StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,939
of 17,787 indexed, latest versions
Container images
4,537
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 3,939 of 17,787 indexed charts deploy, on 4,537 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,537
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

3,939 by stars
ChartLatestAffected imagesRadar Score
kubeform-provider-azureappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-azure appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
stdlib@go1.20.5
1.25.10

Open the chart page →

2,716
kubeform-provider-gcpappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-gcp appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
stdlib@go1.19.9
1.25.10

Open the chart page →

2,743
kubestashappscodeVerified publisher2026.7.102 of 2See more

kubestash appscode 2026.7.10

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.10

Open the chart page →

1,091
kubestash-certifiedappscodeVerified publisher2026.7.102 of 2See more

kubestash-certified appscode 2026.7.10

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.10

Open the chart page →

1,091
kubestash-operatorappscodeVerified publisher0.29.02 of 2See more

kubestash-operator appscode 0.29.0

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.10

Open the chart page →

1,091
kubevaultappscodeVerified publisher2026.8.71 of 2See more

kubevault appscode 2026.8.7

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

789
kubevault-certifiedappscodeVerified publisher2026.2.271 of 1See more

kubevault-certified appscode 2026.2.27

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kubevault/vault-operator:v0.24.00087cb49616f
stdlib@go1.25.9
1.25.10

Open the chart page →

1,112
kubevault-webhook-serverappscodeVerified publisher0.25.01 of 2See more

kubevault-webhook-server appscode 0.25.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

789
kubevirt-infra-csi-driverappscodeVerified publisher0.1.02 of 6See more

kubevirt-infra-csi-driver appscode 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-csi-driver:latest7b31b21b3f1e
stdlib@go1.24.13
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
stdlib@go1.23.1
1.25.10

Open the chart page →

1,177
kubevirt-tenant-csi-driverappscodeVerified publisher0.1.02 of 4See more

kubevirt-tenant-csi-driver appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-csi-driver:latest7b31b21b3f1e
stdlib@go1.24.13
1.25.10
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.10

Open the chart page →

1,278
license-proxyserverappscodeVerified publisher2026.2.161 of 1See more

license-proxyserver appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.1.1e192ad567e0b
stdlib@go1.25.7
1.25.10

Open the chart page →

1,106
license-proxyserver-addon-managerappscodeVerified publisher2024.2.251 of 1See more

license-proxyserver-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
stdlib@go1.22.1
1.25.10

Open the chart page →

1,384
license-proxyserver-managerappscodeVerified publisher2026.2.161 of 1See more

license-proxyserver-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.1.1e192ad567e0b
stdlib@go1.25.7
1.25.10

Open the chart page →

1,106
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
stdlib@go1.22.0
1.25.10

Open the chart page →

2,404
managed-serviceaccount-managerappscodeVerified publisher2026.2.161 of 1See more

managed-serviceaccount-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
stdlib@go1.25.8
1.25.10

Open the chart page →

912
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10

Open the chart page →

2,605
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
stdlib@go1.19.4
1.25.10

Open the chart page →

4,043
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
stdlib@go1.21.8
1.25.10

Open the chart page →

2,568
multicluster-ingress-readerappscodeVerified publisher2024.7.101 of 1See more

multicluster-ingress-reader appscode 2024.7.10

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

302
offline-license-serverappscodeVerified publisher2026.9.111 of 2See more

offline-license-server appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
stdlib@go1.25.5
1.25.10

Open the chart page →

1,682
opentelemetry-kube-stackappscodeVerified publisher0.14.123 of 3See more

opentelemetry-kube-stack appscode 0.14.12

3 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
stdlib@go1.24.6
1.25.10
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.144.079b81912f1fb
stdlib@go1.25.6
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
stdlib@go1.25.1
1.25.10

Open the chart page →

1,872
panopticonappscodeVerified publisher2026.6.221 of 2See more

panopticon appscode 2026.6.22

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

468
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
stdlib@go1.25.4
1.25.10

Open the chart page →

37,184
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
stdlib@go1.25.4
1.25.10

Open the chart page →

771
regcacheappscodeVerified publisher2026.9.111 of 1See more

regcache appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
stdlib@go1.25.9
1.25.10

Open the chart page →

634
secrets-store-csi-driver-provider-virtual-secretsappscodeVerified publisher2026.8.141 of 1See more

secrets-store-csi-driver-provider-virtual-secrets appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/secrets-store-csi-driver-provider-virtual-secrets:v0.2.07afb394f9f97
stdlib@go1.24.1
1.25.10

Open the chart page →

547
service-backendappscodeVerified publisher2026.9.111 of 1See more

service-backend appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
stdlib@go1.25.5
1.25.10

Open the chart page →

1,330
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109fa56a9251de6
stdlib@go1.19
1.25.10

Open the chart page →

2,088
service-presetsappscodeVerified publisher2024.2.111 of 1See more

service-presets appscode 2024.2.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.25.10

Open the chart page →

823
service-providerappscodeVerified publisher2026.9.112 of 2See more

service-provider appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
stdlib@go1.23.3
1.25.10
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
stdlib@go1.25.5
1.25.10

Open the chart page →

2,224
stash-communityappscodeVerified publisher0.42.04 of 4See more

stash-community appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.25.10
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
stdlib@go1.24.9
1.25.10
ghcr.io/stashed/stash:v0.42.03a98245a7667
stdlib@go1.25.3
1.25.10
ghcr.io/stashed/stash-crd-installer:v0.42.076f0a650e44b
stdlib@go1.25.3
1.25.10

Open the chart page →

3,661
stash-opscenterappscodeVerified publisher2025.10.171 of 1See more

stash-opscenter appscode 2025.10.17

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.10

Open the chart page →

672
stash-ui-serverappscodeVerified publisher0.23.01 of 1See more

stash-ui-server appscode 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.10

Open the chart page →

672
statefulsetappscodeVerified publisher0.0.12 of 3See more

statefulset appscode 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
stdlib@go1.15.14
1.25.10
ghcr.io/appscode/kubectl-nonroot:v1.248ee5bdd68977
stdlib@go1.20.7
1.25.10

Open the chart page →

2,732
taskqueueappscodeVerified publisher2026.2.161 of 1See more

taskqueue appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
stdlib@go1.25.5
1.25.10

Open the chart page →

1,076
thanos-operatorappscodeVerified publisher2026.6.21 of 1See more

thanos-operator appscode 2026.6.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/thanos-operator:v2026.4.24e05a3e701291
stdlib@go1.26.2
1.25.10

Open the chart page →

371
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
stdlib@go1.25.5
1.25.10

Open the chart page →

1,221
voyagerappscodeVerified publisher2026.3.231 of 1See more

voyager appscode 2026.3.23

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/voyager:v17.5.04964ceaf9d35
stdlib@go1.25.8
1.25.10

Open the chart page →

713
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
stdlib@go1.21.1
1.25.10

Open the chart page →

4,899
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
stdlib@go1.22.2
1.25.10

Open the chart page →

1,204
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.24.6
1.25.10

Open the chart page →

8,904
appwriteappwrite-helmVerified publisher1.3.24 of 8See more

appwrite appwrite-helm 1.3.2

4 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
stdlib@go1.25.7
1.25.10
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.25.10
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.25.10
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.25.10

Open the chart page →

9,847
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
stdlib@go1.16.4
1.25.10

Open the chart page →

5,203
arcadearcadeVerified publisher1.10.11 of 10See more

arcade arcade 1.10.1

1 of the 10 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10

Open the chart page →

991
argocd-bitbucket-proxyargocd-bitbucket-proxy1.1.11 of 1See more

argocd-bitbucket-proxy argocd-bitbucket-proxy 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/salemgolemugoo/argocd-bitbucket-proxy:latesta72df069095b
stdlib@go1.26.1
1.25.10

Open the chart page →

189
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
stdlib@go1.23.4
1.25.10
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.10
quay.io/argoproj/argocd:v2.14.115fc69e31c755
stdlib@go1.22.2
1.25.10

Open the chart page →

7,338
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
stdlib@go1.24.6
1.25.10
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
stdlib@go1.24.6
1.25.10

Open the chart page →

1,826
argonix-apiargonix0.2.32 of 4See more

argonix-api argonix 0.2.3

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
stdlib@go1.22.7
1.25.10
ghcr.io/argonix-io/argonix-api-frontend:1.0.0d041bbf2814f
stdlib@go1.23.12
1.25.10

Open the chart page →

4,819
argo-zombiesargo-zombies0.1.521 of 1See more

argo-zombies argo-zombies 0.1.52

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
stdlib@go1.26.1
1.25.10

Open the chart page →

254
arlas-aiasarlas-stackVerified publisher28.8.06 of 22See more

arlas-aias arlas-stack 28.8.0

6 of the 22 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
stdlib@go1.23.9
1.25.10
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.25.10
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
stdlib@go1.22.11
1.25.10
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
stdlib@go1.24.2
1.25.10
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
stdlib@go1.23.8
1.25.10
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.25.10

Open the chart page →

40,411

Container images carrying it

4,537 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
alpine/k8s:1.32.12048f8d9c8cc7
stdlib@go1.25.7
1.25.10
2
alpine/kubectl:1.35.49ccd82364762
stdlib@go1.25.9
1.25.10
2
alpine/kubectl:1.35.2ec8f734b0a10
stdlib@go1.25.7
1.25.10
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
stdlib@go1.19.10
1.25.10
2
altinity/metrics-exporter:0.21.2df3d57215356
stdlib@go1.19.10
1.25.10
2
apache/superset:dockerizeafe59523a6c8
stdlib@go1.20.4
1.25.10
2
apecloud/apecloud-mcp:0.1.094041b080510
stdlib@go1.23.7
1.25.10
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
stdlib@go1.21.7
1.25.10
2
assistiot/fl_repository_db:latestad8f72108636
stdlib@go1.17.10
1.25.10
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
stdlib@go1.18.9
1.25.10
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
stdlib@go1.24.6
1.25.10
2
bitnamilegacy/etcd:latest99b408c15272
stdlib@go1.23.10
1.25.10
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
stdlib@go1.19.6
1.25.10
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
stdlib@go1.19.8
1.25.10
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
stdlib@go1.23.7
1.25.10
2
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
stdlib@go1.15.1
1.25.10
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.25.10
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.25.10
2
bitnamilegacy/redis:latest5927ff3702df
stdlib@go1.24.5
1.25.10
2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
stdlib@go1.24.6
1.25.10
2
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.25.10
2
bitnamisecure/git72ae5bd9715f
stdlib@go1.24.6
1.25.10
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
stdlib@go1.17.13
1.25.10
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
stdlib@go1.19.9
1.25.10
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.10
2
cesanta/docker_auth:1.6.04d16885f3d4c
stdlib@go1.13.7
1.25.10
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
stdlib@go1.20.14
1.25.10
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
stdlib@go1.14.5
1.25.10
2
clickhouse/clickhouse-server:24.2ed9640bfff07
stdlib@go1.19.10
1.25.10
2
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.25.10
2
coredns/coredns:1.13.19b9128672209
stdlib@go1.25.2
1.25.10
2
crate/crate_adapter:latestb8d89fa5d19b
stdlib@go1.16.3
1.25.10
2
cs3org/revad:v1.19.03b57a34a7dfd
stdlib@go1.17.3
1.25.10
2
cs3org/revad:v1.24.0e80a4d67b352
stdlib@go1.20.4
1.25.10
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
stdlib@go1.19.13
1.25.10
2
danielfm/aws-limits-exporter:0.6.07152b84e57cb
stdlib@go1.17.2
1.25.10
2
danielqsj/kafka-exporter:v1.9.04150e46b2e96
stdlib@go1.24.0
1.25.10
2
danielqsj/kafka-exporter:latesta51b280b55a7
stdlib@go1.26.2
1.25.10
2
datawire/aes:1.14.48588eafe6862
stdlib@go1.15
1.25.10
2
devopsfaith/krakend:latestf8bdaa8a1a43
stdlib@go1.24.2
1.25.10
2
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
stdlib@go1.16.2
1.25.10
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
stdlib@go1.16.15
1.25.10
2
dtzar/helm-kubectl:3.14.455429449408e
stdlib@go1.21.8
1.25.10
2
eqalpha/keydb:latest6537505c4235
stdlib@go1.16.7
1.25.10
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.25.10
2
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.25.10
2
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.25.10
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
stdlib@go1.18.3
1.25.10
2
free5gc/amf:v3.4.31bc96ff5a2a6
stdlib@go1.21.8
1.25.10
2
free5gc/ausf:v3.4.3687ff4daf5da
stdlib@go1.21.8
1.25.10
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.