StackRadar

CVE-2026-39825

Medium

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,939
of 17,787 indexed, latest versions
Container images
4,537
deployed by those charts
Fix available
1 of 2
affected packages

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

Carried by container images the latest versions of 3,939 of 17,787 indexed charts deploy, on 4,537 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,537
OSV records
DEBIAN-CVE-2026-39825GO-2026-4976
Also known as
BIT-golang-2026-39825

Charts affected

3,939 by stars
ChartLatestAffected imagesRadar Score
kubeform-provider-azureappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-azure appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
stdlib@go1.20.5
1.25.10

Open the chart page →

2,716
kubeform-provider-gcpappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-gcp appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
stdlib@go1.19.9
1.25.10

Open the chart page →

2,743
kubestashappscodeVerified publisher2026.7.102 of 2See more

kubestash appscode 2026.7.10

2 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.10

Open the chart page →

1,091
kubestash-certifiedappscodeVerified publisher2026.7.102 of 2See more

kubestash-certified appscode 2026.7.10

2 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.10

Open the chart page →

1,091
kubestash-operatorappscodeVerified publisher0.29.02 of 2See more

kubestash-operator appscode 0.29.0

2 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.10

Open the chart page →

1,091
kubevaultappscodeVerified publisher2026.8.71 of 2See more

kubevault appscode 2026.8.7

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

789
kubevault-certifiedappscodeVerified publisher2026.2.271 of 1See more

kubevault-certified appscode 2026.2.27

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/kubevault/vault-operator:v0.24.00087cb49616f
stdlib@go1.25.9
1.25.10

Open the chart page →

1,112
kubevault-webhook-serverappscodeVerified publisher0.25.01 of 2See more

kubevault-webhook-server appscode 0.25.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

789
kubevirt-infra-csi-driverappscodeVerified publisher0.1.02 of 6See more

kubevirt-infra-csi-driver appscode 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-csi-driver:latest7b31b21b3f1e
stdlib@go1.24.13
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
stdlib@go1.23.1
1.25.10

Open the chart page →

1,177
kubevirt-tenant-csi-driverappscodeVerified publisher0.1.02 of 4See more

kubevirt-tenant-csi-driver appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-csi-driver:latest7b31b21b3f1e
stdlib@go1.24.13
1.25.10
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.10

Open the chart page →

1,278
license-proxyserverappscodeVerified publisher2026.2.161 of 1See more

license-proxyserver appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.1.1e192ad567e0b
stdlib@go1.25.7
1.25.10

Open the chart page →

1,106
license-proxyserver-addon-managerappscodeVerified publisher2024.2.251 of 1See more

license-proxyserver-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
stdlib@go1.22.1
1.25.10

Open the chart page →

1,384
license-proxyserver-managerappscodeVerified publisher2026.2.161 of 1See more

license-proxyserver-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.1.1e192ad567e0b
stdlib@go1.25.7
1.25.10

Open the chart page →

1,106
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
stdlib@go1.22.0
1.25.10

Open the chart page →

2,404
managed-serviceaccount-managerappscodeVerified publisher2026.2.161 of 1See more

managed-serviceaccount-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
stdlib@go1.25.8
1.25.10

Open the chart page →

912
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10

Open the chart page →

2,605
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
stdlib@go1.19.4
1.25.10

Open the chart page →

4,043
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
stdlib@go1.21.8
1.25.10

Open the chart page →

2,568
multicluster-ingress-readerappscodeVerified publisher2024.7.101 of 1See more

multicluster-ingress-reader appscode 2024.7.10

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

302
offline-license-serverappscodeVerified publisher2026.9.111 of 2See more

offline-license-server appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
stdlib@go1.25.5
1.25.10

Open the chart page →

1,682
opentelemetry-kube-stackappscodeVerified publisher0.14.123 of 3See more

opentelemetry-kube-stack appscode 0.14.12

3 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
stdlib@go1.24.6
1.25.10
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.144.079b81912f1fb
stdlib@go1.25.6
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
stdlib@go1.25.1
1.25.10

Open the chart page →

1,872
panopticonappscodeVerified publisher2026.6.221 of 2See more

panopticon appscode 2026.6.22

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

468
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
stdlib@go1.25.4
1.25.10

Open the chart page →

37,184
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
stdlib@go1.25.4
1.25.10

Open the chart page →

771
regcacheappscodeVerified publisher2026.9.111 of 1See more

regcache appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
stdlib@go1.25.9
1.25.10

Open the chart page →

634
secrets-store-csi-driver-provider-virtual-secretsappscodeVerified publisher2026.8.141 of 1See more

secrets-store-csi-driver-provider-virtual-secrets appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/secrets-store-csi-driver-provider-virtual-secrets:v0.2.07afb394f9f97
stdlib@go1.24.1
1.25.10

Open the chart page →

547
service-backendappscodeVerified publisher2026.9.111 of 1See more

service-backend appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
stdlib@go1.25.5
1.25.10

Open the chart page →

1,330
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109fa56a9251de6
stdlib@go1.19
1.25.10

Open the chart page →

2,088
service-presetsappscodeVerified publisher2024.2.111 of 1See more

service-presets appscode 2024.2.11

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.25.10

Open the chart page →

823
service-providerappscodeVerified publisher2026.9.112 of 2See more

service-provider appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
stdlib@go1.23.3
1.25.10
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
stdlib@go1.25.5
1.25.10

Open the chart page →

2,224
stash-communityappscodeVerified publisher0.42.04 of 4See more

stash-community appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.25.10
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
stdlib@go1.24.9
1.25.10
ghcr.io/stashed/stash:v0.42.03a98245a7667
stdlib@go1.25.3
1.25.10
ghcr.io/stashed/stash-crd-installer:v0.42.076f0a650e44b
stdlib@go1.25.3
1.25.10

Open the chart page →

3,661
stash-opscenterappscodeVerified publisher2025.10.171 of 1See more

stash-opscenter appscode 2025.10.17

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.10

Open the chart page →

672
stash-ui-serverappscodeVerified publisher0.23.01 of 1See more

stash-ui-server appscode 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.10

Open the chart page →

672
statefulsetappscodeVerified publisher0.0.12 of 3See more

statefulset appscode 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
stdlib@go1.15.14
1.25.10
ghcr.io/appscode/kubectl-nonroot:v1.248ee5bdd68977
stdlib@go1.20.7
1.25.10

Open the chart page →

2,732
taskqueueappscodeVerified publisher2026.2.161 of 1See more

taskqueue appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
stdlib@go1.25.5
1.25.10

Open the chart page →

1,076
thanos-operatorappscodeVerified publisher2026.6.21 of 1See more

thanos-operator appscode 2026.6.2

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/thanos-operator:v2026.4.24e05a3e701291
stdlib@go1.26.2
1.25.10

Open the chart page →

371
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
stdlib@go1.25.5
1.25.10

Open the chart page →

1,221
voyagerappscodeVerified publisher2026.3.231 of 1See more

voyager appscode 2026.3.23

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/voyager:v17.5.04964ceaf9d35
stdlib@go1.25.8
1.25.10

Open the chart page →

713
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
stdlib@go1.21.1
1.25.10

Open the chart page →

4,899
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
stdlib@go1.22.2
1.25.10

Open the chart page →

1,204
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.24.6
1.25.10

Open the chart page →

8,904
appwriteappwrite-helmVerified publisher1.3.24 of 8See more

appwrite appwrite-helm 1.3.2

4 of the 8 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
stdlib@go1.25.7
1.25.10
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.25.10
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.25.10
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.25.10

Open the chart page →

9,847
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
stdlib@go1.16.4
1.25.10

Open the chart page →

5,203
arcadearcadeVerified publisher1.10.11 of 10See more

arcade arcade 1.10.1

1 of the 10 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10

Open the chart page →

991
argocd-bitbucket-proxyargocd-bitbucket-proxy1.1.11 of 1See more

argocd-bitbucket-proxy argocd-bitbucket-proxy 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/salemgolemugoo/argocd-bitbucket-proxy:latesta72df069095b
stdlib@go1.26.1
1.25.10

Open the chart page →

189
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
stdlib@go1.23.4
1.25.10
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.10
quay.io/argoproj/argocd:v2.14.115fc69e31c755
stdlib@go1.22.2
1.25.10

Open the chart page →

7,338
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
stdlib@go1.24.6
1.25.10
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
stdlib@go1.24.6
1.25.10

Open the chart page →

1,826
argonix-apiargonix0.2.32 of 4See more

argonix-api argonix 0.2.3

2 of the 4 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
stdlib@go1.22.7
1.25.10
ghcr.io/argonix-io/argonix-api-frontend:1.0.0d041bbf2814f
stdlib@go1.23.12
1.25.10

Open the chart page →

4,819
argo-zombiesargo-zombies0.1.521 of 1See more

argo-zombies argo-zombies 0.1.52

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
stdlib@go1.26.1
1.25.10

Open the chart page →

254
arlas-aiasarlas-stackVerified publisher28.8.06 of 22See more

arlas-aias arlas-stack 28.8.0

6 of the 22 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
stdlib@go1.23.9
1.25.10
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.25.10
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
stdlib@go1.22.11
1.25.10
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
stdlib@go1.24.2
1.25.10
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
stdlib@go1.23.8
1.25.10
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.25.10

Open the chart page →

40,411

Container images carrying it

4,537 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
argoproj/argocd:v1.8.1830e86cacefd
stdlib@go1.14.12
1.25.10
3
bitnamilegacy/kubectl:latestcd354d5b2556
stdlib@go1.24.5
1.25.10
3
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
stdlib@go1.17.10
1.25.10
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
stdlib@go1.25.0
1.25.10
3
caddy/ingress:v0.2.118d1366fc0e9
stdlib@go1.21.4
1.25.10
3
ciscolabs/rtsp-server:latestb59fc10bb821
stdlib@go1.19.2
1.25.10
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
stdlib@go1.25.7
1.25.10
3
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
stdlib@go1.23.12
1.25.10
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
stdlib@go1.16
1.25.10
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
stdlib@go1.15
1.25.10
3
derailed/popeye:v0.22.18e68e22c7663
stdlib@go1.23.5
1.25.10
3
dgraph/dgraph:v21.12.03b55ea83fffe
stdlib@go1.17.3
1.25.10
3
ethpandaops/tracoor:latestd8514b9f4c59
stdlib@go1.24.13
1.25.10
3
grafana/grafana:8.2.500568d89c4f8
stdlib@go1.17
1.25.10
3
grafana/grafana:11.0.00dc5a246ab16
stdlib@go1.21.10
1.25.10
3
grafana/grafana:11.3.0a0f881232a6f
stdlib@go1.23.1
1.25.10
3
grafana/loki:3.4.258a6c186ce78
stdlib@go1.23.6
1.25.10
3
grafana/loki-canary:3.6.70dac7d5cb383
stdlib@go1.24.13
1.25.10
3
grafana/promtail:2.4.2626900031c4e
stdlib@go1.17.2
1.25.10
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.25.10
3
hashicorp/http-echo:1.0.0:latestfcb75f691c8b
stdlib@go1.21.1
1.25.10
3
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.10
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
stdlib@go1.25.4
1.25.10
3
kubegems/kubegems:v1.24.10a730bcf9322a
stdlib@go1.24.10
1.25.10
3
library/docker:20.10-dind:20-dindaf96c680a7e1
stdlib@go1.19.7
1.25.10
3
library/mysql:latest66aec17cd21a
stdlib@go1.24.6
1.25.10
3
library/nats:2.10-alpineb83efabe3e7d
stdlib@go1.24.2
1.25.10
3
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.25.10
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.25.10
3
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.10
3
library/postgres:14-alpine727876d27466
stdlib@go1.24.6
1.25.10
3
library/rabbitmq:4.3.5-management:4-management:managementffd1b50c522a
stdlib@go1.22.2
1.25.10
3
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.10
3
migrate/migrate:latestcc4ad8e19d66
stdlib@go1.25.4
1.25.10
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
stdlib@go1.15.7
1.25.10
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
stdlib@go1.13.11
1.25.10
3
natsio/nats-box:0.19.28031d190c7ee
stdlib@go1.25.2
1.25.10
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.25.10
3
neosmemo/memos:0.30.071a5b4738d1b
stdlib@go1.26.2
1.25.10
3
oryd/hydra:v2.2.02c93beb5e5f2
stdlib@go1.21.5
1.25.10
3
prom/alertmanager:v0.28.0d5155cfac40a
stdlib@go1.23.4
1.25.10
3
prom/prometheus:v3.0.1565ee8650122
stdlib@go1.23.3
1.25.10
3
prom/prometheus:v2.19.0bfad037f95e5
stdlib@go1.14.4
1.25.10
3
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.25.10
3
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.10
3
prom/statsd-exporter:v0.28.04e7a1f00b9b2
stdlib@go1.23.2
1.25.10
3
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.25.10
3
rancher/kubectl:v1.34.1090bef429ed1
stdlib@go1.24.6
1.25.10
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.25.10
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
stdlib@go1.21.3
1.25.10
3

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.