StackRadar

CVE-2026-56852

Unscored

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,357
of 17,805 indexed, latest versions
Container images
4,075
deployed by those charts
Fix available
1 of 1
affected package

Infinite loop on invalid input in golang.org/x/text

Carried by container images the latest versions of 3,357 of 17,805 indexed charts deploy, on 4,075 images.

Affected packageAffected versionsFixed inImages
golang.org/x/textgolangv0.3.0, v0.3.1-0.20180807135948-17ff2d5776d2, v0.3.1-0.20181227161524-e6919f6577db, v0.3.2+44 more0.39.04,075
OSV records
GO-2026-5970

Charts affected

3,357 by stars
ChartLatestAffected imagesRadar Score
ddns-kubernetes-controllerddns-kubernetes-controller0.1.01 of 1See more

ddns-kubernetes-controller ddns-kubernetes-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
golang.org/x/text@v0.5.0
0.39.0

Open the chart page →

971
kube-better-nodedecayofmind0.0.41 of 1See more

kube-better-node decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
golang.org/x/text@v0.3.4
0.39.0

Open the chart page →

1,584
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
defactops/defactops-ui:1.0.16825cdf9ba706
golang.org/x/text@v0.15.0
0.39.0

Open the chart page →

4,576
symfony-appdefault-ghVerified publisher0.6.51 of 3See more

symfony-app default-gh 0.6.5

1 of the 3 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
alpine/git:2.36.366b210a97bc0
golang.org/x/text@v0.3.7
0.39.0

Open the chart page →

5,124
csi-driver-smbdeimosfr-charts1.20.35 of 5See more

csi-driver-smb deimosfr-charts 1.20.3

5 of the 5 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/text@v0.37.0
0.39.0
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/text@v0.37.0
0.39.0
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/text@v0.33.0
0.39.0
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/text@v0.37.0
0.39.0
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
golang.org/x/text@v0.38.0
0.39.0

Open the chart page →

3,022
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/text@v0.3.7
0.39.0

Open the chart page →

2,242
field-exporterdeliveryheroVerified publisher1.4.11 of 1See more

field-exporter deliveryhero 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
ghcr.io/deliveryhero/field-exporter:v1.4.06b71ba4f9297
golang.org/x/text@v0.16.0
0.39.0

Open the chart page →

471
k8s-cloudwatch-adapterdeliveryheroVerified publisher0.2.21 of 1See more

k8s-cloudwatch-adapter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/text@v0.3.2
0.39.0

Open the chart page →

2,476
prometheus-dellhw-exporterdellhw-exporterVerified publisher1.3.01 of 1See more

prometheus-dellhw-exporter dellhw-exporter 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0b3a5806d73b5
golang.org/x/text@v0.32.0
0.39.0

Open the chart page →

1,883
kubeteach-coredergeberl0.2.31 of 1See more

kubeteach-core dergeberl 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
golang.org/x/text@v0.4.0
0.39.0

Open the chart page →

1,505
kubeteach-exerciseset1dergeberl0.2.31 of 2See more

kubeteach-exerciseset1 dergeberl 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
golang.org/x/text@v0.4.0
0.39.0

Open the chart page →

1,505
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
golang.org/x/text@v0.3.7
0.39.0

Open the chart page →

76,730
clamav-apidevhatVerified publisher1.0.11 of 1See more

clamav-api devhat 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
golang.org/x/text@v0.15.0
0.39.0

Open the chart page →

2,246
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
golang.org/x/text@v0.3.7
0.39.0
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
golang.org/x/text@v0.3.7
0.39.0

Open the chart page →

4,736
devopsweeklydevopsweekly2.1.01 of 1See more

devopsweekly devopsweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
zufardhiyaulhaq/devopsweekly:v2.1.046625567fb60
golang.org/x/text@v0.3.7
0.39.0

Open the chart page →

1,218
lxd8sdevplayer0Verified publisher0.5.12 of 2See more

lxd8s devplayer0 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/text@v0.3.6
0.39.0
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
golang.org/x/text@v0.3.3
0.39.0

Open the chart page →

5,432
octolxddevplayer0Verified publisher0.1.11 of 1See more

octolxd devplayer0 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
golang.org/x/text@v0.3.5
0.39.0

Open the chart page →

2,525
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/text@v0.16.0
0.39.0

Open the chart page →

9,771
argocddevtron1.8.12 of 3See more

argocd devtron 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/text@v0.3.2
0.39.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/text@v0.3.2
0.39.0

Open the chart page →

10,486
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/text@v0.5.0
0.39.0

Open the chart page →

13,204
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/text@v0.8.0
0.39.0

Open the chart page →

1,587
caddy-reverse-proxydevtron0.10.11 of 1See more

caddy-reverse-proxy devtron 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
library/caddy:latest13ba145cba2f
golang.org/x/text@v0.37.0
0.39.0

Open the chart page →

863
devtron-enterprisedevtron48.0.017 of 28See more

devtron-enterprise devtron 48.0.0

17 of the 28 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/text@v0.3.7
0.39.0
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
golang.org/x/text@v0.33.0
0.39.0
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
golang.org/x/text@v0.25.0
0.39.0
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/text@v0.3.6
0.39.0
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/text@v0.13.0
0.39.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/text@v0.3.4
0.39.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/text@v0.3.4
0.39.0
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/text@v0.9.0
0.39.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/text@v0.3.7
0.39.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/text@v0.3.6
0.39.0
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/text@v0.17.0
0.39.0

Open the chart page →

69,641
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/text@v0.3.4
0.39.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/text@v0.8.0
0.39.0

Open the chart page →

5,057
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/text@v0.8.0
0.39.0

Open the chart page →

4,993
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/text@v0.3.6
0.39.0

Open the chart page →

12,000
jcmhproxy-ingressdevtron0.14.61 of 1See more

jcmhproxy-ingress devtron 0.14.6

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/text@v0.14.0
0.39.0

Open the chart page →

1,379
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/text@v0.3.6
0.39.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/text@v0.3.6
0.39.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/text@v0.3.6
0.39.0

Open the chart page →

8,661
migrantdevtron0.0.31 of 1See more

migrant devtron 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
migrate/migrate:latest76cc2074cb66
golang.org/x/text@v0.38.0
0.39.0

Open the chart page →

114
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/text@v0.3.7
0.39.0

Open the chart page →

2,442
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/text@v0.3.7
0.39.0

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/text@v0.6.0
0.39.0

Open the chart page →

1,514
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/text@v0.16.0
0.39.0

Open the chart page →

9,771
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/text@v0.3.2
0.39.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/text@v0.3.2
0.39.0

Open the chart page →

10,486
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/text@v0.5.0
0.39.0

Open the chart page →

13,204
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/text@v0.8.0
0.39.0

Open the chart page →

1,587
caddy-reverse-proxydevtron-labs0.10.11 of 1See more

caddy-reverse-proxy devtron-labs 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
library/caddy:latestdf7f1c2fb114
golang.org/x/text@v0.37.0
0.39.0

Open the chart page →

863
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/text@v0.3.4
0.39.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/text@v0.3.4
0.39.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/text@v0.3.4
0.39.0

Open the chart page →

10,097
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/text@v0.3.6
0.39.0

Open the chart page →

6,239
devtron-enterprisedevtron-labs48.0.017 of 28See more

devtron-enterprise devtron-labs 48.0.0

17 of the 28 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/text@v0.3.7
0.39.0
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
golang.org/x/text@v0.33.0
0.39.0
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
golang.org/x/text@v0.25.0
0.39.0
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/text@v0.3.6
0.39.0
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/text@v0.13.0
0.39.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/text@v0.3.4
0.39.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/text@v0.3.4
0.39.0
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/text@v0.9.0
0.39.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/text@v0.3.7
0.39.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/text@v0.3.6
0.39.0
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/text@v0.17.0
0.39.0

Open the chart page →

69,641
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/text@v0.3.4
0.39.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/text@v0.8.0
0.39.0

Open the chart page →

5,057
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/text@v0.8.0
0.39.0

Open the chart page →

4,993
devtron-operatordevtron-labs0.23.38 of 11See more

devtron-operator devtron-labs 0.23.3

8 of the 11 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/text@v0.3.7
0.39.0
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/text@v0.33.0
0.39.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/text@v0.3.6
0.39.0
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/text@v0.3.4
0.39.0
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/text@v0.32.0
0.39.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/text@v0.9.0
0.39.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/text@v0.3.6
0.39.0

Open the chart page →

33,387
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/text@v0.3.6
0.39.0

Open the chart page →

12,000
jcmhproxy-ingressdevtron-labs0.14.61 of 1See more

jcmhproxy-ingress devtron-labs 0.14.6

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/text@v0.14.0
0.39.0

Open the chart page →

1,379
kube-prometheus-stackdevtron-labs19.3.03 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

3 of the 6 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/text@v0.3.6
0.39.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/text@v0.3.6
0.39.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/text@v0.3.6
0.39.0

Open the chart page →

8,661
migrantdevtron-labs0.0.31 of 1See more

migrant devtron-labs 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
migrate/migrate:latestcc4ad8e19d66
golang.org/x/text@v0.31.0
0.39.0

Open the chart page →

743
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/text@v0.3.7
0.39.0

Open the chart page →

2,442
winter-soldierdevtron-labs0.10.61 of 1See more

winter-soldier devtron-labs 0.10.6

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/text@v0.3.7
0.39.0

Open the chart page →

1,176
zincdevtron-labs0.1.21 of 1See more

zinc devtron-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56852.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/text@v0.6.0
0.39.0

Open the chart page →

1,514

Container images carrying it

4,075 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gcr.io/kaniko-project/executor:latest4e7a52dd1f14
golang.org/x/text@v0.25.0
0.39.0
1
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
golang.org/x/text@v0.31.0
0.39.0
1
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/filterd675f211a40f
golang.org/x/text@v0.19.0
0.39.0
1
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/ingressec4b544499ba
golang.org/x/text@v0.19.0
0.39.0
1
gcr.io/knative-releases/knative.dev/eventing/cmd/mtchannel_broker395f4ff1bd34
golang.org/x/text@v0.19.0
0.39.0
1
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhook873b968f02b5
golang.org/x/text@v0.3.2
0.39.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.13.1a5b041ba3c9e
golang.org/x/text@v0.14.0
0.39.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllere70bc675f977
golang.org/x/text@v0.19.0
0.39.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook7d76a6d42d13
golang.org/x/text@v0.19.0
0.39.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.13.1f066376eee17
golang.org/x/text@v0.14.0
0.39.0
1
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourier15a601147ef4
golang.org/x/text@v0.24.0
0.39.0
1
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourier197fbb71d1f1
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/operator/cmd/operator:v1.22.3733f21dc06f9
golang.org/x/text@v0.36.0
0.39.0
1
gcr.io/knative-releases/knative.dev/operator/cmd/webhook:v1.22.366ae76179a80
golang.org/x/text@v0.36.0
0.39.0
1
gcr.io/knative-releases/knative.dev/operator/cmd/webhook6c5c90cdf707
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator08315309da4b
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator1e3db4f2eeed
golang.org/x/text@v0.3.3
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.13.121f8e11a44bf
golang.org/x/text@v0.14.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activatora5de0fb75046
golang.org/x/text@v0.3.2
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.10.2c2994c2b6c2c
golang.org/x/text@v0.7.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler105bdd14ecaa
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler2ef460356b17
golang.org/x/text@v0.3.2
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.13.134796e9f760b
golang.org/x/text@v0.14.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.10.28319aa662b49
golang.org/x/text@v0.7.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdb6ceff2aab4
golang.org/x/text@v0.3.3
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa:v1.10.2eb612b929eaa
golang.org/x/text@v0.7.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller30ce73388ae5
golang.org/x/text@v0.3.2
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.13.153d9aa4d2c7a
golang.org/x/text@v0.14.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
golang.org/x/text@v0.7.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerb2cd45b8a8a4
golang.org/x/text@v0.3.3
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerbac158dfb0c7
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/default-domain5e0429b70299
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mappinge384a295069b
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.10.2f66c41ad7a73
golang.org/x/text@v0.7.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook15f1ce7f35b4
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.10.27368aaddf2be
golang.org/x/text@v0.7.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook1282a399cbb9
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.10.24305209ce498
golang.org/x/text@v0.7.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.13.1700c69915dc7
golang.org/x/text@v0.14.0
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
golang.org/x/text@v0.3.7
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookd27b4495ccc3
golang.org/x/text@v0.3.3
0.39.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookf16c0e022203
golang.org/x/text@v0.3.2
0.39.0
1
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
golang.org/x/text@v0.21.0
0.39.0
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.