StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,358
of 17,939 indexed, latest versions
Container images
4,902
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,358 of 17,939 indexed charts deploy, on 4,902 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+186 more1.25.114,902
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,358 by stars
ChartLatestAffected imagesRadar Score
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
stdlib@go1.16.5
1.25.11

Open the chart page →

14,153
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
stdlib@go1.21.6
1.25.11

Open the chart page →

6,375
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
stdlib@go1.17.8
1.25.11

Open the chart page →

7,641
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
stdlib@go1.13.5
1.25.11

Open the chart page →

14,875
ferretdbferretdb-helm-chart0.2.31 of 1See more

ferretdb ferretdb-helm-chart 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/ferretdb/ferretdb:2.7.05706414241eb
stdlib@go1.25.4
1.25.11

Open the chart page →

771
infrafibonacci-cluster-infraVerified publisher1.0.02 of 4See more

infra fibonacci-cluster-infra 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.25.11
library/redis:7.4.1bb142a9c18ac
stdlib@go1.18.2
1.25.11

Open the chart page →

13,097
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
stdlib@go1.17.5
1.25.11

Open the chart page →

3,338
grgatefikaworks0.3.41 of 1See more

grgate fikaworks 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
stdlib@go1.20.2
1.25.11

Open the chart page →

1,073
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
stdlib@go1.19.13
1.25.11

Open the chart page →

8,117
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mariadb:11.470cc072b29b4
stdlib@go1.24.6
1.25.11

Open the chart page →

7,650
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

5,639
first-matefirst-mateVerified publisher1.0.51 of 1See more

first-mate first-mate 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
chriswells0/first-mate:1.0.5f3918ec8471c
stdlib@go1.20.5
1.25.11

Open the chart page →

1,730
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:3.6.213e51da56fc54
stdlib@go1.15.1
1.25.11

Open the chart page →

118,033
dsba-pdpfiware0.1.22 of 2See more

dsba-pdp fiware 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
stdlib@go1.18.10
1.25.11
quay.io/wi_stefan/dsba-db-migrations:0.0.125b986cd14a08
stdlib@go1.18.9
1.25.11

Open the chart page →

4,109
endpoint-auth-servicefiware0.1.43 of 4See more

endpoint-auth-service fiware 0.1.4

3 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
stdlib@go1.18.3
1.25.11
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
stdlib@go1.18.5
1.25.11
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
stdlib@go1.18.5
1.25.11

Open the chart page →

12,000
grafanaflagger1.7.01 of 1See more

grafana flagger 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:7.3.46d42886b3ebe
stdlib@go1.15.5
1.25.11

Open the chart page →

3,374
podinfoflagger6.1.41 of 1See more

podinfo flagger 6.1.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
stdlib@go1.17.9
1.25.11

Open the chart page →

2,826
apm-hubflanksourceVerified publisher0.0.472 of 2See more

apm-hub flanksource 0.0.47

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
stdlib@go1.20.7
1.25.11
library/postgres:14816cf7d06ec3
stdlib@go1.24.6
1.25.11

Open the chart page →

5,973
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
stdlib@go1.25.5
1.25.11

Open the chart page →

5,772
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
stdlib@go1.20.7
1.25.11

Open the chart page →

4,827
facetflanksourceVerified publisher0.1.731 of 1See more

facet flanksource 0.1.73

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
stdlib@go1.23.12
1.25.11

Open the chart page →

22,454
flanksource-uiflanksourceVerified publisher1.4.3201 of 1See more

flanksource-ui flanksource 1.4.320

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.320d952c2a774a2
stdlib@go1.23.5
1.25.11

Open the chart page →

2,734
mission-controlflanksourceVerified publisher0.1.3383 of 8See more

mission-control flanksource 0.1.338

3 of the 8 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
stdlib@go1.25.4
1.25.11
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
stdlib@go1.23.5
1.25.11
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
stdlib@go1.25.2
1.25.11

Open the chart page →

9,456
mission-control-tenantflanksourceVerified publisher1.0.923 of 3See more

mission-control-tenant flanksource 1.0.92

3 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
stdlib@go1.17.13
1.25.11
rancher/k3s:v1.28.2-k3s18c2599ecfca8
stdlib@go1.20.8
1.25.11
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
stdlib@go1.20.8
1.25.11

Open the chart page →

5,733
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

5,639
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.11

Open the chart page →

4,252
floating-serverfloating-server1.6.31 of 2See more

floating-server floating-server 1.6.3

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
censedata/floating-server:v1.6.3ebfffb9dd4c0
stdlib@go1.24.3
1.25.11

Open the chart page →

1,627
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.11

Open the chart page →

8,174
fluent-operatorfluent-operatorVerified publisher0.1.01 of 2See more

fluent-operator fluent-operator 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
kubesphere/fluent-operator:v1.0.2702df77228c6
stdlib@go1.16.6
1.25.11

Open the chart page →

2,626
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
louislam/uptime-kuma:170233f4acb51
stdlib@go1.20.5
1.25.11

Open the chart page →

3,627
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
stdlib@go1.25.9
1.25.11

Open the chart page →

2,510
fluxer-helmfluxer-helm0.3.02 of 18See more

fluxer-helm fluxer-helm 0.3.0

2 of the 18 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.25.11
ghcr.io/fluxerapp/fluxer-static:2026.812.125337cfe98ae544df
stdlib@go1.25.0
1.25.11

Open the chart page →

29,230
flyte-depsflyte1.16.81 of 3See more

flyte-deps flyte 1.16.8

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
stdlib@go1.15.1
1.25.11

Open the chart page →

2,240
flyte-devboxflyte0.1.07 of 14See more

flyte-devbox flyte 0.1.0

7 of the 14 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
stdlib@go1.24.6
1.25.11
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
stdlib@go1.24.6
1.25.11
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
stdlib@go1.24.3
1.25.11
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
stdlib@go1.24.3
1.25.11
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
stdlib@go1.24.3
1.25.11
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
stdlib@go1.24.3
1.25.11
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
stdlib@go1.24.3
1.25.11

Open the chart page →

8,624
gobackupfmjstudios0.2.21 of 1See more

gobackup fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
huacnlee/gobackup:v2.11.2d9c693e99576
stdlib@go1.20.3
1.25.11

Open the chart page →

2,939
gotenbergfmjstudios0.2.21 of 1See more

gotenberg fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.7.0437b9cd3c351
stdlib@go1.22.4
1.25.11

Open the chart page →

10,057
ntfyfmjstudios0.2.21 of 1See more

ntfy fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
stdlib@go1.22.2
1.25.11

Open the chart page →

1,284
popeyefmjstudios0.1.21 of 1See more

popeye fmjstudios 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
derailed/popeye:v0.21.363b2d2a8f674
stdlib@go1.21.8
1.25.11

Open the chart page →

1,202
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
stdlib@go1.19.6
1.25.11

Open the chart page →

4,345
csp-reporterfoomoVerified publisher2.2.01 of 1See more

csp-reporter foomo 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
foomo/csp-reporter:1.3.0e436da524785
stdlib@go1.18
1.25.11

Open the chart page →

1,410
forkliftforklift0.1.42 of 2See more

forklift forklift 0.1.4

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
wuhan005/forklift:daemon4e6da210e449
stdlib@go1.19.8
1.25.11
wuhan005/forklift:controllerbfbe82d59850
stdlib@go1.19.8
1.25.11

Open the chart page →

1,822
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
stdlib@go1.18.10
1.25.11

Open the chart page →

4,810
forwardforward1.3.11 of 1See more

forward forward 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
udhos/forward:1.1.312e120d39fdb
stdlib@go1.20.5
1.25.11

Open the chart page →

2,208
cloudflaredfossa0.1.11 of 1See more

cloudflared fossa 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2022.1.361f608cd1123
stdlib@go1.17.1
1.25.11

Open the chart page →

2,478
uptime-kumafossa1.0.11 of 1See more

uptime-kuma fossa 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
stdlib@go1.19.4
1.25.11

Open the chart page →

5,315
maxscalefour-allportalVerified publisher4.1.162 of 3See more

maxscale four-allportal 4.1.16

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:10.6.12-debian-11-r1643a70df0e7c6
stdlib@go1.19.7
1.25.11
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
stdlib@go1.17.8
1.25.11

Open the chart page →

6,684
readium-lcpserverfpetr0.0.51 of 3See more

readium-lcpserver fpetr 0.0.5

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
stdlib@go1.22.0
1.25.11

Open the chart page →

1,366
readium-lsdserverfpetr0.0.11 of 2See more

readium-lsdserver fpetr 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
stdlib@go1.22.0
1.25.11

Open the chart page →

1,366
ff-testfrankframework0.7.61 of 2See more

ff-test frankframework 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:17-bookworm639ab7ceb90e
stdlib@go1.24.6
1.25.11

Open the chart page →

1,830
frank2examplefrankframework0.7.41 of 2See more

frank2example frankframework 0.7.4

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:17-bookworm639ab7ceb90e
stdlib@go1.24.6
1.25.11

Open the chart page →

1,830

Container images carrying it

4,902 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.11
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.11
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.