StackRadar

CVE-2026-56860

Medium

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,577
of 17,828 indexed, latest versions
Container images
5,287
deployed by those charts
Fix available
1 of 2
affected packages

Avoid quadratic complexity in resolvePath in net/url

Carried by container images the latest versions of 4,577 of 17,828 indexed charts deploy, on 5,287 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,287
OSV records
DEBIAN-CVE-2026-56860GO-2026-6218
Also known as
BIT-golang-2026-56860

Charts affected

4,577 by stars
ChartLatestAffected imagesRadar Score
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
stdlib@go1.18.3
1.25.13

Open the chart page →

3,077
retail-store-sample-catalog-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-catalog-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-catalog:1.3.0b654b266fa32
stdlib@go1.24.6
1.25.13

Open the chart page →

773
stageset-controllerstageset-controllerOfficialVerified publisher2026.6.15+1543421 of 1See more

stageset-controller stageset-controller 2026.6.15+154342

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/metio/stageset-controller:2026.6.14234b66bb3319
stdlib@go1.26.4
1.25.13

Open the chart page →

313
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
stdlib@go1.16.6
1.25.13

Open the chart page →

28,618
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
stdlib@go1.17.5
1.25.13

Open the chart page →

2,089
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.13

Open the chart page →

2,451
k8scostoptimizerstakaterVerified publisher0.0.51 of 1See more

k8scostoptimizer stakater 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
stdlib@go1.17.8
1.25.13

Open the chart page →

1,409
konfiguratorstakaterVerified publisher0.1.391 of 1See more

konfigurator stakater 0.1.39

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
stakater/konfigurator:v0.1.393409565b1ef5
stdlib@go1.17.13
1.25.13

Open the chart page →

1,280
mongodbstakaterVerified publisher1.0.31 of 1See more

mongodb stakater 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
bitnami/mongodb:latest84254ace18df
stdlib@go1.26.5
1.25.13

Open the chart page →

82
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.25.13

Open the chart page →

2,854
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
stdlib@go1.15.11
1.25.13

Open the chart page →

2,174
vaultstakaterVerified publisher0.8.42 of 2See more

vault stakater 0.8.4

2 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
stdlib@go1.16.7
1.25.13
hashicorp/vault-k8s:0.14.0aff47b5ba39c
stdlib@go1.17.2
1.25.13

Open the chart page →

5,874
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
stdlib@go1.13.1
1.25.13

Open the chart page →

2,566
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
stdlib@go1.16.13
1.25.13

Open the chart page →

6,683
stakefishstakefish0.1.06 of 8See more

stakefish stakefish 0.1.0

6 of the 8 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
stdlib@go1.22.3
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
stdlib@go1.22.2
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.25.13
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
stdlib@go1.22.2
1.25.13
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.13

Open the chart page →

20,487
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
stdlib@go1.22.12
1.25.13

Open the chart page →

3,003
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.13

Open the chart page →

1,262
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.25.13

Open the chart page →

4,124
mev-booststakewise1.7.41 of 1See more

mev-boost stakewise 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
flashbots/mev-boost:1.8.07c486b5789da
stdlib@go1.22.6
1.25.13

Open the chart page →

1,261
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
stdlib@go1.17.5
1.25.13

Open the chart page →

6,609
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
stdlib@go1.22.11
1.25.13

Open the chart page →

7,067
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
stdlib@go1.23.6
1.25.13

Open the chart page →

1,262
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
stdlib@go1.25.8
1.25.13

Open the chart page →

576
open-appsec-injectorstartechnicaVerified publisher1.1.22 of 3See more

open-appsec-injector startechnica 1.1.2

2 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/openappsec/smartsync:latest580d68c50cc7
stdlib@go1.18.10
1.25.13
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
stdlib@go1.18.10
1.25.13

Open the chart page →

4,363
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.25.13

Open the chart page →

14,629
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
stdlib@go1.18.4
1.25.13

Open the chart page →

1,986
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
stdlib@go1.16.1
1.25.13
prom/prometheus:v2.22.2f7ffebdd428b
stdlib@go1.15.5
1.25.13
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
stdlib@go1.16.5
1.25.13
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
stdlib@go1.16.5
1.25.13

Open the chart page →

16,545
fluentd-operatorstatcan0.5.11 of 1See more

fluentd-operator statcan 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
vmware/kube-fluentd-operator:latestf028c138a5f4
stdlib@go1.21.7
1.25.13

Open the chart page →

1,960
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
stdlib@go1.18.10
1.25.13

Open the chart page →

1,584
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
stdlib@go1.16.3
1.25.13

Open the chart page →

6,600
prometheus-operatorstatcan0.2.24 of 7See more

prometheus-operator statcan 0.2.2

4 of the 7 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.13
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
stdlib@go1.13.11
1.25.13
squareup/ghostunnel:v1.5.270f4cf270425
stdlib@go1.13.4
1.25.13
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
stdlib@go1.14.3
1.25.13

Open the chart page →

12,257
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
stdlib@go1.19.10
1.25.13

Open the chart page →

1,316
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
stdlib@go1.17.8
1.25.13

Open the chart page →

1,828
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
stdlib@go1.13.5
1.25.13

Open the chart page →

4,224
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.25.13

Open the chart page →

13,673
steadybit-agentsteadybit3.1.1692 of 6See more

steadybit-agent steadybit 3.1.169

2 of the 6 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/steadybit/extension-container:v1.8.1ae79f958b479
stdlib@go1.25.12
1.25.13
ghcr.io/steadybit/extension-host:v1.8.103a5ef26aac5
stdlib@go1.25.12
1.25.13

Open the chart page →

3,875
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,287
snapshot-controllerstevehipwellVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
stdlib@go1.23.1
1.25.13

Open the chart page →

495
vertical-pod-autoscalerstevehipwellVerified publisher1.12.13 of 3See more

vertical-pod-autoscaler stevehipwell 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
stdlib@go1.26.5
1.25.13

Open the chart page →

228
snapshot-controllerstevehipwell-helm-charts-snapshot-controllerVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell-helm-charts-snapshot-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
stdlib@go1.23.1
1.25.13

Open the chart page →

495
its-mytabsstone0.3.01 of 1See more

its-mytabs stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.25.13

Open the chart page →

1,533
meerkat-crmstone0.3.01 of 1See more

meerkat-crm stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/fbuchner/meerkat-crm:1.7.0d513bdd3ae80
stdlib@go1.26.5
1.25.13

Open the chart page →

104
pulsar-resources-operatorstreamnative0.21.21 of 1See more

pulsar-resources-operator streamnative 0.21.2

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
streamnative/pulsar-resources-operator:v0.21.282434bb2a8ad
stdlib@go1.25.12
1.25.13

Open the chart page →

128
sn-platform-slimstreamnative1.11.453See more

sn-platform-slim streamnative 1.11.45

3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.13
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
stdlib@go1.20.4
1.25.13
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.13

Open the chart page →

supabase-operatorstrrl-helm2026.7.251 of 1See more

supabase-operator strrl-helm 2026.7.25

1 of the 1 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
ghcr.io/strrl/supabase-operator:2026.7.2587d083ab8980
stdlib@go1.25.12
1.25.13

Open the chart page →

237
wonder-mesh-netstrrl-helm2026.629.02 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

2 of the 3 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
headscale/headscale:0.27.1cd37b3001857
stdlib@go1.25.1
1.25.13
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
stdlib@go1.25.11
1.25.13

Open the chart page →

5,202
stunner-devstunner1.2.12 of 2See more

stunner-dev stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13

Open the chart page →

136
stunner-gateway-operator-devstunner1.1.12 of 2See more

stunner-gateway-operator-dev stunner 1.1.1

2 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13

Open the chart page →

136
stunner-premiumstunner1.2.12 of 2See more

stunner-premium stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:1.2.10d2094060b72
stdlib@go1.26.4
1.25.13
l7mp/stunner-gateway-operator-premium:1.2.14383766e66c5
stdlib@go1.26.4
1.25.13

Open the chart page →

269
stunner-prometheusstunner0.2.14 of 4See more

stunner-prometheus stunner 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-56860.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
stdlib@go1.26.5
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
stdlib@go1.23.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
stdlib@go1.23.2
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.13

Open the chart page →

3,066

Container images carrying it

5,287 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
stdlib@go1.21.5
1.25.13
1
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
stdlib@go1.16.5
1.25.13
1
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
stdlib@go1.23.4
1.25.13
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
stdlib@go1.16.5
1.25.13
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
stdlib@go1.16.4
1.25.13
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
stdlib@go1.21.7
1.25.13
1
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
stdlib@go1.17.6
1.25.13
1
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
stdlib@go1.21.7
1.25.13
1
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
stdlib@go1.17.6
1.25.13
1
gcr.io/ml-pipeline/mysql:5.7-debiandf28187b5455
stdlib@go1.16.7
1.25.13
1
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
stdlib@go1.17.6
1.25.13
1
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
stdlib@go1.21.7
1.25.13
1
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
stdlib@go1.17.6
1.25.13
1
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
stdlib@go1.21.7
1.25.13
1
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
stdlib@go1.17.6
1.25.13
1
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
stdlib@go1.21.7
1.25.13
1
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
stdlib@go1.17.11
1.25.13
1
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
stdlib@go1.16.3
1.25.13
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
stdlib@go1.21.1
1.25.13
1
gcr.io/projectsigstore/cosigned784518ff3ee7
stdlib@go1.17.9
1.25.13
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
stdlib@go1.17.9
1.25.13
1
gcr.io/spotit-today/spot-ocean-admission-controller:0.1.64f634aeb31b8
stdlib@go1.24.13
1.25.13
1
ghcr.io/0xerr0r/blocky:v0.29.0a6d99f323d30
stdlib@go1.26.0
1.25.13
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
stdlib@go1.17.7
1.25.13
1
ghcr.io/291-group/lan-orangutan:3.3.886b55c80eeb1
stdlib@go1.25.12
1.25.13
1
ghcr.io/abstract-foundation/zksync-external-node-sidecar:v1.0.03e705d0eb1ce
stdlib@go1.18.10
1.25.13
1
ghcr.io/actions/gha-runner-scale-set-controller:0.14.21b4c7f62e971
stdlib@go1.26.3
1.25.13
1
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
stdlib@go1.23.7
1.25.13
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
stdlib@go1.22.1
1.25.13
1
ghcr.io/aeyrtonvs/k8s-drain-surge:0.0.338bce7856b5c
stdlib@go1.25.10
1.25.13
1
ghcr.io/afairgiant/medikeep:v0.70.04c28334f3c79
stdlib@go1.19.8
1.25.13
1
ghcr.io/agjmills/sentry-operator:v1.2.500389ef6a00e
stdlib@go1.24.2
1.25.13
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
stdlib@go1.22.5
1.25.13
1
ghcr.io/ajnart/homarr:lateste103abadfb52
stdlib@go1.22.5
1.25.13
1
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
stdlib@go1.16.9
1.25.13
1
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
stdlib@go1.19.3
1.25.13
1
ghcr.io/alexbakker/alertmanager-ntfy:1.0.12f4db8064595
stdlib@go1.24.4
1.25.13
1
ghcr.io/alexellis/registry-creds:0.3.2-rc1f5c72501e559
stdlib@go1.19.5
1.25.13
1
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
stdlib@go1.24.2
1.25.13
1
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
stdlib@go1.23.3
1.25.13
1
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
stdlib@go1.23.3
1.25.13
1
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
stdlib@go1.23.1
1.25.13
1
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
stdlib@go1.24.4
1.25.13
1
ghcr.io/amaanx86/oci-prometheus-sd-proxy:latest297a8379a328
stdlib@go1.26.4
1.25.13
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
stdlib@go1.26.4
1.25.13
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
stdlib@go1.20.14
1.25.13
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
stdlib@go1.25.5
1.25.13
1
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
stdlib@go1.25.7
1.25.13
1
ghcr.io/andylibrian/terjang:latest20a46b199247
stdlib@go1.16.4
1.25.13
1
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.25.13
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.