StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,158
of 17,813 indexed, latest versions
Container images
4,758
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,158 of 17,813 indexed charts deploy, on 4,758 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+184 more1.25.114,758
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,158 by stars
ChartLatestAffected imagesRadar Score
kubeservice-ebpf-exporterkubservice-chartsVerified publisher1.2.11 of 1See more

kubeservice-ebpf-exporter kubservice-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/cloudflare/ebpf_exporter:v2.3.075370b2ec2bb
stdlib@go1.21.5
1.25.11

Open the chart page →

545
kubeservice-namespace-node-affinitykubservice-chartsVerified publisher1.1.25 of 5See more

kubeservice-namespace-node-affinity kubservice-charts 1.1.2

5 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
dongjiang1989/ns-node-affinity:latest451f7823723c
stdlib@go1.18.5
1.25.11
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
stdlib@go1.20.8
1.25.11
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
stdlib@go1.20.8
1.25.11
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
stdlib@go1.20.8
1.25.11
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
stdlib@go1.20.8
1.25.11

Open the chart page →

6,911
kubeservice-scheduler-pluskubservice-chartsVerified publisher0.2.11 of 2See more

kubeservice-scheduler-plus kubservice-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
stdlib@go1.19.9
1.25.11

Open the chart page →

1,804
ingress-annotatorkuossOfficialVerified publisher0.3.01 of 1See more

ingress-annotator kuoss 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/kuoss/ingress-annotator:v0.3.0ae179f65d869
stdlib@go1.24.6
1.25.11

Open the chart page →

494
kube-fencingkvaps2.4.12 of 2See more

kube-fencing kvaps 2.4.1

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
stdlib@go1.18.8
1.25.11
ghcr.io/kvaps/kube-fencing-switcher:v2.4.0f8c378e63b78
stdlib@go1.18.8
1.25.11

Open the chart page →

2,538
linstorkvaps1.14.04 of 11See more

linstor kvaps 1.14.0

4 of the 11 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
stdlib@go1.15.14
1.25.11
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
stdlib@go1.15.14
1.25.11
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
stdlib@go1.15.14
1.25.11
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
stdlib@go1.15.14
1.25.11

Open the chart page →

15,579
kymaroskymarosVerified publisher0.6.91 of 1See more

kymaros kymaros 0.6.9

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/kymaroshq/kymaros:0.6.9fb3b88633381
stdlib@go1.25.9
1.25.11

Open the chart page →

283
chibisafel4gVerified publisher0.1.12 of 3See more

chibisafe l4g 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
stdlib@go1.20.12
1.25.11
library/caddy:2-alpinede23def33b17
stdlib@go1.26.3
1.25.11

Open the chart page →

5,075
authz-pdplabs64io-helm-chartsVerified publisher0.8.01 of 1See more

authz-pdp labs64io-helm-charts 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/cerbos/cerbos:0.51.08d35a64e4a99
stdlib@go1.25.6
1.25.11

Open the chart page →

817
checkoutlabs64io-helm-chartsVerified publisher0.11.01 of 3See more

checkout labs64io-helm-charts 0.11.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
stdlib@go1.24.6
1.25.11

Open the chart page →

1,699
payment-gatewaylabs64io-helm-chartsVerified publisher0.10.01 of 2See more

payment-gateway labs64io-helm-charts 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
stdlib@go1.24.6
1.25.11

Open the chart page →

2,799
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
stdlib@go1.24.3
1.25.11

Open the chart page →

2,281
landelijketabellencataloguslandelijketabellencatalogus1.0.01 of 3See more

landelijketabellencatalogus landelijketabellencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
stdlib@go1.13.10
1.25.11

Open the chart page →

7,521
lgtmlgtmVerified publisher0.27.01 of 9See more

lgtm lgtm 0.27.0

1 of the 9 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:13.2.1-distroless3600073f45a9
stdlib@go1.26.3
1.25.11

Open the chart page →

1,123
lgtm-stacklgtm-stackVerified publisher0.1.31 of 8See more

lgtm-stack lgtm-stack 0.1.3

1 of the 8 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:13.1.0121a7a9ece6d
stdlib@go1.25.7
1.25.11

Open the chart page →

2,527
keptn-cert-managerlifecycle-toolkitVerified publisher0.3.01 of 1See more

keptn-cert-manager lifecycle-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
stdlib@go1.23.3
1.25.11

Open the chart page →

507
keptn-lifecycle-operatorlifecycle-toolkitVerified publisher0.6.01 of 1See more

keptn-lifecycle-operator lifecycle-toolkit 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
stdlib@go1.23.3
1.25.11

Open the chart page →

610
keptn-metrics-operatorlifecycle-toolkitVerified publisher0.5.01 of 1See more

keptn-metrics-operator lifecycle-toolkit 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
stdlib@go1.23.3
1.25.11

Open the chart page →

840
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
stdlib@go1.13.8
1.25.11

Open the chart page →

4,481
linkerd-jaegerlinkerd2-edgeVerified publisher30.14.11-edge2 of 4See more

linkerd-jaeger linkerd2-edge 30.14.11-edge

2 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
stdlib@go1.17.6
1.25.11
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
stdlib@go1.20.7
1.25.11

Open the chart page →

4,410
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
stdlib@go1.23.8
1.25.11

Open the chart page →

8,114
go-hello-worldloafoe0.14.01 of 1See more

go-hello-world loafoe 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/loafoe/go-hello-world:v2.13.0d3fb171f20e1
stdlib@go1.25.3
1.25.11

Open the chart page →

687
home-assistantloeken-at-homeVerified publisher2026.5.11 of 1See more

home-assistant loeken-at-home 2026.5.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
loeken/home-assistant:2026.5.14ce6abc553b3
stdlib@go1.23.3
1.25.11

Open the chart page →

3,076
jspolicyloftVerified publisher0.2.21 of 1See more

jspolicy loft 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
loftsh/jspolicy:0.2.225deb9bd2683
stdlib@go1.17.13
1.25.11

Open the chart page →

2,313
vcluster-eksloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-eks loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
stdlib@go1.16.15
1.25.11
public.ecr.aws/eks-distro/kubernetes/kube-apiserver:v1.24.9-eks-1-24-772e06b605692
stdlib@go1.18.9
1.25.11
public.ecr.aws/eks-distro/kubernetes/kube-controller-manager:v1.24.9-eks-1-24-7eaea8c230432
stdlib@go1.18.9
1.25.11

Open the chart page →

3,312
vcluster-k0sloftVerified publisher0.0.0-ci.31 of 2See more

vcluster-k0s loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
stdlib@go1.19.4
1.25.11

Open the chart page →

3,154
log2rbac-operatorlog2rbac-operator0.0.51 of 1See more

log2rbac-operator log2rbac-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
jkremser/log2rbac:v0.0.5e35cf56ef183
stdlib@go1.17.6
1.25.11

Open the chart page →

1,953
logclilogcliVerified publisher0.1.01 of 1See more

logcli logcli 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/logcli:main-c90366d-amd643d85bb66e39b
stdlib@go1.16.2
1.25.11

Open the chart page →

2,955
lumenvoxlumenvox7.1.010 of 11See more

lumenvox lumenvox 7.1.0

10 of the 11 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
lumenvox/admin-portal:7.112310cf52f79
stdlib@go1.26.2
1.25.11
lumenvox/archive:7.15114f08ab8ef
stdlib@go1.26.2
1.25.11
lumenvox/cloud-init-tools:7.1de940e2ec601
stdlib@go1.26.2
1.25.11
lumenvox/configuration:7.182bf01d9ebec
stdlib@go1.26.2
1.25.11
lumenvox/deployment:7.1dadac2a74be6
stdlib@go1.26.2
1.25.11
lumenvox/file-store:7.138aa8711c9ef
stdlib@go1.26.2
1.25.11
lumenvox/license:7.135d0b1ac053e
stdlib@go1.26.2
1.25.11
lumenvox/management-api:7.16420a6e7d6c2
stdlib@go1.26.2
1.25.11
lumenvox/resource:7.193fd6ff1d62c
stdlib@go1.26.2
1.25.11
lumenvox/storage:7.1c961fe78e2ca
stdlib@go1.26.2
1.25.11

Open the chart page →

5,156
voice-biometricslumenvox2.0.18 of 26See more

voice-biometrics lumenvox 2.0.1

8 of the 26 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.11
library/traefik:v2.57d5a6ae66572
stdlib@go1.17.6
1.25.11
lumenvox/cloud-init-tools:2.0.07ff037a71c50
stdlib@go1.17.3
1.25.11
lumenvox/cloud-license:2.0.09a69862e1248
stdlib@go1.17.3
1.25.11
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.11
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.25.11
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
stdlib@go1.15.8
1.25.11
quay.io/prometheus/prometheus:v2.26.038d40a760569
stdlib@go1.16.2
1.25.11

Open the chart page →

71,528
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/luzilla/dnsbl_exporter:v0.12.0ecba7360ff12
stdlib@go1.25.0
1.25.11

Open the chart page →

1,422
lynqlynqVerified publisher1.1.221 of 1See more

lynq lynq 1.1.22

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/k8s-lynq/lynq:1.1.22229b05e3c717
stdlib@go1.24.13
1.25.11

Open the chart page →

635
magentomagento3.2.35 of 12See more

magento magento 3.2.3

5 of the 12 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
stdlib@go1.18.2
1.25.11
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.25.11
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
stdlib@go1.24.6
1.25.11
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
stdlib@go1.24.6
1.25.11
longhornio/longhorn-ui:v1.10.0e60f36161511
stdlib@go1.24.6
1.25.11

Open the chart page →

13,758
mcp-orchestratormagertronVerified publisher3.8.631 of 7See more

mcp-orchestrator magertron 3.8.63

1 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:17-alpinef02121de6f74
stdlib@go1.24.6
1.25.11

Open the chart page →

1,558
goblackholemainVerified publisher0.0.41 of 1See more

goblackhole main 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
bedag/goblackhole:0.2.0447a88598f4c
stdlib@go1.16.6
1.25.11

Open the chart page →

1,980
plane-enterprisemakeplaneOfficialVerified publisher3.7.43 of 13See more

plane-enterprise makeplane 3.7.4

3 of the 13 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.25.11
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
stdlib@go1.24.6
1.25.11
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
stdlib@go1.24.6
1.25.11

Open the chart page →

5,200
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:885b9bf2e29cf
stdlib@go1.24.6
1.25.11

Open the chart page →

19,235
mcpmcp-chartsVerified publisher0.0.232 of 7See more

mcp mcp-charts 0.0.23

2 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
stdlib@go1.25.4
1.25.11
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
stdlib@go1.25.4
1.25.11

Open the chart page →

7,173
traefik-forward-authmesosphere0.3.102 of 2See more

traefik-forward-auth mesosphere 0.3.10

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
stdlib@go1.15.11
1.25.11
mesosphere/traefik-forward-auth:3.1.05456581d7b76
stdlib@go1.14.15
1.25.11

Open the chart page →

5,310
metadata-injectormetadata-injector-operator0.0.11 of 1See more

metadata-injector metadata-injector-operator 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ruslanguns/metadata-injector-operator:v0.0.16c77e4675e07
stdlib@go1.22.11
1.25.11

Open the chart page →

575
metrics-server-exportermetrics-server-exporterVerified publisher2.4.01 of 1See more

metrics-server-exporter metrics-server-exporter 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
mrnim94/metrics-server-exporter:v2.4.086c4807a4bca
stdlib@go1.26.3
1.25.11

Open the chart page →

1,267
subspacemglants0.1.01 of 1See more

subspace mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
subspacecommunity/subspace:1.5.0e2042b63fb35
stdlib@go1.14.6
1.25.11

Open the chart page →

3,256
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
stdlib@go1.23.4
1.25.11

Open the chart page →

4,255
librenmsmidokura-communityVerified publisher0.3.21 of 6See more

librenms midokura-community 0.3.2

1 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
librenms/librenms:22.4.14f1f3d667cc7
stdlib@go1.16.12
1.25.11

Open the chart page →

8,976
chartmuseummike75151.2.01 of 1See more

chartmuseum mike7515 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
stdlib@go1.17.8
1.25.11

Open the chart page →

3,177
mimir-syncmimir-sync3.1.01 of 1See more

mimir-sync mimir-sync 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/antnsn/mal-sync:v1.0.52f06e72cef36
stdlib@go1.23.7
1.25.11

Open the chart page →

1,303
minecraft-exporterminecraft-exporterVerified publisher0.16.01 of 1See more

minecraft-exporter minecraft-exporter 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/dirien/minecraft-exporter:0.24.061d89bf99ff7
stdlib@go1.25.10
1.25.11

Open the chart page →

362
miniapiminiapi1.3.21 of 1See more

miniapi miniapi 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
udhos/miniapi:1.3.28a7042db82ce
stdlib@go1.23.2
1.25.11

Open the chart page →

855
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
stdlib@go1.25.5
1.25.11

Open the chart page →

5,839
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
stdlib@go1.25.4
1.25.11

Open the chart page →

35,191

Container images carrying it

4,758 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
stdlib@go1.22.3
1.25.11
1
quay.io/prometheus-operator/prometheus-operator:v0.85.0890b3bb05cf4
stdlib@go1.24.6
1.25.11
1
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
stdlib@go1.17.10
1.25.11
1
quay.io/prometheus-operator/prometheus-operator:v0.75.1a7cc63108511
stdlib@go1.22.4
1.25.11
1
quay.io/prometheus-operator/prometheus-operator:v0.88.0b4f51de53357
stdlib@go1.25.5
1.25.11
1
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
stdlib@go1.17.6
1.25.11
1
quay.io/prometheus-operator/prometheus-operator:v0.61.1cd7d1a82ef00
stdlib@go1.19.3
1.25.11
1
quay.io/prometheus/prometheus:v3.0.03b9b2a15d376
stdlib@go1.23.3
1.25.11
1
quay.io/prometheus/prometheus:v2.39.14748e26f9369
stdlib@go1.19.2
1.25.11
1
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
stdlib@go1.18.4
1.25.11
1
quay.io/prometheus/prometheus:v3.2.05888c188cf09
stdlib@go1.23.6
1.25.11
1
quay.io/prometheus/prometheus:v3.5.063805ebb8d2b
stdlib@go1.24.5
1.25.11
1
quay.io/prometheus/prometheus:v3.2.16927e0919a14
stdlib@go1.23.6
1.25.11
1
quay.io/prometheus/prometheus:v2.33.591100b06e86d
stdlib@go1.17.8
1.25.11
1
quay.io/prometheus/prometheus:v3.4.19abc6cf6aea7
stdlib@go1.24.3
1.25.11
1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
stdlib@go1.17.8
1.25.11
1
quay.io/prometheus/prometheus:v3.11.3c0b857aead0d
stdlib@go1.26.2
1.25.11
1
quay.io/prometheus/prometheus:v3.11.2cd37346c9745
stdlib@go1.26.2
1.25.11
1
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
stdlib@go1.22.5
1.25.11
1
quay.io/prometheus/pushgateway:v1.11.103738d278e08
stdlib@go1.24.1
1.25.11
1
quay.io/prometheus/pushgateway:v1.6.05111de00e969
stdlib@go1.20.4
1.25.11
1
quay.io/prometheus/statsd-exporter:v0.30.0378cb79c4ac7
stdlib@go1.26.3
1.25.11
1
quay.io/prometheus/statsd-exporter:v0.27.29ed70604d941
stdlib@go1.22.8
1.25.11
1
quay.io/prometheus/statsd-exporter:v0.22.8f53cca722a03
stdlib@go1.18.6
1.25.11
1
quay.io/rabbitmqoperator/messaging-topology-operator:1.18.1f97c36882244
stdlib@go1.24.6
1.25.11
1
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
stdlib@go1.25.5
1.25.11
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
stdlib@go1.20.8
1.25.11
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
stdlib@go1.19.13
1.25.11
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
stdlib@go1.21.9
1.25.11
1
quay.io/redhat-developer/servicebinding-operator16286ac84ddd
stdlib@go1.20.6
1.25.11
1
quay.io/reiml/smtp-gotify:latest80ffa9d2044a
stdlib@go1.23.9
1.25.11
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
stdlib@go1.16
1.25.11
1
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
stdlib@go1.16.7
1.25.11
1
quay.io/sergeyshevch/s3manager:feature_refactoringff59fcdf44eb
stdlib@go1.18
1.25.11
1
quay.io/skopeo/stable:v1.134853591bd1d2
stdlib@go1.21.0
1.25.11
1
quay.io/solo-io/certgen:0.0.0-forkb17a8c7d1f32
stdlib@go1.18.1
1.25.11
1
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
stdlib@go1.18.1
1.25.11
1
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
stdlib@go1.18.1
1.25.11
1
quay.io/solo-io/gloo-envoy-wrapper:0.0.0-fork26ae185e835a
stdlib@go1.18.1
1.25.11
1
quay.io/spotahome/redis-operator:latest8c772955184e
stdlib@go1.20.7
1.25.11
1
quay.io/superq/draytek-exporter:v0.2.03b577bdceaae
stdlib@go1.25.4
1.25.11
1
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
stdlib@go1.20.5
1.25.11
1
quay.io/thanos/thanos:v0.40.1aae7b2b030ed
stdlib@go1.25.3
1.25.11
1
quay.io/thanos/thanos:v0.17.1e362f02ed304
stdlib@go1.15
1.25.11
1
quay.io/thanos/thanos:v0.36.1e542959e1b36
stdlib@go1.21.13
1.25.11
1
quay.io/tigera/operator:v1.20.1379efe0c2541
stdlib@go1.15.2
1.25.11
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
stdlib@go1.15.2
1.25.11
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
stdlib@go1.13.15
1.25.11
1
quay.io/uswitch/kiam:v4.0be3a5846922d
stdlib@go1.13.8
1.25.11
1
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
stdlib@go1.18.10
1.25.11
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.