StackRadar

CVE-2026-39823

Medium

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,017
of 17,821 indexed, latest versions
Container images
4,602
deployed by those charts
Fix available
1 of 2
affected packages

Bypass of meta content URL escaping causes XSS in html/template

Carried by container images the latest versions of 4,017 of 17,821 indexed charts deploy, on 4,602 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,602
OSV records
DEBIAN-CVE-2026-39823GO-2026-4982
Also known as
BIT-golang-2026-39823

Charts affected

4,017 by stars
ChartLatestAffected imagesRadar Score
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
stdlib@go1.14.15
1.25.10

Open the chart page →

2,116
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
stdlib@go1.24.0
1.25.10

Open the chart page →

572
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
stdlib@go1.24.0
1.25.10

Open the chart page →

572
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
stdlib@go1.24.3
1.25.10

Open the chart page →

1,152
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
stdlib@go1.24.2
1.25.10

Open the chart page →

548
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
stdlib@go1.23.3
1.25.10
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
stdlib@go1.23.1
1.25.10

Open the chart page →

4,576
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
stdlib@go1.23.3
1.25.10

Open the chart page →

590
versitygwalpineworks0.1.21 of 1See more

versitygw alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
versity/versitygw:v1.0.145192635d0353
stdlib@go1.24.3
1.25.10

Open the chart page →

1,261
versitygw-webhook-pulsar-proxyalpineworks0.1.11 of 1See more

versitygw-webhook-pulsar-proxy alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
stdlib@go1.24.4
1.25.10

Open the chart page →

908
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
stdlib@go1.22.2
1.25.10
daprio/dashboard:0.14.07ba5d51e5b97
stdlib@go1.19.13
1.25.10
daprio/injector:1.11.2763b9b70b0c8
stdlib@go1.20.6
1.25.10
daprio/operator:1.11.2c584428aa12d
stdlib@go1.20.6
1.25.10
daprio/placement:1.11.2d8e1446da996
stdlib@go1.20.6
1.25.10
daprio/sentry:1.11.21f507c1a181b
stdlib@go1.20.6
1.25.10
hashicorp/vault:1.15.26b4e5dadf082
stdlib@go1.21.3
1.25.10
hashicorp/vault-k8s:1.3.15d74a885ae3e
stdlib@go1.21.3
1.25.10

Open the chart page →

28,437
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
stdlib@go1.20.14
1.25.10

Open the chart page →

1,607
anchore-admission-controlleranchore-charts0.9.01 of 2See more

anchore-admission-controller anchore-charts 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
stdlib@go1.20.14
1.25.10

Open the chart page →

7,644
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
stdlib@go1.19.7
1.25.10

Open the chart page →

1,326
cert-manager-webhook-inwxandibraeuVerified publisher0.9.01 of 1See more

cert-manager-webhook-inwx andibraeu 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
stdlib@go1.25.7
1.25.10

Open the chart page →

607
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
stdlib@go1.25.7
1.25.10

Open the chart page →

5,919
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
stdlib@go1.25.7
1.25.10

Open the chart page →

1,300
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
stdlib@go1.16.4
1.25.10

Open the chart page →

1,986
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.25.10

Open the chart page →

2,240
dnsmadeeasy-webhookangelnu6.0.71 of 1See more

dnsmadeeasy-webhook angelnu 6.0.7

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/angelnu/dnsmadeeasy-webhook:v1.9.0a5ca158b1f02
stdlib@go1.24.1
1.25.10

Open the chart page →

818
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.25.10

Open the chart page →

118,407
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
stdlib@go1.23.12
1.25.10

Open the chart page →

919
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
stdlib@go1.13.15
1.25.10

Open the chart page →

2,496
ddosifyanteonVerified publisher1.7.55 of 13See more

ddosify anteon 1.7.5

5 of the 13 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
stdlib@go1.20.8
1.25.10
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
stdlib@go1.18.1
1.25.10
library/influxdb:2.6.1-alpine44a366dd7724
stdlib@go1.19.4
1.25.10
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.10
prom/prometheus:v2.37.98176adea328e
stdlib@go1.19.11
1.25.10

Open the chart page →

26,306
antmediaantmediaVerified publisher3.1.03 of 4See more

antmedia antmedia 3.1.0

3 of the 4 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
library/mongo:8.002a0cc7939f5
stdlib@go1.24.6
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.10

Open the chart page →

4,644
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.10

Open the chart page →

3,324
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
grafana/grafana:latestac461fb352ab
stdlib@go1.25.7
1.25.10

Open the chart page →

2,480
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
stdlib@go1.15
1.25.10

Open the chart page →

2,731
glauthanza-labsVerified publisher1.0.11 of 1See more

glauth anza-labs 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/glauth/glauth:v2.5.209c782ca5984
stdlib@go1.25.0
1.25.10

Open the chart page →

1,327
apipingapiping1.5.01 of 1See more

apiping apiping 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
udhos/apiping:1.5.041ab9bae6f3b
stdlib@go1.25.4
1.25.10

Open the chart page →

1,151
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
stdlib@go1.23.6
1.25.10

Open the chart page →

2,996
api-usage-cleanerapi-usage-cleaner1.16.01 of 1See more

api-usage-cleaner api-usage-cleaner 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.25.10

Open the chart page →

596
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

19,830
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
stdlib@go1.18.5
1.25.10
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
stdlib@go1.18.5
1.25.10
velero/velero:v1.8.18d784580931c
stdlib@go1.16.6
1.25.10

Open the chart page →

12,562
app-movies-seriesapp-movies-seriesVerified publisher0.1.01 of 2See more

app-movies-series app-movies-series 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.25.10

Open the chart page →

3,170
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10

Open the chart page →

2,716
aceappscodeVerified publisher2026.9.112 of 2See more

ace appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

3,018
ace-installerappscodeVerified publisher2026.9.112 of 2See more

ace-installer appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
stdlib@go1.25.9
1.25.10
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10

Open the chart page →

3,374
ace-installer-certifiedappscodeVerified publisher2026.9.112 of 2See more

ace-installer-certified appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
stdlib@go1.25.9
1.25.10
ghcr.io/appscode/b3:v2026.9.1178a9fb785ec5
stdlib@go1.25.3
1.25.10

Open the chart page →

3,142
acerproxyappscodeVerified publisher2026.9.111 of 1See more

acerproxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
stdlib@go1.25.5
1.25.10

Open the chart page →

1,332
aceshifterappscodeVerified publisher2026.9.111 of 1See more

aceshifter appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/aceshifter:v0.0.3e5f5c254a55a
stdlib@go1.25.8
1.25.10

Open the chart page →

1,046
appscode-otel-stackappscodeVerified publisher2026.7.153 of 3See more

appscode-otel-stack appscode 2026.7.15

3 of the 3 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
stdlib@go1.24.6
1.25.10
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.150.089490ef63b72
stdlib@go1.26.2
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
stdlib@go1.25.1
1.25.10

Open the chart page →

1,460
auditorappscodeVerified publisher2023.10.11 of 1See more

auditor appscode 2023.10.1

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
stdlib@go1.19.4
1.25.10

Open the chart page →

1,681
aws-credential-managerappscodeVerified publisher2026.4.161 of 1See more

aws-credential-manager appscode 2026.4.16

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/aws-credential-manager:v0.1.00511bbe501c3
stdlib@go1.25.9
1.25.10

Open the chart page →

621
azure-credential-managerappscodeVerified publisher2026.4.161 of 1See more

azure-credential-manager appscode 2026.4.16

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/azure-credential-manager:v0.1.0f5c797f7fbe7
stdlib@go1.25.9
1.25.10

Open the chart page →

887
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10

Open the chart page →

2,716
capa-vpc-peering-operatorappscodeVerified publisher2023.12.111 of 1See more

capa-vpc-peering-operator appscode 2023.12.11

1 of the 1 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
stdlib@go1.21.5
1.25.10

Open the chart page →

1,433
capi-ops-managerappscodeVerified publisher2024.8.142 of 2See more

capi-ops-manager appscode 2024.8.14

2 of the 2 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
stdlib@go1.23.2
1.25.10
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
stdlib@go1.15.14
1.25.10

Open the chart page →

3,585
cert-manager-csi-driver-cacertsappscodeVerified publisher2026.9.182 of 3See more

cert-manager-csi-driver-cacerts appscode 2026.9.18

2 of the 3 container images this version deploys carry CVE-2026-39823.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
stdlib@go1.24.2
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
stdlib@go1.24.2
1.25.10

Open the chart page →

2,515

Container images carrying it

4,602 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/zncdatadev/airflow-operator:0.4.0b716ef483b75
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/commons-operator:0.4.01a353def9fe1
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/dolphinscheduler-operator:0.4.0d0a4e55eeb7f
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/hbase-operator:0.4.069e9a1b0daf8
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/hdfs-operator:0.4.0eb3c2928250e
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/hive-operator:0.4.0d66ba9149c22
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/kafka-operator:0.4.00a0b4c39c1ba
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/listener-csi-driver:0.4.0b69bed123b02
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/listener-operator:0.4.068b92dae8d75
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/nifi-operator:0.4.0bb4e26ff5e2f
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/secret-csi-driver:0.4.0604a7d98ab58
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/spark-k8s-operator:0.4.0d3f2b10c4a6d
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/superset-operator:0.4.0102e66e32218
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/trino-operator:0.4.04f516757aee3
stdlib@go1.25.8
1.25.10
1
quay.io/zncdatadev/zookeeper-operator:0.4.0b4f33d89ac45
stdlib@go1.25.8
1.25.10
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
stdlib@go1.19.1
1.25.10
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
stdlib@go1.16.4
1.25.10
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
stdlib@go1.18.1
1.25.10
1
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.25.10
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.25.10
1
registry.gitlab.com/bitspur/rock8s/easy-olm-operator:0.0.1779454fea06c
stdlib@go1.19.10
1.25.10
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
stdlib@go1.20.8
1.25.10
1
registry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.063cf51392ce7
stdlib@go1.19.13
1.25.10
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.25.10
1
registry.gitlab.com/dyff/dyff-operator:0.24.20e9ca51627601
stdlib@go1.24.13
1.25.10
1
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
stdlib@go1.20.14
1.25.10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
stdlib@go1.25.7
1.25.10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
stdlib@go1.25.7
1.25.10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.25.10
1
registry.gitlab.com/gitlab-org/build/cng/cfssl-self-sign:v19.4.07757679afa1b
stdlib@go1.22.0
1.25.10
1
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
stdlib@go1.25.0
1.25.10
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
stdlib@go1.16.14
1.25.10
1
registry.gitlab.com/lenitech/docker/keycloak-ppolicy:0.6.09895d6915075
stdlib@go1.25.7
1.25.10
1
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
stdlib@go1.24.5
1.25.10
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
stdlib@go1.21.0
1.25.10
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
stdlib@go1.15.15
1.25.10
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
stdlib@go1.25.7
1.25.10
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
stdlib@go1.25.7
1.25.10
1
registry.gitlab.com/xrow-public/ci-tools/kubectl:main9357cfeef63c
stdlib@go1.24.9
1.25.10
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
stdlib@go1.24.13
1.25.10
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
stdlib@go1.24.5
1.25.10
1
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.25.10
1
registry.k8s.io/agent-sandbox/sandbox-router-go:v1.0.125b1a0939630
stdlib@go1.26.2
1.25.10
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
stdlib@go1.24.4
1.25.10
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
stdlib@go1.24.7
1.25.10
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.4.171d817780aa9
stdlib@go1.24.3
1.25.10
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
stdlib@go1.25.7
1.25.10
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
stdlib@go1.24.6
1.25.10
1
registry.k8s.io/autoscaling/vpa-recommender:1.4.140b6d76e8526
stdlib@go1.24.3
1.25.10
1
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
stdlib@go1.24.6
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.