 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/twin/lighthouse:v0.0.45aeda2ea2ba2
stdlib@go1.22.3
1.25.10

Open the chart page →

544
twitter-apptwitter-helm0.1.124 of 8See more

twitter-app twitter-helm 0.1.12

4 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
stdlib@go1.18.3
1.25.10
stakkato95/twitter-service-graphql:0.1.13cbe857234f2
stdlib@go1.18.3
1.25.10
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
stdlib@go1.18.3
1.25.10
stakkato95/twitter-service-users:0.1.1456049efee9a
stdlib@go1.18.3
1.25.10

Open the chart page →

6,147
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
stdlib@go1.20.4
1.25.10

Open the chart page →

1,569
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.25.10

Open the chart page →

4,135
tyk-bootstraptyk-helm5.3.03 of 3See more

tyk-bootstrap tyk-helm 5.3.0

3 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
stdlib@go1.22.7
1.25.10
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
stdlib@go1.22.7
1.25.10
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.25.10

Open the chart page →

1,374
tyk-control-planetyk-helm5.3.03 of 7See more

tyk-control-plane tyk-helm 5.3.0

3 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
stdlib@go1.22.7
1.25.10
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
stdlib@go1.22.7
1.25.10
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.25.10

Open the chart page →

2,992
tyk-stacktyk-helm5.3.03 of 7See more

tyk-stack tyk-helm 5.3.0

3 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
stdlib@go1.22.7
1.25.10
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
stdlib@go1.22.7
1.25.10
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.25.10

Open the chart page →

2,936
typhoontyphoonVerified publisher0.2.32 of 2See more

typhoon typhoon 0.2.3

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
stdlib@go1.24.0
1.25.10
ghcr.io/zeiss/typhoon/typhoon-webhook:0.2.378f9b82050bc
stdlib@go1.24.0
1.25.10

Open the chart page →

1,686
deep-learning-toolsuninettsigma29.1.21 of 3See more

deep-learning-tools uninettsigma2 9.1.2

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
sigma2as/goidc-proxy:next656ac798963a
stdlib@go1.25.7
1.25.10

Open the chart page →

1,570
desktop-vncuninettsigma22.0.21 of 2See more

desktop-vnc uninettsigma2 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
sigma2as/goidc-proxy:next656ac798963a
stdlib@go1.25.7
1.25.10

Open the chart page →

476
jupyteruninettsigma21.1.41 of 2See more

jupyter uninettsigma2 1.1.4

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
sigma2as/goidc-proxy:next656ac798963a
stdlib@go1.25.7
1.25.10

Open the chart page →

476
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
stdlib@go1.22.9
1.25.10

Open the chart page →

8,674
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
stdlib@go1.19.2
1.25.10

Open the chart page →

4,967
rstudiouninettsigma21.3.61 of 3See more

rstudio uninettsigma2 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
sigma2as/goidc-proxy:next656ac798963a
stdlib@go1.25.7
1.25.10

Open the chart page →

847
sparkuninettsigma21.1.41 of 3See more

spark uninettsigma2 1.1.4

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
sigma2as/goidc-proxy:next656ac798963a
stdlib@go1.25.7
1.25.10

Open the chart page →

847
agent-sandbox-controllerunique-oci-agent-sandbox-controller1.0.11 of 2See more

agent-sandbox-controller unique-oci-agent-sandbox-controller 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/agent-sandbox/sandbox-router-go:v1.0.125b1a0939630
stdlib@go1.26.2
1.25.10

Open the chart page →

174
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
stdlib@go1.20.7
1.25.10

Open the chart page →

5,251
opencloudunxwaresVerified publisher0.2.33 of 13See more

opencloud unxwares 0.2.3

3 of the 13 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:alpined3e1620b530c
stdlib@go1.24.6
1.25.10
minio/minio:latest14cea493d9a3
stdlib@go1.24.6
1.25.10
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
stdlib@go1.24.2
1.25.10

Open the chart page →

45,540
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10

Open the chart page →

3,176
kiamuswitch6.1.21 of 1See more

kiam uswitch 6.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/uswitch/kiam:v4.0be3a5846922d
stdlib@go1.13.8
1.25.10

Open the chart page →

2,972
utho-app-operator-chartutho-operatorVerified publisher0.1.61 of 2See more

utho-app-operator-chart utho-operator 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
utho/utho-app-operator:0.1.46e8a690e8b7a
stdlib@go1.22.8
1.25.10

Open the chart page →

491
gohttpserverutkuozdemirVerified publisher0.2.01 of 1See more

gohttpserver utkuozdemir 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
codeskyblue/gohttpserver:latestcaa862590e34
stdlib@go1.16.3
1.25.10

Open the chart page →

1,898
transmission-exporterutkuozdemirVerified publisher1.1.01 of 1See more

transmission-exporter utkuozdemir 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
metalmatze/transmission-exporter:0.3.090d6acb6d47d
stdlib@go1.13
1.25.10

Open the chart page →

1,646
proxyv2flyVerified publisher0.0.61 of 1See more

proxy v2fly 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
v2fly/v2fly-core:latestd06727b221fe
stdlib@go1.24.2
1.25.10

Open the chart page →

1,434
vals-operatorvals-operatorVerified publisher0.8.11 of 1See more

vals-operator vals-operator 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
stdlib@go1.25.7
1.25.10

Open the chart page →

703
vault-raft-snapshot-agentvault-raft-snapshot-agentVerified publisher0.6.91 of 1See more

vault-raft-snapshot-agent vault-raft-snapshot-agent 0.6.9

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
stdlib@go1.23.10
1.25.10

Open the chart page →

1,121
vault-sync-operatorvault-sync-operatorVerified publisher0.1.11 of 1See more

vault-sync-operator vault-sync-operator 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/danieldonoghue/vault-sync-operator:v0.0.1-beta.38d7ec69a193c
stdlib@go1.25.9
1.25.10

Open the chart page →

269
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
stdlib@go1.23.12
1.25.10

Open the chart page →

3,758
openldap-havcnngrVerified publisher1.0.01 of 3See more

openldap-ha vcnngr 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.25.10

Open the chart page →

5,515
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10

Open the chart page →

4,777
velocityvelocity1.0.01 of 2See more

velocity velocity 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10

Open the chart page →

967

Container images carrying it

4,529 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
stdlib@go1.20.4
1.25.10
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
stdlib@go1.25.0
1.25.10
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
stdlib@go1.25.0
1.25.10
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
stdlib@go1.25.5
1.25.10
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
stdlib@go1.20.7
1.25.10
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
stdlib@go1.25.5
1.25.10
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.25.10
3
quay.io/devtron/nats-box:latest48cdd3054b20
stdlib@go1.19.2
1.25.10
3
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.25.10
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.25.10
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
stdlib@go1.21.5
1.25.10
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
stdlib@go1.18.10
1.25.10
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
stdlib@go1.14.9
1.25.10
3
quay.io/jcmoraisjr/haproxy-ingress:v0.16.16fd744191ef6
stdlib@go1.25.9
1.25.10
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.25.10
3
quay.io/metallb/controller:v0.13.101b33357b3595
stdlib@go1.19.5
1.25.10
3
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.25.10
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.25.10
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.25.10
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
stdlib@go1.15.8
1.25.10
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.25.10
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
stdlib@go1.16.7
1.25.10
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
stdlib@go1.25.9
1.25.10
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
stdlib@go1.22.3
1.25.10
3
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
stdlib@go1.25.8
1.25.10
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
stdlib@go1.16
1.25.10
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.25.10
3
quay.io/prometheus/prometheus:v2.55.0378f4e037035
stdlib@go1.23.2
1.25.10
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
stdlib@go1.16.2
1.25.10
3
quay.io/prometheus/prometheus:v3.10.07571a304e67f
stdlib@go1.26.0
1.25.10
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
stdlib@go1.17.3
1.25.10
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.10
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
stdlib@go1.23.1
1.25.10
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.25.10
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
stdlib@go1.15.15
1.25.10
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
stdlib@go1.16.8
1.25.10
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.10
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.25.10
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
stdlib@go1.22.2
1.25.10
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
stdlib@go1.24.1
1.25.10
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
stdlib@go1.22.5
1.25.10
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
stdlib@go1.24.6
1.25.10
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
stdlib@go1.26.2
1.25.10
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
stdlib@go1.20.3
1.25.10
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
stdlib@go1.22.5
1.25.10
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
stdlib@go1.24.2
1.25.10
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
stdlib@go1.21.5
1.25.10
3
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
stdlib@go1.23.1
1.25.10
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
stdlib@go1.20.3
1.25.10
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
stdlib@go1.23.1
1.25.10
3

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.