StackRadar

CVE-2026-42499

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,937
of 17,792 indexed, latest versions
Container images
4,529
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatenation in consumePhrase in net/mail

Carried by container images the latest versions of 3,937 of 17,792 indexed charts deploy, on 4,529 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,529
OSV records
DEBIAN-CVE-2026-42499GO-2026-4977
Also known as
BIT-golang-2026-42499

Charts affected

3,937 by stars
ChartLatestAffected imagesRadar Score
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
stdlib@go1.20.7
1.25.10

Open the chart page →

1,657
hello-worldsumudu-repo1.0.01 of 1See more

hello-world sumudu-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
sumuduliya/hello-world:latestb7788a2984a3
stdlib@go1.19.13
1.25.10

Open the chart page →

940
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,262
cludodsuperorbitalVerified publisher0.0.51 of 1See more

cludod superorbital 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
superorbital/cludod:0.0.2-alphad59732f61d6e
stdlib@go1.17.6
1.25.10

Open the chart page →

2,371
do-database-metrics-adaptersupporttools1.0.21 of 1See more

do-database-metrics-adapter supporttools 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
supporttools/do-database-metrics-adapter:1.0.2ab55fd5a69c3
stdlib@go1.22.3
1.25.10

Open the chart page →

430
do-operatorsupporttools0.1.71 of 2See more

do-operator supporttools 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
digitalocean/do-operator:v0.1.65e5deb4db76e
stdlib@go1.18.10
1.25.10

Open the chart page →

1,063
go-redis-proxysupporttools0.0.71 of 1See more

go-redis-proxy supporttools 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
supporttools/go-redis-proxy:0.0.7cbd45f6b02b8
stdlib@go1.21.6
1.25.10

Open the chart page →

529
go-web-cachesupporttools1.3.21 of 1See more

go-web-cache supporttools 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
supporttools/go-web-cache:v1.3.2f4f775dd43b9
stdlib@go1.21.6
1.25.10

Open the chart page →

511
nfs-provisionersupporttools0.11.01 of 1See more

nfs-provisioner supporttools 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
openebs/provisioner-nfs:0.11.04f41dd782761
stdlib@go1.19.13
1.25.10

Open the chart page →

2,680
powerdns-admin-proxysupporttools0.1.51 of 1See more

powerdns-admin-proxy supporttools 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
supporttools/powerdns-admin-proxy:5e3687d66bcfa
stdlib@go1.21.3
1.25.10

Open the chart page →

558
push-to-k8ssupporttools1.1.21 of 1See more

push-to-k8s supporttools 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
cube8021/push-to-k8s:v1.1.21be9baf096ff
stdlib@go1.22.4
1.25.10

Open the chart page →

530
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
stdlib@go1.24.13
1.25.10

Open the chart page →

3,474
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.25.10

Open the chart page →

12,732
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
stdlib@go1.20.4
1.25.10

Open the chart page →

10,980
icinga2svtech-public-helm-charts1.0.02 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.25.10
svtechnmaa/svtech_icingadb:v1.1.26d91c2e4e882
stdlib@go1.21.5
1.25.10

Open the chart page →

5,542
icingawebsvtech-public-helm-charts1.0.01 of 2See more

icingaweb svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
stdlib@go1.21.6
1.25.10

Open the chart page →

2,039
ingress-nginxsvtech-public-helm-charts1.0.01 of 1See more

ingress-nginx svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
stdlib@go1.21.3
1.25.10

Open the chart page →

1,480
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.25.10

Open the chart page →

5,891
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
stdlib@go1.20.5
1.25.10

Open the chart page →

18,853
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
stdlib@go1.21.5
1.25.10

Open the chart page →

2,336
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
stdlib@go1.23.9
1.25.10

Open the chart page →

1,369
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
stdlib@go1.24.3
1.25.10

Open the chart page →

2,397
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
stdlib@go1.23.10
1.25.10

Open the chart page →

8,263
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
stdlib@go1.21.3
1.25.10

Open the chart page →

1,971
agentssynapse0.1.304 of 9See more

agents synapse 0.1.30

4 of the 9 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.42.07d32a4eddec7
stdlib@go1.19.5
1.25.10
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
stdlib@go1.20.3
1.25.10
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
stdlib@go1.22.4
1.25.10
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
stdlib@go1.20.3
1.25.10

Open the chart page →

7,272
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
stdlib@go1.20.5
1.25.10

Open the chart page →

1,822
explorersynapse0.2.163 of 6See more

explorer synapse 0.2.16

3 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
yandex/clickhouse-server:latest1cbf75aabe1e
stdlib@go1.16.7
1.25.10
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
stdlib@go1.22.4
1.25.10
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
stdlib@go1.22.4
1.25.10

Open the chart page →

8,581
omnirpcsynapse0.2.921 of 2See more

omnirpc synapse 0.2.92

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
stdlib@go1.22.4
1.25.10

Open the chart page →

1,128
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
stdlib@go1.20.6
1.25.10

Open the chart page →

1,711
screenersynapse0.2.51 of 4See more

screener synapse 0.2.5

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
stdlib@go1.22.4
1.25.10

Open the chart page →

1,098
scribesynapse0.2.162 of 7See more

scribe synapse 0.2.16

2 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
stdlib@go1.22.4
1.25.10
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
stdlib@go1.22.4
1.25.10

Open the chart page →

2,694
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
stdlib@go1.20.14
1.25.10

Open the chart page →

1,962
ccm-hcloudsyself1.0.111 of 1See more

ccm-hcloud syself 1.0.11

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
stdlib@go1.19
1.25.10

Open the chart page →

1,713
ccm-hetznersyself2.0.71 of 1See more

ccm-hetzner syself 2.0.7

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/syself/hetzner-cloud-controller-manager:v2.0.77d4a5e29c387
stdlib@go1.24.5
1.25.10

Open the chart page →

709
csi-hcloudsyself1.3.15 of 6See more

csi-hcloud syself 1.3.1

5 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.9.05aaefc24f315
stdlib@go1.24.2
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
stdlib@go1.24.2
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
stdlib@go1.24.2
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
stdlib@go1.24.2
1.25.10

Open the chart page →

2,495
hcloud-csisyself0.1.11 of 6See more

hcloud-csi syself 0.1.1

1 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
stdlib@go1.17
1.25.10

Open the chart page →

2,917
topolvmsyself1.3.01 of 1See more

topolvm syself 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
stdlib@go1.22.8
1.25.10

Open the chart page →

3,599
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
stdlib@go1.13.11
1.25.10

Open the chart page →

2,876
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
stdlib@go1.13.11
1.25.10

Open the chart page →

2,828
tidewayst3n2.0.11 of 1See more

tideways t3n 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
t3nde/tideways:1.7.2777e008f764db
stdlib@go1.16.4
1.25.10

Open the chart page →

2,206
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
stdlib@go1.13.10
1.25.10

Open the chart page →

7,490
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.25.10

Open the chart page →

4,910
paperless-ngx-backuptaskmediaVerified publisher1.1.01 of 1See more

paperless-ngx-backup taskmedia 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/taskmedia/kubectl-gpg-ncftp:main0fb2b5584f7c
stdlib@go1.22.10
1.25.10

Open the chart page →

518
act-runnertektonops0.1.22 of 2See more

act-runner tektonops 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
stdlib@go1.26.2
1.25.10
library/docker:23.0.6-dindafa5d5134900
stdlib@go1.19.9
1.25.10

Open the chart page →

4,218
drl-exportertektonops0.1.31 of 1See more

drl-exporter tektonops 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
khaliq/drl-exporter:latestf63cf53166f8
stdlib@go1.22.6
1.25.10

Open the chart page →

883
ipup-dynutektonops0.1.11 of 1See more

ipup-dynu tektonops 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
tektonops/ipup-dynu:latestc2198746cf8f
stdlib@go1.22.6
1.25.10

Open the chart page →

863
pingmetektonops0.1.21 of 1See more

pingme tektonops 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
khaliq/pingme:v0.2.749f96888d2ab
stdlib@go1.25.4
1.25.10

Open the chart page →

1,254
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
stdlib@go1.16.5
1.25.10

Open the chart page →

3,772
clickhousetemp-charts0.7.12 of 3See more

clickhouse temp-charts 0.7.1

2 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
stdlib@go1.13.15
1.25.10
altinity/metrics-exporter:0.16.185b4fdbae053
stdlib@go1.13.15
1.25.10

Open the chart page →

8,707
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
stdlib@go1.16.4
1.25.10

Open the chart page →

10,606

Container images carrying it

4,529 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
stdlib@go1.16
1.25.10
4
grafana/grafana:13.1.0121a7a9ece6d
stdlib@go1.25.7
1.25.10
4
grafana/grafana:6.7.11ff3999e0fc0
stdlib@go1.13.4
1.25.10
4
grafana/grafana:13.2.2-distroless69a5d2d957ca
stdlib@go1.25.7
1.25.10
4
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.25.10
4
grafana/loki:3.6.73c8fd3570dd9
stdlib@go1.24.13
1.25.10
4
grafana/tempo:2.9.065a578975943
stdlib@go1.25.1
1.25.10
4
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.25.10
4
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.25.10
4
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.25.10
4
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
stdlib@go1.21.5
1.25.10
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.25.10
4
jaegertracing/jaeger-collector:1.53.07f1269222903
stdlib@go1.21.5
1.25.10
4
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
stdlib@go1.21.5
1.25.10
4
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.25.10
4
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.10
4
library/mongo:5.0-focal5e15a3f014ed
stdlib@go1.25.9
1.25.10
4
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.10
4
library/mysql:latest4b40b165f348
stdlib@go1.24.6
1.25.10
4
library/postgres:134689940c6838
stdlib@go1.24.6
1.25.10
4
library/registry:3.1.1:latest1be55279f18a
stdlib@go1.25.9
1.25.10
4
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.25.10
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.25.10
4
rancher/rancher:v2.15.15f6c4dc52a05
stdlib@go1.26.1
1.25.10
4
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
stdlib@go1.21.7
1.25.10
4
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
stdlib@go1.22.5
1.25.10
4
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
stdlib@go1.25.5
1.25.10
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
stdlib@go1.18.10
1.25.10
4
ghcr.io/sigstore/scaffolding/createtree:v0.7.31e5232e8c9122
stdlib@go1.25.0
1.25.10
4
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
stdlib@go1.22.4
1.25.10
4
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
stdlib@go1.20.8
1.25.10
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
stdlib@go1.20.8
1.25.10
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
stdlib@go1.20.8
1.25.10
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
stdlib@go1.20.8
1.25.10
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
stdlib@go1.19.4
1.25.10
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.25.10
4
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
stdlib@go1.23.7
1.25.10
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.10
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
stdlib@go1.19.4
1.25.10
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
stdlib@go1.16.9
1.25.10
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
stdlib@go1.24.4
1.25.10
4
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
stdlib@go1.24.4
1.25.10
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
stdlib@go1.22.2
1.25.10
4
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
stdlib@go1.23.1
1.25.10
4
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
stdlib@go1.23.1
1.25.10
4
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
stdlib@go1.21.5
1.25.10
4
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
stdlib@go1.24.2
1.25.10
4
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
stdlib@go1.25.7
1.25.10
4
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
stdlib@go1.23.1
1.25.10
4
alfhou/hammond:v0.0.24c85dc0293aa1
stdlib@go1.20.6
1.25.10
3

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.