StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,940
of 17,790 indexed, latest versions
Container images
4,539
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 3,940 of 17,790 indexed charts deploy, on 4,539 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,539
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

3,940 by stars
ChartLatestAffected imagesRadar Score
listmonklbenicio-communityVerified publisher0.1.01 of 1See more

listmonk lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
listmonk/listmonk:latestf535d59e1499
stdlib@go1.26.1
1.25.10

Open the chart page →

720
pinglbenicio-communityVerified publisher0.1.11 of 1See more

ping lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.28.0e753ff9f3fc4
stdlib@go1.25.5
1.25.10

Open the chart page →

600
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
stdlib@go1.20.5
1.25.10

Open the chart page →

33,540
metallblectures-k8sinfra0.10.22 of 2See more

metallb lectures-k8sinfra 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.10.221164241c045
stdlib@go1.16.5
1.25.10
quay.io/metallb/speaker:v0.10.258cb99053bb3
stdlib@go1.16.5
1.25.10

Open the chart page →

5,406
prometheuslectures-k8sinfra15.8.55 of 6See more

prometheus lectures-k8sinfra 15.8.5

5 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.10
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.25.10
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
stdlib@go1.16.7
1.25.10
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
stdlib@go1.17.3
1.25.10
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
stdlib@go1.18.4
1.25.10

Open the chart page →

9,100
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.10

Open the chart page →

3,198
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.10

Open the chart page →

4,445
prometheusleechistest11.6.04 of 6See more

prometheus leechistest 11.6.0

4 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.25.10
prom/prometheus:v2.19.0bfad037f95e5
stdlib@go1.14.4
1.25.10
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.25.10
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.25.10

Open the chart page →

8,491
kube-benchlemontechVerified publisher0.1.01 of 1See more

kube-bench lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.6.9c329d73fea58
stdlib@go1.19
1.25.10

Open the chart page →

1,632
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
stdlib@go1.19
1.25.10

Open the chart page →

4,280
minioleprechaun-charts0.1.61 of 1See more

minio leprechaun-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-01-20T14-49-07Z-cpuv114b7076ca85a
stdlib@go1.23.5
1.25.10

Open the chart page →

1,319
adguard-homelib42Verified publisher2.0.01 of 1See more

adguard-home lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.65d765078d2140
stdlib@go1.24.6
1.25.10

Open the chart page →

1,060
libredb-studiolibredb-studio-oci0.1.631 of 1See more

libredb-studio libredb-studio-oci 0.1.63

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
stdlib@go1.24.4
1.25.10

Open the chart page →

1,244
librenmslibrenms10.1.12 of 5See more

librenms librenms 10.1.1

2 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
stdlib@go1.24.6
1.25.10
librenms/librenms:26.8.28194a4a9ff49
stdlib@go1.24.6
1.25.10

Open the chart page →

3,149
kltlifecycle-toolkitOfficialVerified publisher0.2.64 of 4See more

klt lifecycle-toolkit 0.2.6

4 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v1.1.08fdd311a6d33
stdlib@go1.20.4
1.25.10
ghcr.io/keptn/lifecycle-operator:v0.8.2487bfc37c4b4
stdlib@go1.20.4
1.25.10
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
stdlib@go1.20.4
1.25.10
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
stdlib@go1.20.4
1.25.10

Open the chart page →

4,680
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
stdlib@go1.13.8
1.25.10

Open the chart page →

4,459
op-scim-bridgelifen1.0.31 of 2See more

op-scim-bridge lifen 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
stdlib@go1.16.8
1.25.10

Open the chart page →

2,777
op-scim-bridgelifen-chartsVerified publisher1.0.31 of 2See more

op-scim-bridge lifen-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
stdlib@go1.16.8
1.25.10

Open the chart page →

2,777
lightsteplightstep-microsat2.0.211 of 1See more

lightstep lightstep-microsat 2.0.21

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
stdlib@go1.22.1
1.25.10

Open the chart page →

1,127
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
stdlib@go1.17.8
1.25.10

Open the chart page →

3,133
linkerd-preview-vizlinkerd-buoyantVerified publisher25.4.34 of 5See more

linkerd-preview-viz linkerd-buoyant 25.4.3

4 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
stdlib@go1.24.2
1.25.10
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
stdlib@go1.23.2
1.25.10
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
stdlib@go1.24.2
1.25.10
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
stdlib@go1.24.2
1.25.10

Open the chart page →

3,454
linkerd-dashboardlinkerd-dashboardOfficial0.11.11 of 2See more

linkerd-dashboard linkerd-dashboard 0.11.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
stdlib@go1.24.2
1.25.10

Open the chart page →

1,050
linode-blockstorage-csi-driverlinode-blockstorage-csi-driverOfficialVerified publisher1.1.44 of 5See more

linode-blockstorage-csi-driver linode-blockstorage-csi-driver 1.1.4

4 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
stdlib@go1.25.7
1.25.10

Open the chart page →

2,967
school-botlinuxoid690.1.01 of 1See more

school-bot linuxoid69 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/linuxoid69/school-bot:v0.3.3c8872438f1e0
stdlib@go1.23.3
1.25.10

Open the chart page →

772
liqo-upgrade-operatorliqo-upgrade-operatorVerified publisher0.1.01 of 1See more

liqo-upgrade-operator liqo-upgrade-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
kazem26/liqo-upgrade-operator:v0.1268b7c6a59dd
stdlib@go1.24.13
1.25.10

Open the chart page →

375
listmonklistmonk-chartVerified publisher2.0.12 of 2See more

listmonk listmonk-chart 2.0.1

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
stdlib@go1.24.6
1.25.10
listmonk/listmonk:v6.0.0bf3903d54a46
stdlib@go1.24.1
1.25.10

Open the chart page →

3,091
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
stdlib@go1.20.7
1.25.10

Open the chart page →

10,780
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
stdlib@go1.16.2
1.25.10

Open the chart page →

2,135
livekit-serverlivekit-server1.9.01 of 1See more

livekit-server livekit-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.9.03602a85840d5
stdlib@go1.24.3
1.25.10

Open the chart page →

1,560
pagesliviu884422-pages1.0.01 of 3See more

pages liviu884422-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,242
llmarinerllmariner1.53.115 of 21See more

llmariner llmariner 1.53.1

15 of the 21 container images this version deploys carry CVE-2026-39820.

Open the chart page →

12,150
llm-dllm-dVerified publisher1.0.231 of 2See more

llm-d llm-d 1.0.23

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
stdlib@go1.24.3
1.25.10

Open the chart page →

2,539
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
stdlib@go1.25.6
1.25.10

Open the chart page →

2,450
go-ocpp-serverloafoe0.2.11 of 1See more

go-ocpp-server loafoe 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loafoe/go-ocpp-server:v0.2.145bb960674ab
stdlib@go1.21.13
1.25.10

Open the chart page →

399
mt-mcp-grafanaloafoe0.10.01 of 2See more

mt-mcp-grafana loafoe 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loafoe/mt-mcp-grafana:v0.1.12332d9b47475
stdlib@go1.26.2
1.25.10

Open the chart page →

1,933
otlp-gatewayloafoe0.0.22 of 2See more

otlp-gateway loafoe 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/jimmidyson/configmap-reload:v0.13.1ca0c14eef541
stdlib@go1.22.4
1.25.10
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
stdlib@go1.22.5
1.25.10

Open the chart page →

2,162
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
stdlib@go1.15.15
1.25.10

Open the chart page →

4,911
picoclawloafoe0.1.11 of 2See more

picoclaw loafoe 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loafoe/picoclaw:v0.0.1942e1b6862913
stdlib@go1.26.2
1.25.10

Open the chart page →

479
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
stdlib@go1.21.0
1.25.10

Open the chart page →

2,108
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
stdlib@go1.22.6
1.25.10

Open the chart page →

2,027
weather-app-chartlocal-weatherapp0.1.02 of 4See more

weather-app-chart local-weatherapp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:8.0.36-debian-11-r38aad73aa0c6d
stdlib@go1.21.6
1.25.10
youssef11gaber10/deployment-auth-go:latest6597b26959d2
stdlib@go1.26.1
1.25.10

Open the chart page →

5,905
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
stdlib@go1.13.10
1.25.10

Open the chart page →

7,519
locust-pluginslocust-pluginsVerified publisher0.0.42 of 3See more

locust-plugins locust-plugins 0.0.4

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
stdlib@go1.21.8
1.25.10
sky5367/locust-plugins-timescale:latestd3150f201471
stdlib@go1.18.7
1.25.10

Open the chart page →

7,534
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
stdlib@go1.20.5
1.25.10

Open the chart page →

33,540
central-hostpath-mapperloftVerified publisher0.2.91 of 1See more

central-hostpath-mapper loft 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
stdlib@go1.23.2
1.25.10

Open the chart page →

924
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
stdlib@go1.20.10
1.25.10

Open the chart page →

3,234
devspace-cloudloftVerified publisher0.3.32 of 8See more

devspace-cloud loft 0.3.3

2 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
stdlib@go1.13.8
1.25.10
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.10

Open the chart page →

9,888
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
stdlib@go1.15.7
1.25.10

Open the chart page →

3,094
license-serverloftVerified publisher0.6.01 of 1See more

license-server loft 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
stdlib@go1.24.3
1.25.10

Open the chart page →

804
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
stdlib@go1.18.10
1.25.10

Open the chart page →

2,453

Container images carrying it

4,539 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
stdlib@go1.24.6
1.25.10
3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
stdlib@go1.20.3
1.25.10
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
stdlib@go1.16.2
1.25.10
3
1password/scim:v2.3.129d0c6cb67eb
stdlib@go1.16.8
1.25.10
2
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.25.10
2
alazidis/kube-netlag:1.1.00e8c84152201
stdlib@go1.24.13
1.25.10
2
alpine/git:2.47.2062a01ad7a0e
stdlib@go1.23.9
1.25.10
2
alpine/k8s:1.32.12048f8d9c8cc7
stdlib@go1.25.7
1.25.10
2
alpine/kubectl:1.35.49ccd82364762
stdlib@go1.25.9
1.25.10
2
alpine/kubectl:1.35.2ec8f734b0a10
stdlib@go1.25.7
1.25.10
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
stdlib@go1.19.10
1.25.10
2
altinity/metrics-exporter:0.21.2df3d57215356
stdlib@go1.19.10
1.25.10
2
apache/superset:dockerizeafe59523a6c8
stdlib@go1.20.4
1.25.10
2
apecloud/apecloud-mcp:0.1.094041b080510
stdlib@go1.23.7
1.25.10
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
stdlib@go1.21.7
1.25.10
2
assistiot/fl_repository_db:latestad8f72108636
stdlib@go1.17.10
1.25.10
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
stdlib@go1.18.9
1.25.10
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
stdlib@go1.24.6
1.25.10
2
bitnamilegacy/etcd:latest99b408c15272
stdlib@go1.23.10
1.25.10
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
stdlib@go1.19.6
1.25.10
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
stdlib@go1.19.8
1.25.10
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
stdlib@go1.23.7
1.25.10
2
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
stdlib@go1.15.1
1.25.10
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.25.10
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.25.10
2
bitnamilegacy/redis:latest5927ff3702df
stdlib@go1.24.5
1.25.10
2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
stdlib@go1.24.6
1.25.10
2
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.25.10
2
bitnamisecure/git72ae5bd9715f
stdlib@go1.24.6
1.25.10
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
stdlib@go1.17.13
1.25.10
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
stdlib@go1.19.9
1.25.10
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.10
2
cesanta/docker_auth:1.6.04d16885f3d4c
stdlib@go1.13.7
1.25.10
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
stdlib@go1.20.14
1.25.10
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
stdlib@go1.14.5
1.25.10
2
clickhouse/clickhouse-server:24.2ed9640bfff07
stdlib@go1.19.10
1.25.10
2
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.25.10
2
coredns/coredns:1.13.19b9128672209
stdlib@go1.25.2
1.25.10
2
crate/crate_adapter:latestb8d89fa5d19b
stdlib@go1.16.3
1.25.10
2
cs3org/revad:v1.19.03b57a34a7dfd
stdlib@go1.17.3
1.25.10
2
cs3org/revad:v1.24.0e80a4d67b352
stdlib@go1.20.4
1.25.10
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
stdlib@go1.19.13
1.25.10
2
danielfm/aws-limits-exporter:0.6.07152b84e57cb
stdlib@go1.17.2
1.25.10
2
danielqsj/kafka-exporter:v1.9.04150e46b2e96
stdlib@go1.24.0
1.25.10
2
danielqsj/kafka-exporter:latesta51b280b55a7
stdlib@go1.26.2
1.25.10
2
datawire/aes:1.14.48588eafe6862
stdlib@go1.15
1.25.10
2
devopsfaith/krakend:latestf8bdaa8a1a43
stdlib@go1.24.2
1.25.10
2
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
stdlib@go1.16.2
1.25.10
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
stdlib@go1.16.15
1.25.10
2
dtzar/helm-kubectl:3.14.455429449408e
stdlib@go1.21.8
1.25.10
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.