StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,341
of 17,957 indexed, latest versions
Container images
4,873
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,341 of 17,957 indexed charts deploy, on 4,873 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+186 more1.25.114,873
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,341 by stars
ChartLatestAffected imagesRadar Score
alustan-helmalustan-helm1.0.01 of 1See more

alustan-helm alustan-helm 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
alustan/install-argocd:1.0.0c16c34f46ad3
stdlib@go1.22.5
1.25.11

Open the chart page →

1,926
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
stdlib@go1.22.2
1.25.11
daprio/dashboard:0.14.07ba5d51e5b97
stdlib@go1.19.13
1.25.11
daprio/injector:1.11.2763b9b70b0c8
stdlib@go1.20.6
1.25.11
daprio/operator:1.11.2c584428aa12d
stdlib@go1.20.6
1.25.11
daprio/placement:1.11.2d8e1446da996
stdlib@go1.20.6
1.25.11
daprio/sentry:1.11.21f507c1a181b
stdlib@go1.20.6
1.25.11
hashicorp/vault:1.15.26b4e5dadf082
stdlib@go1.21.3
1.25.11
hashicorp/vault-k8s:1.3.15d74a885ae3e
stdlib@go1.21.3
1.25.11

Open the chart page →

29,178
ampsamps0.1.95 of 10See more

amps amps 0.1.9

5 of the 10 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
hashicorp/vault:1.9.2ff9b17b0cefe
stdlib@go1.17.5
1.25.11
library/nats:2.7.2-alpine8b3fb2423a8c
stdlib@go1.17.6
1.25.11
natsio/nats-box:0.8.1b7f9328145f4
stdlib@go1.17.6
1.25.11
natsio/nats-server-config-reloader:0.6.2ad0374303b13
stdlib@go1.15.14
1.25.11
natsio/prometheus-nats-exporter:0.9.14665cdc7e749
stdlib@go1.16.13
1.25.11

Open the chart page →

10,775
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
stdlib@go1.20.14
1.25.11

Open the chart page →

1,609
anchore-admission-controlleranchore-charts0.9.01 of 2See more

anchore-admission-controller anchore-charts 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
stdlib@go1.20.14
1.25.11

Open the chart page →

7,829
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
stdlib@go1.19.7
1.25.11

Open the chart page →

1,321
cert-manager-webhook-inwxandibraeuVerified publisher0.9.01 of 1See more

cert-manager-webhook-inwx andibraeu 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
stdlib@go1.25.7
1.25.11

Open the chart page →

605
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
stdlib@go1.25.7
1.25.11

Open the chart page →

6,300
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
stdlib@go1.25.7
1.25.11

Open the chart page →

1,353
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,574
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
stdlib@go1.16.4
1.25.11

Open the chart page →

1,989
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.25.11

Open the chart page →

2,241
dnsmadeeasy-webhookangelnu6.0.71 of 1See more

dnsmadeeasy-webhook angelnu 6.0.7

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/angelnu/dnsmadeeasy-webhook:v1.9.0a5ca158b1f02
stdlib@go1.24.1
1.25.11

Open the chart page →

817
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.25.11

Open the chart page →

123,013
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
stdlib@go1.23.12
1.25.11

Open the chart page →

927
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
stdlib@go1.13.15
1.25.11

Open the chart page →

2,495
ddosifyanteonVerified publisher1.7.55 of 13See more

ddosify anteon 1.7.5

5 of the 13 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
stdlib@go1.20.8
1.25.11
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
stdlib@go1.18.1
1.25.11
library/influxdb:2.6.1-alpine44a366dd7724
stdlib@go1.19.4
1.25.11
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.11
prom/prometheus:v2.37.98176adea328e
stdlib@go1.19.11
1.25.11

Open the chart page →

26,820
antmediaantmediaVerified publisher3.1.03 of 4See more

antmedia antmedia 3.1.0

3 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mongo:8.04968f22d0c6c
stdlib@go1.24.6
1.25.11
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.11
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.11

Open the chart page →

4,285
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.25.11
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.25.11

Open the chart page →

3,331
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:latestac461fb352ab
stdlib@go1.26.3
1.25.11

Open the chart page →

2,515
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
stdlib@go1.15
1.25.11

Open the chart page →

2,728
kesque-dashboardapache-pulsar-helm-chart-repo0.0.51 of 5See more

kesque-dashboard apache-pulsar-helm-chart-repo 0.0.5

1 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mariadb:latestd4fdec0510ad
stdlib@go1.24.6
1.25.11

Open the chart page →

3,983
pulsar-monitorapache-pulsar-helm-chart-repo0.1.61 of 1See more

pulsar-monitor apache-pulsar-helm-chart-repo 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
kesque/pulsar-monitor:1.0.8ce85c1e7d613
stdlib@go1.14.4
1.25.11

Open the chart page →

3,058
apipingapiping1.5.01 of 1See more

apiping apiping 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
udhos/apiping:1.5.041ab9bae6f3b
stdlib@go1.25.4
1.25.11

Open the chart page →

1,194
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
stdlib@go1.23.6
1.25.11

Open the chart page →

3,038
api-usage-cleanerapi-usage-cleaner1.16.01 of 1See more

api-usage-cleaner api-usage-cleaner 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.25.11

Open the chart page →

592
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.11
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.11

Open the chart page →

20,447
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
stdlib@go1.18.5
1.25.11
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
stdlib@go1.18.5
1.25.11
velero/velero:v1.8.18d784580931c
stdlib@go1.16.6
1.25.11

Open the chart page →

12,780
app-movies-seriesapp-movies-seriesVerified publisher0.1.01 of 2See more

app-movies-series app-movies-series 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.25.11

Open the chart page →

3,184
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1139076a89c36b
stdlib@go1.25.3
1.25.11

Open the chart page →

2,575
aceappscodeVerified publisher2026.9.112 of 2See more

ace appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1139076a89c36b
stdlib@go1.25.3
1.25.11
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
stdlib@go1.24.13
1.25.11

Open the chart page →

2,881
ace-installerappscodeVerified publisher2026.9.112 of 2See more

ace-installer appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
stdlib@go1.25.9
1.25.11
ghcr.io/appscode/b3:v2026.9.1139076a89c36b
stdlib@go1.25.3
1.25.11

Open the chart page →

3,247
ace-installer-certifiedappscodeVerified publisher2026.9.112 of 2See more

ace-installer-certified appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
stdlib@go1.25.9
1.25.11
ghcr.io/appscode/b3:v2026.9.1178a9fb785ec5
stdlib@go1.25.3
1.25.11

Open the chart page →

3,247
acerproxyappscodeVerified publisher2026.9.111 of 1See more

acerproxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
stdlib@go1.25.5
1.25.11

Open the chart page →

1,363
aceshifterappscodeVerified publisher2026.9.111 of 1See more

aceshifter appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/aceshifter:v0.0.3e5f5c254a55a
stdlib@go1.25.8
1.25.11

Open the chart page →

1,071
appcatalogappscodeVerified publisher2023.3.231 of 1See more

appcatalog appscode 2023.3.23

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/appcatalog:v0.0.109709a346888
stdlib@go1.20.5
1.25.11

Open the chart page →

1,665
appscode-otel-stackappscodeVerified publisher2026.9.223 of 3See more

appscode-otel-stack appscode 2026.9.22

3 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
stdlib@go1.24.6
1.25.11
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.150.089490ef63b72
stdlib@go1.26.2
1.25.11
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
stdlib@go1.25.1
1.25.11

Open the chart page →

1,473
auditorappscodeVerified publisher2023.10.11 of 1See more

auditor appscode 2023.10.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
stdlib@go1.19.4
1.25.11

Open the chart page →

1,680
aws-credential-managerappscodeVerified publisher2026.4.161 of 1See more

aws-credential-manager appscode 2026.4.16

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/aws-credential-manager:v0.1.00511bbe501c3
stdlib@go1.25.9
1.25.11

Open the chart page →

639
azure-credential-managerappscodeVerified publisher2026.4.161 of 1See more

azure-credential-manager appscode 2026.4.16

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/azure-credential-manager:v0.1.0f5c797f7fbe7
stdlib@go1.25.9
1.25.11

Open the chart page →

897
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1139076a89c36b
stdlib@go1.25.3
1.25.11

Open the chart page →

2,575
capa-vpc-peering-operatorappscodeVerified publisher2023.12.111 of 1See more

capa-vpc-peering-operator appscode 2023.12.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
stdlib@go1.21.5
1.25.11

Open the chart page →

1,428
capi-ops-managerappscodeVerified publisher2024.8.142 of 2See more

capi-ops-manager appscode 2024.8.14

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
stdlib@go1.23.2
1.25.11
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
stdlib@go1.15.14
1.25.11

Open the chart page →

3,610
cert-manager-csi-driver-cacertsappscodeVerified publisher2026.9.182 of 3See more

cert-manager-csi-driver-cacerts appscode 2026.9.18

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
stdlib@go1.24.2
1.25.11
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
stdlib@go1.24.2
1.25.11

Open the chart page →

2,603
cert-manager-webhook-aceappscodeVerified publisher2026.9.111 of 1See more

cert-manager-webhook-ace appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/cert-manager-webhook-ace:v0.0.2dc6b5fdcec06
stdlib@go1.25.5
1.25.11

Open the chart page →

1,357
cluster-auth-agentappscodeVerified publisher2026.2.161 of 1See more

cluster-auth-agent appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
stdlib@go1.25.7
1.25.11

Open the chart page →

1,006
cluster-auth-managerappscodeVerified publisher2026.2.161 of 1See more

cluster-auth-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
stdlib@go1.25.7
1.25.11

Open the chart page →

1,006
cluster-connectorappscodeVerified publisher2025.12.151 of 1See more

cluster-connector appscode 2025.12.15

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/cluster-connector:v0.0.140efd9d9ef6ca
stdlib@go1.25.5
1.25.11

Open the chart page →

625
cluster-importerappscodeVerified publisher2026.9.111 of 1See more

cluster-importer appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/appscode/ace:v0.2.0b8e03da90e70
stdlib@go1.25.9
1.25.11

Open the chart page →

1,056
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
stdlib@go1.25.7
1.25.11

Open the chart page →

1,134

Container images carrying it

4,873 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-42507.

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.