StackRadar

CVE-2026-94440

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,544
of 18,087 indexed, latest versions
Container images
6,392
deployed by those charts
Fix available
1 of 3
affected packages

Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart

Carried by container images the latest versions of 5,544 of 18,087 indexed charts deploy, on 6,392 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.96,392
golang-1.19deb1.19.8-2no fix listed1
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
OSV records
CGA-2wpp-p453-fwrjDEBIAN-CVE-2026-94440GO-2026-6608
Also known as
CGA-8235-g5m3-vf73, CGA-frxc-9943-gmf8, CGA-gmgx-vgc6-mmw7, CGA-gw93-g38m-27f8, CGA-j2rm-vrxp-7gvc
Trending
Rank 8 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,544 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-communityOfficialVerified publisher92.2.05 of 6See more

kube-prometheus-stack prometheus-community 92.2.0

5 of the 6 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
stdlib@go1.26.7
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
stdlib@go1.27.1
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
stdlib@go1.26.8
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
stdlib@go1.26.5
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
stdlib@go1.26.6
1.26.9

Open the chart page →

1,050
cert-managercert-managerOfficialVerified publisher1.21.24 of 4See more

cert-manager cert-manager 1.21.2

4 of the 4 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
stdlib@go1.26.8
1.26.9

Open the chart page →

528
argo-cdargoOfficialVerified publisher10.10.22 of 3See more

argo-cd argo 10.10.2

2 of the 3 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
stdlib@go1.27.1
1.26.9
quay.io/argoproj/argocd:v3.5.449dff79439bb
stdlib@go1.25.3
1.26.9

Open the chart page →

2,506
ingress-nginxingress-nginx4.15.12 of 2See more

ingress-nginx ingress-nginx 4.15.1

2 of the 2 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
stdlib@go1.26.1
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
stdlib@go1.26.1
1.26.9

Open the chart page →

2,200
prometheusprometheus-communityOfficialVerified publisher29.36.16 of 6See more

prometheus prometheus-community 29.36.1

6 of the 6 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.106b52bd4dbe3
stdlib@go1.26.8
1.26.9
quay.io/prometheus/alertmanager:v0.34.1e9733bafb1bd
stdlib@go1.26.8
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
stdlib@go1.26.5
1.26.9
quay.io/prometheus/prometheus:v3.15.0efd719c99d83
stdlib@go1.27.1
1.26.9
quay.io/prometheus/pushgateway:v1.11.491a56b89b97d
stdlib@go1.27.1
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
stdlib@go1.26.6
1.26.9

Open the chart page →

1,145
redisbitnamiVerified publisher28.3.11 of 1See more

redis bitnami 28.3.1

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9

Open the chart page →

89
traefiktraefikOfficialVerified publisher41.7.11 of 1See more

traefik traefik 41.7.1

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
library/traefik:v3.7.14575fa15b1350
stdlib@go1.26.8
1.26.9

Open the chart page →

141
kubernetes-dashboardk8s-dashboard7.14.04 of 5See more

kubernetes-dashboard k8s-dashboard 7.14.0

4 of the 5 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
kubernetesui/dashboard-api:1.14.096a702cfd339
stdlib@go1.23.12
1.26.9
kubernetesui/dashboard-auth:1.4.053e9917898bf
stdlib@go1.23.12
1.26.9
kubernetesui/dashboard-metrics-scraper:1.2.25154b68252bd
stdlib@go1.23.4
1.26.9
kubernetesui/dashboard-web:1.7.0cc7c31bd2d84
stdlib@go1.23.9
1.26.9

Open the chart page →

4,694
lokigrafana7.3.03 of 6See more

loki grafana 7.3.0

3 of the 6 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
grafana/loki:3.6.1144148ad243c0
stdlib@go1.26.2
1.26.9
grafana/loki-canary:3.6.121e9bfcff3867
stdlib@go1.26.4
1.26.9
prom/memcached-exporter:v0.15.4b6763ecb3c47
stdlib@go1.25.3
1.26.9

Open the chart page →

5,110
metrics-servermetrics-serverVerified publisher3.14.01 of 1See more

metrics-server metrics-server 3.14.0

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
stdlib@go1.26.4
1.26.9

Open the chart page →

385
vaulthashicorpVerified publisher0.34.12 of 2See more

vault hashicorp 0.34.1

2 of the 2 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
hashicorp/vault:2.0.45be49781ecf7
stdlib@go1.26.5
1.26.9
hashicorp/vault-k8s:1.7.655e27b080c9b
stdlib@go1.26.5
1.26.9

Open the chart page →

1,034
gitlabgitlabVerified publisher10.4.118 of 21See more

gitlab gitlab 10.4.1

18 of the 21 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.9.10049bcb384c5
stdlib@go1.26.7
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
stdlib@go1.26.8
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.0142a1f11df8d
stdlib@go1.26.8
1.26.9
quay.io/prometheus/prometheus:v3.14.05ce7540c3c00
stdlib@go1.26.6
1.26.9
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.104019bb2e325
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/cfssl-self-sign:v19.4.15dd7827fa474
stdlib@go1.22.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.198d46dc7e071
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.19df7d5aa03fe
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabb21661438ee9
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.2693bfdee8aa8
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-kas:v19.4.14ed6de4d77e1
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3180688274b2c
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.17419aa33eb17
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.1a072f0a41f28
stdlib@go1.26.4
1.26.9
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
stdlib@go1.26.5
1.26.9

Open the chart page →

20,608
harborharborOfficialVerified publisher1.19.25 of 8See more

harbor harbor 1.19.2

5 of the 8 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.2d7b780d23721
stdlib@go1.26.4
1.26.9
goharbor/harbor-jobservice:v2.15.2f71a4452a095
stdlib@go1.26.4
1.26.9
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
stdlib@go1.26.4
1.26.9
goharbor/registry-photon:v2.15.2c4ebef61ceb5
stdlib@go1.26.4
1.26.9
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
stdlib@go1.26.4
1.26.9

Open the chart page →

2,986
jenkinsjenkinsciOfficialVerified publisher5.9.671 of 2See more

jenkins jenkinsci 5.9.67

1 of the 2 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
jenkins/jenkins:2.580.1-jdk21a660310e39ad
stdlib@go1.27.0
1.26.9

Open the chart page →

2,148
external-secretsexternal-secrets-operatorVerified publisher2.12.01 of 1See more

external-secrets external-secrets-operator 2.12.0

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v2.12.07a3c4f7e038f
stdlib@go1.26.6
1.26.9

Open the chart page →

185
external-dnsexternal-dnsVerified publisher1.23.01 of 1See more

external-dns external-dns 1.23.0

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
registry.k8s.io/external-dns/external-dns:v0.23.01854499e2b08
stdlib@go1.27.0
1.26.9

Open the chart page →

128
longhornlonghorn1.13.03 of 3See more

longhorn longhorn 1.13.0

3 of the 3 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.13.07372f3c59239
stdlib@go1.26.8
1.26.9
longhornio/longhorn-share-manager:v1.13.053950f78b7af
stdlib@go1.26.8
1.26.9
longhornio/longhorn-ui:v1.13.0f22fb0254ae5
stdlib@go1.26.8
1.26.9

Open the chart page →

443
gitlab-runnergitlabVerified publisher0.93.01 of 1See more

gitlab-runner gitlab 0.93.0

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
stdlib@go1.26.5
1.26.9

Open the chart page →

575
ciliumciliumOfficialVerified publisher1.20.23 of 3See more

cilium cilium 1.20.2

3 of the 3 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.22939231d0d3e
stdlib@go1.26.8
1.26.9
quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82af7382699576
stdlib@go1.27.1
1.26.9
quay.io/cilium/operator-generic:v1.20.264d8798350e8
stdlib@go1.26.8
1.26.9

Open the chart page →

1,840
airflowapache-airflowOfficialVerified publisher1.22.01 of 4See more

airflow apache-airflow 1.22.0

1 of the 4 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/prometheus/statsd-exporter:v0.30.0378cb79c4ac7
stdlib@go1.26.3
1.26.9

Open the chart page →

3,770
mongodbbitnamiVerified publisher20.0.01 of 1See more

mongodb bitnami 20.0.0

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
bitnami/mongodb:latestad05bb9a19fa
stdlib@go1.26.8
1.26.9

Open the chart page →

432
velerovmware-tanzu12.2.11 of 1See more

velero vmware-tanzu 12.2.1

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
velero/velero:v1.18.237396519f399
stdlib@go1.25.11
1.26.9

Open the chart page →

1,429
metallbmetallbVerified publisher0.16.13 of 4See more

metallb metallb 0.16.1

3 of the 4 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.16.1f51ab515de9c
stdlib@go1.25.9
1.26.9
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
stdlib@go1.25.8
1.26.9
quay.io/metallb/speaker:v0.16.116561e96531e
stdlib@go1.25.9
1.26.9

Open the chart page →

3,179
rancherrancher-stable2.15.22 of 2See more

rancher rancher-stable 2.15.2

2 of the 2 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.20c3d8e570255
stdlib@go1.26.4
1.26.9
rancher/shell:v0.8.21eeed72d4eda
stdlib@go1.26.8
1.26.9

Open the chart page →

2,431
cloudnative-pgcloudnative-pgVerified publisher0.29.11 of 1See more

cloudnative-pg cloudnative-pg 0.29.1

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.30.1923c267ec296
stdlib@go1.27.1
1.26.9

Open the chart page →

124
kyvernokyvernoOfficialVerified publisher3.9.11 of 7See more

kyverno kyverno 3.9.1

1 of the 7 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
ghcr.io/kyverno/readiness-checker:v1.19.131bb42ce7f5b
stdlib@go1.26.6
1.26.9

Open the chart page →

159
argo-workflowsargoOfficialVerified publisher2.0.123 of 3See more

argo-workflows argo 2.0.12

3 of the 3 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-workflows-crdinstaller:v4.1.593534a0d0ba3
stdlib@go1.26.5
1.26.9
quay.io/argoproj/argocli:v4.1.5e0824b55297b
stdlib@go1.26.5
1.26.9
quay.io/argoproj/workflow-controller:v4.1.5328307c9436f
stdlib@go1.26.5
1.26.9

Open the chart page →

766
giteagiteaOfficialVerified publisher12.7.02 of 4See more

gitea gitea 12.7.0

2 of the 4 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.26.9
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
stdlib@go1.24.6
1.26.9

Open the chart page →

10,350
oauth2-proxyoauth2-proxyOfficialVerified publisher10.7.11 of 1See more

oauth2-proxy oauth2-proxy 10.7.1

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.15.58498b0d0ef0a
stdlib@go1.26.8
1.26.9

Open the chart page →

128
nginxbitnamiVerified publisher25.2.11 of 1See more

nginx bitnami 25.2.1

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
bitnami/nginx:latestb8d42f076789
stdlib@go1.26.8
1.26.9

Open the chart page →

111
wordpressbitnamiVerified publisher34.1.32 of 2See more

wordpress bitnami 34.1.3

2 of the 2 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9
bitnami/wordpress:latest845d250ecd73
stdlib@go1.26.8
1.26.9

Open the chart page →

618
sealed-secretsbitnami-labsVerified publisher2.18.61 of 1See more

sealed-secrets bitnami-labs 2.18.6

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.37.03fe0103896b8
stdlib@go1.26.3
1.26.9

Open the chart page →

599
kedakedacore2.21.03 of 3See more

keda kedacore 2.21.0

3 of the 3 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.21.081fe6547ce8d
stdlib@go1.26.8
1.26.9
ghcr.io/kedacore/keda-admission-webhooks:2.21.0e1969628cca6
stdlib@go1.26.8
1.26.9
ghcr.io/kedacore/keda-metrics-apiserver:2.21.0255375037fe5
stdlib@go1.26.8
1.26.9

Open the chart page →

384
nginx-ingressnginxVerified publisher2.7.31 of 1See more

nginx-ingress nginx 2.7.3

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
nginx/nginx-ingress:5.6.313dafd0b7bf5
stdlib@go1.27.1
1.26.9

Open the chart page →

1,566
nfs-subdir-external-provisionernfs-subdir-external-provisioner4.0.181 of 1See more

nfs-subdir-external-provisioner nfs-subdir-external-provisioner 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
stdlib@go1.15
1.26.9

Open the chart page →

3,917
artifact-hubartifact-hubVerified publisher1.23.06 of 7See more

artifact-hub artifact-hub 1.23.0

6 of the 7 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
stdlib@go1.25.7
1.26.9
artifacthub/db-migrator:v1.23.028c13565ac5c
stdlib@go1.26.4
1.26.9
artifacthub/hub:v1.23.07d3a91c539dc
stdlib@go1.26.4
1.26.9
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.26.9
artifacthub/scanner:v1.23.02d8365601f0e
stdlib@go1.25.7
1.26.9
artifacthub/tracker:v1.23.05368d21a6e5c
stdlib@go1.24.4
1.26.9

Open the chart page →

14,535
kube-state-metricsprometheus-communityVerified publisher8.6.01 of 1See more

kube-state-metrics prometheus-community 8.6.0

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
stdlib@go1.26.6
1.26.9

Open the chart page →

237
consulhashicorpVerified publisher2.0.42 of 2See more

consul hashicorp 2.0.4

2 of the 2 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
hashicorp/consul:2.0.41c59f007df8e
stdlib@go1.26.7
1.26.9
hashicorp/consul-k8s-control-plane:2.0.49334d7f4bcf0
stdlib@go1.26.7
1.26.9

Open the chart page →

291
mariadbbitnamiVerified publisher28.1.11 of 1See more

mariadb bitnami 28.1.1

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9

Open the chart page →

89
alloygrafana1.13.12 of 2See more

alloy grafana 1.13.1

2 of the 2 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
grafana/alloy:v1.20.12aa2099af76c
stdlib@go1.26.7
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.0142a1f11df8d
stdlib@go1.26.8
1.26.9

Open the chart page →

796
prometheus-blackbox-exporterprometheus-communityOfficialVerified publisher11.20.01 of 1See more

prometheus-blackbox-exporter prometheus-community 11.20.0

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.29.09613f2884689
stdlib@go1.27.1
1.26.9

Open the chart page →

128
reloaderstakaterVerified publisher2.2.181 of 1See more

reloader stakater 2.2.18

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
ghcr.io/stakater/reloader:v1.4.22def2480040ad
stdlib@go1.26.8
1.26.9

Open the chart page →

124
argo-rolloutsargoOfficialVerified publisher2.43.61 of 1See more

argo-rollouts argo 2.43.6

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-rollouts:v1.10.0187630ba7228
stdlib@go1.26.7
1.26.9

Open the chart page →

284
deschedulerdescheduler0.37.01 of 1See more

descheduler descheduler 0.37.0

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
registry.k8s.io/descheduler/descheduler:v0.37.088deef34ff5c
stdlib@go1.26.0
1.26.9

Open the chart page →

540
argo-cdargo-cd-oci10.10.22 of 3See more

argo-cd argo-cd-oci 10.10.2

2 of the 3 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
stdlib@go1.27.1
1.26.9
quay.io/argoproj/argocd:v3.5.449dff79439bb
stdlib@go1.25.3
1.26.9

Open the chart page →

2,506
jaegerjaegertracingOfficialVerified publisher4.14.11 of 1See more

jaeger jaegertracing 4.14.1

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
jaegertracing/jaeger:2.21.03d0ac795ff98
stdlib@go1.27.1
1.26.9

Open the chart page →

324
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-image-awaiter:4.4.2c4df1176d152
stdlib@go1.23.12
1.26.9
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
stdlib@go1.23.10
1.26.9

Open the chart page →

10,019
mimir-distributedgrafana6.2.13 of 5See more

mimir-distributed grafana 6.2.1

3 of the 5 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
grafana/mimir:3.2.192838f113ba5
stdlib@go1.26.7
1.26.9
grafana/rollout-operator:v0.38.132fe838b79dd
stdlib@go1.26.5
1.26.9
pgsty/silo:RELEASE.2026-09-03T13-18-01Zb616a0cf8cb2
stdlib@go1.27.1
1.26.9

Open the chart page →

2,812
headlampheadlampOfficialVerified publisher0.45.01 of 1See more

headlamp headlamp 0.45.0

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.45.0db3f0e0fc58d
stdlib@go1.26.7
1.26.9

Open the chart page →

448
argocd-image-updaterargoOfficialVerified publisher1.3.11 of 1See more

argocd-image-updater argo 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-94440.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
stdlib@go1.26.5
1.26.9

Open the chart page →

1,167

Container images carrying it

6,392 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
enketo/enketo-express:3.0.4dcad9c2273f6
stdlib@go1.17.1
1.26.9
1
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
stdlib@go1.24.6
1.26.9
1
envoyproxy/gateway:v0.5.02a9f99d28567
stdlib@go1.20.6
1.26.9
1
envoyproxy/gateway-dev:latest97b2a036f523
stdlib@go1.27.1
1.26.9
1
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
stdlib@go1.24.5
1.26.9
1
envoyproxy/ratelimit:v1.4.071081616da3e
stdlib@go1.14
1.26.9
1
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
stdlib@go1.14.13
1.26.9
1
envoyproxy/ratelimit:4d2efd61ede09a75a84c
stdlib@go1.14.15
1.26.9
1
epamedp/admin-console-operator:2.14.090f9921d8d58
stdlib@go1.19.6
1.26.9
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
stdlib@go1.17.2
1.26.9
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
stdlib@go1.18.3
1.26.9
1
epamedp/edp-argocd-operator:0.2.0976a662a5e72
stdlib@go1.18.4
1.26.9
1
epamedp/edp-headlamp:0.25.093417e18bb1a
stdlib@go1.21.13
1.26.9
1
epamedp/edp-tekton:0.2.4924939850655
stdlib@go1.18.3
1.26.9
1
epamedp/gerrit-operator:2.25.08de22fc5051c
stdlib@go1.25.12
1.26.9
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
stdlib@go1.17.2
1.26.9
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
stdlib@go1.20.11
1.26.9
1
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
stdlib@go1.17.2
1.26.9
1
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
stdlib@go1.17.2
1.26.9
1
epamedp/keycloak-operator:1.35.0a5398eaa7b80
stdlib@go1.25.12
1.26.9
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
stdlib@go1.17.2
1.26.9
1
epamedp/nexus-operator:3.6.09fede333ef27
stdlib@go1.25.12
1.26.9
1
epamedp/perf-operator:2.13.0bd2079b7bfcb
stdlib@go1.19.6
1.26.9
1
epamedp/reconciler:2.12.0d33e938b6d59
stdlib@go1.18.4
1.26.9
1
epamedp/sonar-operator:3.4.0661d1648a49a
stdlib@go1.25.12
1.26.9
1
epamedp/tekton-custom-task:0.2.067d896676f45
stdlib@go1.24.2
1.26.9
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.26.9
1
erenozcan17/go_backend:v4.250b4f23422b6
stdlib@go1.23.12
1.26.9
1
erigontech/erigon:latest28ee51ce29ec
stdlib@go1.27.1
1.26.9
1
erigontech/erigon:v2.61.288706754b627
stdlib@go1.22.12
1.26.9
1
erudikaltd/para:latest_stablea6aba08c21fa
stdlib@go1.26.7
1.26.9
1
escaping/core-keeper-dedicated:latest87fa79255962
stdlib@go1.24.4
1.26.9
1
etejeda/butlerci:0.1.0737d58183abc
stdlib@go1.16.3
1.26.9
1
ethereum/client-go:v1.10.2603604c12f612
stdlib@go1.18.8
1.26.9
1
ethereum/client-go:v1.15.101f36ca5922a5
stdlib@go1.24.2
1.26.9
1
ethereum/client-go:v1.16.532b878e4144a
stdlib@go1.24.9
1.26.9
1
ethereum/client-go:stable4753febf6e7c
stdlib@go1.27.1
1.26.9
1
ethereum/client-go:latest5ab9a76153b0
stdlib@go1.27.1
1.26.9
1
ethereum/client-go:v1.10.186d6d12a40465
stdlib@go1.18.2
1.26.9
1
ethereum/client-go:v1.14.8886ec69b35b0
stdlib@go1.22.6
1.26.9
1
ethereum/client-go:v1.10.23cce21b423165
stdlib@go1.18.5
1.26.9
1
ethereum/client-go:v1.10.15d99fbb9585c7
stdlib@go1.17.5
1.26.9
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
stdlib@go1.19.3
1.26.9
1
ethereumoptimism/l2geth:0.5.315577036dc36d
stdlib@go1.18
1.26.9
1
etherpad/etherpad:latest6f87beef31d9
stdlib@go1.26.4
1.26.9
1
ethersphere/bee:2.2.0a884fd84b72f
stdlib@go1.22.7
1.26.9
1
ethersphere/beekeeper:lateste3bc0da9ffde
stdlib@go1.26.8
1.26.9
1
ethersphere/ethproxy:latest3a8a3926caa2
stdlib@go1.18.7
1.26.9
1
ethersphere/onboarding-faucet:0.3.0513154aab230
stdlib@go1.18.2
1.26.9
1
ethpandaops/armiarma:master1a9c3264f0a9
stdlib@go1.21.8
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.