StackRadar

CVE-2026-39823

Medium

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,934
of 17,803 indexed, latest versions
Container images
4,529
deployed by those charts
Fix available
1 of 2
affected packages

Bypass of meta content URL escaping causes XSS in html/template

Carried by container images the latest versions of 3,934 of 17,803 indexed charts deploy, on 4,529 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,529
OSV records
DEBIAN-CVE-2026-39823GO-2026-4982
Also known as
BIT-golang-2026-39823

Charts affected

3,934 by stars
ChartLatestAffected imagesRadar Score
kubestashappscodeVerified publisher2026.7.102 of 2See more

kubestash appscode 2026.7.10

2 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.10

Open the chart page →

1,105
kubestash-certifiedappscodeVerified publisher2026.7.102 of 2See more

kubestash-certified appscode 2026.7.10

2 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.10

Open the chart page →

1,105
kubestash-operatorappscodeVerified publisher0.29.02 of 2See more

kubestash-operator appscode 0.29.0

2 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.10

Open the chart page →

1,105
kubevaultappscodeVerified publisher2026.8.71 of 2See more

kubevault appscode 2026.8.7

1 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

826
kubevault-certifiedappscodeVerified publisher2026.2.271 of 1See more

kubevault-certified appscode 2026.2.27

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/kubevault/vault-operator:v0.24.00087cb49616f
stdlib@go1.25.9
1.25.10

Open the chart page →

1,149
kubevault-webhook-serverappscodeVerified publisher0.25.01 of 2See more

kubevault-webhook-server appscode 0.25.0

1 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

826
kubevirt-infra-csi-driverappscodeVerified publisher0.1.02 of 6See more

kubevirt-infra-csi-driver appscode 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-csi-driver:latest7b31b21b3f1e
stdlib@go1.24.13
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
stdlib@go1.23.1
1.25.10

Open the chart page →

1,225
kubevirt-tenant-csi-driverappscodeVerified publisher0.1.02 of 4See more

kubevirt-tenant-csi-driver appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-csi-driver:latest7b31b21b3f1e
stdlib@go1.24.13
1.25.10
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.10

Open the chart page →

1,298
license-proxyserver-addon-managerappscodeVerified publisher2024.2.251 of 1See more

license-proxyserver-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
stdlib@go1.22.1
1.25.10

Open the chart page →

1,399
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
stdlib@go1.22.0
1.25.10

Open the chart page →

2,405
managed-serviceaccount-managerappscodeVerified publisher2026.2.161 of 1See more

managed-serviceaccount-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
stdlib@go1.25.8
1.25.10

Open the chart page →

928
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10

Open the chart page →

2,710
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
stdlib@go1.19.4
1.25.10

Open the chart page →

4,191
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
stdlib@go1.21.8
1.25.10

Open the chart page →

2,584
multicluster-ingress-readerappscodeVerified publisher2024.7.101 of 1See more

multicluster-ingress-reader appscode 2024.7.10

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

302
offline-license-serverappscodeVerified publisher2026.9.111 of 2See more

offline-license-server appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
stdlib@go1.25.5
1.25.10

Open the chart page →

1,692
opentelemetry-kube-stackappscodeVerified publisher0.14.123 of 3See more

opentelemetry-kube-stack appscode 0.14.12

3 of the 3 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
stdlib@go1.24.6
1.25.10
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.144.079b81912f1fb
stdlib@go1.25.6
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
stdlib@go1.25.1
1.25.10

Open the chart page →

1,911
panopticonappscodeVerified publisher2026.9.181 of 2See more

panopticon appscode 2026.9.18

1 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

422
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
stdlib@go1.25.4
1.25.10

Open the chart page →

37,889
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
stdlib@go1.25.4
1.25.10

Open the chart page →

778
regcacheappscodeVerified publisher2026.9.111 of 1See more

regcache appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
stdlib@go1.25.9
1.25.10

Open the chart page →

658
secrets-store-csi-driver-provider-virtual-secretsappscodeVerified publisher2026.8.141 of 1See more

secrets-store-csi-driver-provider-virtual-secrets appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/secrets-store-csi-driver-provider-virtual-secrets:v0.2.07afb394f9f97
stdlib@go1.24.1
1.25.10

Open the chart page →

553
service-backendappscodeVerified publisher2026.9.111 of 1See more

service-backend appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
stdlib@go1.25.5
1.25.10

Open the chart page →

1,344
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109fa56a9251de6
stdlib@go1.19
1.25.10

Open the chart page →

2,197
service-presetsappscodeVerified publisher2024.2.111 of 1See more

service-presets appscode 2024.2.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.25.10

Open the chart page →

824
service-providerappscodeVerified publisher2026.9.112 of 2See more

service-provider appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
stdlib@go1.23.3
1.25.10
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
stdlib@go1.25.5
1.25.10

Open the chart page →

2,252
stash-communityappscodeVerified publisher0.42.04 of 4See more

stash-community appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.25.10
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
stdlib@go1.24.9
1.25.10
ghcr.io/stashed/stash:v0.42.03a98245a7667
stdlib@go1.25.3
1.25.10
ghcr.io/stashed/stash-crd-installer:v0.42.076f0a650e44b
stdlib@go1.25.3
1.25.10

Open the chart page →

3,677
stash-opscenterappscodeVerified publisher2025.10.171 of 1See more

stash-opscenter appscode 2025.10.17

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.10

Open the chart page →

686
stash-ui-serverappscodeVerified publisher0.23.01 of 1See more

stash-ui-server appscode 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.10

Open the chart page →

686
statefulsetappscodeVerified publisher0.0.12 of 3See more

statefulset appscode 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
stdlib@go1.15.14
1.25.10
ghcr.io/appscode/kubectl-nonroot:v1.248ee5bdd68977
stdlib@go1.20.7
1.25.10

Open the chart page →

2,739
taskqueueappscodeVerified publisher2026.2.161 of 1See more

taskqueue appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
stdlib@go1.25.5
1.25.10

Open the chart page →

1,091
thanos-operatorappscodeVerified publisher2026.6.21 of 1See more

thanos-operator appscode 2026.6.2

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/thanos-operator:v2026.4.24e05a3e701291
stdlib@go1.26.2
1.25.10

Open the chart page →

385
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
stdlib@go1.25.5
1.25.10

Open the chart page →

1,227
voyagerappscodeVerified publisher2026.3.231 of 1See more

voyager appscode 2026.3.23

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/voyager:v17.5.04964ceaf9d35
stdlib@go1.25.8
1.25.10

Open the chart page →

728
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
stdlib@go1.21.1
1.25.10

Open the chart page →

5,704
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
stdlib@go1.22.2
1.25.10

Open the chart page →

1,205
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.24.6
1.25.10

Open the chart page →

8,931
appwriteappwrite-helmVerified publisher1.3.24 of 8See more

appwrite appwrite-helm 1.3.2

4 of the 8 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
stdlib@go1.25.7
1.25.10
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.25.10
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.25.10
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.25.10

Open the chart page →

9,855
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
stdlib@go1.16.4
1.25.10

Open the chart page →

5,212
arcadearcadeVerified publisher1.10.11 of 10See more

arcade arcade 1.10.1

1 of the 10 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10

Open the chart page →

991
argocd-bitbucket-proxyargocd-bitbucket-proxy1.1.11 of 1See more

argocd-bitbucket-proxy argocd-bitbucket-proxy 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/salemgolemugoo/argocd-bitbucket-proxy:latesta72df069095b
stdlib@go1.26.1
1.25.10

Open the chart page →

189
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
stdlib@go1.23.4
1.25.10
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.10
quay.io/argoproj/argocd:v2.14.115fc69e31c755
stdlib@go1.22.2
1.25.10

Open the chart page →

7,697
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
stdlib@go1.24.6
1.25.10
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
stdlib@go1.24.6
1.25.10

Open the chart page →

1,845
argonix-apiargonix0.2.92 of 4See more

argonix-api argonix 0.2.9

2 of the 4 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0aa679ddf5c3a
stdlib@go1.22.7
1.25.10
ghcr.io/argonix-io/argonix-api-frontend:1.0.0a584153dfae5
stdlib@go1.23.12
1.25.10

Open the chart page →

4,999
argo-zombiesargo-zombies0.1.521 of 1See more

argo-zombies argo-zombies 0.1.52

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
stdlib@go1.26.1
1.25.10

Open the chart page →

254
arlas-aiasarlas-stackVerified publisher28.8.06 of 22See more

arlas-aias arlas-stack 28.8.0

6 of the 22 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
stdlib@go1.23.9
1.25.10
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.25.10
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
stdlib@go1.22.11
1.25.10
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
stdlib@go1.24.2
1.25.10
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
stdlib@go1.23.8
1.25.10
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.25.10

Open the chart page →

41,099
arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
stdlib@go1.19.3
1.25.10
stakater/reloader:v1.0.15f4b87a8e56d4
stdlib@go1.20.1
1.25.10
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
stdlib@go1.18.10
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
stdlib@go1.19.5
1.25.10
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
stdlib@go1.19.4
1.25.10
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.25.10
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
stdlib@go1.19.4
1.25.10

Open the chart page →

23,461
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
stdlib@go1.19.2
1.25.10

Open the chart page →

1,780
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
stdlib@go1.17.11
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
stdlib@go1.17.10
1.25.10
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
stdlib@go1.17.3
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
stdlib@go1.18.3
1.25.10

Open the chart page →

8,630
assemblylineassemblylineVerified publisher7.4.202 of 12See more

assemblyline assemblyline 7.4.20

2 of the 12 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
stdlib@go1.21.5
1.25.10
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
stdlib@go1.21.5
1.25.10

Open the chart page →

12,862

Container images carrying it

4,529 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
shyim/shopware:6.4.6.0a951c0e6b836
stdlib@go1.20.7
1.25.10
1
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
stdlib@go1.19.2
1.25.10
1
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.25.10
1
signald/signald:0.23.2edbff058278c
stdlib@go1.18.10
1.25.10
1
signoz/alertmanager:0.5.07bc7de2e33c2
stdlib@go1.14
1.25.10
1
signoz/signoz:v0.142.149501b04d77a
stdlib@go1.25.7
1.25.10
1
signoz/signoz-otel-collector:v0.144.1034ecb436b687
stdlib@go1.25.0
1.25.10
1
sikalabs/signpost:v0.7.0c8b0e21d61b4
stdlib@go1.24.6
1.25.10
1
sikalabs/slu:v0.72.07bd267f30247
stdlib@go1.21.4
1.25.10
1
sikalabs/slu:v0.34.0fdc0c6711add
stdlib@go1.17.6
1.25.10
1
simonschneider/traefik-jwt-decode:latestd674ac370f80
stdlib@go1.17.13
1.25.10
1
simpleidserver/faasprometheus:0.0.425e378d57d78
stdlib@go1.17.1
1.25.10
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
stdlib@go1.20.4
1.25.10
1
sky5367/locust-plugins-grafana:latestd51bf68d4b26
stdlib@go1.21.8
1.25.10
1
sky5367/locust-plugins-timescale:latestd3150f201471
stdlib@go1.18.7
1.25.10
1
skylenet/ethereum-genesis-generator:latest210353ce7c89
stdlib@go1.17.13
1.25.10
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
stdlib@go1.17.2
1.25.10
1
slagattollas/weatherservice-practica:latest68e7f56393fc
stdlib@go1.15.6
1.25.10
1
slamdev/config-connector-templater:0.0.3a234541c9fa8
stdlib@go1.16.5
1.25.10
1
slamdev/external-secrets-operator:0.0.8855f6625dda4
stdlib@go1.13.15
1.25.10
1
slamdev/flux-notifier:v0.0.8b173d809132d
stdlib@go1.13.11
1.25.10
1
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
stdlib@go1.13.11
1.25.10
1
smailkoz/torrserver:1.0.1117b52d15de8f0
stdlib@go1.17.5
1.25.10
1
softonic/homing-pigeon:0.9.6f26d467b7b82
stdlib@go1.23.10
1.25.10
1
softonic/node-policy-webhook:0.1.2ab6098c04a53
stdlib@go1.14.6
1.25.10
1
softonic/pod-defaulter:0.1.072017aed5902
stdlib@go1.14.9
1.25.10
1
softonic/preemptible-killer:1.2.6-294b87f1fb362
stdlib@go1.14.10
1.25.10
1
softonic/rate-limit-operator:0.1.1910f6de37763
stdlib@go1.13.15
1.25.10
1
softwaremill/bootzooka:latest845b5e8f8056
stdlib@go1.26.2
1.25.10
1
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
stdlib@go1.25.4
1.25.10
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
stdlib@go1.18.2
1.25.10
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
stdlib@go1.24.13
1.25.10
1
sophos/nginx-vts-exporter:latestf1073556b29b
stdlib@go1.13.6
1.25.10
1
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
stdlib@go1.13.8
1.25.10
1
sosedoff/pgweb:latesta5256d416e2e
stdlib@go1.24.6
1.25.10
1
speckle/alertmanager-discord:latestf6221ff308e9
stdlib@go1.22.4
1.25.10
1
splunk/splunk-operator:2.0.0c4e0d3146226
stdlib@go1.17.12
1.25.10
1
springhack/frpc_ingress:latest4aceb821da88
stdlib@go1.19.5
1.25.10
1
sstarcher/ecr-cleaner:0.1.12d43c390cb19
stdlib@go1.14.2
1.25.10
1
sstarcher/helm-exporter:0.5.011769d01ba35
stdlib@go1.13.6
1.25.10
1
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
stdlib@go1.13.9
1.25.10
1
stakater/gitwebhookproxy:v0.2.79c1226e5270cd
stdlib@go1.13.1
1.25.10
1
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
stdlib@go1.17.8
1.25.10
1
stakater/konfigurator:v0.1.393409565b1ef5
stdlib@go1.17.13
1.25.10
1
stakater/reloader:v1.0.15f4b87a8e56d4
stdlib@go1.20.1
1.25.10
1
stakater/tronador:v0.0.137ce9acf2722
stdlib@go1.15.11
1.25.10
1
stakater/whitelister:v0.0.1639107924063e
stdlib@go1.13.1
1.25.10
1
stakater/workshop-operator:v0.0.3897bf456cc97c
stdlib@go1.16.13
1.25.10
1
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
stdlib@go1.18.3
1.25.10
1
stakkato95/twitter-service-graphql:0.1.13cbe857234f2
stdlib@go1.18.3
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.