StackRadar

CVE-2026-42499

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,043
of 17,821 indexed, latest versions
Container images
4,634
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatenation in consumePhrase in net/mail

Carried by container images the latest versions of 4,043 of 17,821 indexed charts deploy, on 4,634 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,634
OSV records
DEBIAN-CVE-2026-42499GO-2026-4977
Also known as
BIT-golang-2026-42499

Charts affected

4,043 by stars
ChartLatestAffected imagesRadar Score
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
stdlib@go1.20.4
1.25.10

Open the chart page →

2,514
webhook-receiversoftonic2.1.11 of 1See more

webhook-receiver softonic 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
almir/webhook:2.8.01698346f6077
stdlib@go1.14.7
1.25.10

Open the chart page →

1,928
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
stdlib@go1.26.2
1.25.10

Open the chart page →

3,131
gloo-meshsolo-gloo-mesh1.1.21 of 1See more

gloo-mesh solo-gloo-mesh 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
stdlib@go1.16.3
1.25.10

Open the chart page →

3,268
buildkitsomaz94Verified publisher0.1.41 of 1See more

buildkit somaz94 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
moby/buildkit:v0.33.06c2fa84a6b61
stdlib@go1.25.7
1.25.10

Open the chart page →

717
redis-high-availabilitysomeblackmagic1.3.102 of 3See more

redis-high-availability someblackmagic 1.3.10

2 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.8-debian-11-r0bf01d031ba8c
stdlib@go1.18.2
1.25.10
haproxytech/haproxy-alpine:2.9.57f3dc8c7e031
stdlib@go1.22.0
1.25.10

Open the chart page →

3,152
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
stdlib@go1.18.2
1.25.10

Open the chart page →

101,953
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

12,133
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
stdlib@go1.22.8
1.25.10

Open the chart page →

3,313
spire-ha-agentspiffeVerified publisher0.3.21 of 2See more

spire-ha-agent spiffe 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-ha-agent:0.5.0307cf2d05afe
stdlib@go1.25.0
1.25.10

Open the chart page →

368
spire-identity-exchangespiffeVerified publisher0.2.22 of 3See more

spire-identity-exchange spiffe 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-identity-exchange-server:v0.5.0239bc70c1988
stdlib@go1.26.0
1.25.10
registry.k8s.io/kubectl:v1.31.099b37df34bc4
stdlib@go1.22.5
1.25.10

Open the chart page →

1,442
spillwayspillwayVerified publisher0.4.41 of 1See more

spillway spillway 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/kroy-the-rabbit/spillway:0.4.48de556d3bda7
stdlib@go1.26.1
1.25.10

Open the chart page →

267
spinnakerspinnakerVerified publisher2.2.132 of 4See more

spinnaker spinnaker 2.2.13

2 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
stdlib@go1.15.5
1.25.10
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
stdlib@go1.13.5
1.25.10

Open the chart page →

6,878
spoolmanspoolmanVerified publisher0.2.61 of 1See more

spoolman spoolman 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.25.10

Open the chart page →

1,772
ocean-admission-controllerspot1.0.32 of 3See more

ocean-admission-controller spot 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
gcr.io/spotit-today/spot-ocean-admission-controller:0.1.64f634aeb31b8
stdlib@go1.24.13
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.10

Open the chart page →

773
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
stdlib@go1.24.13
1.25.10

Open the chart page →

51,225
ocean-vpaspot1.0.73 of 4See more

ocean-vpa spot 1.0.7

3 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
stdlib@go1.25.7
1.25.10
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
stdlib@go1.25.7
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
stdlib@go1.22.2
1.25.10

Open the chart page →

1,195
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
stdlib@go1.16.5
1.25.10

Open the chart page →

66,245
airflowsqream-chartsVerified publisher1.17.01 of 4See more

airflow sqream-charts 1.17.0

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/prometheus/statsd-exporter:v0.27.29ed70604d941
stdlib@go1.22.8
1.25.10

Open the chart page →

1,833
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
stdlib@go1.22.4
1.25.10

Open the chart page →

2,427
sqs-prometheus-exportersqs-prometheus-exporterVerified publisher2.0.31 of 1See more

sqs-prometheus-exporter sqs-prometheus-exporter 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/jmriebold/sqs-prometheus-exporter:1.1.07564828ab7cb
stdlib@go1.24.0
1.25.10

Open the chart page →

368
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,287
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
stdlib@go1.18.9
1.25.10

Open the chart page →

70,106
ecr-cleanersstarcher0.1.1+d13a1ab1 of 1See more

ecr-cleaner sstarcher 0.1.1+d13a1ab

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
sstarcher/ecr-cleaner:0.1.12d43c390cb19
stdlib@go1.14.2
1.25.10

Open the chart page →

2,576
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
stdlib@go1.13.9
1.25.10

Open the chart page →

3,098
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
stdlib@go1.18.3
1.25.10

Open the chart page →

3,077
retail-store-sample-catalog-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-catalog-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-catalog:1.3.0b654b266fa32
stdlib@go1.24.6
1.25.10

Open the chart page →

773
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
stdlib@go1.16.6
1.25.10

Open the chart page →

28,618
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
stdlib@go1.17.5
1.25.10

Open the chart page →

2,089
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.10

Open the chart page →

2,451
k8scostoptimizerstakaterVerified publisher0.0.51 of 1See more

k8scostoptimizer stakater 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
stdlib@go1.17.8
1.25.10

Open the chart page →

1,409
konfiguratorstakaterVerified publisher0.1.391 of 1See more

konfigurator stakater 0.1.39

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/konfigurator:v0.1.393409565b1ef5
stdlib@go1.17.13
1.25.10

Open the chart page →

1,280
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.25.10

Open the chart page →

2,854
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
stdlib@go1.15.11
1.25.10

Open the chart page →

2,174
vaultstakaterVerified publisher0.8.42 of 2See more

vault stakater 0.8.4

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
stdlib@go1.16.7
1.25.10
hashicorp/vault-k8s:0.14.0aff47b5ba39c
stdlib@go1.17.2
1.25.10

Open the chart page →

5,874
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
stdlib@go1.13.1
1.25.10

Open the chart page →

2,566
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
stdlib@go1.16.13
1.25.10

Open the chart page →

6,683
stakefishstakefish0.1.06 of 8See more

stakefish stakefish 0.1.0

6 of the 8 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
stdlib@go1.22.3
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
stdlib@go1.22.2
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.10
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
stdlib@go1.22.2
1.25.10
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.10

Open the chart page →

20,487
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
stdlib@go1.22.12
1.25.10

Open the chart page →

3,003
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.10

Open the chart page →

1,262
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.25.10

Open the chart page →

4,124
mev-booststakewise1.7.41 of 1See more

mev-boost stakewise 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
flashbots/mev-boost:1.8.07c486b5789da
stdlib@go1.22.6
1.25.10

Open the chart page →

1,261
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
stdlib@go1.17.5
1.25.10

Open the chart page →

6,609
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
stdlib@go1.22.11
1.25.10

Open the chart page →

7,067
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.10

Open the chart page →

1,262
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
stdlib@go1.25.8
1.25.10

Open the chart page →

576
open-appsec-injectorstartechnicaVerified publisher1.1.22 of 3See more

open-appsec-injector startechnica 1.1.2

2 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/openappsec/smartsync:latest580d68c50cc7
stdlib@go1.18.10
1.25.10
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
stdlib@go1.18.10
1.25.10

Open the chart page →

4,363
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.25.10

Open the chart page →

14,629
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
stdlib@go1.18.4
1.25.10

Open the chart page →

1,986
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
stdlib@go1.16.1
1.25.10
prom/prometheus:v2.22.2f7ffebdd428b
stdlib@go1.15.5
1.25.10
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
stdlib@go1.16.5
1.25.10
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
stdlib@go1.16.5
1.25.10

Open the chart page →

16,545

Container images carrying it

4,634 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.25.10
1
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
stdlib@go1.17.2
1.25.10
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
stdlib@go1.24.4
1.25.10
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
stdlib@go1.24.4
1.25.10
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
stdlib@go1.25.7
1.25.10
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
stdlib@go1.25.7
1.25.10
1
ghcr.io/spidernet-io/spiderpool/spiderpool-plugins:19f19457ae7cec86457b0411543a3cf21dd9f95a8edc39be1e22
stdlib@go1.25.7
1.25.10
1
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
stdlib@go1.20.1
1.25.10
1
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
stdlib@go1.20.1
1.25.10
1
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
stdlib@go1.20.1
1.25.10
1
ghcr.io/spiffe/spire-ha-agent:0.5.0307cf2d05afe
stdlib@go1.25.0
1.25.10
1
ghcr.io/spiffe/spire-identity-exchange-server:v0.5.0239bc70c1988
stdlib@go1.26.0
1.25.10
1
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
stdlib@go1.20.1
1.25.10
1
ghcr.io/squat/generic-device-plugin:0.2.066c8d5c270eb
stdlib@go1.26.1
1.25.10
1
ghcr.io/squat/generic-device-plugin:latestdc192e164c69
stdlib@go1.26.2
1.25.10
1
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
stdlib@go1.24.13
1.25.10
1
ghcr.io/stakater/reloader:v1.4.4a571c5b32c0f
stdlib@go1.24.4
1.25.10
1
ghcr.io/stashed/stash:v0.42.03a98245a7667
stdlib@go1.25.3
1.25.10
1
ghcr.io/stashed/stash-crd-installer:v0.42.076f0a650e44b
stdlib@go1.25.3
1.25.10
1
ghcr.io/stashed/stash-crd-installer:v0.32.0c6f2a844b5dd
stdlib@go1.20.8
1.25.10
1
ghcr.io/stashed/stash-crd-installer:v0.42.1d6c9b7a1f7b8
stdlib@go1.25.5
1.25.10
1
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
stdlib@go1.25.5
1.25.10
1
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
stdlib@go1.20.7
1.25.10
1
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
stdlib@go1.17.9
1.25.10
1
ghcr.io/stenic/k8status:0.17.093298e03089e
stdlib@go1.23.12
1.25.10
1
ghcr.io/stenic/sql-operator:1.13.2f4324baa2aad
stdlib@go1.17.13
1.25.10
1
ghcr.io/stenic/well-known:1.11.0ae85f257a10f
stdlib@go1.24.13
1.25.10
1
ghcr.io/storax/kubedoom:0.6.0851ba8c80b93
stdlib@go1.17.6
1.25.10
1
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
stdlib@go1.22.1
1.25.10
1
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
stdlib@go1.18.5
1.25.10
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
stdlib@go1.24.10
1.25.10
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
stdlib@go1.24.5
1.25.10
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
stdlib@go1.18.5
1.25.10
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
stdlib@go1.24.2
1.25.10
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
stdlib@go1.25.7
1.25.10
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
stdlib@go1.22.9
1.25.10
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
stdlib@go1.22.9
1.25.10
1
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
stdlib@go1.18.10
1.25.10
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
stdlib@go1.18.10
1.25.10
1
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
stdlib@go1.21.13
1.25.10
1
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
stdlib@go1.22.5
1.25.10
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
stdlib@go1.20.3
1.25.10
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
stdlib@go1.20.5
1.25.10
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
stdlib@go1.22.4
1.25.10
1
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
stdlib@go1.20.6
1.25.10
1
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
stdlib@go1.22.4
1.25.10
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
stdlib@go1.20.3
1.25.10
1
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
stdlib@go1.22.4
1.25.10
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
stdlib@go1.20.14
1.25.10
1
ghcr.io/syself/hetzner-cloud-controller-manager:v2.0.77d4a5e29c387
stdlib@go1.24.5
1.25.10
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.