StackRadar

CVE-2026-46601

Unscored

Advisory

Published 18 Jun 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
123
of 17,781 indexed, latest versions
Container images
119
deployed by those charts
Fix available
1 of 1
affected package

Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image

Carried by container images the latest versions of 123 of 17,781 indexed charts deploy, on 119 images.

Affected packageAffected versionsFixed inImages
golang.org/x/imagegolangv0.0.0-20190802002840-cff245a6509b, v0.0.0-20191009234506-e7c1f5e7dbb8, v0.0.0-20201208152932-35266b937fa6, v0.0.0-20210216034530-4410531fe030+39 more0.43.0119
OSV records
GO-2026-5061

Charts affected

123 by stars
ChartLatestAffected imagesRadar Score
memosrm3lVerified publisher0.1.11 of 1See more

memos rm3l 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
neosmemo/memos:0.24c6defc2dfb98
golang.org/x/image@v0.27.0
0.43.0

Open the chart page →

1,614
imgproxyrock8sVerified publisher0.8.301 of 1See more

imgproxy rock8s 0.8.30

1 of the 1 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/image@v0.5.0
0.43.0

Open the chart page →

2,022
recipyartomik-helm-chartsVerified publisher0.0.21 of 2See more

recipya rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
reaper99/recipya:v1.2.27f7ec3aeb88c
golang.org/x/image@v0.18.0
0.43.0

Open the chart page →

2,066
memorubxkubeVerified publisher1.2.11 of 1See more

memo rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
neosmemo/memos:0.293e1253477066
golang.org/x/image@v0.39.0
0.43.0

Open the chart page →

555
rmfakecloudrubxkubeVerified publisher0.1.11 of 1See more

rmfakecloud rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
ddvk/rmfakecloud:latest2f5c45cbf0c5
golang.org/x/image@v0.18.0
0.43.0

Open the chart page →

498
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.43.0

Open the chart page →

5,582
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/image@v0.20.0
0.43.0

Open the chart page →

4,070
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
golang.org/x/image@v0.41.0
0.43.0

Open the chart page →

10,348
seaweedfs-operatorseaweedfs-operatorVerified publisher1.5.81 of 3See more

seaweedfs-operator seaweedfs-operator 1.5.8

1 of the 3 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
ghcr.io/nnstd/seaweedfs-operator:1.43ebe2fd253f6
golang.org/x/image@v0.29.0
0.43.0

Open the chart page →

2,092
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
golang.org/x/image@v0.18.0
0.43.0

Open the chart page →

3,286
tailscalesinextraVerified publisher0.18.11 of 2See more

tailscale sinextra 0.18.1

1 of the 2 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/tailscale:1.102.3d91287e83d1a
golang.org/x/image@v0.41.0
0.43.0

Open the chart page →

1,047
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.43.0

Open the chart page →

3,073
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/image@v0.28.0
0.43.0

Open the chart page →

2,540
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
golang.org/x/image@v0.18.0
0.43.0

Open the chart page →

2,396
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
golang.org/x/image@v0.22.0
0.43.0

Open the chart page →

8,193
agentssynapse0.1.302 of 9See more

agents synapse 0.1.30

2 of the 9 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.43.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.43.0

Open the chart page →

7,244
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
golang.org/x/image@v0.6.0
0.43.0

Open the chart page →

8,518
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
golang.org/x/image@v0.6.0
0.43.0

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.43.0

Open the chart page →

1,955
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/image@v0.25.0
0.43.0

Open the chart page →

45,239
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.43.0

Open the chart page →

3,174
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/image@v0.5.0
0.43.0

Open the chart page →

16,083
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-46601.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.43.0

Open the chart page →

1,960

Container images carrying it

119 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/image@v0.23.0
0.43.0
1
ghcr.io/nnstd/seaweedfs-operator:1.43ebe2fd253f6
golang.org/x/image@v0.29.0
0.43.0
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
golang.org/x/image@v0.27.0
0.43.0
1
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
golang.org/x/image@v0.39.0
0.43.0
1
ghcr.io/sergelogvinov/tailscale:1.102.3d91287e83d1a
golang.org/x/image@v0.41.0
0.43.0
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.43.0
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
golang.org/x/image@v0.6.0
0.43.0
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.43.0
1
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
golang.org/x/image@v0.6.0
0.43.0
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.43.0
1
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/image@v0.29.0
0.43.0
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
golang.org/x/image@v0.0.0-20210607152325-775e3b0c77b9
0.43.0
1
ghcr.io/usememos/memos:0.24.04723d86e6797
golang.org/x/image@v0.21.0
0.43.0
1
ghcr.io/zoriya/kyoo_transcoder:4.7.12dadea51a91e
golang.org/x/image@v0.23.0
0.43.0
1
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/image@v0.41.0
0.43.0
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/image@v0.21.0
0.43.0
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.43.0
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
golang.org/x/image@v0.20.0
0.43.0
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
golang.org/x/image@v0.20.0
0.43.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.