StackRadar

CVE-2026-39822

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,226
of 17,790 indexed, latest versions
Container images
4,913
deployed by those charts
Fix available
1 of 1
affected package

Root escape via symlink plus trailing slash in os

Carried by container images the latest versions of 4,226 of 17,790 indexed charts deploy, on 4,913 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+186 more1.25.124,913
OSV records
GO-2026-4970
Also known as
BIT-golang-2026-39822

Charts affected

4,226 by stars
ChartLatestAffected imagesRadar Score
goweeklygoweekly2.0.01 of 1See more

goweekly goweekly 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
zufardhiyaulhaq/goweekly:v2.0.008dcc130fbea
stdlib@go1.17.12
1.25.12

Open the chart page →

1,229
harborgpg-dev1.18.35 of 8See more

harbor gpg-dev 1.18.3

5 of the 8 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.14.3a30e5a8be3d9
stdlib@go1.24.13
1.25.12
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
stdlib@go1.24.13
1.25.12
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
stdlib@go1.24.13
1.25.12
goharbor/registry-photon:v2.14.36533fc396cbc
stdlib@go1.24.13
1.25.12
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
stdlib@go1.25.7
1.25.12

Open the chart page →

3,406
ingress-nginxgpg-dev4.9.02 of 2See more

ingress-nginx gpg-dev 4.9.0

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
stdlib@go1.21.5
1.25.12
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
stdlib@go1.21.3
1.25.12

Open the chart page →

2,316
jaegergpg-dev3.3.34 of 5See more

jaeger gpg-dev 3.3.3

4 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
stdlib@go1.21.5
1.25.12
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.25.12
jaegertracing/jaeger-collector:1.53.07f1269222903
stdlib@go1.21.5
1.25.12
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
stdlib@go1.21.5
1.25.12

Open the chart page →

19,311
kube-prometheus-stackgpg-dev84.0.05 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

5 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:13.0.10f86bada30d6
stdlib@go1.26.0
1.25.12
ghcr.io/jkroepke/kube-webhook-certgen:1.8.14f6da0256b1b
stdlib@go1.26.2
1.25.12
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
stdlib@go1.25.8
1.25.12
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
stdlib@go1.26.1
1.25.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.12

Open the chart page →

4,303
kubernetes-dashboardgpg-dev7.5.04 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

4 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
kubernetesui/dashboard-api:1.7.060595892c2cf
stdlib@go1.22.3
1.25.12
kubernetesui/dashboard-auth:1.1.307135c09e9ff
stdlib@go1.22.2
1.25.12
kubernetesui/dashboard-metrics-scraper:1.1.17747d363c9fe
stdlib@go1.22.1
1.25.12
kubernetesui/dashboard-web:1.4.04445b31a2c25
stdlib@go1.22.3
1.25.12

Open the chart page →

6,078
metrics-servergpg-dev3.12.11 of 1See more

metrics-server gpg-dev 3.12.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
stdlib@go1.21.8
1.25.12

Open the chart page →

1,078
opentelemetry-demogpg-dev0.33.88 of 27See more

opentelemetry-demo gpg-dev 0.33.8

8 of the 27 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
stdlib@go1.23.1
1.25.12
jaegertracing/all-in-one:1.53.060e65bfffe1f
stdlib@go1.21.5
1.25.12
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
stdlib@go1.23.3
1.25.12
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
stdlib@go1.22.5
1.25.12
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
stdlib@go1.22.8
1.25.12
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
stdlib@go1.22.8
1.25.12
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
stdlib@go1.21.5
1.25.12
quay.io/prometheus/prometheus:v3.0.03b9b2a15d376
stdlib@go1.23.3
1.25.12

Open the chart page →

49,362
prometheusgpg-dev29.2.16 of 6See more

prometheus gpg-dev 29.2.1

6 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.90.1693faa0b8724
stdlib@go1.25.8
1.25.12
quay.io/prometheus/alertmanager:v0.32.058e117eabcce
stdlib@go1.26.2
1.25.12
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
stdlib@go1.26.1
1.25.12
quay.io/prometheus/prometheus:v3.11.2cd37346c9745
stdlib@go1.26.2
1.25.12
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
stdlib@go1.25.3
1.25.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.12

Open the chart page →

3,281
prometheus-operator-admission-webhookgpg-dev0.18.12 of 2See more

prometheus-operator-admission-webhook gpg-dev 0.18.1

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/admission-webhook:v0.79.2d4c97a1b2d67
stdlib@go1.23.4
1.25.12
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
stdlib@go1.19.4
1.25.12

Open the chart page →

1,685
thanosgpg-dev0.5.31 of 1See more

thanos gpg-dev 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
thanosio/thanos:v0.41.0cf3e9b292e43
stdlib@go1.25.7
1.25.12

Open the chart page →

592
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
stdlib@go1.25.8
1.25.12

Open the chart page →

1,280
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
stdlib@go1.25.7
1.25.12

Open the chart page →

1,562
whoami-demogpg-dev0.1.01 of 1See more

whoami-demo gpg-dev 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.25.12

Open the chart page →

1,280
cloudcost-exportergrafana1.1.131 of 1See more

cloudcost-exporter grafana 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/cloudcost-exporter:v1.12.0eeb2cfecb23e
stdlib@go1.26.4
1.25.12

Open the chart page →

160
grafana-cloud-onboardinggrafana0.4.75 of 5See more

grafana-cloud-onboarding grafana 0.4.7

5 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/beyla-k8s-cache:253b2f561cb1b
stdlib@go1.25.3
1.25.12
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
stdlib@go1.25.8
1.25.12
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
stdlib@go1.23.6
1.25.12
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
stdlib@go1.26.1
1.25.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.12

Open the chart page →

4,681
grafana-samplinggrafana1.1.72 of 2See more

grafana-sampling grafana 1.1.7

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
stdlib@go1.24.6
1.25.12
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
stdlib@go1.23.7
1.25.12

Open the chart page →

3,370
mimir-openshift-experimentalgrafana2.1.03 of 4See more

mimir-openshift-experimental grafana 2.1.0

3 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
stdlib@go1.17.8
1.25.12
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
stdlib@go1.15.7
1.25.12
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
stdlib@go1.15.7
1.25.12

Open the chart page →

17,780
pyroscope-monitoringgrafana0.1.15 of 6See more

pyroscope-monitoring grafana 0.1.1

5 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
stdlib@go1.24.6
1.25.12
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
stdlib@go1.24.5
1.25.12
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
stdlib@go1.23.6
1.25.12
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
stdlib@go1.23.7
1.25.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
stdlib@go1.24.6
1.25.12

Open the chart page →

8,269
snyk-exportergrafana0.1.01 of 1See more

snyk-exporter grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/snyk_exporter:v1.4.1d3c9093401ca
stdlib@go1.21.0
1.25.12

Open the chart page →

669
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
stdlib@go1.23.3
1.25.12
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
stdlib@go1.23.3
1.25.12
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.12
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.12
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
stdlib@go1.23.1
1.25.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
stdlib@go1.23.3
1.25.12

Open the chart page →

5,312
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
stdlib@go1.13.10
1.25.12

Open the chart page →

7,519
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
stdlib@go1.18.10
1.25.12

Open the chart page →

7,956
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:85211c51171f5
stdlib@go1.24.6
1.25.12

Open the chart page →

5,347
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
stdlib@go1.21.10
1.25.12

Open the chart page →

1,398
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
stdlib@go1.15.2
1.25.12

Open the chart page →

14,327
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
stdlib@go1.22.7
1.25.12

Open the chart page →

2,598
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
stdlib@go1.17.13
1.25.12

Open the chart page →

2,182
routergroundcover1.12.3624 of 7See more

router groundcover 1.12.362

4 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
stdlib@go1.26.3
1.25.12
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
stdlib@go1.25.7
1.25.12
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
stdlib@go1.25.7
1.25.12
quay.io/groundcover/tools:20260719b705e0cbe171
stdlib@go1.24.4
1.25.12

Open the chart page →

6,070
temporalgroundcover1.12.3621 of 2See more

temporal groundcover 1.12.362

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
stdlib@go1.26.3
1.25.12

Open the chart page →

2,027
mysqlgroundhog2k3.1.41 of 1See more

mysql groundhog2k 3.1.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
stdlib@go1.24.6
1.25.12

Open the chart page →

463
tailscale-subnet-routergtaylor1.2.11 of 1See more

tailscale-subnet-router gtaylor 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
stdlib@go1.19.2-ts3fd24dee31
1.25.12

Open the chart page →

1,834
minifluxhajowielandVerified publisher1.0.01 of 1See more

miniflux hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
stdlib@go1.24.2
1.25.12

Open the chart page →

1,113
hakoniwahakoniwa0.1.01 of 1See more

hakoniwa hakoniwa 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/aplulu/hakoniwa:0.1.0accf0b921388
stdlib@go1.25.5
1.25.12

Open the chart page →

338
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
stdlib@go1.13.7
1.25.12

Open the chart page →

2,381
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
stdlib@go1.16.3
1.25.12

Open the chart page →

4,462
mautrix-signalhalkeye0.3.01 of 2See more

mautrix-signal halkeye 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
signald/signald:0.23.2edbff058278c
stdlib@go1.18.10
1.25.12

Open the chart page →

1,500
thunderdome-planning-pokerhalkeye0.1.11 of 1See more

thunderdome-planning-poker halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
stdlib@go1.26.4
1.25.12

Open the chart page →

425
whoamihalkeye1.0.11 of 1See more

whoami halkeye 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
containous/whoami:v1.5.07d6a3c8f9147
stdlib@go1.14
1.25.12

Open the chart page →

1,280
hcp-terraform-operatorhashicorpVerified publisher2.12.11 of 2See more

hcp-terraform-operator hashicorp 2.12.1

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.20.1f5fbfec6a2b2
stdlib@go1.25.4
1.25.12

Open the chart page →

685
hatchet-apihatchetOfficialVerified publisher0.19.01 of 4See more

hatchet-api hatchet 0.19.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.12

Open the chart page →

1,689
hatchet-hahatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-ha hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.12

Open the chart page →

7,407
hatchet-stackhatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-stack hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.12

Open the chart page →

7,407
hawk-envoy-pluginhawk0.1.02 of 4See more

hawk-envoy-plugin hawk 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/collector-go:main7217f1a4fa28
stdlib@go1.17.13
1.25.12
ghcr.io/privacyengineering/consumer:main73f59c032812
stdlib@go1.17.13
1.25.12

Open the chart page →

9,178
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
stdlib@go1.15.6
1.25.12

Open the chart page →

3,029
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
stdlib@go1.14.7
1.25.12

Open the chart page →

2,637
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.25.12

Open the chart page →

6,751
headcniheadcni1.0.101 of 1See more

headcni headcni 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
binrc/headcni:1.0.10e199c334b957
stdlib@go1.22.10
1.25.12

Open the chart page →

724
heliconehelicone0.1.422 of 14See more

helicone helicone 0.1.42

2 of the 14 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
stdlib@go1.19.5
1.25.12
supabase/gotrue:v2.91.07174d551d720
stdlib@go1.20.7
1.25.12

Open the chart page →

25,183
hello-gohello-goVerified publisher0.2.21 of 1See more

hello-go hello-go 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.25.12

Open the chart page →

1,315

Container images carrying it

4,913 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.12
6
library/registry:2:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.25.12
6
minio/mc:latest:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
stdlib@go1.24.6
1.25.12
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
stdlib@go1.18.2
1.25.12
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.25.12
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
stdlib@go1.16.6
1.25.12
6
quay.io/devtron/kubectl:latest2ad610626658
stdlib@go1.18.5
1.25.12
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
stdlib@go1.19.9
1.25.12
6
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.25.12
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
stdlib@go1.17.6
1.25.12
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.25.12
6
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
stdlib@go1.26.1
1.25.12
6
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
stdlib@go1.25.3
1.25.12
6
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.25.12
6
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
stdlib@go1.23.7
1.25.12
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
stdlib@go1.23.3
1.25.12
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.12
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.12
6
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
stdlib@go1.26.3
1.25.12
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0:v2.8.1f6717ce72a26
stdlib@go1.20.3
1.25.12
6
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.25.12
6
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
stdlib@go1.26.3
1.25.12
6
alpine/kubectl:1.34.18413f8890d19
stdlib@go1.24.6
1.25.12
5
bitnamilegacy/kubectl:1.29.2c74b703deed2
stdlib@go1.21.7
1.25.12
5
containous/whoami:latest:v1.5.07d6a3c8f9147
stdlib@go1.14
1.25.12
5
keelhq/keel:latest73714afb4443
stdlib@go1.23.4
1.25.12
5
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.25.12
5
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.25.12
5
library/redis:7.4.2-alpine:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.25.12
5
library/redis:5:5.0fc5ecd863862
stdlib@go1.16.7
1.25.12
5
natsio/nats-box:0.14.1a67913df95f1
stdlib@go1.21.3
1.25.12
5
outcoldsolutions/collectorforkubernetes:26.04.457973ff65b5b
stdlib@go1.26.4
1.25.12
5
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.12
5
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.25.12
5
prom/memcached-exporter:v0.15.4b6763ecb3c47
stdlib@go1.25.3
1.25.12
5
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.25.12
5
sigma2as/goidc-proxy:next656ac798963a
stdlib@go1.25.7
1.25.12
5
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.12
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
stdlib@go1.24.2
1.25.12
5
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.25.12
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
stdlib@go1.16.7
1.25.12
5
quay.io/prometheus/blackbox-exporter:latest:v0.28.0e753ff9f3fc4
stdlib@go1.25.5
1.25.12
5
quay.io/prometheus/pushgateway:v1.11.374fa117cef2d
stdlib@go1.26.3
1.25.12
5
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
stdlib@go1.26.1
1.25.12
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
stdlib@go1.26.1
1.25.12
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.25.12
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
stdlib@go1.21.3
1.25.12
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.12
5
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
stdlib@go1.25.7
1.25.12
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
stdlib@go1.16.2
1.25.12
5

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.