StackRadar

CVE-2026-42499

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,925
of 17,792 indexed, latest versions
Container images
4,508
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatenation in consumePhrase in net/mail

Carried by container images the latest versions of 3,925 of 17,792 indexed charts deploy, on 4,508 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,508
OSV records
DEBIAN-CVE-2026-42499GO-2026-4977
Also known as
BIT-golang-2026-42499

Charts affected

3,925 by stars
ChartLatestAffected imagesRadar Score
ddns-updaterdeimosfr-charts2.10.01 of 1See more

ddns-updater deimosfr-charts 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
qmcgaw/ddns-updater:v2.10.03e2aa558946b
stdlib@go1.26.2
1.25.10

Open the chart page →

211
garage-webuideimosfr-charts1.1.01 of 1See more

garage-webui deimosfr-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
khairul169/garage-webui:1.1.017c793551873
stdlib@go1.23.12
1.25.10

Open the chart page →

567
aws-s3-proxydeliveryheroVerified publisher0.1.71 of 1See more

aws-s3-proxy deliveryhero 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
pottava/s3-proxy:2.020a0bcb15f76
stdlib@go1.13.7
1.25.10

Open the chart page →

1,323
aws-service-events-exporterdeliveryheroVerified publisher1.0.71 of 1See more

aws-service-events-exporter deliveryhero 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
stdlib@go1.15.6
1.25.10

Open the chart page →

1,299
aws-service-quotas-exporterdeliveryheroVerified publisher0.1.41 of 1See more

aws-service-quotas-exporter deliveryhero 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
thoughtmachine/aws-service-quotas-exporter:v1.3.2c6065ba55c72
stdlib@go1.19.4
1.25.10

Open the chart page →

771
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
stdlib@go1.18
1.25.10

Open the chart page →

2,241
field-exporterdeliveryheroVerified publisher1.4.11 of 1See more

field-exporter deliveryhero 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/deliveryhero/field-exporter:v1.4.06b71ba4f9297
stdlib@go1.22.12
1.25.10

Open the chart page →

471
k8s-cloudwatch-adapterdeliveryheroVerified publisher0.2.21 of 1See more

k8s-cloudwatch-adapter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
stdlib@go1.14.5
1.25.10

Open the chart page →

2,475
killgravedeliveryheroVerified publisher1.0.21 of 1See more

killgrave deliveryhero 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
friendsofgo/killgrave:0.4.139cfbecca342
stdlib@go1.16.3
1.25.10

Open the chart page →

1,181
prometheus-aws-limits-exporterdeliveryheroVerified publisher0.2.21 of 1See more

prometheus-aws-limits-exporter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
danielfm/aws-limits-exporter:0.6.07152b84e57cb
stdlib@go1.17.2
1.25.10

Open the chart page →

1,846
prometheus-soti-mobicontrol-exporterdeliveryheroVerified publisher1.0.31 of 1See more

prometheus-soti-mobicontrol-exporter deliveryhero 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.25.10

Open the chart page →

1,644
prometheus-statsd-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-statsd-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.25.10

Open the chart page →

1,315
toxiproxydeliveryheroVerified publisher1.3.91 of 2See more

toxiproxy deliveryhero 1.3.9

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
stdlib@go1.19.13
1.25.10

Open the chart page →

598
dellhw_exporterdellhw-exporterVerified publisher1.0.11 of 1See more

dellhw_exporter dellhw-exporter 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
stdlib@go1.23.2
1.25.10

Open the chart page →

3,233
prometheus-dellhw-exporterdellhw-exporterVerified publisher1.3.01 of 1See more

prometheus-dellhw-exporter dellhw-exporter 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0b3a5806d73b5
stdlib@go1.25.8
1.25.10

Open the chart page →

1,855
challengedeneme0.1.01 of 2See more

challenge deneme 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

2,721
kubeteach-coredergeberl0.2.31 of 1See more

kubeteach-core dergeberl 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
stdlib@go1.19.2
1.25.10

Open the chart page →

1,505
kubeteach-exerciseset1dergeberl0.2.31 of 2See more

kubeteach-exerciseset1 dergeberl 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
stdlib@go1.19.2
1.25.10

Open the chart page →

1,505
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
stdlib@go1.20
1.25.10

Open the chart page →

14,920
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
stdlib@go1.23.7
1.25.10

Open the chart page →

2,530
clamav-apidevhatVerified publisher1.0.11 of 1See more

clamav-api devhat 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
stdlib@go1.20.14
1.25.10

Open the chart page →

2,097
mysqldev-krishan-dhaka-charts1.0.11 of 1See more

mysql dev-krishan-dhaka-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.4b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

463
postgresdev-krishan-dhaka-charts1.0.21 of 1See more

postgres dev-krishan-dhaka-charts 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.10

Open the chart page →

494
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
stdlib@go1.16.7
1.25.10

Open the chart page →

30,156
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mariadb:10.9.4fbb8456ebdb1
stdlib@go1.16.7
1.25.10

Open the chart page →

29,157
wordpressdevops0.12.01 of 4See more

wordpress devops 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
stdlib@go1.16.7
1.25.10

Open the chart page →

13,039
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:13-alpinefb9065b6e3e2
stdlib@go1.24.6
1.25.10

Open the chart page →

2,549
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
stdlib@go1.17.9
1.25.10
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
stdlib@go1.17.9
1.25.10

Open the chart page →

4,735
pushproxdevopstalesVerified publisher0.1.62 of 2See more

pushprox devopstales 0.1.6

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
stdlib@go1.16.4
1.25.10
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
stdlib@go1.16.4
1.25.10

Open the chart page →

3,754
devopsweeklydevopsweekly2.1.01 of 1See more

devopsweekly devopsweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
zufardhiyaulhaq/devopsweekly:v2.1.046625567fb60
stdlib@go1.17.13
1.25.10

Open the chart page →

1,217
lxd8sdevplayer0Verified publisher0.5.12 of 2See more

lxd8s devplayer0 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
stdlib@go1.16.5
1.25.10
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
stdlib@go1.17
1.25.10

Open the chart page →

5,431
octolxddevplayer0Verified publisher0.1.11 of 1See more

octolxd devplayer0 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
stdlib@go1.16.6
1.25.10

Open the chart page →

2,525
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
stdlib@go1.22.4
1.25.10

Open the chart page →

9,685
argocddevtron1.8.12 of 3See more

argocd devtron 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
stdlib@go1.14.12
1.25.10
quay.io/dexidp/dex:v2.25.07bcf286807b8
stdlib@go1.14.9
1.25.10

Open the chart page →

10,484
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
stdlib@go1.17.13
1.25.10

Open the chart page →

13,011
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
stdlib@go1.19.8
1.25.10

Open the chart page →

1,587
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
stdlib@go1.18
1.25.10

Open the chart page →

4,690
devtron-enterprisedevtron48.0.022 of 28See more

devtron-enterprise devtron 48.0.0

22 of the 28 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
stdlib@go1.18.2
1.25.10
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
stdlib@go1.24.0
1.25.10
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
stdlib@go1.25.0
1.25.10
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
stdlib@go1.24.13
1.25.10
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
stdlib@go1.25.0
1.25.10
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.25.10
quay.io/devtron/dex:v2.30.22e4c14d1b444
stdlib@go1.16.6
1.25.10
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
stdlib@go1.25.5
1.25.10
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
stdlib@go1.25.5
1.25.10
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
stdlib@go1.14.15
1.25.10
quay.io/devtron/kubectl:latest2ad610626658
stdlib@go1.18.5
1.25.10
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
stdlib@go1.25.0
1.25.10
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
stdlib@go1.25.5
1.25.10
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
stdlib@go1.25.5
1.25.10
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
stdlib@go1.19.9
1.25.10
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.25.10
quay.io/devtron/nats-box:latest48cdd3054b20
stdlib@go1.19.2
1.25.10
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.25.10
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.25.10
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
stdlib@go1.17.6
1.25.10
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.25.10
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
stdlib@go1.21.5
1.25.10

Open the chart page →

68,695
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
stdlib@go1.15.7
1.25.10
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
stdlib@go1.20.7
1.25.10

Open the chart page →

5,055
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
stdlib@go1.20.4
1.25.10

Open the chart page →

4,972
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
stdlib@go1.17.3
1.25.10

Open the chart page →

11,959
discord-alertmanagerdevtron0.10.01 of 1See more

discord-alertmanager devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.25.10

Open the chart page →

951
jcmhproxy-ingressdevtron0.14.61 of 1See more

jcmhproxy-ingress devtron 0.14.6

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
stdlib@go1.19.13
1.25.10

Open the chart page →

1,379
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
stdlib@go1.17
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
stdlib@go1.16
1.25.10
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
stdlib@go1.16.7
1.25.10

Open the chart page →

8,659
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.25.10

Open the chart page →

3,908
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
stdlib@go1.16.10
1.25.10

Open the chart page →

2,441
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
stdlib@go1.18.10
1.25.10

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
stdlib@go1.19.7
1.25.10

Open the chart page →

1,514
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
stdlib@go1.22.4
1.25.10

Open the chart page →

9,685
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
stdlib@go1.14.12
1.25.10
quay.io/dexidp/dex:v2.25.07bcf286807b8
stdlib@go1.14.9
1.25.10

Open the chart page →

10,484

Container images carrying it

4,508 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
stdlib@go1.17.2
1.25.10
1
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
stdlib@go1.17.2
1.25.10
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
stdlib@go1.17.2
1.25.10
1
epamedp/perf-operator:2.13.0bd2079b7bfcb
stdlib@go1.19.6
1.25.10
1
epamedp/reconciler:2.12.0d33e938b6d59
stdlib@go1.18.4
1.25.10
1
epamedp/tekton-custom-task:0.2.067d896676f45
stdlib@go1.24.2
1.25.10
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.25.10
1
erenozcan17/go_backend:v4.250b4f23422b6
stdlib@go1.23.12
1.25.10
1
erigontech/erigon:v2.61.288706754b627
stdlib@go1.22.12
1.25.10
1
escaping/core-keeper-dedicated:latest87fa79255962
stdlib@go1.24.4
1.25.10
1
etejeda/butlerci:0.1.0737d58183abc
stdlib@go1.16.3
1.25.10
1
ethereum/client-go:v1.15.101f36ca5922a5
stdlib@go1.24.2
1.25.10
1
ethereum/client-go:v1.16.532b878e4144a
stdlib@go1.24.9
1.25.10
1
ethereum/client-go:v1.10.186d6d12a40465
stdlib@go1.18.2
1.25.10
1
ethereum/client-go:v1.14.8886ec69b35b0
stdlib@go1.22.6
1.25.10
1
ethereum/client-go:v1.10.23cce21b423165
stdlib@go1.18.5
1.25.10
1
ethereum/client-go:v1.10.15d99fbb9585c7
stdlib@go1.17.5
1.25.10
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
stdlib@go1.19.3
1.25.10
1
ethereumoptimism/l2geth:0.5.315577036dc36d
stdlib@go1.18
1.25.10
1
ethersphere/bee:2.2.0a884fd84b72f
stdlib@go1.22.7
1.25.10
1
ethersphere/ethproxy:latest3a8a3926caa2
stdlib@go1.18.7
1.25.10
1
ethersphere/onboarding-faucet:0.3.0513154aab230
stdlib@go1.18.2
1.25.10
1
ethpandaops/armiarma:master1a9c3264f0a9
stdlib@go1.21.8
1.25.10
1
ethpandaops/blob-me-baby:latestad26158420dd
stdlib@go1.20.1
1.25.10
1
ethpandaops/cbt:latest5377ffb3091a
stdlib@go1.26.1
1.25.10
1
ethpandaops/contributoor:latest1edd4074fd79
stdlib@go1.26.1
1.25.10
1
ethpandaops/dugtrio:1.0.0e261d1734e9f
stdlib@go1.21.4
1.25.10
1
ethpandaops/ethereum-address-metrics-exporter:latest431cd3790ed2
stdlib@go1.26.1
1.25.10
1
ethpandaops/ethereumjs:masterfb84b718500f
stdlib@go1.23.12
1.25.10
1
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
stdlib@go1.18.10
1.25.10
1
ethpandaops/ethereum-validator-metrics-exporter:latest38448e9d4aef
stdlib@go1.19.10
1.25.10
1
ethpandaops/execution-processor:latest5c4832e9588f
stdlib@go1.25.4
1.25.10
1
ethpandaops/panda-pulse:latestad6fc3b3e6b8
stdlib@go1.26.1
1.25.10
1
ethpandaops/slashoor:latesta71967db581f
stdlib@go1.23.12
1.25.10
1
ethpandaops/splitoor:latest989da6bea4bd
stdlib@go1.26.1
1.25.10
1
ethpandaops/stubbies:latest9f1d6aec0d04
stdlib@go1.19.8
1.25.10
1
ethpandaops/xatu-cbt-api:latestf7dec2e07091
stdlib@go1.25.1
1.25.10
1
evcc/evcc:0.300.8ddf2a25afce5
stdlib@go1.25.6
1.25.10
1
everpcpc/channels:latestb378d137ae8b
stdlib@go1.17
1.25.10
1
evoapicloud/evolution-api:latest966625532d90
stdlib@go1.23.12
1.25.10
1
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
stdlib@go1.18.3
1.25.10
1
factly/dega-api:0.15.166fafc7b0a17
stdlib@go1.16.2
1.25.10
1
factly/dega-server:0.15.194d21479382e
stdlib@go1.16.2
1.25.10
1
factly/kavach-server:0.22.3be85ff1b9bd3
stdlib@go1.16.2
1.25.10
1
factly/mande-server:0.34.1384d384310ef
stdlib@go1.18.10
1.25.10
1
factly/vidcheck-server:0.12.087064eb0463c
stdlib@go1.14.2
1.25.10
1
falcosecurity/falcoctl:0.13.00eeb79adc580
stdlib@go1.26.2
1.25.10
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
stdlib@go1.25.7
1.25.10
1
falcosecurity/falco-operator:0.4.18a99fcc57a57
stdlib@go1.26.0
1.25.10
1
falcosecurity/falcosidekick:2.32.01976da721518
stdlib@go1.25.1
1.25.10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.