argo-cd9.7.1
Helm chartA Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 17
- Low
- 402
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
419 findings over 2 of 3 images measured · scored 2 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of 9.7.1, one sample per day, last 90 days. Hover a point for its date and advisory data.
Score moves
A score can move without the chart changing: the advisory data behind every finding is refreshed daily. Each move lists which inputs changed. Why a score moves
Fewer than two samples so far.
Findings
343 distinct across the version’s images
| Advisory | Package | Fixed in | Contribution | EPSS | Since | Digests |
|---|---|---|---|---|---|---|
| GHSA-5cgq-3rg8-m6cv golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 38/100 | 0.073 (94th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-2x32-jm95-2cpx Authentication Bypass in dex | github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang | 2.27.0 | 25/100 | 0.017 (75th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-m9hp-7r99-94h5 Critical security issues in XML encoding in github.com/dexidp/dex | github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang | 2.27.0 | 24/100 | 0.017 (75th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-p77j-4mvh-x3m3 gRPC-Go has an authorization bypass via missing leading slash in :path | google.golang.org/grpc@v1.72.1golang | 1.79.3 | 23/100 | 0.016 (73th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-vh7g-p26c-j2cw Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code | github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang | 2.35.0 | 21/100 | 0.012 (66th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-x527-x647-q7gg golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.005 (41th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-vgwf-h737-ff37 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.006 (47th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-f5wc-c3c7-36mc golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.006 (46th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-pc3f-x583-g7j2 SpdyStream: DOS on CRI | github.com/moby/spdystream@v0.5.0golang | 0.5.1 | 16/100 | 0.007 (49th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-rm3j-f69w-wqmq golang.org/x/crypto vulnerable to infinite loop on large channel writes | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 16/100 | 0.005 (42th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-r53h-jv2g-vpx6 Helm's Missing YAML Content Leads To Panic | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.14.2 | 16/100 | 0.009 (58th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-89gr-r52h-f8rx golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 15/100 | 0.004 (35th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-jppx-rxg9-jmrx golang.org/x/crypto doesn't enforce invoking key constraints | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 15/100 | 0.004 (34th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-7hfp-qfw3-5jxh Helm Vulnerable to denial of service through string value parsing | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.9.4 | 14/100 | 0.010 (61th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-mh2q-q3fh-2475 OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) | go.opentelemetry.io/otel@v1.39.0golang | 1.41.0 | 14/100 | 0.007 (48th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-78h2-9frx-2jm8 Go JOSE Panics in JWE decryption | github.com/go-jose/go-jose/v4@v4.1.3golang | 4.1.4 | 14/100 | 0.007 (48th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-56hp-xqp3-w2jf Helm passes repository credentials to alternate domain | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.6.1 | 13/100 | 0.014 (70th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-557j-xg8c-q2mm Helm vulnerable to Code Injection through malicious chart.yaml content | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.4 | 13/100 | 0.004 (29th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-q4h4-gmj2-qvw2 golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 13/100 | 0.005 (39th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-w879-237q-wc7r golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 13/100 | 0.005 (38th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-8xwf-rjm4-xvhv oras-go has file store write outside workingDir via symlink traversal | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 12/100 | 0.005 (41th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-qw64-3x98-g7q2 go-billy has path traversal vulnerabilities | github.com/go-git/go-billy/v5@v5.6.2golang | 5.9.0 | 12/100 | 0.003 (23th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-jxpm-75mh-9fp7 oras-go blob upload vulnerable to credential forwarding via unvalidated Location header | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 12/100 | 0.004 (31th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-fxhp-mv3v-67qp `oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution | oras.land/oras-go/v2@v2.6.0golang | 2.6.2 | 12/100 | 0.004 (36th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-pjcq-xvwq-hhpj go-ntlmssp NTLM challenges can panic on malformed payloads | github.com/Azure/go-ntlmssp@v0.0.0-20221128193559-754e69321358golang | 0.1.1 | 12/100 | 0.010 (61th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-v53g-5gjp-272r Helm dependency management path traversal | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.14.1 | 11/100 | 0.006 (45th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-hc8v-wwc9-vgxm go-git: Worktree operations may follow symlinks | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.2 | 11/100 | 0.004 (29th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4341 Memory exhaustion in query parameter parsing in net/url | stdlib@go1.24.11golang | 1.24.12 | 11/100 | 0.020 (79th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-479m-364c-43vc validateSignature Loop Variable Capture Signature Bypass in goxmldsig | github.com/russellhaering/goxmldsig@v1.5.0golang | 1.6.0 | 11/100 | 0.003 (22th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-5xqw-8hwv-wg92 Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.3 | 11/100 | 0.005 (38th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-53c4-hhmh-vw5q Helm vulnerable to denial of service through through repository index file | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 11/100 | 0.008 (54th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-67fx-wx78-jx33 Helm vulnerable to denial of service through schema file | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 11/100 | 0.008 (54th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-4hfp-h4cw-hj8p Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.3 | 11/100 | 0.004 (36th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-6rx9-889q-vv2r Helm vulnerable to denial of service through string value parsing | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 10/100 | 0.008 (52th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-xhf5-7wjv-pqxp containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull | github.com/containerd/containerd@v1.7.29golang | 1.7.33 | 10/100 | 0.002 (6th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-m3xc-h892-ggx6 go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion | github.com/go-git/go-billy/v5@v5.6.2golang | 5.9.0 | 10/100 | 0.004 (32th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-qgq7-7hm3-q39j go-git: Malicious reference names may modify files outside the reference storage | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.2 | 10/100 | 0.004 (34th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-hfvc-g4fc-pqhx opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking | go.opentelemetry.io/otel/sdk@v1.39.0golang | 1.43.0 | 10/100 | 0.003 (17th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-q9hv-hpm4-hj6x CIRCL has an incorrect calculation in secp384r1 CombinedMult | github.com/cloudflare/circl@v1.6.1golang | 1.6.3 | 10/100 | 0.004 (33th pct) | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-31789 | openssl@3.5.5-r0apk | 3.5.6-r0 | 10/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-63073 | openssl@3.5.5-r0apk | 3.5.8-r0 | 10/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2025-69720 | ncurses@6.5+20250216-2build1deb | 6.5+20250216-2ubuntu0.1 | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-10536 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.5 | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-11856 | curl@8.14.1-2ubuntu1.3deb | no fix listed | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-5450 | glibc@2.42-0ubuntu3.1deb | no fix listed | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-8376 | perl@5.40.1-6build1deb | 5.40.1-6ubuntu0.1 | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-8925 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-9079 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 10/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-45gg-vh54-h5m9 golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 10/100 | 0.004 (30th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-9h84-qmv7-982p Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.18.5 | 10/100 | 0.003 (26th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-f9f8-9pmf-xv68 Helm May Panic Due To Incorrect YAML Content | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.18.5 | 10/100 | 0.003 (26th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-5cv4-jp36-h3mw Go Net HTML parser is vulnerable to denial of service | golang.org/x/net@v0.47.0golang | 0.55.0 | 10/100 | 0.003 (25th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-jpcc-p29g-p8mq containerd image-triggered runtime DoS via unbounded group parsing | github.com/containerd/containerd@v1.7.29golang | 1.7.33 | 10/100 | 0.003 (18th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-j5w8-q4qc-rx2x golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption | golang.org/x/crypto@v0.36.0golang | 0.45.0 | 9/100 | 0.006 (44th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-4739 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 9/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-fqw6-gf59-qr4w containerd user ID handling bypass allows runAsNonRoot evasion | github.com/containerd/containerd@v1.7.29golang | 1.7.32 | 9/100 | 0.002 (6th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-qpw4-5x99-6vjp golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 9/100 | 0.003 (20th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-f6x5-jh6r-wrfv golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read | golang.org/x/crypto@v0.36.0golang | 0.45.0 | 9/100 | 0.005 (41th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| ALPINE-CVE-2026-34182 | openssl@3.5.5-r0apk | 3.5.7-r0 | 9/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-75803 | openssl@3.5.5-r0apk | 3.5.8-r0 | 9/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2026-12087 | perl@5.40.1-6build1deb | no fix listed | 9/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-42496 | perl@5.40.1-6build1deb | 5.40.1-6ubuntu0.1 | 9/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-8924 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 9/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-8926 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 9/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-8927 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 9/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-78mq-xcr3-xm33 golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 9/100 | 0.005 (41th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| ALPINE-CVE-2026-45447 | openssl@3.5.5-r0apk | 3.5.7-r0 | 9/100 | — | 2 Sept 2026 | 8499afd690c4 |
| GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | google.golang.org/grpc@v1.72.1golang | 1.82.1 | 9/100 | — | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2024-52005 | git@1:2.51.0-1ubuntu1deb | no fix listed | 9/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-vp52-pcj8-j9qc gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | google.golang.org/grpc@v1.72.1golang | 1.83.1 | 9/100 | — | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-9m57-25v3-79x9 golang.org/x/crypto: Invoking pathological inputs can lead to client panic | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 8/100 | 0.004 (34th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-gxhx-2686-5h9g slack-go `SecretsVerifier` accepts empty signing secret without precondition | github.com/slack-go/slack@v0.16.0golang | 0.23.1 | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-389r-gv7p-r3rp go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.0 | 8/100 | 0.002 (5th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-9h8m-3fm2-qjrq OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking | go.opentelemetry.io/otel/sdk@v1.39.0golang | 1.40.0 | 8/100 | 0.002 (5th pct) | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-28387 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-40200 | musl@1.2.5-r21apk | 1.2.5-r23 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-7383 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2026-55200 | libssh2@1.11.1-1ubuntu0.25.10.1deb | 1.11.1-1ubuntu0.25.10.2 | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-8286 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4981 Crash when handling long CNAME response in net | stdlib@go1.24.11golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4977 Quadratic string concatenation in consumePhrase in net/mail | stdlib@go1.24.11golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4986 Quadratic string concatentation in consumeComment in net/mail | stdlib@go1.24.11golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | stdlib@go1.24.11golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | golang.org/x/net@v0.47.0golang | 0.53.0 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2025-3563 Request smuggling due to acceptance of invalid chunked data in net/http | stdlib@go1.24.0golang | 1.23.8 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2023-1547 Information disclosure in helm.sh/helm/v3 | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.11.1 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4337 Unexpected session resumption in crypto/tls | stdlib@go1.24.11golang | 1.24.13 | 8/100 | 0.008 (52th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| ALPINE-CVE-2026-22184 | zlib@1.3.1-r2apk | 1.3.2-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2026-11822 | sqlite3@3.46.1-8deb | 3.46.1-8ubuntu0.1 | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-11824 | sqlite3@3.46.1-8deb | 3.46.1-8ubuntu0.1 | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35368 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-crhj-59gh-8x96 go-git: Crafted repositories may modify main and submodule .git directories | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.1 | 8/100 | 0.003 (22th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4601 Incorrect parsing of IPv6 host literals in net/url | stdlib@go1.24.11golang | 1.25.8 | 8/100 | 0.007 (51th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2026-60002 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | stdlib@go1.24.11golang | 1.25.13 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | golang.org/x/net@v0.47.0golang | 0.55.0 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4342 Excessive CPU consumption when building archive index in archive/zip | stdlib@go1.24.11golang | 1.24.12 | 8/100 | 0.007 (49th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| ALPINE-CVE-2026-14456 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-14457 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-18798 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-28388 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-28389 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-28390 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-31790 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-34180 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-34183 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-42764 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-45445 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-54874 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-63072 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-63075 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-63076 | openssl@3.5.5-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-9076 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2026-12064 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.5 | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-4046 | glibc@2.42-0ubuntu3.1deb | no fix listed | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-41992 | gzip@1.13-1ubuntu4deb | no fix listed | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-42497 | perl@5.40.1-6build1deb | no fix listed | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-4437 | glibc@2.42-0ubuntu3.1deb | no fix listed | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-48959 | perl@5.40.1-6build1deb | no fix listed | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-5928 | glibc@2.42-0ubuntu3.1deb | no fix listed | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-8932 | curl@8.14.1-2ubuntu1.3deb | no fix listed | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-9538 | perl@5.40.1-6build1deb | no fix listed | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-9545 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 8/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| ALPINE-CVE-2026-34181 | openssl@3.5.5-r0apk | 3.5.7-r0 | 7/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2026-9547 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-4116 Potential denial of service in golang.org/x/crypto/ssh/agent | golang.org/x/crypto@v0.36.0golang | 0.43.0 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4870 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls | stdlib@go1.24.11golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2025-4009 Quadratic complexity when parsing some invalid inputs in encoding/pem | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4947 Unexpected work during chain building in crypto/x509 | stdlib@go1.24.11golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2026-35338 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-48961 | perl@5.40.1-6build1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-48962 | perl@5.40.1-6build1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-5435 | glibc@2.42-0ubuntu3.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-9080 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4599 Incorrect enforcement of email constraints in crypto/x509 | stdlib@go1.26.0golang | 1.26.1 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2025-3751 Sensitive headers not cleared on cross-origin redirect in net/http | stdlib@go1.24.0golang | 1.23.10 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-4006 Excessive CPU consumption in ParseAddress in net/mail | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5037 Inefficient candidate hostname parsing in crypto/x509 | stdlib@go1.24.11golang | 1.25.11 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4971 Panic in Dial and LookupPort when handling NUL byte on Windows in net | stdlib@go1.24.11golang | 1.25.10 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5972 Enforce maximum recursion depth in encoding/asn1 | stdlib@go1.24.11golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-6088 Add recursion depth guard during decode in encoding/xml | stdlib@go1.24.11golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-6089 Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http | stdlib@go1.24.11golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-6090 Limit handshake messages we are willing to accept post-handshake in crypto/tls | stdlib@go1.24.11golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5038 Quadratic complexity in WordDecoder.DecodeHeader in mime | stdlib@go1.24.11golang | 1.25.11 | 7/100 | 0.006 (44th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2026-35341 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-54369 | acl@2.3.2-2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-54371 | attr@1:2.5.2-3build1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-7017 | perl@5.40.1-6build1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | stdlib@go1.26.0golang | 1.26.6 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | golang.org/x/net@v0.47.0golang | 0.56.0 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2025-3521 Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes | k8s.io/kubernetes@v1.34.2golang | no fix listed | 7/100 | 0.005 (43th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35352 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-58050 | libssh2@1.11.1-1ubuntu0.25.10.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-4012 Lack of limit when parsing cookies can cause memory exhaustion in net/http | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-3956 Unexpected paths returned from LookPath in os/exec | stdlib@go1.24.0golang | 1.23.12 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-4011 Parsing DER payload can cause memory exhaustion in encoding/asn1 | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-4015 Excessive CPU consumption in Reader.ReadResponse in net/textproto | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-6218 Avoid quadratic complexity in resolvePath in net/url | stdlib@go1.24.11golang | 1.25.13 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-vh4v-2xq2-g5cg ORAS Go forwards registry credentials across registry redirects | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56132 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56403 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56404 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56405 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56406 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56407 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56408 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56410 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56411 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4440 Quadratic parsing complexity in golang.org/x/net/html | golang.org/x/net@v0.38.0golang | 0.45.0 | 7/100 | 0.005 (41th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4559 Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net | golang.org/x/net@v0.50.0golang | 0.51.0 | 7/100 | 0.005 (41th pct) | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2026-13595 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4441 Infinite parsing loop in golang.org/x/net | golang.org/x/net@v0.38.0golang | 0.45.0 | 7/100 | 0.005 (40th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5970 Infinite loop on invalid input in golang.org/x/text | golang.org/x/text@v0.28.0golang | 0.39.0 | 7/100 | 0.005 (39th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2026-35349 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-4155 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 | stdlib@go1.25.3golang | 1.24.11 | 7/100 | 0.005 (38th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35350 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35365 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-4008 ALPN negotiation error contains attacker controlled information in crypto/tls | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.004 (36th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-4010 Insufficient validation of bracketed IPv6 hostnames in net/url | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.004 (36th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2024-2476 Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers in github.com/dexidp/dex | github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang | no fix listed | 7/100 | 0.004 (36th pct) | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-2673 | openssl@3.5.5-r0apk | 3.5.6-r0 | 7/100 | — | 2 Sept 2026 | 8499afd690c4 |
| GHSA-w5pp-99ch-qj29 go-git: Malformed Git object data may cause panics or resource exhaustion | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.1 | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2016-2781 | coreutils@9.5-1ubuntu4.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2016-2781 | coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu24deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2025-15661 | libssh2@1.11.1-1ubuntu0.25.10.1deb | 1.11.1-1ubuntu0.25.10.2 | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56409 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-58051 | libssh2@1.11.1-1ubuntu0.25.10.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-60001 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-6238 | glibc@2.42-0ubuntu3.1deb | no fix listed | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-8458 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 7/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-3xc5-wrhm-f963 go-git: Credential leak via cross-host redirect in smart HTTP transport | github.com/go-git/go-git/v5@v5.14.0golang | 5.18.0 | 6/100 | 0.003 (17th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2025-4014 Unbounded allocation when parsing GNU sparse map in archive/tar | stdlib@go1.24.0golang | 1.24.8 | 6/100 | 0.004 (34th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-3503 HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net | stdlib@go1.24.0golang | 1.23.7 | 6/100 | 0.004 (33th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-6107 Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 | go.etcd.io/etcd/client/pkg/v3@v3.6.8golang | 3.5.33 | 6/100 | 0.004 (33th pct) | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2026-35355 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35356 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35360 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35364 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35374 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-54370 | acl@2.3.2-2deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4976 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil | stdlib@go1.24.11golang | 1.25.10 | 6/100 | 0.004 (32th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5856 Invoking Encrypted Client Hello privacy leak in crypto/tls | stdlib@go1.24.11golang | 1.25.12 | 6/100 | 0.004 (31th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2025-4007 Quadratic complexity when checking name constraints in crypto/x509 | stdlib@go1.24.0golang | 1.24.9 | 6/100 | 0.004 (31th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-13757 | p11-kit@0.25.5-3ubuntu1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4980 Escaper bypass leads to XSS in html/template | stdlib@go1.24.11golang | 1.25.10 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5039 Arbitrary inputs are included in errors without any escaping in net/textproto | stdlib@go1.24.11golang | 1.25.11 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2025-4013 Panic when validating certificates with DSA public keys in crypto/x509 | stdlib@go1.24.0golang | 1.24.8 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-3849 Incorrect results returned from Rows.Scan in database/sql | stdlib@go1.24.0golang | 1.23.12 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4946 Inefficient policy validation in crypto/x509 | stdlib@go1.24.11golang | 1.25.9 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2026-50813 | sqlite3@3.46.1-8deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4600 Panic in name constraint checking for malformed certificates in crypto/x509 | stdlib@go1.26.0golang | 1.26.1 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5064 containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd | github.com/containerd/containerd@v1.7.29golang | no fix listed | 6/100 | 0.003 (27th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2022-0646 CBC padding oracle issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go | github.com/aws/aws-sdk-go@v1.55.7golang | no fix listed | 6/100 | 0.003 (27th pct) | 2 Sept 2026 | 8499afd690c4 |
| GHSA-hr2v-4r36-88hr Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.20.2 | 6/100 | 0.002 (10th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4866 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 | stdlib@go1.26.0golang | 1.26.2 | 6/100 | 0.003 (27th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2025-3749 Usage of ExtKeyUsageAny disables policy validation in crypto/x509 | stdlib@go1.24.0golang | 1.24.4 | 6/100 | 0.003 (27th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5158 Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel | go.opentelemetry.io/otel@v1.43.0golang | 1.42.0 | 6/100 | 0.003 (26th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4603 URLs in meta content attribute actions are not escaped in html/template | stdlib@go1.24.11golang | 1.25.8 | 6/100 | 0.003 (25th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-6303 Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | golang.org/x/crypto@v0.36.0golang | 0.55.0 | 6/100 | 0.003 (25th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| ALPINE-CVE-2026-42766 | openssl@3.5.5-r0apk | 3.5.7-r0 | 6/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-42767 | openssl@3.5.5-r0apk | 3.5.7-r0 | 6/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-63074 | openssl@3.5.5-r0apk | 3.5.8-r0 | 6/100 | — | 2 Sept 2026 | 8499afd690c4 |
| GHSA-xmrv-pmrh-hhx2 Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder | github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.7.4golang | 1.7.8 | 6/100 | — | 2 Sept 2026 | 8499afd690c4 |
| GHSA-xmrv-pmrh-hhx2 Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder | github.com/aws/aws-sdk-go-v2/service/s3@v1.95.1golang | 1.97.3 | 6/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2024-2236 | libgcrypt20@1.11.0-7ubuntu0.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-40355 | krb5@1.21.3-5ubuntu2deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-40356 | krb5@1.21.3-5ubuntu2deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-54411 | pam@1.7.0-5ubuntu2deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-55199 | libssh2@1.11.1-1ubuntu0.25.10.1deb | 1.11.1-1ubuntu0.25.10.2 | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-59999 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-3547 Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes | k8s.io/kubernetes@v1.34.2golang | no fix listed | 6/100 | 0.003 (24th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4982 Bypass of meta content URL escaping causes XSS in html/template | stdlib@go1.24.11golang | 1.25.10 | 6/100 | 0.003 (24th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-6091 Fix Javascript regexp context tracking in html/template | stdlib@go1.24.11golang | 1.25.13 | 6/100 | 0.003 (23th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5338 containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd | github.com/containerd/containerd@v1.7.29golang | no fix listed | 6/100 | 0.003 (22th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-6180 Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb | golang.org/x/mod@v0.32.0golang | 0.40.0 | 6/100 | 0.003 (22th pct) | 2 Sept 2026 | 8499afd690c4 |
| GO-2026-4864 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix | stdlib@go1.24.11golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4865 JsBraceDepth Context Tracking Bugs (XSS) in html/template | stdlib@go1.24.11golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4869 Unbounded allocation for old GNU sparse in archive/tar | stdlib@go1.24.11golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GHSA-jhf3-xxhw-2wpp go-git: Maliciously crafted idx file can cause asymmetric memory consumption | github.com/go-git/go-git/v5@v5.14.0golang | 5.17.1 | 6/100 | 0.001 (4th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4340 Handshake messages may be processed at the incorrect encryption level in crypto/tls | stdlib@go1.24.11golang | 1.24.12 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-4175 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 | stdlib@go1.25.3golang | 1.24.11 | 6/100 | 0.003 (20th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35363 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2025-3750 Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscall | stdlib@go1.24.0golang | 1.23.10 | 6/100 | 0.003 (18th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| ALPINE-CVE-2026-27171 | zlib@1.3.1-r2apk | 1.3.2-r0 | 6/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2025-15649 | perl@5.40.1-6build1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35339 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35340 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35348 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35369 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35380 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-50812 | sqlite3@3.46.1-8deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-53612 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-53613 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-53614 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-53615 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 6/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-4438 | glibc@2.42-0ubuntu3.1deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-58055 | nghttp2@1.64.0-1.1ubuntu1.1deb | 1.64.0-1.1ubuntu1.2 | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4403 Improper access to parent directory of root in os | stdlib@go1.24.0golang | 1.23.9 | 5/100 | 0.002 (15th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5025 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | golang.org/x/net@v0.47.0golang | 0.55.0 | 5/100 | 0.002 (14th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| ALPINE-CVE-2026-42769 | openssl@3.5.5-r0apk | 3.5.7-r0 | 5/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2026-35345 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-4970 Root escape via symlink plus trailing slash in os | stdlib@go1.24.11golang | 1.25.12 | 5/100 | 0.002 (14th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2022-0635 In-band key negotiation issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go | github.com/aws/aws-sdk-go@v1.55.7golang | no fix listed | 5/100 | 0.002 (14th pct) | 2 Sept 2026 | 8499afd690c4 |
| GO-2026-5027 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | golang.org/x/net@v0.47.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5029 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | golang.org/x/net@v0.47.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5030 Invoking duplicate attributes can cause XSS in golang.org/x/net/html | golang.org/x/net@v0.47.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-4602 FileInfo can escape from a Root in os | stdlib@go1.24.11golang | 1.25.8 | 5/100 | 0.002 (10th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2026-11850 | krb5@1.21.3-5ubuntu2deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35372 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-55655 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-5704 | tar@1.35+dfsg-3.1build1deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-50219 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56131 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-56412 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5622 Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd | github.com/containerd/containerd@v1.7.29golang | no fix listed | 5/100 | 0.002 (7th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
| ALPINE-CVE-2026-45446 | openssl@3.5.5-r0apk | 3.5.7-r0 | 5/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-6042 | musl@1.2.5-r21apk | 1.2.5-r22 | 5/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2026-42250 | bzip2@1.0.8-6build1deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-59998 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-37cx-329c-33x3 go-git improperly verifies data integrity values for .idx and .pack files | github.com/go-git/go-git/v5@v5.14.0golang | 5.16.5 | 5/100 | 0.001 (3th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2026-27456 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35354 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35357 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35359 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-41991 | gzip@1.13-1ubuntu4deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35376 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2025-5278 | coreutils@9.5-1ubuntu4.1deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2025-5278 | coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu24deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35347 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35358 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35366 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35370 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35351 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-59995 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-59996 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-59997 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5024 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | golang.org/x/sys@v0.42.0golang | 0.44.0 | 4/100 | 0.001 (2th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2025-45582 | tar@1.35+dfsg-3.1build1deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-6179 Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog | golang.org/x/mod@v0.32.0golang | 0.40.0 | 4/100 | 0.001 (1th pct) | 2 Sept 2026 | 8499afd690c4 |
| GO-2026-5410 SecretsVerifier accepts empty signing secret without precondition in github.com/slack-go/slack | github.com/slack-go/slack@v0.16.0golang | 0.23.1 | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5693 Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.1 | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-5764 DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream | github.com/aws/aws-sdk-go-v2/service/s3@v1.95.1golang | 1.97.3 | 4/100 | — | 2 Sept 2026 | 8499afd690c4 |
| GO-2026-5764 DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream | github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.7.4golang | 1.7.8 | 4/100 | — | 2 Sept 2026 | 8499afd690c4 |
| GO-2026-5841 OOB read in github.com/klauspost/compress/s2 | github.com/klauspost/compress@v1.18.0golang | 1.18.7 | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5884 ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | golang.org/x/crypto@v0.36.0golang | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| GO-2026-6061 Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc | google.golang.org/grpc@v1.72.1golang | 1.82.1 | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2026-32776 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-32777 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| USN-8467-2 perl vulnerabilities | perl@5.40.1-6build1deb | 5.40.1-6ubuntu0.1 | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| ALPINE-CVE-2026-42768 | openssl@3.5.5-r0apk | 3.5.7-r0 | 4/100 | — | 2 Sept 2026 | 8499afd690c4 |
| ALPINE-CVE-2026-42770 | openssl@3.5.5-r0apk | 3.5.7-r0 | 4/100 | — | 2 Sept 2026 | 8499afd690c4 |
| UBUNTU-CVE-2026-3184 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-55654 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-60000 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2024-56433 | shadow@1:4.17.4-2ubuntu2deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35362 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-m7cr-m3pv-hgrp go-git: Improper single-quote escaping in go-git SSH transport | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.1 | 4/100 | 0.004 (29th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2026-35361 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2022-3219 | gnupg2@2.4.8-2ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2025-6141 | ncurses@6.5+20250216-2build1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35342 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35343 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35344 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35346 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35353 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35367 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35371 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35373 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35375 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35377 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35378 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35379 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-35381 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-gm2x-2g9h-ccm8 go-git missing validation decoding Index v4 files leads to panic | github.com/go-git/go-git/v5@v5.14.0golang | 5.17.1 | 3/100 | 0.002 (5th pct) | 2 Sept 2026 | 2fb3efa9eaa48499afd690c4 |
| UBUNTU-CVE-2025-66382 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-27171 | zlib@1:1.3.dfsg+really1.3.1-1ubuntu2deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-32778 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-40228 | systemd@257.9-0ubuntu2.5deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-41080 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-45186 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| UBUNTU-CVE-2026-57062 | gnupg2@2.4.8-2ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 | 2fb3efa9eaa4 |
| GHSA-xf85-363p-868w oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 3/100 | 0.003 (17th pct) | 2 Sept 2026 | 2fb3efa9eaa4 |
Workloads and images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
| Container | Image | Tag | Digest | Radar Score |
|---|---|---|---|---|
| Deployment candidate-argocd-applicationset-controller | ||||
| applicationset-controller | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| Deployment candidate-argocd-notifications-controller | ||||
| notifications-controller | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| Deployment candidate-argocd-repo-server | ||||
| copyutilinit | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| repo-server | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| Deployment candidate-argocd-server | ||||
| server | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| Deployment candidate-argocd-dex-server | ||||
| copyutilinit | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| dex-server | ghcr.io/dexidp/dex | v2.45.1 | 8499afd690c4 | 1,104 |
| Deployment candidate-argocd-redis | ||||
| redis | ecr-public.aws.com/docker/library/redis | 8.2.3-alpine | unmeasured: registry not in allow-list | — |
| StatefulSet candidate-argocd-application-controller | ||||
| application-controller | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
| Job candidate-argocd-redis-secret-init | ||||
| secret-inithook: pre-install,pre-upgrade | quay.io/argoproj/argocd | v3.4.4 | 2fb3efa9eaa4 | 2,003 |
Unmeasured images (1)
ecr-public.aws.com/docker/library/redis:8.2.3-alpineregistry not in allow-list