StackRadar

CVE-2026-42499

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,939
of 17,787 indexed, latest versions
Container images
4,537
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatenation in consumePhrase in net/mail

Carried by container images the latest versions of 3,939 of 17,787 indexed charts deploy, on 4,537 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,537
OSV records
DEBIAN-CVE-2026-42499GO-2026-4977
Also known as
BIT-golang-2026-42499

Charts affected

3,939 by stars
ChartLatestAffected imagesRadar Score
butane-operatorbutane-operatorVerified publisher0.3.02 of 2See more

butane-operator butane-operator 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/naval-group/butane-operator:v0.1.1-rc285818b510780
stdlib@go1.26.0
1.25.10
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
stdlib@go1.21.7
1.25.10

Open the chart page →

1,396
butlercibutlerciVerified publisher0.1.01 of 1See more

butlerci butlerci 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
etejeda/butlerci:0.1.0737d58183abc
stdlib@go1.16.3
1.25.10

Open the chart page →

2,374
accelerationbuttahtoastVerified publisher0.1.01 of 1See more

acceleration buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
goharbor/harbor-acceld:0.2.13451103a6c8d8
stdlib@go1.21.5
1.25.10

Open the chart page →

1,400
fluobuttahtoastVerified publisher0.1.01 of 1See more

fluo buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
stdlib@go1.20.6
1.25.10

Open the chart page →

1,298
kubermatic-operatorbuttahtoastVerified publisher2.24.51 of 1See more

kubermatic-operator buttahtoast 2.24.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
stdlib@go1.20.6
1.25.10

Open the chart page →

2,772
kubevirt-managerbuttahtoastVerified publisher0.1.31 of 1See more

kubevirt-manager buttahtoast 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
stdlib@go1.21.7
1.25.10

Open the chart page →

1,497
mariadbbysamioVerified publisher1.0.21 of 1See more

mariadb bysamio 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mariadb:12.0.2607835cd628b
stdlib@go1.24.6
1.25.10

Open the chart page →

2,942
miniobysamioVerified publisher1.0.31 of 1See more

minio bysamio 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
stdlib@go1.24.6
1.25.10

Open the chart page →

1,069
caddycaddyVerified publisher0.0.41 of 1See more

caddy caddy 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/caddy:2.11.2-alpine834468128c76
stdlib@go1.26.0
1.25.10

Open the chart page →

1,677
etcdcagriekinVerified publisher0.1.51 of 1See more

etcd cagriekin 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.16d967d98a12dc
stdlib@go1.22.7
1.25.10

Open the chart page →

892
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.9.04150e46b2e96
stdlib@go1.24.0
1.25.10

Open the chart page →

2,399
rediscagriekinVerified publisher1.5.21 of 2See more

redis cagriekin 1.5.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.67.0120f7ec77293
stdlib@go1.23.4
1.25.10

Open the chart page →

1,369
ct-singlecalltelemetry0.8.44 of 7See more

ct-single calltelemetry 0.8.4

4 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.25.10
natsio/nats-box:0.11.09fbf7bf684e4
stdlib@go1.18.1
1.25.10
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.25.10
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.25.10

Open the chart page →

10,442
stablecalltelemetry0.7.14 of 9See more

stable calltelemetry 0.7.1

4 of the 9 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.25.10
natsio/nats-box:0.11.09fbf7bf684e4
stdlib@go1.18.1
1.25.10
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.25.10
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.25.10

Open the chart page →

7,702
stable-hacalltelemetry0.11.43 of 7See more

stable-ha calltelemetry 0.11.4

3 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/nats:2.10.12-alpinebca70839d953
stdlib@go1.21.8
1.25.10
natsio/nats-box:0.14.2e808e0644ce1
stdlib@go1.21.5
1.25.10
natsio/nats-server-config-reloader:0.14.10d50270fa374
stdlib@go1.20.5
1.25.10

Open the chart page →

4,705
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,233
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/redis:5.0fc5ecd863862
stdlib@go1.16.7
1.25.10

Open the chart page →

7,329
geoservercamptocamp20.0.31 of 12See more

geoserver camptocamp2 0.0.3

1 of the 12 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.25.10

Open the chart page →

88,377
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
stdlib@go1.16.5
1.25.10

Open the chart page →

4,518
getconfigcamptocamp30.1.11 of 1See more

getconfig camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
stdlib@go1.17.10
1.25.10

Open the chart page →

2,195
prometheus-puppetdb-sdcamptocamp38.0.21 of 2See more

prometheus-puppetdb-sd camptocamp3 8.0.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/prometheus-puppetdb-sd:0.14.0414c0c99fd06
stdlib@go1.23.5
1.25.10

Open the chart page →

6,158
redisoperatorcamptocamp33.0.11 of 1See more

redisoperator camptocamp3 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/spotahome/redis-operator:latest8c772955184e
stdlib@go1.20.7
1.25.10

Open the chart page →

1,193
s3-exportercamptocamp32.2.01 of 1See more

s3-exporter camptocamp3 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ribbybibby/s3-exporter:v0.5.0998184c51a00
stdlib@go1.15.15
1.25.10

Open the chart page →

1,183
snyk-exportercamptocamp30.1.41 of 1See more

snyk-exporter camptocamp3 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/lunarway/snyk_exporter:v1.11.155e5cc5aaa0a
stdlib@go1.17.7
1.25.10

Open the chart page →

1,079
ssl-exportercamptocamp30.1.01 of 1See more

ssl-exporter camptocamp3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
stdlib@go1.18.3
1.25.10

Open the chart page →

1,632
terraboardcamptocamp32.4.01 of 1See more

terraboard camptocamp3 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
stdlib@go1.21.3
1.25.10

Open the chart page →

1,330
caninecanine0.1.105 of 7See more

canine canine 0.1.10

5 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
stdlib@go1.22.7
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
stdlib@go1.22.5
1.25.10
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
stdlib@go1.22.5
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
stdlib@go1.22.5
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
stdlib@go1.22.5
1.25.10

Open the chart page →

13,363
cert-managercanine1.15.34 of 4See more

cert-manager canine 1.15.3

4 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
stdlib@go1.22.5
1.25.10
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
stdlib@go1.22.5
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
stdlib@go1.22.5
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
stdlib@go1.22.5
1.25.10

Open the chart page →

2,880
capi2argo-cluster-operatorcapi2argo1.5.01 of 1See more

capi2argo-cluster-operator capi2argo 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/dntosas/capi2argo-cluster-operator:v1.5.0fb8c6457ef6e
stdlib@go1.25.6
1.25.10

Open the chart page →

281
capsule-argo-addoncapsule-argo-addonVerified publisher0.7.52 of 2See more

capsule-argo-addon capsule-argo-addon 0.7.5

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.25.10
ghcr.io/peak-scale/capsule-argo-addon:0.7.5087a80163971
stdlib@go1.24.13
1.25.10

Open the chart page →

2,040
freebox-exportercaptnbpVerified publisher1.0.01 of 1See more

freebox-exporter captnbp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
captnbp/freebox-exporter:1.0.0-r01600c5a253e0
stdlib@go1.21.3
1.25.10

Open the chart page →

717
ranchercarbide-charts2.15.11 of 2See more

rancher carbide-charts 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
stdlib@go1.26.1
1.25.10

Open the chart page →

1,456
stigatroncarbide-charts0.4.13 of 10See more

stigatron carbide-charts 0.4.1

3 of the 10 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.25.10
natsio/nats-box:0.14.1a67913df95f1
stdlib@go1.21.3
1.25.10
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.25.10

Open the chart page →

4,423
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,233
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,233
casdoor-helm-chartscasdoor4.4.01 of 1See more

casdoor-helm-charts casdoor 4.4.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
casbin/casdoor:4.4.08511c0757ac3
stdlib@go1.25.8
1.25.10

Open the chart page →

1,103
cassandra-webcassandra-web0.1.01 of 1See more

cassandra-web cassandra-web 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ipushc/cassandra-web:latestfa3e0c66c289
stdlib@go1.20.2
1.25.10

Open the chart page →

1,301
castai-tetragoncastaiVerified publisher0.6.12 of 4See more

castai-tetragon castai 0.6.1

2 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
stdlib@go1.19.2
1.25.10
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
stdlib@go1.18.3
1.25.10

Open the chart page →

4,136
castware-componentscastaiVerified publisher0.4.01 of 1See more

castware-components castai 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
stdlib@go1.19.3
1.25.10

Open the chart page →

3,451
temporalcastaiVerified publisher0.54.210 of 14See more

temporal castai 0.54.2

10 of the 14 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
stdlib@go1.21.10
1.25.10
temporalio/admin-tools:1.26.237e2e33dbd7b
stdlib@go1.22.5
1.25.10
temporalio/server:1.26.21e2626efcbc1
stdlib@go1.23.2
1.25.10
temporalio/ui:2.33.05c586a3c8ec5
stdlib@go1.23.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
stdlib@go1.22.3
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.10
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.25.10
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
stdlib@go1.22.4
1.25.10
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.10

Open the chart page →

16,197
catalyst-agentscatalyst-agents0.1.305 of 18See more

catalyst-agents catalyst-agents 0.1.30

5 of the 18 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
stdlib@go1.23.6
1.25.10
grafana/loki:3.0.0757b5fadf816
stdlib@go1.21.9
1.25.10
grafana/loki-canary:3.0.028d7c00588aa
stdlib@go1.21.9
1.25.10
grafana/tempo:2.5.0f0200a9bff6d
stdlib@go1.21.3
1.25.10
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
stdlib@go1.25.5
1.25.10

Open the chart page →

14,865
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
stdlib@go1.14.10
1.25.10

Open the chart page →

6,389
openldapccowleyVerified publisher2.0.41 of 3See more

openldap ccowley 2.0.4

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
stdlib@go1.13.4
1.25.10

Open the chart page →

6,219
openldap_exporterccowleyVerified publisher0.1.01 of 1See more

openldap_exporter ccowley 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
stdlib@go1.15.7
1.25.10

Open the chart page →

2,143
kube-ceemsceemsOfficialVerified publisher1.40.01 of 5See more

kube-ceems ceems 1.40.0

1 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/grafana:13.2.1-distroless3600073f45a9
stdlib@go1.25.7
1.25.10

Open the chart page →

640
cerberuscerberusVerified publisher0.16.01 of 1See more

cerberus cerberus 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/tsouza/cerberus:1.20.0ef384585f9a3
stdlib@go1.26.2
1.25.10

Open the chart page →

162
cert-manager-alidns-webhookcert-manager-alidns-webhook0.1.41 of 1See more

cert-manager-alidns-webhook cert-manager-alidns-webhook 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/crazygit/cert-manager-alidns-webhook:0.1.4976be6506eb6
stdlib@go1.25.3
1.25.10

Open the chart page →

1,321
cert-manager-desec-webhookcert-manager-desec-webhook1.0.11 of 1See more

cert-manager-desec-webhook cert-manager-desec-webhook 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
stdlib@go1.23.4
1.25.10

Open the chart page →

1,263
cert-manager-webhook-abioncert-manager-webhook-abion1.3.21 of 1See more

cert-manager-webhook-abion cert-manager-webhook-abion 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
abiondevelopment/cert-manager-webhook-abion:latestc741988fbd23
stdlib@go1.25.1
1.25.10

Open the chart page →

1,087
cert-manager-webhook-bunnycert-manager-webhook-bunnyVerified publisher1.0.21 of 1See more

cert-manager-webhook-bunny cert-manager-webhook-bunny 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/o0th/cert-manager-webhook-bunny:1.0.2fe7ce555a12d
stdlib@go1.23.5
1.25.10

Open the chart page →

832

Container images carrying it

4,537 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.25.10
3
quay.io/devtron/nats-box:latest48cdd3054b20
stdlib@go1.19.2
1.25.10
3
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.25.10
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.25.10
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
stdlib@go1.21.5
1.25.10
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
stdlib@go1.18.10
1.25.10
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
stdlib@go1.14.9
1.25.10
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.25.10
3
quay.io/metallb/controller:v0.13.101b33357b3595
stdlib@go1.19.5
1.25.10
3
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.25.10
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.25.10
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.25.10
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
stdlib@go1.15.8
1.25.10
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.25.10
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
stdlib@go1.16.7
1.25.10
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
stdlib@go1.25.9
1.25.10
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
stdlib@go1.22.3
1.25.10
3
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
stdlib@go1.25.8
1.25.10
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
stdlib@go1.16
1.25.10
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.25.10
3
quay.io/prometheus/prometheus:v2.55.0378f4e037035
stdlib@go1.23.2
1.25.10
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
stdlib@go1.16.2
1.25.10
3
quay.io/prometheus/prometheus:v3.10.07571a304e67f
stdlib@go1.26.0
1.25.10
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
stdlib@go1.17.3
1.25.10
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.10
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
stdlib@go1.23.1
1.25.10
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.25.10
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
stdlib@go1.15.15
1.25.10
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
stdlib@go1.16.8
1.25.10
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.10
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.25.10
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
stdlib@go1.22.2
1.25.10
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
stdlib@go1.24.1
1.25.10
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
stdlib@go1.22.5
1.25.10
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
stdlib@go1.24.6
1.25.10
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
stdlib@go1.26.2
1.25.10
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
stdlib@go1.20.3
1.25.10
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
stdlib@go1.22.5
1.25.10
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
stdlib@go1.24.2
1.25.10
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
stdlib@go1.21.5
1.25.10
3
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
stdlib@go1.23.1
1.25.10
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
stdlib@go1.20.3
1.25.10
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
stdlib@go1.23.1
1.25.10
3
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
stdlib@go1.24.6
1.25.10
3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
stdlib@go1.20.3
1.25.10
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
stdlib@go1.16.2
1.25.10
3
1password/scim:v2.3.129d0c6cb67eb
stdlib@go1.16.8
1.25.10
2
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.25.10
2
alazidis/kube-netlag:1.1.00e8c84152201
stdlib@go1.24.13
1.25.10
2
alpine/git:2.47.2062a01ad7a0e
stdlib@go1.23.9
1.25.10
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.