StackRadar

CVE-2026-39822

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,215
of 17,803 indexed, latest versions
Container images
4,896
deployed by those charts
Fix available
1 of 1
affected package

Root escape via symlink plus trailing slash in os

Carried by container images the latest versions of 4,215 of 17,803 indexed charts deploy, on 4,896 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+187 more1.25.124,896
OSV records
GO-2026-4970
Also known as
BIT-golang-2026-39822

Charts affected

4,215 by stars
ChartLatestAffected imagesRadar Score
qantas-apiqantas-helm0.1.01 of 3See more

qantas-api qantas-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.12

Open the chart page →

1,686
open-terminalqaoruVerified publisher0.2.41 of 1See more

open-terminal qaoru 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/open-webui/open-terminal:0.13.0-slimdec44673c865
stdlib@go1.24.4
1.25.12

Open the chart page →

2,075
unifiqaoruVerified publisher1.1.31 of 2See more

unifi qaoru 1.1.3

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:7.0-jammy84c4a18b60a0
stdlib@go1.24.6
1.25.12

Open the chart page →

3,487
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
stdlib@go1.13.3
1.25.12
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
stdlib@go1.13.4
1.25.12

Open the chart page →

11,956
quarksquarks7.0.1+0.g5396b114 of 5See more

quarks quarks 7.0.1+0.g5396b11

4 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
stdlib@go1.14.7
1.25.12
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
stdlib@go1.13.15
1.25.12
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
stdlib@go1.14.7
1.25.12
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
stdlib@go1.14.7
1.25.12

Open the chart page →

18,202
quarks-statefulsetquarks0.0.1304-g4b4f2ac51 of 1See more

quarks-statefulset quarks 0.0.1304-g4b4f2ac5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
stdlib@go1.14.7
1.25.12

Open the chart page →

4,011
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/loki:3.3.28af2de1abbdd
stdlib@go1.23.4
1.25.12

Open the chart page →

4,515
ingress-controllerqumine0.8.5001 of 1See more

ingress-controller qumine 0.8.500

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
qumine/ingress-controller:v0.8.5f2c8a2148381
stdlib@go1.19
1.25.12

Open the chart page →

1,533
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
stdlib@go1.19.8
1.25.12

Open the chart page →

7,847
rabbitpingrabbitping1.3.01 of 1See more

rabbitping rabbitping 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
udhos/rabbitping:1.3.0474c467bbf42
stdlib@go1.24.3
1.25.12

Open the chart page →

1,148
kubemirrorraczylo-comVerified publisher0.9.221 of 1See more

kubemirror raczylo-com 0.9.22

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/lukaszraczylo/kubemirror:0.9.2265f266df3289
stdlib@go1.26.4
1.25.12

Open the chart page →

74
rada-platformrada-platform0.1.02 of 7See more

rada-platform rada-platform 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
stdlib@go1.22.7
1.25.12
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
stdlib@go1.20.6
1.25.12

Open the chart page →

21,370
cloudnative-pgradar-baseVerified publisher0.23.21 of 1See more

cloudnative-pg radar-base 0.23.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
stdlib@go1.24.0
1.25.12

Open the chart page →

856
headlampradar-baseVerified publisher1.0.01 of 1See more

headlamp radar-base 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.43.05d03caa26df7
stdlib@go1.26.3
1.25.12

Open the chart page →

656
hydraradar-baseVerified publisher0.48.01 of 1See more

hydra radar-base 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
oryd/hydra:v2.2.02c93beb5e5f2
stdlib@go1.21.5
1.25.12

Open the chart page →

1,541
kratosradar-baseVerified publisher0.43.11 of 1See more

kratos radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
oryd/kratos:v1.1.08f15006a080d
stdlib@go1.21.5
1.25.12

Open the chart page →

1,793
kubecostradar-baseVerified publisher1.0.03 of 7See more

kubecost radar-base 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
stdlib@go1.23.1
1.25.12
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
stdlib@go1.23.4
1.25.12
quay.io/prometheus/prometheus:v3.2.05888c188cf09
stdlib@go1.23.6
1.25.12

Open the chart page →

9,625
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
stdlib@go1.26.2
1.25.12

Open the chart page →

3,236
nginx-gateway-fabricradar-baseVerified publisher2.6.61 of 1See more

nginx-gateway-fabric radar-base 2.6.6

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/nginx/nginx-gateway-fabric:2.6.6c10f734589e9
stdlib@go1.26.4
1.25.12

Open the chart page →

132
nifikopradar-baseVerified publisher1.14.11 of 1See more

nifikop radar-base 1.14.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
stdlib@go1.24.4
1.25.12

Open the chart page →

512
radar-grafanaradar-baseVerified publisher0.1.41 of 2See more

radar-grafana radar-base 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:11.6.062d2b9d20a19
stdlib@go1.23.7
1.25.12

Open the chart page →

1,836
radar-hydraradar-baseVerified publisher0.3.41 of 2See more

radar-hydra radar-base 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
oryd/hydra:v2.3.0b94007e19a1f
stdlib@go1.23.4
1.25.12

Open the chart page →

2,196
radar-kratosradar-baseVerified publisher0.1.51 of 1See more

radar-kratos radar-base 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
oryd/kratos:v1.3.1fe2428f103a6
stdlib@go1.23.2
1.25.12

Open the chart page →

1,578
radar-nifiradar-baseVerified publisher3.1.01 of 1See more

radar-nifi radar-base 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
stdlib@go1.24.4
1.25.12

Open the chart page →

512
radar-redisradar-baseVerified publisher1.3.01 of 1See more

radar-redis radar-base 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/opstree/redis-operator:v0.22.2464ac61a6eb4
stdlib@go1.23.12
1.25.12

Open the chart page →

412
redis-operatorradar-baseVerified publisher0.22.21 of 1See more

redis-operator radar-base 0.22.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/opstree/redis-operator:v0.22.2464ac61a6eb4
stdlib@go1.23.12
1.25.12

Open the chart page →

412
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
stdlib@go1.26.4
1.25.12

Open the chart page →

1,954
pagesranjinigogga1.0.01 of 3See more

pages ranjinigogga 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

20,261
raven_profilerraven-profilerVerified publisher0.1.621 of 1See more

raven_profiler raven-profiler 0.1.62

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
public.ecr.aws/t0u0d5o5/ecr_authenticator:latest077e4e57e41c
stdlib@go1.21.5
1.25.12

Open the chart page →

1,301
rawfile-localpvrawfile0.15.35 of 6See more

rawfile-localpv rawfile 0.15.3

5 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
stdlib@go1.26.3
1.25.12
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.25.12
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
stdlib@go1.26.3
1.25.12
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
stdlib@go1.26.3
1.25.12
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
stdlib@go1.26.3
1.25.12

Open the chart page →

2,772
aws-ec2-runtime-checkerrayselfs-chartsVerified publisher0.1.41 of 1See more

aws-ec2-runtime-checker rayselfs-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
rayselfs/aws-ec2-runtime-checker:v0.1.5562e5b2f81ce
stdlib@go1.24.11
1.25.12

Open the chart page →

292
thanosrayselfs-chartsVerified publisher0.1.51 of 1See more

thanos rayselfs-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.40.1aae7b2b030ed
stdlib@go1.25.3
1.25.12

Open the chart page →

767
saleorrc-helm-charts0.1.11 of 5See more

saleor rc-helm-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.22.0ca6b73330616
stdlib@go1.15.8
1.25.12

Open the chart page →

3,746
pagesrebecca-pages1.0.01 of 3See more

pages rebecca-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

20,261
recipe-apprecipe-app0.1.01 of 2See more

recipe-app recipe-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
stdlib@go1.20.12
1.25.12

Open the chart page →

3,568
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
sharanalwar/redchef-frontend:latest5e82950b16b7
stdlib@go1.23.7
1.25.12

Open the chart page →

4,956
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
stdlib@go1.15.14
1.25.12

Open the chart page →

15,300
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
stdlib@go1.15.14
1.25.12

Open the chart page →

15,300
etherpadredhat-cop0.0.81 of 1See more

etherpad redhat-cop 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
etherpad/etherpad:latest6020e7b57f4b
stdlib@go1.26.4
1.25.12

Open the chart page →

908
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
stdlib@go1.15.14
1.25.12

Open the chart page →

11,447
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
stdlib@go1.21.3
1.25.12

Open the chart page →

16,391
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
stdlib@go1.16
1.25.12

Open the chart page →

29,584
redirectorredirectorVerified publisher0.0.31 of 1See more

redirector redirector 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/chilledornaments/redirector:latest94d48447d967
stdlib@go1.26.4
1.25.12

Open the chart page →

74
redisredis-arm17.8.01 of 1See more

redis redis-arm 17.8.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/zcube/bitnami-compat/redis:7.0-debian-11-r55118a403046f7
stdlib@go1.19.4
1.25.12

Open the chart page →

1,906
redis-enforce-expireredis-enforce-expire1.0.01 of 1See more

redis-enforce-expire redis-enforce-expire 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
udhos/redis-enforce-expire:1.0.0615b6a7d742e
stdlib@go1.26.1
1.25.12

Open the chart page →

1,296
registry-credsregistry-creds0.2.31 of 1See more

registry-creds registry-creds 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/alexellis/registry-creds:0.3.2-rc1f5c72501e559
stdlib@go1.19.5
1.25.12

Open the chart page →

1,042
regoregoOfficialVerified publisher0.1.31 of 1See more

rego rego 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
drorivry4/rego:lateste035d49b15ca
stdlib@go1.22.0
1.25.12

Open the chart page →

2,967
longhornrelease-longhorn1.12.03 of 3See more

longhorn release-longhorn 1.12.0

3 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.12.0fd245bae2e82
stdlib@go1.25.10
1.25.12
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
stdlib@go1.26.3
1.25.12
longhornio/longhorn-ui:v1.12.03870d52a2b0a
stdlib@go1.25.10
1.25.12

Open the chart page →

1,602
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
stdlib@go1.21.9
1.25.12

Open the chart page →

6,356
reporting-chartreporting-application0.1.01 of 1See more

reporting-chart reporting-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ibarreche/cloud-reporting-ci:latest1f45af91da6a
stdlib@go1.16.15
1.25.12

Open the chart page →

1,585

Container images carrying it

4,896 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.25.12
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
stdlib@go1.18
1.25.12
2
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
stdlib@go1.16.6
1.25.12
2
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
stdlib@go1.19.2
1.25.12
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
stdlib@go1.16.2
1.25.12
2
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
stdlib@go1.21.10
1.25.12
2
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
stdlib@go1.26.4
1.25.12
2
ghcr.io/fluxcd/helm-controller:v1.6.2e17ab0e5885d
stdlib@go1.26.4
1.25.12
2
ghcr.io/fluxcd/source-controller:v1.9.22b8d06650a1b
stdlib@go1.26.4
1.25.12
2
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
stdlib@go1.25.0
1.25.12
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
stdlib@go1.22.5
1.25.12
2
ghcr.io/gotify/server:3.1.144fc5bbd1c06
stdlib@go1.26.0
1.25.12
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
stdlib@go1.23.6
1.25.12
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.25.12
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.476a2170cd0c9
stdlib@go1.26.4
1.25.12
2
ghcr.io/jkroepke/kube-webhook-certgen:1.7.47a62bba56a7c
stdlib@go1.25.5
1.25.12
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.38ce13c365c8e
stdlib@go1.26.3
1.25.12
2
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
stdlib@go1.24.11
1.25.12
2
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
stdlib@go1.23.4
1.25.12
2
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
stdlib@go1.23.3
1.25.12
2
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
stdlib@go1.23.3
1.25.12
2
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
stdlib@go1.23.3
1.25.12
2
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
stdlib@go1.25.7
1.25.12
2
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
stdlib@go1.24.4
1.25.12
2
ghcr.io/libredb/libredb-studio:0.16.0fa925884368a
stdlib@go1.24.4
1.25.12
2
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
stdlib@go1.20.14
1.25.12
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
stdlib@go1.24.5
1.25.12
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
stdlib@go1.24.5
1.25.12
2
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
stdlib@go1.21.1
1.25.12
2
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
stdlib@go1.26.4
1.25.12
2
ghcr.io/projectcapsule/capsule-proxy:v0.14.17c90292e3172
stdlib@go1.26.4
1.25.12
2
ghcr.io/rabbitmq/messaging-topology-operator:1.19.124c4649ef3ef
stdlib@go1.25.9
1.25.12
2
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
stdlib@go1.18.10
1.25.12
2
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
stdlib@go1.19.7
1.25.12
2
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
stdlib@go1.19.13
1.25.12
2
ghcr.io/sigstore/fulcio:v1.8.8ef72cf56c64b
stdlib@go1.26.4
1.25.12
2
ghcr.io/sigstore/rekor/rekor-server:v1.5.4100d793d68d0
stdlib@go1.26.4
1.25.12
2
ghcr.io/sigstore/scaffolding/createcerts7f59f7c08d1a
stdlib@go1.25.0
1.25.12
2
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
stdlib@go1.19.3
1.25.12
2
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
stdlib@go1.24.0
1.25.12
2
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
stdlib@go1.25.3
1.25.12
2
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
stdlib@go1.20.2
1.25.12
2
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.12
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
stdlib@go1.20.1
1.25.12
2
ghcr.io/victoriametrics/sync-job:v0.0.17b6f233532a85
stdlib@go1.26.4-X:jsonv2
1.25.12
2
ghcr.io/voyagermesh/echoserver:v20221109:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.25.12
2
ghcr.io/voyagermesh/gateway:v1.8.24237fd16a3cb
stdlib@go1.26.4
1.25.12
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
stdlib@go1.26.3
1.25.12
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
stdlib@go1.25.4
1.25.12
2
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.25.12
2

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.