StackRadar

CVE-2026-42499

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,043
of 17,821 indexed, latest versions
Container images
4,634
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatenation in consumePhrase in net/mail

Carried by container images the latest versions of 4,043 of 17,821 indexed charts deploy, on 4,634 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,634
OSV records
DEBIAN-CVE-2026-42499GO-2026-4977
Also known as
BIT-golang-2026-42499

Charts affected

4,043 by stars
ChartLatestAffected imagesRadar Score
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
stdlib@go1.16.12
1.25.10

Open the chart page →

23,651
staticnicholaswildeVerified publisher1.0.01 of 1See more

static nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/static:version-ee8a20cd1d47c730bc4
stdlib@go1.16.5
1.25.10

Open the chart page →

1,155
todonicholaswildeVerified publisher0.1.01 of 1See more

todo nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/todo:941c0d3-ls1d7ba1341a940
stdlib@go1.14.15
1.25.10

Open the chart page →

1,230
twtxtnicholaswildeVerified publisher1.0.01 of 1See more

twtxt nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/twtxt:version-0.1.158736a73ca10
stdlib@go1.16.5
1.25.10

Open the chart page →

2,334
wikinicholaswildeVerified publisher1.0.01 of 1See more

wiki nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/wiki:version-900b76a6c4f261d8f5e
stdlib@go1.16.5
1.25.10

Open the chart page →

1,789
cert-managernicklasfrahm-cert-managerVerified publisher0.1.24 of 4See more

cert-manager nicklasfrahm-cert-manager 0.1.2

4 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.18.2af59e01ad975
stdlib@go1.24.4
1.25.10
quay.io/jetstack/cert-manager-controller:v1.18.281316365dc0b
stdlib@go1.24.4
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.18.21075e0974151
stdlib@go1.24.4
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.18.29431f0d8b510
stdlib@go1.24.4
1.25.10

Open the chart page →

2,856
ciliumnicklasfrahm-ciliumVerified publisher0.7.45 of 6See more

cilium nicklasfrahm-cilium 0.7.4

5 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
stdlib@go1.24.2
1.25.10
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
stdlib@go1.24.7
1.25.10
quay.io/cilium/hubble-relay:v1.18.26079308ee15e
stdlib@go1.24.7
1.25.10
quay.io/cilium/hubble-ui-backend:v0.13.3db1454e45dc3
stdlib@go1.24.5
1.25.10
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
stdlib@go1.24.7
1.25.10

Open the chart page →

7,266
metrics-servernicklasfrahm-metrics-serverVerified publisher0.1.11 of 1See more

metrics-server nicklasfrahm-metrics-server 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
stdlib@go1.24.4
1.25.10

Open the chart page →

799
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
stdlib@go1.21.5
1.25.10

Open the chart page →

2,294
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
stdlib@go1.17.6
1.25.10

Open the chart page →

2,063
terraform-backendnimbolus0.3.21 of 2See more

terraform-backend nimbolus 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/terraform-backend:0.2.2bf876252fbe1
stdlib@go1.24.13
1.25.10

Open the chart page →

2,520
yopassnimbolus0.6.11 of 2See more

yopass nimbolus 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
jhaals/yopass:11.17.026873480863b
stdlib@go1.20.5
1.25.10

Open the chart page →

1,842
airflownineinfra-charts1.12.12 of 4See more

airflow nineinfra-charts 1.12.1

2 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.25.10
quay.io/prometheus/statsd-exporter:v0.22.8f53cca722a03
stdlib@go1.18.6
1.25.10

Open the chart page →

2,260
cloudnative-pgnineinfra-charts0.19.11 of 1See more

cloudnative-pg nineinfra-charts 0.19.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
stdlib@go1.21.3
1.25.10

Open the chart page →

1,188
doris-operatornineinfra-charts1.3.11 of 1See more

doris-operator nineinfra-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
selectdb/doris.k8s-operator:1.3.1919210765cb8
stdlib@go1.19.13
1.25.10

Open the chart page →

870
hdfs-operatornineinfra-charts0.7.01 of 1See more

hdfs-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
nineinfra/hdfs-operator:v0.7.0debb1e3410e2
stdlib@go1.21.3
1.25.10

Open the chart page →

724
kyuubi-operatornineinfra-charts0.7.01 of 1See more

kyuubi-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
nineinfra/kyuubi-operator:v0.7.08d8ed87ef77c
stdlib@go1.20.8
1.25.10

Open the chart page →

815
metastore-operatornineinfra-charts0.7.01 of 1See more

metastore-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
nineinfra/metastore-operator:v0.7.011259032fb04
stdlib@go1.20.8
1.25.10

Open the chart page →

815
minio-directpvnineinfra-charts4.0.85 of 5See more

minio-directpv nineinfra-charts 4.0.8

5 of the 5 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/minio/csi-node-driver-registrardigest-pinnedc805fdc16676
stdlib@go1.20.3
1.25.10
quay.io/minio/csi-provisionerdigest-pinned7b5c070ec70d
stdlib@go1.20.3
1.25.10
quay.io/minio/csi-resizerdigest-pinned819f68a4daf7
stdlib@go1.20.3
1.25.10
quay.io/minio/directpv:v4.0.84560083eb77d
stdlib@go1.21.0
1.25.10
quay.io/minio/livenessprobedigest-pinnedf3bc9a84f149
stdlib@go1.20.3
1.25.10

Open the chart page →

7,073
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
stdlib@go1.21.1
1.25.10

Open the chart page →

3,427
nineinfranineinfra-charts0.7.01 of 1See more

nineinfra nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
nineinfra/nineinfra:v0.7.0d4aad414eccd
stdlib@go1.21.3
1.25.10

Open the chart page →

1,120
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.25.10

Open the chart page →

3,979
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
stdlib@go1.20.4
1.25.10

Open the chart page →

1,440
zookeeper-operatornineinfra-charts0.7.01 of 1See more

zookeeper-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
nineinfra/zookeeper-operator:v0.7.0af6eb2f37bfc
stdlib@go1.21.3
1.25.10

Open the chart page →

724
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
stdlib@go1.23.3
1.25.10

Open the chart page →

6,993
cosmoshub-rpcnodeifyVerified publisher1.0.71 of 2See more

cosmoshub-rpc nodeify 1.0.7

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
stdlib@go1.24.5
1.25.10

Open the chart page →

1,870
cosmos-nodenodeifyVerified publisher2.6.01 of 2See more

cosmos-node nodeify 2.6.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
stdlib@go1.24.5
1.25.10

Open the chart page →

1,870
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
stdlib@go1.24.10
1.25.10

Open the chart page →

6,628
firehose-ethereumnodeifyVerified publisher1.7.11 of 2See more

firehose-ethereum nodeify 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
stdlib@go1.25.7
1.25.10

Open the chart page →

5,742
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
stdlib@go1.19.3
1.25.10

Open the chart page →

2,922
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
stdlib@go1.18.5
1.25.10

Open the chart page →

4,785
nodejsweeklynodejsweekly1.1.01 of 1See more

nodejsweekly nodejsweekly 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
stdlib@go1.16.15
1.25.10

Open the chart page →

1,490
node-labels-exporternode-labels-exporter0.1.91 of 1See more

node-labels-exporter node-labels-exporter 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/node-labels-exporter:v0.5.1dd6875a0a963
stdlib@go1.25.5
1.25.10

Open the chart page →

292
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
stdlib@go1.21.3
1.25.10

Open the chart page →

2,986
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
stdlib@go1.20.6
1.25.10
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.25.10
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.25.10
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
stdlib@go1.21.0
1.25.10
quay.io/prometheus/pushgateway:v1.6.05111de00e969
stdlib@go1.20.4
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
stdlib@go1.20.7
1.25.10

Open the chart page →

7,760
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
robjuz/postgresql-nominatim:latest805c7bab76df
stdlib@go1.16.5
1.25.10

Open the chart page →

22,831
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

5,872
ingress-helm-chartnotesprojectchart0.1.02 of 2See more

ingress-helm-chart notesprojectchart 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.25.10

Open the chart page →

2,958
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
stdlib@go1.17.10
1.25.10

Open the chart page →

4,559
keycloak-helm-chartnotesprojectchart0.1.01 of 2See more

keycloak-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

1,618
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

6,839
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

5,899
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

5,855
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
stdlib@go1.20.4
1.25.10

Open the chart page →

2,257
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
stdlib@go1.13.10
1.25.10

Open the chart page →

7,540
clusterfannousefreakVerified publisher0.1.21 of 1See more

clusterfan nousefreak 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/nousefreak/clusterfan:v0.1.04ea05e2a7b57
stdlib@go1.17.5
1.25.10

Open the chart page →

1,791
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
stdlib@go1.15.5
1.25.10

Open the chart page →

4,862
nfs-server-provisionernovum-rgi-charts1.1.21 of 1See more

nfs-server-provisioner novum-rgi-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.25.10

Open the chart page →

2,807
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
stdlib@go1.17.11
1.25.10

Open the chart page →

27,585
nri-memory-policynri-pluginsVerified publisher0.14.01 of 1See more

nri-memory-policy nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-42499.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memory-policy:v0.14.0531d21ec4ba2
stdlib@go1.26.0
1.25.10

Open the chart page →

272

Container images carrying it

4,634 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
stdlib@go1.17.8
1.25.10
1
ghcr.io/wjentner/k8s-db-backup-retention:v1.1.08027bb46d1f4
stdlib@go1.23.5
1.25.10
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
stdlib@go1.18.1
1.25.10
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
stdlib@go1.21.9
1.25.10
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
stdlib@go1.22.3
1.25.10
1
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
stdlib@go1.23.6
1.25.10
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
stdlib@go1.23.6
1.25.10
1
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
stdlib@go1.23.12
1.25.10
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
stdlib@go1.20.7
1.25.10
1
ghcr.io/wyrihaximusnet/kubernetes-redis-db-assignment-operator:v1.0.831060be60bec
stdlib@go1.16.15
1.25.10
1
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
stdlib@go1.18.6
1.25.10
1
ghcr.io/yeonghoo2/crashloop-operator:0.0.6565d1115e6bd
stdlib@go1.24.9
1.25.10
1
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
stdlib@go1.23.4
1.25.10
1
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
stdlib@go1.22.3
1.25.10
1
ghcr.io/zcube/bitnami-compat/redis:7.0-debian-11-r55118a403046f7
stdlib@go1.19.4
1.25.10
1
ghcr.io/zeiss/natz-operator/account-server:0.9.5b380b5f17c3f
stdlib@go1.23.3
1.25.10
1
ghcr.io/zeiss/natz-operator/operator:0.9.5187007974540
stdlib@go1.23.3
1.25.10
1
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
stdlib@go1.24.0
1.25.10
1
ghcr.io/zeiss/typhoon/typhoon-webhook:0.2.378f9b82050bc
stdlib@go1.24.0
1.25.10
1
ghcr.io/zokeber/velero-notifications:0.0.176d84f6c4ce20
stdlib@go1.25.8
1.25.10
1
ghcr.io/zoriya/kyoo_transcoder:4.7.12dadea51a91e
stdlib@go1.23.4
1.25.10
1
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
stdlib@go1.23.12
1.25.10
1
mcr.microsoft.com/aks/kaito/gpu-provisioner:0.2.01204a7e948e9
stdlib@go1.21.8
1.25.10
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
stdlib@go1.17.3
1.25.10
1
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
stdlib@go1.15.4
1.25.10
1
mcr.microsoft.com/mssql/server:2022-latest4402d880dd4c
stdlib@go1.26.1
1.25.10
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
stdlib@go1.26.1
1.25.10
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
stdlib@go1.23.1
1.25.10
1
mcr.microsoft.com/oss/azure/aad-pod-identity/mic:v1.8.173004b93fcb74
stdlib@go1.19.10
1.25.10
1
mcr.microsoft.com/oss/azure/aad-pod-identity/nmi:v1.8.1777788bf38938
stdlib@go1.19.10
1.25.10
1
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
stdlib@go1.14
1.25.10
1
mcr.microsoft.com/oss/kubernetes-csi/csi-node-driver-registrar:v2.0.1fc5d14e9f26f
stdlib@go1.15
1.25.10
1
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
stdlib@go1.15.2
1.25.10
1
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
stdlib@go1.15.2
1.25.10
1
mcr.microsoft.com/oss/kubernetes-csi/livenessprobe:v2.2.0b7d82802cca8
stdlib@go1.15.6
1.25.10
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v5.2.0afdfa3da79df
stdlib@go1.25.5
1.25.10
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v1.13.2fa8eba9843ff
stdlib@go1.25.7
1.25.10
1
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
stdlib@go1.25.7
1.25.10
1
public.ecr.aws/aktosecurity/akto-agent-guard-service:latest5c6ff17c5849
stdlib@go1.25.5
1.25.10
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
stdlib@go1.24.6
1.25.10
1
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
stdlib@go1.23.4
1.25.10
1
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
stdlib@go1.25.9
1.25.10
1
public.ecr.aws/aws-containers/retail-store-sample-catalog:1.3.0b654b266fa32
stdlib@go1.24.6
1.25.10
1
public.ecr.aws/aws-ec2/amazon-ec2-metadata-mock:v1.11.2dd02d3569da0
stdlib@go1.17.13
1.25.10
1
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.19.0844478ebd5b8
stdlib@go1.19.5
1.25.10
1
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.25.69ad31fb4e5be
stdlib@go1.25.8
1.25.10
1
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
stdlib@go1.19.3
1.25.10
1
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
stdlib@go1.19.3
1.25.10
1
public.ecr.aws/aws-observability/aws-for-fluent-bit:3.2.1a480a1241720
stdlib@go1.25.6
1.25.10
1
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
stdlib@go1.24.3
1.25.10
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.