StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,036
of 17,787 indexed, latest versions
Container images
4,636
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,036 of 17,787 indexed charts deploy, on 4,636 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.114,636
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,036 by stars
ChartLatestAffected imagesRadar Score
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
stdlib@go1.21.12
1.25.11

Open the chart page →

4,300
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
stdlib@go1.17.2
1.25.11

Open the chart page →

1,573
hybrid-csi-pluginhybrid-csi-plugin0.1.111 of 1See more

hybrid-csi-plugin hybrid-csi-plugin 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/hybrid-csi-provisioner:v0.3.1221e07794a8a
stdlib@go1.25.5
1.25.11

Open the chart page →

373
spoolmanideaplexusVerified publisher2.7.11 of 1See more

spoolman ideaplexus 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.25.11

Open the chart page →

1,779
backendikusi-bk-chart1.0.31 of 3See more

backend ikusi-bk-chart 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
stdlib@go1.24.6
1.25.11

Open the chart page →

5,940
ilum-coreilumOfficialVerified publisher6.7.32 of 5See more

ilum-core ilum 6.7.3

2 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
stdlib@go1.24.6
1.25.11
ilum/mongodb:6.0.542b6d774c37d
stdlib@go1.20.12
1.25.11

Open the chart page →

3,556
ilum-jupyterilumVerified publisher6.7.31 of 2See more

ilum-jupyter ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
bitnamisecure/gitdigest-pinned72ae5bd9715f
stdlib@go1.24.6
1.25.11

Open the chart page →

644
odooimioVerified publisher3.0.21 of 3See more

odoo imio 3.0.2

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:17.10ebba4f4de37f
stdlib@go1.24.6
1.25.11

Open the chart page →

3,068
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.25.11

Open the chart page →

15,712
webhook-broker-chartimytech0.2.41 of 1See more

webhook-broker-chart imytech 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
stdlib@go1.23.0
1.25.11

Open the chart page →

1,246
inbucketinbucketVerified publisher2.5.01 of 1See more

inbucket inbucket 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
inbucket/inbucket:3.0.01f10a0efea69
stdlib@go1.17.1
1.25.11

Open the chart page →

2,167
telegraf-operatorinfluxdata1.4.01 of 1See more

telegraf-operator influxdata 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
stdlib@go1.18.10
1.25.11

Open the chart page →

925
valkey-clusterinnagoVerified publisher1.1.01 of 2See more

valkey-cluster innago 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.66.0d98e6db8094f
stdlib@go1.23.2
1.25.11

Open the chart page →

2,622
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
stdlib@go1.25.5
1.25.11

Open the chart page →

7,129
intel-device-plugins-operatorintelVerified publisher0.36.01 of 1See more

intel-device-plugins-operator intel 0.36.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
intel/intel-deviceplugin-operator:0.36.09879685d0b5b
stdlib@go1.26.3
1.25.11

Open the chart page →

88
interlinkinterlink0.6.11 of 2See more

interlink interlink 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/interlink-hq/interlink/virtual-kubelet-inttw:latest0e05a7b49c33
stdlib@go1.24.5
1.25.11

Open the chart page →

2,416
irsa-managerirsa-managerVerified publisher0.3.21 of 1See more

irsa-manager irsa-manager 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/kkb0318/irsa-manager:0.3.296d600ae97b4
stdlib@go1.22.7
1.25.11

Open the chart page →

820
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
stdlib@go1.16.6
1.25.11

Open the chart page →

10,400
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
stdlib@go1.16.6
1.25.11

Open the chart page →

10,475
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.25.11

Open the chart page →

10,421
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.25.11

Open the chart page →

10,421
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
stdlib@go1.16.6
1.25.11

Open the chart page →

10,701
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
stdlib@go1.14.15
1.25.11

Open the chart page →

1,812
kubernetes-event-exporteritakurahVerified publisher0.2.31 of 1See more

kubernetes-event-exporter itakurah 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/itakurah/kubernetes-event-exporter:v1.78abb52b66557
stdlib@go1.20.14
1.25.11

Open the chart page →

1,135
jessejesse-chartVerified publisher0.0.462 of 6See more

jesse jesse-chart 0.0.46

2 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
alpine/git:latest6f3b5029566d
stdlib@go1.26.3
1.25.11
library/postgres:alpined3e1620b530c
stdlib@go1.24.6
1.25.11

Open the chart page →

3,421
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
stdlib@go1.17.13
1.25.11

Open the chart page →

9,318
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
stdlib@go1.21.8
1.25.11

Open the chart page →

7,387
job-manager-dispatcherjob-manager-dispatcher1.27.01 of 1See more

job-manager-dispatcher job-manager-dispatcher 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
stdlib@go1.23.12
1.25.11

Open the chart page →

472
job-manager-serverjob-manager-server1.27.01 of 1See more

job-manager-server job-manager-server 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-server:1.27.0fe9de719f91e
stdlib@go1.23.12
1.25.11

Open the chart page →

750
hncjouveVerified publisher0.8.31 of 1See more

hnc jouve 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-multitenancy/hnc-manager:v1.1.08ab8229f6a89
stdlib@go1.20.5
1.25.11

Open the chart page →

1,071
joylive-injectorjoyliveOfficialVerified publisher1.3.51 of 2See more

joylive-injector joylive 1.3.5

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
otel/opentelemetry-collector:0.100.09e36620d6c2c
stdlib@go1.22.2
1.25.11

Open the chart page →

1,273
git-configmap-syncjulb-meVerified publisher1.0.11 of 2See more

git-configmap-sync julb-me 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
alpine/git:latest4f9488b7295b
stdlib@go1.26.3
1.25.11

Open the chart page →

2,618
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
stdlib@go1.18.7
1.25.11

Open the chart page →

3,369
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.3213 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

13 of the 17 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/alloy:v1.14.0f50931848bd8
stdlib@go1.25.7
1.25.11
grafana/grafana:12.3.12175aaa91c96
stdlib@go1.25.5
1.25.11
grafana/loki:3.6.73c8fd3570dd9
stdlib@go1.24.13
1.25.11
grafana/loki-canary:3.6.70dac7d5cb383
stdlib@go1.24.13
1.25.11
grafana/tempo:2.9.065a578975943
stdlib@go1.25.1
1.25.11
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
stdlib@go1.23.4
1.25.11
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
stdlib@go1.23.4
1.25.11
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
stdlib@go1.23.7
1.25.11
quay.io/prometheus-operator/prometheus-config-reloader:v0.89.0cb4ac6a56555
stdlib@go1.25.6
1.25.11
quay.io/prometheus/alertmanager:v0.31.188b605de9aba
stdlib@go1.25.7
1.25.11
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
stdlib@go1.25.3
1.25.11
quay.io/prometheus/prometheus:v3.10.07571a304e67f
stdlib@go1.26.0
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.11

Open the chart page →

15,418
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
stdlib@go1.24.7
1.25.11

Open the chart page →

5,508
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
stdlib@go1.24.4
1.25.11

Open the chart page →

5,789
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
stdlib@go1.20.7
1.25.11

Open the chart page →

5,228
keycloakkeycloak1.13.51 of 2See more

keycloak keycloak 1.13.5

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.gitlab.com/lenitech/docker/keycloak-ppolicy:0.6.09895d6915075
stdlib@go1.25.7
1.25.11

Open the chart page →

328
keycloak-client-operatorkeycloak-client-operator0.9.11 of 1See more

keycloak-client-operator keycloak-client-operator 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
stdlib@go1.24.5
1.25.11

Open the chart page →

507
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.25.11

Open the chart page →

5,264
giteakeyporttech0.2.102 of 4See more

gitea keyporttech 0.2.10

2 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
gitea/gitea:1.12.485416d6f65fe
stdlib@go1.14.8
1.25.11
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.11

Open the chart page →

5,408
kikplatekikplateVerified publisher0.22.01 of 3See more

kikplate kikplate 0.22.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.11

Open the chart page →

2,770
glpikitsune-itopsVerified publisher1.0.71 of 3See more

glpi kitsune-itops 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mariadb:latestdd9b303aed4f
stdlib@go1.24.6
1.25.11

Open the chart page →

4,802
kokukokuVerified publisher1.0.03 of 7See more

koku koku 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
minio/mc:latesta7fe349ef4bd
stdlib@go1.24.6
1.25.11
public.ecr.aws/v0r6c2e2/minio:latest08c90bd040bf
stdlib@go1.23.5
1.25.11
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
stdlib@go1.23.0
1.25.11

Open the chart page →

12,019
komkomVerified publisher0.3.01 of 1See more

kom kom 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/kkb0318/kom:0.3.04e77eff2d906
stdlib@go1.24.4
1.25.11

Open the chart page →

398
kronos-corekronos-coreVerified publisher0.4.11 of 2See more

kronos-core kronos-core 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
kronosorg/kronos-core:v0.4.0301da21c59a5
stdlib@go1.21.10
1.25.11

Open the chart page →

544
kubeadaptkubeadaptVerified publisher1.0.41 of 1See more

kubeadapt kubeadapt 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-agent:v3.0.1d75b6da94913
stdlib@go1.26.2
1.25.11

Open the chart page →

214
cert-managerkubeblocksVerified publisher1.17.24 of 4See more

cert-manager kubeblocks 1.17.2

4 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.17.2ec56edb1161d
stdlib@go1.23.8
1.25.11
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
stdlib@go1.23.8
1.25.11
quay.io/jetstack/cert-manager-startupapicheck:v1.17.2e18989b4f912
stdlib@go1.23.8
1.25.11
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
stdlib@go1.23.8
1.25.11

Open the chart page →

2,900
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
stdlib@go1.20.6
1.25.11

Open the chart page →

20,403
ks-corekubeblocksVerified publisher1.1.32 of 5See more

ks-core kubeblocks 1.1.3

2 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
kubesphere/ks-extensions-museum:latest29681958f220
stdlib@go1.20.12
1.25.11
kubesphere/kubectl:v1.27.1649b445b1b732
stdlib@go1.18.10
1.25.11

Open the chart page →

4,721

Container images carrying it

4,636 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
stdlib@go1.18
1.25.11
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
stdlib@go1.25.6
1.25.11
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
stdlib@go1.16.10
1.25.11
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
stdlib@go1.25.5
1.25.11
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
stdlib@go1.14.15
1.25.11
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
stdlib@go1.19.13
1.25.11
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
stdlib@go1.20.4
1.25.11
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
stdlib@go1.25.0
1.25.11
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
stdlib@go1.25.0
1.25.11
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
stdlib@go1.25.5
1.25.11
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
stdlib@go1.20.7
1.25.11
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
stdlib@go1.25.5
1.25.11
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.25.11
3
quay.io/devtron/nats-box:latest48cdd3054b20
stdlib@go1.19.2
1.25.11
3
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.25.11
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.25.11
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
stdlib@go1.21.5
1.25.11
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
stdlib@go1.18.10
1.25.11
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
stdlib@go1.14.9
1.25.11
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.25.11
3
quay.io/metallb/controller:v0.13.101b33357b3595
stdlib@go1.19.5
1.25.11
3
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.25.11
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.25.11
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.25.11
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
stdlib@go1.15.8
1.25.11
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.25.11
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
stdlib@go1.16.7
1.25.11
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
stdlib@go1.25.9
1.25.11
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
stdlib@go1.22.3
1.25.11
3
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
stdlib@go1.25.8
1.25.11
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
stdlib@go1.16
1.25.11
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.25.11
3
quay.io/prometheus/prometheus:v2.55.0378f4e037035
stdlib@go1.23.2
1.25.11
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
stdlib@go1.16.2
1.25.11
3
quay.io/prometheus/prometheus:v3.10.07571a304e67f
stdlib@go1.26.0
1.25.11
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
stdlib@go1.17.3
1.25.11
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.11
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
stdlib@go1.23.1
1.25.11
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.25.11
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
stdlib@go1.15.15
1.25.11
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
stdlib@go1.16.8
1.25.11
3
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
stdlib@go1.26.3
1.25.11
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.11
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.25.11
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
stdlib@go1.22.2
1.25.11
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
stdlib@go1.24.1
1.25.11
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
stdlib@go1.22.5
1.25.11
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
stdlib@go1.24.6
1.25.11
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
stdlib@go1.26.2
1.25.11
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
stdlib@go1.20.3
1.25.11
3

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.