StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,158
of 17,813 indexed, latest versions
Container images
4,758
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,158 of 17,813 indexed charts deploy, on 4,758 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+184 more1.25.114,758
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,158 by stars
ChartLatestAffected imagesRadar Score
loki-standaloneot-container-kit1.0.22 of 5See more

loki-standalone ot-container-kit 1.0.2

2 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/opstree/loki:3.6-debian13bdfee214c7ea
stdlib@go1.26.2
1.25.11
quay.io/opstree/memcached-exporter:0.15.5-debian13cf8f8410eaad
stdlib@go1.26.2
1.25.11

Open the chart page →

3,667
mongodb-operatorot-container-kit0.3.11 of 1See more

mongodb-operator ot-container-kit 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/opstree/mongodb-operator:v0.3.0879b9bead838
stdlib@go1.17.8
1.25.11

Open the chart page →

1,874
mysqlot-container-kit0.1.01 of 1See more

mysql ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

463
otel-operatorot-container-kit1.0.11 of 1See more

otel-operator ot-container-kit 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/opstree/opentelemetry-operator:0.149.0-debian13a21405ab9a9a
stdlib@go1.25.9
1.25.11

Open the chart page →

290
ot-karpenterot-container-kit0.3.01 of 1See more

ot-karpenter ot-container-kit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:1.1.1fe383abf1dbc
stdlib@go1.23.2
1.25.11

Open the chart page →

495
pgaot-container-kit1.0.34 of 6See more

pga ot-container-kit 1.0.3

4 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:11.1.0079600c9517b
stdlib@go1.22.4
1.25.11
quay.io/prometheus-operator/prometheus-operator:v0.75.1a7cc63108511
stdlib@go1.22.4
1.25.11
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.11

Open the chart page →

5,153
tempo-standaloneot-container-kit1.0.11 of 1See more

tempo-standalone ot-container-kit 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/opstree/tempo:2.10.4-debian13cb734024b3fd
stdlib@go1.26.2
1.25.11

Open the chart page →

612
vmot-container-kit0.0.34 of 7See more

vm ot-container-kit 0.0.3

4 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
stdlib@go1.22.4
1.25.11
victoriametrics/operator:v0.47.271be93cfafb6
stdlib@go1.23.0
1.25.11
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.11

Open the chart page →

5,428
vm-standaloneot-container-kit0.0.44 of 6See more

vm-standalone ot-container-kit 0.0.4

4 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/opstree/grafana:12.4.3b61c1ed2f015
stdlib@go1.26.2
1.25.11
quay.io/opstree/kube-state-metrics:2.18.0-debian1353525d253793
stdlib@go1.25.9
1.25.11
quay.io/opstree/node-exporter:1.11.1-alpine3.233b6b3a7eb001
stdlib@go1.26.2
1.25.11
quay.io/opstree/victoriametrics-operator:v0.69.066fe5216c278
stdlib@go1.26.2
1.25.11

Open the chart page →

3,507
otel-add-onotel-add-onVerified publisher0.1.41 of 1See more

otel-add-on otel-add-on 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/kedify/otel-add-on:v0.1.4a6f2155bd822
stdlib@go1.24.3
1.25.11

Open the chart page →

734
otsotsVerified publisher1.8.41 of 2See more

ots ots 1.8.4

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/luzifer/ots:v1.21.5c94f6c9ed173
stdlib@go1.26.2
1.25.11

Open the chart page →

367
adotowan-charts0.1.01 of 1See more

adot owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
stdlib@go1.24.3
1.25.11

Open the chart page →

1,033
httpbunowan-charts0.1.01 of 1See more

httpbun owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
sharat87/httpbun:latest405332d9050a
stdlib@go1.25.1
1.25.11

Open the chart page →

314
minioowan-charts0.1.21 of 2See more

minio owan-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
stdlib@go1.24.4
1.25.11

Open the chart page →

1,083
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
stdlib@go1.17
1.25.11

Open the chart page →

1,827
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
stdlib@go1.22.5
1.25.11

Open the chart page →

1,997
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
stdlib@go1.22.1
1.25.11

Open the chart page →

3,695
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
stdlib@go1.22.5
1.25.11

Open the chart page →

3,362
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
stdlib@go1.21.1
1.25.11
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
stdlib@go1.21.1
1.25.11

Open the chart page →

2,336
predicatep2p-avs0.1.41 of 1See more

predicate p2p-avs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
stdlib@go1.23.5
1.25.11

Open the chart page →

893
p4p40.1.03 of 7See more

p4 p4 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
stdlib@go1.18.10
1.25.11
library/mongo:5.0-focal5e15a3f014ed
stdlib@go1.25.9
1.25.11
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.11

Open the chart page →

27,879
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.11

Open the chart page →

19,768
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
stdlib@go1.24.0
1.25.11

Open the chart page →

3,627
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-andromeda1.0.01 of 3See more

pages pages-andromeda 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespagesbadami1.0.01 of 3See more

pages pagesbadami 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-blackburn1.0.01 of 3See more

pages pages-blackburn 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-botes1.0.01 of 3See more

pages pages-botes 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-brian1.0.01 of 3See more

pages pages-brian 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-buckll1.0.01 of 3See more

pages pages-buckll 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-camden1.0.01 of 3See more

pages pages-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-camden7711.0.01 of 3See more

pages pages-camden771 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-diarmuidkeane1.0.01 of 3See more

pages pages-diarmuidkeane 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-draco1.0.01 of 3See more

pages pages-draco 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-ellora1.0.01 of 3See more

pages pages-ellora 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-finchley1.0.01 of 3See more

pages pages-finchley 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-fornax1.0.01 of 3See more

pages pages-fornax 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-harsh1.0.01 of 3See more

pages pages-harsh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespagesk1.0.01 of 3See more

pages pagesk 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-microservice-ashim1.0.01 of 3See more

pages pages-microservice-ashim 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-mihai1.0.01 of 3See more

pages pages-mihai 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespages-nivesh1.0.01 of 3See more

pages pages-nivesh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285
pagespagessandeepgudu1.0.01 of 3See more

pages pagessandeepgudu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,285

Container images carrying it

4,758 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
conduction/agendaservice-php:latest9cfeeb6c7c20
stdlib@go1.13.10
1.25.11
1
conduction/balance-registration-php:devc36094a41369
stdlib@go1.13.10
1.25.11
1
conduction/betaalservice-php:latestece1ab544c57
stdlib@go1.13.10
1.25.11
1
conduction/cgrc-php:dev25415534d245
stdlib@go1.13.10
1.25.11
1
conduction/checkin-component-php:dev3423845692c1
stdlib@go1.13.10
1.25.11
1
conduction/conduction-ui-php:dev2744565516e8
stdlib@go1.13.10
1.25.11
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
stdlib@go1.13.10
1.25.11
1
conduction/docparser-php:devb6f95c8ead7d
stdlib@go1.13.10
1.25.11
1
conduction/kvk-php:dev8f177f9f8a7b
stdlib@go1.13.10
1.25.11
1
conduction/pan-php:dev24f03c57568f
stdlib@go1.13.10
1.25.11
1
containous/maesh:v1.3.2587162516502
stdlib@go1.14.4
1.25.11
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
stdlib@go1.22.7
1.25.11
1
coredns/coredns:1.12.040384aa1f5ea
stdlib@go1.23.3
1.25.11
1
coredns/coredns:1.7.073ca82b4ce82
stdlib@go1.14.4
1.25.11
1
coredns/coredns:1.11.39caabbf6238b
stdlib@go1.21.11
1.25.11
1
coredns/coredns:1.10.1a0ead06651cf
stdlib@go1.20
1.25.11
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
stdlib@go1.24.1
1.25.11
1
cortezaproject/corteza:2024.9.08eb7a26605c9
stdlib@go1.19.13
1.25.11
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
stdlib@go1.24.1
1.25.11
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
stdlib@go1.23.5
1.25.11
1
countly/api:25.05.4f4cc7447c4f5
stdlib@go1.19.4
1.25.11
1
countly/countly-server:25.05.4e3c238248f99
stdlib@go1.21.11
1.25.11
1
countly/frontend:25.05.42acbc11499b6
stdlib@go1.19.4
1.25.11
1
craftypath/sops-operator:v0.8.0402a0024c732
stdlib@go1.16.5
1.25.11
1
crossplane/crossplane:v0.12.066666e6963af
stdlib@go1.14.4
1.25.11
1
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
stdlib@go1.13.14
1.25.11
1
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
stdlib@go1.13.15
1.25.11
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
stdlib@go1.14.2
1.25.11
1
csepulvedab/secret-sync:0.5227a6f2b0ff8
stdlib@go1.19.4
1.25.11
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
stdlib@go1.14.4
1.25.11
1
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
stdlib@go1.15
1.25.11
1
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
stdlib@go1.16.13
1.25.11
1
cube8021/push-to-k8s:v1.1.21be9baf096ff
stdlib@go1.22.4
1.25.11
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
stdlib@go1.25.4
1.25.11
1
czerwonk/ping_exporter:v1.1.394f51e1ef1e2
stdlib@go1.22.1
1.25.11
1
dabealu/zookeeper-exporter:latest86106fec315f
stdlib@go1.14.15
1.25.11
1
dagster/dagster-cloud-agent:1.13.2322036fc83927
stdlib@go1.25.7
1.25.11
1
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.25.11
1
dalf/morty:latest248a4849c350
stdlib@go1.18.2
1.25.11
1
danielfm/kube-ecr-cleanup-controller:0.1.1012485563b1d0
stdlib@go1.19.6
1.25.11
1
danielqsj/kafka-exporter:latesta51b280b55a7
stdlib@go1.26.2
1.25.11
1
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
stdlib@go1.20.4
1.25.11
1
dannielkil/book-db:latest433290c5c1db
stdlib@go1.18.2
1.25.11
1
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.25.11
1
daprio/dashboard:0.15.04be696707bd1
stdlib@go1.21.13
1.25.11
1
daprio/dashboard:0.14.07ba5d51e5b97
stdlib@go1.19.13
1.25.11
1
daprio/injector:1.11.2763b9b70b0c8
stdlib@go1.20.6
1.25.11
1
daprio/operator:1.11.2c584428aa12d
stdlib@go1.20.6
1.25.11
1
daprio/placement:1.11.2d8e1446da996
stdlib@go1.20.6
1.25.11
1
daprio/sentry:1.11.21f507c1a181b
stdlib@go1.20.6
1.25.11
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.