StackRadar

CVE-2026-94448

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,515
of 18,090 indexed, latest versions
Container images
6,355
deployed by those charts
Fix available
1 of 3
affected packages

Reset context tracking on consecutive template expressions in html/template

Carried by container images the latest versions of 5,515 of 18,090 indexed charts deploy, on 6,355 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.96,355
golang-1.19deb1.19.8-2no fix listed1
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
OSV records
CGA-2h88-jxv5-q7mvDEBIAN-CVE-2026-94448GO-2026-6599
Also known as
CGA-7269-wr3g-w84m, CGA-8p8w-2cqf-g6hq, CGA-98rx-6p2c-qw5v, CGA-9h83-8hpv-mrf5, CGA-qgc9-59hj-5mr6
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,515 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-communityOfficialVerified publisher92.3.05See more

kube-prometheus-stack prometheus-community 92.3.0

5 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
stdlib@go1.26.7
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
stdlib@go1.27.1
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
stdlib@go1.26.8
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
stdlib@go1.26.5
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
stdlib@go1.26.6
1.26.9

Open the chart page →

—
cert-managercert-managerOfficialVerified publisher1.21.24 of 4See more

cert-manager cert-manager 1.21.2

4 of the 4 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
stdlib@go1.26.8
1.26.9

Open the chart page →

528
argo-cdargoOfficialVerified publisher10.10.22 of 3See more

argo-cd argo 10.10.2

2 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
stdlib@go1.27.1
1.26.9
quay.io/argoproj/argocd:v3.5.449dff79439bb
stdlib@go1.25.3
1.26.9

Open the chart page →

2,506
ingress-nginxingress-nginx4.15.12 of 2See more

ingress-nginx ingress-nginx 4.15.1

2 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
stdlib@go1.26.1
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
stdlib@go1.26.1
1.26.9

Open the chart page →

2,200
prometheusprometheus-communityOfficialVerified publisher29.36.16 of 6See more

prometheus prometheus-community 29.36.1

6 of the 6 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.106b52bd4dbe3
stdlib@go1.26.8
1.26.9
quay.io/prometheus/alertmanager:v0.34.1e9733bafb1bd
stdlib@go1.26.8
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
stdlib@go1.26.5
1.26.9
quay.io/prometheus/prometheus:v3.15.0efd719c99d83
stdlib@go1.27.1
1.26.9
quay.io/prometheus/pushgateway:v1.11.491a56b89b97d
stdlib@go1.27.1
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
stdlib@go1.26.6
1.26.9

Open the chart page →

1,145
redisbitnamiVerified publisher28.3.11 of 1See more

redis bitnami 28.3.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9

Open the chart page →

89
traefiktraefikOfficialVerified publisher41.7.11 of 1See more

traefik traefik 41.7.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
library/traefik:v3.7.14575fa15b1350
stdlib@go1.26.8
1.26.9

Open the chart page →

141
kubernetes-dashboardk8s-dashboard7.14.04 of 5See more

kubernetes-dashboard k8s-dashboard 7.14.0

4 of the 5 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
kubernetesui/dashboard-api:1.14.096a702cfd339
stdlib@go1.23.12
1.26.9
kubernetesui/dashboard-auth:1.4.053e9917898bf
stdlib@go1.23.12
1.26.9
kubernetesui/dashboard-metrics-scraper:1.2.25154b68252bd
stdlib@go1.23.4
1.26.9
kubernetesui/dashboard-web:1.7.0cc7c31bd2d84
stdlib@go1.23.9
1.26.9

Open the chart page →

4,694
lokigrafana7.3.03 of 6See more

loki grafana 7.3.0

3 of the 6 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
grafana/loki:3.6.1144148ad243c0
stdlib@go1.26.2
1.26.9
grafana/loki-canary:3.6.121e9bfcff3867
stdlib@go1.26.4
1.26.9
prom/memcached-exporter:v0.15.4b6763ecb3c47
stdlib@go1.25.3
1.26.9

Open the chart page →

5,110
metrics-servermetrics-serverVerified publisher3.14.01 of 1See more

metrics-server metrics-server 3.14.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
stdlib@go1.26.4
1.26.9

Open the chart page →

385
vaulthashicorpVerified publisher0.34.12 of 2See more

vault hashicorp 0.34.1

2 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
hashicorp/vault:2.0.45be49781ecf7
stdlib@go1.26.5
1.26.9
hashicorp/vault-k8s:1.7.655e27b080c9b
stdlib@go1.26.5
1.26.9

Open the chart page →

1,034
gitlabgitlabVerified publisher10.4.118 of 21See more

gitlab gitlab 10.4.1

18 of the 21 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.9.10049bcb384c5
stdlib@go1.26.7
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
stdlib@go1.26.8
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
stdlib@go1.26.8
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.0142a1f11df8d
stdlib@go1.26.8
1.26.9
quay.io/prometheus/prometheus:v3.14.05ce7540c3c00
stdlib@go1.26.6
1.26.9
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.104019bb2e325
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/cfssl-self-sign:v19.4.15dd7827fa474
stdlib@go1.22.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.198d46dc7e071
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.19df7d5aa03fe
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabb21661438ee9
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.2693bfdee8aa8
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-kas:v19.4.14ed6de4d77e1
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3180688274b2c
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.17419aa33eb17
stdlib@go1.26.7
1.26.9
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.1a072f0a41f28
stdlib@go1.26.4
1.26.9
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
stdlib@go1.26.5
1.26.9

Open the chart page →

20,608
harborharborOfficialVerified publisher1.19.25 of 8See more

harbor harbor 1.19.2

5 of the 8 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.2d7b780d23721
stdlib@go1.26.4
1.26.9
goharbor/harbor-jobservice:v2.15.2f71a4452a095
stdlib@go1.26.4
1.26.9
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
stdlib@go1.26.4
1.26.9
goharbor/registry-photon:v2.15.2c4ebef61ceb5
stdlib@go1.26.4
1.26.9
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
stdlib@go1.26.4
1.26.9

Open the chart page →

2,986
jenkinsjenkinsciOfficialVerified publisher5.9.671 of 2See more

jenkins jenkinsci 5.9.67

1 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
jenkins/jenkins:2.580.1-jdk21a660310e39ad
stdlib@go1.27.0
1.26.9

Open the chart page →

2,148
external-secretsexternal-secrets-operatorVerified publisher2.12.01 of 1See more

external-secrets external-secrets-operator 2.12.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v2.12.07a3c4f7e038f
stdlib@go1.26.6
1.26.9

Open the chart page →

185
external-dnsexternal-dnsVerified publisher1.23.01 of 1See more

external-dns external-dns 1.23.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
registry.k8s.io/external-dns/external-dns:v0.23.01854499e2b08
stdlib@go1.27.0
1.26.9

Open the chart page →

128
longhornlonghorn1.13.03 of 3See more

longhorn longhorn 1.13.0

3 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.13.07372f3c59239
stdlib@go1.26.8
1.26.9
longhornio/longhorn-share-manager:v1.13.053950f78b7af
stdlib@go1.26.8
1.26.9
longhornio/longhorn-ui:v1.13.0f22fb0254ae5
stdlib@go1.26.8
1.26.9

Open the chart page →

443
gitlab-runnergitlabVerified publisher0.93.01 of 1See more

gitlab-runner gitlab 0.93.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
stdlib@go1.26.5
1.26.9

Open the chart page →

575
ciliumciliumOfficialVerified publisher1.20.23 of 3See more

cilium cilium 1.20.2

3 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.22939231d0d3e
stdlib@go1.26.8
1.26.9
quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82af7382699576
stdlib@go1.27.1
1.26.9
quay.io/cilium/operator-generic:v1.20.264d8798350e8
stdlib@go1.26.8
1.26.9

Open the chart page →

1,840
airflowapache-airflowOfficialVerified publisher1.22.01 of 4See more

airflow apache-airflow 1.22.0

1 of the 4 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/prometheus/statsd-exporter:v0.30.0378cb79c4ac7
stdlib@go1.26.3
1.26.9

Open the chart page →

3,770
mongodbbitnamiVerified publisher20.0.01 of 1See more

mongodb bitnami 20.0.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnami/mongodb:latestad05bb9a19fa
stdlib@go1.26.8
1.26.9

Open the chart page →

432
velerovmware-tanzu12.2.11 of 1See more

velero vmware-tanzu 12.2.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
velero/velero:v1.18.237396519f399
stdlib@go1.25.11
1.26.9

Open the chart page →

1,429
metallbmetallbVerified publisher0.16.13 of 4See more

metallb metallb 0.16.1

3 of the 4 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.16.1f51ab515de9c
stdlib@go1.25.9
1.26.9
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
stdlib@go1.25.8
1.26.9
quay.io/metallb/speaker:v0.16.116561e96531e
stdlib@go1.25.9
1.26.9

Open the chart page →

3,179
rancherrancher-stable2.15.22 of 2See more

rancher rancher-stable 2.15.2

2 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.20c3d8e570255
stdlib@go1.26.4
1.26.9
rancher/shell:v0.8.21eeed72d4eda
stdlib@go1.26.8
1.26.9

Open the chart page →

2,431
cloudnative-pgcloudnative-pgVerified publisher0.29.11 of 1See more

cloudnative-pg cloudnative-pg 0.29.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.30.1923c267ec296
stdlib@go1.27.1
1.26.9

Open the chart page →

124
kyvernokyvernoOfficialVerified publisher3.9.11 of 7See more

kyverno kyverno 3.9.1

1 of the 7 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/kyverno/readiness-checker:v1.19.131bb42ce7f5b
stdlib@go1.26.6
1.26.9

Open the chart page →

159
argo-workflowsargoOfficialVerified publisher2.0.123 of 3See more

argo-workflows argo 2.0.12

3 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-workflows-crdinstaller:v4.1.593534a0d0ba3
stdlib@go1.26.5
1.26.9
quay.io/argoproj/argocli:v4.1.5e0824b55297b
stdlib@go1.26.5
1.26.9
quay.io/argoproj/workflow-controller:v4.1.5328307c9436f
stdlib@go1.26.5
1.26.9

Open the chart page →

766
giteagiteaOfficialVerified publisher12.7.02 of 4See more

gitea gitea 12.7.0

2 of the 4 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.26.9
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
stdlib@go1.24.6
1.26.9

Open the chart page →

10,350
oauth2-proxyoauth2-proxyOfficialVerified publisher10.7.11 of 1See more

oauth2-proxy oauth2-proxy 10.7.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.15.58498b0d0ef0a
stdlib@go1.26.8
1.26.9

Open the chart page →

128
nginxbitnamiVerified publisher25.2.11 of 1See more

nginx bitnami 25.2.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnami/nginx:latestb8d42f076789
stdlib@go1.26.8
1.26.9

Open the chart page →

111
wordpressbitnamiVerified publisher34.1.32 of 2See more

wordpress bitnami 34.1.3

2 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9
bitnami/wordpress:latest845d250ecd73
stdlib@go1.26.8
1.26.9

Open the chart page →

618
sealed-secretsbitnami-labsVerified publisher2.18.61 of 1See more

sealed-secrets bitnami-labs 2.18.6

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.37.03fe0103896b8
stdlib@go1.26.3
1.26.9

Open the chart page →

599
kedakedacore2.21.03 of 3See more

keda kedacore 2.21.0

3 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.21.081fe6547ce8d
stdlib@go1.26.8
1.26.9
ghcr.io/kedacore/keda-admission-webhooks:2.21.0e1969628cca6
stdlib@go1.26.8
1.26.9
ghcr.io/kedacore/keda-metrics-apiserver:2.21.0255375037fe5
stdlib@go1.26.8
1.26.9

Open the chart page →

384
nginx-ingressnginxVerified publisher2.7.31 of 1See more

nginx-ingress nginx 2.7.3

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
nginx/nginx-ingress:5.6.313dafd0b7bf5
stdlib@go1.27.1
1.26.9

Open the chart page →

1,566
nfs-subdir-external-provisionernfs-subdir-external-provisioner4.0.181 of 1See more

nfs-subdir-external-provisioner nfs-subdir-external-provisioner 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
stdlib@go1.15
1.26.9

Open the chart page →

3,917
artifact-hubartifact-hubVerified publisher1.23.06 of 7See more

artifact-hub artifact-hub 1.23.0

6 of the 7 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
stdlib@go1.25.7
1.26.9
artifacthub/db-migrator:v1.23.028c13565ac5c
stdlib@go1.26.4
1.26.9
artifacthub/hub:v1.23.07d3a91c539dc
stdlib@go1.26.4
1.26.9
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.26.9
artifacthub/scanner:v1.23.02d8365601f0e
stdlib@go1.25.7
1.26.9
artifacthub/tracker:v1.23.05368d21a6e5c
stdlib@go1.24.4
1.26.9

Open the chart page →

14,535
kube-state-metricsprometheus-communityVerified publisher8.6.01 of 1See more

kube-state-metrics prometheus-community 8.6.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
stdlib@go1.26.6
1.26.9

Open the chart page →

237
consulhashicorpVerified publisher2.0.42 of 2See more

consul hashicorp 2.0.4

2 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
hashicorp/consul:2.0.41c59f007df8e
stdlib@go1.26.7
1.26.9
hashicorp/consul-k8s-control-plane:2.0.49334d7f4bcf0
stdlib@go1.26.7
1.26.9

Open the chart page →

291
mariadbbitnamiVerified publisher28.1.11 of 1See more

mariadb bitnami 28.1.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9

Open the chart page →

89
alloygrafana1.13.12 of 2See more

alloy grafana 1.13.1

2 of the 2 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
grafana/alloy:v1.20.12aa2099af76c
stdlib@go1.26.7
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.0142a1f11df8d
stdlib@go1.26.8
1.26.9

Open the chart page →

796
prometheus-blackbox-exporterprometheus-communityOfficialVerified publisher11.20.01 of 1See more

prometheus-blackbox-exporter prometheus-community 11.20.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.29.09613f2884689
stdlib@go1.27.1
1.26.9

Open the chart page →

128
reloaderstakaterVerified publisher2.2.181 of 1See more

reloader stakater 2.2.18

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/stakater/reloader:v1.4.22def2480040ad
stdlib@go1.26.8
1.26.9

Open the chart page →

124
argo-rolloutsargoOfficialVerified publisher2.43.61 of 1See more

argo-rollouts argo 2.43.6

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-rollouts:v1.10.0187630ba7228
stdlib@go1.26.7
1.26.9

Open the chart page →

284
deschedulerdescheduler0.37.01 of 1See more

descheduler descheduler 0.37.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
registry.k8s.io/descheduler/descheduler:v0.37.088deef34ff5c
stdlib@go1.26.0
1.26.9

Open the chart page →

540
argo-cdargo-cd-oci10.10.22 of 3See more

argo-cd argo-cd-oci 10.10.2

2 of the 3 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
stdlib@go1.27.1
1.26.9
quay.io/argoproj/argocd:v3.5.449dff79439bb
stdlib@go1.25.3
1.26.9

Open the chart page →

2,506
jaegerjaegertracingOfficialVerified publisher4.14.11 of 1See more

jaeger jaegertracing 4.14.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
jaegertracing/jaeger:2.21.03d0ac795ff98
stdlib@go1.27.1
1.26.9

Open the chart page →

324
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-image-awaiter:4.4.2c4df1176d152
stdlib@go1.23.12
1.26.9
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
stdlib@go1.23.10
1.26.9

Open the chart page →

10,019
mimir-distributedgrafana6.2.13 of 5See more

mimir-distributed grafana 6.2.1

3 of the 5 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
grafana/mimir:3.2.192838f113ba5
stdlib@go1.26.7
1.26.9
grafana/rollout-operator:v0.38.132fe838b79dd
stdlib@go1.26.5
1.26.9
pgsty/silo:RELEASE.2026-09-03T13-18-01Zb616a0cf8cb2
stdlib@go1.27.1
1.26.9

Open the chart page →

2,812
headlampheadlampOfficialVerified publisher0.45.01 of 1See more

headlamp headlamp 0.45.0

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.45.0db3f0e0fc58d
stdlib@go1.26.7
1.26.9

Open the chart page →

448
argocd-image-updaterargoOfficialVerified publisher1.3.11 of 1See more

argocd-image-updater argo 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-94448.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
stdlib@go1.26.5
1.26.9

Open the chart page →

1,167

Container images carrying it

6,355 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
labs64/auditflow9c1bd414fcfb
stdlib@go1.26.7
1.26.9
1
labs64/checkout4009b8251b57
stdlib@go1.26.7
1.26.9
1
labs64/payment-gateway5421f763b53e
stdlib@go1.26.7
1.26.9
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
stdlib@go1.26.5
1.26.9
1
langgenius/dify-api:1.16.1dcefa5f7c47c
stdlib@go1.26.4
1.26.9
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
stdlib@go1.26.2
1.26.9
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
stdlib@go1.26.2
1.26.9
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
stdlib@go1.26.2
1.26.9
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
stdlib@go1.26.2
1.26.9
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
stdlib@go1.26.2
1.26.9
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
stdlib@go1.26.2
1.26.9
1
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
stdlib@go1.26.2
1.26.9
1
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
stdlib@go1.26.2
1.26.9
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
stdlib@go1.26.4
1.26.9
1
langgenius/dify-plugin-daemon:main-local4b07ca30ab2a
stdlib@go1.26.8
1.26.9
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
stdlib@go1.25.5
1.26.9
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
stdlib@go1.23.3
1.26.9
1
langgenius/dify-sandbox:0.2.15750e1111426e
stdlib@go1.24.13
1.26.9
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.26.9
1
langgenius/dify-web:1.0.0d64914ff0d6d
stdlib@go1.22.5
1.26.9
1
launchdarkly/ld-relay:8.22.0065f211f5d7c
stdlib@go1.27.1
1.26.9
1
lavr/express-botx:0.42.0-rootlessad6ec93952fc
stdlib@go1.25.14
1.26.9
1
layer5/meshery:stable-latest78a8be21bef3
stdlib@go1.23.9
1.26.9
1
layer5/meshery-app-mesh:stable-latest77d59943b3d6
stdlib@go1.19.5
1.26.9
1
layer5/meshery-consul:stable-latest25a4cc38abcd
stdlib@go1.19.13
1.26.9
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
stdlib@go1.13.1
1.26.9
1
layer5/meshery-istio:stable-latestfde47c141ec6
stdlib@go1.23.9
1.26.9
1
layer5/meshery-kuma:stable-latest9d25f029a8a2
stdlib@go1.23.4
1.26.9
1
layer5/meshery-linkerd:stable-latestb99c73bac1f5
stdlib@go1.23.6
1.26.9
1
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
stdlib@go1.19.11
1.26.9
1
layer5/meshery-nsm:stable-latestebd6a8faf21f
stdlib@go1.15.12
1.26.9
1
layer5/meshery-operator:stable-latest6f58a28fe422
stdlib@go1.23.9
1.26.9
1
layer5/meshery-osm:stable-latestec898e5786c6
stdlib@go1.19.8
1.26.9
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
stdlib@go1.19.11
1.26.9
1
lbenicio/kubernetes-dashboard-api:1.14.951d3d30206c8
stdlib@go1.25.11
1.26.9
1
lbenicio/kubernetes-dashboard-auth:1.4.1635eb784c03fa
stdlib@go1.25.12
1.26.9
1
lbenicio/kubernetes-dashboard-scraper:1.2.69202e96ad403
stdlib@go1.25.11
1.26.9
1
lbenicio/kubernetes-dashboard-web:1.7.142797937bc2a5
stdlib@go1.25.11
1.26.9
1
leonardomulticloud/svc-vault:v1.0.0e4acd2fbb7b1
stdlib@go1.23.1
1.26.9
1
leonardomulticloud/webhook:v1.0.0d119918900e8
stdlib@go1.22.6
1.26.9
1
library/caddy:2.660fb54d36b4b
stdlib@go1.20
1.26.9
1
library/caddy:2.2.0-alpine7367adca165f
stdlib@go1.15.2
1.26.9
1
library/caddy:2.11.2-alpine834468128c76
stdlib@go1.26.0
1.26.9
1
library/caddy:2.4.5874405536b3e
stdlib@go1.17
1.26.9
1
library/caddy:2.9-alpineb4e3952384eb
stdlib@go1.23.4
1.26.9
1
library/caddy:2-alpined44355d3c214
stdlib@go1.26.8
1.26.9
1
library/caddy:2.11.7-alpined76116d819d5
stdlib@go1.26.8
1.26.9
1
library/caddy:2.4.2-alpinefbc51bcf1ab0
stdlib@go1.16.5
1.26.9
1
library/cassandra:4.00909b1681015
stdlib@go1.24.6
1.26.9
1
library/chronograf:1.9.496d8a3f65a4f
stdlib@go1.16.4
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.