StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,940
of 17,790 indexed, latest versions
Container images
4,539
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 3,940 of 17,790 indexed charts deploy, on 4,539 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,539
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

3,940 by stars
ChartLatestAffected imagesRadar Score
listmonklbenicio-communityVerified publisher0.1.01 of 1See more

listmonk lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
listmonk/listmonk:latestf535d59e1499
stdlib@go1.26.1
1.25.10

Open the chart page →

720
pinglbenicio-communityVerified publisher0.1.11 of 1See more

ping lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.28.0e753ff9f3fc4
stdlib@go1.25.5
1.25.10

Open the chart page →

600
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
stdlib@go1.20.5
1.25.10

Open the chart page →

33,540
metallblectures-k8sinfra0.10.22 of 2See more

metallb lectures-k8sinfra 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.10.221164241c045
stdlib@go1.16.5
1.25.10
quay.io/metallb/speaker:v0.10.258cb99053bb3
stdlib@go1.16.5
1.25.10

Open the chart page →

5,406
prometheuslectures-k8sinfra15.8.55 of 6See more

prometheus lectures-k8sinfra 15.8.5

5 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.10
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.25.10
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
stdlib@go1.16.7
1.25.10
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
stdlib@go1.17.3
1.25.10
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
stdlib@go1.18.4
1.25.10

Open the chart page →

9,100
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.10

Open the chart page →

3,198
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.10

Open the chart page →

4,445
prometheusleechistest11.6.04 of 6See more

prometheus leechistest 11.6.0

4 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.25.10
prom/prometheus:v2.19.0bfad037f95e5
stdlib@go1.14.4
1.25.10
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.25.10
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.25.10

Open the chart page →

8,491
kube-benchlemontechVerified publisher0.1.01 of 1See more

kube-bench lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.6.9c329d73fea58
stdlib@go1.19
1.25.10

Open the chart page →

1,632
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
stdlib@go1.19
1.25.10

Open the chart page →

4,280
minioleprechaun-charts0.1.61 of 1See more

minio leprechaun-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-01-20T14-49-07Z-cpuv114b7076ca85a
stdlib@go1.23.5
1.25.10

Open the chart page →

1,319
adguard-homelib42Verified publisher2.0.01 of 1See more

adguard-home lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.65d765078d2140
stdlib@go1.24.6
1.25.10

Open the chart page →

1,060
libredb-studiolibredb-studio-oci0.1.631 of 1See more

libredb-studio libredb-studio-oci 0.1.63

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
stdlib@go1.24.4
1.25.10

Open the chart page →

1,244
librenmslibrenms10.1.12 of 5See more

librenms librenms 10.1.1

2 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
stdlib@go1.24.6
1.25.10
librenms/librenms:26.8.28194a4a9ff49
stdlib@go1.24.6
1.25.10

Open the chart page →

3,149
kltlifecycle-toolkitOfficialVerified publisher0.2.64 of 4See more

klt lifecycle-toolkit 0.2.6

4 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v1.1.08fdd311a6d33
stdlib@go1.20.4
1.25.10
ghcr.io/keptn/lifecycle-operator:v0.8.2487bfc37c4b4
stdlib@go1.20.4
1.25.10
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
stdlib@go1.20.4
1.25.10
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
stdlib@go1.20.4
1.25.10

Open the chart page →

4,680
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
stdlib@go1.13.8
1.25.10

Open the chart page →

4,459
op-scim-bridgelifen1.0.31 of 2See more

op-scim-bridge lifen 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
stdlib@go1.16.8
1.25.10

Open the chart page →

2,777
op-scim-bridgelifen-chartsVerified publisher1.0.31 of 2See more

op-scim-bridge lifen-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
stdlib@go1.16.8
1.25.10

Open the chart page →

2,777
lightsteplightstep-microsat2.0.211 of 1See more

lightstep lightstep-microsat 2.0.21

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
stdlib@go1.22.1
1.25.10

Open the chart page →

1,127
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
stdlib@go1.17.8
1.25.10

Open the chart page →

3,133
linkerd-preview-vizlinkerd-buoyantVerified publisher25.4.34 of 5See more

linkerd-preview-viz linkerd-buoyant 25.4.3

4 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
stdlib@go1.24.2
1.25.10
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
stdlib@go1.23.2
1.25.10
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
stdlib@go1.24.2
1.25.10
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
stdlib@go1.24.2
1.25.10

Open the chart page →

3,454
linkerd-dashboardlinkerd-dashboardOfficial0.11.11 of 2See more

linkerd-dashboard linkerd-dashboard 0.11.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
stdlib@go1.24.2
1.25.10

Open the chart page →

1,050
linode-blockstorage-csi-driverlinode-blockstorage-csi-driverOfficialVerified publisher1.1.44 of 5See more

linode-blockstorage-csi-driver linode-blockstorage-csi-driver 1.1.4

4 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
stdlib@go1.25.7
1.25.10

Open the chart page →

2,967
school-botlinuxoid690.1.01 of 1See more

school-bot linuxoid69 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/linuxoid69/school-bot:v0.3.3c8872438f1e0
stdlib@go1.23.3
1.25.10

Open the chart page →

772
liqo-upgrade-operatorliqo-upgrade-operatorVerified publisher0.1.01 of 1See more

liqo-upgrade-operator liqo-upgrade-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
kazem26/liqo-upgrade-operator:v0.1268b7c6a59dd
stdlib@go1.24.13
1.25.10

Open the chart page →

375
listmonklistmonk-chartVerified publisher2.0.12 of 2See more

listmonk listmonk-chart 2.0.1

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
stdlib@go1.24.6
1.25.10
listmonk/listmonk:v6.0.0bf3903d54a46
stdlib@go1.24.1
1.25.10

Open the chart page →

3,091
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
stdlib@go1.20.7
1.25.10

Open the chart page →

10,780
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
stdlib@go1.16.2
1.25.10

Open the chart page →

2,135
livekit-serverlivekit-server1.9.01 of 1See more

livekit-server livekit-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.9.03602a85840d5
stdlib@go1.24.3
1.25.10

Open the chart page →

1,560
pagesliviu884422-pages1.0.01 of 3See more

pages liviu884422-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,242
llmarinerllmariner1.53.115 of 21See more

llmariner llmariner 1.53.1

15 of the 21 container images this version deploys carry CVE-2026-39820.

Open the chart page →

12,150
llm-dllm-dVerified publisher1.0.231 of 2See more

llm-d llm-d 1.0.23

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
stdlib@go1.24.3
1.25.10

Open the chart page →

2,539
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
stdlib@go1.25.6
1.25.10

Open the chart page →

2,450
go-ocpp-serverloafoe0.2.11 of 1See more

go-ocpp-server loafoe 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loafoe/go-ocpp-server:v0.2.145bb960674ab
stdlib@go1.21.13
1.25.10

Open the chart page →

399
mt-mcp-grafanaloafoe0.10.01 of 2See more

mt-mcp-grafana loafoe 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loafoe/mt-mcp-grafana:v0.1.12332d9b47475
stdlib@go1.26.2
1.25.10

Open the chart page →

1,933
otlp-gatewayloafoe0.0.22 of 2See more

otlp-gateway loafoe 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/jimmidyson/configmap-reload:v0.13.1ca0c14eef541
stdlib@go1.22.4
1.25.10
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
stdlib@go1.22.5
1.25.10

Open the chart page →

2,162
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
stdlib@go1.15.15
1.25.10

Open the chart page →

4,911
picoclawloafoe0.1.11 of 2See more

picoclaw loafoe 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loafoe/picoclaw:v0.0.1942e1b6862913
stdlib@go1.26.2
1.25.10

Open the chart page →

479
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
stdlib@go1.21.0
1.25.10

Open the chart page →

2,108
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
stdlib@go1.22.6
1.25.10

Open the chart page →

2,027
weather-app-chartlocal-weatherapp0.1.02 of 4See more

weather-app-chart local-weatherapp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:8.0.36-debian-11-r38aad73aa0c6d
stdlib@go1.21.6
1.25.10
youssef11gaber10/deployment-auth-go:latest6597b26959d2
stdlib@go1.26.1
1.25.10

Open the chart page →

5,905
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
stdlib@go1.13.10
1.25.10

Open the chart page →

7,519
locust-pluginslocust-pluginsVerified publisher0.0.42 of 3See more

locust-plugins locust-plugins 0.0.4

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
stdlib@go1.21.8
1.25.10
sky5367/locust-plugins-timescale:latestd3150f201471
stdlib@go1.18.7
1.25.10

Open the chart page →

7,534
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
stdlib@go1.20.5
1.25.10

Open the chart page →

33,540
central-hostpath-mapperloftVerified publisher0.2.91 of 1See more

central-hostpath-mapper loft 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
stdlib@go1.23.2
1.25.10

Open the chart page →

924
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
stdlib@go1.20.10
1.25.10

Open the chart page →

3,234
devspace-cloudloftVerified publisher0.3.32 of 8See more

devspace-cloud loft 0.3.3

2 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
stdlib@go1.13.8
1.25.10
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.10

Open the chart page →

9,888
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
stdlib@go1.15.7
1.25.10

Open the chart page →

3,094
license-serverloftVerified publisher0.6.01 of 1See more

license-server loft 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
stdlib@go1.24.3
1.25.10

Open the chart page →

804
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
stdlib@go1.18.10
1.25.10

Open the chart page →

2,453

Container images carrying it

4,539 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10
89
library/postgres:18:18.6:18.6-trixie:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10
69
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10
22
library/postgres:18.6-alpine:18-alpine:alpined3e1620b530c
stdlib@go1.24.6
1.25.10
17
library/mysql:8:8.4:8.4.11b3b90af2a655
stdlib@go1.24.6
1.25.10
16
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10
16
minio/minio:latest:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
stdlib@go1.24.6
1.25.10
16
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.10
14
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
stdlib@go1.18.10
1.25.10
13
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
stdlib@go1.25.3
1.25.10
13
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10
13
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
13
grafana/grafana:latestf772d434e8fa
stdlib@go1.25.7
1.25.10
12
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.10
12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.10
12
library/mariadb:12.3.3:latest:ltsdd9b303aed4f
stdlib@go1.24.6
1.25.10
11
library/mongo:8:8.3.8:latest5211c51171f5
stdlib@go1.24.6
1.25.10
11
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10
11
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.10
11
jwilder/dockerize:latestf94fb59fb4f6
stdlib@go1.25.5
1.25.10
10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
10
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.10
10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.10
9
library/rabbitmq:3.13-management:3-managemente582c0bc7766
stdlib@go1.22.2
1.25.10
8
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.25.10
8
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
stdlib@go1.23.4
1.25.10
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.10
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.25.10
8
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.10
7
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.25.10
7
wurstmeister/kafka:latest2d4bbf9cc83d
stdlib@go1.17.10
1.25.10
7
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10
7
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10
7
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
stdlib@go1.23.4
1.25.10
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
stdlib@go1.23.4
1.25.10
7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
stdlib@go1.24.6
1.25.10
7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
stdlib@go1.25.7
1.25.10
7
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
stdlib@go1.25.7
1.25.10
7
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
stdlib@go1.24.2
1.25.10
7
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
stdlib@go1.19.12
1.25.10
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.10
6
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.25.10
6
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.10
6
library/mariadb:10:10.11ce66c7be32a0
stdlib@go1.24.6
1.25.10
6
library/mysql:9.7.2257388edf9c8
stdlib@go1.24.6
1.25.10
6
library/postgres:159b1d34adbce1
stdlib@go1.24.6
1.25.10
6
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.10
6
library/registry:2:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.25.10
6
minio/mc:latest:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
stdlib@go1.24.6
1.25.10
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
stdlib@go1.18.2
1.25.10
6

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.