StackRadar

CVE-2026-39835

Medium

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,426
of 17,792 indexed, latest versions
Container images
2,770
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

Carried by container images the latest versions of 2,426 of 17,792 indexed charts deploy, on 2,770 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+153 more0.52.02,770
OSV records
GHSA-78mq-xcr3-xm33
Also known as
GO-2026-5015

Charts affected

2,426 by stars
ChartLatestAffected imagesRadar Score
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.52.0

Open the chart page →

9,246
gke-preemptible-notifierslamdev0.0.61 of 1See more

gke-preemptible-notifier slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.52.0

Open the chart page →

2,860
octavia-ingress-controllerslamdev0.0.71 of 1See more

octavia-ingress-controller slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.52.0

Open the chart page →

2,761
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.52.0

Open the chart page →

8,697
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.52.0

Open the chart page →

3,471
avalanchesnowplow-devopsVerified publisher0.12.11 of 6See more

avalanche snowplow-devops 0.12.1

1 of the 6 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
golang.org/x/crypto@v0.37.0
0.52.0

Open the chart page →

1,330
snspingsnsping1.2.91 of 1See more

snsping snsping 1.2.9

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
udhos/snsping:1.2.96ae70677b6a3
golang.org/x/crypto@v0.31.0
0.52.0

Open the chart page →

1,333
cost-analyzersoftonic2.5.53 of 6See more

cost-analyzer softonic 2.5.5

3 of the 6 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
grafana/grafana:11.5.28b37a2f028f1
golang.org/x/crypto@v0.32.0
0.52.0
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
golang.org/x/crypto@v0.31.0
0.52.0
quay.io/prometheus/prometheus:v3.2.16927e0919a14
golang.org/x/crypto@v0.32.0
0.52.0

Open the chart page →

7,957
harborsoftonic1.13.04 of 8See more

harbor softonic 1.13.0

4 of the 8 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
golang.org/x/crypto@v0.7.0
0.52.0
goharbor/harbor-jobservice:v2.9.039435daedd0c
golang.org/x/crypto@v0.7.0
0.52.0
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/crypto@v0.7.0
0.52.0
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/crypto@v0.11.0
0.52.0

Open the chart page →

7,701
kedasoftonic2.17.03 of 3See more

keda softonic 2.17.0

3 of the 3 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.17.0112fc427d933
golang.org/x/crypto@v0.37.0
0.52.0
ghcr.io/kedacore/keda-admission-webhooks:2.17.0a87c42275757
golang.org/x/crypto@v0.37.0
0.52.0
ghcr.io/kedacore/keda-metrics-apiserver:2.17.0167fd532bd43
golang.org/x/crypto@v0.37.0
0.52.0

Open the chart page →

2,597
kube-prometheus-stacksoftonic81.5.13 of 6See more

kube-prometheus-stack softonic 81.5.1

3 of the 6 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
grafana/grafana:12.3.2ba93c9d192e5
golang.org/x/crypto@v0.45.0
0.52.0
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/crypto@v0.42.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

4,989
pod-defaultersoftonic0.1.31 of 1See more

pod-defaulter softonic 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
softonic/pod-defaulter:0.1.072017aed5902
golang.org/x/crypto@v0.0.0-20200728195943-123391ffb6de
0.52.0

Open the chart page →

2,561
rate-limit-operatorsoftonic1.1.01 of 2See more

rate-limit-operator softonic 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
softonic/rate-limit-operator:0.1.1910f6de37763
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.52.0

Open the chart page →

2,219
rclonesoftonic2.1.01 of 1See more

rclone softonic 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
rclone/rclone:1.6874c51b8817e5
golang.org/x/crypto@v0.25.0
0.52.0

Open the chart page →

1,680
sealed-secretssoftonic2.6.91 of 1See more

sealed-secrets softonic 2.6.9

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.52.0

Open the chart page →

1,515
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/crypto@v0.12.0
0.52.0

Open the chart page →

2,513
gloo-meshsolo-gloo-mesh1.1.21 of 1See more

gloo-mesh solo-gloo-mesh 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.52.0

Open the chart page →

3,266
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.52.0

Open the chart page →

30,779
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
golang.org/x/crypto@v0.31.0
0.52.0

Open the chart page →

3,284
spinnakerspinnakerVerified publisher2.2.132 of 4See more

spinnaker spinnaker 2.2.13

2 of the 4 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/crypto@v0.0.0-20201012173705-84dcc777aaee
0.52.0
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/crypto@v0.0.0-20191117063200-497ca9f6d64f
0.52.0

Open the chart page →

6,850
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
golang.org/x/crypto@v0.47.0
0.52.0

Open the chart page →

2,264
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.52.0

Open the chart page →

6,959
airflowsqream-chartsVerified publisher1.17.01 of 4See more

airflow sqream-charts 1.17.0

1 of the 4 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
quay.io/prometheus/statsd-exporter:v0.27.29ed70604d941
golang.org/x/crypto@v0.26.0
0.52.0

Open the chart page →

1,854
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
golang.org/x/crypto@v0.21.0
0.52.0

Open the chart page →

2,422
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/crypto@v0.3.0
0.52.0

Open the chart page →

67,262
ecr-cleanersstarcher0.1.1+d13a1ab1 of 1See more

ecr-cleaner sstarcher 0.1.1+d13a1ab

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
sstarcher/ecr-cleaner:0.1.12d43c390cb19
golang.org/x/crypto@v0.0.0-20190426145343-a29dc8fdc734
0.52.0

Open the chart page →

2,575
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
golang.org/x/crypto@v0.0.0-20191028145041-f83a4685e152
0.52.0

Open the chart page →

3,096
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.52.0

Open the chart page →

3,073
retail-store-sample-catalog-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-catalog-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-catalog:1.3.0b654b266fa32
golang.org/x/crypto@v0.39.0
0.52.0

Open the chart page →

766
stageset-controllerstageset-controllerOfficialVerified publisher2026.6.15+1543421 of 1See more

stageset-controller stageset-controller 2026.6.15+154342

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
ghcr.io/metio/stageset-controller:2026.6.14234b66bb3319
golang.org/x/crypto@v0.51.0
0.52.0

Open the chart page →

313
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.52.0

Open the chart page →

28,515
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.52.0

Open the chart page →

2,088
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/crypto@v0.36.0
0.52.0

Open the chart page →

2,498
konfiguratorstakaterVerified publisher0.1.391 of 1See more

konfigurator stakater 0.1.39

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
stakater/konfigurator:v0.1.393409565b1ef5
golang.org/x/crypto@v0.17.0
0.52.0

Open the chart page →

1,279
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.52.0

Open the chart page →

2,853
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.52.0

Open the chart page →

2,173
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.52.0

Open the chart page →

5,871
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.52.0

Open the chart page →

2,564
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.52.0

Open the chart page →

6,678
stakefishstakefish0.1.06 of 8See more

stakefish stakefish 0.1.0

6 of the 8 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
golang.org/x/crypto@v0.22.0
0.52.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
golang.org/x/crypto@v0.21.0
0.52.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/crypto@v0.18.0
0.52.0
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
golang.org/x/crypto@v0.21.0
0.52.0
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/crypto@v0.21.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/crypto@v0.21.0
0.52.0

Open the chart page →

20,321
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
golang.org/x/crypto@v0.31.0
0.52.0

Open the chart page →

2,968
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/crypto@v0.32.0
0.52.0

Open the chart page →

1,249
mev-booststakewise1.7.41 of 1See more

mev-boost stakewise 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
flashbots/mev-boost:1.8.07c486b5789da
golang.org/x/crypto@v0.23.0
0.52.0

Open the chart page →

1,260
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0

Open the chart page →

6,587
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
golang.org/x/crypto@v0.32.0
0.52.0

Open the chart page →

6,873
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/crypto@v0.32.0
0.52.0

Open the chart page →

1,249
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
golang.org/x/crypto@v0.49.0
0.52.0

Open the chart page →

576
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.52.0

Open the chart page →

1,985
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.52.0
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.52.0
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.52.0
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.52.0

Open the chart page →

16,537
fluentd-operatorstatcan0.5.11 of 1See more

fluentd-operator statcan 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-39835.

Container imageDigestPackageFixed in
vmware/kube-fluentd-operator:latestf028c138a5f4
golang.org/x/crypto@v0.17.0
0.52.0

Open the chart page →

1,957

Container images carrying it

2,770 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.52.0
4
grafana/loki:2.6.11ee60f980950
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.52.0
4
grafana/loki:3.6.73c8fd3570dd9
golang.org/x/crypto@v0.45.0
0.52.0
4
grafana/tempo:2.9.065a578975943
golang.org/x/crypto@v0.41.0
0.52.0
4
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0
4
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0
4
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0
4
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/crypto@v0.17.0
0.52.0
4
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/crypto@v0.17.0
0.52.0
4
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/crypto@v0.45.0
0.52.0
4
library/mongo:4.4.66efa05203990
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.52.0
4
library/registry:3.1.1:latest1be55279f18a
golang.org/x/crypto@v0.49.0
0.52.0
4
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/crypto@v0.48.0
0.52.0
4
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
golang.org/x/crypto@v0.18.0
0.52.0
4
ghcr.io/appscode/petset:v0.1.093fa0daf603c
golang.org/x/crypto@v0.46.0
0.52.0
4
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
golang.org/x/crypto@v0.46.0
0.52.0
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/crypto@v0.5.0
0.52.0
4
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
golang.org/x/crypto@v0.33.0
0.52.0
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/crypto@v0.13.0
0.52.0
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/crypto@v0.13.0
0.52.0
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/crypto@v0.13.0
0.52.0
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/crypto@v0.1.0
0.52.0
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.52.0
4
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/crypto@v0.36.0
0.52.0
4
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/crypto@v0.38.0
0.52.0
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/crypto@v0.22.0
0.52.0
4
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.52.0
3
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.52.0
3
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.52.0
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/crypto@v0.14.0
0.52.0
3
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.52.0
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/crypto@v0.43.0
0.52.0
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.52.0
3
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/crypto@v0.32.0
0.52.0
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.52.0
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
golang.org/x/crypto@v0.45.0
0.52.0
3
ethpandaops/tracoor:latestd8514b9f4c59
golang.org/x/crypto@v0.38.0
0.52.0
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.52.0
3
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/crypto@v0.21.0
0.52.0
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/crypto@v0.27.0
0.52.0
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/crypto@v0.32.0
0.52.0
3
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/crypto@v0.45.0
0.52.0
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.52.0
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.52.0
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/crypto@v0.45.0
0.52.0
3
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/crypto@v0.17.0
0.52.0
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/crypto@v0.2.0
0.52.0
3
library/nats:2.10-alpineb83efabe3e7d
golang.org/x/crypto@v0.37.0
0.52.0
3
louislam/uptime-kuma:2.5.4917318f9d7be
golang.org/x/crypto@v0.51.0
0.52.0
3
migrate/migrate:latestcc4ad8e19d66
golang.org/x/crypto@v0.45.0
0.52.0
3

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.