StackRadar

CVE-2026-39822

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,226
of 17,790 indexed, latest versions
Container images
4,913
deployed by those charts
Fix available
1 of 1
affected package

Root escape via symlink plus trailing slash in os

Carried by container images the latest versions of 4,226 of 17,790 indexed charts deploy, on 4,913 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+186 more1.25.124,913
OSV records
GO-2026-4970
Also known as
BIT-golang-2026-39822

Charts affected

4,226 by stars
ChartLatestAffected imagesRadar Score
tenzu-frontbiru-scop3.1.01 of 1See more

tenzu-front biru-scop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
stdlib@go1.26.3
1.25.12

Open the chart page →

853
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
stdlib@go1.21.1
1.25.12

Open the chart page →

2,336
stackbitpokeVerified publisher0.12.46 of 6See more

stack bitpoke 0.12.4

6 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
stdlib@go1.17.13
1.25.12
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
stdlib@go1.19.9
1.25.12
bitpoke/stack-default-backend:latestc5eed1ddf692
stdlib@go1.16.6
1.25.12
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
stdlib@go1.17.13
1.25.12
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
stdlib@go1.18.2
1.25.12
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
stdlib@go1.18.2
1.25.12

Open the chart page →

9,898
wordpress-operatorbitpokeVerified publisher0.12.41 of 1See more

wordpress-operator bitpoke 0.12.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bitpoke/wordpress-operator:v0.12.421284d1df473
stdlib@go1.17.13
1.25.12

Open the chart page →

1,123
baserowblackbird-cloudVerified publisher1.0.172 of 6See more

baserow blackbird-cloud 1.0.17

2 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
stdlib@go1.19.8
1.25.12
caddy/ingress:v0.2.118d1366fc0e9
stdlib@go1.21.4
1.25.12

Open the chart page →

10,225
prometheus-domain-exporterblackbox-domain-exporter1.0.01 of 1See more

prometheus-domain-exporter blackbox-domain-exporter 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bulich/domain-exporter:latest6d0b780f7c7b
stdlib@go1.20.4
1.25.12

Open the chart page →

1,408
bdbablackduck2026.6.34 of 9See more

bdba blackduck 2026.6.3

4 of the 9 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
blackducksoftware/bdba-pgupgrader:2026.6.35c97f3a3f8b7
stdlib@go1.18.2
1.25.12
library/postgres:15.18-bookworme8db9bd3e9e1
stdlib@go1.24.6
1.25.12
library/rabbitmq:4.2.87561d672fae4
stdlib@go1.22.2
1.25.12
versity/versitygw:v1.6.0d6ec798f66ca
stdlib@go1.26.4
1.25.12

Open the chart page →

9,667
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert-db:8.4.06310fac39d53
stdlib@go1.24.6
1.25.12

Open the chart page →

4,297
firehoseblip-firehoseVerified publisher0.0.183 of 11See more

firehose blip-firehose 0.0.18

3 of the 11 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
blipai/deckard:0.0.28737d5d19a312
stdlib@go1.18.10
1.25.12
hashicorp/vault:1.15.26b4e5dadf082
stdlib@go1.21.3
1.25.12
hashicorp/vault-k8s:1.3.15d74a885ae3e
stdlib@go1.21.3
1.25.12

Open the chart page →

13,517
blob-csi-driverblob-csi-driverVerified publisher1.27.91 of 5See more

blob-csi-driver blob-csi-driver 1.27.9

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/blob-csi:v1.27.9f9e20264150a
stdlib@go1.26.4
1.25.12

Open the chart page →

791
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.25.12

Open the chart page →

15,302
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-nti:logc947c3629371
stdlib@go1.23.12
1.25.12

Open the chart page →

27,215
csi-driver-nfsbook-k8sinfra-v24.12.16 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

6 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
stdlib@go1.24.6
1.25.12
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.25.12
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
stdlib@go1.24.2
1.25.12
registry.k8s.io/sig-storage/csi-snapshotter:v8.3.0bc7be893ecc3
stdlib@go1.24.2
1.25.12
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
stdlib@go1.24.6
1.25.12
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.12

Open the chart page →

6,289
grafanabook-k8sinfra-v28.8.21 of 1See more

grafana book-k8sinfra-v2 8.8.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
stdlib@go1.23.1
1.25.12

Open the chart page →

1,808
jaegerbook-k8sinfra-v23.4.04 of 5See more

jaeger book-k8sinfra-v2 3.4.0

4 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
stdlib@go1.21.5
1.25.12
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.25.12
jaegertracing/jaeger-collector:1.53.07f1269222903
stdlib@go1.21.5
1.25.12
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
stdlib@go1.21.5
1.25.12

Open the chart page →

19,311
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
stdlib@go1.21.8
1.25.12

Open the chart page →

8,339
kube-prometheus-stackbook-k8sinfra-v265.5.15 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

5 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:11.2.2-security-01464eac539793
stdlib@go1.22.7
1.25.12
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
stdlib@go1.23.2
1.25.12
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.12
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
stdlib@go1.19.4
1.25.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.12

Open the chart page →

6,044
metallbbook-k8sinfra-v20.13.102 of 3See more

metallb book-k8sinfra-v2 0.13.10

2 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
stdlib@go1.19.5
1.25.12
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
stdlib@go1.19.5
1.25.12

Open the chart page →

3,857
nfs-subdir-external-provisionerbook-k8sinfra-v24.0.181 of 1See more

nfs-subdir-external-provisioner book-k8sinfra-v2 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.12

Open the chart page →

2,745
prometheusbook-k8sinfra-v226.0.16 of 6See more

prometheus book-k8sinfra-v2 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
stdlib@go1.23.3
1.25.12
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
stdlib@go1.23.3
1.25.12
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.12
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.12
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
stdlib@go1.23.1
1.25.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
stdlib@go1.23.3
1.25.12

Open the chart page →

5,312
pyroscopebook-k8sinfra-v21.10.03 of 3See more

pyroscope book-k8sinfra-v2 1.10.0

3 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/alloy:v1.1.1c3dac4e26471
stdlib@go1.22.3
1.25.12
grafana/pyroscope:1.10.0319bf32ae06b
stdlib@go1.22.7
1.25.12
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.12

Open the chart page →

3,257
redisbook-k8sinfra-v21.0.01 of 1See more

redis book-k8sinfra-v2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.25.12

Open the chart page →

1,731
tempobook-k8sinfra-v21.10.31 of 1See more

tempo book-k8sinfra-v2 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/tempo:2.5.0f0200a9bff6d
stdlib@go1.21.3
1.25.12

Open the chart page →

1,867
boundary-softsciboundary-softsci0.2.41 of 1See more

boundary-softsci boundary-softsci 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
hashicorp/boundary:latest76a201954ca0
stdlib@go1.25.7
1.25.12

Open the chart page →

734
branchdbbranch-dbVerified publisher0.1.42 of 3See more

branchdb branch-db 0.1.4

2 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/masucchi/branchdb:0.1.47ea1820c1da1
stdlib@go1.26.4
1.25.12
ghcr.io/masucchi/branchdb-operator:0.1.4c16578615a43
stdlib@go1.26.4
1.25.12

Open the chart page →

517
bitmagnetbrandan-schmitz-helm-chartsVerified publisher1.0.62 of 2See more

bitmagnet brandan-schmitz-helm-charts 1.0.6

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.12
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
stdlib@go1.23.6
1.25.12

Open the chart page →

1,721
Filebrowserbrandan-schmitz-helm-chartsVerified publisher1.3.11 of 1See more

Filebrowser brandan-schmitz-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.63.15-s6dbac07403040
stdlib@go1.26.4
1.25.12

Open the chart page →

995
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

20,242
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

20,242
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

20,242
tautullibryanalves0.1.01 of 1See more

tautulli bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
tautulli/tautulli:latest670e68dd9efc
stdlib@go1.24.4
1.25.12

Open the chart page →

1,929
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
stdlib@go1.24.3
1.25.12

Open the chart page →

14,513
buildkitbuildkit0.1.01 of 1See more

buildkit buildkit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
moby/buildkit:master-rootless07115a67cd22
stdlib@go1.25.7
1.25.12

Open the chart page →

620
buildkit-privilegedbuildkit-privileged0.1.01 of 1See more

buildkit-privileged buildkit-privileged 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
moby/buildkit:masterbc964521ee58
stdlib@go1.25.7
1.25.12

Open the chart page →

403
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.24.6
1.25.12

Open the chart page →

11,958
butane-operatorbutane-operatorVerified publisher0.3.02 of 2See more

butane-operator butane-operator 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/naval-group/butane-operator:v0.1.1-rc285818b510780
stdlib@go1.26.0
1.25.12
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
stdlib@go1.21.7
1.25.12

Open the chart page →

1,403
butlercibutlerciVerified publisher0.1.01 of 1See more

butlerci butlerci 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
etejeda/butlerci:0.1.0737d58183abc
stdlib@go1.16.3
1.25.12

Open the chart page →

2,374
accelerationbuttahtoastVerified publisher0.1.01 of 1See more

acceleration buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
goharbor/harbor-acceld:0.2.13451103a6c8d8
stdlib@go1.21.5
1.25.12

Open the chart page →

1,408
fluobuttahtoastVerified publisher0.1.01 of 1See more

fluo buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
stdlib@go1.20.6
1.25.12

Open the chart page →

1,298
kubermatic-operatorbuttahtoastVerified publisher2.24.51 of 1See more

kubermatic-operator buttahtoast 2.24.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
stdlib@go1.20.6
1.25.12

Open the chart page →

2,781
kubevirt-managerbuttahtoastVerified publisher0.1.31 of 1See more

kubevirt-manager buttahtoast 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
stdlib@go1.21.7
1.25.12

Open the chart page →

1,497
mariadbbysamioVerified publisher1.0.21 of 1See more

mariadb bysamio 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mariadb:12.0.2607835cd628b
stdlib@go1.24.6
1.25.12

Open the chart page →

2,948
miniobysamioVerified publisher1.0.31 of 1See more

minio bysamio 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
stdlib@go1.24.6
1.25.12

Open the chart page →

1,084
payloadboxbyteforkVerified publisher0.0.41 of 1See more

payloadbox bytefork 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/bytefork/payloadbox:0.0.73e0164e975b3
stdlib@go1.26.3
1.25.12

Open the chart page →

88
caddycaddyVerified publisher0.0.41 of 1See more

caddy caddy 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/caddy:2.11.2-alpine834468128c76
stdlib@go1.26.0
1.25.12

Open the chart page →

1,684
etcdcagriekinVerified publisher0.1.51 of 1See more

etcd cagriekin 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.16d967d98a12dc
stdlib@go1.22.7
1.25.12

Open the chart page →

899
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.9.04150e46b2e96
stdlib@go1.24.0
1.25.12

Open the chart page →

2,399
rediscagriekinVerified publisher1.5.21 of 2See more

redis cagriekin 1.5.2

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.67.0120f7ec77293
stdlib@go1.23.4
1.25.12

Open the chart page →

1,394
ct-singlecalltelemetry0.8.44 of 7See more

ct-single calltelemetry 0.8.4

4 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.25.12
natsio/nats-box:0.11.09fbf7bf684e4
stdlib@go1.18.1
1.25.12
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.25.12
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.25.12

Open the chart page →

10,661
stablecalltelemetry0.7.14 of 9See more

stable calltelemetry 0.7.1

4 of the 9 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.25.12
natsio/nats-box:0.11.09fbf7bf684e4
stdlib@go1.18.1
1.25.12
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.25.12
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.25.12

Open the chart page →

7,702

Container images carrying it

4,913 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.25.12
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
stdlib@go1.18
1.25.12
2
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
stdlib@go1.16.6
1.25.12
2
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
stdlib@go1.19.2
1.25.12
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
stdlib@go1.16.2
1.25.12
2
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
stdlib@go1.21.10
1.25.12
2
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
stdlib@go1.26.4
1.25.12
2
ghcr.io/fluxcd/helm-controller:v1.6.2e17ab0e5885d
stdlib@go1.26.4
1.25.12
2
ghcr.io/fluxcd/source-controller:v1.9.22b8d06650a1b
stdlib@go1.26.4
1.25.12
2
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
stdlib@go1.25.0
1.25.12
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
stdlib@go1.22.5
1.25.12
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
stdlib@go1.23.6
1.25.12
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.25.12
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.476a2170cd0c9
stdlib@go1.26.4
1.25.12
2
ghcr.io/jkroepke/kube-webhook-certgen:1.7.47a62bba56a7c
stdlib@go1.25.5
1.25.12
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.38ce13c365c8e
stdlib@go1.26.3
1.25.12
2
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
stdlib@go1.24.11
1.25.12
2
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
stdlib@go1.23.4
1.25.12
2
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
stdlib@go1.23.3
1.25.12
2
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
stdlib@go1.23.3
1.25.12
2
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
stdlib@go1.23.3
1.25.12
2
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
stdlib@go1.25.7
1.25.12
2
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
stdlib@go1.24.4
1.25.12
2
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
stdlib@go1.24.4
1.25.12
2
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
stdlib@go1.20.14
1.25.12
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
stdlib@go1.24.5
1.25.12
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
stdlib@go1.24.5
1.25.12
2
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
stdlib@go1.21.1
1.25.12
2
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
stdlib@go1.26.4
1.25.12
2
ghcr.io/projectcapsule/capsule-proxy:v0.14.17c90292e3172
stdlib@go1.26.4
1.25.12
2
ghcr.io/rabbitmq/messaging-topology-operator:1.19.124c4649ef3ef
stdlib@go1.25.9
1.25.12
2
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
stdlib@go1.18.10
1.25.12
2
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
stdlib@go1.19.7
1.25.12
2
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
stdlib@go1.19.13
1.25.12
2
ghcr.io/sigstore/fulcio:v1.8.8ef72cf56c64b
stdlib@go1.26.4
1.25.12
2
ghcr.io/sigstore/rekor/rekor-server:v1.5.4100d793d68d0
stdlib@go1.26.4
1.25.12
2
ghcr.io/sigstore/scaffolding/createcerts7f59f7c08d1a
stdlib@go1.25.0
1.25.12
2
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
stdlib@go1.19.3
1.25.12
2
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
stdlib@go1.24.0
1.25.12
2
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
stdlib@go1.25.3
1.25.12
2
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
stdlib@go1.20.2
1.25.12
2
ghcr.io/stakater/reloader:v1.4.190530cf462fa3
stdlib@go1.26.4
1.25.12
2
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.12
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
stdlib@go1.20.1
1.25.12
2
ghcr.io/victoriametrics/sync-job:v0.0.17b6f233532a85
stdlib@go1.26.4-X:jsonv2
1.25.12
2
ghcr.io/voyagermesh/echoserver:v20221109:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.25.12
2
ghcr.io/voyagermesh/gateway:v1.8.24237fd16a3cb
stdlib@go1.26.4
1.25.12
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
stdlib@go1.26.3
1.25.12
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
stdlib@go1.25.4
1.25.12
2
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.25.12
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.