prometheus28.16.0
Helm chartPrometheus is a monitoring system and time series database.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 36
- Low
- 338
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
374 findings over 6 of 6 images measured · scored 2 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of 28.16.0, one sample per day, last 90 days. Hover a point for its date and advisory data.
Score moves
A score can move without the chart changing: the advisory data behind every finding is refreshed daily. Each move lists which inputs changed. Why a score moves
Fewer than two samples so far.
Findings
88 distinct across the version’s images
| Advisory | Package | Fixed in | Contribution | EPSS | Since | Digests |
|---|---|---|---|---|---|---|
| GHSA-5cgq-3rg8-m6cv golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 38/100 | 0.073 (94th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-p77j-4mvh-x3m3 gRPC-Go has an authorization bypass via missing leading slash in :path | google.golang.org/grpc@v1.78.0golang | 1.79.3 | 23/100 | 0.016 (73th pct) | 2 Sept 2026 | 1545919b72e388b605de9aba |
| GO-2026-4887 Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/docker | github.com/docker/docker@v28.5.2+incompatiblegolang | no fix listed | 18/100 | 0.091 (95th pct) | 2 Sept 2026 | 131bf4c9d8a0 |
| GHSA-x527-x647-q7gg golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 17/100 | 0.005 (41th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-vgwf-h737-ff37 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 17/100 | 0.006 (47th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-f5wc-c3c7-36mc golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 17/100 | 0.006 (46th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-rm3j-f69w-wqmq golang.org/x/crypto vulnerable to infinite loop on large channel writes | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 16/100 | 0.005 (42th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-8rm2-7qqf-34qm Prometheus: Remote read endpoint allows denial of service via crafted snappy payload | github.com/prometheus/prometheus@v0.307.3golang | 0.311.3 | 15/100 | 0.008 (54th pct) | 2 Sept 2026 | 131bf4c9d8a049ed9fdf3780693faa0b8724 |
| GHSA-89gr-r52h-f8rx golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 15/100 | 0.004 (35th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-6g7g-w4f8-9c9x github.com/buger/jsonparser has a denial of service vulnerability | github.com/buger/jsonparser@v1.1.1golang | 1.1.2 | 15/100 | 0.007 (52th pct) | 2 Sept 2026 | 131bf4c9d8a0 |
| GHSA-jppx-rxg9-jmrx golang.org/x/crypto doesn't enforce invoking key constraints | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 15/100 | 0.004 (34th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-mh2q-q3fh-2475 OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) | go.opentelemetry.io/otel@v1.39.0golang | 1.41.0 | 14/100 | 0.007 (48th pct) | 2 Sept 2026 | 1545919b72e388b605de9aba |
| GHSA-q4h4-gmj2-qvw2 golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 13/100 | 0.005 (39th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-w879-237q-wc7r golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 13/100 | 0.005 (38th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-wg65-39gg-5wfj Prometheus Azure AD remote write OAuth client secret exposed via config API | github.com/prometheus/prometheus@v0.307.3golang | 0.311.3 | 11/100 | 0.004 (28th pct) | 2 Sept 2026 | 49ed9fdf3780693faa0b8724 |
| GO-2026-4341 Memory exhaustion in query parameter parsing in net/url | stdlib@go1.25.3golang | 1.24.12 | 11/100 | 0.020 (79th pct) | 2 Sept 2026 | 1545919b72e349ed9fdf3780 |
| GHSA-pxq6-2prw-chj9 Moby has an Off-by-one error in its plugin privilege validation | github.com/docker/docker@v28.5.2+incompatiblegolang | no fix listed | 11/100 | 0.004 (32th pct) | 2 Sept 2026 | 131bf4c9d8a0 |
| GHSA-hfvc-g4fc-pqhx opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking | go.opentelemetry.io/otel/sdk@v1.39.0golang | 1.43.0 | 10/100 | 0.003 (17th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e388b605de9aba |
| GHSA-45gg-vh54-h5m9 golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 10/100 | 0.004 (30th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-5cv4-jp36-h3mw Go Net HTML parser is vulnerable to denial of service | golang.org/x/net@v0.46.0golang | 0.55.0 | 10/100 | 0.003 (25th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-j5w8-q4qc-rx2x golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption | golang.org/x/crypto@v0.43.0golang | 0.45.0 | 9/100 | 0.006 (44th pct) | 2 Sept 2026 | 49ed9fdf3780 |
| GHSA-qpw4-5x99-6vjp golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 9/100 | 0.003 (20th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-f6x5-jh6r-wrfv golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read | golang.org/x/crypto@v0.43.0golang | 0.45.0 | 9/100 | 0.005 (41th pct) | 2 Sept 2026 | 49ed9fdf3780 |
| GHSA-78mq-xcr3-xm33 golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 9/100 | 0.005 (41th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | google.golang.org/grpc@v1.78.0golang | 1.82.1 | 9/100 | — | 2 Sept 2026 | 131bf4c9d8a01545919b72e388b605de9aba |
| GHSA-vp52-pcj8-j9qc gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | google.golang.org/grpc@v1.78.0golang | 1.83.1 | 9/100 | — | 2 Sept 2026 | 131bf4c9d8a01545919b72e388b605de9aba |
| GHSA-9m57-25v3-79x9 golang.org/x/crypto: Invoking pathological inputs can lead to client panic | golang.org/x/crypto@v0.43.0golang | 0.52.0 | 8/100 | 0.004 (34th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-cp6g-7hqx-qxhp mongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling | go.mongodb.org/mongo-driver@v1.17.6golang | 1.17.7 | 8/100 | 0.002 (13th pct) | 2 Sept 2026 | 88b605de9aba |
| GHSA-x86f-5xw2-fm2r Docker: `PUT /containers/{id}/archive` executes container binary on the host | github.com/docker/docker@v28.5.2+incompatiblegolang | no fix listed | 8/100 | 0.002 (6th pct) | 2 Sept 2026 | 131bf4c9d8a0 |
| GHSA-vffh-x6r8-xx99 Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer | github.com/prometheus/prometheus@v0.307.3golang | 0.311.2-0.20260410083055-07c6232d159b | 8/100 | 0.003 (17th pct) | 2 Sept 2026 | 131bf4c9d8a049ed9fdf3780693faa0b8724 |
| GHSA-9h8m-3fm2-qjrq OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking | go.opentelemetry.io/otel/sdk@v1.39.0golang | 1.40.0 | 8/100 | 0.002 (5th pct) | 2 Sept 2026 | 1545919b72e388b605de9aba |
| GO-2026-4981 Crash when handling long CNAME response in net | stdlib@go1.25.3golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4977 Quadratic string concatenation in consumePhrase in net/mail | stdlib@go1.25.3golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4986 Quadratic string concatentation in consumeComment in net/mail | stdlib@go1.25.3golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | golang.org/x/net@v0.46.0golang | 0.53.0 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | stdlib@go1.25.3golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4337 Unexpected session resumption in crypto/tls | stdlib@go1.25.3golang | 1.24.13 | 8/100 | 0.008 (52th pct) | 2 Sept 2026 | 1545919b72e349ed9fdf3780 |
| GO-2026-4601 Incorrect parsing of IPv6 host literals in net/url | stdlib@go1.25.3golang | 1.25.8 | 8/100 | 0.007 (51th pct) | 2 Sept 2026 | 1545919b72e349ed9fdf378088b605de9aba |
| GHSA-fw8g-cg8f-9j28 Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display | github.com/prometheus/prometheus@v0.307.3golang | 0.311.3 | 8/100 | 0.002 (10th pct) | 2 Sept 2026 | 131bf4c9d8a049ed9fdf3780693faa0b8724 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | stdlib@go1.25.3golang | 1.25.13 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | golang.org/x/net@v0.46.0golang | 0.55.0 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4342 Excessive CPU consumption when building archive index in archive/zip | stdlib@go1.25.3golang | 1.24.12 | 8/100 | 0.007 (49th pct) | 2 Sept 2026 | 1545919b72e349ed9fdf3780 |
| GO-2026-4870 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls | stdlib@go1.25.3golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4947 Unexpected work during chain building in crypto/x509 | stdlib@go1.25.3golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-rg2x-37c3-w2rh Docker: Race condition in docker cp allows bind mount redirection to host path | github.com/docker/docker@v28.5.2+incompatiblegolang | no fix listed | 7/100 | 0.001 (1th pct) | 2 Sept 2026 | 131bf4c9d8a0 |
| GO-2026-5037 Inefficient candidate hostname parsing in crypto/x509 | stdlib@go1.25.3golang | 1.25.11 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4971 Panic in Dial and LookupPort when handling NUL byte on Windows in net | stdlib@go1.25.3golang | 1.25.10 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-5972 Enforce maximum recursion depth in encoding/asn1 | stdlib@go1.25.3golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-6088 Add recursion depth guard during decode in encoding/xml | stdlib@go1.25.3golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-6089 Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http | stdlib@go1.25.3golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-6090 Limit handshake messages we are willing to accept post-handshake in crypto/tls | stdlib@go1.25.3golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-5038 Quadratic complexity in WordDecoder.DecodeHeader in mime | stdlib@go1.25.3golang | 1.25.11 | 7/100 | 0.006 (44th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | golang.org/x/net@v0.46.0golang | 0.56.0 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | stdlib@go1.26.1golang | 1.26.6 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 | 131bf4c9d8a02f0cc335ef9e |
| GO-2026-6218 Avoid quadratic complexity in resolvePath in net/url | stdlib@go1.25.3golang | 1.25.13 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-5970 Infinite loop on invalid input in golang.org/x/text | golang.org/x/text@v0.30.0golang | 0.39.0 | 7/100 | 0.005 (39th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2025-4155 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 | stdlib@go1.25.3golang | 1.24.11 | 7/100 | 0.005 (38th pct) | 2 Sept 2026 | 49ed9fdf3780 |
| GHSA-w8rr-5gcm-pp58 opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.39.0golang | 1.43.0 | 7/100 | 0.002 (9th pct) | 2 Sept 2026 | 131bf4c9d8a088b605de9aba |
| GHSA-gcjh-h69q-9w9g cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag | github.com/google/cel-go@v0.26.0golang | 0.29.0 | 6/100 | — | 2 Sept 2026 | 1545919b72e3 |
| GO-2026-4976 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil | stdlib@go1.25.3golang | 1.25.10 | 6/100 | 0.004 (32th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GHSA-vp62-88p7-qqf5 Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap | github.com/docker/docker@v28.5.2+incompatiblegolang | no fix listed | 6/100 | 0.001 (1th pct) | 2 Sept 2026 | 131bf4c9d8a0 |
| GO-2026-5856 Invoking Encrypted Client Hello privacy leak in crypto/tls | stdlib@go1.25.3golang | 1.25.12 | 6/100 | 0.004 (31th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4980 Escaper bypass leads to XSS in html/template | stdlib@go1.25.3golang | 1.25.10 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-5039 Arbitrary inputs are included in errors without any escaping in net/textproto | stdlib@go1.25.3golang | 1.25.11 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4946 Inefficient policy validation in crypto/x509 | stdlib@go1.25.3golang | 1.25.9 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4866 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 | stdlib@go1.26.1golang | 1.26.2 | 6/100 | 0.003 (27th pct) | 2 Sept 2026 | 131bf4c9d8a02f0cc335ef9e |
| GO-2026-4603 URLs in meta content attribute actions are not escaped in html/template | stdlib@go1.25.3golang | 1.25.8 | 6/100 | 0.003 (25th pct) | 2 Sept 2026 | 1545919b72e349ed9fdf378088b605de9aba |
| GO-2026-6303 Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | golang.org/x/crypto@v0.43.0golang | 0.55.0 | 6/100 | 0.003 (25th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4982 Bypass of meta content URL escaping causes XSS in html/template | stdlib@go1.25.3golang | 1.25.10 | 6/100 | 0.003 (24th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-6091 Fix Javascript regexp context tracking in html/template | stdlib@go1.25.3golang | 1.25.13 | 6/100 | 0.003 (23th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-6180 Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb | golang.org/x/mod@v0.32.0golang | 0.40.0 | 6/100 | 0.003 (22th pct) | 2 Sept 2026 | 88b605de9aba |
| GO-2026-4864 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix | stdlib@go1.25.3golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4865 JsBraceDepth Context Tracking Bugs (XSS) in html/template | stdlib@go1.25.3golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4869 Unbounded allocation for old GNU sparse in archive/tar | stdlib@go1.25.3golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4340 Handshake messages may be processed at the incorrect encryption level in crypto/tls | stdlib@go1.25.3golang | 1.24.12 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 | 1545919b72e349ed9fdf3780 |
| GO-2025-4175 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 | stdlib@go1.25.3golang | 1.24.11 | 6/100 | 0.003 (20th pct) | 2 Sept 2026 | 49ed9fdf3780 |
| GO-2026-5025 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | golang.org/x/net@v0.46.0golang | 0.55.0 | 5/100 | 0.002 (14th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4970 Root escape via symlink plus trailing slash in os | stdlib@go1.25.3golang | 1.25.12 | 5/100 | 0.002 (14th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-5027 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | golang.org/x/net@v0.46.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-5029 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | golang.org/x/net@v0.46.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-5030 Invoking duplicate attributes can cause XSS in golang.org/x/net/html | golang.org/x/net@v0.46.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-4602 FileInfo can escape from a Root in os | stdlib@go1.25.3golang | 1.25.8 | 5/100 | 0.002 (10th pct) | 2 Sept 2026 | 1545919b72e349ed9fdf378088b605de9aba |
| GO-2026-5024 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | golang.org/x/sys@v0.37.0golang | 0.44.0 | 4/100 | 0.001 (2th pct) | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-6179 Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog | golang.org/x/mod@v0.32.0golang | 0.40.0 | 4/100 | 0.001 (1th pct) | 2 Sept 2026 | 88b605de9aba |
| GO-2026-5841 OOB read in github.com/klauspost/compress/s2 | github.com/klauspost/compress@v1.18.5golang | 1.18.7 | 4/100 | — | 2 Sept 2026 | 131bf4c9d8a0 |
| GO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | golang.org/x/crypto@v0.43.0golang | no fix listed | 4/100 | — | 2 Sept 2026 | 131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba |
| GO-2026-6061 Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc | google.golang.org/grpc@v1.78.0golang | 1.82.1 | 4/100 | — | 2 Sept 2026 | 131bf4c9d8a01545919b72e388b605de9aba |
| GO-2026-6094 JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go | github.com/google/cel-go@v0.26.0golang | 0.30.0 | 4/100 | — | 2 Sept 2026 | 1545919b72e3 |
Workloads and images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
| Container | Image | Tag | Digest | Radar Score |
|---|---|---|---|---|
| DaemonSet candidate-prometheus-node-exporter | ||||
| node-exporter | quay.io/prometheus/node-exporter | v1.11.0 | 2f0cc335ef9e | 459 |
| Deployment candidate-kube-state-metrics | ||||
| kube-state-metrics | registry.k8s.io/kube-state-metrics/kube-state-metrics | v2.18.0 | 1545919b72e3 | 583 |
| Deployment candidate-prometheus-pushgateway | ||||
| pushgateway | quay.io/prometheus/pushgateway | v1.11.2 | 49ed9fdf3780 | 570 |
| Deployment candidate-prometheus-server | ||||
| prometheus-server-configmap-reload | quay.io/prometheus-operator/prometheus-config-reloader | v0.90.1 | 693faa0b8724 | 488 |
| prometheus-server | quay.io/prometheus/prometheus | v3.11.0 | 131bf4c9d8a0 | 597 |
| StatefulSet candidate-alertmanager | ||||
| alertmanager | quay.io/prometheus/alertmanager | v0.31.1 | 88b605de9aba | 566 |
Unmeasured images (0)
Every image the render resolved has a scan.