StackRadar

CVE-2026-56860

Medium

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,526
of 17,787 indexed, latest versions
Container images
5,287
deployed by those charts
Fix available
1 of 2
affected packages

Avoid quadratic complexity in resolvePath in net/url

Carried by container images the latest versions of 4,526 of 17,787 indexed charts deploy, on 5,287 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,287
OSV records
DEBIAN-CVE-2026-56860GO-2026-6218
Also known as
BIT-golang-2026-56860

Charts affected

4,526 by stars
ChartLatestAffected imagesRadar Score
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
stdlib@go1.18.1
1.25.13

Open the chart page →

3,466
seaweedfs-csi-driverseaweedfs-csi-driver0.2.385 of 7See more

seaweedfs-csi-driver seaweedfs-csi-driver 0.2.38

5 of the 7 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
stdlib@go1.20.3
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
stdlib@go1.20.3
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
stdlib@go1.20.3
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
stdlib@go1.20.3
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
stdlib@go1.20.3
1.25.13

Open the chart page →

5,272
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
stdlib@go1.24.11
1.25.13

Open the chart page →

860
bentoself-hosters-by-nightVerified publisher0.9.11 of 1See more

bento self-hosters-by-night 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
stdlib@go1.23.10
1.25.13

Open the chart page →

1,046
lldapself-hosters-by-nightVerified publisher0.5.22 of 2See more

lldap self-hosters-by-night 0.5.2

2 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
stdlib@go1.24.6
1.25.13
ghcr.io/lldap/lldap:2025-05-193de697c3ba57
stdlib@go1.18.2
1.25.13

Open the chart page →

3,412
appshini4iVerified publisher0.4.01 of 1See more

app shini4i 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
traefik/whoami:v1.10.21474027c3166
stdlib@go1.22.2
1.25.13

Open the chart page →

537
skypilotskypilotOfficialVerified publisher0.13.03 of 3See more

skypilot skypilot 0.13.0

3 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
stdlib@go1.26.4
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
stdlib@go1.24.4
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
stdlib@go1.24.4
1.25.13

Open the chart page →

5,889
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
stdlib@go1.20
1.25.13

Open the chart page →

1,663
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
stdlib@go1.14.2
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
stdlib@go1.14.2
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
stdlib@go1.14.2
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
stdlib@go1.14.2
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
stdlib@go1.14.2
1.25.13

Open the chart page →

12,502
miniosolidchartsVerified publisher0.5.01 of 1See more

minio solidcharts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
stdlib@go1.24.6
1.25.13

Open the chart page →

1,055
forecastlestakaterVerified publisher2.1.11 of 1See more

forecastle stakater 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
stakater/forecastle:v2.0.2382cd9572352
stdlib@go1.26.4
1.25.13

Open the chart page →

712
ingressmonitorcontrollerstakaterVerified publisher2.2.131 of 1See more

ingressmonitorcontroller stakater 2.2.13

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
stdlib@go1.24.13
1.25.13

Open the chart page →

576
vertical-pod-autoscalerstevehipwell-helm-charts-vertical-pod-autoscalerVerified publisher1.12.13 of 3See more

vertical-pod-autoscaler stevehipwell-helm-charts-vertical-pod-autoscaler 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
stdlib@go1.26.5
1.25.13

Open the chart page →

228
sn-platformstreamnative1.11.446 of 9See more

sn-platform streamnative 1.11.44

6 of the 9 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.13
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
stdlib@go1.20.4
1.25.13
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
stdlib@go1.17.11
1.25.13
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
stdlib@go1.19.4
1.25.13
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.25.13
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.13

Open the chart page →

15,525
stunnerstunner1.2.12 of 2See more

stunner stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:1.2.10d2094060b72
stdlib@go1.26.4
1.25.13
l7mp/stunner-gateway-operator:1.2.10ea40a1d42d5
stdlib@go1.26.4
1.25.13

Open the chart page →

263
pocketbasetechwolf12Verified publisher0.29.31 of 1See more

pocketbase techwolf12 0.29.3

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
stdlib@go1.24.6
1.25.13

Open the chart page →

1,447
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.13

Open the chart page →

9,825
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
stdlib@go1.24.4
1.25.13

Open the chart page →

3,816
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.263 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

3 of the 6 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
stdlib@go1.20.5
1.25.13
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
stdlib@go1.19.12
1.25.13
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.25.13

Open the chart page →

14,568
feedbacksystemthm-mni-iiVerified publisher0.47.16 of 10See more

feedbacksystem thm-mni-ii 0.47.1

6 of the 10 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
stdlib@go1.21.5
1.25.13
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
stdlib@go1.19.12
1.25.13
bitnamilegacy/mysql:8.0.35-debian-11-r2be03e8ea6129
stdlib@go1.21.5
1.25.13
library/docker:20.10.21-dind3153fa63f546
stdlib@go1.18.7
1.25.13
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
stdlib@go1.20.12
1.25.13
thmmniii/fbs-runner:v1.27.186105349c1a3
stdlib@go1.20.11
1.25.13

Open the chart page →

28,579
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
stdlib@go1.24.2
1.25.13

Open the chart page →

1,494
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
stdlib@go1.14.4
1.25.13

Open the chart page →

4,136
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
stdlib@go1.14.4
1.25.13
library/traefik:v2.57d5a6ae66572
stdlib@go1.17.6
1.25.13
traefik/mesh:v1.4.8cf071f3e165c
stdlib@go1.19
1.25.13

Open the chart page →

9,257
k8s-ttl-controllertwin0.4.01 of 1See more

k8s-ttl-controller twin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
stdlib@go1.24.1
1.25.13

Open the chart page →

471
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
stdlib@go1.19.6
1.25.13
quay.io/argoproj/argocd:v2.8.6acaf37352569
stdlib@go1.20.4
1.25.13

Open the chart page →

10,355
crossplaneupbound-stable2.4.0-up.11 of 5See more

crossplane upbound-stable 2.4.0-up.1

1 of the 5 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.13

Open the chart page →

1,638
uptraceuptrace2.0.21 of 2See more

uptrace uptrace 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
uptrace/uptrace:2.0.234a02c3b2d12
stdlib@go1.24.10
1.25.13

Open the chart page →

1,620
vaultvaultVerified publisher1.22.04 of 4See more

vault vault 1.22.0

4 of the 4 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
alpine/k8s:1.35.5d870622d0040
stdlib@go1.26.0
1.25.13
hashicorp/vault:2.0.1755355002715
stdlib@go1.26.3
1.25.13
prom/statsd-exporter:v0.29.0632f70580492
stdlib@go1.26.0
1.25.13
ghcr.io/bank-vaults/bank-vaults:v1.33.198b6ea2ed319
stdlib@go1.26.3
1.25.13

Open the chart page →

4,243
vouchvouchVerified publisher3.2.01 of 1See more

vouch vouch 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
stdlib@go1.18.10
1.25.13

Open the chart page →

1,031
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
stdlib@go1.20.7
1.25.13

Open the chart page →

1,344
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
stdlib@go1.18.5
1.25.13

Open the chart page →

2,245
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
stdlib@go1.25.8
1.25.13

Open the chart page →

1,000
wallarm-ingresswallarmVerified publisher5.3.10-12 of 2See more

wallarm-ingress wallarm 5.3.10-1

2 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
stdlib@go1.23.1
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.13

Open the chart page →

1,301
wallarm-sidecarwallarmOfficialVerified publisher6.13.11 of 3See more

wallarm-sidecar wallarm 6.13.1

1 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
stdlib@go1.22.2
1.25.13

Open the chart page →

965
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.25.13

Open the chart page →

3,178
argo-cdwenerme10.9.12 of 3See more

argo-cd wenerme 10.9.1

2 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
stdlib@go1.25.6
1.25.13
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
stdlib@go1.26.4
1.25.13

Open the chart page →

2,989
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
stdlib@go1.17.4
1.25.13

Open the chart page →

6,085
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/postgres:15.186eb0add3b77c
stdlib@go1.24.6
1.25.13

Open the chart page →

8,587
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
stdlib@go1.18.1
1.25.13
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
stdlib@go1.18.2
1.25.13
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
stdlib@go1.18.2
1.25.13
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
stdlib@go1.18.2
1.25.13

Open the chart page →

10,033
windmillwindmill4.0.2631 of 3See more

windmill windmill 4.0.263

1 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

1,638
buildkitdwiremindVerified publisher0.33.01 of 1See more

buildkitd wiremind 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
moby/buildkit:v0.32.2-rootless504731e577c2
stdlib@go1.25.7
1.25.13

Open the chart page →

1,153
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
stdlib@go1.13.8
1.25.13

Open the chart page →

4,713
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
stdlib@go1.18.4
1.25.13

Open the chart page →

4,041
yet-another-cloudwatch-exporteryet-another-cloudwatch-exporter0.38.01 of 1See more

yet-another-cloudwatch-exporter yet-another-cloudwatch-exporter 0.38.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
stdlib@go1.22.4
1.25.13

Open the chart page →

923
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
stdlib@go1.23.12
1.25.13

Open the chart page →

4,016
paperlesszekker6Verified publisher11.8.01 of 1See more

paperless zekker6 11.8.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.13

Open the chart page →

4,644
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
stdlib@go1.22.6
1.25.13

Open the chart page →

828
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
stdlib@go1.23.7
1.25.13

Open the chart page →

1,836
no-latest-tag-webhookadmission-webhook-no-latest1.0.141 of 1See more

no-latest-tag-webhook admission-webhook-no-latest 1.0.14

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/omkar-shelke25/admission-webhook-no-latest:sha-33165455976a1d3236a
stdlib@go1.26.3
1.25.13

Open the chart page →

162
paperless-ngxadnoctemVerified publisher0.4.22 of 5See more

paperless-ngx adnoctem 0.4.2

2 of the 5 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
stdlib@go1.26.5
1.25.13
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.13

Open the chart page →

19,769

Container images carrying it

5,287 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
stdlib@go1.16.6
1.25.13
2
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
stdlib@go1.19.2
1.25.13
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
stdlib@go1.16.2
1.25.13
2
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
stdlib@go1.21.10
1.25.13
2
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
stdlib@go1.26.4
1.25.13
2
ghcr.io/fluxcd/helm-controller:v1.6.2e17ab0e5885d
stdlib@go1.26.4
1.25.13
2
ghcr.io/fluxcd/source-controller:v1.9.22b8d06650a1b
stdlib@go1.26.4
1.25.13
2
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
stdlib@go1.25.0
1.25.13
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
stdlib@go1.22.5
1.25.13
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
stdlib@go1.23.6
1.25.13
2
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
stdlib@go1.23.3
1.25.13
2
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
stdlib@go1.25.6
1.25.13
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.25.13
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.476a2170cd0c9
stdlib@go1.26.4
1.25.13
2
ghcr.io/jkroepke/kube-webhook-certgen:1.7.47a62bba56a7c
stdlib@go1.25.5
1.25.13
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.38ce13c365c8e
stdlib@go1.26.3
1.25.13
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.5d0e80b2f62fe
stdlib@go1.26.5
1.25.13
2
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
stdlib@go1.24.11
1.25.13
2
ghcr.io/juanfont/headscale:0.29.3:v0.29.30e7f1c6e4ce6
stdlib@go1.26.5
1.25.13
2
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
stdlib@go1.23.4
1.25.13
2
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
stdlib@go1.23.3
1.25.13
2
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
stdlib@go1.23.3
1.25.13
2
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
stdlib@go1.23.3
1.25.13
2
ghcr.io/klicktipp/kubectl:1.36.30c2402d92b5c
stdlib@go1.26.5
1.25.13
2
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
stdlib@go1.25.7
1.25.13
2
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
stdlib@go1.24.4
1.25.13
2
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
stdlib@go1.24.4
1.25.13
2
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
stdlib@go1.20.14
1.25.13
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
stdlib@go1.24.5
1.25.13
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
stdlib@go1.24.5
1.25.13
2
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
stdlib@go1.21.1
1.25.13
2
ghcr.io/projectcapsule/capsule:v0.14.5e9ee63f6196c
stdlib@go1.26.4
1.25.13
2
ghcr.io/projectcapsule/capsule-proxy:v0.14.17c90292e3172
stdlib@go1.26.4
1.25.13
2
ghcr.io/rabbitmq/messaging-topology-operator:1.19.124c4649ef3ef
stdlib@go1.25.9
1.25.13
2
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
stdlib@go1.18.10
1.25.13
2
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
stdlib@go1.19.7
1.25.13
2
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
stdlib@go1.19.13
1.25.13
2
ghcr.io/sigstore/fulcio:v1.8.8ef72cf56c64b
stdlib@go1.26.4
1.25.13
2
ghcr.io/sigstore/rekor/rekor-server:v1.5.4100d793d68d0
stdlib@go1.26.4
1.25.13
2
ghcr.io/sigstore/scaffolding/createcerts7f59f7c08d1a
stdlib@go1.25.0
1.25.13
2
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
stdlib@go1.19.3
1.25.13
2
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
stdlib@go1.24.0
1.25.13
2
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
stdlib@go1.25.3
1.25.13
2
ghcr.io/spiffe/spire-controller-manager:0.7.0d7b9e710f542
stdlib@go1.26.5
1.25.13
2
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
stdlib@go1.20.2
1.25.13
2
ghcr.io/stakater/reloader:v1.4.190530cf462fa3
stdlib@go1.26.4
1.25.13
2
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
stdlib@go1.25.3
1.25.13
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
stdlib@go1.20.1
1.25.13
2
ghcr.io/victoriametrics/sync-job:v0.0.17b6f233532a85
stdlib@go1.26.4-X:jsonv2
1.25.13
2
ghcr.io/voyagermesh/echoserver:v20221109:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.25.13
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.