StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,358
of 17,939 indexed, latest versions
Container images
4,902
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,358 of 17,939 indexed charts deploy, on 4,902 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+186 more1.25.114,902
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,358 by stars
ChartLatestAffected imagesRadar Score
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.11

Open the chart page →

7,829
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.25.11

Open the chart page →

32,092
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
stdlib@go1.24.4
1.25.11
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
stdlib@go1.24.4
1.25.11

Open the chart page →

4,220
eg-universal-agent-operatoreg-universal-agent-operatorVerified publisher0.0.51 of 1See more

eg-universal-agent-operator eg-universal-agent-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
stdlib@go1.24.6
1.25.11

Open the chart page →

593
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
stdlib@go1.13.10
1.25.11

Open the chart page →

7,565
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
stdlib@go1.23.6
1.25.11

Open the chart page →

907
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.11

Open the chart page →

8,174
eks-auto-pod-id-assoceks-auto-pod-id-assoc0.6.01 of 1See more

eks-auto-pod-id-assoc eks-auto-pod-id-assoc 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
udhos/eks-auto-pod-id-assoc:0.6.0196ef68af380
stdlib@go1.26.3
1.25.11

Open the chart page →

967
postgresqleks-storageclass0.1.01 of 1See more

postgresql eks-storageclass 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
stdlib@go1.24.6
1.25.11

Open the chart page →

1,320
elastic-agentelasticVerified publisher9.5.41 of 2See more

elastic-agent elastic 9.5.4

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
stdlib@go1.24.4
1.25.11

Open the chart page →

766
kube-state-metricselasticVerified publisher6.1.01 of 1See more

kube-state-metrics elastic 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
stdlib@go1.24.4
1.25.11

Open the chart page →

766
netobserv-flowelastiflowVerified publisher0.11.01 of 1See more

netobserv-flow elastiflow 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
elastiflow/flow-collector:7.26.0fee67842e16b
stdlib@go1.25.10
1.25.11

Open the chart page →

1,600
seafileeleksbai0.1.12 of 3See more

seafile eleksbai 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mariadb:10.640153feb479c
stdlib@go1.24.6
1.25.11
seafileltd/seafile-mc:9.0.106693911bcc40
stdlib@go1.19
1.25.11

Open the chart page →

95,641
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
stdlib@go1.23.12
1.25.11

Open the chart page →

3,416
elsaelsa0.1.02 of 4See more

elsa elsa 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
geldata/gel:6b3a2815a3956
stdlib@go1.19.8
1.25.11
ghcr.io/stakater/reloader:v1.4.4a571c5b32c0f
stdlib@go1.24.4
1.25.11

Open the chart page →

4,243
rabbitmqemberstackVerified publisher1.0.211 of 1See more

rabbitmq emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/rabbitmq:managementddc75301edf5
stdlib@go1.22.2
1.25.11

Open the chart page →

868
emissary-ingressemissary-ingress4.1.01 of 1See more

emissary-ingress emissary-ingress 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
stdlib@go1.24.13
1.25.11

Open the chart page →

1,017
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
stdlib@go1.19.5
1.25.11

Open the chart page →

2,847
parrot-mirroremmas-chartsVerified publisher1.0.01 of 1See more

parrot-mirror emmas-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
stdlib@go1.21.0
1.25.11

Open the chart page →

2,278
cost-reportempathyco0.7.81 of 1See more

cost-report empathyco 0.7.8

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
empathyco/cost-report:0.0.124f1e26eaacbf
stdlib@go1.15.15
1.25.11

Open the chart page →

1,169
deadman-switchempathyco0.0.21 of 1See more

deadman-switch empathyco 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
stdlib@go1.16.3
1.25.11

Open the chart page →

1,260
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.25.11

Open the chart page →

10,862
yace-exporterempathyco0.1.01 of 1See more

yace-exporter empathyco 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
stdlib@go1.17.3
1.25.11

Open the chart page →

1,644
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
stdlib@go1.19.10
1.25.11

Open the chart page →

1,324
kube-ecp-stackemqx-operator2.5.111 of 16See more

kube-ecp-stack emqx-operator 2.5.1

11 of the 16 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
stdlib@go1.23.3
1.25.11
emqx/ecp-main:2.5.1fa876f71e5d6
stdlib@go1.22.0
1.25.11
emqxecp/otelcol:2.5.04c31d9bec846
stdlib@go1.22.12
1.25.11
library/telegraf:1.27507a3eecf809
stdlib@go1.20.7
1.25.11
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
stdlib@go1.23.2
1.25.11
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
stdlib@go1.23.2
1.25.11
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
stdlib@go1.23.2
1.25.11
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
stdlib@go1.23.2
1.25.11
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
stdlib@go1.23.2
1.25.11
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.1e2dc5623bcdd
stdlib@go1.23.2
1.25.11
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
stdlib@go1.23.1
1.25.11

Open the chart page →

24,555
cnpg-monitoringenixVerified publisher0.3.01 of 1See more

cnpg-monitoring enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.11

Open the chart page →

819
kube-packetloss-exporterenixVerified publisher0.2.12 of 2See more

kube-packetloss-exporter enix 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
stdlib@go1.23.4
1.25.11
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
stdlib@go1.20.5
1.25.11

Open the chart page →

6,354
mariadb-operator-monitoringenixVerified publisher0.1.01 of 1See more

mariadb-operator-monitoring enix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
stdlib@go1.24.6
1.25.11

Open the chart page →

743
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
stdlib@go1.21.7
1.25.11

Open the chart page →

4,119
network-exporterenixVerified publisher0.3.01 of 1See more

network-exporter enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
syepes/network_exporter:1.8.000af1691570e
stdlib@go1.25.1
1.25.11

Open the chart page →

1,399
topomatikenixVerified publisher1.3.11 of 1See more

topomatik enix 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
stdlib@go1.26.3
1.25.11

Open the chart page →

2,284
zfs-exporterenixVerified publisher2.2.01 of 1See more

zfs-exporter enix 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/enix/zfs-exporter:2.3.1223b053f1cbd0
stdlib@go1.24.2
1.25.11

Open the chart page →

984
ai-gateway-helmenvoy-ai-gateway0.0.0-003ab39f36923b5d40609a601e2951b73f6318fb1 of 1See more

ai-gateway-helm envoy-ai-gateway 0.0.0-003ab39f36923b5d40609a601e2951b73f6318fb

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
stdlib@go1.24.6
1.25.11

Open the chart page →

865
eoapi-supporteoapiVerified publisher0.1.76 of 7See more

eoapi-support eoapi 0.1.7

6 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:10.3.38640e5038e83
stdlib@go1.21.5
1.25.11
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
stdlib@go1.20.6
1.25.11
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
stdlib@go1.20.6
1.25.11
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
stdlib@go1.21.0
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
stdlib@go1.20.7
1.25.11
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
stdlib@go1.20.4
1.25.11

Open the chart page →

8,678
backendeoc-chartsVerified publisher0.1.01 of 1See more

backend eoc-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
hashicorp/http-echo:latestfcb75f691c8b
stdlib@go1.21.1
1.25.11

Open the chart page →

551
databaseeoc-chartsVerified publisher0.1.01 of 1See more

database eoc-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:14-alpine1a916758fce6
stdlib@go1.24.6
1.25.11

Open the chart page →

312
mariadbeoc-chartsVerified publisher0.3.141 of 1See more

mariadb eoc-charts 0.3.14

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.25.11

Open the chart page →

5,342
umbrella-appeoc-chartsVerified publisher0.1.02 of 3See more

umbrella-app eoc-charts 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
hashicorp/http-echo:latestfcb75f691c8b
stdlib@go1.21.1
1.25.11
library/postgres:14-alpine4ea9e5ed0659
stdlib@go1.24.6
1.25.11

Open the chart page →

876
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.25.11
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.25.11

Open the chart page →

28,227
eoloPlanteolo-plannerVerified publisher0.1.03 of 7See more

eoloPlant eolo-planner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
stdlib@go1.18.10
1.25.11
library/mongo:5.0-focal5e15a3f014ed
stdlib@go1.25.9
1.25.11
library/mysql:885b9bf2e29cf
stdlib@go1.24.6
1.25.11

Open the chart page →

28,822
eoloplannereoloplannerVerified publisher0.1.03 of 7See more

eoloplanner eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
stdlib@go1.18.10
1.25.11
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.11
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.11

Open the chart page →

33,480
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.03 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
stdlib@go1.18.10
1.25.11
library/mongo:5.0-focal5e15a3f014ed
stdlib@go1.25.9
1.25.11
library/mysql:885b9bf2e29cf
stdlib@go1.24.6
1.25.11

Open the chart page →

28,822
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.25.11
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.25.11

Open the chart page →

28,193
eoloplannereoloplanner-molynx-gat0.1.03 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
stdlib@go1.18.10
1.25.11
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.11
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.11

Open the chart page →

29,474
eolo-plannereolo-planner-repo0.1.03 of 7See more

eolo-planner eolo-planner-repo 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
stdlib@go1.18.10
1.25.11
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.11
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.11

Open the chart page →

28,201
eoloplanteoloplant1.0.03 of 7See more

eoloplant eoloplant 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
stdlib@go1.18.10
1.25.11
library/mongo:5.0-focal5e15a3f014ed
stdlib@go1.25.9
1.25.11
library/mysql:80744ee5ef89c
stdlib@go1.24.6
1.25.11

Open the chart page →

28,822
eoloplantseoloplants-urjcVerified publisher0.1.03 of 7See more

eoloplants eoloplants-urjc 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
stdlib@go1.18.10
1.25.11
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.11
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.11

Open the chart page →

28,742
servereoloserverVerified publisher0.1.03 of 7See more

server eoloserver 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
stdlib@go1.18.10
1.25.11
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.11
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.11

Open the chart page →

33,480
download-from-github-repoeosc-lot-1Verified publisher0.1.01 of 2See more

download-from-github-repo eosc-lot-1 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
stdlib@go1.21.10
1.25.11

Open the chart page →

994
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
alpine/git:v2.49.1c0280cf95723
stdlib@go1.24.8
1.25.11

Open the chart page →

76,384

Container images carrying it

4,902 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.11
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.11
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.