StackRadar

CVE-2026-49835

Medium

Advisory

Published 30 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
25
deployed by those charts
Fix available
1 of 2
affected packages

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
github.com/sigstore/timestamp-authoritygolangv1.1.1, v1.1.2, v1.2.2, v1.2.5+1 moreno fix listed13
github.com/sigstore/timestamp-authority/v2golangv2.0.3, v2.0.62.1.012
OSV records
GHSA-9c54-x2g4-v92j
Also known as
GO-2026-5851

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
harborharborOfficialVerified publisher1.19.21 of 8See more

harbor harbor 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0

Open the chart page →

1,650
artifact-hubartifact-hubVerified publisher1.23.02 of 7See more

artifact-hub artifact-hub 1.23.0

2 of the 7 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.1.0
artifacthub/scanner:v1.23.02d8365601f0e
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.1.0

Open the chart page →

10,755
falcofalcosecurity9.1.02 of 3See more

falco falcosecurity 9.1.0

2 of the 3 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.44.17df783d5269a
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0
falcosecurity/falcoctl:0.13.00eeb79adc580
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0

Open the chart page →

5,227
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
securesystemsengineering/connaisseur:v3.12.038918befbdad
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0

Open the chart page →

3,012
nuclionuclio0.23.81 of 2See more

nuclio nuclio 0.23.8

1 of the 2 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
quay.io/nuclio/dashboard:1.17.8-amd64b5f5bd4efbee
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0

Open the chart page →

963
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.1.0

Open the chart page →

3,997
policy-controllersigstoreVerified publisher0.10.71 of 2See more

policy-controller sigstore 0.10.7

1 of the 2 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
ghcr.io/sigstore/policy-controller/policy-controllerdigest-pinned0bcd60beb93f
github.com/sigstore/timestamp-authority@v1.2.5
no fix listed

Open the chart page →

911
finops-stackcert-managerVerified publisher0.0.56 of 12See more

finops-stack cert-manager 0.0.5

6 of the 12 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed

Open the chart page →

12,562
dockyarddockyardVerified publisher0.4.01 of 1See more

dockyard dockyard 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed

Open the chart page →

1,542
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.11 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/sigstore/timestamp-authority@v1.1.1
no fix listed

Open the chart page →

7,087
opikopikOfficialVerified publisher2.2.591 of 13See more

opik opik 2.2.59

1 of the 13 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
ghcr.io/comet-ml/opik/opik-python-backend:2.2.59269d0e55ea97
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0

Open the chart page →

14,334
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0

Open the chart page →

8,158
harborgpg-dev1.18.31 of 8See more

harbor gpg-dev 1.18.3

1 of the 8 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.1.0

Open the chart page →

3,376
harborhelm-harborVerified publisher2.3.51 of 8See more

harbor helm-harbor 2.3.5

1 of the 8 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0

Open the chart page →

1,650
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed

Open the chart page →

1,893
agent-control-cdnewrelic1.0.01 of 3See more

agent-control-cd newrelic 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed

Open the chart page →

5,034
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/sigstore/timestamp-authority@v1.1.2
no fix listed

Open the chart page →

8,599
sigstore-probersigstoreVerified publisher0.3.11 of 1See more

sigstore-prober sigstore 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0

Open the chart page →

424
tufsigstoreVerified publisher0.1.321 of 1See more

tuf sigstore 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/serverdigest-pinnedae8eb69c7b70
github.com/sigstore/timestamp-authority@v1.2.9
no fix listed

Open the chart page →

761
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-49835.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0

Open the chart page →

1,650

Container images carrying it

25 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0
3
aquasec/trivy:0.69.3bcc376de8d77
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.1.0
1
artifacthub/scanner:v1.23.02d8365601f0e
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.1.0
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/sigstore/timestamp-authority@v1.1.1
no fix listed
1
falcosecurity/falcoctl:0.13.00eeb79adc580
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.1.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0
1
securesystemsengineering/connaisseur:v3.12.038918befbdad
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0
1
ghcr.io/comet-ml/opik/opik-python-backend:2.2.59269d0e55ea97
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/sigstore/timestamp-authority@v1.2.2
no fix listed
1
ghcr.io/sigstore/policy-controller/policy-controller0bcd60beb93f
github.com/sigstore/timestamp-authority@v1.2.5
no fix listed
1
ghcr.io/sigstore/scaffolding/serverae8eb69c7b70
github.com/sigstore/timestamp-authority@v1.2.9
no fix listed
1
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/sigstore/timestamp-authority/v2@v2.0.3
2.1.0
1
quay.io/nuclio/dashboard:1.17.8-amd64b5f5bd4efbee
github.com/sigstore/timestamp-authority/v2@v2.0.6
2.1.0
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/sigstore/timestamp-authority@v1.1.2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.