StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,166
of 17,821 indexed, latest versions
Container images
4,772
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,166 of 17,821 indexed charts deploy, on 4,772 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+185 more1.25.114,772
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,166 by stars
ChartLatestAffected imagesRadar Score
keeper-injectorkeeper-securityVerified publisher0.11.31 of 2See more

keeper-injector keeper-security 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.11

Open the chart page →

505
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
stdlib@go1.20.7
1.25.11

Open the chart page →

5,295
kestra-starterkestraOfficialVerified publisher2.0.22 of 5See more

kestra-starter kestra 2.0.2

2 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.25.11
versity/versitygw:v1.1.0f730e0dbc1ef
stdlib@go1.25.5
1.25.11

Open the chart page →

5,552
keycloak-operator-legacykeycloak-operator-legacy1.0.01 of 1See more

keycloak-operator-legacy keycloak-operator-legacy 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
stdlib@go1.13.8
1.25.11

Open the chart page →

5,071
csi-driver-nfskeyporttech0.1.41 of 2See more

csi-driver-nfs keyporttech 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
stdlib@go1.14.2
1.25.11

Open the chart page →

3,365
gogskeyporttech0.1.31 of 3See more

gogs keyporttech 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
gogs/gogs:0.12.30195b095d0b2
stdlib@go1.14.7
1.25.11

Open the chart page →

3,525
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
stdlib@go1.13.15
1.25.11

Open the chart page →

8,842
connectkfirfer1.15.02 of 2See more

connect kfirfer 1.15.0

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
1password/connect-api:1.7.26aa94cf713f9
stdlib@go1.20.6
1.25.11
1password/connect-sync:1.7.2fe527ed9d81f
stdlib@go1.20.6
1.25.11

Open the chart page →

2,787
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
stdlib@go1.13.11
1.25.11

Open the chart page →

2,793
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
stdlib@go1.17.1
1.25.11

Open the chart page →

6,519
keelkfirfer1.0.51 of 1See more

keel kfirfer 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
keelhq/keel:0.19.202ac4ea616c4
stdlib@go1.20.5
1.25.11

Open the chart page →

2,083
kubernetes-replicatorkfirfer2.9.11 of 1See more

kubernetes-replicator kfirfer 2.9.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.9.1baf5f784398b
stdlib@go1.20.5
1.25.11

Open the chart page →

864
mysqldumpkfirfer2.8.01 of 1See more

mysqldump kfirfer 2.8.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
stdlib@go1.21.5
1.25.11

Open the chart page →

3,525
pod-cleanupkfirfer0.0.41 of 1See more

pod-cleanup kfirfer 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
stdlib@go1.25.0
1.25.11

Open the chart page →

743
prometheus-elasticsearch-exporterkfirfer6.5.11 of 1See more

prometheus-elasticsearch-exporter kfirfer 6.5.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.8.0073dd360de2c
stdlib@go1.22.7
1.25.11

Open the chart page →

779
scriptskfirfer0.1.361 of 1See more

scripts kfirfer 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
kfirfer/scripts:0.0.2481e5c4e5d70e
stdlib@go1.17.10
1.25.11

Open the chart page →

2,321
kiaekiae0.1.66 of 9See more

kiae kiae 0.1.6

6 of the 9 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.25.11
grafana/promtail:2.6.1072527b12cdf
stdlib@go1.17.9
1.25.11
istio/pilot:1.15.2db08d6963975
stdlib@go1.19.2
1.25.11
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
stdlib@go1.19.2
1.25.11
ghcr.io/dexidp/dex:v2.35.313964b29d63e
stdlib@go1.19.2
1.25.11
ghcr.io/kiaedev/kiae:latestebd03028ff6a
stdlib@go1.18.9
1.25.11

Open the chart page →

19,289
kimai-helmchartkimai2tet0.1.01 of 2See more

kimai-helmchart kimai2tet 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.11

Open the chart page →

1,519
local-path-provisionerkir4hVerified publisher0.0.351 of 1See more

local-path-provisioner kir4h 0.0.35

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.3534ff0847cc47
stdlib@go1.26.1
1.25.11

Open the chart page →

754
process-exporterkir4hVerified publisher1.0.11 of 1See more

process-exporter kir4h 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ncabatoff/process-exporterdigest-pinned6f0549dc24e9
stdlib@go1.23.1
1.25.11

Open the chart page →

742
typebotiokitsune-itopsVerified publisher0.1.41 of 4See more

typebotio kitsune-itops 0.1.4

1 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.11

Open the chart page →

639
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
stdlib@go1.22.10
1.25.11

Open the chart page →

12,204
rabbitmq-cluster-operatorklicktippVerified publisher0.4.22 of 3See more

rabbitmq-cluster-operator klicktipp 0.4.2

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/rabbitmq/cluster-operator:2.20.1a96853470256
stdlib@go1.25.9
1.25.11
ghcr.io/rabbitmq/messaging-topology-operator:1.19.124c4649ef3ef
stdlib@go1.25.9
1.25.11

Open the chart page →

826
rabbitmq-topology-operatorklicktippVerified publisher0.4.11 of 2See more

rabbitmq-topology-operator klicktipp 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/rabbitmq/messaging-topology-operator:1.19.124c4649ef3ef
stdlib@go1.25.9
1.25.11

Open the chart page →

557
kloudlite-platformkloudlite1.1.51 of 3See more

kloudlite-platform kloudlite 1.1.5

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
stdlib@go1.21.3
1.25.11

Open the chart page →

1,971
klumklumVerified publisher1.17.11 of 1See more

klum klum 1.17.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/jadolg/klum:v0.8.17c66cc93f9d03
stdlib@go1.26.3
1.25.11

Open the chart page →

357
klustre-csi-pluginklustre-csi-plugin0.1.11 of 2See more

klustre-csi-plugin klustre-csi-plugin 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
stdlib@go1.21.5
1.25.11

Open the chart page →

1,474
knative-servingknative-servingVerified publisher1.18.37 of 7See more

knative-serving knative-serving 1.18.3

7 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
stdlib@go1.24.6
1.25.11
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
stdlib@go1.24.6
1.25.11
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
stdlib@go1.24.3
1.25.11
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
stdlib@go1.24.3
1.25.11
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
stdlib@go1.24.3
1.25.11
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
stdlib@go1.24.3
1.25.11
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
stdlib@go1.24.3
1.25.11

Open the chart page →

3,777
kollektorkollektorVerified publisher1.0.51 of 1See more

kollektor kollektor 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
pannoi/kollektor:1.0.59559617788fc
stdlib@go1.20.14
1.25.11

Open the chart page →

717
ingress-nginxkomailo-helm-charts1.0.02 of 2See more

ingress-nginx komailo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
stdlib@go1.22.8
1.25.11
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.11

Open the chart page →

1,548
metallbkomailo-helm-charts1.2.43 of 4See more

metallb komailo-helm-charts 1.2.4

3 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.16.1f51ab515de9c
stdlib@go1.25.9
1.25.11
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
stdlib@go1.25.8
1.25.11
quay.io/metallb/speaker:v0.16.116561e96531e
stdlib@go1.25.9
1.25.11

Open the chart page →

2,176
komiserkomiser-eks3.1.101 of 1See more

komiser komiser-eks 3.1.10

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
tailwarden/komiser:3.1.103f68c8ae7993
stdlib@go1.22.0
1.25.11

Open the chart page →

1,272
komoplanekomodorVerified publisher0.1.81 of 1See more

komoplane komodor 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
komodorio/komoplane:0.2.19678d02c3f2e
stdlib@go1.26.2
1.25.11

Open the chart page →

955
simple-oauth2-proxykostiantyn-matsebora-helm-chartsVerified publisher0.3.71 of 1See more

simple-oauth2-proxy kostiantyn-matsebora-helm-charts 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
stdlib@go1.22.8
1.25.11

Open the chart page →

927
kovi-tile38kovi-charts0.1.11 of 1See more

kovi-tile38 kovi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
tile38/tile38:1.33.4afb7e82f9485
stdlib@go1.23.2
1.25.11

Open the chart page →

1,208
kpingkpingOfficialVerified publisher0.3.51 of 1See more

kping kping 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
kayrosuno/kping:latestf3bd44b29b0d
stdlib@go1.26.1
1.25.11

Open the chart page →

2,255
cadvisorkrakazyabraVerified publisher1.0.11 of 1See more

cadvisor krakazyabra 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
stdlib@go1.13.15
1.25.11

Open the chart page →

3,186
krakenkraken0.2.01 of 7See more

kraken kraken 0.2.0

1 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/redis:5.0fc5ecd863862
stdlib@go1.16.7
1.25.11

Open the chart page →

1,732
authnkrateo0.23.01 of 1See more

authn krateo 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/authn:0.23.0791c8f9d885a
stdlib@go1.24.2
1.25.11

Open the chart page →

678
autopilotkrateo1.0.01 of 2See more

autopilot krateo 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.11

Open the chart page →

1,618
installerkrateo2.7.12 of 2See more

installer krateo 2.7.1

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
stdlib@go1.21.8
1.25.11
ghcr.io/krateoplatformops/installer/installer:0.6.3a7e922ddac55
stdlib@go1.25.5
1.25.11

Open the chart page →

3,277
installer-pre-upgradekrateo2.7.11 of 1See more

installer-pre-upgrade krateo 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
stdlib@go1.21.8
1.25.11

Open the chart page →

2,543
sweeperkrateo0.2.12 of 2See more

sweeper krateo 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
alpine/kubectl:1.36.01ee9df6316d4
stdlib@go1.26.2
1.25.11
ghcr.io/krateoplatformops/eventstack/sweeper:0.1.05d5e24119ff1
stdlib@go1.25.3
1.25.11

Open the chart page →

1,506
krokro0.9.41 of 1See more

kro kro 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/kro/kro:v0.9.4eaf9fbaddd9d
stdlib@go1.26.3
1.25.11

Open the chart page →

88
kubeflowkromanow94-kubeflow0.5.116 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

16 of the 30 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
kubeflow/model-registry:v0.2.95783f6db428f
stdlib@go1.21.13
1.25.11
kubeflow/training-operator:v1-04f9f13dabb76dbda29
stdlib@go1.22.7
1.25.11
kubeflowkatib/katib-controller:v0.17.072f14e03b9e1
stdlib@go1.22.5
1.25.11
kubeflowkatib/katib-db-manager:v0.17.0916a7695b0dd
stdlib@go1.22.5
1.25.11
kubeflowkatib/katib-ui:v0.17.07a41c508deb1
stdlib@go1.22.5
1.25.11
kubeflownotebookswg/kfam:v1.9.22060a2ede788
stdlib@go1.17.13
1.25.11
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
stdlib@go1.17.13
1.25.11
kubeflownotebookswg/poddefaults-webhook:v1.9.2bde88d98ad74
stdlib@go1.21.13
1.25.11
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
stdlib@go1.17.13
1.25.11
kubeflownotebookswg/pvcviewer-controller:v1.9.29815e9b1728f
stdlib@go1.22.2
1.25.11
kubeflownotebookswg/tensorboard-controller:v1.9.26536a9f61193
stdlib@go1.17.13
1.25.11
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
stdlib@go1.21.7
1.25.11
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
stdlib@go1.21.7
1.25.11
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
stdlib@go1.21.7
1.25.11
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
stdlib@go1.21.7
1.25.11
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
stdlib@go1.21.7
1.25.11

Open the chart page →

71,477
kron-aapm-sidecarkron-aapm-sidecar1.1.01 of 1See more

kron-aapm-sidecar kron-aapm-sidecar 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
stdlib@go1.17.10
1.25.11

Open the chart page →

2,112
adventureworkskronkltdVerified publisher0.1.01 of 1See more

adventureworks kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
chriseaton/adventureworks:latest54c3384ce701
stdlib@go1.23.1
1.25.11

Open the chart page →

4,531
lndkronkltdVerified publisher0.3.93 of 4See more

lnd kronkltd 0.3.9

3 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
stdlib@go1.17.1
1.25.11
thesisrobot/loop:v0.11.1-beta89ae07e787ca
stdlib@go1.13.12
1.25.11
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
stdlib@go1.14.12
1.25.11

Open the chart page →

8,475
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
stdlib@go1.20.13
1.25.11

Open the chart page →

9,886
world-dbkronkltdVerified publisher0.1.01 of 1See more

world-db kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghusta/postgres-world-db:latest879d0919fdcc
stdlib@go1.24.6
1.25.11

Open the chart page →

1,735

Container images carrying it

4,772 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/lenitech/docker/keycloak-ppolicy:0.6.09895d6915075
stdlib@go1.25.7
1.25.11
1
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
stdlib@go1.24.5
1.25.11
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
stdlib@go1.21.0
1.25.11
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
stdlib@go1.15.15
1.25.11
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
stdlib@go1.25.7
1.25.11
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
stdlib@go1.25.7
1.25.11
1
registry.gitlab.com/xrow-public/ci-tools/kubectl:main9357cfeef63c
stdlib@go1.24.9
1.25.11
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
stdlib@go1.24.13
1.25.11
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
stdlib@go1.24.5
1.25.11
1
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.25.11
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.93.006a950310ecd
stdlib@go1.26.2
1.25.11
1
registry.k8s.io/agent-sandbox/sandbox-router-go:v1.0.125b1a0939630
stdlib@go1.26.2
1.25.11
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
stdlib@go1.24.4
1.25.11
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
stdlib@go1.24.7
1.25.11
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.4.171d817780aa9
stdlib@go1.24.3
1.25.11
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
stdlib@go1.25.7
1.25.11
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
stdlib@go1.24.6
1.25.11
1
registry.k8s.io/autoscaling/vpa-recommender:1.4.140b6d76e8526
stdlib@go1.24.3
1.25.11
1
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
stdlib@go1.24.6
1.25.11
1
registry.k8s.io/autoscaling/vpa-updater:1.4.18ebf269779c1
stdlib@go1.24.3
1.25.11
1
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
stdlib@go1.25.7
1.25.11
1
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
stdlib@go1.24.6
1.25.11
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
stdlib@go1.20.7
1.25.11
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
stdlib@go1.23.0
1.25.11
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
stdlib@go1.25.5
1.25.11
1
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
stdlib@go1.24.4
1.25.11
1
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
stdlib@go1.22.12
1.25.11
1
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
stdlib@go1.22.12
1.25.11
1
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
stdlib@go1.24.4
1.25.11
1
registry.k8s.io/descheduler/descheduler:v0.36.07ca92c0a7b4f
stdlib@go1.26.0
1.25.11
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
stdlib@go1.21.7
1.25.11
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
stdlib@go1.24.8
1.25.11
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
stdlib@go1.22.3
1.25.11
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
stdlib@go1.18.3
1.25.11
1
registry.k8s.io/etcd:3.6.4-0e36c08168342
stdlib@go1.23.11
1.25.11
1
registry.k8s.io/gateway-api/admission-server:v0.7.1fe43ee5176a8
stdlib@go1.19.9
1.25.11
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
stdlib@go1.25.1
1.25.11
1
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
stdlib@go1.20.6
1.25.11
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
stdlib@go1.20.10
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
stdlib@go1.19.4
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
stdlib@go1.24.6
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
stdlib@go1.24.6
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
stdlib@go1.22.0
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
stdlib@go1.18.2
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
stdlib@go1.18.2
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
stdlib@go1.20.1
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
stdlib@go1.20.1
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
stdlib@go1.18.2
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
stdlib@go1.22.8
1.25.11
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
stdlib@go1.22.2
1.25.11
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.