StackRadar

CVE-2026-42499

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,955
of 17,805 indexed, latest versions
Container images
4,520
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatenation in consumePhrase in net/mail

Carried by container images the latest versions of 3,955 of 17,805 indexed charts deploy, on 4,520 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,520
OSV records
DEBIAN-CVE-2026-42499GO-2026-4977
Also known as
BIT-golang-2026-42499

Charts affected

3,955 by stars
ChartLatestAffected imagesRadar Score
stk-fluent-bit-loki-s3paxtecnologia0.2.12 of 6See more

stk-fluent-bit-loki-s3 paxtecnologia 0.2.1

2 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/loki:3.6.1144148ad243c0
stdlib@go1.26.2
1.25.10
prom/memcached-exporter:v0.15.4b6763ecb3c47
stdlib@go1.25.3
1.25.10

Open the chart page →

3,763
everest-db-namespacepercona1.13.01 of 1See more

everest-db-namespace percona 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
stdlib@go1.24.6
1.25.10

Open the chart page →

769
pmm-ha-dependenciespercona1.0.04 of 4See more

pmm-ha-dependencies percona 1.0.0

4 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.25.41d6f18dbd599
stdlib@go1.25.1
1.25.10
altinity/metrics-exporter:0.25.46ecf67edfb71
stdlib@go1.25.1
1.25.10
percona/percona-postgresql-operator:2.8.06cce2698d3f5
stdlib@go1.25.4
1.25.10
victoriametrics/operator:v0.65.0716b89a3ed79
stdlib@go1.25.3
1.25.10

Open the chart page →

2,485
permission-managerpermission-manager1.0.0-seal1 of 1See more

permission-manager permission-manager 1.0.0-seal

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
stdlib@go1.16.8
1.25.10

Open the chart page →

2,267
matomopetbattle11.0.12 of 2See more

matomo petbattle 11.0.1

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.25.10
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
stdlib@go1.25.0
1.25.10

Open the chart page →

11,177
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
stdlib@go1.16.12
1.25.10

Open the chart page →

15,476
pet-battle-nsffpetbattle0.0.22 of 4See more

pet-battle-nsff petbattle 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
minio/mc:latesta7fe349ef4bd
stdlib@go1.24.6
1.25.10
minio/minio:latest14cea493d9a3
stdlib@go1.24.6
1.25.10

Open the chart page →

3,878
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
stdlib@go1.16.12
1.25.10

Open the chart page →

15,476
mariadbpetersandor15.2.51 of 1See more

mariadb petersandor 15.2.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bitnami/mariadb:11.7.216a7dae804fb
stdlib@go1.22.12
1.25.10

Open the chart page →

2,943
mongodbpetersandor14.1.81 of 1See more

mongodb petersandor 14.1.8

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bitnami/mongodb:8.0.8b3bd5b6be9a0
stdlib@go1.23.7
1.25.10

Open the chart page →

4,511
redispetersandor15.2.21 of 1See more

redis petersandor 15.2.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bitnami/redis:7.4.24e65bf641805
stdlib@go1.23.8
1.25.10

Open the chart page →

2,781
whoamiphilippwaller1.0.31 of 1See more

whoami philippwaller 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
traefik/whoami:v1.8.08d0f943abdbf
stdlib@go1.17.7
1.25.10

Open the chart page →

1,007
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
stdlib@go1.16
1.25.10

Open the chart page →

6,528
container-agentphntom100.0.11 of 1See more

container-agent phntom 100.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
circleci/container-agent:34d8d0ae5efc3
stdlib@go1.19.7
1.25.10

Open the chart page →

1,974
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
stdlib@go1.19.2
1.25.10

Open the chart page →

4,649
goalertphntom0.0.291 of 1See more

goalert phntom 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
phntom/goalert:0.0.298ca4df55499b
stdlib@go1.21.5
1.25.10

Open the chart page →

1,050
kochiphntom1.1.41 of 1See more

kochi phntom 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
phntom/kochi:1.1.33b82358bd56e
stdlib@go1.15.5
1.25.10

Open the chart page →

2,964
loki-stackphntom2.10.22 of 2See more

loki-stack phntom 2.10.2

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/loki:2.4.2b3af8ead67d7
stdlib@go1.17.2
1.25.10
grafana/promtail:2.4.2626900031c4e
stdlib@go1.17.2
1.25.10

Open the chart page →

5,725
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
stdlib@go1.16.2
1.25.10

Open the chart page →

4,160
npre-essentialsphntom0.1.6013 of 22See more

npre-essentials phntom 0.1.60

13 of the 22 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.25.10
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.25.10
grafana/promtail:2.7.0c16c710f7333
stdlib@go1.19.2
1.25.10
phntom/chartmuseum:v0.15.29242b4df9e65
stdlib@go1.18.5
1.25.10
phntom/kochi:1.1.33b82358bd56e
stdlib@go1.15.5
1.25.10
phntom/oauth2-proxy:v7.3.48ea656a2a895
stdlib@go1.19.2
1.25.10
quay.io/groundcover/grafana:9.3.18c65b333a3d3
stdlib@go1.19.3
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.61.1cd7d1a82ef00
stdlib@go1.19.3
1.25.10
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.25.10
quay.io/prometheuscommunity/elasticsearch-exporter:v1.5.013a41e8ac836
stdlib@go1.18.4
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
stdlib@go1.19.3
1.25.10

Open the chart page →

26,899
prometheus-elasticsearch-exporterphntom4.5.11 of 2See more

prometheus-elasticsearch-exporter phntom 4.5.1

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.25.10

Open the chart page →

2,030
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
stdlib@go1.19
1.25.10

Open the chart page →

88,025
picoclawpicoclawVerified publisher0.1.261 of 1See more

picoclaw picoclaw 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/mattn/picoclaw:latest517556c8b144
stdlib@go1.26.0
1.25.10

Open the chart page →

1,550
pagespighosh-pages1.0.01 of 3See more

pages pighosh-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,261
blockmeta-servicepinaxVerified publisher0.0.31 of 1See more

blockmeta-service pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
stdlib@go1.22.1
1.25.10

Open the chart page →

1,698
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
stdlib@go1.18.5
1.25.10

Open the chart page →

3,553
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
stdlib@go1.24.2
1.25.10

Open the chart page →

7,210
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
stdlib@go1.22.9
1.25.10

Open the chart page →

53,858
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
stdlib@go1.22.9
1.25.10

Open the chart page →

53,799
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
stdlib@go1.24.5
1.25.10

Open the chart page →

4,984
pixie-operator-chartpixie0.1.71 of 3See more

pixie-operator-chart pixie 0.1.7

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned1b6002156f56
stdlib@go1.21.7
1.25.10

Open the chart page →

1,915
pixie-operator-helm2-chartpixie0.1.21 of 2See more

pixie-operator-helm2-chart pixie 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinnedf9ea8cef95ac
stdlib@go1.19.6
1.25.10

Open the chart page →

1,769
planectlplanectlVerified publisher0.7.06 of 10See more

planectl planectl 0.7.0

6 of the 10 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
stdlib@go1.22.3
1.25.10
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
stdlib@go1.24.6
1.25.10
gitea/act_runner:0.2.11c57233403eff
stdlib@go1.23.1
1.25.10
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.25.10
pulumi/pulumi-kubernetes-operator:v2.5.17dace4491358
stdlib@go1.24.13
1.25.10
quay.io/argoproj/argocd:v2.14.115fc69e31c755
stdlib@go1.22.2
1.25.10

Open the chart page →

26,407
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
stdlib@go1.13.12
1.25.10

Open the chart page →

11,163
pixiecorepnnl-miscscripts0.0.161 of 1See more

pixiecore pnnl-miscscripts 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
pnnlmiscscripts/pixiecore:1.0.1-1c6f17741a0d7
stdlib@go1.24.1
1.25.10

Open the chart page →

943
tenant-namespacepnnl-miscscripts0.6.231 of 1See more

tenant-namespace pnnl-miscscripts 0.6.23

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
stdlib@go1.18.2
1.25.10

Open the chart page →

2,578
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
stdlib@go1.19.13
1.25.10

Open the chart page →

13,114
podnat-controllerpodnat-controller0.5.21 of 1See more

podnat-controller podnat-controller 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
gutmensch/podnat-controller:0.5.2566979793fc4
stdlib@go1.22.3
1.25.10

Open the chart page →

984
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.25.10

Open the chart page →

11,311
static-sitepodzone-chartsVerified publisher0.1.11 of 2See more

static-site podzone-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
stdlib@go1.20.10
1.25.10

Open the chart page →

6,606
agentpolyaxon2.17.01 of 4See more

agent polyaxon 2.17.0

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
polyaxon/polyaxon-operator:2.17.07664c1cebb9d
stdlib@go1.24.13
1.25.10

Open the chart page →

8,953
polyaxonpolyaxon2.17.01 of 5See more

polyaxon polyaxon 2.17.0

1 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
polyaxon/polyaxon-operator:2.17.07664c1cebb9d
stdlib@go1.24.13
1.25.10

Open the chart page →

12,731
trainingjobspolyaxon2.1.01 of 1See more

trainingjobs polyaxon 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
polyaxon/training-operator:2.1.0b5b29deaec9a
stdlib@go1.20.13
1.25.10

Open the chart page →

726
beylaportefaix-hub0.1.01 of 1See more

beyla portefaix-hub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/beyla:1.3.336d07f8d276e
stdlib@go1.21.7
1.25.10

Open the chart page →

2,729
cloudflare-tunnelportefaix-hub0.4.01 of 1See more

cloudflare-tunnel portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.8.314d9c6b01b29
stdlib@go1.22.2-devel-cf
1.25.10

Open the chart page →

1,344
podtato-headportefaix-hub0.3.06 of 6See more

podtato-head portefaix-hub 0.3.0

6 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/podtato-head/entry:latestc3d9d9c98be7
stdlib@go1.19
1.25.10
ghcr.io/podtato-head/hat:latestde37ff39a4c0
stdlib@go1.19
1.25.10
ghcr.io/podtato-head/left-arm:latest97596c95276a
stdlib@go1.19
1.25.10
ghcr.io/podtato-head/left-leg:latest00bb31622b1e
stdlib@go1.19
1.25.10
ghcr.io/podtato-head/right-arm:latest5f8f97a60558
stdlib@go1.19
1.25.10
ghcr.io/podtato-head/right-leg:latest03e125b9279e
stdlib@go1.19
1.25.10

Open the chart page →

5,279
prometheus-bbox-exporterportefaix-hub0.4.11 of 1See more

prometheus-bbox-exporter portefaix-hub 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/nlamirault/bbox_exporter:1.0.0f5dd1f7794c6
stdlib@go1.18.3
1.25.10

Open the chart page →

2,014
prometheus-freebox-exporterportefaix-hub0.1.11 of 1See more

prometheus-freebox-exporter portefaix-hub 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/nlamirault/freebox-exporter:1.0.02d522b664e12
stdlib@go1.19.2
1.25.10

Open the chart page →

1,755
speedtest-exporterportefaix-hub0.5.01 of 1See more

speedtest-exporter portefaix-hub 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
stdlib@go1.16.6
1.25.10

Open the chart page →

1,209
unifi-pollerportefaix-hub0.1.01 of 1See more

unifi-poller portefaix-hub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
golift/unifi-poller:v2.9.5486a63339969
stdlib@go1.21.5
1.25.10

Open the chart page →

975

Container images carrying it

4,520 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
miniflux/miniflux:2.0.36e2fb990dae74
stdlib@go1.17.8
1.25.10
1
minio/kes:v0.22.255f3aef5803e
stdlib@go1.19.3
1.25.10
1
minio/kes:2023-04-03T16-41-28Zf93c2d9088df
stdlib@go1.20.2
1.25.10
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
stdlib@go1.15.7
1.25.10
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
stdlib@go1.17.9
1.25.10
1
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
stdlib@go1.13.8
1.25.10
1
minio/mc:RELEASE.2024-01-16T16-06-34Z591b097ea2d4
stdlib@go1.21.6
1.25.10
1
minio/mc:RELEASE.2025-04-16T18-13-26Zaead63c77f9d
stdlib@go1.24.2
1.25.10
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
stdlib@go1.19.6
1.25.10
1
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
stdlib@go1.15.5
1.25.10
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
stdlib@go1.17.5
1.25.10
1
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
stdlib@go1.22.3
1.25.10
1
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
stdlib@go1.21.6
1.25.10
1
minio/minio:RELEASE.2024-01-18T22-51-28Z551682a57a94
stdlib@go1.21.6
1.25.10
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
stdlib@go1.19.7
1.25.10
1
minio/minio:RELEASE.2025-07-23T15-54-02Zd249d1fb6966
stdlib@go1.24.5
1.25.10
1
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
stdlib@go1.14.9
1.25.10
1
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
stdlib@go1.13.5
1.25.10
1
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
stdlib@go1.19.2
1.25.10
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
stdlib@go1.19.4
1.25.10
1
minio/operator:v5.0.9170b154d2c61
stdlib@go1.21.1
1.25.10
1
minio/operator:v4.1.02adc5be088f5
stdlib@go1.16.3
1.25.10
1
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
stdlib@go1.13.12
1.25.10
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
stdlib@go1.13.9
1.25.10
1
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
stdlib@go1.13.9
1.25.10
1
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
stdlib@go1.13.9
1.25.10
1
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
stdlib@go1.13.9
1.25.10
1
mirrorgitlabcontainers/kubectl:1.13.1299931bd06b41
stdlib@go1.13.3
1.25.10
1
mitre/vulcan:latest2bc4dfb8150f
stdlib@go1.25.5
1.25.10
1
moby/buildkit:master-rootless07115a67cd22
stdlib@go1.25.7
1.25.10
1
moby/buildkit:v0.33.06c2fa84a6b61
stdlib@go1.25.7
1.25.10
1
moby/buildkit:v0.33.0-rootless80b15f0735e8
stdlib@go1.25.7
1.25.10
1
moby/buildkit:v0.31.0a095b3d11ce1
stdlib@go1.25.7
1.25.10
1
moby/buildkit:masterbc964521ee58
stdlib@go1.25.7
1.25.10
1
moby/buildkit:v0.10.0c2aeafaed434
stdlib@go1.17.8
1.25.10
1
moikot/basic-git-server:0.0.20d941bd30ffa
stdlib@go1.14.9
1.25.10
1
moikot/smartthings-metrics:0.1.08625f53aa9b7
stdlib@go1.14.13
1.25.10
1
moikot/smartthings-metrics:feat-log-detailsfb8565140106
stdlib@go1.14.15
1.25.10
1
mongodb/mongodb-atlas-local:8925c3d34f0c6
stdlib@go1.25.9
1.25.10
1
monitoror/monitoror:44b88edcf51ff
stdlib@go1.14.6
1.25.10
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
stdlib@go1.20.12
1.25.10
1
moul/sshportal:v1.19.3332b603727c3
stdlib@go1.17.6
1.25.10
1
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
stdlib@go1.15.13
1.25.10
1
muonsoft/openapi-mock:latestc9afe1295484
stdlib@go1.20.2
1.25.10
1
murtazashah46/helmfile:latest4d11726cf803
stdlib@go1.22.8
1.25.10
1
mvisonneau/tailscale:v1.68.1fc45ad8abf10
stdlib@go1.22.4
1.25.10
1
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
stdlib@go1.16.1
1.25.10
1
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
stdlib@go1.19.13
1.25.10
1
n8nio/n8n:1.86.08b39ed5a2de9
stdlib@go1.24.0
1.25.10
1
n8nio/n8n:1.115.1ed16e560c40e
stdlib@go1.24.6
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.