StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,358
of 17,939 indexed, latest versions
Container images
4,902
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,358 of 17,939 indexed charts deploy, on 4,902 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+186 more1.25.114,902
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,358 by stars
ChartLatestAffected imagesRadar Score
free5gc-amffree5gc-amfVerified publisher0.1.31 of 1See more

free5gc-amf free5gc-amf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
stdlib@go1.21.8
1.25.11

Open the chart page →

897
free5gc-ausffree5gc-ausfVerified publisher0.1.31 of 1See more

free5gc-ausf free5gc-ausf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/ausf:v3.4.3687ff4daf5da
stdlib@go1.21.8
1.25.11

Open the chart page →

906
free5gc-chffree5gc-chfVerified publisher0.1.31 of 1See more

free5gc-chf free5gc-chf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/chf:v3.4.3e2a4dd98a4ed
stdlib@go1.21.8
1.25.11

Open the chart page →

1,003
free5gc-nrffree5gc-nrfVerified publisher0.1.31 of 1See more

free5gc-nrf free5gc-nrf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/nrf:v3.4.399e46b860efb
stdlib@go1.21.8
1.25.11

Open the chart page →

914
free5gc-nssffree5gc-nssfVerified publisher0.1.31 of 1See more

free5gc-nssf free5gc-nssf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/nssf:v3.4.3dfe8c68c04b4
stdlib@go1.21.8
1.25.11

Open the chart page →

906
free5gc-pcffree5gc-pcfVerified publisher0.1.31 of 1See more

free5gc-pcf free5gc-pcf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/pcf:v3.4.3f712e8ecd927
stdlib@go1.21.8
1.25.11

Open the chart page →

898
free5gc-smffree5gc-smfVerified publisher0.1.31 of 1See more

free5gc-smf free5gc-smf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/smf:v3.4.360e38baa4b10
stdlib@go1.21.8
1.25.11

Open the chart page →

913
free5gc-udmfree5gc-udmVerified publisher0.1.31 of 1See more

free5gc-udm free5gc-udm 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/udm:v3.4.32f68df062a50
stdlib@go1.21.8
1.25.11

Open the chart page →

906
free5gc-udrfree5gc-udrVerified publisher0.1.31 of 1See more

free5gc-udr free5gc-udr 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/udr:v3.4.3c0783bcdcbdc
stdlib@go1.21.8
1.25.11

Open the chart page →

914
free5gc-upffree5gc-upfVerified publisher0.1.31 of 1See more

free5gc-upf free5gc-upf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/upf:v3.4.3b6b362a39fdd
stdlib@go1.21.8
1.25.11

Open the chart page →

1,070
free5gc-webuifree5gc-webuiVerified publisher0.1.31 of 1See more

free5gc-webui free5gc-webui 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
free5gc/webui:v3.4.39adeb18492cb
stdlib@go1.21.8
1.25.11

Open the chart page →

1,265
dbmatefrinx-helm-charts1.0.01 of 1See more

dbmate frinx-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
amacneil/dbmate:2.6.03fdce58cc189
stdlib@go1.21.0
1.25.11

Open the chart page →

1,440
frinx-machinefrinx-helm-charts11.0.010 of 26See more

frinx-machine frinx-helm-charts 11.0.0

10 of the 26 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
frinx/krakend:7.0.0bf8edd4f52f3
stdlib@go1.22.7
1.25.11
frinx/resource-manager:6.1.09cd0147a09bd
stdlib@go1.21.7
1.25.11
frinx/schellar:6.1.04693dc627d32
stdlib@go1.21.11
1.25.11
grafana/grafana:11.0.00dc5a246ab16
stdlib@go1.21.10
1.25.11
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.25.11
grafana/promtail:2.9.3b338a29de45e
stdlib@go1.21.3
1.25.11
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
stdlib@go1.22.3
1.25.11
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
stdlib@go1.22.2
1.25.11
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
stdlib@go1.19.4
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.11

Open the chart page →

44,191
frinx-machine-monitoringfrinx-helm-charts0.1.27 of 8See more

frinx-machine-monitoring frinx-helm-charts 0.1.2

7 of the 8 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
stdlib@go1.21.10
1.25.11
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.25.11
grafana/promtail:2.9.3b338a29de45e
stdlib@go1.21.3
1.25.11
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
stdlib@go1.22.3
1.25.11
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
stdlib@go1.22.2
1.25.11
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
stdlib@go1.19.4
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.11

Open the chart page →

10,720
frinx-machine-operatorsfrinx-helm-charts0.3.02 of 2See more

frinx-machine-operators frinx-helm-charts 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
arangodb/kube-arangodb:1.2.4108d1720cec3b
stdlib@go1.22.3
1.25.11
ghcr.io/cloudnative-pg/cloudnative-pg:1.23.2f1f3c20f3637
stdlib@go1.22.4
1.25.11

Open the chart page →

1,927
krakendfrinx-helm-charts5.0.21 of 1See more

krakend frinx-helm-charts 5.0.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
frinx/krakend:7.0.0bf8edd4f52f3
stdlib@go1.22.7
1.25.11

Open the chart page →

1,398
resource-managerfrinx-helm-charts2.3.11 of 4See more

resource-manager frinx-helm-charts 2.3.1

1 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
frinx/resource-manager:6.1.09cd0147a09bd
stdlib@go1.21.7
1.25.11

Open the chart page →

9,810
uniresourcefrinx-helm-charts1.1.12 of 3See more

uniresource frinx-helm-charts 1.1.1

2 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
frinx/resource-manager:1.0.455575caebd01
stdlib@go1.17.9
1.25.11
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.25.11

Open the chart page →

3,333
workflow-managerfrinx-helm-charts3.2.11 of 5See more

workflow-manager frinx-helm-charts 3.2.1

1 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
frinx/schellar:6.1.04693dc627d32
stdlib@go1.21.11
1.25.11

Open the chart page →

9,378
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
pschiffe/pdns-mysql:alpinea7d2d021c788
stdlib@go1.21.5
1.25.11

Open the chart page →

1,972
aptlyg0dscookie0.4.01 of 2See more

aptly g0dscookie 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
stdlib@go1.18.3
1.25.11

Open the chart page →

3,970
icinga2g0dscookie0.2.01 of 1See more

icinga2 g0dscookie 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
stdlib@go1.18.1
1.25.11

Open the chart page →

4,445
passboltg0dscookie0.5.22 of 2See more

passbolt g0dscookie 0.5.2

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mariadb:10.79a48ac9f196f
stdlib@go1.16.7
1.25.11
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
stdlib@go1.14.4
1.25.11

Open the chart page →

8,196
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
stdlib@go1.23.5
1.25.11

Open the chart page →

2,636
castsponsorskipgabe565Verified publisher0.8.11 of 1See more

castsponsorskip gabe565 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
stdlib@go1.23.4
1.25.11

Open the chart page →

1,410
generic-device-plugingabe565Verified publisher0.1.31 of 1See more

generic-device-plugin gabe565 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:latestdc192e164c69
stdlib@go1.26.2
1.25.11

Open the chart page →

268
gotifygabe565Verified publisher0.4.01 of 1See more

gotify gabe565 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/gotify/server:2.6.104f4c4bb7cdd
stdlib@go1.23.3
1.25.11

Open the chart page →

758
hammondgabe565Verified publisher0.6.41 of 1See more

hammond gabe565 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
stdlib@go1.20.6
1.25.11

Open the chart page →

1,801
limogabe565Verified publisher0.8.01 of 1See more

limo gabe565 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/gabe565/limo:latest6dfdbc9853bb
stdlib@go1.20.12
1.25.11

Open the chart page →

1,329
matrimonygabe565Verified publisher0.7.01 of 1See more

matrimony gabe565 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/gabe565/matrimony:latestd39a9d7c3e1b
stdlib@go1.22.0
1.25.11

Open the chart page →

1,129
podgrabgabe565Verified publisher0.5.21 of 1See more

podgrab gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
stdlib@go1.15.2
1.25.11

Open the chart page →

2,397
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
stdlib@go1.19.8
1.25.11

Open the chart page →

13,900
smarter-device-managergabe565Verified publisher0.5.21 of 1See more

smarter-device-manager gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
stdlib@go1.19.1
1.25.11

Open the chart page →

1,234
transsmutegabe565Verified publisher1.1.01 of 1See more

transsmute gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
stdlib@go1.24.1
1.25.11

Open the chart page →

802
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
stdlib@go1.24.6
1.25.11

Open the chart page →

6,625
galoygaloymoney0.34.74 of 24See more

galoy galoymoney 0.34.7

4 of the 24 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.25.11
oryd/hydra:v2.2.02c93beb5e5f2
stdlib@go1.21.5
1.25.11
oryd/kratos:v1.0.0d06fc5845f63
stdlib@go1.20.5
1.25.11
oryd/oathkeeper:v0.40.6e8cb9b79a89c
stdlib@go1.20.5
1.25.11

Open the chart page →

8,727
galoy-depsgaloymoney0.10.208 of 9See more

galoy-deps galoymoney 0.10.20

8 of the 9 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
stdlib@go1.18.9
1.25.11
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
stdlib@go1.23.2
1.25.11
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
stdlib@go1.21.7
1.25.11
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
stdlib@go1.21.7
1.25.11
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
stdlib@go1.21.7
1.25.11
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
stdlib@go1.21.7
1.25.11
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.25.11
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.25.11

Open the chart page →

12,167
lndgaloymoney0.10.61 of 3See more

lnd galoymoney 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
stdlib@go1.22.5
1.25.11

Open the chart page →

2,186
monitoringgaloymoney0.12.215 of 6See more

monitoring galoymoney 0.12.21

5 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
stdlib@go1.23.1
1.25.11
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
stdlib@go1.23.2
1.25.11
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.11
quay.io/prometheus/prometheus:v2.55.0378f4e037035
stdlib@go1.23.2
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.11

Open the chart page →

5,356
galoygaloymoney20.34.74 of 24See more

galoy galoymoney2 0.34.7

4 of the 24 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.25.11
oryd/hydra:v2.2.02c93beb5e5f2
stdlib@go1.21.5
1.25.11
oryd/kratos:v1.0.0d06fc5845f63
stdlib@go1.20.5
1.25.11
oryd/oathkeeper:v0.40.6e8cb9b79a89c
stdlib@go1.20.5
1.25.11

Open the chart page →

8,727
galoy-depsgaloymoney20.10.208 of 9See more

galoy-deps galoymoney2 0.10.20

8 of the 9 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
stdlib@go1.18.9
1.25.11
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
stdlib@go1.23.2
1.25.11
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
stdlib@go1.21.7
1.25.11
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
stdlib@go1.21.7
1.25.11
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
stdlib@go1.21.7
1.25.11
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
stdlib@go1.21.7
1.25.11
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.25.11
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.25.11

Open the chart page →

12,167
lndgaloymoney20.10.61 of 3See more

lnd galoymoney2 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
stdlib@go1.22.5
1.25.11

Open the chart page →

2,186
monitoringgaloymoney20.12.215 of 6See more

monitoring galoymoney2 0.12.21

5 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
stdlib@go1.23.1
1.25.11
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
stdlib@go1.23.2
1.25.11
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.11
quay.io/prometheus/prometheus:v2.55.0378f4e037035
stdlib@go1.23.2
1.25.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.11

Open the chart page →

5,356
gameserver-operatorgameserver-operator0.3.01 of 1See more

gameserver-operator gameserver-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/idebeijer/gameserver-operator:latest1b099cfe9e5e
stdlib@go1.25.7
1.25.11

Open the chart page →

390
pagesgary-pages1.0.01 of 3See more

pages gary-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,574
alertmanager-discordgeek-cookbookVerified publisher1.3.21 of 1See more

alertmanager-discord geek-cookbook 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
rogerrum/alertmanager-discord:1.0.3827593369625
stdlib@go1.17.4
1.25.11

Open the chart page →

1,046
anonaddygeek-cookbookVerified publisher6.0.01 of 1See more

anonaddy geek-cookbook 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.25.11

Open the chart page →

4,837
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
stdlib@go1.18.4
1.25.11

Open the chart page →

15,109
autobrrgeek-cookbookVerified publisher1.1.31 of 1See more

autobrr geek-cookbook 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
stdlib@go1.19.3
1.25.11

Open the chart page →

2,233
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
stdlib@go1.16.7
1.25.11

Open the chart page →

16,699

Container images carrying it

4,902 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.11
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.11
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.