StackRadar

CVE-2026-56865

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
453
of 17,781 indexed, latest versions
Container images
422
deployed by those charts
Fix available
1 of 2
affected packages

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

Carried by container images the latest versions of 453 of 17,781 indexed charts deploy, on 422 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
golang.org/x/modgolangv0.1.0, v0.2.0, v0.3.0, v0.4.2+38 more0.40.0421
OSV records
DEBIAN-CVE-2026-56865GO-2026-6179
Also known as
BIT-golang-2026-56865

Charts affected

453 by stars
ChartLatestAffected imagesRadar Score
mission-controlflanksourceVerified publisher0.1.3361 of 8See more

mission-control flanksource 0.1.336

1 of the 8 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
golang.org/x/mod@v0.27.0
0.40.0

Open the chart page →

8,902
mission-control-tenantflanksourceVerified publisher1.0.922 of 3See more

mission-control-tenant flanksource 1.0.92

2 of the 3 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/mod@v0.10.0
0.40.0
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/mod@v0.10.0
0.40.0

Open the chart page →

5,684
galoygaloymoney0.34.71 of 24See more

galoy galoymoney 0.34.7

1 of the 24 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/mod@v0.14.0
0.40.0

Open the chart page →

8,677
monitoringgaloymoney0.12.211 of 6See more

monitoring galoymoney 0.12.21

1 of the 6 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/mod@v0.20.0
0.40.0

Open the chart page →

5,295
galoygaloymoney20.34.71 of 24See more

galoy galoymoney2 0.34.7

1 of the 24 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/mod@v0.14.0
0.40.0

Open the chart page →

8,677
monitoringgaloymoney20.12.211 of 6See more

monitoring galoymoney2 0.12.21

1 of the 6 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/mod@v0.20.0
0.40.0

Open the chart page →

5,295
dispatchoor-apigeneral-helm-chartsVerified publisher0.1.11 of 1See more

dispatchoor-api general-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
golang.org/x/mod@v0.30.0
0.40.0

Open the chart page →

635
gitlab-goproxygitlab-goproxy0.2.21 of 1See more

gitlab-goproxy gitlab-goproxy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/mod@v0.8.0
0.40.0

Open the chart page →

1,325
harborgpg-dev1.18.31 of 8See more

harbor gpg-dev 1.18.3

1 of the 8 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
golang.org/x/mod@v0.31.0
0.40.0

Open the chart page →

3,376
opentelemetry-demogpg-dev0.33.85 of 27See more

opentelemetry-demo gpg-dev 0.33.8

5 of the 27 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
golang.org/x/mod@v0.20.0
0.40.0
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
golang.org/x/mod@v0.21.0
0.40.0
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
golang.org/x/mod@v0.19.0
0.40.0
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
golang.org/x/mod@v0.17.0
0.40.0
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
golang.org/x/mod@v0.17.0
0.40.0

Open the chart page →

49,025
prometheusgpg-dev29.2.11 of 6See more

prometheus gpg-dev 29.2.1

1 of the 6 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.32.058e117eabcce
golang.org/x/mod@v0.34.0
0.40.0

Open the chart page →

3,261
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
golang.org/x/mod@v0.32.0
0.40.0

Open the chart page →

1,274
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
golang.org/x/mod@v0.30.0
0.40.0

Open the chart page →

1,546
grafana-samplinggrafana1.1.71 of 2See more

grafana-sampling grafana 1.1.7

1 of the 2 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
golang.org/x/mod@v0.27.0
0.40.0

Open the chart page →

3,318
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
golang.org/x/mod@v0.24.0
0.40.0

Open the chart page →

8,188
prometheusgrafana-uxadax26.0.11 of 6See more

prometheus grafana-uxadax 26.0.1

1 of the 6 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/mod@v0.14.0
0.40.0

Open the chart page →

5,304
armada-executorgresearch0.22.81 of 1See more

armada-executor gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
gresearch/armada-executor:latest393aff4aa8f2
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

707
armada-lookout-ingestergresearch0.22.81 of 1See more

armada-lookout-ingester gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
gresearch/armada-lookout-ingester:latest3df14cda1855
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

707
armada-lookout-migrationgresearch0.22.81 of 1See more

armada-lookout-migration gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
gresearch/armada-lookout:latestf5e3226f1d33
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

707
armada-scheduler-migrationgresearch0.22.81 of 1See more

armada-scheduler-migration gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
gresearch/armada-scheduler:latest6141a6213fcb
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

707
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/mod@v0.20.0
0.40.0

Open the chart page →

2,590
routergroundcover1.12.3571 of 7See more

router groundcover 1.12.357

1 of the 7 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

6,009
thunderdome-planning-pokerhalkeye0.1.11 of 1See more

thunderdome-planning-poker halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
golang.org/x/mod@v0.34.0
0.40.0

Open the chart page →

418
logging-stackhelm-charts-alexis-carbillet0.1.01 of 9See more

logging-stack helm-charts-alexis-carbillet 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/grafana:11.1.0079600c9517b
golang.org/x/mod@v0.18.0
0.40.0

Open the chart page →

12,650
monitoring-stackhelm-charts-alexis-carbillet0.1.02 of 11See more

monitoring-stack helm-charts-alexis-carbillet 0.1.0

2 of the 11 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/mod@v0.20.0
0.40.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/mod@v0.9.0
0.40.0

Open the chart page →

9,460
gripmockhelm-charts-nr1.1.31 of 1See more

gripmock helm-charts-nr 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
golang.org/x/mod@v0.4.2
0.40.0

Open the chart page →

2,793
listmonkhelm-charts-nr0.1.121 of 1See more

listmonk helm-charts-nr 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/mod@v0.5.1
0.40.0

Open the chart page →

2,537
giteahelmforgeVerified publisher1.1.201 of 1See more

gitea helmforge 1.1.20

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
gitea/gitea:1.27.3-rootless1c17ecaead42
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

535
listmonkhelmforgeVerified publisher1.1.141 of 3See more

listmonk helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
listmonk/listmonk:v6.2.0f535d59e1499
golang.org/x/mod@v0.33.0
0.40.0

Open the chart page →

2,839
memoshelmforgeVerified publisher2.0.01 of 2See more

memos helmforge 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
neosmemo/memos:0.30.071a5b4738d1b
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

792
olivetinhelmforgeVerified publisher1.2.11 of 2See more

olivetin helmforge 1.2.1

1 of the 2 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
jamesread/olivetin:3000.19.0af9d7c4db6dc
golang.org/x/mod@v0.38.0
0.40.0

Open the chart page →

307
harborhelm-harborVerified publisher2.3.51 of 8See more

harbor helm-harbor 2.3.5

1 of the 8 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/mod@v0.36.0
0.40.0

Open the chart page →

1,650
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
no fix listed

Open the chart page →

25,017
homeboxhomebox-helmVerified publisher0.3.01 of 2See more

homebox homebox-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
sysadminsmedia/homebox:0.26.056e880b62309
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

556
sing-boxhuscker-chartsVerified publisher1.0.71 of 1See more

sing-box huscker-charts 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
golang.org/x/mod@v0.26.0
0.40.0

Open the chart page →

1,443
s-uihuscker-chartsVerified publisher1.0.31 of 1See more

s-ui huscker-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
alireza7/s-ui:1.5.302aa86983cdb
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

524
vcbackendi4trustVerified publisher0.0.81 of 1See more

vcbackend i4trust 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
wistefan/vcbackend:0.0.13bd436164b51
golang.org/x/mod@v0.7.0
0.40.0

Open the chart page →

1,848
ilum-otel-collectorilumVerified publisher0.1.01 of 1See more

ilum-otel-collector ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.113.05ac3e0ba2b0b
golang.org/x/mod@v0.21.0
0.40.0

Open the chart page →

1,384
intel-gaudi-resource-driverintelVerified publisher0.3.01 of 1See more

intel-gaudi-resource-driver intel 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
intel/intel-gaudi-resource-driver:v0.3.0ac758c14c2de
golang.org/x/mod@v0.21.0
0.40.0

Open the chart page →

559
intel-qat-resource-driverintelVerified publisher0.1.01 of 1See more

intel-qat-resource-driver intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
intel/intel-qat-resource-driver:v0.1.0ac7616986a2b
golang.org/x/mod@v0.17.0
0.40.0

Open the chart page →

602
hetzner-dyndnsitsmethemojoVerified publisher1.4.01 of 1See more

hetzner-dyndns itsmethemojo 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
hashicorp/terraform:1.9.7b77efab1a448
golang.org/x/mod@v0.16.0
0.40.0

Open the chart page →

1,836
jx-app-athensjenkins-x0.0.181 of 1See more

jx-app-athens jenkins-x 0.0.18

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/mod@v0.1.0
0.40.0

Open the chart page →

4,225
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
golang.org/x/mod@v0.19.0
0.40.0

Open the chart page →

3,999
corednsjouveVerified publisher1.45.01 of 1See more

coredns jouve 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
golang.org/x/mod@v0.27.0
0.40.0

Open the chart page →

887
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/mod@v0.20.0
0.40.0

Open the chart page →

1,893
bitmagnetk8s-home-lab-repo1.0.21 of 1See more

bitmagnet k8s-home-lab-repo 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/bitmagnet-io/bitmagnet:v0.10b6373349a301
golang.org/x/mod@v0.26.0
0.40.0

Open the chart page →

1,168
blockyk8s-home-lab-repo11.2.11 of 1See more

blocky k8s-home-lab-repo 11.2.1

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.29.0a6d99f323d30
golang.org/x/mod@v0.32.0
0.40.0

Open the chart page →

580
giteak8s-home-lab-repo2.6.01 of 1See more

gitea k8s-home-lab-repo 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
gitea/gitea:1.26.27d13848af126
golang.org/x/mod@v0.35.0
0.40.0

Open the chart page →

2,139
workspacekaitoVerified publisher0.12.01 of 7See more

workspace kaito 0.12.0

1 of the 7 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/nvidia/k8s-device-plugin:v0.18.2-125a4e52c87bb9
golang.org/x/mod@v0.37.0
0.40.0

Open the chart page →

2,362
dockerdkarljorgensen0.1.01 of 1See more

dockerd karljorgensen 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56865.

Container imageDigestPackageFixed in
library/docker:28.5.2-dind2a232a42256f
golang.org/x/mod@v0.24.0
0.40.0

Open the chart page →

2,034

Container images carrying it

422 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/fluxcd/flagger:1.45.015b372d35012
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/fluxcd/notification-controller:v1.9.29ce503e7bcb8
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/mod@v0.22.0
0.40.0
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/mod@v0.25.0
0.40.0
1
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/honeycombio/refinery/refinery:3.4.0d437676941d6
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
golang.org/x/mod@v0.27.0
0.40.0
1
ghcr.io/inlets/inlets-operator:0.17.2208265c006973
golang.org/x/mod@v0.34.0
0.40.0
1
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
golang.org/x/mod@v0.27.0
0.40.0
1
ghcr.io/jarodr47/portager:0.5.06a7a61b37568
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
golang.org/x/mod@v0.20.0
0.40.0
1
ghcr.io/kedacore/keda:2.20.2fe74c7b88495
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/kedacore/keda-admission-webhooks:2.20.241f74102aba7
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/kedacore/keda-metrics-apiserver:2.20.227286536a8a7
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
golang.org/x/mod@v0.21.0
0.40.0
1
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
golang.org/x/mod@v0.15.0
0.40.0
1
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
golang.org/x/mod@v0.15.0
0.40.0
1
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
golang.org/x/mod@v0.25.0
0.40.0
1
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
golang.org/x/mod@v0.6.0-dev.0.20220419223038-86c51ed26bb4
0.40.0
1
ghcr.io/kubehippie/keycloak-operator:1.6.06c0275fb9736
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
golang.org/x/mod@v0.26.0
0.40.0
1
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
golang.org/x/mod@v0.6.0-dev.0.20220106191415-9b9b3d81d5e3
0.40.0
1
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
golang.org/x/mod@v0.6.0-dev.0.20220106191415-9b9b3d81d5e3
0.40.0
1
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/kyverno/policy-reporter:3.10.0a77e93fe5117
golang.org/x/mod@v0.39.0
0.40.0
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/mod@v0.16.0
0.40.0
1
ghcr.io/lockdep/stackradar-scanner:0.3.0dd8a35d50c2d
golang.org/x/mod@v0.32.0
0.40.0
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/mod@v0.8.0
0.40.0
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/mod@v0.15.0
0.40.0
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/mod@v0.12.0
0.40.0
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/mod@v0.10.0
0.40.0
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/mod@v0.15.0
0.40.0
1
ghcr.io/loft-sh/vcluster-hpm:0.2.7f65f6810ea23
golang.org/x/mod@v0.25.0
0.40.0
1
ghcr.io/loft-sh/vcluster-platform:4.12.0ef92da4621e6
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
golang.org/x/mod@v0.14.0
0.40.0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/mod@v0.20.0
0.40.0
1
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
golang.org/x/mod@v0.37.0
0.40.0
1
ghcr.io/okteto/backend:0.0.0-2026-08-03244f87e8c52d
golang.org/x/mod@v0.38.0
0.40.0
1
ghcr.io/okteto/buildkit:0.0.0-2026-08-0314527ca5d2a9
golang.org/x/mod@v0.36.0
0.40.0
1
ghcr.io/openclarity/grype-server:v0.6.079412399f301
golang.org/x/mod@v0.12.0
0.40.0
1
ghcr.io/open-feature/flagd:v0.16.032234e63c1d0
golang.org/x/mod@v0.33.0
0.40.0
1
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
golang.org/x/mod@v0.19.0
0.40.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.