StackRadar

CVE-2026-46603

Unscored

Advisory

Published 14 Aug 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
155
of 17,781 indexed, latest versions
Container images
144
deployed by those charts
Fix available
1 of 1
affected package

Excessive memory allocation during VP8L decoding in golang.org/x/image

Carried by container images the latest versions of 155 of 17,781 indexed charts deploy, on 144 images.

Affected packageAffected versionsFixed inImages
golang.org/x/imagegolangv0.0.0-20190802002840-cff245a6509b, v0.0.0-20191009234506-e7c1f5e7dbb8, v0.0.0-20201208152932-35266b937fa6, v0.0.0-20210216034530-4410531fe030+41 more0.45.0144
OSV records
GO-2026-6222

Charts affected

155 by stars
ChartLatestAffected imagesRadar Score
tyk-stacktyk-helm5.3.02 of 7See more

tyk-stack tyk-helm 5.3.0

2 of the 7 container images this version deploys carry CVE-2026-46603.

Container imageDigestPackageFixed in
tykio/tyk-dashboard:v5.13.10e03b94c153d
golang.org/x/image@v0.43.0
0.45.0
tykio/tyk-gateway-ee:v5.13.13e907e675bf9
golang.org/x/image@v0.43.0
0.45.0

Open the chart page →

2,875
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-46603.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/image@v0.25.0
0.45.0

Open the chart page →

45,239
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46603.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.45.0

Open the chart page →

3,174
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-46603.

Container imageDigestPackageFixed in
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/image@v0.5.0
0.45.0

Open the chart page →

16,083
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-46603.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.45.0

Open the chart page →

1,960

Container images carrying it

144 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.45.0
1
filebrowser/filebrowser:v2.63.15-s6dbac07403040
golang.org/x/image@v0.42.0
0.45.0
1
flashcatcloud/nightingale:8.5.1421acb36181b
golang.org/x/image@v0.18.0
0.45.0
1
fortio/fortio:latest_releasefc8221136fe2
golang.org/x/image@v0.27.0
0.45.0
1
garethgeorge/backrest:v1.14.1b85297975428
golang.org/x/image@v0.43.0
0.45.0
1
gitea/gitea:1.27.3-rootless1c17ecaead42
golang.org/x/image@v0.43.0
0.45.0
1
gitea/gitea:1.27.134e3f6b75f5c
golang.org/x/image@v0.43.0
0.45.0
1
gitea/gitea:1.22.376f516a1a8c2
golang.org/x/image@v0.18.0
0.45.0
1
gitea/gitea:1.26.27d13848af126
golang.org/x/image@v0.38.0
0.45.0
1
gitea/gitea:1.27.387a67ee09d3a
golang.org/x/image@v0.43.0
0.45.0
1
gitea/gitea:1.21.6ac73e0da341f
golang.org/x/image@v0.13.0
0.45.0
1
gotenberg/gotenberg:8.30206a6c708fc6
golang.org/x/image@v0.32.0
0.45.0
1
gotenberg/gotenberg:8.3467097317623a
golang.org/x/image@v0.39.0
0.45.0
1
gotenberg/gotenberg:8-chromiuma40f92d7419a
golang.org/x/image@v0.44.0
0.45.0
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
golang.org/x/image@v0.27.0
0.45.0
1
instill/model-backend:611f0f2e980125e5ba5
golang.org/x/image@v0.19.0
0.45.0
1
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.45.0
1
langgenius/dify-api:1.16.1dcefa5f7c47c
golang.org/x/image@v0.43.0
0.45.0
1
listmonk/listmonk:v6.0.0bf3903d54a46
golang.org/x/image@v0.29.0
0.45.0
1
livekit/ingress:v1.2.21ab01641b366
golang.org/x/image@v0.14.0
0.45.0
1
maponyacharles/sceptreai:seaweedfs-0.1.127c8a525f08e9
golang.org/x/image@v0.43.0
0.45.0
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.45.0
1
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.45.0
1
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.45.0
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.45.0
1
mattermost/mattermost-enterprise-edition:11.7ca5e5553a767
golang.org/x/image@v0.44.0
0.45.0
1
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/image@v0.5.0
0.45.0
1
miniflux/miniflux:2.3.349d7b6098761
golang.org/x/image@v0.44.0
0.45.0
1
miniflux/miniflux:2.2.18a3ca6bbc1f74
golang.org/x/image@v0.37.0
0.45.0
1
neosmemo/memos:0.293e1253477066
golang.org/x/image@v0.39.0
0.45.0
1
neosmemo/memos:0.26.23eefcc231141
golang.org/x/image@v0.30.0
0.45.0
1
neosmemo/memos:0.24c6defc2dfb98
golang.org/x/image@v0.27.0
0.45.0
1
opencloudeu/opencloud:7.2.46d992ccc5f1c
golang.org/x/image@v0.40.0
0.45.0
1
opencsghq/csghub-portal:v2.4.0-ee93ad59164d87
golang.org/x/image@v0.28.0
0.45.0
1
openmined/syft-seaweedfs:0.9.53a4144c0bb82
golang.org/x/image@v0.15.0
0.45.0
1
owncloud/ocis:7.1.388e7c854517d
golang.org/x/image@v0.22.0
0.45.0
1
owncloud/ocis:8.0.1b38fd8fdd58f
golang.org/x/image@v0.32.0
0.45.0
1
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.45.0
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/image@v0.8.0
0.45.0
1
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.45.0
1
photoprism/photoprism:231128-ce284de9cc4f9c
golang.org/x/image@v0.14.0
0.45.0
1
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/image@v0.0.0-20220617043117-41969df76e82
0.45.0
1
photoprism/photoprism:260601650c6ad5a651
golang.org/x/image@v0.41.0
0.45.0
1
photoprism/photoprism:260728958642220223
golang.org/x/image@v0.44.0
0.45.0
1
photoprism/photoprism:251130db16ee6b1ba3
golang.org/x/image@v0.33.0
0.45.0
1
photoprism/photoprism:240711-cefc6fd632ca74
golang.org/x/image@v0.18.0
0.45.0
1
reaper99/recipya:v1.2.27f7ec3aeb88c
golang.org/x/image@v0.18.0
0.45.0
1
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.45.0
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.45.0
1
stashapp/stash:latest24dbd7607174
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.45.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.