CVE-2026-42499
HighAdvisory
Published 7 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.008
- 55th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,934
- of 17,803 indexed, latest versions
- Container images
- 4,529
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Quadratic string concatenation in consumePhrase in net/mail
Carried by container images the latest versions of 3,934 of 17,803 indexed charts deploy, on 4,529 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+180 more | 1.25.10 | 4,529 |
- OSV records
- DEBIAN-CVE-2026-42499GO-2026-4977
- Also known as
- BIT-golang-2026-42499
Charts affected
3,934 by stars
Container images carrying it
4,529 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 28e98eece020 | stdlib | 1.25.10 | 1 |
| library/ | 507a3eecf809 | stdlib | 1.25.10 | 1 |
| library/ | 794079a7f241 | stdlib | 1.25.10 | 1 |
| library/ | addb86c0c520 | stdlib | 1.25.10 | 1 |
| library/ | 0a5157f742d2 | stdlib | 1.25.10 | 1 |
| library/ | 104204dadedf | stdlib | 1.25.10 | 1 |
| library/ | 1489caffaedb | stdlib | 1.25.10 | 1 |
| library/ | 1957e3314f43 | stdlib | 1.25.10 | 1 |
| library/ | 2f603f8d3abe | stdlib | 1.25.10 | 1 |
| library/ | 34d5089d0b41 | stdlib | 1.25.10 | 1 |
| library/ | 5d47b7bb2546 | stdlib | 1.25.10 | 1 |
| library/ | 7d0228d19042 | stdlib | 1.25.10 | 1 |
| library/ | eda951fd29a8 | stdlib | 1.25.10 | 1 |
| library/ | f5af5a5ce17f | stdlib | 1.25.10 | 1 |
| library/ | f98ac9dd97b0 | stdlib | 1.25.10 | 1 |
| library/ | cab8944a33a1 | stdlib | 1.25.10 | 1 |
| library/ | dfa9ba46d14b | stdlib | 1.25.10 | 1 |
| librenms/ | 0920bc9117a8 | stdlib | 1.25.10 | 1 |
| librenms/ | 4f1f3d667cc7 | stdlib | 1.25.10 | 1 |
| librenms/ | 8194a4a9ff49 | stdlib | 1.25.10 | 1 |
| lifailon/ | ea37e4b6b952 | stdlib | 1.25.10 | 1 |
| lightstep/ | c800e05e1eff | stdlib | 1.25.10 | 1 |
| linuxserver/ | 241009026e6f | stdlib | 1.25.10 | 1 |
| linuxserver/ | 938810eca3d3 | stdlib | 1.25.10 | 1 |
| linuxserver/ | 45c5fe102ff3 | stdlib | 1.25.10 | 1 |
| linuxserver/ | 2f4488c9afcd | stdlib | 1.25.10 | 1 |
| linuxserver/ | b7f906899cd3 | stdlib | 1.25.10 | 1 |
| lishimeng/ | 3d5752dac834 | stdlib | 1.25.10 | 1 |
| lishimeng/ | c79a67657baf | stdlib | 1.25.10 | 1 |
| lishimeng/ | 3d00485e64dc | stdlib | 1.25.10 | 1 |
| lishimeng/ | 3e7d05ded625 | stdlib | 1.25.10 | 1 |
| lishimeng/ | 0970dfe5dc8f | stdlib | 1.25.10 | 1 |
| lishimeng/ | 8145c3dc83c8 | stdlib | 1.25.10 | 1 |
| lishimeng/ | 9b2f8be6c7d3 | stdlib | 1.25.10 | 1 |
| lishimeng/ | e0b8d2d8ca28 | stdlib | 1.25.10 | 1 |
| listmonk/ | bf3903d54a46 | stdlib | 1.25.10 | 1 |
| litestream/ | c5a1e1b01916 | stdlib | 1.25.10 | 1 |
| livekit/ | 1ab01641b366 | stdlib | 1.25.10 | 1 |
| livekit/ | ecf1409c75e0 | stdlib | 1.25.10 | 1 |
| livekit/ | 3602a85840d5 | stdlib | 1.25.10 | 1 |
| livekit/ | 8391fd1b834f | stdlib | 1.25.10 | 1 |
| lmierzwa/ | 3751e5eed656 | stdlib | 1.25.10 | 1 |
| lmierzwa/ | d417abe7ddb5 | stdlib | 1.25.10 | 1 |
| localstack/ | 9d278167f2b7 | stdlib | 1.25.10 | 1 |
| loeken/ | 4ce6abc553b3 | stdlib | 1.25.10 | 1 |
| loftsh/ | 310cc7d690f5 | stdlib | 1.25.10 | 1 |
| loftsh/ | 25deb9bd2683 | stdlib | 1.25.10 | 1 |
| loftsh/ | 023b13bf5898 | stdlib | 1.25.10 | 1 |
| logiqai/ | 65b996bc7bdc | stdlib | 1.25.10 | 1 |
| logiqai/ | f5b551bca98e | stdlib | 1.25.10 | 1 |