StackRadar

CVE-2026-45022

High

Advisory

Published 11 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
161
of 17,781 indexed, latest versions
Container images
169
deployed by those charts
Fix available
1 of 1
affected package

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

Carried by container images the latest versions of 161 of 17,781 indexed charts deploy, on 169 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+21 more5.19.0169
OSV records
GHSA-389r-gv7p-r3rp
Also known as
GO-2026-5074

Charts affected

161 by stars
ChartLatestAffected imagesRadar Score
explorersynapse0.2.162 of 6See more

explorer synapse 0.2.16

2 of the 6 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/go-git/go-git/v5@v5.12.0
5.19.0
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.19.0

Open the chart page →

8,518
omnirpcsynapse0.2.921 of 2See more

omnirpc synapse 0.2.92

1 of the 2 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.19.0

Open the chart page →

1,121
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/go-git/go-git/v5@v5.5.2
5.19.0

Open the chart page →

1,704
screenersynapse0.2.51 of 4See more

screener synapse 0.2.5

1 of the 4 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
github.com/go-git/go-git/v5@v5.12.0
5.19.0

Open the chart page →

1,091
scribesynapse0.2.162 of 7See more

scribe synapse 0.2.16

2 of the 7 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.19.0
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
github.com/go-git/go-git/v5@v5.12.0
5.19.0

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
github.com/go-git/go-git/v5@v5.11.0
5.19.0

Open the chart page →

1,955
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
github.com/go-git/go-git/v5@v5.18.0
5.19.0

Open the chart page →

4,212
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/go-git/go-git/v5@v5.11.0
5.19.0

Open the chart page →

2,477
tfy-agenttruefoundryVerified publisher0.2.1031 of 5See more

tfy-agent truefoundry 0.2.103

1 of the 5 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v2.4.19440a40b3947
github.com/go-git/go-git/v5@v5.18.0
5.19.0

Open the chart page →

681
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/go-git/go-git/v5@v5.13.2
5.19.0

Open the chart page →

45,239
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-45022.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/go-git/go-git/v5@v5.16.0
5.19.0

Open the chart page →

969

Container images carrying it

169 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
github.com/go-git/go-git/v5@v5.16.2
5.19.0
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/go-git/go-git/v5@v5.7.0
5.19.0
1
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
github.com/go-git/go-git/v5@v5.16.5
5.19.0
1
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
github.com/go-git/go-git/v5@v5.16.0
5.19.0
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/go-git/go-git/v5@v5.11.0
5.19.0
1
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
github.com/go-git/go-git/v5@v5.16.0
5.19.0
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
github.com/go-git/go-git/v5@v5.14.0
5.19.0
1
quay.io/argoprojlabs/argocd-operator:v0.18.0a09814522a72
github.com/go-git/go-git/v5@v5.16.5
5.19.0
1
quay.io/argoprojlabs/argocd-rbac-operator:v0.2.451dded00137a
github.com/go-git/go-git/v5@v5.14.0
5.19.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/go-git/go-git/v5@v5.3.0
5.19.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/go-git/go-git/v5@v5.3.0
5.19.0
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/go-git/go-git/v5@v5.6.1
5.19.0
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/go-git/go-git/v5@v5.11.0
5.19.0
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
github.com/go-git/go-git/v5@v5.11.0
5.19.0
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/go-git/go-git/v5@v5.11.0
5.19.0
1
quay.io/operator-framework/catalogd:v1.8.06ff40fa6257f
github.com/go-git/go-git/v5@v5.16.5
5.19.0
1
quay.io/operator-framework/operator-controller:v1.8.0bca5dfcc67ca
github.com/go-git/go-git/v5@v5.16.5
5.19.0
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-git/go-git/v5@v5.3.0
5.19.0
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/go-git/go-git/v5@v5.16.2
5.19.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.