StackRadar

CVE-2026-42507

Medium

Advisory

Published 2 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,359
of 17,926 indexed, latest versions
Container images
4,906
deployed by those charts
Fix available
1 of 2
affected packages

Arbitrary inputs are included in errors without any escaping in net/textproto

Carried by container images the latest versions of 4,359 of 17,926 indexed charts deploy, on 4,906 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+186 more1.25.114,906
OSV records
DEBIAN-CVE-2026-42507GO-2026-5039
Also known as
BIT-golang-2026-42507

Charts affected

4,359 by stars
ChartLatestAffected imagesRadar Score
headlampradar-baseVerified publisher1.0.01 of 1See more

headlamp radar-base 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.43.05d03caa26df7
stdlib@go1.26.3
1.25.11

Open the chart page →

686
hydraradar-baseVerified publisher0.48.01 of 1See more

hydra radar-base 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
oryd/hydra:v2.2.02c93beb5e5f2
stdlib@go1.21.5
1.25.11

Open the chart page →

1,544
kratosradar-baseVerified publisher0.43.11 of 1See more

kratos radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
oryd/kratos:v1.1.08f15006a080d
stdlib@go1.21.5
1.25.11

Open the chart page →

1,783
kubecostradar-baseVerified publisher1.0.03 of 7See more

kubecost radar-base 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
stdlib@go1.23.1
1.25.11
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
stdlib@go1.23.4
1.25.11
quay.io/prometheus/prometheus:v3.2.05888c188cf09
stdlib@go1.23.6
1.25.11

Open the chart page →

9,765
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
stdlib@go1.26.2
1.25.11

Open the chart page →

3,374
nifikopradar-baseVerified publisher1.14.11 of 1See more

nifikop radar-base 1.14.1

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
stdlib@go1.24.4
1.25.11

Open the chart page →

519
radar-grafanaradar-baseVerified publisher0.1.41 of 2See more

radar-grafana radar-base 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
grafana/grafana:11.6.062d2b9d20a19
stdlib@go1.23.7
1.25.11

Open the chart page →

1,896
radar-hydraradar-baseVerified publisher0.3.41 of 2See more

radar-hydra radar-base 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
oryd/hydra:v2.3.0b94007e19a1f
stdlib@go1.23.4
1.25.11

Open the chart page →

2,248
radar-kratosradar-baseVerified publisher0.1.51 of 1See more

radar-kratos radar-base 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
oryd/kratos:v1.3.1fe2428f103a6
stdlib@go1.23.2
1.25.11

Open the chart page →

1,593
radar-nifiradar-baseVerified publisher3.1.01 of 1See more

radar-nifi radar-base 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
stdlib@go1.24.4
1.25.11

Open the chart page →

519
radar-redisradar-baseVerified publisher1.3.01 of 1See more

radar-redis radar-base 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/opstree/redis-operator:v0.22.2464ac61a6eb4
stdlib@go1.23.12
1.25.11

Open the chart page →

417
redis-operatorradar-baseVerified publisher0.22.21 of 1See more

redis-operator radar-base 0.22.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/opstree/redis-operator:v0.22.2464ac61a6eb4
stdlib@go1.23.12
1.25.11

Open the chart page →

417
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
stdlib@go1.24.13
1.25.11

Open the chart page →

1,761
pagesranjinigogga1.0.01 of 3See more

pages ranjinigogga 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,573
raven_profilerraven-profilerVerified publisher0.1.621 of 1See more

raven_profiler raven-profiler 0.1.62

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
public.ecr.aws/t0u0d5o5/ecr_authenticator:latest077e4e57e41c
stdlib@go1.21.5
1.25.11

Open the chart page →

1,307
rawfile-localpvrawfile0.15.35 of 6See more

rawfile-localpv rawfile 0.15.3

5 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
stdlib@go1.26.3
1.25.11
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.25.11
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
stdlib@go1.26.3
1.25.11
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
stdlib@go1.26.3
1.25.11
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
stdlib@go1.26.3
1.25.11

Open the chart page →

2,959
aws-ec2-runtime-checkerrayselfs-chartsVerified publisher0.1.41 of 1See more

aws-ec2-runtime-checker rayselfs-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
rayselfs/aws-ec2-runtime-checker:v0.1.5562e5b2f81ce
stdlib@go1.24.11
1.25.11

Open the chart page →

295
thanosrayselfs-chartsVerified publisher0.1.51 of 1See more

thanos rayselfs-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.40.1aae7b2b030ed
stdlib@go1.25.3
1.25.11

Open the chart page →

769
saleorrc-helm-charts0.1.11 of 5See more

saleor rc-helm-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.22.0ca6b73330616
stdlib@go1.15.8
1.25.11

Open the chart page →

3,744
pagesrebecca-pages1.0.01 of 3See more

pages rebecca-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.11

Open the chart page →

20,573
recipe-apprecipe-app0.1.01 of 2See more

recipe-app recipe-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
stdlib@go1.20.12
1.25.11

Open the chart page →

3,703
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
sharanalwar/redchef-frontend:latest5e82950b16b7
stdlib@go1.23.7
1.25.11

Open the chart page →

5,010
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
stdlib@go1.15.14
1.25.11

Open the chart page →

15,427
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
stdlib@go1.15.14
1.25.11

Open the chart page →

15,427
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
stdlib@go1.15.14
1.25.11

Open the chart page →

11,556
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
stdlib@go1.21.3
1.25.11

Open the chart page →

16,600
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
stdlib@go1.16
1.25.11

Open the chart page →

29,803
redisredis-arm17.8.01 of 1See more

redis redis-arm 17.8.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/zcube/bitnami-compat/redis:7.0-debian-11-r55118a403046f7
stdlib@go1.19.4
1.25.11

Open the chart page →

1,910
redis-enforce-expireredis-enforce-expire1.0.01 of 1See more

redis-enforce-expire redis-enforce-expire 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
udhos/redis-enforce-expire:1.0.0615b6a7d742e
stdlib@go1.26.1
1.25.11

Open the chart page →

1,332
registry-credsregistry-creds0.2.31 of 1See more

registry-creds registry-creds 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/alexellis/registry-creds:0.3.2-rc1f5c72501e559
stdlib@go1.19.5
1.25.11

Open the chart page →

1,046
regoregoOfficialVerified publisher0.1.31 of 1See more

rego rego 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
drorivry4/rego:lateste035d49b15ca
stdlib@go1.22.0
1.25.11

Open the chart page →

3,049
longhornrelease-longhorn1.12.03 of 3See more

longhorn release-longhorn 1.12.0

3 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.12.0fd245bae2e82
stdlib@go1.25.10
1.25.11
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
stdlib@go1.26.3
1.25.11
longhornio/longhorn-ui:v1.12.03870d52a2b0a
stdlib@go1.25.10
1.25.11

Open the chart page →

1,647
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
stdlib@go1.21.9
1.25.11

Open the chart page →

6,318
reporting-chartreporting-application0.1.01 of 1See more

reporting-chart reporting-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ibarreche/cloud-reporting-ci:latest1f45af91da6a
stdlib@go1.16.15
1.25.11

Open the chart page →

1,586
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
reportportal/migrations:5.7.0da5d8e1395fe
stdlib@go1.13.6
1.25.11
reportportal/service-index:5.0.112b27a2d7a87d
stdlib@go1.17.1
1.25.11

Open the chart page →

25,906
resource-manager-operatorresource-manager-operator0.1.01 of 1See more

resource-manager-operator resource-manager-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/tikalk/resource-manager:latest7f21d50e69cb
stdlib@go1.19
1.25.11

Open the chart page →

1,619
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
stdlib@go1.24.6
1.25.11

Open the chart page →

4,630
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
stdlib@go1.20.12
1.25.11

Open the chart page →

7,462
spoolmanretsamedocVerified publisher26.9.01 of 1See more

spoolman retsamedoc 26.9.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.25.11

Open the chart page →

1,930
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
stdlib@go1.13.10
1.25.11

Open the chart page →

7,547
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
stdlib@go1.20.12
1.25.11

Open the chart page →

5,027
istio-fortiorgnu1.0.31 of 1See more

istio-fortio rgnu 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
fortio/fortio:latest_releasefc8221136fe2
stdlib@go1.23.9
1.25.11

Open the chart page →

563
whoamirgnu1.0.01 of 1See more

whoami rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
traefik/whoami:v1.6.0d38496bf0900
stdlib@go1.15.2
1.25.11

Open the chart page →

1,231
security-sample-chartrimusz0.2.11 of 3See more

security-sample-chart rimusz 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
rimusz/security-sample-app:0.2.0b9a178ca76ef
stdlib@go1.14.4
1.25.11

Open the chart page →

1,349
backup-maker-controllerriotkit-org0.1.21 of 1See more

backup-maker-controller riotkit-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-maker-controller:v0.1.262370545ba3d
stdlib@go1.19.4
1.25.11

Open the chart page →

1,571
haproxy-loadbalanced-redisrivals-spaceVerified publisher0.1.21 of 3See more

haproxy-loadbalanced-redis rivals-space 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
haproxytech/haproxy-alpine:2.6.614e4afa90dfd
stdlib@go1.19.3
1.25.11

Open the chart page →

1,432
flannelrke2-charts0.24.02 of 2See more

flannel rke2-charts 0.24.0

2 of the 2 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
rancher/hardened-cni-plugins:v1.2.0-build202401084f0fd4a0201c
stdlib@go1.20.7
1.25.11
rancher/hardened-flannel:v0.24.0-build20240108de22a17107b6
stdlib@go1.20.7
1.25.11

Open the chart page →

3,930
harvester-csi-driverrke2-charts0.1.32005 of 6See more

harvester-csi-driver rke2-charts 0.1.3200

5 of the 6 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
rancher/mirrored-longhornio-csi-attacher:v4.11.0-20260428fe417c28a6b8
stdlib@go1.25.9
1.25.11
rancher/mirrored-longhornio-csi-node-driver-registrar:v2.16.0-20260428e82a8c8f800d
stdlib@go1.25.9
1.25.11
rancher/mirrored-longhornio-csi-provisioner:v5.3.0-202604289e519a21a77c
stdlib@go1.25.9
1.25.11
rancher/mirrored-longhornio-csi-resizer:v2.1.0-2026042841cb674d1154
stdlib@go1.25.9
1.25.11
rancher/mirrored-longhornio-csi-snapshotter:v8.5.0-202604281975fac3890f
stdlib@go1.25.9
1.25.11

Open the chart page →

2,172
rancher-vsphere-cpirke2-charts1.16.2001 of 1See more

rancher-vsphere-cpi rke2-charts 1.16.200

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
rancher/mirrored-cloud-provider-vsphere:v1.31.1febfd0517838
stdlib@go1.22.8
1.25.11

Open the chart page →

919
rke2-calicorke2-charts3.18.1-1011 of 1See more

rke2-calico rke2-charts 3.18.1-101

1 of the 1 container images this version deploys carry CVE-2026-42507.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.15.1c6591da87aa8
stdlib@go1.15.2
1.25.11

Open the chart page →

2,245

Container images carrying it

4,906 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.11
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.11
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.11
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.11
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.11
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.11
1

syft 1.42.1 · advisories as of 28 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.