CVE-2026-44740
MediumAdvisory
Published 13 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.004
- 32nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 167
- of 17,781 indexed, latest versions
- Container images
- 176
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion
Carried by container images the latest versions of 167 of 17,781 indexed charts deploy, on 176 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v5.0.0, v5.1.0, v5.3.1, v5.4.0+7 more | 5.9.0 | 175 |
| github.com/ | v6.0.0-20250711053805-c1f149aaab07 | 6.0.0-alpha.1 | 1 |
- OSV records
- GHSA-m3xc-h892-ggx6
- Also known as
- GO-2026-5490
Charts affected
167 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| sn-platform-slimstreamnative | 1.11.44 | 1 of 6See more | 10,134 |
| grafanasvtech-public-helm-charts | 1.0.0 | 1 of 2See more | 10,902 |
| switchbladeswitchblade | 0.0.19 | 1 of 1See more | 1,360 |
| agentssynapse | 0.1.30 | 3 of 9See more | 7,244 |
| cctpsynapse | 0.3.0 | 1 of 4See more | 1,815 |
| explorersynapse | 0.2.16 | 2 of 6See more | 8,518 |
| omnirpcsynapse | 0.2.92 | 1 of 2See more | 1,121 |
| promexportersynapse | 0.1.1 | 1 of 1See more | 1,704 |
| screenersynapse | 0.2.5 | 1 of 4See more | 1,091 |
| scribesynapse | 0.2.16 | 2 of 7See more | 2,680 |
| sinnersynapse | 0.1.0 | 1 of 6See more | 1,955 |
| act-runnertektonops | 0.1.2 | 1 of 2See more | 4,212 |
| owncloudth-chartsVerified publisher | 0.2.1 | 1 of 1See more | 10,006 |
| harbor-scanner-trivytrivy-operator | 0.31.2 | 1 of 1See more | 2,477 |
| tfy-agenttruefoundryVerified publisher | 0.2.103 | 1 of 5See more | 681 |
| opencloudunxwaresVerified publisher | 0.2.3 | 1 of 13See more | 45,239 |
| argo-eventswenerme | 2.4.27 | 1 of 1See more | 969 |
Container images carrying it
176 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 5e0a3dfa9f96 | github.com/ | 5.9.0 | 1 |
| ghcr.io/ | 81edba952403 | github.com/ | 5.9.0 | 1 |
| ghcr.io/ | 3e98a98f6074 | github.com/ | 5.9.0 | 1 |
| public.ecr.aws/ | 01d8413d5075 | github.com/ | 5.9.0 | 1 |
| public.ecr.aws/ | e97e0e7a2088 | github.com/ | 5.9.0 | 1 |
| quay.io/ | 5b6701d8fb31 | github.com/ | 5.9.0 | 1 |
| quay.io/ | 95b5cf7ba6fe | github.com/ | 5.9.0 | 1 |
| quay.io/ | a36ab0c0860c | github.com/ | 5.9.0 | 1 |
| quay.io/ | acaf37352569 | github.com/ | 5.9.0 | 1 |
| quay.io/ | 577fc18f86ad | github.com/ | 5.9.0 | 1 |
| quay.io/ | 6efd1cb89dc1 | github.com/ | 5.9.0 | 1 |
| quay.io/ | 91b9825f09a8 | github.com/ | 5.9.0 | 1 |
| quay.io/ | a83d2699ae53 | github.com/ | 5.9.0 | 1 |
| quay.io/ | 3c56f354fac5 | github.com/ | 5.9.0 | 1 |
| quay.io/ | a09814522a72 | github.com/ | 5.9.0 | 1 |
| quay.io/ | 51dded00137a | github.com/ | 5.9.0 | 1 |
| quay.io/ | d6fd2a9e3273 | github.com/ | 5.9.0 | 1 |
| quay.io/ | 13aaae779248 | github.com/ | 5.9.0 | 1 |
| quay.io/ | d7d93debf1f4 | github.com/ | 5.9.0 | 1 |
| quay.io/ | ec6ab507c5da | github.com/ | 5.9.0 | 1 |
| quay.io/ | ebba936046ab | github.com/ | 5.9.0 | 1 |
| quay.io/ | c241c971aef8 | github.com/ | 5.9.0 | 1 |
| quay.io/ | 6ff40fa6257f | github.com/ | 5.9.0 | 1 |
| quay.io/ | bca5dfcc67ca | github.com/ | 5.9.0 | 1 |
| quay.io/ | 7b4202c25b67 | github.com/ | 5.9.0 | 1 |
| registry.gitlab.com/ | 9b9d1ed86b6a | github.com/ | 5.9.0 | 1 |