StackRadar

CVE-2026-42504

High

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,204
of 17,828 indexed, latest versions
Container images
4,808
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic complexity in WordDecoder.DecodeHeader in mime

Carried by container images the latest versions of 4,204 of 17,828 indexed charts deploy, on 4,808 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+185 more1.25.114,808
OSV records
DEBIAN-CVE-2026-42504GO-2026-5038
Also known as
BIT-golang-2026-42504

Charts affected

4,204 by stars
ChartLatestAffected imagesRadar Score
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42504.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
stdlib@go1.20.5
1.25.11

Open the chart page →

2,482
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-42504.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
stdlib@go1.17.13
1.25.11

Open the chart page →

3,702
zookeeper-exporterzookeeper-exporter0.1.01 of 1See more

zookeeper-exporter zookeeper-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42504.

Container imageDigestPackageFixed in
dabealu/zookeeper-exporter:latest86106fec315f
stdlib@go1.14.15
1.25.11

Open the chart page →

1,249
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-42504.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
stdlib@go1.24.6
1.25.11

Open the chart page →

8,105

Container images carrying it

4,808 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/crashappsec/chalk-operator:v0.1.128eee62e9bfa
stdlib@go1.24.13
1.25.11
1
ghcr.io/crazygit/cert-manager-alidns-webhook:0.1.4976be6506eb6
stdlib@go1.25.3
1.25.11
1
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
stdlib@go1.24.7
1.25.11
1
ghcr.io/crazy-max/diun:4.19.0c94e32b888e4
stdlib@go1.16.5
1.25.11
1
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.25.11
1
ghcr.io/cronschedules/cronjob-scale-down-operator:0.4.41c4e803d7169
stdlib@go1.25.0
1.25.11
1
ghcr.io/csepulveda/trivy-webhook-aws-security-hub:v0.1.206836b779b060
stdlib@go1.26.2
1.25.11
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
stdlib@go1.20.10
1.25.11
1
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
stdlib@go1.18.4
1.25.11
1
ghcr.io/cybozu-go/accurate:2.0.0be4a2680bef4
stdlib@go1.26.3
1.25.11
1
ghcr.io/danieldonoghue/vault-sync-operator:v0.0.1-beta.38d7ec69a193c
stdlib@go1.25.9
1.25.11
1
ghcr.io/daocloud/crproxy/crproxy:v0.8.0ee1eb3c9c9a1
stdlib@go1.21.11
1.25.11
1
ghcr.io/dapr/injector:1.17.0-rc.37a2fd888ed5f
stdlib@go1.24.11
1.25.11
1
ghcr.io/dapr/operator:1.17.0-rc.3d5cc61cbe735
stdlib@go1.24.11
1.25.11
1
ghcr.io/dapr/placement:1.17.0-rc.3a237b43cd5c6
stdlib@go1.24.11
1.25.11
1
ghcr.io/dapr/scheduler:1.17.0-rc.36c62e01e736b
stdlib@go1.24.11
1.25.11
1
ghcr.io/dapr/sentry:1.17.0-rc.3bf79b03591e0
stdlib@go1.24.11
1.25.11
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
stdlib@go1.21.5
1.25.11
1
ghcr.io/davidkarlsen/flyway-operator:0.2.1366f60b461c0d
stdlib@go1.24.4
1.25.11
1
ghcr.io/dcristobalhmad/kube-secrets-exporter:latesta9043737cb73
stdlib@go1.22.3
1.25.11
1
ghcr.io/debridmediamanager/zurg-testing:v0.9.3-final5c47ef99443a
stdlib@go1.22.5
1.25.11
1
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
stdlib@go1.16.6
1.25.11
1
ghcr.io/deliveryhero/field-exporter:v1.4.06b71ba4f9297
stdlib@go1.22.12
1.25.11
1
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
stdlib@go1.25.10
1.25.11
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
stdlib@go1.24.4
1.25.11
1
ghcr.io/desuuuu/cluster-network-policy-operator:v1.1.0d943d13c5281
stdlib@go1.26.0
1.25.11
1
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
stdlib@go1.25.8
1.25.11
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
stdlib@go1.20.14
1.25.11
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
stdlib@go1.25.4
1.25.11
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
stdlib@go1.26.1
1.25.11
1
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
stdlib@go1.17
1.25.11
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
stdlib@go1.16.6
1.25.11
1
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
stdlib@go1.24.3
1.25.11
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
stdlib@go1.19.2
1.25.11
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
stdlib@go1.25.0
1.25.11
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
stdlib@go1.23.4
1.25.11
1
ghcr.io/dexidp/dex:v2.38.0b1d793440a98
stdlib@go1.21.6
1.25.11
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
stdlib@go1.19.6
1.25.11
1
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
stdlib@go1.25.7
1.25.11
1
ghcr.io/dirien/minecraft-exporter:0.24.061d89bf99ff7
stdlib@go1.25.10
1.25.11
1
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
stdlib@go1.23.7
1.25.11
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
stdlib@go1.17.5
1.25.11
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
stdlib@go1.21.0
1.25.11
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.25.11
1
ghcr.io/dntosas/capi2argo-cluster-operator:v1.5.0fb8c6457ef6e
stdlib@go1.25.6
1.25.11
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
stdlib@go1.17.9
1.25.11
1
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
stdlib@go1.18.1
1.25.11
1
ghcr.io/donkie/spoolman:0.24.042135965c42d
stdlib@go1.19.8
1.25.11
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
stdlib@go1.17.8
1.25.11
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
stdlib@go1.16.15
1.25.11
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.