StackRadar

CVE-2026-42499

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,939
of 17,787 indexed, latest versions
Container images
4,537
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatenation in consumePhrase in net/mail

Carried by container images the latest versions of 3,939 of 17,787 indexed charts deploy, on 4,537 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,537
OSV records
DEBIAN-CVE-2026-42499GO-2026-4977
Also known as
BIT-golang-2026-42499

Charts affected

3,939 by stars
ChartLatestAffected imagesRadar Score
akto-k8s-ebpfakto0.1.31 of 1See more

akto-k8s-ebpf akto 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_ebpffcf8be10bead
stdlib@go1.25.8
1.25.10

Open the chart page →

838
akto-k8s-ebpf-openshiftakto0.1.11 of 1See more

akto-k8s-ebpf-openshift akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
stdlib@go1.25.9
1.25.10

Open the chart page →

1,277
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
stdlib@go1.25.4
1.25.10

Open the chart page →

3,181
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
stdlib@go1.23.4
1.25.10

Open the chart page →

6,447
akto-mini-testing-kafkaakto1.42.11 of 5See more

akto-mini-testing-kafka akto 1.42.1

1 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
stdlib@go1.23.4
1.25.10

Open the chart page →

6,395
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
stdlib@go1.24.6
1.25.10

Open the chart page →

1,843
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
stdlib@go1.23.4
1.25.10

Open the chart page →

11,283
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
stdlib@go1.22.5
1.25.10

Open the chart page →

4,881
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
stdlib@go1.23.4
1.25.10

Open the chart page →

4,856
api-gateway-loggingakto0.1.21 of 1See more

api-gateway-logging akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-openapi12ed2544756f
stdlib@go1.23.3
1.25.10

Open the chart page →

413
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
stdlib@go1.16.9
1.25.10

Open the chart page →

2,228
rabbitmq-cluster-operatoralekcVerified publisher2.9.01 of 1See more

rabbitmq-cluster-operator alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
stdlib@go1.25.8
1.25.10

Open the chart page →

257
valkey-operatoralekcVerified publisher0.4.01 of 1See more

valkey-operator alekc 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/hyperspike/valkey-operator:v0.0.617d8c669f11a4
stdlib@go1.25.2
1.25.10

Open the chart page →

333
mautrix-signalalexanderbadel0.1.11 of 2See more

mautrix-signal alexanderbadel 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.25.10

Open the chart page →

2,099
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
stdlib@go1.20.2
1.25.10

Open the chart page →

882
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
stdlib@go1.25.7
1.25.10

Open the chart page →

1,624
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.25.10

Open the chart page →

1,727
gotifyalexvanderberkelVerified publisher0.7.01 of 1See more

gotify alexvanderberkel 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
gotify/server:3.1.0be44495e4609
stdlib@go1.26.0
1.25.10

Open the chart page →

320
book-serveral-masood-helm-charts0.1.01 of 1See more

book-server al-masood-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
almasood/book-server:latest6ffac9b63cdf
stdlib@go1.24.6
1.25.10

Open the chart page →

480
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
stdlib@go1.14.15
1.25.10

Open the chart page →

2,115
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
stdlib@go1.24.0
1.25.10

Open the chart page →

557
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
stdlib@go1.24.0
1.25.10

Open the chart page →

557
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
stdlib@go1.24.3
1.25.10

Open the chart page →

1,005
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
stdlib@go1.24.2
1.25.10

Open the chart page →

534
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
stdlib@go1.23.3
1.25.10
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
stdlib@go1.23.1
1.25.10

Open the chart page →

4,414
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
stdlib@go1.23.3
1.25.10

Open the chart page →

575
versitygwalpineworks0.1.21 of 1See more

versitygw alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
versity/versitygw:v1.0.145192635d0353
stdlib@go1.24.3
1.25.10

Open the chart page →

1,114
versitygw-webhook-pulsar-proxyalpineworks0.1.11 of 1See more

versitygw-webhook-pulsar-proxy alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
stdlib@go1.24.4
1.25.10

Open the chart page →

893
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,233
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
stdlib@go1.22.2
1.25.10
daprio/dashboard:0.14.07ba5d51e5b97
stdlib@go1.19.13
1.25.10
daprio/injector:1.11.2763b9b70b0c8
stdlib@go1.20.6
1.25.10
daprio/operator:1.11.2c584428aa12d
stdlib@go1.20.6
1.25.10
daprio/placement:1.11.2d8e1446da996
stdlib@go1.20.6
1.25.10
daprio/sentry:1.11.21f507c1a181b
stdlib@go1.20.6
1.25.10
hashicorp/vault:1.15.26b4e5dadf082
stdlib@go1.21.3
1.25.10
hashicorp/vault-k8s:1.3.15d74a885ae3e
stdlib@go1.21.3
1.25.10

Open the chart page →

28,212
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
stdlib@go1.20.14
1.25.10

Open the chart page →

1,592
anchore-admission-controlleranchore-charts0.8.51 of 2See more

anchore-admission-controller anchore-charts 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
stdlib@go1.20.14
1.25.10

Open the chart page →

7,559
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
stdlib@go1.19.7
1.25.10

Open the chart page →

1,326
cert-manager-webhook-inwxandibraeuVerified publisher0.9.01 of 1See more

cert-manager-webhook-inwx andibraeu 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
stdlib@go1.25.7
1.25.10

Open the chart page →

592
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
stdlib@go1.25.7
1.25.10

Open the chart page →

5,838
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
stdlib@go1.25.7
1.25.10

Open the chart page →

1,286
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,233
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
stdlib@go1.16.4
1.25.10

Open the chart page →

1,985
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.25.10

Open the chart page →

2,239
dnsmadeeasy-webhookangelnu6.0.71 of 1See more

dnsmadeeasy-webhook angelnu 6.0.7

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/angelnu/dnsmadeeasy-webhook:v1.9.0a5ca158b1f02
stdlib@go1.24.1
1.25.10

Open the chart page →

803
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.25.10

Open the chart page →

42,345
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
stdlib@go1.23.12
1.25.10

Open the chart page →

767
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
stdlib@go1.13.15
1.25.10

Open the chart page →

2,488
ddosifyanteonVerified publisher1.7.55 of 13See more

ddosify anteon 1.7.5

5 of the 13 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
stdlib@go1.20.8
1.25.10
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
stdlib@go1.18.1
1.25.10
library/influxdb:2.6.1-alpine44a366dd7724
stdlib@go1.19.4
1.25.10
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.10
prom/prometheus:v2.37.98176adea328e
stdlib@go1.19.11
1.25.10

Open the chart page →

25,720
antmediaantmediaVerified publisher3.1.03 of 4See more

antmedia antmedia 3.1.0

3 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mongo:8.002a0cc7939f5
stdlib@go1.24.6
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.10

Open the chart page →

4,615
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.10

Open the chart page →

3,322
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
stdlib@go1.25.7
1.25.10

Open the chart page →

2,454
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
stdlib@go1.15
1.25.10

Open the chart page →

2,730
glauthanza-labsVerified publisher1.0.11 of 1See more

glauth anza-labs 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/glauth/glauth:v2.5.209c782ca5984
stdlib@go1.25.0
1.25.10

Open the chart page →

1,285
apipingapiping1.5.01 of 1See more

apiping apiping 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
udhos/apiping:1.5.041ab9bae6f3b
stdlib@go1.25.4
1.25.10

Open the chart page →

1,132

Container images carrying it

4,537 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
stdlib@go1.18.2
1.25.10
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.25.10
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
stdlib@go1.16.6
1.25.10
6
quay.io/devtron/kubectl:latest2ad610626658
stdlib@go1.18.5
1.25.10
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
stdlib@go1.19.9
1.25.10
6
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.25.10
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
stdlib@go1.17.6
1.25.10
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.25.10
6
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
stdlib@go1.26.1
1.25.10
6
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
stdlib@go1.25.3
1.25.10
6
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.25.10
6
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
stdlib@go1.23.7
1.25.10
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
stdlib@go1.23.3
1.25.10
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.10
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.10
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0:v2.8.1f6717ce72a26
stdlib@go1.20.3
1.25.10
6
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.25.10
6
alpine/kubectl:1.34.18413f8890d19
stdlib@go1.24.6
1.25.10
5
bitnamilegacy/kubectl:1.29.2c74b703deed2
stdlib@go1.21.7
1.25.10
5
containous/whoami:latest:v1.5.07d6a3c8f9147
stdlib@go1.14
1.25.10
5
keelhq/keel:latest73714afb4443
stdlib@go1.23.4
1.25.10
5
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.25.10
5
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.25.10
5
library/redis:7.4.2-alpine:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.25.10
5
library/redis:5:5.0fc5ecd863862
stdlib@go1.16.7
1.25.10
5
natsio/nats-box:0.14.1a67913df95f1
stdlib@go1.21.3
1.25.10
5
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10
5
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.25.10
5
prom/memcached-exporter:v0.15.4b6763ecb3c47
stdlib@go1.25.3
1.25.10
5
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.25.10
5
sigma2as/goidc-proxy:next656ac798963a
stdlib@go1.25.7
1.25.10
5
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.10
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
stdlib@go1.24.2
1.25.10
5
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.25.10
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
stdlib@go1.16.7
1.25.10
5
quay.io/prometheus/blackbox-exporter:latest:v0.28.0e753ff9f3fc4
stdlib@go1.25.5
1.25.10
5
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
stdlib@go1.26.1
1.25.10
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
stdlib@go1.26.1
1.25.10
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.25.10
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
stdlib@go1.21.3
1.25.10
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.10
5
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
stdlib@go1.25.7
1.25.10
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
stdlib@go1.16.2
1.25.10
5
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
stdlib@go1.25.7
1.25.10
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
stdlib@go1.20.3
1.25.10
5
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
stdlib@go1.25.7
1.25.10
5
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.25.10
4
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.25.10
4
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.10
4
cloudflare/cloudflared:2026.3.06b599ca3e974
stdlib@go1.24.13
1.25.10
4

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.