StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,043
of 17,821 indexed, latest versions
Container images
4,634
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 4,043 of 17,821 indexed charts deploy, on 4,634 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,634
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

4,043 by stars
ChartLatestAffected imagesRadar Score
dendritegeek-cookbookVerified publisher6.4.01 of 1See more

dendrite geek-cookbook 6.4.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
stdlib@go1.18.5
1.25.10

Open the chart page →

2,145
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:lateste1fdac6133ad
stdlib@go1.24.9
1.25.10

Open the chart page →

1,736
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
stdlib@go1.15
1.25.10

Open the chart page →

8,612
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
stdlib@go1.18.1
1.25.10

Open the chart page →

1,882
gonicgeek-cookbookVerified publisher6.4.21 of 1See more

gonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
sentriz/gonic:v0.13.1a74012a6adf3
stdlib@go1.16.4
1.25.10

Open the chart page →

3,526
gotifygeek-cookbookVerified publisher1.2.21 of 1See more

gotify geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
gotify/server:2.1.409c79bc1e403
stdlib@go1.16
1.25.10

Open the chart page →

3,133
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
stdlib@go1.15
1.25.10

Open the chart page →

11,080
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
stdlib@go1.18.3
1.25.10

Open the chart page →

9,922
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
stdlib@go1.16.7
1.25.10

Open the chart page →

14,492
maddygeek-cookbookVerified publisher3.2.01 of 1See more

maddy geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
foxcpp/maddy:v0.5.28fa2bd8f6830
stdlib@go1.17.2
1.25.10

Open the chart page →

2,631
minifluxgeek-cookbookVerified publisher5.2.01 of 2See more

miniflux geek-cookbook 5.2.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
miniflux/miniflux:2.0.36e2fb990dae74
stdlib@go1.17.8
1.25.10

Open the chart page →

2,431
navidromegeek-cookbookVerified publisher6.4.21 of 1See more

navidrome geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
deluan/navidrome:0.43.04e9ae3bff6aa
stdlib@go1.16.4
1.25.10

Open the chart page →

3,598
nullservgeek-cookbookVerified publisher2.4.21 of 1See more

nullserv geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nullserv:v1.3.00792c7e6d814
stdlib@go1.16.5
1.25.10

Open the chart page →

1,118
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
stdlib@go1.18.4
1.25.10

Open the chart page →

12,330
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
stdlib@go1.15
1.25.10

Open the chart page →

17,824
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
stdlib@go1.16.5
1.25.10

Open the chart page →

3,244
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
stdlib@go1.18.3
1.25.10

Open the chart page →

19,612
pod-gatewaygeek-cookbookVerified publisher5.6.21 of 2See more

pod-gateway geek-cookbook 5.6.2

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v3.5.0175512bb3f61
stdlib@go1.18.3
1.25.10

Open the chart page →

2,361
pod-gateway-settergeek-cookbookVerified publisher1.0.01 of 1See more

pod-gateway-setter geek-cookbook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
stdlib@go1.16.4
1.25.10

Open the chart page →

1,642
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.25.10

Open the chart page →

12,049
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
stdlib@go1.18.4
1.25.10

Open the chart page →

10,608
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.25.10

Open the chart page →

7,832
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
stdlib@go1.18.1
1.25.10

Open the chart page →

3,490
searxgeek-cookbookVerified publisher5.6.23 of 4See more

searx geek-cookbook 5.6.2

3 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.25.10
dalf/morty:latest248a4849c350
stdlib@go1.18.2
1.25.10
library/caddy:2.2.0-alpine7367adca165f
stdlib@go1.15.2
1.25.10

Open the chart page →

7,507
skypilotgeek-cookbookVerified publisher0.0.13 of 3See more

skypilot geek-cookbook 0.0.1

3 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
stdlib@go1.23.5
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
stdlib@go1.24.4
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
stdlib@go1.24.4
1.25.10

Open the chart page →

9,116
torrservergeek-cookbookVerified publisher1.2.21 of 1See more

torrserver geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
smailkoz/torrserver:1.0.1117b52d15de8f0
stdlib@go1.17.5
1.25.10

Open the chart page →

3,167
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
stdlib@go1.18.4
1.25.10

Open the chart page →

12,103
vikunjageek-cookbookVerified publisher6.2.02 of 4See more

vikunja geek-cookbook 6.2.0

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/caddy:2.4.2-alpinefbc51bcf1ab0
stdlib@go1.16.5
1.25.10
vikunja/api:0.17.18cba0520bf8c
stdlib@go1.16.5
1.25.10

Open the chart page →

6,905
webhook-receivergeek-cookbookVerified publisher0.0.11 of 1See more

webhook-receiver geek-cookbook 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
stdlib@go1.21.3
1.25.10

Open the chart page →

1,369
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.25.10

Open the chart page →

18,153
asynqmongeneral-helm-chartsVerified publisher0.0.11 of 1See more

asynqmon general-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
hibiken/asynqmon:latestac80bcffd2f9
stdlib@go1.18.10
1.25.10

Open the chart page →

752
cbtgeneral-helm-chartsVerified publisher0.0.51 of 1See more

cbt general-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ethpandaops/cbt:latest5377ffb3091a
stdlib@go1.26.1
1.25.10

Open the chart page →

566
chproxygeneral-helm-chartsVerified publisher0.0.21 of 1See more

chproxy general-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
contentsquareplatform/chproxy:v1.26.524555f22d4be
stdlib@go1.22.7
1.25.10

Open the chart page →

3,686
dispatchoor-apigeneral-helm-chartsVerified publisher0.1.11 of 1See more

dispatchoor-api general-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
stdlib@go1.24.13
1.25.10

Open the chart page →

780
panda-pulsegeneral-helm-chartsVerified publisher1.0.61 of 1See more

panda-pulse general-helm-charts 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ethpandaops/panda-pulse:latestad6fc3b3e6b8
stdlib@go1.26.1
1.25.10

Open the chart page →

622
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
stdlib@go1.17.10
1.25.10

Open the chart page →

4,559
mongogengxiankun-charts0.1.01 of 1See more

mongo gengxiankun-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
stdlib@go1.25.9
1.25.10

Open the chart page →

4,030
mysqlgengxiankun-charts0.2.01 of 1See more

mysql gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

463
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
stdlib@go1.19.8
1.25.10

Open the chart page →

4,209
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.82 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

2 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
stdlib@go1.19.11
1.25.10
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.25.10

Open the chart page →

35,014
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
stdlib@go1.16.7
1.25.10
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
stdlib@go1.16.7
1.25.10

Open the chart page →

16,899
ghostghostVerified publisher0.1.02 of 4See more

ghost ghost 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
stdlib@go1.18.2
1.25.10
litestream/litestream:0.3c5a1e1b01916
stdlib@go1.21.3
1.25.10

Open the chart page →

8,851
rabbitmqginger-society0.1.02 of 2See more

rabbitmq ginger-society 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
kbudde/rabbitmq-exporter:latest12f27d6d84e6
stdlib@go1.21.8
1.25.10
library/rabbitmq:4-managementffd1b50c522a
stdlib@go1.22.2
1.25.10

Open the chart page →

1,537
gitanagitana1.4.01 of 1See more

gitana gitana 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ntakashi/gitana:1.4.04171ec641120
stdlib@go1.17.7
1.25.10

Open the chart page →

3,479
github-rate-limits-prometheus-exportergithub-rate-limit-prometheus-exporterVerified publisher0.2.151 of 1See more

github-rate-limits-prometheus-exporter github-rate-limit-prometheus-exporter 0.2.15

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kalgurn/grl-exporter:v3.2.0bd109b2bda38
stdlib@go1.23.5
1.25.10

Open the chart page →

896
gitlab-goproxygitlab-goproxy0.2.21 of 1See more

gitlab-goproxy gitlab-goproxy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
stdlib@go1.21.0
1.25.10

Open the chart page →

1,332
gitlab-mr-conformgitlab-mr-conform0.5.21 of 1See more

gitlab-mr-conform gitlab-mr-conform 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/chrxmvtik/gitlab-mr-conform:0.5.2b2eb79fc99cb
stdlib@go1.25.9
1.25.10

Open the chart page →

428
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
stdlib@go1.19.12
1.25.10

Open the chart page →

2,617
prometheus-container-resource-exportergkarthiks0.3.11 of 1See more

prometheus-container-resource-exporter gkarthiks 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
gkarthics/container-resource-exporter:latest6799af333e8a
stdlib@go1.14.7
1.25.10

Open the chart page →

2,219
prometheus-couchdb-exportergkarthiks0.1.31 of 1See more

prometheus-couchdb-exporter gkarthiks 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
gesellix/couchdb-prometheus-exporter:v27.2.05b891f1fc2b9
stdlib@go1.13.10
1.25.10

Open the chart page →

1,285

Container images carrying it

4,634 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.25.10
1
registry.gitlab.com/bitspur/rock8s/easy-olm-operator:0.0.1779454fea06c
stdlib@go1.19.10
1.25.10
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
stdlib@go1.20.8
1.25.10
1
registry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.063cf51392ce7
stdlib@go1.19.13
1.25.10
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.25.10
1
registry.gitlab.com/dyff/dyff-operator:0.24.20e9ca51627601
stdlib@go1.24.13
1.25.10
1
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
stdlib@go1.20.14
1.25.10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
stdlib@go1.25.7
1.25.10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
stdlib@go1.25.7
1.25.10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.25.10
1
registry.gitlab.com/gitlab-org/build/cng/cfssl-self-sign:v19.4.07757679afa1b
stdlib@go1.22.0
1.25.10
1
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
stdlib@go1.25.0
1.25.10
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
stdlib@go1.16.14
1.25.10
1
registry.gitlab.com/lenitech/docker/keycloak-ppolicy:0.6.09895d6915075
stdlib@go1.25.7
1.25.10
1
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
stdlib@go1.24.5
1.25.10
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
stdlib@go1.21.0
1.25.10
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
stdlib@go1.15.15
1.25.10
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
stdlib@go1.25.7
1.25.10
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
stdlib@go1.25.7
1.25.10
1
registry.gitlab.com/xrow-public/ci-tools/kubectl:main9357cfeef63c
stdlib@go1.24.9
1.25.10
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
stdlib@go1.24.13
1.25.10
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
stdlib@go1.24.5
1.25.10
1
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.25.10
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.93.006a950310ecd
stdlib@go1.26.2
1.25.10
1
registry.k8s.io/agent-sandbox/sandbox-router-go:v1.0.125b1a0939630
stdlib@go1.26.2
1.25.10
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
stdlib@go1.24.4
1.25.10
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
stdlib@go1.24.7
1.25.10
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.4.171d817780aa9
stdlib@go1.24.3
1.25.10
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
stdlib@go1.25.7
1.25.10
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
stdlib@go1.24.6
1.25.10
1
registry.k8s.io/autoscaling/vpa-recommender:1.4.140b6d76e8526
stdlib@go1.24.3
1.25.10
1
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
stdlib@go1.24.6
1.25.10
1
registry.k8s.io/autoscaling/vpa-updater:1.4.18ebf269779c1
stdlib@go1.24.3
1.25.10
1
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
stdlib@go1.25.7
1.25.10
1
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
stdlib@go1.24.6
1.25.10
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
stdlib@go1.20.7
1.25.10
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
stdlib@go1.23.0
1.25.10
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
stdlib@go1.25.5
1.25.10
1
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
stdlib@go1.24.4
1.25.10
1
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
stdlib@go1.22.12
1.25.10
1
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
stdlib@go1.22.12
1.25.10
1
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
stdlib@go1.24.4
1.25.10
1
registry.k8s.io/descheduler/descheduler:v0.36.07ca92c0a7b4f
stdlib@go1.26.0
1.25.10
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
stdlib@go1.21.7
1.25.10
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
stdlib@go1.24.8
1.25.10
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
stdlib@go1.22.3
1.25.10
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
stdlib@go1.18.3
1.25.10
1
registry.k8s.io/etcd:3.6.4-0e36c08168342
stdlib@go1.23.11
1.25.10
1
registry.k8s.io/gateway-api/admission-server:v0.7.1fe43ee5176a8
stdlib@go1.19.9
1.25.10
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
stdlib@go1.25.1
1.25.10
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.