StackRadar

CVE-2026-39825

Medium

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,940
of 17,790 indexed, latest versions
Container images
4,539
deployed by those charts
Fix available
1 of 2
affected packages

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

Carried by container images the latest versions of 3,940 of 17,790 indexed charts deploy, on 4,539 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,539
OSV records
DEBIAN-CVE-2026-39825GO-2026-4976
Also known as
BIT-golang-2026-39825

Charts affected

3,940 by stars
ChartLatestAffected imagesRadar Score
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.10

Open the chart page →

7,360
k8s-pausek8s-pause0.1.41 of 1See more

k8s-pause k8s-pause 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
stdlib@go1.17.8
1.25.10

Open the chart page →

1,846
k8s-s3-bucket-operatork8s-s3-bucket-operator0.2.21 of 1See more

k8s-s3-bucket-operator k8s-s3-bucket-operator 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
stdlib@go1.25.8
1.25.10

Open the chart page →

535
k8s-ssh-bastionk8s-ssh-bastion0.5.41 of 1See more

k8s-ssh-bastion k8s-ssh-bastion 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
stdlib@go1.21.11
1.25.10

Open the chart page →

3,327
k8s-validating-webhookk8s-validating-webhook0.4.01 of 2See more

k8s-validating-webhook k8s-validating-webhook 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
stdlib@go1.22.5
1.25.10

Open the chart page →

2,010
kube-admission-controller-starterk8s-validating-webhook0.2.01 of 2See more

kube-admission-controller-starter k8s-validating-webhook 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
stdlib@go1.22.5
1.25.10

Open the chart page →

2,167
k8svault-controllerk8svault-controller0.1.21 of 1See more

k8svault-controller k8svault-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
stdlib@go1.16.15
1.25.10

Open the chart page →

1,885
kagentkagent0.10.12 of 6See more

kagent kagent 0.10.1

2 of the 6 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/kagent-dev/kagent/tools:0.2.150b431281d3e
stdlib@go1.25.8
1.25.10
ghcr.io/kagent-dev/kmcp/controller:0.3.086ab878da25a
stdlib@go1.24.13
1.25.10

Open the chart page →

2,942
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
stdlib@go1.25.5
1.25.10

Open the chart page →

4,591
postgresqlkagiso-me0.4.01 of 1See more

postgresql kagiso-me 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.25.10

Open the chart page →

1,488
rediskagiso-me0.1.61 of 1See more

redis kagiso-me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.25.10

Open the chart page →

1,288
kom-operatorkaisoVerified publisher1.3.01 of 2See more

kom-operator kaiso 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
kaiso/kom-operator:v2.2.0e0e22b928bdd
stdlib@go1.21.5
1.25.10

Open the chart page →

710
gpu-provisionerkaitoVerified publisher0.2.01 of 1See more

gpu-provisioner kaito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
mcr.microsoft.com/aks/kaito/gpu-provisioner:0.2.01204a7e948e9
stdlib@go1.21.8
1.25.10

Open the chart page →

1,045
workspacekaitoVerified publisher0.12.02 of 7See more

workspace kaito 0.12.0

2 of the 7 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v5.2.0afdfa3da79df
stdlib@go1.25.5
1.25.10
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v1.13.2fa8eba9843ff
stdlib@go1.25.7
1.25.10

Open the chart page →

2,410
jenkinskallakruparaju-jenkins1.0.01 of 1See more

jenkins kallakruparaju-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.10

Open the chart page →

2,498
crashlooping-pod-deleterkarljorgensen0.1.31 of 1See more

crashlooping-pod-deleter karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
stdlib@go1.24.6
1.25.10

Open the chart page →

1,153
dockerdkarljorgensen0.1.01 of 1See more

dockerd karljorgensen 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/docker:28.5.2-dind2a232a42256f
stdlib@go1.24.9
1.25.10

Open the chart page →

2,041
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
stdlib@go1.25.7
1.25.10

Open the chart page →

7,137
k10restorekastenVerified publisher8.0.141 of 1See more

k10restore kasten 8.0.14

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
stdlib@go1.25.4
1.25.10

Open the chart page →

1,485
kbot-self-hostedkbot-self-hostedVerified publisher0.1.81 of 7See more

kbot-self-hosted kbot-self-hosted 0.1.8

1 of the 7 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.30206a6c708fc6
stdlib@go1.26.0
1.25.10

Open the chart page →

32,812
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/mysql:latest66aec17cd21a
stdlib@go1.24.6
1.25.10

Open the chart page →

8,877
kcmkcm1.11.02 of 12See more

kcm kcm 1.11.0

2 of the 12 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
stdlib@go1.26.2
1.25.10
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
stdlib@go1.25.5
1.25.10

Open the chart page →

2,857
keeper-injectorkeeper-injectorVerified publisher0.10.02 of 2See more

keeper-injector keeper-injector 0.10.0

2 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
keeper/injector-webhook:0.10.0aeb5476b95f0
stdlib@go1.25.6
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.10

Open the chart page →

758
keeper-injectorkeeper-securityVerified publisher0.11.31 of 2See more

keeper-injector keeper-security 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.10

Open the chart page →

505
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
stdlib@go1.20.7
1.25.10

Open the chart page →

5,245
kestra-starterkestraOfficialVerified publisher2.0.22 of 5See more

kestra-starter kestra 2.0.2

2 of the 5 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.25.10
versity/versitygw:v1.1.0f730e0dbc1ef
stdlib@go1.25.5
1.25.10

Open the chart page →

5,455
keycloak-operator-legacykeycloak-operator-legacy1.0.01 of 1See more

keycloak-operator-legacy keycloak-operator-legacy 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
stdlib@go1.13.8
1.25.10

Open the chart page →

5,066
csi-driver-nfskeyporttech0.1.41 of 2See more

csi-driver-nfs keyporttech 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
stdlib@go1.14.2
1.25.10

Open the chart page →

3,364
gogskeyporttech0.1.31 of 3See more

gogs keyporttech 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
gogs/gogs:0.12.30195b095d0b2
stdlib@go1.14.7
1.25.10

Open the chart page →

3,524
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
stdlib@go1.13.15
1.25.10

Open the chart page →

8,819
connectkfirfer1.15.02 of 2See more

connect kfirfer 1.15.0

2 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
1password/connect-api:1.7.26aa94cf713f9
stdlib@go1.20.6
1.25.10
1password/connect-sync:1.7.2fe527ed9d81f
stdlib@go1.20.6
1.25.10

Open the chart page →

2,786
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
stdlib@go1.13.11
1.25.10

Open the chart page →

2,791
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
stdlib@go1.17.1
1.25.10

Open the chart page →

6,447
keelkfirfer1.0.51 of 1See more

keel kfirfer 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
keelhq/keel:0.19.202ac4ea616c4
stdlib@go1.20.5
1.25.10

Open the chart page →

2,083
kubernetes-replicatorkfirfer2.9.11 of 1See more

kubernetes-replicator kfirfer 2.9.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.9.1baf5f784398b
stdlib@go1.20.5
1.25.10

Open the chart page →

864
mysqldumpkfirfer2.8.01 of 1See more

mysqldump kfirfer 2.8.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
stdlib@go1.21.5
1.25.10

Open the chart page →

3,514
pod-cleanupkfirfer0.0.41 of 1See more

pod-cleanup kfirfer 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
stdlib@go1.25.0
1.25.10

Open the chart page →

742
prometheus-elasticsearch-exporterkfirfer6.5.11 of 1See more

prometheus-elasticsearch-exporter kfirfer 6.5.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.8.0073dd360de2c
stdlib@go1.22.7
1.25.10

Open the chart page →

778
scriptskfirfer0.1.361 of 1See more

scripts kfirfer 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
kfirfer/scripts:0.0.2481e5c4e5d70e
stdlib@go1.17.10
1.25.10

Open the chart page →

2,320
kiaekiae0.1.66 of 9See more

kiae kiae 0.1.6

6 of the 9 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.25.10
grafana/promtail:2.6.1072527b12cdf
stdlib@go1.17.9
1.25.10
istio/pilot:1.15.2db08d6963975
stdlib@go1.19.2
1.25.10
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
stdlib@go1.19.2
1.25.10
ghcr.io/dexidp/dex:v2.35.313964b29d63e
stdlib@go1.19.2
1.25.10
ghcr.io/kiaedev/kiae:latestebd03028ff6a
stdlib@go1.18.9
1.25.10

Open the chart page →

19,257
kimai-helmchartkimai2tet0.1.01 of 2See more

kimai-helmchart kimai2tet 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10

Open the chart page →

1,518
local-path-provisionerkir4hVerified publisher0.0.351 of 1See more

local-path-provisioner kir4h 0.0.35

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.3534ff0847cc47
stdlib@go1.26.1
1.25.10

Open the chart page →

753
process-exporterkir4hVerified publisher1.0.11 of 1See more

process-exporter kir4h 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ncabatoff/process-exporterdigest-pinned6f0549dc24e9
stdlib@go1.23.1
1.25.10

Open the chart page →

741
typebotiokitsune-itopsVerified publisher0.1.41 of 4See more

typebotio kitsune-itops 0.1.4

1 of the 4 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10

Open the chart page →

494
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
stdlib@go1.22.10
1.25.10

Open the chart page →

12,206
rabbitmq-cluster-operatorklicktippVerified publisher0.4.22 of 3See more

rabbitmq-cluster-operator klicktipp 0.4.2

2 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/rabbitmq/cluster-operator:2.20.1a96853470256
stdlib@go1.25.9
1.25.10
ghcr.io/rabbitmq/messaging-topology-operator:1.19.124c4649ef3ef
stdlib@go1.25.9
1.25.10

Open the chart page →

810
rabbitmq-topology-operatorklicktippVerified publisher0.4.11 of 2See more

rabbitmq-topology-operator klicktipp 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/rabbitmq/messaging-topology-operator:1.19.124c4649ef3ef
stdlib@go1.25.9
1.25.10

Open the chart page →

549
kloudlite-platformkloudlite1.1.51 of 3See more

kloudlite-platform kloudlite 1.1.5

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
stdlib@go1.21.3
1.25.10

Open the chart page →

1,970
klustre-csi-pluginklustre-csi-plugin0.1.11 of 2See more

klustre-csi-plugin klustre-csi-plugin 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
stdlib@go1.21.5
1.25.10

Open the chart page →

1,472
knative-servingknative-servingVerified publisher1.18.37 of 7See more

knative-serving knative-serving 1.18.3

7 of the 7 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
stdlib@go1.24.6
1.25.10
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
stdlib@go1.24.6
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
stdlib@go1.24.3
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
stdlib@go1.24.3
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
stdlib@go1.24.3
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
stdlib@go1.24.3
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
stdlib@go1.24.3
1.25.10

Open the chart page →

3,777

Container images carrying it

4,539 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10
89
library/postgres:18:18.6:18.6-trixie:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10
69
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10
22
library/postgres:18.6-alpine:18-alpine:alpined3e1620b530c
stdlib@go1.24.6
1.25.10
17
library/mysql:8:8.4:8.4.11b3b90af2a655
stdlib@go1.24.6
1.25.10
16
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10
16
minio/minio:latest:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
stdlib@go1.24.6
1.25.10
16
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.10
14
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
stdlib@go1.18.10
1.25.10
13
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
stdlib@go1.25.3
1.25.10
13
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10
13
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10
13
grafana/grafana:latestf772d434e8fa
stdlib@go1.25.7
1.25.10
12
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.10
12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.10
12
library/mariadb:12.3.3:latest:ltsdd9b303aed4f
stdlib@go1.24.6
1.25.10
11
library/mongo:8:8.3.8:latest5211c51171f5
stdlib@go1.24.6
1.25.10
11
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10
11
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.10
11
jwilder/dockerize:latestf94fb59fb4f6
stdlib@go1.25.5
1.25.10
10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
10
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.10
10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.10
9
library/rabbitmq:3.13-management:3-managemente582c0bc7766
stdlib@go1.22.2
1.25.10
8
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.25.10
8
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
stdlib@go1.23.4
1.25.10
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.10
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.25.10
8
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.10
7
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.25.10
7
wurstmeister/kafka:latest2d4bbf9cc83d
stdlib@go1.17.10
1.25.10
7
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10
7
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10
7
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
stdlib@go1.23.4
1.25.10
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
stdlib@go1.23.4
1.25.10
7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
stdlib@go1.24.6
1.25.10
7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
stdlib@go1.25.7
1.25.10
7
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
stdlib@go1.25.7
1.25.10
7
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
stdlib@go1.24.2
1.25.10
7
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
stdlib@go1.19.12
1.25.10
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.10
6
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.25.10
6
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.10
6
library/mariadb:10:10.11ce66c7be32a0
stdlib@go1.24.6
1.25.10
6
library/mysql:9.7.2257388edf9c8
stdlib@go1.24.6
1.25.10
6
library/postgres:159b1d34adbce1
stdlib@go1.24.6
1.25.10
6
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.10
6
library/registry:2:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.25.10
6
minio/mc:latest:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
stdlib@go1.24.6
1.25.10
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
stdlib@go1.18.2
1.25.10
6

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.