StackRadar

CVE-2026-39829

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,440
of 17,787 indexed, latest versions
Container images
2,788
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

Carried by container images the latest versions of 2,440 of 17,787 indexed charts deploy, on 2,788 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+153 more0.52.02,788
OSV records
GHSA-w879-237q-wc7r
Also known as
GO-2026-5018

Charts affected

2,440 by stars
ChartLatestAffected imagesRadar Score
gitlab-mr-conformgitlab-mr-conform0.5.21 of 1See more

gitlab-mr-conform gitlab-mr-conform 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
ghcr.io/chrxmvtik/gitlab-mr-conform:0.5.2b2eb79fc99cb
golang.org/x/crypto@v0.48.0
0.52.0

Open the chart page →

428
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
golang.org/x/crypto@v0.10.0
0.52.0

Open the chart page →

2,609
prometheus-container-resource-exportergkarthiks0.3.11 of 1See more

prometheus-container-resource-exporter gkarthiks 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
gkarthics/container-resource-exporter:latest6799af333e8a
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.52.0

Open the chart page →

2,218
glassflow-etlglassflowVerified publisher0.5.217 of 16See more

glassflow-etl glassflow 0.5.21

7 of the 16 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
library/nats:2.12.3-alpine88fe8e0e09d6
golang.org/x/crypto@v0.46.0
0.52.0
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/crypto@v0.31.0
0.52.0
natsio/prometheus-nats-exporter:0.17.326c826662ac8
golang.org/x/crypto@v0.38.0
0.52.0
otel/opentelemetry-collector-contrib:0.108.0923eb1cfae32
golang.org/x/crypto@v0.26.0
0.52.0
ghcr.io/glassflow/glassflow-etl-be:v3.2.020f066d0f631
golang.org/x/crypto@v0.49.0
0.52.0
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
golang.org/x/crypto@v0.41.0
0.52.0
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

12,072
glassflow-operatorglassflow-operatorVerified publisher0.8.51 of 3See more

glassflow-operator glassflow-operator 0.8.5

1 of the 3 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
golang.org/x/crypto@v0.41.0
0.52.0

Open the chart page →

763
glauthglauthVerified publisher0.3.171 of 2See more

glauth glauth 0.3.17

1 of the 2 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
golang.org/x/crypto@v0.39.0
0.52.0

Open the chart page →

2,605
glidergliderVerified publisher0.1.51 of 1See more

glider glider 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
nadoo/glider:0.1638aadefbd607
golang.org/x/crypto@v0.26.0
0.52.0

Open the chart page →

894
gnp-stackgnp-stack0.0.54 of 14See more

gnp-stack gnp-stack 0.0.5

4 of the 14 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
grafana/grafana:12.2.135c41e0fd029
golang.org/x/crypto@v0.42.0
0.52.0
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
golang.org/x/crypto@v0.48.0
0.52.0
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/crypto@v0.36.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/crypto@v0.40.0
0.52.0

Open the chart page →

7,662
go-file-servergo-file-server1.0.01 of 2See more

go-file-server go-file-server 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
goccx/go-file-server:latestf4b3ebea0303
golang.org/x/crypto@v0.25.0
0.52.0

Open the chart page →

2,215
gofitgofit0.0.11 of 1See more

gofit gofit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
ghcr.io/bamaas/gofit:0.0.132b6a174b419
golang.org/x/crypto@v0.22.0
0.52.0

Open the chart page →

650
gorsegorse-io0.4.23 of 4See more

gorse gorse-io 0.4.2

3 of the 4 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/crypto@v0.0.0-20221010152910-d6f0a8c073c2
0.52.0
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/crypto@v0.0.0-20221010152910-d6f0a8c073c2
0.52.0
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/crypto@v0.0.0-20221010152910-d6f0a8c073c2
0.52.0

Open the chart page →

4,380
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.52.0

Open the chart page →

22,565
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.52.0

Open the chart page →

24,360
harborgpg-dev1.18.34 of 8See more

harbor gpg-dev 1.18.3

4 of the 8 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.14.3a30e5a8be3d9
golang.org/x/crypto@v0.45.0
0.52.0
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
golang.org/x/crypto@v0.45.0
0.52.0
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
golang.org/x/crypto@v0.45.0
0.52.0
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

3,376
jaegergpg-dev3.3.32 of 5See more

jaeger gpg-dev 3.3.3

2 of the 5 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/crypto@v0.17.0
0.52.0
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/crypto@v0.17.0
0.52.0

Open the chart page →

19,291
kube-prometheus-stackgpg-dev84.0.03 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

3 of the 6 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
grafana/grafana:13.0.10f86bada30d6
golang.org/x/crypto@v0.49.0
0.52.0
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/crypto@v0.49.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

4,290
kubernetes-dashboardgpg-dev7.5.03 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

3 of the 5 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
kubernetesui/dashboard-api:1.7.060595892c2cf
golang.org/x/crypto@v0.23.0
0.52.0
kubernetesui/dashboard-auth:1.1.307135c09e9ff
golang.org/x/crypto@v0.21.0
0.52.0
kubernetesui/dashboard-web:1.4.04445b31a2c25
golang.org/x/crypto@v0.23.0
0.52.0

Open the chart page →

6,075
metrics-servergpg-dev3.12.11 of 1See more

metrics-server gpg-dev 3.12.1

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/crypto@v0.18.0
0.52.0

Open the chart page →

1,071
opentelemetry-demogpg-dev0.33.87 of 27See more

opentelemetry-demo gpg-dev 0.33.8

7 of the 27 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
golang.org/x/crypto@v0.27.0
0.52.0
jaegertracing/all-in-one:1.53.060e65bfffe1f
golang.org/x/crypto@v0.17.0
0.52.0
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
golang.org/x/crypto@v0.29.0
0.52.0
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
golang.org/x/crypto@v0.25.0
0.52.0
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
golang.org/x/crypto@v0.23.0
0.52.0
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
golang.org/x/crypto@v0.17.0
0.52.0
quay.io/prometheus/prometheus:v3.0.03b9b2a15d376
golang.org/x/crypto@v0.28.0
0.52.0

Open the chart page →

47,117
prometheusgpg-dev29.2.16 of 6See more

prometheus gpg-dev 29.2.1

6 of the 6 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.90.1693faa0b8724
golang.org/x/crypto@v0.49.0
0.52.0
quay.io/prometheus/alertmanager:v0.32.058e117eabcce
golang.org/x/crypto@v0.49.0
0.52.0
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/crypto@v0.49.0
0.52.0
quay.io/prometheus/prometheus:v3.11.2cd37346c9745
golang.org/x/crypto@v0.49.0
0.52.0
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/crypto@v0.43.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

3,261
thanosgpg-dev0.5.31 of 1See more

thanos gpg-dev 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/crypto@v0.47.0
0.52.0

Open the chart page →

592
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
golang.org/x/crypto@v0.48.0
0.52.0

Open the chart page →

1,275
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

1,553
grafana-cloud-onboardinggrafana0.4.73 of 5See more

grafana-cloud-onboarding grafana 0.4.7

3 of the 5 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
golang.org/x/crypto@v0.47.0
0.52.0
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/crypto@v0.49.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

4,657
grafana-samplinggrafana1.1.72 of 2See more

grafana-sampling grafana 1.1.7

2 of the 2 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
golang.org/x/crypto@v0.41.0
0.52.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/crypto@v0.36.0
0.52.0

Open the chart page →

3,357
mimir-openshift-experimentalgrafana2.1.03 of 4See more

mimir-openshift-experimental grafana 2.1.0

3 of the 4 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.52.0
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
golang.org/x/crypto@v0.0.0-20201124201722-c8d3bf9c5392
0.52.0
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/crypto@v0.0.0-20201124201722-c8d3bf9c5392
0.52.0

Open the chart page →

17,759
pyroscope-monitoringgrafana0.1.14 of 6See more

pyroscope-monitoring grafana 0.1.1

4 of the 6 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
golang.org/x/crypto@v0.41.0
0.52.0
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
golang.org/x/crypto@v0.39.0
0.52.0
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/crypto@v0.36.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/crypto@v0.40.0
0.52.0

Open the chart page →

8,226
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/crypto@v0.28.0
0.52.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/crypto@v0.28.0
0.52.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/crypto@v0.18.0
0.52.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/crypto@v0.21.0
0.52.0
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/crypto@v0.26.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/crypto@v0.28.0
0.52.0

Open the chart page →

5,304
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.52.0

Open the chart page →

7,510
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/crypto@v0.27.0
0.52.0

Open the chart page →

7,935
armada-executorgresearch0.22.81 of 1See more

armada-executor gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
gresearch/armada-executor:latest393aff4aa8f2
golang.org/x/crypto@v0.51.0
0.52.0

Open the chart page →

707
armada-lookout-ingestergresearch0.22.81 of 1See more

armada-lookout-ingester gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
gresearch/armada-lookout-ingester:latest3df14cda1855
golang.org/x/crypto@v0.51.0
0.52.0

Open the chart page →

707
armada-lookout-migrationgresearch0.22.81 of 1See more

armada-lookout-migration gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
gresearch/armada-lookout:latestf5e3226f1d33
golang.org/x/crypto@v0.51.0
0.52.0

Open the chart page →

707
armada-scheduler-migrationgresearch0.22.81 of 1See more

armada-scheduler-migration gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
gresearch/armada-scheduler:latest6141a6213fcb
golang.org/x/crypto@v0.51.0
0.52.0

Open the chart page →

707
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/crypto@v0.22.0
0.52.0

Open the chart page →

1,391
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.52.0

Open the chart page →

14,312
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/crypto@v0.25.0
0.52.0

Open the chart page →

2,589
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.52.0

Open the chart page →

2,175
routergroundcover1.12.3591 of 7See more

router groundcover 1.12.359

1 of the 7 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/crypto@v0.49.0
0.52.0

Open the chart page →

6,038
temporalgroundcover1.12.3591 of 2See more

temporal groundcover 1.12.359

1 of the 2 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
golang.org/x/crypto@v0.50.0
0.52.0

Open the chart page →

2,001
tailscale-subnet-routergtaylor1.2.11 of 1See more

tailscale-subnet-router gtaylor 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.52.0

Open the chart page →

1,834
minifluxhajowielandVerified publisher1.0.01 of 1See more

miniflux hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/crypto@v0.37.0
0.52.0

Open the chart page →

1,112
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.52.0

Open the chart page →

2,374
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.52.0

Open the chart page →

4,455
thunderdome-planning-pokerhalkeye0.1.11 of 1See more

thunderdome-planning-poker halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
golang.org/x/crypto@v0.49.0
0.52.0

Open the chart page →

418
hcp-terraform-operatorhashicorpVerified publisher2.12.11 of 2See more

hcp-terraform-operator hashicorp 2.12.1

1 of the 2 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.20.1f5fbfec6a2b2
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

678
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.52.0

Open the chart page →

3,022
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/crypto@v0.0.0-20191029031824-8986dd9e96cf
0.52.0

Open the chart page →

2,630
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.52.0

Open the chart page →

6,747
headcniheadcni1.0.101 of 1See more

headcni headcni 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-39829.

Container imageDigestPackageFixed in
binrc/headcni:1.0.10e199c334b957
golang.org/x/crypto@v0.50.0
0.52.0

Open the chart page →

724

Container images carrying it

2,788 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
minio/minio:latest:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
golang.org/x/crypto@v0.40.0
0.52.0
16
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
golang.org/x/crypto@v0.36.0
0.52.0
13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/crypto@v0.46.0
0.52.0
12
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/crypto@v0.45.0
0.52.0
10
library/mongo:5.0.6-focal8e70544b6c76
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.52.0
10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/crypto@v0.21.0
0.52.0
9
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.52.0
8
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/crypto@v0.27.0
0.52.0
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/crypto@v0.18.0
0.52.0
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.52.0
8
minio/mc:latest:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
golang.org/x/crypto@v0.40.0
0.52.0
7
osixia/openldap:1.5.018742e9c449c
golang.org/x/crypto@v0.0.0-20201012173705-84dcc777aaee
0.52.0
7
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.52.0
7
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
golang.org/x/crypto@v0.38.0
0.52.0
7
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
golang.org/x/crypto@v0.27.0
0.52.0
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/crypto@v0.28.0
0.52.0
7
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/crypto@v0.46.0
0.52.0
7
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/crypto@v0.12.0
0.52.0
6
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/crypto@v0.0.0-20200406173513-056763e48d71
0.52.0
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.52.0
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
0.52.0
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0
6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.52.0
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.52.0
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.52.0
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.52.0
6
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/crypto@v0.49.0
0.52.0
6
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/crypto@v0.42.0
0.52.0
6
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/crypto@v0.21.0
0.52.0
6
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/crypto@v0.36.0
0.52.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/crypto@v0.28.0
0.52.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/crypto@v0.24.0
0.52.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/crypto@v0.21.0
0.52.0
6
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/crypto@v0.51.0
0.52.0
6
keelhq/keel:latest73714afb4443
golang.org/x/crypto@v0.31.0
0.52.0
5
library/mongo:4.44be76f674fc4
golang.org/x/crypto@v0.25.0
0.52.0
5
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/crypto@v0.13.0
0.52.0
5
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/crypto@v0.0.0-20190617133340-57b3e21c3d56
0.52.0
5
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/crypto@v0.42.0
0.52.0
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.52.0
5
sigma2as/goidc-proxy:next656ac798963a
golang.org/x/crypto@v0.48.0
0.52.0
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/crypto@v0.37.0
0.52.0
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.52.0
5
quay.io/prometheus/blackbox-exporter:latest:v0.28.0e753ff9f3fc4
golang.org/x/crypto@v0.45.0
0.52.0
5
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
golang.org/x/crypto@v0.45.0
0.52.0
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.52.0
5
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
golang.org/x/crypto@v0.48.0
0.52.0
5
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/crypto@v0.47.0
0.52.0
5
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
golang.org/x/crypto@v0.47.0
0.52.0
5
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/crypto@v0.38.0
0.52.0
4

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.