StackRadar

CVE-2026-42499

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,934
of 17,803 indexed, latest versions
Container images
4,529
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatenation in consumePhrase in net/mail

Carried by container images the latest versions of 3,934 of 17,803 indexed charts deploy, on 4,529 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,529
OSV records
DEBIAN-CVE-2026-42499GO-2026-4977
Also known as
BIT-golang-2026-42499

Charts affected

3,934 by stars
ChartLatestAffected imagesRadar Score
retail-store-sample-catalog-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-catalog-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-catalog:1.3.0b654b266fa32
stdlib@go1.24.6
1.25.10

Open the chart page →

773
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
stdlib@go1.16.6
1.25.10

Open the chart page →

28,532
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
stdlib@go1.17.5
1.25.10

Open the chart page →

2,089
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.10

Open the chart page →

2,517
k8scostoptimizerstakaterVerified publisher0.0.51 of 1See more

k8scostoptimizer stakater 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
stdlib@go1.17.8
1.25.10

Open the chart page →

1,409
konfiguratorstakaterVerified publisher0.1.391 of 1See more

konfigurator stakater 0.1.39

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/konfigurator:v0.1.393409565b1ef5
stdlib@go1.17.13
1.25.10

Open the chart page →

1,279
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.25.10

Open the chart page →

2,854
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
stdlib@go1.15.11
1.25.10

Open the chart page →

2,174
vaultstakaterVerified publisher0.8.42 of 2See more

vault stakater 0.8.4

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
stdlib@go1.16.7
1.25.10
hashicorp/vault-k8s:0.14.0aff47b5ba39c
stdlib@go1.17.2
1.25.10

Open the chart page →

5,872
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
stdlib@go1.13.1
1.25.10

Open the chart page →

2,565
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
stdlib@go1.16.13
1.25.10

Open the chart page →

6,679
stakefishstakefish0.1.06 of 8See more

stakefish stakefish 0.1.0

6 of the 8 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
stdlib@go1.22.3
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
stdlib@go1.22.2
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.10
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
stdlib@go1.22.2
1.25.10
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.10

Open the chart page →

20,351
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
stdlib@go1.22.12
1.25.10

Open the chart page →

2,994
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.10

Open the chart page →

1,262
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.25.10

Open the chart page →

4,110
mev-booststakewise1.7.41 of 1See more

mev-boost stakewise 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
flashbots/mev-boost:1.8.07c486b5789da
stdlib@go1.22.6
1.25.10

Open the chart page →

1,260
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
stdlib@go1.17.5
1.25.10

Open the chart page →

6,601
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
stdlib@go1.22.11
1.25.10

Open the chart page →

7,028
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.10

Open the chart page →

1,262
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
stdlib@go1.25.8
1.25.10

Open the chart page →

576
open-appsec-injectorstartechnicaVerified publisher1.1.22 of 3See more

open-appsec-injector startechnica 1.1.2

2 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/openappsec/smartsync:latest580d68c50cc7
stdlib@go1.18.10
1.25.10
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
stdlib@go1.18.10
1.25.10

Open the chart page →

4,354
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.25.10

Open the chart page →

14,619
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
stdlib@go1.18.4
1.25.10

Open the chart page →

1,985
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
stdlib@go1.16.1
1.25.10
prom/prometheus:v2.22.2f7ffebdd428b
stdlib@go1.15.5
1.25.10
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
stdlib@go1.16.5
1.25.10
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
stdlib@go1.16.5
1.25.10

Open the chart page →

16,539
fluentd-operatorstatcan0.5.11 of 1See more

fluentd-operator statcan 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
vmware/kube-fluentd-operator:latestf028c138a5f4
stdlib@go1.21.7
1.25.10

Open the chart page →

1,960
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
stdlib@go1.18.10
1.25.10

Open the chart page →

1,584
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
stdlib@go1.16.3
1.25.10

Open the chart page →

6,597
prometheus-operatorstatcan0.2.24 of 7See more

prometheus-operator statcan 0.2.2

4 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.10
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
stdlib@go1.13.11
1.25.10
squareup/ghostunnel:v1.5.270f4cf270425
stdlib@go1.13.4
1.25.10
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
stdlib@go1.14.3
1.25.10

Open the chart page →

12,252
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
stdlib@go1.19.10
1.25.10

Open the chart page →

1,316
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
stdlib@go1.17.8
1.25.10

Open the chart page →

1,827
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
stdlib@go1.13.5
1.25.10

Open the chart page →

4,223
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.25.10

Open the chart page →

13,669
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,261
snapshot-controllerstevehipwellVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
stdlib@go1.23.1
1.25.10

Open the chart page →

495
snapshot-controllerstevehipwell-helm-charts-snapshot-controllerVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell-helm-charts-snapshot-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
stdlib@go1.23.1
1.25.10

Open the chart page →

495
its-mytabsstone0.3.01 of 1See more

its-mytabs stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.25.10

Open the chart page →

1,526
sn-platform-slimstreamnative1.11.443 of 6See more

sn-platform-slim streamnative 1.11.44

3 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.10
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
stdlib@go1.20.4
1.25.10
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.10

Open the chart page →

62,314
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
headscale/headscale:0.27.1cd37b3001857
stdlib@go1.25.1
1.25.10

Open the chart page →

5,158
stunner-prometheusstunner0.2.14 of 4See more

stunner-prometheus stunner 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
stdlib@go1.25.7
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
stdlib@go1.23.0
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
stdlib@go1.23.2
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.10

Open the chart page →

3,064
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
stdlib@go1.24.3
1.25.10

Open the chart page →

2,617
orchestratorsubstraVerified publisher8.8.02 of 3See more

orchestrator substra 8.8.0

2 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.10
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
stdlib@go1.21.13
1.25.10

Open the chart page →

3,058
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.10

Open the chart page →

4,851
lingosubstratusVerified publisher0.2.11 of 1See more

lingo substratus 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
stdlib@go1.22.5
1.25.10

Open the chart page →

1,596
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
stdlib@go1.15.2
1.25.10

Open the chart page →

2,354
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
stdlib@go1.17.8
1.25.10

Open the chart page →

2,071
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
stdlib@go1.20.2
1.25.10

Open the chart page →

2,130
ingress-nginx-external-lbsuminhong1.0.02 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
stdlib@go1.22.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
stdlib@go1.21.6
1.25.10

Open the chart page →

2,094
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
stdlib@go1.20.7
1.25.10

Open the chart page →

1,801
hello-worldsumudu-repo1.0.01 of 1See more

hello-world sumudu-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
sumuduliya/hello-world:latestb7788a2984a3
stdlib@go1.19.13
1.25.10

Open the chart page →

940
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,261

Container images carrying it

4,529 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
stdlib@go1.16.6
1.25.10
1
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
stdlib@go1.15.2
1.25.10
1
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
stdlib@go1.15.2
1.25.10
1
cloudflare/cloudflared:2024.8.314d9c6b01b29
stdlib@go1.22.2-devel-cf
1.25.10
1
cloudflare/cloudflared:2024.5.05d5f70a59d5e
stdlib@go1.22.2-devel-cf
1.25.10
1
cloudflare/cloudflared:2023.10.0c18744ae1767
stdlib@go1.20.6
1.25.10
1
cloudflare/cloudflared:2025.8.0eb5c9324efe3
stdlib@go1.24.4
1.25.10
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
stdlib@go1.19.5
1.25.10
1
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.25.10
1
cloudreve/cloudreve:4.18.0f7a464100bf6
stdlib@go1.25.5
1.25.10
1
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
stdlib@go1.15
1.25.10
1
cmacrae/lgtm:0.1.0dec8d490fe40
stdlib@go1.14.1
1.25.10
1
cockroachdb/cockroach-operator:v2.1.0983312754620
stdlib@go1.13.14
1.25.10
1
codecov/self-hosted-gateway:24.4.1de483faad6e5
stdlib@go1.22.0
1.25.10
1
codenotary/immudb:1.9.77c85d7cc4f22
stdlib@go1.18.10
1.25.10
1
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.25.10
1
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.25.10
1
coderenvs/coder-service:1.44.61deffc4670e6
stdlib@go1.21.9
1.25.10
1
codeskyblue/gohttpserver:latestcaa862590e34
stdlib@go1.16.3
1.25.10
1
cometbft/cometbft:v0.38.1722c2ac018f40
stdlib@go1.22.11
1.25.10
1
conduction/agendaservice-php:latest9cfeeb6c7c20
stdlib@go1.13.10
1.25.10
1
conduction/balance-registration-php:devc36094a41369
stdlib@go1.13.10
1.25.10
1
conduction/betaalservice-php:latestece1ab544c57
stdlib@go1.13.10
1.25.10
1
conduction/cgrc-php:dev25415534d245
stdlib@go1.13.10
1.25.10
1
conduction/checkin-component-php:dev3423845692c1
stdlib@go1.13.10
1.25.10
1
conduction/conduction-ui-php:dev2744565516e8
stdlib@go1.13.10
1.25.10
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
stdlib@go1.13.10
1.25.10
1
conduction/docparser-php:devb6f95c8ead7d
stdlib@go1.13.10
1.25.10
1
conduction/kvk-php:dev8f177f9f8a7b
stdlib@go1.13.10
1.25.10
1
conduction/pan-php:dev24f03c57568f
stdlib@go1.13.10
1.25.10
1
containous/maesh:v1.3.2587162516502
stdlib@go1.14.4
1.25.10
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
stdlib@go1.22.7
1.25.10
1
coredns/coredns:1.12.040384aa1f5ea
stdlib@go1.23.3
1.25.10
1
coredns/coredns:1.7.073ca82b4ce82
stdlib@go1.14.4
1.25.10
1
coredns/coredns:1.10.1a0ead06651cf
stdlib@go1.20
1.25.10
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
stdlib@go1.24.1
1.25.10
1
cortezaproject/corteza:2024.9.08eb7a26605c9
stdlib@go1.19.13
1.25.10
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
stdlib@go1.24.1
1.25.10
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
stdlib@go1.23.5
1.25.10
1
countly/api:25.05.4f4cc7447c4f5
stdlib@go1.19.4
1.25.10
1
countly/countly-server:25.05.4e3c238248f99
stdlib@go1.21.11
1.25.10
1
countly/frontend:25.05.42acbc11499b6
stdlib@go1.19.4
1.25.10
1
craftypath/sops-operator:v0.8.0402a0024c732
stdlib@go1.16.5
1.25.10
1
crossplane/crossplane:v0.12.066666e6963af
stdlib@go1.14.4
1.25.10
1
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
stdlib@go1.13.14
1.25.10
1
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
stdlib@go1.13.15
1.25.10
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
stdlib@go1.14.2
1.25.10
1
csepulvedab/secret-sync:0.5227a6f2b0ff8
stdlib@go1.19.4
1.25.10
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
stdlib@go1.14.4
1.25.10
1
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
stdlib@go1.15
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.