StackRadar

CVE-2026-39825

Medium

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,006
of 17,805 indexed, latest versions
Container images
4,576
deployed by those charts
Fix available
1 of 2
affected packages

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

Carried by container images the latest versions of 4,006 of 17,805 indexed charts deploy, on 4,576 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,576
OSV records
DEBIAN-CVE-2026-39825GO-2026-4976
Also known as
BIT-golang-2026-39825

Charts affected

4,006 by stars
ChartLatestAffected imagesRadar Score
appwriteappwrite-helmVerified publisher1.3.24 of 8See more

appwrite appwrite-helm 1.3.2

4 of the 8 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
stdlib@go1.25.7
1.25.10
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.25.10
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.25.10
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.25.10

Open the chart page →

9,859
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
stdlib@go1.16.4
1.25.10

Open the chart page →

5,212
arcadearcadeVerified publisher1.10.11 of 10See more

arcade arcade 1.10.1

1 of the 10 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10

Open the chart page →

991
argocd-bitbucket-proxyargocd-bitbucket-proxy1.1.11 of 1See more

argocd-bitbucket-proxy argocd-bitbucket-proxy 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/salemgolemugoo/argocd-bitbucket-proxy:latesta72df069095b
stdlib@go1.26.1
1.25.10

Open the chart page →

189
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
stdlib@go1.23.4
1.25.10
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.10
quay.io/argoproj/argocd:v2.14.115fc69e31c755
stdlib@go1.22.2
1.25.10

Open the chart page →

7,709
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
stdlib@go1.24.6
1.25.10
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
stdlib@go1.24.6
1.25.10

Open the chart page →

1,845
argonix-apiargonix0.3.12 of 4See more

argonix-api argonix 0.3.1

2 of the 4 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.05b50081a8b99
stdlib@go1.22.7
1.25.10
ghcr.io/argonix-io/argonix-api-frontend:1.0.032fea68f7dc5
stdlib@go1.23.12
1.25.10

Open the chart page →

5,003
argo-zombiesargo-zombies0.1.521 of 1See more

argo-zombies argo-zombies 0.1.52

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
stdlib@go1.26.1
1.25.10

Open the chart page →

254
arlas-aiasarlas-stackVerified publisher28.9.06 of 22See more

arlas-aias arlas-stack 28.9.0

6 of the 22 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
stdlib@go1.23.9
1.25.10
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.25.10
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
stdlib@go1.22.11
1.25.10
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
stdlib@go1.24.2
1.25.10
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
stdlib@go1.23.8
1.25.10
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.25.10

Open the chart page →

39,861
arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
stdlib@go1.19.3
1.25.10
stakater/reloader:v1.0.15f4b87a8e56d4
stdlib@go1.20.1
1.25.10
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
stdlib@go1.18.10
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
stdlib@go1.19.5
1.25.10
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
stdlib@go1.19.4
1.25.10
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.25.10
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
stdlib@go1.19.4
1.25.10

Open the chart page →

23,475
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
stdlib@go1.19.2
1.25.10

Open the chart page →

1,780
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
stdlib@go1.17.11
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
stdlib@go1.17.10
1.25.10
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
stdlib@go1.17.3
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
stdlib@go1.18.3
1.25.10

Open the chart page →

8,632
assemblylineassemblylineVerified publisher7.4.202 of 12See more

assemblyline assemblyline 7.4.20

2 of the 12 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
stdlib@go1.21.5
1.25.10
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
stdlib@go1.21.5
1.25.10

Open the chart page →

12,874
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.25.10

Open the chart page →

5,538
dltkvassist-iot-data-integrity-verification0.2.04 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
stdlib@go1.17.13
1.25.10
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.25.10
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.25.10
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.25.10

Open the chart page →

194,425
dltflassist-iot-dlt-based-fl0.2.04 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
stdlib@go1.17.13
1.25.10
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.25.10
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.25.10
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.25.10

Open the chart page →

194,425
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
stdlib@go1.17.10
1.25.10

Open the chart page →

3,806
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.25.10

Open the chart page →

9,446
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
stdlib@go1.17.10
1.25.10

Open the chart page →

4,387
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.25.10

Open the chart page →

13,419
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.25.10

Open the chart page →

10,189
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
stdlib@go1.18.6
1.25.10
kong/kubernetes-ingress-controller:2.35e66021b64a8
stdlib@go1.18
1.25.10

Open the chart page →

88,229
performanceandusagediagnosisassist-iot-pud1.0.05 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

5 of the 7 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
stdlib@go1.17.12
1.25.10
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.10
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.25.10
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
stdlib@go1.18.3
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
stdlib@go1.18.5
1.25.10

Open the chart page →

8,592
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10

Open the chart page →

8,074
semantic-repositoryassist-iot-semantic-repository1.1.01 of 3See more

semantic-repository assist-iot-semantic-repository 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
stdlib@go1.24.6
1.25.10

Open the chart page →

1,201
smartorchestratorassist-iot-smart-orchestrator4.0.04 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

4 of the 14 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.22.1
1.25.10
devopsfaith/krakend:latestf8bdaa8a1a43
stdlib@go1.24.2
1.25.10
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.10
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10

Open the chart page →

46,026
astrotrekastria0.0.24 of 4See more

astrotrek astria 0.0.2

4 of the 4 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.25.10
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
stdlib@go1.23.1
1.25.10
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
stdlib@go1.23.1
1.25.10
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.25.10

Open the chart page →

32,762
celestia-localastria9.0.02 of 2See more

celestia-local astria 9.0.0

2 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
stdlib@go1.24.6
1.25.10
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
stdlib@go1.24.7
1.25.10

Open the chart page →

3,312
celestia-nodeastria0.7.11 of 1See more

celestia-node astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
stdlib@go1.24.7
1.25.10

Open the chart page →

1,521
evm-faucetastria0.1.51 of 1See more

evm-faucet astria 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.25.10

Open the chart page →

1,765
evm-rollupastria4.1.01 of 2See more

evm-rollup astria 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
stdlib@go1.22.12
1.25.10

Open the chart page →

4,044
evm-stackastria5.0.31 of 2See more

evm-stack astria 5.0.3

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
stdlib@go1.22.12
1.25.10

Open the chart page →

4,044
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
stdlib@go1.22.12
1.25.10

Open the chart page →

3,887
graph-nodeastria0.2.22 of 3See more

graph-node astria 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ipfs/kubo:v0.17.0803fac58ba15
stdlib@go1.19.1
1.25.10
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

5,629
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
stdlib@go1.22.11
1.25.10
rclone/rclone:1.56.0f2fc45c8bc57
stdlib@go1.16.6
1.25.10

Open the chart page →

6,511
sequencer-faucetastria0.9.21 of 1See more

sequencer-faucet astria 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
stdlib@go1.22.6
1.25.10

Open the chart page →

1,320
phonebook-chartasumankamberoglu0.1.51 of 3See more

phonebook-chart asumankamberoglu 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10

Open the chart page →

3,176
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
stdlib@go1.18.10
1.25.10

Open the chart page →

9,473
hcloud-csi-driveratem181.5.12 of 6See more

hcloud-csi-driver atem18 1.5.1

2 of the 6 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
stdlib@go1.15.3
1.25.10
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.25.10

Open the chart page →

6,511
bamboo-agentatlassian-data-centerVerified publisher2.0.151 of 1See more

bamboo-agent atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
stdlib@go1.22.2
1.25.10

Open the chart page →

1,730
alertmanager-discordatrox3.1.01 of 1See more

alertmanager-discord atrox 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/atrox/alertmanager-discord:v1.0.0ac011a4b6df1
stdlib@go1.20.5
1.25.10

Open the chart page →

587
attestkeepattestkeepVerified publisher1.1.11 of 2See more

attestkeep attestkeep 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/postgres:16.15-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10

Open the chart page →

860
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
stdlib@go1.13.10
1.25.10

Open the chart page →

7,573
okd-webhookav1o-chartsVerified publisher0.1.01 of 1See more

okd-webhook av1o-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.25.10

Open the chart page →

1,728
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
stdlib@go1.19.7
1.25.10

Open the chart page →

5,083
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
stdlib@go1.19.3
1.25.10

Open the chart page →

6,980
kubeslice-workeraveshaVerified publisher1.5.02 of 14See more

kubeslice-worker avesha 1.5.0

2 of the 14 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
stdlib@go1.22.2
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.1f6717ce72a26
stdlib@go1.20.3
1.25.10

Open the chart page →

1,645
amazon-ec2-metadata-mockaws1.11.21 of 1See more

amazon-ec2-metadata-mock aws 1.11.2

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/amazon-ec2-metadata-mock:v1.11.2dd02d3569da0
stdlib@go1.17.13
1.25.10

Open the chart page →

861
appmesh-jaegeraws1.0.31 of 1See more

appmesh-jaeger aws 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.2942822be7888b
stdlib@go1.17.3
1.25.10

Open the chart page →

2,488
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.25.10

Open the chart page →

2,947

Container images carrying it

4,576 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.13.1700c69915dc7
stdlib@go1.21.5
1.25.10
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
stdlib@go1.17.8
1.25.10
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookd27b4495ccc3
stdlib@go1.14.10
1.25.10
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookf16c0e022203
stdlib@go1.14.2
1.25.10
1
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
stdlib@go1.23.3
1.25.10
1
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
stdlib@go1.16.4
1.25.10
1
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
stdlib@go1.21.5
1.25.10
1
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
stdlib@go1.16.5
1.25.10
1
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
stdlib@go1.23.4
1.25.10
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
stdlib@go1.16.5
1.25.10
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
stdlib@go1.16.4
1.25.10
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
stdlib@go1.21.7
1.25.10
1
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
stdlib@go1.17.6
1.25.10
1
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
stdlib@go1.21.7
1.25.10
1
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
stdlib@go1.17.6
1.25.10
1
gcr.io/ml-pipeline/mysql:5.7-debiandf28187b5455
stdlib@go1.16.7
1.25.10
1
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
stdlib@go1.17.6
1.25.10
1
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
stdlib@go1.21.7
1.25.10
1
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
stdlib@go1.17.6
1.25.10
1
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
stdlib@go1.21.7
1.25.10
1
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
stdlib@go1.17.6
1.25.10
1
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
stdlib@go1.21.7
1.25.10
1
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
stdlib@go1.17.11
1.25.10
1
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
stdlib@go1.16.3
1.25.10
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
stdlib@go1.21.1
1.25.10
1
gcr.io/projectsigstore/cosigned784518ff3ee7
stdlib@go1.17.9
1.25.10
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
stdlib@go1.17.9
1.25.10
1
gcr.io/spotit-today/spot-ocean-admission-controller:0.1.64f634aeb31b8
stdlib@go1.24.13
1.25.10
1
ghcr.io/0xerr0r/blocky:v0.29.0a6d99f323d30
stdlib@go1.26.0
1.25.10
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
stdlib@go1.17.7
1.25.10
1
ghcr.io/abstract-foundation/zksync-external-node-sidecar:v1.0.03e705d0eb1ce
stdlib@go1.18.10
1.25.10
1
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
stdlib@go1.23.7
1.25.10
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
stdlib@go1.22.1
1.25.10
1
ghcr.io/afairgiant/medikeep:v0.70.04c28334f3c79
stdlib@go1.19.8
1.25.10
1
ghcr.io/agjmills/sentry-operator:v1.2.500389ef6a00e
stdlib@go1.24.2
1.25.10
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
stdlib@go1.22.5
1.25.10
1
ghcr.io/ajnart/homarr:lateste103abadfb52
stdlib@go1.22.5
1.25.10
1
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
stdlib@go1.16.9
1.25.10
1
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
stdlib@go1.19.3
1.25.10
1
ghcr.io/alexbakker/alertmanager-ntfy:1.0.12f4db8064595
stdlib@go1.24.4
1.25.10
1
ghcr.io/alexellis/registry-creds:0.3.2-rc1f5c72501e559
stdlib@go1.19.5
1.25.10
1
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
stdlib@go1.24.2
1.25.10
1
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
stdlib@go1.23.3
1.25.10
1
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
stdlib@go1.23.3
1.25.10
1
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
stdlib@go1.23.1
1.25.10
1
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
stdlib@go1.24.4
1.25.10
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
stdlib@go1.20.14
1.25.10
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
stdlib@go1.25.5
1.25.10
1
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
stdlib@go1.25.7
1.25.10
1
ghcr.io/andylibrian/terjang:latest20a46b199247
stdlib@go1.16.4
1.25.10
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.