StackRadar

CVE-2026-94448

Unscored

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,554
of 18,071 indexed, latest versions
Container images
6,411
deployed by those charts
Fix available
1 of 2
affected packages

Reset context tracking on consecutive template expressions in html/template

Carried by container images the latest versions of 5,554 of 18,071 indexed charts deploy, on 6,411 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.96,411
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-94448GO-2026-6599
Trending
Rank 10 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,554 by stars
ChartLatestAffected imagesRadar Score
postgrescloudpirates-postgresVerified publisher0.21.21 of 1See more

postgres cloudpirates-postgres 0.21.2

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
library/postgres:18.674935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

1,636
vault-secrets-operatorhashicorpVerified publisher1.6.02 of 2See more

vault-secrets-operator hashicorp 1.6.0

2 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
hashicorp/vault-secrets-operator:1.6.002a79a046037
stdlib@go1.27.1
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
stdlib@go1.23.0
1.26.9

Open the chart page →

1,467
linkerd-vizlinkerd2Verified publisher30.12.111 of 5See more

linkerd-viz linkerd2 30.12.11

1 of the 5 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
prom/prometheus:v2.48.0b440bc0e8aa5
stdlib@go1.21.4
1.26.9

Open the chart page →

1,933
trust-managercert-managerOfficialVerified publisher0.25.02 of 2See more

trust-manager cert-manager 0.25.0

2 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/jetstack/trust-manager:v0.25.00521921c2a46
stdlib@go1.27.1
1.26.9
quay.io/jetstack/trust-pkg-debian-trixie:20250419.23093d4f6634f
stdlib@go1.27.1
1.26.9

Open the chart page →

128
gatekeepergatekeeperVerified publisher3.23.12 of 3See more

gatekeeper gatekeeper 3.23.1

2 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.23.1dfc6fc78753f
stdlib@go1.26.6
1.26.9
openpolicyagent/gatekeeper-crds:v3.23.1ab3620e6bec9
stdlib@go1.26.6
1.26.9

Open the chart page →

694
snapshot-controllerpiraeus-chartsVerified publisher5.3.01 of 1See more

snapshot-controller piraeus-charts 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
stdlib@go1.26.3
1.26.9

Open the chart page →

452
rocketchatrocketchat-server7.0.26 of 12See more

rocketchat rocketchat-server 7.0.2

6 of the 12 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
stdlib@go1.19.12
1.26.9
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
stdlib@go1.20.7
1.26.9
library/nats:2.12-alpineb270f5e24283
stdlib@go1.25.12
1.26.9
natsio/nats-box:0.19.28031d190c7ee
stdlib@go1.25.2
1.26.9
natsio/nats-server-config-reloader:0.21.110ff229eaf52
stdlib@go1.25.5
1.26.9
natsio/prometheus-nats-exporter:0.18.002469dc907bc
stdlib@go1.24.6
1.26.9

Open the chart page →

16,018
zammadzammadOfficialVerified publisher19.1.41 of 5See more

zammad zammad 19.1.4

1 of the 5 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.26.9

Open the chart page →

6,014
victoria-metrics-clustervictoriametricsVerified publisher0.52.03 of 3See more

victoria-metrics-cluster victoriametrics 0.52.0

3 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
victoriametrics/vminsert:v1.153.0-cluster629d128af12f
stdlib@go1.27.1
1.26.9
victoriametrics/vmselect:v1.153.0-cluster3a593a1d02f7
stdlib@go1.27.1
1.26.9
victoriametrics/vmstorage:v1.153.0-cluster83e67bde1b2a
stdlib@go1.27.1
1.26.9

Open the chart page →

215
solr-operatorapache-solrVerified publisher0.9.12 of 3See more

solr-operator apache-solr 0.9.1

2 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
apache/solr-operator:v0.9.14db34508137f
stdlib@go1.22.12
1.26.9
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
stdlib@go1.19.7
1.26.9

Open the chart page →

3,970
influxdb2influxdata2.1.21 of 1See more

influxdb2 influxdata 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
library/influxdb:2.7.4-alpinea10d46445d68
stdlib@go1.21.3
1.26.9

Open the chart page →

2,747
k10kastenVerified publisher9.0.722 of 23See more

k10 kasten 9.0.7

22 of the 23 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
gcr.io/kasten-images/aggregatedapis:9.0.79a189cf0aff8
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/auth:9.0.716efe4c210e0
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/bloblifecyclemanager:9.0.783f7c06dc4d1
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/catalog:9.0.70ea3df63f5b6
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/configmap-reload:9.0.7b9b8a1b65f7a
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/controllermanager:9.0.7a01f872d8e0c
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/crypto:9.0.76c6b6d9af1d4
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/dashboardbff:9.0.71a8b1ccfc402
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/events:9.0.7e7beb79514f9
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/executor:9.0.74fe7419cecd9
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/garbagecollector:9.0.74dfd4a2dae57
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/gateway:9.0.76f14d4acd0c5
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/jobs:9.0.7a093d080604f
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/kanister:9.0.703d05d517803
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/kanister-tools:9.0.79778af80396e
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/logging:9.0.7e41747f4a3c3
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/metering:9.0.7209e1aaee219
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/prometheus:9.0.793bdb766db72
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/repositories:9.0.75c5435aea185
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/state:9.0.7c4bfd7feb74a
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/upgrade:9.0.7b2447f8bc553
stdlib@go1.27.1
1.26.9
gcr.io/kasten-images/vbrintegrationapi:9.0.785e432303eff
stdlib@go1.27.1
1.26.9

Open the chart page →

3,394
mariadb-operatormariadb-operator26.10.11 of 1See more

mariadb-operator mariadb-operator 26.10.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/mariadb-operator/mariadb-operator:26.10.137714fb240a5
stdlib@go1.27.1
1.26.9

Open the chart page →

416
ceph-csi-cephfsceph-csiOfficialVerified publisher3.18.16 of 6See more

ceph-csi-cephfs ceph-csi 3.18.1

6 of the 6 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.18.1a8c0653a9565
stdlib@go1.26.4
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.13.0d1a26170efed
stdlib@go1.26.6
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.18.0b7fefd08651f
stdlib@go1.26.6
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
stdlib@go1.26.3
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
stdlib@go1.26.3
1.26.9

Open the chart page →

2,061
ceph-csi-rbdceph-csiOfficialVerified publisher3.18.16 of 6See more

ceph-csi-rbd ceph-csi 3.18.1

6 of the 6 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.18.1a8c0653a9565
stdlib@go1.26.4
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.13.0d1a26170efed
stdlib@go1.26.6
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.18.0b7fefd08651f
stdlib@go1.26.6
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
stdlib@go1.26.3
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
stdlib@go1.26.3
1.26.9

Open the chart page →

2,061
chaos-meshchaos-meshVerified publisher2.8.44 of 4See more

chaos-mesh chaos-mesh 2.8.4

4 of the 4 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
stdlib@go1.25.5
1.26.9
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
stdlib@go1.25.11
1.26.9
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
stdlib@go1.25.11
1.26.9
ghcr.io/chaos-mesh/chaos-mesh:v2.8.49e48285bb44c
stdlib@go1.25.11
1.26.9

Open the chart page →

8,160
rabbitmqcloudpirates-rabbitmqVerified publisher0.21.311 of 2See more

rabbitmq cloudpirates-rabbitmq 0.21.31

1 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6-management8dd6e3570dda
stdlib@go1.22.2
1.26.9

Open the chart page →

1,243
csi-driver-nfscsi-driver-nfsVerified publisher4.13.46 of 6See more

csi-driver-nfs csi-driver-nfs 4.13.4

6 of the 6 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
stdlib@go1.26.3
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
stdlib@go1.26.3
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
stdlib@go1.26.3
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
stdlib@go1.26.3
1.26.9
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
stdlib@go1.26.4
1.26.9

Open the chart page →

4,787
podinfopodinfo6.15.01 of 1See more

podinfo podinfo 6.15.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/stefanprodan/podinfo:6.15.0ec73780a8425
stdlib@go1.27.0
1.26.9

Open the chart page →

377
portainerportainer245.2.01 of 1See more

portainer portainer 245.2.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
portainer/portainer-ce:2.45.203f94a406496
stdlib@go1.26.6
1.26.9

Open the chart page →

420
atlantisatlantis6.16.11 of 1See more

atlantis atlantis 6.16.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/runatlantis/atlantis:v0.48.142bde40e38ec
stdlib@go1.26.6
1.26.9

Open the chart page →

730
codercoder-v2OfficialVerified publisher2.38.01 of 1See more

coder coder-v2 2.38.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/coder/coder:v2.38.038a4cfc548b0
stdlib@go1.26.4
1.26.9

Open the chart page →

243
vclusterloftVerified publisher0.0.0-ci.31 of 2See more

vcluster loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
stdlib@go1.19.4
1.26.9

Open the chart page →

3,214
milvusmilvus4.0.313 of 5See more

milvus milvus 4.0.31

3 of the 5 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.5-r2102aac62827b
stdlib@go1.18.2
1.26.9
milvusdb/milvus:v2.2.13a3a55e1c1497
stdlib@go1.18.3
1.26.9
milvusdb/milvus-config-tool:v0.1.12212dfb61401
stdlib@go1.16.15
1.26.9

Open the chart page →

177,006
semaphoresemaphoreuiOfficialVerified publisher16.2.21 of 1See more

semaphore semaphoreui 16.2.2

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.18.3e9260bfa8255
stdlib@go1.25.5
1.26.9

Open the chart page →

3,051
victoria-metrics-operatorvictoriametricsVerified publisher0.68.11 of 1See more

victoria-metrics-operator victoriametrics 0.68.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
victoriametrics/operator:v0.75.078da26b41a81
stdlib@go1.27.1
1.26.9

Open the chart page →

76
cockroachdbcockroachdbVerified publisher22.0.41 of 3See more

cockroachdb cockroachdb 22.0.4

1 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.10b0fcc6c8147a
stdlib@go1.26.2
1.26.9

Open the chart page →

567
flaggerflagger1.45.01 of 1See more

flagger flagger 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger:1.45.015b372d35012
stdlib@go1.26.7
1.26.9

Open the chart page →

357
grafana-agentgrafana0.44.22 of 2See more

grafana-agent grafana 0.44.2

2 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
grafana/agent:v0.44.23364714a2f64
stdlib@go1.22.11
1.26.9
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.26.9

Open the chart page →

4,613
tempografana-communityVerified publisher3.1.01 of 1See more

tempo grafana-community 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
grafana/tempo:3.1.03076b8dcdfb3
stdlib@go1.27.1
1.26.9

Open the chart page →

123
mesherymesheryOfficialVerified publisher1.0.701 of 1See more

meshery meshery 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
stdlib@go1.26.4
1.26.9

Open the chart page →

1,841
prometheus-mysql-exporterprometheus-communityVerified publisher2.15.01 of 1See more

prometheus-mysql-exporter prometheus-community 2.15.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/prometheus/mysqld-exporter:v0.20.0abed8dac117b
stdlib@go1.26.5
1.26.9

Open the chart page →

221
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
stdlib@go1.19.12
1.26.9

Open the chart page →

12,087
tomcatbitnamiVerified publisher13.6.321 of 1See more

tomcat bitnami 13.6.32

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnami/tomcat:latesta364a0270d35
stdlib@go1.26.8
1.26.9

Open the chart page →

137
local-path-provisionercontainerooVerified publisher0.0.381 of 1See more

local-path-provisioner containeroo 0.0.38

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.37e757967a5ec3
stdlib@go1.26.5
1.26.9

Open the chart page →

191
mailpitjouveVerified publisher0.37.01 of 1See more

mailpit jouve 0.37.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
axllent/mailpit:v1.31.198b916bd3c8d
stdlib@go1.27.1
1.26.9

Open the chart page →

89
signozsignoz0.145.05 of 5See more

signoz signoz 0.145.0

5 of the 5 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.21.2cd9252644ce0
stdlib@go1.19.10
1.26.9
altinity/metrics-exporter:0.21.2df3d57215356
stdlib@go1.19.10
1.26.9
signoz/signoz:v0.145.01301f2df51f0
stdlib@go1.25.7
1.26.9
signoz/signoz-otel-collector:v0.144.12deb566a7a3c0
stdlib@go1.25.0
1.26.9
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.26.9

Open the chart page →

10,350
weblateweblateOfficialVerified publisher0.5.412 of 3See more

weblate weblate 0.5.41

2 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnamilegacy/redis:latest5927ff3702df
stdlib@go1.24.5
1.26.9
weblate/weblate:2026.10.0.16084353e0b28
stdlib@go1.26.7
1.26.9

Open the chart page →

7,282
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
library/postgres:18.65a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

1,753
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
stdlib@go1.19.8
1.26.9

Open the chart page →

5,552
keelkeel1.2.31 of 1See more

keel keel 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/keel-hq/keel:0.22.409872633675d
stdlib@go1.26.5
1.26.9

Open the chart page →

1,014
community-operatormongodb-helm-charts0.13.01 of 1See more

community-operator mongodb-helm-charts 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
stdlib@go1.24.2
1.26.9

Open the chart page →

1,555
openfgaopenfgaOfficialVerified publisher0.3.161 of 1See more

openfga openfga 0.3.16

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
openfga/openfga:v1.22.09cf9a20af32a
stdlib@go1.26.8
1.26.9

Open the chart page →

72
prometheus-kafka-exporterprometheus-communityVerified publisher4.0.01 of 1See more

prometheus-kafka-exporter prometheus-community 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.9.04150e46b2e96
stdlib@go1.24.0
1.26.9

Open the chart page →

1,119
prometheus-mongodb-exporterprometheus-communityVerified publisher3.22.01 of 1See more

prometheus-mongodb-exporter prometheus-community 3.22.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
percona/mongodb_exporter:0.53.00214e482b2cd
stdlib@go1.26.2
1.26.9

Open the chart page →

471
node-local-dnsdeliveryheroVerified publisher2.9.21 of 1See more

node-local-dns deliveryhero 2.9.2

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
stdlib@go1.24.8
1.26.9

Open the chart page →

2,216
dragonflydragonflyVerified publisher1.8.52 of 3See more

dragonfly dragonfly 1.8.5

2 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
stdlib@go1.26.5
1.26.9
dragonflyoss/scheduler:v2.5.2d5dea9e662cd
stdlib@go1.25.5
1.26.9

Open the chart page →

5,142
fission-allfission-chartsOfficialVerified publisher1.27.03 of 3See more

fission-all fission-charts 1.27.0

3 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/fission/fission-bundle:v1.27.0d353720b037a
stdlib@go1.26.4
1.26.9
ghcr.io/fission/pre-upgrade-checks:v1.27.0b053fc3539b4
stdlib@go1.26.4
1.26.9
ghcr.io/fission/reporter:v1.27.0c77cc925debe
stdlib@go1.26.4
1.26.9

Open the chart page →

773
nginx-gateway-fabricnginx-gateway-fabricOfficialVerified publisher0.0.0-edge1 of 1See more

nginx-gateway-fabric nginx-gateway-fabric 0.0.0-edge

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/nginx/nginx-gateway-fabric:edgeefef59c86605
stdlib@go1.27.1
1.26.9

Open the chart page →

72
rancherrancher-latest2.15.22 of 2See more

rancher rancher-latest 2.15.2

2 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.20c3d8e570255
stdlib@go1.26.4
1.26.9
rancher/shell:v0.8.21eeed72d4eda
stdlib@go1.26.8
1.26.9

Open the chart page →

2,326

Container images carrying it

6,411 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.26.9
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
stdlib@go1.22.2
1.26.9
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
stdlib@go1.24.1
1.26.9
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
stdlib@go1.22.5
1.26.9
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
stdlib@go1.24.6
1.26.9
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
stdlib@go1.26.2
1.26.9
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
stdlib@go1.20.3
1.26.9
3
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
stdlib@go1.23.1
1.26.9
3
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
stdlib@go1.25.7
1.26.9
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
stdlib@go1.22.5
1.26.9
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
stdlib@go1.24.2
1.26.9
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
stdlib@go1.21.5
1.26.9
3
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
stdlib@go1.25.7
1.26.9
3
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
stdlib@go1.23.1
1.26.9
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
stdlib@go1.23.1
1.26.9
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
stdlib@go1.20.3
1.26.9
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
stdlib@go1.23.1
1.26.9
3
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
stdlib@go1.20.5
1.26.9
3
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
stdlib@go1.24.6
1.26.9
3
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
stdlib@go1.25.7
1.26.9
3
registry.k8s.io/sig-storage/livenessprobe:v2.20.019f2cf2f40e1
stdlib@go1.26.6
1.26.9
3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
stdlib@go1.20.3
1.26.9
3
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
stdlib@go1.24.6
1.26.9
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
stdlib@go1.16.2
1.26.9
3
1password/scim:v2.3.129d0c6cb67eb
stdlib@go1.16.8
1.26.9
2
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.26.9
2
alazidis/kube-netlag:1.1.00e8c84152201
stdlib@go1.24.13
1.26.9
2
alpine/git:latest:v2.54.0832b1cd1a271
stdlib@go1.26.8
1.26.9
2
alpine/k8s:1.32.12048f8d9c8cc7
stdlib@go1.25.7
1.26.9
2
alpine/k8s:1.37.0b421c2e9419e
stdlib@go1.26.7
1.26.9
2
alpine/kubectl:1.35.49ccd82364762
stdlib@go1.25.9
1.26.9
2
alpine/kubectl:1.35.2ec8f734b0a10
stdlib@go1.25.7
1.26.9
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
stdlib@go1.19.10
1.26.9
2
altinity/clickhouse-operator:0.16.1db7dde971407
stdlib@go1.13.15
1.26.9
2
altinity/metrics-exporter:0.16.185b4fdbae053
stdlib@go1.13.15
1.26.9
2
altinity/metrics-exporter:0.21.2df3d57215356
stdlib@go1.19.10
1.26.9
2
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
stdlib@go1.13.4
1.26.9
2
amazon/aws-fsx-csi-driver:latestc9b14856fd22
stdlib@go1.16.8
1.26.9
2
apache/doris:operator-latest3a4422656592
stdlib@go1.23.12
1.26.9
2
apache/skywalking-oap-server:8.1.0-es7641237e0299b
stdlib@go1.13.3
1.26.9
2
apache/skywalking-ui:8.1.067d50e4deff4
stdlib@go1.13.3
1.26.9
2
apache/superset:dockerizeafe59523a6c8
stdlib@go1.20.4
1.26.9
2
apecloud/apecloud-mcp:0.1.094041b080510
stdlib@go1.23.7
1.26.9
2
apecloud/servicemirror:0.5.38c8451abf728
stdlib@go1.25.14
1.26.9
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
stdlib@go1.21.7
1.26.9
2
assistiot/fl_repository_db:latestad8f72108636
stdlib@go1.17.10
1.26.9
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
stdlib@go1.18.9
1.26.9
2
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
stdlib@go1.22.2
1.26.9
2
binwiederhier/ntfy:v2.29.04c599cf08189
stdlib@go1.27.1
1.26.9
2
bitnami/git:latest27e3b3fe7123
stdlib@go1.26.8
1.26.9
2

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.