StackRadar

CVE-2026-46599

High

Advisory

Published 29 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,781 indexed, latest versions
Container images
111
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 111 images.

Affected packageAffected versionsFixed inImages
golang.org/x/imagegolangv0.0.0-20190802002840-cff245a6509b, v0.0.0-20191009234506-e7c1f5e7dbb8, v0.0.0-20201208152932-35266b937fa6, v0.0.0-20210216034530-4410531fe030+37 more0.41.0111
OSV records
GHSA-q675-qj96-32m9
Also known as
GO-2026-5032

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/image@v0.20.0
0.41.0

Open the chart page →

4,070
seaweedfs-operatorseaweedfs-operatorVerified publisher1.5.81 of 3See more

seaweedfs-operator seaweedfs-operator 1.5.8

1 of the 3 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
ghcr.io/nnstd/seaweedfs-operator:1.43ebe2fd253f6
golang.org/x/image@v0.29.0
0.41.0

Open the chart page →

2,092
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
golang.org/x/image@v0.18.0
0.41.0

Open the chart page →

3,286
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.41.0

Open the chart page →

3,073
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/image@v0.28.0
0.41.0

Open the chart page →

2,540
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
golang.org/x/image@v0.18.0
0.41.0

Open the chart page →

2,396
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
golang.org/x/image@v0.22.0
0.41.0

Open the chart page →

8,193
agentssynapse0.1.302 of 9See more

agents synapse 0.1.30

2 of the 9 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.41.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.41.0

Open the chart page →

7,244
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
golang.org/x/image@v0.6.0
0.41.0

Open the chart page →

8,518
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
golang.org/x/image@v0.6.0
0.41.0

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.41.0

Open the chart page →

1,955
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/image@v0.25.0
0.41.0

Open the chart page →

45,239
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.41.0

Open the chart page →

3,174
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/image@v0.5.0
0.41.0

Open the chart page →

16,083
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-46599.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.41.0

Open the chart page →

1,960

Container images carrying it

111 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
neosmemo/memos:0.30.071a5b4738d1b
golang.org/x/image@v0.39.0
0.41.0
3
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/image@v0.20.0
0.41.0
3
bloomberg/goldpinger:3.11.2a1fb87c2e9d9
golang.org/x/image@v0.35.0
0.41.0
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.41.0
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.41.0
2
listmonk/listmonk:latest:v6.2.0f535d59e1499
golang.org/x/image@v0.38.0
0.41.0
2
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
golang.org/x/image@v0.27.0
0.41.0
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/image@v0.25.0
0.41.0
2
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
golang.org/x/image@v0.22.0
0.41.0
2
apache/answer:2.0.2a0d71b0e30a5
golang.org/x/image@v0.20.0
0.41.0
1
artifacthub/hub:v1.19.0111918d8c399
golang.org/x/image@v0.10.0
0.41.0
1
artifacthub/hub:v1.23.07d3a91c539dc
golang.org/x/image@v0.25.0
0.41.0
1
artifacthub/scanner:v1.23.02d8365601f0e
golang.org/x/image@v0.25.0
0.41.0
1
artifacthub/scanner:v1.19.0323d026e78c3
golang.org/x/image@v0.10.0
0.41.0
1
artifacthub/tracker:v1.23.05368d21a6e5c
golang.org/x/image@v0.25.0
0.41.0
1
artifacthub/tracker:v1.19.06596c8c4d955
golang.org/x/image@v0.10.0
0.41.0
1
b3log/siyuan:v3.1.2595c0d129bc19
golang.org/x/image@v0.24.0
0.41.0
1
binrc/headcni:1.0.10e199c334b957
golang.org/x/image@v0.27.0
0.41.0
1
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
golang.org/x/image@v0.24.0
0.41.0
1
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/image@v0.13.0
0.41.0
1
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.41.0
1
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.41.0
1
casbin/casdoor:3.62.17729da148c61
golang.org/x/image@v0.18.0
0.41.0
1
casbin/casdoor:3.62.0e08231f16c00
golang.org/x/image@v0.18.0
0.41.0
1
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/image@v0.15.0
0.41.0
1
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/image@v0.11.0
0.41.0
1
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/image@v0.0.0-20210216034530-4410531fe030
0.41.0
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
golang.org/x/image@v0.18.0
0.41.0
1
cortezaproject/corteza:2024.9.08eb7a26605c9
golang.org/x/image@v0.15.0
0.41.0
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
golang.org/x/image@v0.18.0
0.41.0
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
golang.org/x/image@v0.31.0
0.41.0
1
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/image@v0.5.0
0.41.0
1
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/image@v0.21.0
0.41.0
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/image@v0.28.0
0.41.0
1
ddvk/rmfakecloud:latest2f5c45cbf0c5
golang.org/x/image@v0.18.0
0.41.0
1
deluan/navidrome:0.49.311a24da08977
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.41.0
1
deluan/navidrome:0.50.02cf4442b0099
golang.org/x/image@v0.14.0
0.41.0
1
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.41.0
1
deluan/navidrome:0.61.29fa40b3d8dec
golang.org/x/image@v0.38.0
0.41.0
1
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/image@v0.18.0
0.41.0
1
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.41.0
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.41.0
1
flashcatcloud/nightingale:8.5.1421acb36181b
golang.org/x/image@v0.18.0
0.41.0
1
fortio/fortio:latest_releasefc8221136fe2
golang.org/x/image@v0.27.0
0.41.0
1
gitea/gitea:1.22.376f516a1a8c2
golang.org/x/image@v0.18.0
0.41.0
1
gitea/gitea:1.26.27d13848af126
golang.org/x/image@v0.38.0
0.41.0
1
gitea/gitea:1.21.6ac73e0da341f
golang.org/x/image@v0.13.0
0.41.0
1
gotenberg/gotenberg:8.30206a6c708fc6
golang.org/x/image@v0.32.0
0.41.0
1
gotenberg/gotenberg:8.3467097317623a
golang.org/x/image@v0.39.0
0.41.0
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
golang.org/x/image@v0.27.0
0.41.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.