StackRadar

CVE-2026-56854

Unscored

Advisory

Published 28 Aug 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,873
of 17,792 indexed, latest versions
Container images
3,219
deployed by those charts
Fix available
2 of 2
affected packages

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

Carried by container images the latest versions of 2,873 of 17,792 indexed charts deploy, on 3,219 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+156 more0.55.03,219
kubernetes-1.34apk1.34.11-r21.34.11-r31
OSV records
CGA-4wg8-vwxq-5g46GO-2026-6303
Also known as
CGA-548p-j75q-3522, CGA-7fgq-fgg6-f7cr, CGA-8q6m-f35p-p88g, CGA-9xqw-wrfv-3c6w, CGA-fmc9-vwrf-6jq2, CGA-h33c-jrc2-36rr, CGA-jqcq-hwv9-6wwp, CGA-mc7r-3393-487f, CGA-p3hc-qw8w-gf4f, CGA-qf3x-28f7-2hcw, CGA-w35x-xg67-9c7c

Charts affected

2,873 by stars
ChartLatestAffected imagesRadar Score
kube-vipkube-vip0.11.11 of 1See more

kube-vip kube-vip 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/kube-vip/kube-vip:v1.2.32fcdbb014a2e
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

125
linkerd-vizlinkerd2-edgeVerified publisher30.14.11-edge1 of 5See more

linkerd-viz linkerd2-edge 30.14.11-edge

1 of the 5 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/crypto@v0.14.0
0.55.0

Open the chart page →

1,353
plane-cemakeplaneOfficialVerified publisher1.8.12 of 11See more

plane-ce makeplane 1.8.1

2 of the 11 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
golang.org/x/crypto@v0.40.0
0.55.0
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
golang.org/x/crypto@v0.40.0
0.55.0

Open the chart page →

4,885
milvusmilvus-helm5.0.282 of 4See more

milvus milvus-helm 5.0.28

2 of the 4 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.25-r1fededb2f2d63
golang.org/x/crypto@v0.36.0
0.55.0
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/crypto@v0.27.0
0.55.0

Open the chart page →

10,782
opa-kube-mgmtopa-kube-mgmtVerified publisher11.0.121 of 2See more

opa-kube-mgmt opa-kube-mgmt 11.0.12

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
openpolicyagent/opa:1.19.0852359995443
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

609
s3-proxyoxyno-zetaVerified publisher2.28.01 of 1See more

s3-proxy oxyno-zeta 2.28.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
oxynozeta/s3-proxy:5.1.121115040e224
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

183
spirespiffeVerified publisher0.30.23 of 10See more

spire spiffe 0.30.2

3 of the 10 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/spiffe/oidc-discovery-provider:1.15.3bb95f13c2b4e
golang.org/x/crypto@v0.54.0
0.55.0
ghcr.io/spiffe/spire-agent:1.15.341b0dcd8b258
golang.org/x/crypto@v0.54.0
0.55.0
ghcr.io/spiffe/spire-server:1.15.34082f30d3e0d
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

1,684
wireguardwireguardVerified publisher0.32.01 of 3See more

wireguard wireguard 0.32.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-wireguard-mgr:main4c575d037ef2
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

171
bytebasebytebase1.1.51 of 1See more

bytebase bytebase 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
bytebase/bytebase:latest9fcde38c0d5f
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

443
cert-manager-csi-drivercert-managerOfficialVerified publisher0.16.01 of 3See more

cert-manager-csi-driver cert-manager 0.16.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-csi-driver:v0.16.09d13db6dc80e
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

507
ansible-semaphorecloudhippieVerified publisher15.2.101 of 1See more

ansible-semaphore cloudhippie 15.2.10

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.19.1498ad9bc7a2a0
golang.org/x/crypto@v0.35.0
0.55.0

Open the chart page →

1,242
etcdcloudpirates-etcdVerified publisher0.8.81 of 1See more

etcd cloudpirates-etcd 0.8.8

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
gcr.io/etcd-development/etcd:v3.7.1a9983dd6d928
golang.org/x/crypto@v0.52.0
0.55.0

Open the chart page →

135
codefreshcodefresh-onpremOfficialVerified publisher2.12.145 of 42See more

codefresh codefresh-onprem 2.12.14

5 of the 42 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
golang.org/x/crypto@v0.41.0
0.55.0
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
golang.org/x/crypto@v0.25.0
0.55.0
bitnamilegacy/nats:2.11.8-debian-12-r0fa0cfba6034a
golang.org/x/crypto@v0.41.0
0.55.0
ghcr.io/helm/chartmuseum:v0.16.648bc27743c08
golang.org/x/crypto@v0.53.0
0.55.0
quay.io/codefresh/dind:3.0.250885ab519dac
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

15,093
couchbase-operatorcouchbaseVerified publisher2.93.02 of 2See more

couchbase-operator couchbase 2.93.0

2 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
couchbase/admission-controller:2.9.3bf2d2e87e45f
golang.org/x/crypto@v0.41.0
0.55.0
couchbase/operator:2.9.369a385b49e1f
golang.org/x/crypto@v0.41.0
0.55.0

Open the chart page →

754
eck-exporterenixVerified publisher1.14.01 of 1See more

eck-exporter enix 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

89
gitlab-operatorgitlabVerified publisher3.3.21 of 1See more

gitlab-operator gitlab 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:3.3.242dd426130a9
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

152
loki-simple-scalablegrafana1.8.112 of 3See more

loki-simple-scalable grafana 1.8.11

2 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.55.0
grafana/loki:2.6.11ee60f980950
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.55.0

Open the chart page →

6,484
kube-prometheus-stackkube-prometheus-stack-oci91.4.13 of 6See more

kube-prometheus-stack kube-prometheus-stack-oci 91.4.1

3 of the 6 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
grafana/grafana:13.2.2-distroless69a5d2d957ca
golang.org/x/crypto@v0.52.0
0.55.0
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/crypto@v0.54.0
0.55.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

655
lakefslakefsVerified publisher1.12.301 of 1See more

lakefs lakefs 1.12.30

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
treeverse/lakefs:1.86.0fb7a0d90f77e
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

403
adguard-homerm3lVerified publisher0.24.11 of 2See more

adguard-home rm3l 0.24.1

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.513a143e6c071c
golang.org/x/crypto@v0.23.0
0.55.0

Open the chart page →

1,149
spegelspegelVerified publisher0.7.41 of 1See more

spegel spegel 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/spegel-org/spegeldigest-pinned26c60b05e08a
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

188
supabasetokens-studioVerified publisher1.0.02 of 14See more

supabase tokens-studio 1.0.0

2 of the 14 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/crypto@v0.28.0
0.55.0
supabase/gotrue:v2.163.0ba4ddc594b0b
golang.org/x/crypto@v0.26.0
0.55.0

Open the chart page →

23,365
prometheus-operatorarldkaVerified publisher13.0.11 of 2See more

prometheus-operator arldka 13.0.1

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.73.204f2b98d71ef
golang.org/x/crypto@v0.21.0
0.55.0

Open the chart page →

2,108
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
golang.org/x/crypto@v0.48.0
0.55.0

Open the chart page →

8,586
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.55.0

Open the chart page →

3,005
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
golang.org/x/crypto@v0.40.0
0.55.0

Open the chart page →

10,856
kube-prometheuschoerodon9.3.14 of 7See more

kube-prometheus choerodon 9.3.1

4 of the 7 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/crypto@v0.0.0-20200406173513-056763e48d71
0.55.0
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/crypto@v0.0.0-20181203042331-505ab145d0a9
0.55.0
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/crypto@v0.0.0-20191002192127-34f69633bfdc
0.55.0
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.55.0

Open the chart page →

12,251
timescaledbcloudpirates-timescaledbVerified publisher0.13.101 of 1See more

timescaledb cloudpirates-timescaledb 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
timescale/timescaledb:2.30.0-pg173113d12b7839
golang.org/x/crypto@v0.32.0
0.55.0

Open the chart page →

622
csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher1.8.21 of 5See more

csi-secrets-store-provider-azure csi-secrets-store-provider-azure 1.8.2

1 of the 5 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
golang.org/x/crypto@v0.46.0
0.55.0

Open the chart page →

2,263
minifluxgabe565Verified publisher0.9.21 of 2See more

miniflux gabe565 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/crypto@v0.32.0
0.55.0

Open the chart page →

1,247
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.24.061d866e93b56
golang.org/x/crypto@v0.8.0
0.55.0

Open the chart page →

3,048
waypointhashicorpVerified publisher0.1.211 of 2See more

waypoint hashicorp 0.1.21

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
hashicorp/waypoint:0.11.397d521a27498
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.55.0

Open the chart page →

4,176
jaeger-all-in-onejaeger-all-in-oneVerified publisher0.1.121 of 1See more

jaeger-all-in-one jaeger-all-in-one 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.55f6b5d09073f1
golang.org/x/crypto@v0.19.0
0.55.0

Open the chart page →

1,223
etcdkubelauncherVerified publisher0.4.31 of 1See more

etcd kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinned8ab954711fb9
golang.org/x/crypto@v0.52.0
0.55.0

Open the chart page →

818
mongodbkubelauncherVerified publisher0.4.51 of 1See more

mongodb kubelauncher 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinned9bc37ed78a8b
golang.org/x/crypto@v0.45.0
0.55.0

Open the chart page →

1,386
mauticone-acre-fundVerified publisher0.1.71 of 3See more

mautic one-acre-fund 0.1.7

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/crypto@v0.45.0
0.55.0

Open the chart page →

2,667
prometheus-stackdriver-exporterprometheus-communityVerified publisher5.2.01 of 1See more

prometheus-stackdriver-exporter prometheus-community 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
prometheuscommunity/stackdriver-exporter:v0.19.0c0a0cbf76570
golang.org/x/crypto@v0.51.0
0.55.0

Open the chart page →

355
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.55.0

Open the chart page →

4,412
dex-k8s-authenticatorsagikazarmarkVerified publisher0.0.31 of 1See more

dex-k8s-authenticator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.55.0

Open the chart page →

2,791
thanosstevehipwellVerified publisher1.24.11 of 1See more

thanos stevehipwell 1.24.1

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/crypto@v0.53.0
0.55.0

Open the chart page →

203
tailing-sidecar-operatortailing-sidecar-operatorOfficialVerified publisher0.111.01 of 2See more

tailing-sidecar-operator tailing-sidecar-operator 0.111.0

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/crypto@v0.37.0
0.55.0

Open the chart page →

1,212
caddyalekcVerified publisher0.9.01 of 1See more

caddy alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
library/caddy:2.11.4-alpine5f5c8640aae0
golang.org/x/crypto@v0.52.0
0.55.0

Open the chart page →

853
aspnet-corebitnamiVerified publisher9.4.221 of 3See more

aspnet-core bitnami 9.4.22

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
bitnami/git:latest463e347d57f5
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

22
openstack-cinder-csicloud-provider-openstack2.36.52 of 7See more

openstack-cinder-csi cloud-provider-openstack 2.36.5

2 of the 7 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.10.0be59d0556508
golang.org/x/crypto@v0.38.0
0.55.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/crypto@v0.37.0
0.55.0

Open the chart page →

3,653
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
securesystemsengineering/connaisseur:v3.12.038918befbdad
golang.org/x/crypto@v0.54.0
0.55.0

Open the chart page →

3,041
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
golang.org/x/crypto@v0.36.0
0.55.0

Open the chart page →

4,641
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
golang.org/x/crypto@v0.0.0-20191206172530-e9b2fee46413
0.55.0

Open the chart page →

4,577
devtron-operatordevtron0.23.39 of 11See more

devtron-operator devtron 0.23.3

9 of the 11 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.55.0
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/crypto@v0.46.0
0.55.0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
golang.org/x/crypto@v0.14.0
0.55.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.55.0
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/crypto@v0.46.0
0.55.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.55.0
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/crypto@v0.46.0
0.55.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/crypto@v0.7.0
0.55.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.55.0

Open the chart page →

33,180
drone-runner-kubedroneVerified publisher0.1.101 of 1See more

drone-runner-kube drone 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.55.0

Open the chart page →

2,067
hcloud-csihcloud2.23.03 of 6See more

hcloud-csi hcloud 2.23.0

3 of the 6 container images this version deploys carry CVE-2026-56854.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
golang.org/x/crypto@v0.45.0
0.55.0
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
golang.org/x/crypto@v0.48.0
0.55.0
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/crypto@v0.46.0
0.55.0

Open the chart page →

2,666

Container images carrying it

3,219 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/crypto@v0.28.0
0.55.0
1
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.55.0
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/crypto@v0.14.0
0.55.0
1
ghcr.io/bionicstork/bionicstork/relay:latest13290b9a64af
golang.org/x/crypto@v0.53.0
0.55.0
1
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
golang.org/x/crypto@v0.52.0
0.55.0
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10b6373349a301
golang.org/x/crypto@v0.41.0
0.55.0
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
golang.org/x/crypto@v0.32.0
0.55.0
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.55.0
1
ghcr.io/blind-oracle/cortex-tenant:v2.0.09f8896ffc15b
golang.org/x/crypto@v0.36.0
0.55.0
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
golang.org/x/crypto@v0.41.0
0.55.0
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
golang.org/x/crypto@v0.41.0
0.55.0
1
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
golang.org/x/crypto@v0.41.0
0.55.0
1
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
golang.org/x/crypto@v0.36.0
0.55.0
1
ghcr.io/borchero/switchboard:0.7.454a193b757da
golang.org/x/crypto@v0.48.0
0.55.0
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
golang.org/x/crypto@v0.14.0
0.55.0
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
golang.org/x/crypto@v0.18.0
0.55.0
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/crypto@v0.3.0
0.55.0
1
ghcr.io/browsersec/kubebrowse:sha-09dfa1fb853e9e6372a
golang.org/x/crypto@v0.38.0
0.55.0
1
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
golang.org/x/crypto@v0.40.0
0.55.0
1
ghcr.io/bryopsida/k8s-wireguard-mgr:main4c575d037ef2
golang.org/x/crypto@v0.54.0
0.55.0
1
ghcr.io/buildbarn/bb-scheduler:20260908T142432Z-77f7642f627ab242890
golang.org/x/crypto@v0.52.0
0.55.0
1
ghcr.io/buildbarn/bb-storage:20260908T142448Z-db6204132ebc54b769b
golang.org/x/crypto@v0.52.0
0.55.0
1
ghcr.io/buoyantio/linkerd-dashboard-server:0.11.1dd6a29588242
golang.org/x/crypto@v0.54.0
0.55.0
1
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
golang.org/x/crypto@v0.35.0
0.55.0
1
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
golang.org/x/crypto@v0.37.0
0.55.0
1
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
golang.org/x/crypto@v0.0.0-20211215165025-cf75a172585e
0.55.0
1
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
golang.org/x/crypto@v0.37.0
0.55.0
1
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
golang.org/x/crypto@v0.37.0
0.55.0
1
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
golang.org/x/crypto@v0.14.0
0.55.0
1
ghcr.io/caninehq/canine:latesta058034ca006
golang.org/x/crypto@v0.31.0
0.55.0
1
ghcr.io/cedar2025/xboard:latest896e4926e0d7
golang.org/x/crypto@v0.52.0
0.55.0
1
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
golang.org/x/crypto@v0.35.0
0.55.0
1
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
golang.org/x/crypto@v0.42.0
0.55.0
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/crypto@v0.25.0
0.55.0
1
ghcr.io/cerbos/cerbos:0.55.04b9d3b58c4f1
golang.org/x/crypto@v0.54.0
0.55.0
1
ghcr.io/cerbos/cerbos:0.51.08d35a64e4a99
golang.org/x/crypto@v0.47.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
golang.org/x/crypto@v0.49.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
golang.org/x/crypto@v0.49.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
golang.org/x/crypto@v0.17.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.55.0
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
golang.org/x/crypto@v0.42.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
golang.org/x/crypto@v0.17.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.55.0
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
golang.org/x/crypto@v0.49.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.0e7f9e8f1d565
golang.org/x/crypto@v0.42.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-mesh:v2.8.0091b906a0b13
golang.org/x/crypto@v0.42.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.55.0
1
ghcr.io/chaos-mesh/chaos-mesh:v2.7.28bc853c7414c
golang.org/x/crypto@v0.17.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-mesh:v2.8.49e48285bb44c
golang.org/x/crypto@v0.49.0
0.55.0
1
ghcr.io/chaos-mesh/chaos-mesh:v2.8.3bdb31f3121a2
golang.org/x/crypto@v0.49.0
0.55.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.