StackRadar

CVE-2026-39822

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,362
of 17,828 indexed, latest versions
Container images
5,035
deployed by those charts
Fix available
1 of 1
affected package

Root escape via symlink plus trailing slash in os

Carried by container images the latest versions of 4,362 of 17,828 indexed charts deploy, on 5,035 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.125,035
OSV records
GO-2026-4970
Also known as
BIT-golang-2026-39822

Charts affected

4,362 by stars
ChartLatestAffected imagesRadar Score
spire-ha-agentspiffeVerified publisher0.3.21 of 2See more

spire-ha-agent spiffe 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-ha-agent:0.5.0307cf2d05afe
stdlib@go1.25.0
1.25.12

Open the chart page →

368
spire-identity-exchangespiffeVerified publisher0.2.22 of 3See more

spire-identity-exchange spiffe 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-identity-exchange-server:v0.5.0239bc70c1988
stdlib@go1.26.0
1.25.12
registry.k8s.io/kubectl:v1.31.099b37df34bc4
stdlib@go1.22.5
1.25.12

Open the chart page →

1,441
spiffile-operatorspiffile-operatorVerified publisher0.1.41 of 1See more

spiffile-operator spiffile-operator 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/petersr/spiffile-operator:0.1.4411070249287
stdlib@go1.26.4
1.25.12

Open the chart page →

81
spillwayspillwayVerified publisher0.4.41 of 1See more

spillway spillway 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/kroy-the-rabbit/spillway:0.4.48de556d3bda7
stdlib@go1.26.1
1.25.12

Open the chart page →

267
spinnakerspinnakerVerified publisher2.2.132 of 4See more

spinnaker spinnaker 2.2.13

2 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
stdlib@go1.15.5
1.25.12
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
stdlib@go1.13.5
1.25.12

Open the chart page →

6,878
spoolmanspoolmanVerified publisher0.2.61 of 1See more

spoolman spoolman 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.25.12

Open the chart page →

1,843
ocean-admission-controllerspot1.0.32 of 3See more

ocean-admission-controller spot 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
gcr.io/spotit-today/spot-ocean-admission-controller:0.1.64f634aeb31b8
stdlib@go1.24.13
1.25.12
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.12

Open the chart page →

773
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
stdlib@go1.24.13
1.25.12

Open the chart page →

50,457
ocean-vpaspot1.0.73 of 4See more

ocean-vpa spot 1.0.7

3 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
stdlib@go1.25.7
1.25.12
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
stdlib@go1.25.7
1.25.12
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
stdlib@go1.22.2
1.25.12

Open the chart page →

1,195
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
stdlib@go1.16.5
1.25.12

Open the chart page →

63,404
airflowsqream-chartsVerified publisher1.17.01 of 4See more

airflow sqream-charts 1.17.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/prometheus/statsd-exporter:v0.27.29ed70604d941
stdlib@go1.22.8
1.25.12

Open the chart page →

1,829
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
stdlib@go1.22.4
1.25.12

Open the chart page →

2,427
sqs-prometheus-exportersqs-prometheus-exporterVerified publisher2.0.31 of 1See more

sqs-prometheus-exporter sqs-prometheus-exporter 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/jmriebold/sqs-prometheus-exporter:1.1.07564828ab7cb
stdlib@go1.24.0
1.25.12

Open the chart page →

368
sqs-to-snssqs-to-sns2.0.151 of 1See more

sqs-to-sns sqs-to-sns 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
udhos/sqs-to-sns:2.0.15cf7979da82e1
stdlib@go1.26.3
1.25.12

Open the chart page →

951
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

20,350
sshpipersshpiperVerified publisher0.4.71 of 1See more

sshpiper sshpiper 0.4.7

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
farmer1992/sshpiperd:v1.5.4e0064b824403
stdlib@go1.26.3
1.25.12

Open the chart page →

190
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
stdlib@go1.18.9
1.25.12

Open the chart page →

70,029
ecr-cleanersstarcher0.1.1+d13a1ab1 of 1See more

ecr-cleaner sstarcher 0.1.1+d13a1ab

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
sstarcher/ecr-cleaner:0.1.12d43c390cb19
stdlib@go1.14.2
1.25.12

Open the chart page →

2,577
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
stdlib@go1.13.9
1.25.12

Open the chart page →

3,098
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
stdlib@go1.18.3
1.25.12

Open the chart page →

3,077
retail-store-sample-catalog-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-catalog-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-catalog:1.3.0b654b266fa32
stdlib@go1.24.6
1.25.12

Open the chart page →

773
stageset-controllerstageset-controllerOfficialVerified publisher2026.6.15+1543421 of 1See more

stageset-controller stageset-controller 2026.6.15+154342

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/metio/stageset-controller:2026.6.14234b66bb3319
stdlib@go1.26.4
1.25.12

Open the chart page →

313
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
stdlib@go1.16.6
1.25.12

Open the chart page →

28,628
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
stdlib@go1.17.5
1.25.12

Open the chart page →

2,090
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.12

Open the chart page →

2,545
k8scostoptimizerstakaterVerified publisher0.0.51 of 1See more

k8scostoptimizer stakater 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
stdlib@go1.17.8
1.25.12

Open the chart page →

1,410
konfiguratorstakaterVerified publisher0.1.391 of 1See more

konfigurator stakater 0.1.39

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
stakater/konfigurator:v0.1.393409565b1ef5
stdlib@go1.17.13
1.25.12

Open the chart page →

1,280
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.25.12

Open the chart page →

2,854
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
stdlib@go1.15.11
1.25.12

Open the chart page →

2,174
vaultstakaterVerified publisher0.8.42 of 2See more

vault stakater 0.8.4

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
stdlib@go1.16.7
1.25.12
hashicorp/vault-k8s:0.14.0aff47b5ba39c
stdlib@go1.17.2
1.25.12

Open the chart page →

5,874
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
stdlib@go1.13.1
1.25.12

Open the chart page →

2,566
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
stdlib@go1.16.13
1.25.12

Open the chart page →

6,696
stakefishstakefish0.1.06 of 8See more

stakefish stakefish 0.1.0

6 of the 8 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
stdlib@go1.22.3
1.25.12
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
stdlib@go1.22.2
1.25.12
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.12
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
stdlib@go1.22.2
1.25.12
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.25.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.12

Open the chart page →

20,481
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
stdlib@go1.22.12
1.25.12

Open the chart page →

2,992
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.12

Open the chart page →

1,263
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.25.12

Open the chart page →

4,113
mev-booststakewise1.7.41 of 1See more

mev-boost stakewise 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
flashbots/mev-boost:1.8.07c486b5789da
stdlib@go1.22.6
1.25.12

Open the chart page →

1,261
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
stdlib@go1.17.5
1.25.12

Open the chart page →

6,630
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
stdlib@go1.22.11
1.25.12

Open the chart page →

7,070
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.12

Open the chart page →

1,263
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
stdlib@go1.25.8
1.25.12

Open the chart page →

576
open-appsec-injectorstartechnicaVerified publisher1.1.22 of 3See more

open-appsec-injector startechnica 1.1.2

2 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/openappsec/smartsync:latest580d68c50cc7
stdlib@go1.18.10
1.25.12
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
stdlib@go1.18.10
1.25.12

Open the chart page →

4,362
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.25.12

Open the chart page →

14,673
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
stdlib@go1.18.4
1.25.12

Open the chart page →

1,986
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
stdlib@go1.16.1
1.25.12
prom/prometheus:v2.22.2f7ffebdd428b
stdlib@go1.15.5
1.25.12
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
stdlib@go1.16.5
1.25.12
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
stdlib@go1.16.5
1.25.12

Open the chart page →

16,546
fluentd-operatorstatcan0.5.11 of 1See more

fluentd-operator statcan 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
vmware/kube-fluentd-operator:latestf028c138a5f4
stdlib@go1.21.7
1.25.12

Open the chart page →

1,961
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
stdlib@go1.18.10
1.25.12

Open the chart page →

1,584
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
stdlib@go1.16.3
1.25.12

Open the chart page →

6,601
prometheus-operatorstatcan0.2.24 of 7See more

prometheus-operator statcan 0.2.2

4 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.12
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
stdlib@go1.13.11
1.25.12
squareup/ghostunnel:v1.5.270f4cf270425
stdlib@go1.13.4
1.25.12
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
stdlib@go1.14.3
1.25.12

Open the chart page →

12,257
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
stdlib@go1.19.10
1.25.12

Open the chart page →

1,316

Container images carrying it

5,035 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
stdlib@go1.20.14
1.25.12
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
stdlib@go1.25.7
1.25.12
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
stdlib@go1.25.7
1.25.12
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.25.12
1
registry.gitlab.com/gitlab-org/build/cng/cfssl-self-sign:v19.4.07757679afa1b
stdlib@go1.22.0
1.25.12
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
stdlib@go1.26.4
1.25.12
1
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
stdlib@go1.25.0
1.25.12
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
stdlib@go1.16.14
1.25.12
1
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.25448611a3c54
stdlib@go1.26.3
1.25.12
1
registry.gitlab.com/lenitech/docker/keycloak-ppolicy:0.6.09895d6915075
stdlib@go1.25.7
1.25.12
1
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
stdlib@go1.24.5
1.25.12
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
stdlib@go1.21.0
1.25.12
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
stdlib@go1.15.15
1.25.12
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
stdlib@go1.25.7
1.25.12
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
stdlib@go1.25.7
1.25.12
1
registry.gitlab.com/xrow-public/ci-tools/kubectl:main9357cfeef63c
stdlib@go1.24.9
1.25.12
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
stdlib@go1.26.4
1.25.12
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
stdlib@go1.24.5
1.25.12
1
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.25.12
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.93.006a950310ecd
stdlib@go1.26.2
1.25.12
1
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
stdlib@go1.26.4
1.25.12
1
registry.k8s.io/agent-sandbox/sandbox-router-go:v1.0.125b1a0939630
stdlib@go1.26.2
1.25.12
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
stdlib@go1.24.4
1.25.12
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
stdlib@go1.24.7
1.25.12
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.4.171d817780aa9
stdlib@go1.24.3
1.25.12
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
stdlib@go1.25.7
1.25.12
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
stdlib@go1.24.6
1.25.12
1
registry.k8s.io/autoscaling/vpa-recommender:1.4.140b6d76e8526
stdlib@go1.24.3
1.25.12
1
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
stdlib@go1.24.6
1.25.12
1
registry.k8s.io/autoscaling/vpa-updater:1.4.18ebf269779c1
stdlib@go1.24.3
1.25.12
1
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
stdlib@go1.25.7
1.25.12
1
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
stdlib@go1.24.6
1.25.12
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
stdlib@go1.20.7
1.25.12
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
stdlib@go1.23.0
1.25.12
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
stdlib@go1.25.5
1.25.12
1
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
stdlib@go1.24.4
1.25.12
1
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
stdlib@go1.22.12
1.25.12
1
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
stdlib@go1.22.12
1.25.12
1
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
stdlib@go1.24.4
1.25.12
1
registry.k8s.io/descheduler/descheduler:v0.36.07ca92c0a7b4f
stdlib@go1.26.0
1.25.12
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
stdlib@go1.21.7
1.25.12
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
stdlib@go1.24.8
1.25.12
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
stdlib@go1.22.3
1.25.12
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
stdlib@go1.18.3
1.25.12
1
registry.k8s.io/etcd:3.6.4-0e36c08168342
stdlib@go1.23.11
1.25.12
1
registry.k8s.io/gateway-api/admission-server:v0.7.1fe43ee5176a8
stdlib@go1.19.9
1.25.12
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
stdlib@go1.25.1
1.25.12
1
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
stdlib@go1.20.6
1.25.12
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
stdlib@go1.20.10
1.25.12
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
stdlib@go1.19.4
1.25.12
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.