StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,140
of 17,821 indexed, latest versions
Container images
4,738
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,140 of 17,821 indexed charts deploy, on 4,738 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+184 more1.25.114,738
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,140 by stars
ChartLatestAffected imagesRadar Score
offline-license-serverappscodeVerified publisher2026.9.111 of 2See more

offline-license-server appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
stdlib@go1.25.5
1.25.11

Open the chart page →

1,695
opentelemetry-kube-stackappscodeVerified publisher0.14.123 of 3See more

opentelemetry-kube-stack appscode 0.14.12

3 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
stdlib@go1.24.6
1.25.11
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.144.079b81912f1fb
stdlib@go1.25.6
1.25.11
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
stdlib@go1.25.1
1.25.11

Open the chart page →

1,911
panopticonappscodeVerified publisher2026.9.181 of 2See more

panopticon appscode 2026.9.18

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.11

Open the chart page →

422
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
stdlib@go1.25.3
1.25.11
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
stdlib@go1.25.4
1.25.11

Open the chart page →

38,114
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
stdlib@go1.25.4
1.25.11

Open the chart page →

778
prom-label-proxyappscodeVerified publisher2026.7.151 of 1See more

prom-label-proxy appscode 2026.7.15

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/prom-label-proxy:v2026.4.2461344c13f17d
stdlib@go1.25.10
1.25.11

Open the chart page →

179
regcacheappscodeVerified publisher2026.9.111 of 1See more

regcache appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
stdlib@go1.25.9
1.25.11

Open the chart page →

658
secrets-store-csi-driver-provider-virtual-secretsappscodeVerified publisher2026.8.141 of 1See more

secrets-store-csi-driver-provider-virtual-secrets appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/secrets-store-csi-driver-provider-virtual-secrets:v0.2.07afb394f9f97
stdlib@go1.24.1
1.25.11

Open the chart page →

554
service-backendappscodeVerified publisher2026.9.111 of 1See more

service-backend appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
stdlib@go1.25.5
1.25.11

Open the chart page →

1,346
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109fa56a9251de6
stdlib@go1.19
1.25.11

Open the chart page →

2,203
service-presetsappscodeVerified publisher2024.2.111 of 1See more

service-presets appscode 2024.2.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.25.11

Open the chart page →

824
service-providerappscodeVerified publisher2026.9.112 of 2See more

service-provider appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
stdlib@go1.23.3
1.25.11
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
stdlib@go1.25.5
1.25.11

Open the chart page →

2,255
stash-communityappscodeVerified publisher0.42.04 of 4See more

stash-community appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.25.11
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
stdlib@go1.24.9
1.25.11
ghcr.io/stashed/stash:v0.42.03a98245a7667
stdlib@go1.25.3
1.25.11
ghcr.io/stashed/stash-crd-installer:v0.42.076f0a650e44b
stdlib@go1.25.3
1.25.11

Open the chart page →

3,679
stash-opscenterappscodeVerified publisher2025.10.171 of 1See more

stash-opscenter appscode 2025.10.17

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.11

Open the chart page →

686
stash-ui-serverappscodeVerified publisher0.23.01 of 1See more

stash-ui-server appscode 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.11

Open the chart page →

686
statefulsetappscodeVerified publisher0.0.12 of 3See more

statefulset appscode 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
stdlib@go1.15.14
1.25.11
ghcr.io/appscode/kubectl-nonroot:v1.248ee5bdd68977
stdlib@go1.20.7
1.25.11

Open the chart page →

2,740
taskqueueappscodeVerified publisher2026.2.161 of 1See more

taskqueue appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
stdlib@go1.25.5
1.25.11

Open the chart page →

1,092
thanos-operatorappscodeVerified publisher2026.6.21 of 1See more

thanos-operator appscode 2026.6.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/thanos-operator:v2026.4.24e05a3e701291
stdlib@go1.26.2
1.25.11

Open the chart page →

385
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
stdlib@go1.25.5
1.25.11

Open the chart page →

1,228
voyagerappscodeVerified publisher2026.3.231 of 1See more

voyager appscode 2026.3.23

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/voyager:v17.5.04964ceaf9d35
stdlib@go1.25.8
1.25.11

Open the chart page →

728
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
stdlib@go1.21.1
1.25.11

Open the chart page →

5,720
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
stdlib@go1.22.2
1.25.11

Open the chart page →

1,205
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.11

Open the chart page →

8,937
appwriteappwrite-helmVerified publisher1.3.24 of 8See more

appwrite appwrite-helm 1.3.2

4 of the 8 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
stdlib@go1.25.7
1.25.11
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.25.11
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.25.11
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.25.11

Open the chart page →

9,859
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
stdlib@go1.16.4
1.25.11

Open the chart page →

5,213
arcadearcadeVerified publisher1.10.11 of 10See more

arcade arcade 1.10.1

1 of the 10 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.11

Open the chart page →

991
argocd-bitbucket-proxyargocd-bitbucket-proxy1.1.11 of 1See more

argocd-bitbucket-proxy argocd-bitbucket-proxy 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/salemgolemugoo/argocd-bitbucket-proxy:latesta72df069095b
stdlib@go1.26.1
1.25.11

Open the chart page →

189
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
stdlib@go1.23.4
1.25.11
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.11
quay.io/argoproj/argocd:v2.14.115fc69e31c755
stdlib@go1.22.2
1.25.11

Open the chart page →

7,710
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
stdlib@go1.24.6
1.25.11
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
stdlib@go1.24.6
1.25.11

Open the chart page →

1,845
argonix-apiargonix0.3.62 of 4See more

argonix-api argonix 0.3.6

2 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0951622ae173b
stdlib@go1.22.7
1.25.11
ghcr.io/argonix-io/argonix-api-frontend:1.0.0593c1b0f73cb
stdlib@go1.23.12
1.25.11

Open the chart page →

4,890
argo-zombiesargo-zombies0.1.521 of 1See more

argo-zombies argo-zombies 0.1.52

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
stdlib@go1.26.1
1.25.11

Open the chart page →

254
arlas-aiasarlas-stackVerified publisher28.9.06 of 22See more

arlas-aias arlas-stack 28.9.0

6 of the 22 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
stdlib@go1.23.9
1.25.11
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.25.11
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
stdlib@go1.22.11
1.25.11
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
stdlib@go1.24.2
1.25.11
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
stdlib@go1.23.8
1.25.11
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.25.11

Open the chart page →

39,921
arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
stdlib@go1.19.3
1.25.11
stakater/reloader:v1.0.15f4b87a8e56d4
stdlib@go1.20.1
1.25.11
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
stdlib@go1.18.10
1.25.11
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
stdlib@go1.19.5
1.25.11
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
stdlib@go1.19.4
1.25.11
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.25.11
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
stdlib@go1.19.4
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
stdlib@go1.19.4
1.25.11

Open the chart page →

23,478
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
stdlib@go1.19.2
1.25.11

Open the chart page →

1,780
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
stdlib@go1.17.11
1.25.11
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
stdlib@go1.17.10
1.25.11
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
stdlib@go1.17.3
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
stdlib@go1.18.3
1.25.11

Open the chart page →

8,634
assemblylineassemblylineVerified publisher7.4.202 of 12See more

assemblyline assemblyline 7.4.20

2 of the 12 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
stdlib@go1.21.5
1.25.11
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
stdlib@go1.21.5
1.25.11

Open the chart page →

12,896
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.25.11

Open the chart page →

5,538
dltkvassist-iot-data-integrity-verification0.2.04 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
stdlib@go1.17.13
1.25.11
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.25.11
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.25.11
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.25.11

Open the chart page →

194,560
dltflassist-iot-dlt-based-fl0.2.04 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
stdlib@go1.17.13
1.25.11
hyperledger/fabric-orderer:2.46ec3fe59ea55
stdlib@go1.18.10
1.25.11
hyperledger/fabric-peer:2.46ff36af21eb1
stdlib@go1.18.10
1.25.11
hyperledger/fabric-tools:2.4b1194f509085
stdlib@go1.18.10
1.25.11

Open the chart page →

194,560
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
stdlib@go1.17.10
1.25.11

Open the chart page →

3,806
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.25.11

Open the chart page →

9,452
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
stdlib@go1.17.10
1.25.11

Open the chart page →

4,388
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.25.11

Open the chart page →

13,434
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.25.11

Open the chart page →

10,190
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
stdlib@go1.18.6
1.25.11
kong/kubernetes-ingress-controller:2.35e66021b64a8
stdlib@go1.18
1.25.11

Open the chart page →

88,283
performanceandusagediagnosisassist-iot-pud1.0.05 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

5 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
stdlib@go1.17.12
1.25.11
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.11
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.25.11
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
stdlib@go1.18.3
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
stdlib@go1.18.5
1.25.11

Open the chart page →

8,594
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.11

Open the chart page →

8,079
semantic-repositoryassist-iot-semantic-repository1.1.01 of 3See more

semantic-repository assist-iot-semantic-repository 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
stdlib@go1.24.6
1.25.11

Open the chart page →

1,201
smartorchestratorassist-iot-smart-orchestrator4.0.04 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

4 of the 14 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.22.1
1.25.11
devopsfaith/krakend:latestf8bdaa8a1a43
stdlib@go1.24.2
1.25.11
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.11
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.11

Open the chart page →

46,145
astrotrekastria0.0.24 of 4See more

astrotrek astria 0.0.2

4 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.25.11
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
stdlib@go1.23.1
1.25.11
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
stdlib@go1.23.1
1.25.11
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.25.11

Open the chart page →

32,866

Container images carrying it

4,738 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
stdlib@go1.16.4
1.25.11
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
stdlib@go1.18.1
1.25.11
1
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.25.11
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.25.11
1
registry.gitlab.com/bitspur/rock8s/easy-olm-operator:0.0.1779454fea06c
stdlib@go1.19.10
1.25.11
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
stdlib@go1.20.8
1.25.11
1
registry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.063cf51392ce7
stdlib@go1.19.13
1.25.11
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.25.11
1
registry.gitlab.com/dyff/dyff-operator:0.24.20e9ca51627601
stdlib@go1.24.13
1.25.11
1
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
stdlib@go1.20.14
1.25.11
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
stdlib@go1.25.7
1.25.11
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
stdlib@go1.25.7
1.25.11
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.25.11
1
registry.gitlab.com/gitlab-org/build/cng/cfssl-self-sign:v19.4.07757679afa1b
stdlib@go1.22.0
1.25.11
1
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
stdlib@go1.25.0
1.25.11
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
stdlib@go1.16.14
1.25.11
1
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.25448611a3c54
stdlib@go1.26.3
1.25.11
1
registry.gitlab.com/lenitech/docker/keycloak-ppolicy:0.6.09895d6915075
stdlib@go1.25.7
1.25.11
1
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
stdlib@go1.24.5
1.25.11
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
stdlib@go1.21.0
1.25.11
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
stdlib@go1.15.15
1.25.11
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
stdlib@go1.25.7
1.25.11
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
stdlib@go1.25.7
1.25.11
1
registry.gitlab.com/xrow-public/ci-tools/kubectl:main9357cfeef63c
stdlib@go1.24.9
1.25.11
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
stdlib@go1.24.13
1.25.11
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
stdlib@go1.24.5
1.25.11
1
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.25.11
1
registry.k8s.io/agent-sandbox/sandbox-router-go:v1.0.125b1a0939630
stdlib@go1.26.2
1.25.11
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
stdlib@go1.24.4
1.25.11
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
stdlib@go1.24.7
1.25.11
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.4.171d817780aa9
stdlib@go1.24.3
1.25.11
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
stdlib@go1.25.7
1.25.11
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
stdlib@go1.24.6
1.25.11
1
registry.k8s.io/autoscaling/vpa-recommender:1.4.140b6d76e8526
stdlib@go1.24.3
1.25.11
1
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
stdlib@go1.24.6
1.25.11
1
registry.k8s.io/autoscaling/vpa-updater:1.4.18ebf269779c1
stdlib@go1.24.3
1.25.11
1
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
stdlib@go1.25.7
1.25.11
1
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
stdlib@go1.24.6
1.25.11
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
stdlib@go1.20.7
1.25.11
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
stdlib@go1.23.0
1.25.11
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
stdlib@go1.25.5
1.25.11
1
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
stdlib@go1.24.4
1.25.11
1
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
stdlib@go1.22.12
1.25.11
1
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
stdlib@go1.22.12
1.25.11
1
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
stdlib@go1.24.4
1.25.11
1
registry.k8s.io/descheduler/descheduler:v0.36.07ca92c0a7b4f
stdlib@go1.26.0
1.25.11
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
stdlib@go1.21.7
1.25.11
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
stdlib@go1.24.8
1.25.11
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
stdlib@go1.22.3
1.25.11
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
stdlib@go1.18.3
1.25.11
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.