CVE-2026-42499
HighAdvisory
Published 7 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.008
- 55th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,934
- of 17,803 indexed, latest versions
- Container images
- 4,529
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Quadratic string concatenation in consumePhrase in net/mail
Carried by container images the latest versions of 3,934 of 17,803 indexed charts deploy, on 4,529 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+180 more | 1.25.10 | 4,529 |
- OSV records
- DEBIAN-CVE-2026-42499GO-2026-4977
- Also known as
- BIT-golang-2026-42499
Charts affected
3,934 by stars
Container images carrying it
4,529 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| epamedp/ | 93417e18bb1a | stdlib | 1.25.10 | 1 |
| epamedp/ | 924939850655 | stdlib | 1.25.10 | 1 |
| epamedp/ | b71fb39e0c9e | stdlib | 1.25.10 | 1 |
| epamedp/ | 28ef56bc0ca3 | stdlib | 1.25.10 | 1 |
| epamedp/ | ff25e9fe4419 | stdlib | 1.25.10 | 1 |
| epamedp/ | 5d352199e12e | stdlib | 1.25.10 | 1 |
| epamedp/ | 449a53804699 | stdlib | 1.25.10 | 1 |
| epamedp/ | bd2079b7bfcb | stdlib | 1.25.10 | 1 |
| epamedp/ | d33e938b6d59 | stdlib | 1.25.10 | 1 |
| epamedp/ | 67d896676f45 | stdlib | 1.25.10 | 1 |
| eqalpha/ | fd9351ce27a7 | stdlib | 1.25.10 | 1 |
| erenozcan17/ | 50b4f23422b6 | stdlib | 1.25.10 | 1 |
| erigontech/ | 88706754b627 | stdlib | 1.25.10 | 1 |
| escaping/ | 87fa79255962 | stdlib | 1.25.10 | 1 |
| etejeda/ | 737d58183abc | stdlib | 1.25.10 | 1 |
| ethereum/ | 1f36ca5922a5 | stdlib | 1.25.10 | 1 |
| ethereum/ | 32b878e4144a | stdlib | 1.25.10 | 1 |
| ethereum/ | 6d6d12a40465 | stdlib | 1.25.10 | 1 |
| ethereum/ | 886ec69b35b0 | stdlib | 1.25.10 | 1 |
| ethereum/ | cce21b423165 | stdlib | 1.25.10 | 1 |
| ethereum/ | d99fbb9585c7 | stdlib | 1.25.10 | 1 |
| ethereumoptimism/ | e07968a0e686 | stdlib | 1.25.10 | 1 |
| ethereumoptimism/ | 5577036dc36d | stdlib | 1.25.10 | 1 |
| ethersphere/ | a884fd84b72f | stdlib | 1.25.10 | 1 |
| ethersphere/ | 3a8a3926caa2 | stdlib | 1.25.10 | 1 |
| ethersphere/ | 513154aab230 | stdlib | 1.25.10 | 1 |
| ethpandaops/ | 1a9c3264f0a9 | stdlib | 1.25.10 | 1 |
| ethpandaops/ | ad26158420dd | stdlib | 1.25.10 | 1 |
| ethpandaops/ | 5377ffb3091a | stdlib | 1.25.10 | 1 |
| ethpandaops/ | 1edd4074fd79 | stdlib | 1.25.10 | 1 |
| ethpandaops/ | e261d1734e9f | stdlib | 1.25.10 | 1 |
| ethpandaops/ | 431cd3790ed2 | stdlib | 1.25.10 | 1 |
| ethpandaops/ | fb84b718500f | stdlib | 1.25.10 | 1 |
| ethpandaops/ | d1780db2e286 | stdlib | 1.25.10 | 1 |
| ethpandaops/ | 38448e9d4aef | stdlib | 1.25.10 | 1 |
| ethpandaops/ | 5c4832e9588f | stdlib | 1.25.10 | 1 |
| ethpandaops/ | ad6fc3b3e6b8 | stdlib | 1.25.10 | 1 |
| ethpandaops/ | a71967db581f | stdlib | 1.25.10 | 1 |
| ethpandaops/ | 989da6bea4bd | stdlib | 1.25.10 | 1 |
| ethpandaops/ | 9f1d6aec0d04 | stdlib | 1.25.10 | 1 |
| ethpandaops/ | f7dec2e07091 | stdlib | 1.25.10 | 1 |
| evcc/ | ddf2a25afce5 | stdlib | 1.25.10 | 1 |
| everpcpc/ | b378d137ae8b | stdlib | 1.25.10 | 1 |
| evoapicloud/ | 966625532d90 | stdlib | 1.25.10 | 1 |
| expediagroup/ | 193a00ec8dd4 | stdlib | 1.25.10 | 1 |
| factly/ | 66fafc7b0a17 | stdlib | 1.25.10 | 1 |
| factly/ | 94d21479382e | stdlib | 1.25.10 | 1 |
| factly/ | be85ff1b9bd3 | stdlib | 1.25.10 | 1 |
| factly/ | 384d384310ef | stdlib | 1.25.10 | 1 |
| factly/ | 87064eb0463c | stdlib | 1.25.10 | 1 |