StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,033
of 17,813 indexed, latest versions
Container images
4,618
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 4,033 of 17,813 indexed charts deploy, on 4,618 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,618
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

4,033 by stars
ChartLatestAffected imagesRadar Score
memoscharts-derwitt-devVerified publisher1.4.01 of 1See more

memos charts-derwitt-dev 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
neosmemo/memos:0.30.071a5b4738d1b
stdlib@go1.26.2
1.25.10

Open the chart page →

707
paperless-ngxcharts-derwitt-devVerified publisher2.1.41 of 1See more

paperless-ngx charts-derwitt-dev 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10

Open the chart page →

4,834
yas3pcharts-derwitt-devVerified publisher0.3.11 of 1See more

yas3p charts-derwitt-dev 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
denniswitt/yas3p:0.2.488a235619af6
stdlib@go1.26.1
1.25.10

Open the chart page →

738
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
stdlib@go1.20.12
1.25.10

Open the chart page →

2,126
checker-edgechecker-edge1.1.111 of 1See more

checker-edge checker-edge 1.1.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/imcitius/checker-edge:1.1.1174426c1fe00f
stdlib@go1.25.9
1.25.10

Open the chart page →

812
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
stdlib@go1.13.10
1.25.10

Open the chart page →

8,419
aws-ecr-tokencheveo-charts0.1.01 of 1See more

aws-ecr-token cheveo-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
huzafach/aws-cli-k8:1.0.06e271d43ea48
stdlib@go1.22.4
1.25.10

Open the chart page →

1,110
pathling-serverchglVerified publisher0.10.111 of 3See more

pathling-server chgl 0.10.11

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
stdlib@go1.25.7
1.25.10

Open the chart page →

1,230
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
stdlib@go1.13.11
1.25.10

Open the chart page →

2,877
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
stdlib@go1.13.11
1.25.10

Open the chart page →

2,829
supersetchoerodon1.0.01 of 3See more

superset choerodon 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
stdlib@go1.20.4
1.25.10

Open the chart page →

1,440
argocd-metrics-serverchristianhuthVerified publisher1.1.11 of 1See more

argocd-metrics-server christianhuth 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
stdlib@go1.21.11
1.25.10

Open the chart page →

1,031
cluster-api-visualizerchristianhuthVerified publisher0.6.01 of 1See more

cluster-api-visualizer christianhuth 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
stdlib@go1.24.11
1.25.10

Open the chart page →

558
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
stdlib@go1.19.4
1.25.10
countly/frontend:25.05.42acbc11499b6
stdlib@go1.19.4
1.25.10

Open the chart page →

7,325
dnsbl-exporterchristianhuthVerified publisher1.4.01 of 2See more

dnsbl-exporter christianhuth 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/luzilla/dnsbl_exporter:v0.7.0-rc3d9767232a55e
stdlib@go1.20.14
1.25.10

Open the chart page →

1,460
kubedoomchristianhuthVerified publisher1.1.21 of 1See more

kubedoom christianhuth 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/storax/kubedoom:0.6.0851ba8c80b93
stdlib@go1.17.6
1.25.10

Open the chart page →

1,021
kubevirt-cloud-controller-managerchristianhuthVerified publisher0.0.21 of 1See more

kubevirt-cloud-controller-manager christianhuth 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
stdlib@go1.24.13
1.25.10

Open the chart page →

670
kubevirt-managerchristianhuthVerified publisher0.7.01 of 1See more

kubevirt-manager christianhuth 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
stdlib@go1.25.5
1.25.10

Open the chart page →

1,990
mailcow-exporterchristianhuthVerified publisher1.5.01 of 1See more

mailcow-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
stdlib@go1.23.12
1.25.10

Open the chart page →

753
nextcloud-exporterchristianhuthVerified publisher1.5.01 of 1See more

nextcloud-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
xperimental/nextcloud-exporter:0.9.13e90a3897651
stdlib@go1.26.1
1.25.10

Open the chart page →

194
ntp-exporterchristianhuthVerified publisher1.4.01 of 1See more

ntp-exporter christianhuth 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/sapcc/ntp_exporter:v2.9.079c40c65f5d4
stdlib@go1.24.6
1.25.10

Open the chart page →

378
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.10

Open the chart page →

6,033
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
stdlib@go1.16.15
1.25.10

Open the chart page →

2,291
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
stdlib@go1.24.5
1.25.10

Open the chart page →

7,215
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
stdlib@go1.22.10
1.25.10

Open the chart page →

4,901
ethereumchronicleVerified publisher0.3.11 of 1See more

ethereum chronicle 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ethereum/client-go:v1.16.532b878e4144a
stdlib@go1.24.9
1.25.10

Open the chart page →

1,353
ethereum-metrics-exporterchronicleVerified publisher0.1.41 of 1See more

ethereum-metrics-exporter chronicle 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
samcm/ethereum-metrics-exporter:0.29.291a2d9a015c1
stdlib@go1.25.8
1.25.10

Open the chart page →

684
goferchronicleVerified publisher0.4.41 of 1See more

gofer chronicle 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/gofer:0.613915d2e41e04
stdlib@go1.24.6
1.25.10

Open the chart page →

721
mantlechronicleVerified publisher0.1.31 of 1See more

mantle chronicle 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
stdlib@go1.19.10
1.25.10

Open the chart page →

1,942
sith-exporterschronicleVerified publisher0.2.41 of 1See more

sith-exporters chronicle 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/oracles-updates-exporter:0.0.4992d0e793af6
stdlib@go1.19.13
1.25.10

Open the chart page →

997
spirechronicleVerified publisher0.3.61 of 1See more

spire chronicle 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
stdlib@go1.25.5
1.25.10

Open the chart page →

1,553
tor-proxychronicleVerified publisher0.1.01 of 1See more

tor-proxy chronicle 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
btcpayserver/tor:0.4.8.10e9585b68dc6b
stdlib@go1.16.5
1.25.10

Open the chart page →

3,384
zksyncchronicleVerified publisher0.1.01 of 2See more

zksync chronicle 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.10

Open the chart page →

6,111
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.25.10

Open the chart page →

3,603
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/chekrdigest-pinnedf299baf467b5
stdlib@go1.17.3
1.25.10

Open the chart page →

3,468
clairclair-helmVerified publisher0.12.02 of 3See more

clair clair-helm 0.12.0

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10
quay.io/projectquay/clair:4.9.023329c3368e4
stdlib@go1.24.11
1.25.10

Open the chart page →

1,749
calico-cniclastixVerified publisher3.28.13 of 3See more

calico-cni clastix 3.28.1

3 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
calico/cni:v3.28.1e486870cfde8
stdlib@go1.22.5
1.25.10
calico/kube-controllers:v3.28.1eadb3a25109a
stdlib@go1.22.5
1.25.10
calico/node:v3.28.1d8c644a8a3ee
stdlib@go1.22.5
1.25.10

Open the chart page →

3,078
capi-kamaji-vsphere-fullclastixVerified publisher1.0.19 of 9See more

capi-kamaji-vsphere-full clastix 1.0.1

9 of the 9 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
stdlib@go1.24.4
1.25.10
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
stdlib@go1.23.0
1.25.10
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
stdlib@go1.22.12
1.25.10
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
stdlib@go1.22.12
1.25.10
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
stdlib@go1.23.1
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
stdlib@go1.21.5
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
stdlib@go1.23.1
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
stdlib@go1.23.1
1.25.10

Open the chart page →

6,012
capsule-rancher-addonclastixVerified publisher0.1.15 of 5See more

capsule-rancher-addon clastix 0.1.1

5 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
clastix/capsule-rancher-addon:v0.1.143d301afbca8
stdlib@go1.19.2
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
stdlib@go1.19.5
1.25.10
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
stdlib@go1.19.5
1.25.10
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
stdlib@go1.19.5
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
stdlib@go1.19.5
1.25.10

Open the chart page →

7,142
kamajiclastixVerified publisher0.0.0+latest1 of 4See more

kamaji clastix 0.0.0+latest

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
stdlib@go1.16.15
1.25.10

Open the chart page →

4,669
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
stdlib@go1.23.7
1.25.10

Open the chart page →

2,765
kamaji-etcdclastixVerified publisher0.18.02 of 4See more

kamaji-etcd clastix 0.18.0

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
stdlib@go1.20.14
1.25.10
quay.io/coreos/etcd:v3.5.628cb0630cb85
stdlib@go1.16.15
1.25.10

Open the chart page →

12,123
local-path-provisionerclastixVerified publisher0.0.301 of 1See more

local-path-provisioner clastix 0.0.30

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.309b9148811700
stdlib@go1.23.1
1.25.10

Open the chart page →

1,209
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
stdlib@go1.16
1.25.10
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
stdlib@go1.16
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
stdlib@go1.16.2
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
stdlib@go1.17.3
1.25.10

Open the chart page →

7,417
cloudflared-tunnelclouddrove0.1.41 of 1See more

cloudflared-tunnel clouddrove 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2025.8.0eb5c9324efe3
stdlib@go1.24.4
1.25.10

Open the chart page →

1,816
kube-acp-stackcloudentity2.28.03 of 7See more

kube-acp-stack cloudentity 2.28.0

3 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
stdlib@go1.23.8
1.25.10
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
stdlib@go1.21.13
1.25.10
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
stdlib@go1.13.14
1.25.10

Open the chart page →

21,162
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
stdlib@go1.15.14
1.25.10
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
stdlib@go1.15.14
1.25.10
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
stdlib@go1.15.2
1.25.10
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
stdlib@go1.16.6
1.25.10
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
stdlib@go1.15.2
1.25.10
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
stdlib@go1.15.2
1.25.10

Open the chart page →

18,046
cloudflare-ddns-updatecloudflare-ddns-update0.1.21 of 1See more

cloudflare-ddns-update cloudflare-ddns-update 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
stdlib@go1.22.4
1.25.10

Open the chart page →

1,339
cloudflare-dyndnscloudflare-dyndnsVerified publisher1.1.01 of 1See more

cloudflare-dyndns cloudflare-dyndns 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/msueberkrueb/cloudflare-dyndns:1.0.0e5c945a3b000
stdlib@go1.25.1
1.25.10

Open the chart page →

307
cloudflare-tunnel-ingress-controllercloudflare-tunnel-ingress-controller0.2.31 of 1See more

cloudflare-tunnel-ingress-controller cloudflare-tunnel-ingress-controller 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/oliverbaehler/cloudflare-tunnel-ingress-controller:0.2.30aec31e36d95
stdlib@go1.23.7
1.25.10

Open the chart page →

438

Container images carrying it

4,618 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
stdlib@go1.19.2
1.25.10
1
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
stdlib@go1.18.3
1.25.10
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
stdlib@go1.18.1
1.25.10
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
stdlib@go1.19.10
1.25.10
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
stdlib@go1.23.8
1.25.10
1
quay.io/coreos/etcd:v3.5.11842975891182
stdlib@go1.20.12
1.25.10
1
quay.io/coreos/etcd:v3.5.16d967d98a12dc
stdlib@go1.22.7
1.25.10
1
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
stdlib@go1.16.3
1.25.10
1
quay.io/cortexproject/cortex:v1.21.18577eb292a01
stdlib@go1.25.8
1.25.10
1
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
stdlib@go1.23.0
1.25.10
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
stdlib@go1.16.6
1.25.10
1
quay.io/enix/zfs-exporter:2.3.1223b053f1cbd0
stdlib@go1.24.2
1.25.10
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
stdlib@go1.23.6
1.25.10
1
quay.io/evl.ms/pgbouncer-exporter:0.4.074f919b78494
stdlib@go1.14.4
1.25.10
1
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
stdlib@go1.21.1
1.25.10
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
stdlib@go1.20.4
1.25.10
1
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
stdlib@go1.25.7
1.25.10
1
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
stdlib@go1.18.10
1.25.10
1
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
stdlib@go1.18.5
1.25.10
1
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
stdlib@go1.18.5
1.25.10
1
quay.io/fiware/vcverifier:2.0.1cd36290dc849
stdlib@go1.19.9
1.25.10
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
stdlib@go1.20.2
1.25.10
1
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
stdlib@go1.17.12
1.25.10
1
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
stdlib@go1.17.12
1.25.10
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
stdlib@go1.17.12
1.25.10
1
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
stdlib@go1.18.4
1.25.10
1
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
stdlib@go1.18.4
1.25.10
1
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
stdlib@go1.18.4
1.25.10
1
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
stdlib@go1.18.4
1.25.10
1
quay.io/fossa/postgres:17.2-15af45ac79f38
stdlib@go1.18.2
1.25.10
1
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
stdlib@go1.23.2
1.25.10
1
quay.io/galexrt/dellhw_exporter:v2.0.0b3a5806d73b5
stdlib@go1.25.8
1.25.10
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
stdlib@go1.20.5
1.25.10
1
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
stdlib@go1.17.1
1.25.10
1
quay.io/giantswarm/helloworld:0.2.07a07ee730305
stdlib@go1.16.7
1.25.10
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
stdlib@go1.19.12
1.25.10
1
quay.io/go-skynet/local-ai:latest0632c21ddbe4
stdlib@go1.26.0
1.25.10
1
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
stdlib@go1.18
1.25.10
1
quay.io/groundcover/tools:20260719b705e0cbe171
stdlib@go1.24.4
1.25.10
1
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
stdlib@go1.19.4
1.25.10
1
quay.io/gustavojst/kube-botblocker:0.2.04de059bb32ac
stdlib@go1.24.4
1.25.10
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
stdlib@go1.23.7
1.25.10
1
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
stdlib@go1.25.0
1.25.10
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
stdlib@go1.17.5
1.25.10
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
stdlib@go1.16.6
1.25.10
1
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
stdlib@go1.16.4
1.25.10
1
quay.io/influxdb/chronograf:1.9.3c2ed16080689
stdlib@go1.16.4
1.25.10
1
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
stdlib@go1.18.10
1.25.10
1
quay.io/jcluppnow/vpa-manager:0.6.4e459d2fba277
stdlib@go1.22.7
1.25.10
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
stdlib@go1.15.6
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.