StackRadar

CVE-2026-42499

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,929
of 17,797 indexed, latest versions
Container images
4,519
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatenation in consumePhrase in net/mail

Carried by container images the latest versions of 3,929 of 17,797 indexed charts deploy, on 4,519 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,519
OSV records
DEBIAN-CVE-2026-42499GO-2026-4977
Also known as
BIT-golang-2026-42499

Charts affected

3,929 by stars
ChartLatestAffected imagesRadar Score
cratedb-adapterhmdmph0.1.01 of 1See more

cratedb-adapter hmdmph 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
stdlib@go1.16.3
1.25.10

Open the chart page →

2,920
printserverhmediadeVerified publisher1.0.22 of 4See more

printserver hmediade 1.0.2

2 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
stdlib@go1.21.5
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
stdlib@go1.21.3
1.25.10

Open the chart page →

11,002
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
stdlib@go1.16.8
1.25.10

Open the chart page →

2,147
cert-managerhomeenterpriseinc1.10.13 of 3See more

cert-manager homeenterpriseinc 1.10.1

3 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
stdlib@go1.19.3
1.25.10
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
stdlib@go1.19.3
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
stdlib@go1.19.3
1.25.10

Open the chart page →

4,735
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
stdlib@go1.19.8
1.25.10

Open the chart page →

16,444
honeydipperhoneydipperVerified publisher0.1.111 of 2See more

honeydipper honeydipper 0.1.11

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/redis:5fc5ecd863862
stdlib@go1.16.7
1.25.10

Open the chart page →

1,731
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
stdlib@go1.21.10
1.25.10

Open the chart page →

3,625
paperlesshpVerified publisher0.1.23 of 5See more

paperless hp 0.1.2

3 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
stdlib@go1.26.2
1.25.10
gotenberg/gotenberg:8.3467097317623a
stdlib@go1.26.2
1.25.10
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10

Open the chart page →

27,104
wallabaghpVerified publisher0.1.71 of 1See more

wallabag hp 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.25.10

Open the chart page →

1,135
hammerspace-csihscsi1.2.86 of 6See more

hammerspace-csi hscsi 1.2.8

6 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
stdlib@go1.24.4
1.25.10
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
stdlib@go1.23.1
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
stdlib@go1.23.1
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
stdlib@go1.23.1
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
stdlib@go1.24.2
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.10

Open the chart page →

4,509
eoloplanthttpd-eoloplant0.1.03 of 7See more

eoloplant httpd-eoloplant 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
stdlib@go1.18.10
1.25.10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

32,456
http-headershttp-headers1.2.11 of 1See more

http-headers http-headers 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/k8start/http-headers:1.2.0c7a9987f2ac5
stdlib@go1.19.2
1.25.10

Open the chart page →

2,009
cac-systemhuangchengwu-helm-chart0.1.07 of 9See more

cac-system huangchengwu-helm-chart 0.1.0

7 of the 9 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
stdlib@go1.20.4
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.12.0e0a5b06b231c
stdlib@go1.20.4
1.25.10
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
stdlib@go1.20.4
1.25.10
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
stdlib@go1.20.4
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
stdlib@go1.20.4
1.25.10
quay.io/metallb/controller:v0.13.101b33357b3595
stdlib@go1.19.5
1.25.10
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
stdlib@go1.19.5
1.25.10

Open the chart page →

11,221
mariadbhuangchengwu-helm-chart0.1.01 of 1See more

mariadb huangchengwu-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mariadb:latestdd9b303aed4f
stdlib@go1.24.6
1.25.10

Open the chart page →

1,935
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
stdlib@go1.16.9
1.25.10

Open the chart page →

16,516
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
stdlib@go1.16.9
1.25.10

Open the chart page →

20,763
tdenginehuangchengwu-helm-chart3.0.21 of 1See more

tdengine huangchengwu-helm-chart 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
tdengine/tdengine:3.0.2.24140a4021ddb
stdlib@go1.17.6
1.25.10

Open the chart page →

3,763
sing-boxhuscker-chartsVerified publisher1.0.71 of 1See more

sing-box huscker-charts 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
stdlib@go1.24.5
1.25.10

Open the chart page →

1,444
jaegerhuseyinbabalVerified publisher0.1.01 of 3See more

jaeger huseyinbabal 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
stdlib@go1.25.4
1.25.10

Open the chart page →

1,492
kubetaghuseyinbabalVerified publisher1.0.21 of 2See more

kubetag huseyinbabal 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/huseyinbabal/kubetag:lateste161eddc59a0
stdlib@go1.25.5
1.25.10

Open the chart page →

1,277
mocktailhuseyinnurbaki0.2.11 of 1See more

mocktail huseyinnurbaki 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
hhaluk/mocktail:2.0.3350d19360038
stdlib@go1.17.7
1.25.10

Open the chart page →

1,606
vcbackendi4trustVerified publisher0.0.81 of 1See more

vcbackend i4trust 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
wistefan/vcbackend:0.0.13bd436164b51
stdlib@go1.18.3
1.25.10

Open the chart page →

1,848
vcverifieri4trustVerified publisher1.0.231 of 1See more

vcverifier i4trust 1.0.23

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/fiware/vcverifier:2.0.1cd36290dc849
stdlib@go1.19.9
1.25.10

Open the chart page →

1,784
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
stdlib@go1.20.2
1.25.10

Open the chart page →

7,984
stoloniamalryz0.10.01 of 2See more

stolon iamalryz 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
stdlib@go1.13.8
1.25.10

Open the chart page →

4,052
ibexaibexaVerified publisher3.11.12 of 10See more

ibexa ibexa 3.11.1

2 of the 10 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.0.41bf577825b52a
stdlib@go1.18.2
1.25.10
registry.gitlab.com/xrow-public/ci-tools/kubectl:main9357cfeef63c
stdlib@go1.24.9
1.25.10

Open the chart page →

6,050
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.10
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.25.10

Open the chart page →

57,842
ibm-ucv-prodibm-helm5.2.61 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

1 of the 16 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.27.1934d1acd5ca8
stdlib@go1.22.7
1.25.10

Open the chart page →

12,184
metamcpicoretechVerified publisher0.3.101 of 2See more

metamcp icoretech 0.3.10

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.10

Open the chart page →

1,667
multicaicoretechVerified publisher0.4.432 of 5See more

multica icoretech 0.4.43

2 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
stdlib@go1.24.6
1.25.10
pgvector/pgvector:pg17cf134a767f47
stdlib@go1.24.6
1.25.10

Open the chart page →

2,612
tolgeeicoretechVerified publisher0.49.02 of 3See more

tolgee icoretech 0.49.0

2 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:18.369e8582b781c
stdlib@go1.24.6
1.25.10
tolgee/tolgee:v3.224.060392077cbda
stdlib@go1.24.6
1.25.10

Open the chart page →

2,769
monitoring-stackict-platformVerified publisher0.4.010 of 13See more

monitoring-stack ict-platform 0.4.0

10 of the 13 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/loki:3.6.73c8fd3570dd9
stdlib@go1.24.13
1.25.10
prom/memcached-exporter:v0.15.4b6763ecb3c47
stdlib@go1.25.3
1.25.10
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
stdlib@go1.24.10
1.25.10
ghcr.io/grafana/grafana-operator:v5.22.2d45fc24e8f43
stdlib@go1.26.1
1.25.10
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
stdlib@go1.24.9
1.25.10
ghcr.io/jkroepke/kube-webhook-certgen:1.8.043401e216e89
stdlib@go1.26.1
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
stdlib@go1.25.8
1.25.10
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
stdlib@go1.26.1
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.10
registry.k8s.io/kubectl:v1.31.099b37df34bc4
stdlib@go1.22.5
1.25.10

Open the chart page →

9,629
ingress-nginxifmethod-helm-charts4.12.12 of 2See more

ingress-nginx ifmethod-helm-charts 4.12.1

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
stdlib@go1.24.1
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
stdlib@go1.24.1
1.25.10

Open the chart page →

1,477
eoloserverihuertas2021-vmartinp2021-helm0.1.03 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
stdlib@go1.18.10
1.25.10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

27,861
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
stdlib@go1.23.8
1.25.10

Open the chart page →

9,062
ikigaiikigai-chartVerified publisher0.0.93 of 58See more

ikigai ikigai-chart 0.0.9

3 of the 58 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
kuberay/operator:v1.0.04e6ac8a3a2c4
stdlib@go1.19.13
1.25.10
rabbitmqoperator/cluster-operator:2.6.08651dd3cec51
stdlib@go1.20.11
1.25.10
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
stdlib@go1.17.3
1.25.10

Open the chart page →

37,983
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
stdlib@go1.23.7
1.25.10

Open the chart page →

2,203
ilum-jupyterhubilumVerified publisher4.3.11 of 6See more

ilum-jupyterhub ilum 4.3.1

1 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
stdlib@go1.23.10
1.25.10

Open the chart page →

1,843
ilum-otel-collectorilumVerified publisher0.1.01 of 1See more

ilum-otel-collector ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.113.05ac3e0ba2b0b
stdlib@go1.23.2
1.25.10

Open the chart page →

1,400
plausible-analyticsimioVerified publisher0.4.21 of 5See more

plausible-analytics imio 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:17.6-alpineef257d85f76e
stdlib@go1.24.6
1.25.10

Open the chart page →

10,558
apexkube-agentimprowisedVerified publisher1.4.01 of 2See more

apexkube-agent improwised 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
masipcat/wireguard-go:0.0.20230223769f7bb64694
stdlib@go1.20.14
1.25.10

Open the chart page →

3,360
frigateimprowisedVerified publisher1.1.01 of 1See more

frigate improwised 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
stdlib@go1.20.3
1.25.10

Open the chart page →

2,160
kore-boardimprowisedVerified publisher0.5.83 of 4See more

kore-board improwised 0.5.8

3 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.backend:v0.5.5455f6e7a26fd
stdlib@go1.19.4
1.25.10
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
stdlib@go1.19.4
1.25.10
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
stdlib@go1.18.9
1.25.10

Open the chart page →

16,253
fpga-cloudinaccelVerified publisher1.2.23 of 3See more

fpga-cloud inaccel 1.2.2

3 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
inaccel/cloud-init:latesta5d3d0af05c1
stdlib@go1.21.6
1.25.10
inaccel/device-selector:latest44b4f274f40b
stdlib@go1.21.9
1.25.10
inaccel/kubevirt-hack:latestbdfd61803a70
stdlib@go1.21.7
1.25.10

Open the chart page →

3,166
fpga-operatorinaccelVerified publisher2.8.23 of 7See more

fpga-operator inaccel 2.8.2

3 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
inaccel/daemon:latest093e1ea90ab8
stdlib@go1.21.6
1.25.10
inaccel/mkrt:latest187fd448b6f2
stdlib@go1.21.5
1.25.10
inaccel/reef:latestc967218739f3
stdlib@go1.21.6
1.25.10

Open the chart page →

5,771
infisical-agent-injectorinfisical-charts0.1.121 of 1See more

infisical-agent-injector infisical-charts 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
infisical/infisical-agent-injector:v0.1.12718dd5bee7cb
stdlib@go1.24.13
1.25.10

Open the chart page →

761
infisical-csi-providerinfisical-charts0.2.31 of 1See more

infisical-csi-provider infisical-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
infisical/infisical-csi-provider:v0.0.9e3390e677db6
stdlib@go1.24.13
1.25.10

Open the chart page →

636
infisical-pki-issuerinfisical-charts1.0.01 of 1See more

infisical-pki-issuer infisical-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
infisical/pki-issuer:latestff38294270e3
stdlib@go1.24.13
1.25.10

Open the chart page →

573
chronografinfluxdata1.2.61 of 1See more

chronograf influxdata 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/chronograf:1.9.496d8a3f65a4f
stdlib@go1.16.4
1.25.10

Open the chart page →

2,205
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
stdlib@go1.24.13
1.25.10
library/influxdb:1.12.3-datab0f9fc41ed79
stdlib@go1.24.13
1.25.10

Open the chart page →

5,988

Container images carrying it

4,519 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
factly/vidcheck-server:0.12.087064eb0463c
stdlib@go1.14.2
1.25.10
1
falcosecurity/falcoctl:0.13.00eeb79adc580
stdlib@go1.26.2
1.25.10
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
stdlib@go1.25.7
1.25.10
1
falcosecurity/falco-operator:0.4.18a99fcc57a57
stdlib@go1.26.0
1.25.10
1
falcosecurity/falcosidekick:2.32.01976da721518
stdlib@go1.25.1
1.25.10
1
falcosecurity/falcosidekick:2.27.0828ee36cb13a
stdlib@go1.18.1
1.25.10
1
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
stdlib@go1.24.4
1.25.10
1
featureformcom/quickstart-loader:latest82396f8fb5e8
stdlib@go1.21.11
1.25.10
1
federid/webhook:0.1.0fbfb7c6510a7
stdlib@go1.23.3
1.25.10
1
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
stdlib@go1.20.6
1.25.10
1
felipecs8/conversor-temperatura:v1f945423be36d
stdlib@go1.20.12
1.25.10
1
filebrowser/filebrowser:v2.18.04fcd47af573c
stdlib@go1.16.9
1.25.10
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
stdlib@go1.16.2
1.25.10
1
fission/fission-bundle:1.14.13fcfd8a0fa5d
stdlib@go1.15.14
1.25.10
1
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
stdlib@go1.15.14
1.25.10
1
fission/reporter:1.14.104c6e06af175
stdlib@go1.15.14
1.25.10
1
flanksource/apm-hub:v0.0.471dacc3195bf9
stdlib@go1.20.7
1.25.10
1
flanksource/batch-runner:v1.0.44689687a7cf95
stdlib@go1.25.5
1.25.10
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
stdlib@go1.20.7
1.25.10
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
stdlib@go1.23.5
1.25.10
1
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
stdlib@go1.17.13
1.25.10
1
flashbots/mev-boost:1.8.07c486b5789da
stdlib@go1.22.6
1.25.10
1
flashcatcloud/nightingale:8.5.1421acb36181b
stdlib@go1.24.0
1.25.10
1
fleetdm/fleet:v4.66.012e644b7f40e
stdlib@go1.23.4
1.25.10
1
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
stdlib@go1.19.13
1.25.10
1
flomesh/fsm-manager:0.2.1122f849c70b25
stdlib@go1.19.13
1.25.10
1
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
stdlib@go1.19.13
1.25.10
1
flomesh/osm-edge-controller:1.3.9add7a4da4622
stdlib@go1.19.13
1.25.10
1
flomesh/osm-edge-injector:1.3.947287e3ad324
stdlib@go1.19.13
1.25.10
1
flomesh/osm-edge-preinstall:1.3.9bd224d55ed0f
stdlib@go1.19.13
1.25.10
1
fluxcd/flux-cli:v2.9.5704d55295355
stdlib@go1.26.2
1.25.10
1
fluxcd/helm-controller:v0.9.092b891e495d8
stdlib@go1.15.10
1.25.10
1
fluxcd/source-controller:v0.10.031a8c79a6803
stdlib@go1.15.10
1.25.10
1
fluxninja/aperture-operator:2.34.0356d7aa86632
stdlib@go1.21.5
1.25.10
1
fonoster/routr-edgeport:2.13.6d08a8a574a50
stdlib@go1.21.0
1.25.10
1
foomo/csp-reporter:1.3.0e436da524785
stdlib@go1.18
1.25.10
1
forchaladtest/mygowiki:1.0.170827eaecad1
stdlib@go1.22.6
1.25.10
1
fortio/fortio:latest_releasefc8221136fe2
stdlib@go1.23.9
1.25.10
1
fosrl/newt:1.10.4ccd2b0e9a049
stdlib@go1.25.8
1.25.10
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
stdlib@go1.23.7
1.25.10
1
foxcpp/maddy:0.7.16ab538e2f28b
stdlib@go1.19.13
1.25.10
1
foxcpp/maddy:v0.5.28fa2bd8f6830
stdlib@go1.17.2
1.25.10
1
foxcpp/maddy:0.9.2a4b839985b9b
stdlib@go1.23.12
1.25.10
1
foxcpp/maddy:0.8.2eeb5813fc4d1
stdlib@go1.23.12
1.25.10
1
gabekangas/owncast:0.0.797461aedb580
stdlib@go1.15.2
1.25.10
1
galaxy/cloudman-server:lateste5c265fe9fcd
stdlib@go1.17.13
1.25.10
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
stdlib@go1.22.7
1.25.10
1
galexrt/extended-ceph-exporter:v1.8.05373078a3a08
stdlib@go1.24.8
1.25.10
1
garethgeorge/backrest:v1.14.1b85297975428
stdlib@go1.26.0
1.25.10
1
garugaru/presto-exporter:cb666560e9e82d5ae36aef1e663c3d7f51cca9fc5201314c28f3
stdlib@go1.14.13
1.25.10
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.