StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,204
of 17,828 indexed, latest versions
Container images
4,808
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,204 of 17,828 indexed charts deploy, on 4,808 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+185 more1.25.114,808
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,204 by stars
ChartLatestAffected imagesRadar Score
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
stdlib@go1.20.5
1.25.11

Open the chart page →

2,482
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
stdlib@go1.17.13
1.25.11

Open the chart page →

3,702
zookeeper-exporterzookeeper-exporter0.1.01 of 1See more

zookeeper-exporter zookeeper-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
dabealu/zookeeper-exporter:latest86106fec315f
stdlib@go1.14.15
1.25.11

Open the chart page →

1,249
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
stdlib@go1.24.6
1.25.11

Open the chart page →

8,105

Container images carrying it

4,808 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
stdlib@go1.18.4
1.25.11
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
stdlib@go1.16.8
1.25.11
1
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.25.11
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
stdlib@go1.15
1.25.11
1
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
stdlib@go1.16.4
1.25.11
1
ghcr.io/k8s-at-home/gateway-admision-controller:v3.5.0175512bb3f61
stdlib@go1.18.3
1.25.11
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
stdlib@go1.15
1.25.11
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
stdlib@go1.18.3
1.25.11
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
stdlib@go1.16.7
1.25.11
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.25.11
1
ghcr.io/k8s-at-home/nullserv:v1.3.00792c7e6d814
stdlib@go1.16.5
1.25.11
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
stdlib@go1.18.4
1.25.11
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
stdlib@go1.15
1.25.11
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
stdlib@go1.18.4
1.25.11
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.25.11
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.25.11
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
stdlib@go1.18.4
1.25.11
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.25.11
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.25.11
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.25.11
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.25.11
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
stdlib@go1.18.4
1.25.11
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.25.11
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.25.11
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.25.11
1
ghcr.io/k8s-lynq/lynq:1.1.22229b05e3c717
stdlib@go1.24.13
1.25.11
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.4-thick3c20900b5381
stdlib@go1.24.13
1.25.11
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.16bebbda31416
stdlib@go1.23.9
1.25.11
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.39751856cacc8
stdlib@go1.21.13
1.25.11
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
stdlib@go1.13.10
1.25.11
1
ghcr.io/k8snetworkplumbingwg/multus-dynamic-networks-controller:v0.3.72a2bb32c0ea8
stdlib@go1.22.12
1.25.11
1
ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.4f279fd7dc112
stdlib@go1.25.6
1.25.11
1
ghcr.io/k8up-io/k8up:v2.16.029458113b8b6
stdlib@go1.26.3
1.25.11
1
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
stdlib@go1.18
1.25.11
1
ghcr.io/kagent-dev/kagent/tools:0.2.150b431281d3e
stdlib@go1.25.8
1.25.11
1
ghcr.io/kagent-dev/kagent/tools:0.0.13c8882543f693
stdlib@go1.24.9
1.25.11
1
ghcr.io/kagent-dev/kmcp/controller:0.2.283276357d448
stdlib@go1.24.11
1.25.11
1
ghcr.io/kagent-dev/kmcp/controller:0.3.086ab878da25a
stdlib@go1.24.13
1.25.11
1
ghcr.io/kalgurn/grl-exporter:v3.2.0bd109b2bda38
stdlib@go1.23.5
1.25.11
1
ghcr.io/kamu-data/kamu-api-server:0.90.0e61435d44913
stdlib@go1.15.2
1.25.11
1
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
stdlib@go1.25.6
1.25.11
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
stdlib@go1.23.10
1.25.11
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
stdlib@go1.20.7
1.25.11
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
stdlib@go1.23.10
1.25.11
1
ghcr.io/kedacore/keda:2.16.002348a19aeae
stdlib@go1.23.3
1.25.11
1
ghcr.io/kedacore/keda:2.17.0112fc427d933
stdlib@go1.23.8
1.25.11
1
ghcr.io/kedacore/keda:2.17.272dc058e478d
stdlib@go1.23.8
1.25.11
1
ghcr.io/kedacore/keda:2.20.2fe74c7b88495
stdlib@go1.26.2
1.25.11
1
ghcr.io/kedacore/keda-admission-webhooks:2.20.241f74102aba7
stdlib@go1.26.2
1.25.11
1
ghcr.io/kedacore/keda-admission-webhooks:2.17.0a87c42275757
stdlib@go1.23.8
1.25.11
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.