StackRadar

CVE-2026-42499

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,955
of 17,805 indexed, latest versions
Container images
4,520
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatenation in consumePhrase in net/mail

Carried by container images the latest versions of 3,955 of 17,805 indexed charts deploy, on 4,520 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,520
OSV records
DEBIAN-CVE-2026-42499GO-2026-4977
Also known as
BIT-golang-2026-42499

Charts affected

3,955 by stars
ChartLatestAffected imagesRadar Score
api-gateway-loggingakto0.1.21 of 1See more

api-gateway-logging akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-openapi12ed2544756f
stdlib@go1.23.3
1.25.10

Open the chart page →

413
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
stdlib@go1.16.9
1.25.10

Open the chart page →

2,229
rabbitmq-cluster-operatoralekcVerified publisher2.9.01 of 1See more

rabbitmq-cluster-operator alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
stdlib@go1.25.8
1.25.10

Open the chart page →

257
valkey-operatoralekcVerified publisher0.4.01 of 1See more

valkey-operator alekc 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/hyperspike/valkey-operator:v0.0.617d8c669f11a4
stdlib@go1.25.2
1.25.10

Open the chart page →

333
mautrix-signalalexanderbadel0.1.11 of 2See more

mautrix-signal alexanderbadel 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.25.10

Open the chart page →

2,100
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
stdlib@go1.20.2
1.25.10

Open the chart page →

889
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
stdlib@go1.25.7
1.25.10

Open the chart page →

1,617
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.25.10

Open the chart page →

1,746
gotifyalexvanderberkelVerified publisher0.7.11 of 1See more

gotify alexvanderberkel 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/gotify/server:3.1.144fc5bbd1c06
stdlib@go1.26.0
1.25.10

Open the chart page →

320
book-serveral-masood-helm-charts0.1.01 of 1See more

book-server al-masood-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
almasood/book-server:latest6ffac9b63cdf
stdlib@go1.24.6
1.25.10

Open the chart page →

494
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
stdlib@go1.14.15
1.25.10

Open the chart page →

2,116
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
stdlib@go1.24.0
1.25.10

Open the chart page →

571
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
stdlib@go1.24.0
1.25.10

Open the chart page →

571
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
stdlib@go1.24.3
1.25.10

Open the chart page →

1,150
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
stdlib@go1.24.2
1.25.10

Open the chart page →

548
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
stdlib@go1.23.3
1.25.10
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
stdlib@go1.23.1
1.25.10

Open the chart page →

4,569
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
stdlib@go1.23.3
1.25.10

Open the chart page →

589
versitygwalpineworks0.1.21 of 1See more

versitygw alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
versity/versitygw:v1.0.145192635d0353
stdlib@go1.24.3
1.25.10

Open the chart page →

1,259
versitygw-webhook-pulsar-proxyalpineworks0.1.11 of 1See more

versitygw-webhook-pulsar-proxy alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
stdlib@go1.24.4
1.25.10

Open the chart page →

907
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,261
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
stdlib@go1.22.2
1.25.10
daprio/dashboard:0.14.07ba5d51e5b97
stdlib@go1.19.13
1.25.10
daprio/injector:1.11.2763b9b70b0c8
stdlib@go1.20.6
1.25.10
daprio/operator:1.11.2c584428aa12d
stdlib@go1.20.6
1.25.10
daprio/placement:1.11.2d8e1446da996
stdlib@go1.20.6
1.25.10
daprio/sentry:1.11.21f507c1a181b
stdlib@go1.20.6
1.25.10
hashicorp/vault:1.15.26b4e5dadf082
stdlib@go1.21.3
1.25.10
hashicorp/vault-k8s:1.3.15d74a885ae3e
stdlib@go1.21.3
1.25.10

Open the chart page →

28,377
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
stdlib@go1.20.14
1.25.10

Open the chart page →

1,607
anchore-admission-controlleranchore-charts0.9.01 of 2See more

anchore-admission-controller anchore-charts 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
stdlib@go1.20.14
1.25.10

Open the chart page →

7,626
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
stdlib@go1.19.7
1.25.10

Open the chart page →

1,326
cert-manager-webhook-inwxandibraeuVerified publisher0.9.01 of 1See more

cert-manager-webhook-inwx andibraeu 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
stdlib@go1.25.7
1.25.10

Open the chart page →

607
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
stdlib@go1.25.7
1.25.10

Open the chart page →

5,891
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
stdlib@go1.25.7
1.25.10

Open the chart page →

1,299
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,261
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
stdlib@go1.16.4
1.25.10

Open the chart page →

1,985
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.25.10

Open the chart page →

2,239
dnsmadeeasy-webhookangelnu6.0.71 of 1See more

dnsmadeeasy-webhook angelnu 6.0.7

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/angelnu/dnsmadeeasy-webhook:v1.9.0a5ca158b1f02
stdlib@go1.24.1
1.25.10

Open the chart page →

818
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.25.10

Open the chart page →

113,781
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
stdlib@go1.23.12
1.25.10

Open the chart page →

918
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
stdlib@go1.13.15
1.25.10

Open the chart page →

2,495
ddosifyanteonVerified publisher1.7.55 of 13See more

ddosify anteon 1.7.5

5 of the 13 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
stdlib@go1.20.8
1.25.10
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
stdlib@go1.18.1
1.25.10
library/influxdb:2.6.1-alpine44a366dd7724
stdlib@go1.19.4
1.25.10
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.10
prom/prometheus:v2.37.98176adea328e
stdlib@go1.19.11
1.25.10

Open the chart page →

26,236
antmediaantmediaVerified publisher3.1.03 of 4See more

antmedia antmedia 3.1.0

3 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mongo:8.002a0cc7939f5
stdlib@go1.24.6
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.10

Open the chart page →

4,635
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.10

Open the chart page →

3,323
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
stdlib@go1.25.7
1.25.10

Open the chart page →

2,479
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
stdlib@go1.15
1.25.10

Open the chart page →

2,731
glauthanza-labsVerified publisher1.0.11 of 1See more

glauth anza-labs 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/glauth/glauth:v2.5.209c782ca5984
stdlib@go1.25.0
1.25.10

Open the chart page →

1,325
apipingapiping1.5.01 of 1See more

apiping apiping 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
udhos/apiping:1.5.041ab9bae6f3b
stdlib@go1.25.4
1.25.10

Open the chart page →

1,149
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
stdlib@go1.23.6
1.25.10

Open the chart page →

2,995
api-usage-cleanerapi-usage-cleaner1.16.01 of 1See more

api-usage-cleaner api-usage-cleaner 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.25.10

Open the chart page →

596
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

19,821
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
stdlib@go1.18.5
1.25.10
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
stdlib@go1.18.5
1.25.10
velero/velero:v1.8.18d784580931c
stdlib@go1.16.6
1.25.10

Open the chart page →

12,559
app-movies-seriesapp-movies-seriesVerified publisher0.1.01 of 2See more

app-movies-series app-movies-series 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.25.10

Open the chart page →

3,170
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10

Open the chart page →

2,710
aceappscodeVerified publisher2026.9.112 of 2See more

ace appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.10

Open the chart page →

3,012
ace-installerappscodeVerified publisher2026.9.112 of 2See more

ace-installer appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
stdlib@go1.25.9
1.25.10
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10

Open the chart page →

3,368
ace-installer-certifiedappscodeVerified publisher2026.9.112 of 2See more

ace-installer-certified appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
stdlib@go1.25.9
1.25.10
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.10

Open the chart page →

3,368

Container images carrying it

4,520 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/pschichtel/cert-manager-webhook-cloudns:1.1.01020638bbe23
stdlib@go1.21.6
1.25.10
1
ghcr.io/puckpuck/seashell:1.2ef5e31333821
stdlib@go1.20.10
1.25.10
1
ghcr.io/pulumi/pulumi-esc-csi-provider:0.1.13fb058e93502
stdlib@go1.23.1
1.25.10
1
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
stdlib@go1.22.0
1.25.10
1
ghcr.io/pyrra-dev/pyrra:v0.8.10e02ef538ef0
stdlib@go1.23.3
1.25.10
1
ghcr.io/rabbitmq/cluster-operator:2.17.25d690e6cd856
stdlib@go1.25.4
1.25.10
1
ghcr.io/rabbitmq/cluster-operator:2.20.1a96853470256
stdlib@go1.25.9
1.25.10
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
stdlib@go1.26.2
1.25.10
1
ghcr.io/raffis/mongodb-query-exporter:v5.1.0ca6ac8a5b329
stdlib@go1.20.5
1.25.10
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
stdlib@go1.20.7
1.25.10
1
ghcr.io/razvanmacovei/x402-k8s-operator:0.1.0bf3407fad182
stdlib@go1.25.7
1.25.10
1
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
stdlib@go1.25.5
1.25.10
1
ghcr.io/ricardozd/agentgateway-route-reconciler:0.3.1846f6e407c96
stdlib@go1.24.13
1.25.10
1
ghcr.io/riesinger/plausible-exporter:1.1.061112cda1be5
stdlib@go1.19.7
1.25.10
1
ghcr.io/riotkit-org/backup-maker-controller:v0.1.262370545ba3d
stdlib@go1.19.4
1.25.10
1
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
stdlib@go1.17.13
1.25.10
1
ghcr.io/riverqueue/riverui:0.5.32dc54179b25a
stdlib@go1.23.0
1.25.10
1
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
stdlib@go1.22.1
1.25.10
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
stdlib@go1.25.5
1.25.10
1
ghcr.io/rvbsalgado/fencemaster:1.0.0-rc.207056a6aae439
stdlib@go1.25.8
1.25.10
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
stdlib@go1.20.7
1.25.10
1
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
stdlib@go1.24.5
1.25.10
1
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
stdlib@go1.17.11
1.25.10
1
ghcr.io/salaboy/fmtok8s-email-service:v0.1.0-nativecf28472bc460
stdlib@go1.17.11
1.25.10
1
ghcr.io/salemgolemugoo/argocd-bitbucket-proxy:latesta72df069095b
stdlib@go1.26.1
1.25.10
1
ghcr.io/salesforce/kubelet-summary-exporter:sha-c2bf90d377e09d2dd72
stdlib@go1.18.10
1.25.10
1
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
stdlib@go1.16.15
1.25.10
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
stdlib@go1.23.3
1.25.10
1
ghcr.io/sapcc/ntp_exporter:v2.9.079c40c65f5d4
stdlib@go1.24.6
1.25.10
1
ghcr.io/schaka/janitorr:native-stable7cfe1e0c41da
stdlib@go1.24.6
1.25.10
1
ghcr.io/schmitzis/cert-manager-webhook-bunny:latest125e31c8e85a
stdlib@go1.19.13
1.25.10
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
stdlib@go1.23.12
1.25.10
1
ghcr.io/sergelogvinov/hybrid-csi-provisioner:v0.3.1221e07794a8a
stdlib@go1.25.5
1.25.10
1
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
stdlib@go1.18.10
1.25.10
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
stdlib@go1.23.8
1.25.10
1
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
stdlib@go1.23.8
1.25.10
1
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
stdlib@go1.24.4
1.25.10
1
ghcr.io/sergelogvinov/node-labels-exporter:v0.5.1dd6875a0a963
stdlib@go1.25.5
1.25.10
1
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
stdlib@go1.24.6
1.25.10
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
stdlib@go1.24.6
1.25.10
1
ghcr.io/shaharia-lab/teredix:0.0.2ec727be4417a
stdlib@go1.21.5
1.25.10
1
ghcr.io/shift/domain_exporter:v0.1.1347e27690a816
stdlib@go1.17.8
1.25.10
1
ghcr.io/shopware/shopware-operator:1.8.187db0eda7a03
stdlib@go1.26.0
1.25.10
1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
stdlib@go1.26.0
1.25.10
1
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
stdlib@go1.26.2
1.25.10
1
ghcr.io/siderolabs/talos-backup:v0.1.0-beta.203a71e140f1d
stdlib@go1.23.0
1.25.10
1
ghcr.io/sigstore/policy-controller/policy-controller0bcd60beb93f
stdlib@go1.24.7
1.25.10
1
ghcr.io/sigstore/scaffolding/serverae8eb69c7b70
stdlib@go1.25.0
1.25.10
1
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
stdlib@go1.26.0
1.25.10
1
ghcr.io/sigstore/timestamp-server:v2.1.08637f0482ed1
stdlib@go1.25.1
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.