StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,056
of 17,803 indexed, latest versions
Container images
4,669
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,056 of 17,803 indexed charts deploy, on 4,669 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+183 more1.25.114,669
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,056 by stars
ChartLatestAffected imagesRadar Score
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.11

Open the chart page →

10,105
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
stdlib@go1.24.4
1.25.11

Open the chart page →

3,864
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.263 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

3 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
stdlib@go1.20.5
1.25.11
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
stdlib@go1.19.12
1.25.11
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.25.11

Open the chart page →

14,599
feedbacksystemthm-mni-iiVerified publisher0.47.16 of 10See more

feedbacksystem thm-mni-ii 0.47.1

6 of the 10 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
stdlib@go1.21.5
1.25.11
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
stdlib@go1.19.12
1.25.11
bitnamilegacy/mysql:8.0.35-debian-11-r2be03e8ea6129
stdlib@go1.21.5
1.25.11
library/docker:20.10.21-dind3153fa63f546
stdlib@go1.18.7
1.25.11
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
stdlib@go1.20.12
1.25.11
thmmniii/fbs-runner:v1.27.186105349c1a3
stdlib@go1.20.11
1.25.11

Open the chart page →

28,836
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
stdlib@go1.24.2
1.25.11

Open the chart page →

1,674
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
stdlib@go1.14.4
1.25.11

Open the chart page →

4,145
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
stdlib@go1.14.4
1.25.11
library/traefik:v2.57d5a6ae66572
stdlib@go1.17.6
1.25.11
traefik/mesh:v1.4.8cf071f3e165c
stdlib@go1.19
1.25.11

Open the chart page →

9,289
k8s-ttl-controllertwin0.4.01 of 1See more

k8s-ttl-controller twin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
stdlib@go1.24.1
1.25.11

Open the chart page →

471
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
stdlib@go1.19.6
1.25.11
quay.io/argoproj/argocd:v2.8.6acaf37352569
stdlib@go1.20.4
1.25.11

Open the chart page →

10,418
crossplaneupbound-stable2.4.1-up.11 of 5See more

crossplane upbound-stable 2.4.1-up.1

1 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.11

Open the chart page →

1,686
uptraceuptrace2.0.21 of 2See more

uptrace uptrace 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
uptrace/uptrace:2.0.234a02c3b2d12
stdlib@go1.24.10
1.25.11

Open the chart page →

1,749
vaultvaultVerified publisher1.22.04 of 4See more

vault vault 1.22.0

4 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
alpine/k8s:1.35.5d870622d0040
stdlib@go1.26.0
1.25.11
hashicorp/vault:2.0.1755355002715
stdlib@go1.26.3
1.25.11
prom/statsd-exporter:v0.29.0632f70580492
stdlib@go1.26.0
1.25.11
ghcr.io/bank-vaults/bank-vaults:v1.33.198b6ea2ed319
stdlib@go1.26.3
1.25.11

Open the chart page →

4,293
vouchvouchVerified publisher3.2.01 of 1See more

vouch vouch 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
stdlib@go1.18.10
1.25.11

Open the chart page →

1,035
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
stdlib@go1.20.7
1.25.11

Open the chart page →

1,358
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
stdlib@go1.18.5
1.25.11

Open the chart page →

2,246
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
stdlib@go1.25.8
1.25.11

Open the chart page →

1,000
wallarm-ingresswallarmVerified publisher5.3.10-12 of 2See more

wallarm-ingress wallarm 5.3.10-1

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
stdlib@go1.23.1
1.25.11
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.11

Open the chart page →

1,302
wallarm-sidecarwallarmOfficialVerified publisher6.13.11 of 3See more

wallarm-sidecar wallarm 6.13.1

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
stdlib@go1.22.2
1.25.11

Open the chart page →

966
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.25.11

Open the chart page →

3,503
argo-cdwenerme10.9.22 of 3See more

argo-cd wenerme 10.9.2

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
stdlib@go1.25.6
1.25.11
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
stdlib@go1.26.2
1.25.11

Open the chart page →

3,032
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
stdlib@go1.17.4
1.25.11

Open the chart page →

6,087
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:15.186eb0add3b77c
stdlib@go1.24.6
1.25.11

Open the chart page →

8,799
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
stdlib@go1.18.1
1.25.11
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
stdlib@go1.18.2
1.25.11
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
stdlib@go1.18.2
1.25.11
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
stdlib@go1.18.2
1.25.11

Open the chart page →

10,048
windmillwindmill4.0.2641 of 3See more

windmill windmill 4.0.264

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
stdlib@go1.24.6
1.25.11

Open the chart page →

1,686
buildkitdwiremindVerified publisher0.33.01 of 1See more

buildkitd wiremind 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
moby/buildkit:v0.32.2-rootless504731e577c2
stdlib@go1.25.7
1.25.11

Open the chart page →

1,164
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
stdlib@go1.13.8
1.25.11

Open the chart page →

4,715
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
stdlib@go1.18.4
1.25.11

Open the chart page →

4,050
yet-another-cloudwatch-exporteryet-another-cloudwatch-exporter0.38.01 of 1See more

yet-another-cloudwatch-exporter yet-another-cloudwatch-exporter 0.38.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
stdlib@go1.22.4
1.25.11

Open the chart page →

923
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
stdlib@go1.23.12
1.25.11

Open the chart page →

4,175
paperlesszekker6Verified publisher11.8.01 of 1See more

paperless zekker6 11.8.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.11

Open the chart page →

4,679
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
stdlib@go1.22.6
1.25.11

Open the chart page →

829
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
stdlib@go1.23.7
1.25.11

Open the chart page →

1,875
no-latest-tag-webhookadmission-webhook-no-latest1.0.141 of 1See more

no-latest-tag-webhook admission-webhook-no-latest 1.0.14

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/omkar-shelke25/admission-webhook-no-latest:sha-33165455976a1d3236a
stdlib@go1.26.3
1.25.11

Open the chart page →

162
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.11

Open the chart page →

20,339
agentareaagentareaVerified publisher0.0.187 of 16See more

agentarea agentarea 0.0.18

7 of the 16 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-manager:latestefe23cef3727
stdlib@go1.22.5
1.25.11
agentarea/agentarea-mcp-runner:latestd3c209a5d531
stdlib@go1.19.8
1.25.11
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.11
library/postgres:alpined3e1620b530c
stdlib@go1.24.6
1.25.11
oryd/kratos:v1.3.1fe2428f103a6
stdlib@go1.23.2
1.25.11
temporalio/auto-setup:1.29.15b3502a3b685
stdlib@go1.25.0
1.25.11
temporalio/ui:2.39.0b768f87f18b5
stdlib@go1.23.4
1.25.11

Open the chart page →

15,295
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.261 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.26

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
stdlib@go1.26.3
1.25.11

Open the chart page →

2,437
alertmanager-discordalertmanagerdiscordVerified publisher0.3.21 of 1See more

alertmanager-discord alertmanagerdiscord 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
speckle/alertmanager-discord:latestf6221ff308e9
stdlib@go1.22.4
1.25.11

Open the chart page →

420
alertmanager-matrixalertmanager-matrixVerified publisher0.1.161 of 1See more

alertmanager-matrix alertmanager-matrix 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
silkeh/alertmanager_matrix:0.6.1900010497f8c
stdlib@go1.26.3
1.25.11

Open the chart page →

471
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
stdlib@go1.24.4
1.25.11

Open the chart page →

12,161
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.25.11

Open the chart page →

67,934
clearml-servingallegroaiVerified publisher1.6.26 of 9See more

clearml-serving allegroai 1.6.2

6 of the 9 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
stdlib@go1.19.6
1.25.11
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
stdlib@go1.18.2
1.25.11
grafana/grafana:9.4.376dcf36e7d2a
stdlib@go1.19.4
1.25.11
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.11
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
stdlib@go1.19.4
1.25.11
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.25.11

Open the chart page →

17,923
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.25.11

Open the chart page →

5,000
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.25.11

Open the chart page →

8,401
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
stdlib@go1.18.5
1.25.11

Open the chart page →

3,120
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
stdlib@go1.18.10
1.25.11

Open the chart page →

2,173
cloudflare-operatorankra-chartsVerified publisher0.2.01 of 1See more

cloudflare-operator ankra-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
adyanth/cloudflare-operatordigest-pinned6b168dc237d5
stdlib@go1.24.4
1.25.11

Open the chart page →

507
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
stdlib@go1.24.4
1.25.11

Open the chart page →

6,027
upcloud-csiankra-chartsVerified publisher0.4.08 of 8See more

upcloud-csi ankra-charts 0.4.0

8 of the 8 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
stdlib@go1.23.12
1.25.11
ghcr.io/upcloudltd/upcloud-csidigest-pinned5af91c663788
stdlib@go1.24.13
1.25.11
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
stdlib@go1.17.3
1.25.11
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
stdlib@go1.17.3
1.25.11
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
stdlib@go1.17.3
1.25.11
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
stdlib@go1.17.3
1.25.11
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.11
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.11

Open the chart page →

15,002
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
stdlib@go1.19.3
1.25.11

Open the chart page →

1,150
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
stdlib@go1.22.5
1.25.11

Open the chart page →

3,429

Container images carrying it

4,669 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/desuuuu/cluster-network-policy-operator:v1.1.0d943d13c5281
stdlib@go1.26.0
1.25.11
1
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
stdlib@go1.25.8
1.25.11
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
stdlib@go1.20.14
1.25.11
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
stdlib@go1.25.4
1.25.11
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
stdlib@go1.26.1
1.25.11
1
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
stdlib@go1.17
1.25.11
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
stdlib@go1.16.6
1.25.11
1
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
stdlib@go1.24.3
1.25.11
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
stdlib@go1.19.2
1.25.11
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
stdlib@go1.25.0
1.25.11
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
stdlib@go1.23.4
1.25.11
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
stdlib@go1.19.6
1.25.11
1
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
stdlib@go1.25.7
1.25.11
1
ghcr.io/dirien/minecraft-exporter:0.24.061d89bf99ff7
stdlib@go1.25.10
1.25.11
1
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
stdlib@go1.23.7
1.25.11
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
stdlib@go1.17.5
1.25.11
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
stdlib@go1.21.0
1.25.11
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.25.11
1
ghcr.io/dntosas/capi2argo-cluster-operator:v1.5.0fb8c6457ef6e
stdlib@go1.25.6
1.25.11
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
stdlib@go1.17.9
1.25.11
1
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
stdlib@go1.18.1
1.25.11
1
ghcr.io/donkie/spoolman:0.24.042135965c42d
stdlib@go1.19.8
1.25.11
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
stdlib@go1.17.8
1.25.11
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
stdlib@go1.16.15
1.25.11
1
ghcr.io/doodlescheduling/saml-exporter:v0.5.03d5a99841bc2
stdlib@go1.22.3
1.25.11
1
ghcr.io/douban/aliyun-exporter:mainb7c694331362
stdlib@go1.24.2
1.25.11
1
ghcr.io/douban/qiniu-exporter:maind1da3bcfad7d
stdlib@go1.19.5
1.25.11
1
ghcr.io/douban/ucloud-exporter:mainb4bb8a9021a2
stdlib@go1.24.2
1.25.11
1
ghcr.io/douban/upyun-exporter:main6810900c9c4a
stdlib@go1.25.5
1.25.11
1
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
stdlib@go1.22.4
1.25.11
1
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
stdlib@go1.26.3
1.25.11
1
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
stdlib@go1.26.2
1.25.11
1
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
stdlib@go1.16.12
1.25.11
1
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
stdlib@go1.22.2
1.25.11
1
ghcr.io/edgelesssys/continuum/continuum-proxy24c76f294a80
stdlib@go1.23.3
1.25.11
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
stdlib@go1.16.7
1.25.11
1
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
stdlib@go1.26.1
1.25.11
1
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
stdlib@go1.21.6
1.25.11
1
ghcr.io/element-hq/ess-helm/matrix-tools:0.3.20eac0521be29
stdlib@go1.23.7
1.25.11
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
stdlib@go1.19.8
1.25.11
1
ghcr.io/eminaktas/oom-tracer:v0.1.0c90ca8389c87
stdlib@go1.25.1
1.25.11
1
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
stdlib@go1.24.13
1.25.11
1
ghcr.io/emqx/emqx-operator:2.3.23333ed546165
stdlib@go1.24.13
1.25.11
1
ghcr.io/eosc-lot-1/logrotate:3-alpineb0e20d200f89
stdlib@go1.22.4
1.25.11
1
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
stdlib@go1.20
1.25.11
1
ghcr.io/erpc/erpc:0.0.49f5654f745d4c
stdlib@go1.23.9
1.25.11
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
stdlib@go1.21.6
1.25.11
1
ghcr.io/ethpandaops/benchmarkoor:latest5470b2ec3161
stdlib@go1.24.13
1.25.11
1
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
stdlib@go1.24.13
1.25.11
1
ghcr.io/ethpandaops/syncoor:master233aa9808fc7
stdlib@go1.26.0
1.25.11
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.