argo-cd9.7.1

Helm chart
argo repositoryon Artifact Hub 844#3 by starsofficialverified publisher

A Helm chart for Argo CD, a declarative, GitOps continuous delivery tool for Kubernetes.

version 9.7.1kube >=1.25.0-0app version v3.4.4
README badge
[![Radar Score](https://charts.stackradar.io/badge/argo/argo-cd.svg)](https://charts.stackradar.io/charts/argo/argo-cd)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

Radar Score

3,107
worst finding Medium
Critical
0
High
0
Medium
17
Low
402
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

419 findings over 2 of 3 images measured · scored 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of 9.7.1, one sample per day, last 90 days. Hover a point for its date and advisory data.

2 Sept 2026 · Radar Score 3,107 · OSV as of 2 Sept 2026
history since 2 Sept 2026

Score moves

A score can move without the chart changing: the advisory data behind every finding is refreshed daily. Each move lists which inputs changed. Why a score moves

Fewer than two samples so far.

Findings

343 distinct across the version’s images

AdvisoryPackageFixed inContributionEPSSSinceDigests
GHSA-5cgq-3rg8-m6cv

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

golang.org/x/crypto@v0.36.0golang0.52.038/1000.073 (94th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-2x32-jm95-2cpx

Authentication Bypass in dex

github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang2.27.025/1000.017 (75th pct)2 Sept 20268499afd690c4
GHSA-m9hp-7r99-94h5

Critical security issues in XML encoding in github.com/dexidp/dex

github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang2.27.024/1000.017 (75th pct)2 Sept 20268499afd690c4
GHSA-p77j-4mvh-x3m3

gRPC-Go has an authorization bypass via missing leading slash in :path

google.golang.org/grpc@v1.72.1golang1.79.323/1000.016 (73th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-vh7g-p26c-j2cw

Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code

github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang2.35.021/1000.012 (66th pct)2 Sept 20268499afd690c4
GHSA-x527-x647-q7gg

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

golang.org/x/crypto@v0.36.0golang0.52.017/1000.005 (41th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-vgwf-h737-ff37

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

golang.org/x/crypto@v0.36.0golang0.52.017/1000.006 (47th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-f5wc-c3c7-36mc

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

golang.org/x/crypto@v0.36.0golang0.52.017/1000.006 (46th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-pc3f-x583-g7j2

SpdyStream: DOS on CRI

github.com/moby/spdystream@v0.5.0golang0.5.116/1000.007 (49th pct)2 Sept 20262fb3efa9eaa4
GHSA-rm3j-f69w-wqmq

golang.org/x/crypto vulnerable to infinite loop on large channel writes

golang.org/x/crypto@v0.36.0golang0.52.016/1000.005 (42th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-r53h-jv2g-vpx6

Helm's Missing YAML Content Leads To Panic

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.14.216/1000.009 (58th pct)2 Sept 20262fb3efa9eaa4
GHSA-89gr-r52h-f8rx

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

golang.org/x/crypto@v0.36.0golang0.52.015/1000.004 (35th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-jppx-rxg9-jmrx

golang.org/x/crypto doesn't enforce invoking key constraints

golang.org/x/crypto@v0.36.0golang0.52.015/1000.004 (34th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-7hfp-qfw3-5jxh

Helm Vulnerable to denial of service through string value parsing

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.9.414/1000.010 (61th pct)2 Sept 20262fb3efa9eaa4
GHSA-mh2q-q3fh-2475

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

go.opentelemetry.io/otel@v1.39.0golang1.41.014/1000.007 (48th pct)2 Sept 20268499afd690c4
GHSA-78h2-9frx-2jm8

Go JOSE Panics in JWE decryption

github.com/go-jose/go-jose/v4@v4.1.3golang4.1.414/1000.007 (48th pct)2 Sept 20268499afd690c4
GHSA-56hp-xqp3-w2jf

Helm passes repository credentials to alternate domain

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.6.113/1000.014 (70th pct)2 Sept 20262fb3efa9eaa4
GHSA-557j-xg8c-q2mm

Helm vulnerable to Code Injection through malicious chart.yaml content

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.17.413/1000.004 (29th pct)2 Sept 20262fb3efa9eaa4
GHSA-q4h4-gmj2-qvw2

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

golang.org/x/crypto@v0.36.0golang0.52.013/1000.005 (39th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-w879-237q-wc7r

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

golang.org/x/crypto@v0.36.0golang0.52.013/1000.005 (38th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-8xwf-rjm4-xvhv

oras-go has file store write outside workingDir via symlink traversal

oras.land/oras-go/v2@v2.6.0golang2.6.112/1000.005 (41th pct)2 Sept 20262fb3efa9eaa4
GHSA-qw64-3x98-g7q2

go-billy has path traversal vulnerabilities

github.com/go-git/go-billy/v5@v5.6.2golang5.9.012/1000.003 (23th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-jxpm-75mh-9fp7

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

oras.land/oras-go/v2@v2.6.0golang2.6.112/1000.004 (31th pct)2 Sept 20262fb3efa9eaa4
GHSA-fxhp-mv3v-67qp

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

oras.land/oras-go/v2@v2.6.0golang2.6.212/1000.004 (36th pct)2 Sept 20262fb3efa9eaa4
GHSA-pjcq-xvwq-hhpj

go-ntlmssp NTLM challenges can panic on malformed payloads

github.com/Azure/go-ntlmssp@v0.0.0-20221128193559-754e69321358golang0.1.112/1000.010 (61th pct)2 Sept 20268499afd690c4
GHSA-v53g-5gjp-272r

Helm dependency management path traversal

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.14.111/1000.006 (45th pct)2 Sept 20262fb3efa9eaa4
GHSA-hc8v-wwc9-vgxm

go-git: Worktree operations may follow symlinks

github.com/go-git/go-git/v5@v5.14.0golang5.19.211/1000.004 (29th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4341

Memory exhaustion in query parameter parsing in net/url

stdlib@go1.24.11golang1.24.1211/1000.020 (79th pct)2 Sept 20262fb3efa9eaa4
GHSA-479m-364c-43vc

validateSignature Loop Variable Capture Signature Bypass in goxmldsig

github.com/russellhaering/goxmldsig@v1.5.0golang1.6.011/1000.003 (22th pct)2 Sept 20268499afd690c4
GHSA-5xqw-8hwv-wg92

Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.17.311/1000.005 (38th pct)2 Sept 20262fb3efa9eaa4
GHSA-53c4-hhmh-vw5q

Helm vulnerable to denial of service through through repository index file

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.10.311/1000.008 (54th pct)2 Sept 20262fb3efa9eaa4
GHSA-67fx-wx78-jx33

Helm vulnerable to denial of service through schema file

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.10.311/1000.008 (54th pct)2 Sept 20262fb3efa9eaa4
GHSA-4hfp-h4cw-hj8p

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.17.311/1000.004 (36th pct)2 Sept 20262fb3efa9eaa4
GHSA-6rx9-889q-vv2r

Helm vulnerable to denial of service through string value parsing

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.10.310/1000.008 (52th pct)2 Sept 20262fb3efa9eaa4
GHSA-xhf5-7wjv-pqxp

containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull

github.com/containerd/containerd@v1.7.29golang1.7.3310/1000.002 (6th pct)2 Sept 20262fb3efa9eaa4
GHSA-m3xc-h892-ggx6

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

github.com/go-git/go-billy/v5@v5.6.2golang5.9.010/1000.004 (32th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-qgq7-7hm3-q39j

go-git: Malicious reference names may modify files outside the reference storage

github.com/go-git/go-git/v5@v5.14.0golang5.19.210/1000.004 (34th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-hfvc-g4fc-pqhx

opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking

go.opentelemetry.io/otel/sdk@v1.39.0golang1.43.010/1000.003 (17th pct)2 Sept 20268499afd690c4
GHSA-q9hv-hpm4-hj6x

CIRCL has an incorrect calculation in secp384r1 CombinedMult

github.com/cloudflare/circl@v1.6.1golang1.6.310/1000.004 (33th pct)2 Sept 20268499afd690c4
ALPINE-CVE-2026-31789openssl@3.5.5-r0apk3.5.6-r010/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-63073openssl@3.5.5-r0apk3.5.8-r010/1002 Sept 20268499afd690c4
UBUNTU-CVE-2025-69720ncurses@6.5+20250216-2build1deb6.5+20250216-2ubuntu0.110/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-10536curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.510/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-11856curl@8.14.1-2ubuntu1.3debno fix listed10/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-5450glibc@2.42-0ubuntu3.1debno fix listed10/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-8376perl@5.40.1-6build1deb5.40.1-6ubuntu0.110/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-8925curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.410/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-9079curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.410/1002 Sept 20262fb3efa9eaa4
GHSA-45gg-vh54-h5m9

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

golang.org/x/crypto@v0.36.0golang0.52.010/1000.004 (30th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-9h84-qmv7-982p

Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.18.510/1000.003 (26th pct)2 Sept 20262fb3efa9eaa4
GHSA-f9f8-9pmf-xv68

Helm May Panic Due To Incorrect YAML Content

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.18.510/1000.003 (26th pct)2 Sept 20262fb3efa9eaa4
GHSA-5cv4-jp36-h3mw

Go Net HTML parser is vulnerable to denial of service

golang.org/x/net@v0.47.0golang0.55.010/1000.003 (25th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-jpcc-p29g-p8mq

containerd image-triggered runtime DoS via unbounded group parsing

github.com/containerd/containerd@v1.7.29golang1.7.3310/1000.003 (18th pct)2 Sept 20262fb3efa9eaa4
GHSA-j5w8-q4qc-rx2x

golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption

golang.org/x/crypto@v0.36.0golang0.45.09/1000.006 (44th pct)2 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-4739expat@2.7.1-2ubuntu0.2debno fix listed9/1002 Sept 20262fb3efa9eaa4
GHSA-fqw6-gf59-qr4w

containerd user ID handling bypass allows runAsNonRoot evasion

github.com/containerd/containerd@v1.7.29golang1.7.329/1000.002 (6th pct)2 Sept 20262fb3efa9eaa4
GHSA-qpw4-5x99-6vjp

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

golang.org/x/crypto@v0.36.0golang0.52.09/1000.003 (20th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-f6x5-jh6r-wrfv

golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read

golang.org/x/crypto@v0.36.0golang0.45.09/1000.005 (41th pct)2 Sept 20262fb3efa9eaa4
ALPINE-CVE-2026-34182openssl@3.5.5-r0apk3.5.7-r09/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-75803openssl@3.5.5-r0apk3.5.8-r09/1002 Sept 20268499afd690c4
UBUNTU-CVE-2026-12087perl@5.40.1-6build1debno fix listed9/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-42496perl@5.40.1-6build1deb5.40.1-6ubuntu0.19/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-8924curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.49/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-8926curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.49/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-8927curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.49/1002 Sept 20262fb3efa9eaa4
GHSA-78mq-xcr3-xm33

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

golang.org/x/crypto@v0.36.0golang0.52.09/1000.005 (41th pct)2 Sept 20262fb3efa9eaa48499afd690c4
ALPINE-CVE-2026-45447openssl@3.5.5-r0apk3.5.7-r09/1002 Sept 20268499afd690c4
GHSA-hrxh-6v49-42gf

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

google.golang.org/grpc@v1.72.1golang1.82.19/1002 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2024-52005git@1:2.51.0-1ubuntu1debno fix listed9/1002 Sept 20262fb3efa9eaa4
GHSA-vp52-pcj8-j9qc

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

google.golang.org/grpc@v1.72.1golang1.83.19/1002 Sept 20262fb3efa9eaa48499afd690c4
GHSA-9m57-25v3-79x9

golang.org/x/crypto: Invoking pathological inputs can lead to client panic

golang.org/x/crypto@v0.36.0golang0.52.08/1000.004 (34th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-gxhx-2686-5h9g

slack-go `SecretsVerifier` accepts empty signing secret without precondition

github.com/slack-go/slack@v0.16.0golang0.23.18/1002 Sept 20262fb3efa9eaa4
GHSA-389r-gv7p-r3rp

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

github.com/go-git/go-git/v5@v5.14.0golang5.19.08/1000.002 (5th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-9h8m-3fm2-qjrq

OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking

go.opentelemetry.io/otel/sdk@v1.39.0golang1.40.08/1000.002 (5th pct)2 Sept 20268499afd690c4
ALPINE-CVE-2026-28387openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-40200musl@1.2.5-r21apk1.2.5-r238/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-7383openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 20268499afd690c4
UBUNTU-CVE-2026-55200libssh2@1.11.1-1ubuntu0.25.10.1deb1.11.1-1ubuntu0.25.10.28/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-8286curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.48/1002 Sept 20262fb3efa9eaa4
GO-2026-4981

Crash when handling long CNAME response in net

stdlib@go1.24.11golang1.25.108/1000.008 (54th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4977

Quadratic string concatenation in consumePhrase in net/mail

stdlib@go1.24.11golang1.25.108/1000.008 (54th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4986

Quadratic string concatentation in consumeComment in net/mail

stdlib@go1.24.11golang1.25.108/1000.008 (53th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

stdlib@go1.24.11golang1.25.108/1000.008 (53th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

golang.org/x/net@v0.47.0golang0.53.08/1000.008 (53th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2025-3563

Request smuggling due to acceptance of invalid chunked data in net/http

stdlib@go1.24.0golang1.23.88/1000.008 (53th pct)2 Sept 20262fb3efa9eaa4
GO-2023-1547

Information disclosure in helm.sh/helm/v3

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.11.18/1000.008 (53th pct)2 Sept 20262fb3efa9eaa4
GO-2026-4337

Unexpected session resumption in crypto/tls

stdlib@go1.24.11golang1.24.138/1000.008 (52th pct)2 Sept 20262fb3efa9eaa48499afd690c4
ALPINE-CVE-2026-22184zlib@1.3.1-r2apk1.3.2-r08/1002 Sept 20268499afd690c4
UBUNTU-CVE-2026-11822sqlite3@3.46.1-8deb3.46.1-8ubuntu0.18/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-11824sqlite3@3.46.1-8deb3.46.1-8ubuntu0.18/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35368rust-coreutils@0.2.2-0ubuntu2.1debno fix listed8/1002 Sept 20262fb3efa9eaa4
GHSA-crhj-59gh-8x96

go-git: Crafted repositories may modify main and submodule .git directories

github.com/go-git/go-git/v5@v5.14.0golang5.19.18/1000.003 (22th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4601

Incorrect parsing of IPv6 host literals in net/url

stdlib@go1.24.11golang1.25.88/1000.007 (51th pct)2 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2026-60002openssh@1:10.0p1-5ubuntu5.4debno fix listed8/1002 Sept 20262fb3efa9eaa4
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

stdlib@go1.24.11golang1.25.138/1000.007 (50th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

golang.org/x/net@v0.47.0golang0.55.08/1000.007 (50th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4342

Excessive CPU consumption when building archive index in archive/zip

stdlib@go1.24.11golang1.24.128/1000.007 (49th pct)2 Sept 20262fb3efa9eaa4
ALPINE-CVE-2026-14456openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-14457openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-18798openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-28388openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-28389openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-28390openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-31790openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-34180openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-34183openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-42764openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-45445openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-54874openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-63072openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-63075openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-63076openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-9076openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 20268499afd690c4
UBUNTU-CVE-2026-12064curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.58/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-4046glibc@2.42-0ubuntu3.1debno fix listed8/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-41992gzip@1.13-1ubuntu4debno fix listed8/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-42497perl@5.40.1-6build1debno fix listed8/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-4437glibc@2.42-0ubuntu3.1debno fix listed8/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-48959perl@5.40.1-6build1debno fix listed8/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-5928glibc@2.42-0ubuntu3.1debno fix listed8/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-8932curl@8.14.1-2ubuntu1.3debno fix listed8/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-9538perl@5.40.1-6build1debno fix listed8/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-9545curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.48/1002 Sept 20262fb3efa9eaa4
ALPINE-CVE-2026-34181openssl@3.5.5-r0apk3.5.7-r07/1002 Sept 20268499afd690c4
UBUNTU-CVE-2026-9547curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.47/1002 Sept 20262fb3efa9eaa4
GO-2025-4116

Potential denial of service in golang.org/x/crypto/ssh/agent

golang.org/x/crypto@v0.36.0golang0.43.07/1000.006 (47th pct)2 Sept 20262fb3efa9eaa4
GO-2026-4870

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

stdlib@go1.24.11golang1.25.97/1000.006 (47th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2025-4009

Quadratic complexity when parsing some invalid inputs in encoding/pem

stdlib@go1.24.0golang1.24.87/1000.006 (47th pct)2 Sept 20262fb3efa9eaa4
GO-2026-4947

Unexpected work during chain building in crypto/x509

stdlib@go1.24.11golang1.25.97/1000.006 (47th pct)2 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2026-35338rust-coreutils@0.2.2-0ubuntu2.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-48961perl@5.40.1-6build1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-48962perl@5.40.1-6build1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-5435glibc@2.42-0ubuntu3.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-9080curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.47/1002 Sept 20262fb3efa9eaa4
GO-2026-4599

Incorrect enforcement of email constraints in crypto/x509

stdlib@go1.26.0golang1.26.17/1000.006 (46th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2025-3751

Sensitive headers not cleared on cross-origin redirect in net/http

stdlib@go1.24.0golang1.23.107/1000.006 (46th pct)2 Sept 20262fb3efa9eaa4
GO-2025-4006

Excessive CPU consumption in ParseAddress in net/mail

stdlib@go1.24.0golang1.24.87/1000.006 (46th pct)2 Sept 20262fb3efa9eaa4
GO-2026-5037

Inefficient candidate hostname parsing in crypto/x509

stdlib@go1.24.11golang1.25.117/1000.006 (46th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4971

Panic in Dial and LookupPort when handling NUL byte on Windows in net

stdlib@go1.24.11golang1.25.107/1000.006 (45th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5972

Enforce maximum recursion depth in encoding/asn1

stdlib@go1.24.11golang1.25.137/1000.006 (45th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-6088

Add recursion depth guard during decode in encoding/xml

stdlib@go1.24.11golang1.25.137/1000.006 (45th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-6089

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

stdlib@go1.24.11golang1.25.137/1000.006 (45th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-6090

Limit handshake messages we are willing to accept post-handshake in crypto/tls

stdlib@go1.24.11golang1.25.137/1000.006 (45th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5038

Quadratic complexity in WordDecoder.DecodeHeader in mime

stdlib@go1.24.11golang1.25.117/1000.006 (44th pct)2 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2026-35341rust-coreutils@0.2.2-0ubuntu2.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-54369acl@2.3.2-2debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-54371attr@1:2.5.2-3build1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-7017perl@5.40.1-6build1debno fix listed7/1002 Sept 20262fb3efa9eaa4
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

stdlib@go1.26.0golang1.26.67/1000.005 (44th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

golang.org/x/net@v0.47.0golang0.56.07/1000.005 (44th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2025-3521

Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes

k8s.io/kubernetes@v1.34.2golangno fix listed7/1000.005 (43th pct)2 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35352rust-coreutils@0.2.2-0ubuntu2.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-58050libssh2@1.11.1-1ubuntu0.25.10.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
GO-2025-4012

Lack of limit when parsing cookies can cause memory exhaustion in net/http

stdlib@go1.24.0golang1.24.87/1000.005 (42th pct)2 Sept 20262fb3efa9eaa4
GO-2025-3956

Unexpected paths returned from LookPath in os/exec

stdlib@go1.24.0golang1.23.127/1000.005 (42th pct)2 Sept 20262fb3efa9eaa4
GO-2025-4011

Parsing DER payload can cause memory exhaustion in encoding/asn1

stdlib@go1.24.0golang1.24.87/1000.005 (42th pct)2 Sept 20262fb3efa9eaa4
GO-2025-4015

Excessive CPU consumption in Reader.ReadResponse in net/textproto

stdlib@go1.24.0golang1.24.87/1000.005 (42th pct)2 Sept 20262fb3efa9eaa4
GO-2026-6218

Avoid quadratic complexity in resolvePath in net/url

stdlib@go1.24.11golang1.25.137/1000.005 (42th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-vh4v-2xq2-g5cg

ORAS Go forwards registry credentials across registry redirects

oras.land/oras-go/v2@v2.6.0golang2.6.17/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56132expat@2.7.1-2ubuntu0.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56403expat@2.7.1-2ubuntu0.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56404expat@2.7.1-2ubuntu0.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56405expat@2.7.1-2ubuntu0.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56406expat@2.7.1-2ubuntu0.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56407expat@2.7.1-2ubuntu0.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56408expat@2.7.1-2ubuntu0.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56410expat@2.7.1-2ubuntu0.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56411expat@2.7.1-2ubuntu0.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
GO-2026-4440

Quadratic parsing complexity in golang.org/x/net/html

golang.org/x/net@v0.38.0golang0.45.07/1000.005 (41th pct)2 Sept 20262fb3efa9eaa4
GO-2026-4559

Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net

golang.org/x/net@v0.50.0golang0.51.07/1000.005 (41th pct)2 Sept 20268499afd690c4
UBUNTU-CVE-2026-13595util-linux@2.41-4ubuntu4.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
GO-2026-4441

Infinite parsing loop in golang.org/x/net

golang.org/x/net@v0.38.0golang0.45.07/1000.005 (40th pct)2 Sept 20262fb3efa9eaa4
GO-2026-5970

Infinite loop on invalid input in golang.org/x/text

golang.org/x/text@v0.28.0golang0.39.07/1000.005 (39th pct)2 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2026-35349rust-coreutils@0.2.2-0ubuntu2.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
GO-2025-4155

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

stdlib@go1.25.3golang1.24.117/1000.005 (38th pct)2 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35350rust-coreutils@0.2.2-0ubuntu2.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35365rust-coreutils@0.2.2-0ubuntu2.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
GO-2025-4008

ALPN negotiation error contains attacker controlled information in crypto/tls

stdlib@go1.24.0golang1.24.87/1000.004 (36th pct)2 Sept 20262fb3efa9eaa4
GO-2025-4010

Insufficient validation of bracketed IPv6 hostnames in net/url

stdlib@go1.24.0golang1.24.87/1000.004 (36th pct)2 Sept 20262fb3efa9eaa4
GO-2024-2476

Dex discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers in github.com/dexidp/dex

github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golangno fix listed7/1000.004 (36th pct)2 Sept 20268499afd690c4
ALPINE-CVE-2026-2673openssl@3.5.5-r0apk3.5.6-r07/1002 Sept 20268499afd690c4
GHSA-w5pp-99ch-qj29

go-git: Malformed Git object data may cause panics or resource exhaustion

github.com/go-git/go-git/v5@v5.14.0golang5.19.17/1002 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2016-2781coreutils@9.5-1ubuntu4.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2016-2781coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu24debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2025-15661libssh2@1.11.1-1ubuntu0.25.10.1deb1.11.1-1ubuntu0.25.10.27/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56409expat@2.7.1-2ubuntu0.2debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-58051libssh2@1.11.1-1ubuntu0.25.10.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-60001openssh@1:10.0p1-5ubuntu5.4debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-6238glibc@2.42-0ubuntu3.1debno fix listed7/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-8458curl@8.14.1-2ubuntu1.3deb8.14.1-2ubuntu1.47/1002 Sept 20262fb3efa9eaa4
GHSA-3xc5-wrhm-f963

go-git: Credential leak via cross-host redirect in smart HTTP transport

github.com/go-git/go-git/v5@v5.14.0golang5.18.06/1000.003 (17th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2025-4014

Unbounded allocation when parsing GNU sparse map in archive/tar

stdlib@go1.24.0golang1.24.86/1000.004 (34th pct)2 Sept 20262fb3efa9eaa4
GO-2025-3503

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

stdlib@go1.24.0golang1.23.76/1000.004 (33th pct)2 Sept 20262fb3efa9eaa4
GO-2026-6107

Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3

go.etcd.io/etcd/client/pkg/v3@v3.6.8golang3.5.336/1000.004 (33th pct)2 Sept 20268499afd690c4
UBUNTU-CVE-2026-35355rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35356rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35360rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35364rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35374rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-54370acl@2.3.2-2debno fix listed6/1002 Sept 20262fb3efa9eaa4
GO-2026-4976

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

stdlib@go1.24.11golang1.25.106/1000.004 (32th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5856

Invoking Encrypted Client Hello privacy leak in crypto/tls

stdlib@go1.24.11golang1.25.126/1000.004 (31th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2025-4007

Quadratic complexity when checking name constraints in crypto/x509

stdlib@go1.24.0golang1.24.96/1000.004 (31th pct)2 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-13757p11-kit@0.25.5-3ubuntu1debno fix listed6/1002 Sept 20262fb3efa9eaa4
GO-2026-4980

Escaper bypass leads to XSS in html/template

stdlib@go1.24.11golang1.25.106/1000.004 (30th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5039

Arbitrary inputs are included in errors without any escaping in net/textproto

stdlib@go1.24.11golang1.25.116/1000.004 (30th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2025-4013

Panic when validating certificates with DSA public keys in crypto/x509

stdlib@go1.24.0golang1.24.86/1000.004 (28th pct)2 Sept 20262fb3efa9eaa4
GO-2025-3849

Incorrect results returned from Rows.Scan in database/sql

stdlib@go1.24.0golang1.23.126/1000.004 (28th pct)2 Sept 20262fb3efa9eaa4
GO-2026-4946

Inefficient policy validation in crypto/x509

stdlib@go1.24.11golang1.25.96/1000.004 (28th pct)2 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2026-50813sqlite3@3.46.1-8debno fix listed6/1002 Sept 20262fb3efa9eaa4
GO-2026-4600

Panic in name constraint checking for malformed certificates in crypto/x509

stdlib@go1.26.0golang1.26.16/1000.004 (28th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5064

containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd

github.com/containerd/containerd@v1.7.29golangno fix listed6/1000.003 (27th pct)2 Sept 20262fb3efa9eaa4
GO-2022-0646

CBC padding oracle issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go

github.com/aws/aws-sdk-go@v1.55.7golangno fix listed6/1000.003 (27th pct)2 Sept 20268499afd690c4
GHSA-hr2v-4r36-88hr

Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang3.20.26/1000.002 (10th pct)2 Sept 20262fb3efa9eaa4
GO-2026-4866

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

stdlib@go1.26.0golang1.26.26/1000.003 (27th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2025-3749

Usage of ExtKeyUsageAny disables policy validation in crypto/x509

stdlib@go1.24.0golang1.24.46/1000.003 (27th pct)2 Sept 20262fb3efa9eaa4
GO-2026-5158

Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel

go.opentelemetry.io/otel@v1.43.0golang1.42.06/1000.003 (26th pct)2 Sept 20262fb3efa9eaa4
GO-2026-4603

URLs in meta content attribute actions are not escaped in html/template

stdlib@go1.24.11golang1.25.86/1000.003 (25th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-6303

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

golang.org/x/crypto@v0.36.0golang0.55.06/1000.003 (25th pct)2 Sept 20262fb3efa9eaa48499afd690c4
ALPINE-CVE-2026-42766openssl@3.5.5-r0apk3.5.7-r06/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-42767openssl@3.5.5-r0apk3.5.7-r06/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-63074openssl@3.5.5-r0apk3.5.8-r06/1002 Sept 20268499afd690c4
GHSA-xmrv-pmrh-hhx2

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.7.4golang1.7.86/1002 Sept 20268499afd690c4
GHSA-xmrv-pmrh-hhx2

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

github.com/aws/aws-sdk-go-v2/service/s3@v1.95.1golang1.97.36/1002 Sept 20268499afd690c4
UBUNTU-CVE-2024-2236libgcrypt20@1.11.0-7ubuntu0.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-40355krb5@1.21.3-5ubuntu2debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-40356krb5@1.21.3-5ubuntu2debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-54411pam@1.7.0-5ubuntu2debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-55199libssh2@1.11.1-1ubuntu0.25.10.1deb1.11.1-1ubuntu0.25.10.26/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-59999openssh@1:10.0p1-5ubuntu5.4debno fix listed6/1002 Sept 20262fb3efa9eaa4
GO-2025-3547

Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes

k8s.io/kubernetes@v1.34.2golangno fix listed6/1000.003 (24th pct)2 Sept 20262fb3efa9eaa4
GO-2026-4982

Bypass of meta content URL escaping causes XSS in html/template

stdlib@go1.24.11golang1.25.106/1000.003 (24th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-6091

Fix Javascript regexp context tracking in html/template

stdlib@go1.24.11golang1.25.136/1000.003 (23th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5338

containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd

github.com/containerd/containerd@v1.7.29golangno fix listed6/1000.003 (22th pct)2 Sept 20262fb3efa9eaa4
GO-2026-6180

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

golang.org/x/mod@v0.32.0golang0.40.06/1000.003 (22th pct)2 Sept 20268499afd690c4
GO-2026-4864

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

stdlib@go1.24.11golang1.25.96/1000.003 (21th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4865

JsBraceDepth Context Tracking Bugs (XSS) in html/template

stdlib@go1.24.11golang1.25.96/1000.003 (21th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4869

Unbounded allocation for old GNU sparse in archive/tar

stdlib@go1.24.11golang1.25.96/1000.003 (21th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GHSA-jhf3-xxhw-2wpp

go-git: Maliciously crafted idx file can cause asymmetric memory consumption

github.com/go-git/go-git/v5@v5.14.0golang5.17.16/1000.001 (4th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4340

Handshake messages may be processed at the incorrect encryption level in crypto/tls

stdlib@go1.24.11golang1.24.126/1000.003 (21th pct)2 Sept 20262fb3efa9eaa4
GO-2025-4175

Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509

stdlib@go1.25.3golang1.24.116/1000.003 (20th pct)2 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35363rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
GO-2025-3750

Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscall

stdlib@go1.24.0golang1.23.106/1000.003 (18th pct)2 Sept 20262fb3efa9eaa4
ALPINE-CVE-2026-27171zlib@1.3.1-r2apk1.3.2-r06/1002 Sept 20268499afd690c4
UBUNTU-CVE-2025-15649perl@5.40.1-6build1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35339rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35340rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35348rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35369rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35380rust-coreutils@0.2.2-0ubuntu2.1debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-50812sqlite3@3.46.1-8debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-53612util-linux@2.41-4ubuntu4.2debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-53613util-linux@2.41-4ubuntu4.2debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-53614util-linux@2.41-4ubuntu4.2debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-53615util-linux@2.41-4ubuntu4.2debno fix listed6/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-4438glibc@2.42-0ubuntu3.1debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-58055nghttp2@1.64.0-1.1ubuntu1.1deb1.64.0-1.1ubuntu1.25/1002 Sept 20262fb3efa9eaa4
GO-2026-4403

Improper access to parent directory of root in os

stdlib@go1.24.0golang1.23.95/1000.002 (15th pct)2 Sept 20262fb3efa9eaa4
GO-2026-5025

Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

golang.org/x/net@v0.47.0golang0.55.05/1000.002 (14th pct)2 Sept 20262fb3efa9eaa48499afd690c4
ALPINE-CVE-2026-42769openssl@3.5.5-r0apk3.5.7-r05/1002 Sept 20268499afd690c4
UBUNTU-CVE-2026-35345rust-coreutils@0.2.2-0ubuntu2.1debno fix listed5/1002 Sept 20262fb3efa9eaa4
GO-2026-4970

Root escape via symlink plus trailing slash in os

stdlib@go1.24.11golang1.25.125/1000.002 (14th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2022-0635

In-band key negotiation issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go

github.com/aws/aws-sdk-go@v1.55.7golangno fix listed5/1000.002 (14th pct)2 Sept 20268499afd690c4
GO-2026-5027

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

golang.org/x/net@v0.47.0golang0.55.05/1000.002 (13th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5029

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

golang.org/x/net@v0.47.0golang0.55.05/1000.002 (13th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5030

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

golang.org/x/net@v0.47.0golang0.55.05/1000.002 (13th pct)2 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-4602

FileInfo can escape from a Root in os

stdlib@go1.24.11golang1.25.85/1000.002 (10th pct)2 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2026-11850krb5@1.21.3-5ubuntu2debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35372rust-coreutils@0.2.2-0ubuntu2.1debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-55655openssh@1:10.0p1-5ubuntu5.4debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-5704tar@1.35+dfsg-3.1build1debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-50219expat@2.7.1-2ubuntu0.2debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56131expat@2.7.1-2ubuntu0.2debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-56412expat@2.7.1-2ubuntu0.2debno fix listed5/1002 Sept 20262fb3efa9eaa4
GO-2026-5622

Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd

github.com/containerd/containerd@v1.7.29golangno fix listed5/1000.002 (7th pct)2 Sept 20262fb3efa9eaa4
ALPINE-CVE-2026-45446openssl@3.5.5-r0apk3.5.7-r05/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-6042musl@1.2.5-r21apk1.2.5-r225/1002 Sept 20268499afd690c4
UBUNTU-CVE-2026-42250bzip2@1.0.8-6build1debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-59998openssh@1:10.0p1-5ubuntu5.4debno fix listed5/1002 Sept 20262fb3efa9eaa4
GHSA-37cx-329c-33x3

go-git improperly verifies data integrity values for .idx and .pack files

github.com/go-git/go-git/v5@v5.14.0golang5.16.55/1000.001 (3th pct)2 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2026-27456util-linux@2.41-4ubuntu4.2debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35354rust-coreutils@0.2.2-0ubuntu2.1debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35357rust-coreutils@0.2.2-0ubuntu2.1debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35359rust-coreutils@0.2.2-0ubuntu2.1debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-41991gzip@1.13-1ubuntu4debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35376rust-coreutils@0.2.2-0ubuntu2.1debno fix listed5/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2025-5278coreutils@9.5-1ubuntu4.1debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2025-5278coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu24debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35347rust-coreutils@0.2.2-0ubuntu2.1debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35358rust-coreutils@0.2.2-0ubuntu2.1debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35366rust-coreutils@0.2.2-0ubuntu2.1debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35370rust-coreutils@0.2.2-0ubuntu2.1debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35351rust-coreutils@0.2.2-0ubuntu2.1debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-59995openssh@1:10.0p1-5ubuntu5.4debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-59996openssh@1:10.0p1-5ubuntu5.4debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-59997openssh@1:10.0p1-5ubuntu5.4debno fix listed4/1002 Sept 20262fb3efa9eaa4
GO-2026-5024

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

golang.org/x/sys@v0.42.0golang0.44.04/1000.001 (2th pct)2 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2025-45582tar@1.35+dfsg-3.1build1debno fix listed4/1002 Sept 20262fb3efa9eaa4
GO-2026-6179

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

golang.org/x/mod@v0.32.0golang0.40.04/1000.001 (1th pct)2 Sept 20268499afd690c4
GO-2026-5410

SecretsVerifier accepts empty signing secret without precondition in github.com/slack-go/slack

github.com/slack-go/slack@v0.16.0golang0.23.14/1002 Sept 20262fb3efa9eaa4
GO-2026-5693

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

github.com/go-git/go-git/v5@v5.14.0golang5.19.14/1002 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-5764

DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream

github.com/aws/aws-sdk-go-v2/service/s3@v1.95.1golang1.97.34/1002 Sept 20268499afd690c4
GO-2026-5764

DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream

github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.7.4golang1.7.84/1002 Sept 20268499afd690c4
GO-2026-5841

OOB read in github.com/klauspost/compress/s2

github.com/klauspost/compress@v1.18.0golang1.18.74/1002 Sept 20262fb3efa9eaa4
GO-2026-5884

ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go

oras.land/oras-go/v2@v2.6.0golang2.6.14/1002 Sept 20262fb3efa9eaa4
GO-2026-5932

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

golang.org/x/crypto@v0.36.0golangno fix listed4/1002 Sept 20262fb3efa9eaa48499afd690c4
GO-2026-6061

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

google.golang.org/grpc@v1.72.1golang1.82.14/1002 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2026-32776expat@2.7.1-2ubuntu0.2debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-32777expat@2.7.1-2ubuntu0.2debno fix listed4/1002 Sept 20262fb3efa9eaa4
USN-8467-2

perl vulnerabilities

perl@5.40.1-6build1deb5.40.1-6ubuntu0.14/1002 Sept 20262fb3efa9eaa4
ALPINE-CVE-2026-42768openssl@3.5.5-r0apk3.5.7-r04/1002 Sept 20268499afd690c4
ALPINE-CVE-2026-42770openssl@3.5.5-r0apk3.5.7-r04/1002 Sept 20268499afd690c4
UBUNTU-CVE-2026-3184util-linux@2.41-4ubuntu4.2debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-55654openssh@1:10.0p1-5ubuntu5.4debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-60000openssh@1:10.0p1-5ubuntu5.4debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2024-56433shadow@1:4.17.4-2ubuntu2debno fix listed4/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35362rust-coreutils@0.2.2-0ubuntu2.1debno fix listed4/1002 Sept 20262fb3efa9eaa4
GHSA-m7cr-m3pv-hgrp

go-git: Improper single-quote escaping in go-git SSH transport

github.com/go-git/go-git/v5@v5.14.0golang5.19.14/1000.004 (29th pct)2 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2026-35361rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2022-3219gnupg2@2.4.8-2ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2025-6141ncurses@6.5+20250216-2build1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35342rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35343rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35344rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35346rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35353rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35367rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35371rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35373rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35375rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35377rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35378rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35379rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-35381rust-coreutils@0.2.2-0ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
GHSA-gm2x-2g9h-ccm8

go-git missing validation decoding Index v4 files leads to panic

github.com/go-git/go-git/v5@v5.14.0golang5.17.13/1000.002 (5th pct)2 Sept 20262fb3efa9eaa48499afd690c4
UBUNTU-CVE-2025-66382expat@2.7.1-2ubuntu0.2debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-27171zlib@1:1.3.dfsg+really1.3.1-1ubuntu2debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-32778expat@2.7.1-2ubuntu0.2debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-40228systemd@257.9-0ubuntu2.5debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-41080expat@2.7.1-2ubuntu0.2debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-45186expat@2.7.1-2ubuntu0.2debno fix listed3/1002 Sept 20262fb3efa9eaa4
UBUNTU-CVE-2026-57062gnupg2@2.4.8-2ubuntu2.1debno fix listed3/1002 Sept 20262fb3efa9eaa4
GHSA-xf85-363p-868w

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

oras.land/oras-go/v2@v2.6.0golang2.6.13/1000.003 (17th pct)2 Sept 20262fb3efa9eaa4

Workloads and images

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

ContainerImageTagDigestRadar Score
Deployment candidate-argocd-applicationset-controller
applicationset-controllerquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
Deployment candidate-argocd-notifications-controller
notifications-controllerquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
Deployment candidate-argocd-repo-server
copyutilinitquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
repo-serverquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
Deployment candidate-argocd-server
serverquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
Deployment candidate-argocd-dex-server
copyutilinitquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
dex-serverghcr.io/dexidp/dexv2.45.18499afd690c41,104
Deployment candidate-argocd-redis
redisecr-public.aws.com/docker/library/redis8.2.3-alpineunmeasured: registry not in allow-list
StatefulSet candidate-argocd-application-controller
application-controllerquay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003
Job candidate-argocd-redis-secret-init
secret-inithook: pre-install,pre-upgradequay.io/argoproj/argocdv3.4.42fb3efa9eaa42,003

Unmeasured images (1)

  • ecr-public.aws.com/docker/library/redis:8.2.3-alpineregistry not in allow-list

Indexed versions

The latest version and the previous major, as selected nightly from the repository’s index.

VersionApp versionRadar ScoreBandMeasuredRender
10.6.4latestv3.5.22,461Medium2 / 3rendered 2 Sept 2026
9.7.1previous majorv3.4.43,107Medium2 / 3rendered 2 Sept 2026

helm v3.16.4 · syft 1.42.1 · rendered 2 Sept 2026 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.