StackRadar

CVE-2026-40890

High

Advisory

Published 14 Apr 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
22
deployed by those charts
Fix available
1 of 1
affected package

Go Markdown has an Out-of-bounds Read in SmartypantsRenderer

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 22 images.

Affected packageAffected versionsFixed inImages
github.com/gomarkdown/markdowngolangv0.0.0-20191123064959-2c17d62f5098, v0.0.0-20230716120725-531d2d74bc12, v0.0.0-20230922112808-5421fefb8386, v0.0.0-20240729212818-a2a9c4f76ef5+4 more0.0.0-20260411013819-759bbc3e320722
OSV records
GHSA-77fj-vx54-gvh7
Also known as
GO-2026-5208

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.28cfde8170c92f
github.com/gomarkdown/markdown@v0.0.0-20250311123330-531bef5e742b
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

30,816
agentareaagentareaVerified publisher0.0.182 of 16See more

agentarea agentarea 0.0.18

2 of the 16 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
temporalio/auto-setup:1.29.15b3502a3b685
github.com/gomarkdown/markdown@v0.0.0-20250311123330-531bef5e742b
0.0.0-20260411013819-759bbc3e3207
temporalio/ui:2.39.0b768f87f18b5
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

14,914
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
temporalio/auto-setup:1.27.2b44cbfeb43db
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

12,473
platform-apiappscodeVerified publisher2026.9.111 of 3See more

platform-api appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
github.com/gomarkdown/markdown@v0.0.0-20250810172220-2e2c11897d1a
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

37,268
temporalcastaiVerified publisher0.54.23 of 14See more

temporal castai 0.54.2

3 of the 14 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.26.237e2e33dbd7b
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207
temporalio/server:1.26.21e2626efcbc1
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207
temporalio/ui:2.33.05c586a3c8ec5
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

16,198
svacerhelm-svacer0.6.01 of 1See more

svacer helm-svacer 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
ispras/svacer:11-2-042aa9fa9f189
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

6,015
kbot-self-hostedkbot-self-hostedVerified publisher0.1.81 of 7See more

kbot-self-hosted kbot-self-hosted 0.1.8

1 of the 7 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.30206a6c708fc6
github.com/gomarkdown/markdown@v0.0.0-20260217112301-37c66b85d6ab
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

32,509
rotational-apirotationalVerified publisher1.3.11 of 1See more

rotational-api rotational 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
rotationalio/rotational-api:1.3.0f1a2d05d8fff
github.com/gomarkdown/markdown@v0.0.0-20260217112301-37c66b85d6ab
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

1,567
agentssynapse0.1.302 of 9See more

agents synapse 0.1.30

2 of the 9 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/gomarkdown/markdown@v0.0.0-20191123064959-2c17d62f5098
0.0.0-20260411013819-759bbc3e3207
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/gomarkdown/markdown@v0.0.0-20191123064959-2c17d62f5098
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

7,244
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/gomarkdown/markdown@v0.0.0-20230922112808-5421fefb8386
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

8,518
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
github.com/gomarkdown/markdown@v0.0.0-20230922112808-5421fefb8386
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
github.com/gomarkdown/markdown@v0.0.0-20191123064959-2c17d62f5098
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

1,955
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
github.com/gomarkdown/markdown@v0.0.0-20250311123330-531bef5e742b
0.0.0-20260411013819-759bbc3e3207
temporalio/server:1.29.1c1e3326b2ce1
github.com/gomarkdown/markdown@v0.0.0-20250311123330-531bef5e742b
0.0.0-20260411013819-759bbc3e3207
temporalio/ui:2.44.00b36e00aad30
github.com/gomarkdown/markdown@v0.0.0-20240729212818-a2a9c4f76ef5
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

14,983
oauth2xdVerified publisher1.0.01 of 1See more

oauth2 xd 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
lishimeng/hufu:v1.2.13d5752dac834
github.com/gomarkdown/markdown@v0.0.0-20230716120725-531d2d74bc12
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

2,007
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-40890.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
github.com/gomarkdown/markdown@v0.0.0-20230922112808-5421fefb8386
0.0.0-20260411013819-759bbc3e3207
lishimeng/owl-messager:v0.11.23d00485e64dc
github.com/gomarkdown/markdown@v0.0.0-20230922112808-5421fefb8386
0.0.0-20260411013819-759bbc3e3207

Open the chart page →

3,880

Container images carrying it

22 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gotenberg/gotenberg:8.30206a6c708fc6
github.com/gomarkdown/markdown@v0.0.0-20260217112301-37c66b85d6ab
0.0.0-20260411013819-759bbc3e3207
1
ispras/svacer:11-2-042aa9fa9f189
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207
1
lishimeng/hufu:v1.2.13d5752dac834
github.com/gomarkdown/markdown@v0.0.0-20230716120725-531d2d74bc12
0.0.0-20260411013819-759bbc3e3207
1
lishimeng/owl-console:v0.11.2c79a67657baf
github.com/gomarkdown/markdown@v0.0.0-20230922112808-5421fefb8386
0.0.0-20260411013819-759bbc3e3207
1
lishimeng/owl-messager:v0.11.23d00485e64dc
github.com/gomarkdown/markdown@v0.0.0-20230922112808-5421fefb8386
0.0.0-20260411013819-759bbc3e3207
1
rotationalio/rotational-api:1.3.0f1a2d05d8fff
github.com/gomarkdown/markdown@v0.0.0-20260217112301-37c66b85d6ab
0.0.0-20260411013819-759bbc3e3207
1
temporalio/admin-tools:1.26.237e2e33dbd7b
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
github.com/gomarkdown/markdown@v0.0.0-20250311123330-531bef5e742b
0.0.0-20260411013819-759bbc3e3207
1
temporalio/admin-tools:1.28cfde8170c92f
github.com/gomarkdown/markdown@v0.0.0-20250311123330-531bef5e742b
0.0.0-20260411013819-759bbc3e3207
1
temporalio/auto-setup:1.29.15b3502a3b685
github.com/gomarkdown/markdown@v0.0.0-20250311123330-531bef5e742b
0.0.0-20260411013819-759bbc3e3207
1
temporalio/auto-setup:1.27.2b44cbfeb43db
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207
1
temporalio/server:1.26.21e2626efcbc1
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207
1
temporalio/server:1.29.1c1e3326b2ce1
github.com/gomarkdown/markdown@v0.0.0-20250311123330-531bef5e742b
0.0.0-20260411013819-759bbc3e3207
1
temporalio/ui:2.44.00b36e00aad30
github.com/gomarkdown/markdown@v0.0.0-20240729212818-a2a9c4f76ef5
0.0.0-20260411013819-759bbc3e3207
1
temporalio/ui:2.33.05c586a3c8ec5
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207
1
temporalio/ui:2.39.0b768f87f18b5
github.com/gomarkdown/markdown@v0.0.0-20241105142532-d03b89096d81
0.0.0-20260411013819-759bbc3e3207
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
github.com/gomarkdown/markdown@v0.0.0-20250810172220-2e2c11897d1a
0.0.0-20260411013819-759bbc3e3207
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/gomarkdown/markdown@v0.0.0-20191123064959-2c17d62f5098
0.0.0-20260411013819-759bbc3e3207
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/gomarkdown/markdown@v0.0.0-20230922112808-5421fefb8386
0.0.0-20260411013819-759bbc3e3207
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/gomarkdown/markdown@v0.0.0-20191123064959-2c17d62f5098
0.0.0-20260411013819-759bbc3e3207
1
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
github.com/gomarkdown/markdown@v0.0.0-20230922112808-5421fefb8386
0.0.0-20260411013819-759bbc3e3207
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
github.com/gomarkdown/markdown@v0.0.0-20191123064959-2c17d62f5098
0.0.0-20260411013819-759bbc3e3207
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.