StackRadar

GO-2026-6225

Unscored

Advisory

Published 18 Aug 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
61
of 17,781 indexed, latest versions
Container images
54
deployed by those charts
Fix available
None
affected package

Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env

Carried by container images the latest versions of 61 of 17,781 indexed charts deploy, on 54 images.

Affected packageAffected versionsFixed inImages
github.com/chrismellard/docker-credential-acr-envgolangv0.0.0-20220119192733-fe33c00cee21, v0.0.0-20220327082430-c57b701bfc08, v0.0.0-20221002210726-e883f69e0206, v0.0.0-20221129204813-6a4d6ed5d396+1 moreno fix listed54
OSV records
GO-2026-6225

Charts affected

61 by stars
ChartLatestAffected imagesRadar Score
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed

Open the chart page →

8,599
voyager-gatewayopenshift2026.1.151 of 2See more

voyager-gateway openshift 2026.1.15

1 of the 2 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.1.013fd0cccafe8
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed

Open the chart page →

2,567
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
gcr.io/kaniko-project/executor:latest4e7a52dd1f14
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed

Open the chart page →

71,208
piggy-webhookspiggyVerified publisher0.7.51 of 1See more

piggy-webhooks piggy 0.7.5

1 of the 1 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
ghcr.io/kongz/piggy-webhooks:0.7.585a4282455a0
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed

Open the chart page →

504
argo-workflowsquench-argo-workflowsVerified publisher0.0.21 of 1See more

argo-workflows quench-argo-workflows 0.0.2

1 of the 1 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/argo-workflowsdigest-pinned7d5772435793
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed

Open the chart page →

8
crossplanequench-crossplaneVerified publisher0.0.31 of 1See more

crossplane quench-crossplane 0.0.3

1 of the 1 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/crossplanedigest-pinned46bc09ce8fea
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed

Open the chart page →

8
kyvernoquench-kyvernoVerified publisher0.0.11 of 2See more

kyverno quench-kyverno 0.0.1

1 of the 2 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/kyvernodigest-pinned90c78c240157
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed

Open the chart page →

342
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed

Open the chart page →

1,837
argo-workflowromholdings0.1.61 of 1See more

argo-workflow romholdings 0.1.6

1 of the 1 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20220119192733-fe33c00cee21
no fix listed

Open the chart page →

1,580
sigstore-probersigstoreVerified publisher0.3.11 of 1See more

sigstore-prober sigstore 0.3.1

1 of the 1 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed

Open the chart page →

424
projectsveltossveltosVerified publisher1.15.01 of 11See more

projectsveltos sveltos 1.15.0

1 of the 11 container images this version deploys carry GO-2026-6225.

Container imageDigestPackageFixed in
projectsveltos/addon-controller:v1.15.08eb5a2a2a474
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed

Open the chart page →

72

Container images carrying it

54 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/workflow-controller:v3.7.11c46aa0ded8ed
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed
1
quay.io/kubescape/kubescape:v4.0.1358651dce3376
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/chrismellard/docker-credential-acr-env@v0.0.0-20230304212654-82a0ddb27589
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.