prometheus28.16.0

Helm chart
prometheus-community repositoryon Artifact Hub 553#5 by starsofficialverified publisher

Prometheus is a monitoring system and time series database.

version 28.16.0kube >=1.19.0-0app version v3.11.0
README badge
[![Radar Score](https://charts.stackradar.io/badge/prometheus-community/prometheus.svg)](https://charts.stackradar.io/charts/prometheus-community/prometheus)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

Radar Score

3,263
worst finding Medium
Critical
0
High
0
Medium
36
Low
338
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

374 findings over 6 of 6 images measured · scored 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of 28.16.0, one sample per day, last 90 days. Hover a point for its date and advisory data.

2 Sept 2026 · Radar Score 3,263 · OSV as of 2 Sept 2026
history since 2 Sept 2026

Score moves

A score can move without the chart changing: the advisory data behind every finding is refreshed daily. Each move lists which inputs changed. Why a score moves

Fewer than two samples so far.

Findings

88 distinct across the version’s images

AdvisoryPackageFixed inContributionEPSSSinceDigests
GHSA-5cgq-3rg8-m6cv

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

golang.org/x/crypto@v0.43.0golang0.52.038/1000.073 (94th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-p77j-4mvh-x3m3

gRPC-Go has an authorization bypass via missing leading slash in :path

google.golang.org/grpc@v1.78.0golang1.79.323/1000.016 (73th pct)2 Sept 20261545919b72e388b605de9aba
GO-2026-4887

Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/docker

github.com/docker/docker@v28.5.2+incompatiblegolangno fix listed18/1000.091 (95th pct)2 Sept 2026131bf4c9d8a0
GHSA-x527-x647-q7gg

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

golang.org/x/crypto@v0.43.0golang0.52.017/1000.005 (41th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-vgwf-h737-ff37

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

golang.org/x/crypto@v0.43.0golang0.52.017/1000.006 (47th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-f5wc-c3c7-36mc

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

golang.org/x/crypto@v0.43.0golang0.52.017/1000.006 (46th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-rm3j-f69w-wqmq

golang.org/x/crypto vulnerable to infinite loop on large channel writes

golang.org/x/crypto@v0.43.0golang0.52.016/1000.005 (42th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-8rm2-7qqf-34qm

Prometheus: Remote read endpoint allows denial of service via crafted snappy payload

github.com/prometheus/prometheus@v0.307.3golang0.311.315/1000.008 (54th pct)2 Sept 2026131bf4c9d8a049ed9fdf3780693faa0b8724
GHSA-89gr-r52h-f8rx

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

golang.org/x/crypto@v0.43.0golang0.52.015/1000.004 (35th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-6g7g-w4f8-9c9x

github.com/buger/jsonparser has a denial of service vulnerability

github.com/buger/jsonparser@v1.1.1golang1.1.215/1000.007 (52th pct)2 Sept 2026131bf4c9d8a0
GHSA-jppx-rxg9-jmrx

golang.org/x/crypto doesn't enforce invoking key constraints

golang.org/x/crypto@v0.43.0golang0.52.015/1000.004 (34th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-mh2q-q3fh-2475

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

go.opentelemetry.io/otel@v1.39.0golang1.41.014/1000.007 (48th pct)2 Sept 20261545919b72e388b605de9aba
GHSA-q4h4-gmj2-qvw2

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

golang.org/x/crypto@v0.43.0golang0.52.013/1000.005 (39th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-w879-237q-wc7r

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

golang.org/x/crypto@v0.43.0golang0.52.013/1000.005 (38th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-wg65-39gg-5wfj

Prometheus Azure AD remote write OAuth client secret exposed via config API

github.com/prometheus/prometheus@v0.307.3golang0.311.311/1000.004 (28th pct)2 Sept 202649ed9fdf3780693faa0b8724
GO-2026-4341

Memory exhaustion in query parameter parsing in net/url

stdlib@go1.25.3golang1.24.1211/1000.020 (79th pct)2 Sept 20261545919b72e349ed9fdf3780
GHSA-pxq6-2prw-chj9

Moby has an Off-by-one error in its plugin privilege validation

github.com/docker/docker@v28.5.2+incompatiblegolangno fix listed11/1000.004 (32th pct)2 Sept 2026131bf4c9d8a0
GHSA-hfvc-g4fc-pqhx

opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking

go.opentelemetry.io/otel/sdk@v1.39.0golang1.43.010/1000.003 (17th pct)2 Sept 2026131bf4c9d8a01545919b72e388b605de9aba
GHSA-45gg-vh54-h5m9

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

golang.org/x/crypto@v0.43.0golang0.52.010/1000.004 (30th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-5cv4-jp36-h3mw

Go Net HTML parser is vulnerable to denial of service

golang.org/x/net@v0.46.0golang0.55.010/1000.003 (25th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-j5w8-q4qc-rx2x

golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption

golang.org/x/crypto@v0.43.0golang0.45.09/1000.006 (44th pct)2 Sept 202649ed9fdf3780
GHSA-qpw4-5x99-6vjp

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

golang.org/x/crypto@v0.43.0golang0.52.09/1000.003 (20th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-f6x5-jh6r-wrfv

golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read

golang.org/x/crypto@v0.43.0golang0.45.09/1000.005 (41th pct)2 Sept 202649ed9fdf3780
GHSA-78mq-xcr3-xm33

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

golang.org/x/crypto@v0.43.0golang0.52.09/1000.005 (41th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-hrxh-6v49-42gf

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

google.golang.org/grpc@v1.78.0golang1.82.19/1002 Sept 2026131bf4c9d8a01545919b72e388b605de9aba
GHSA-vp52-pcj8-j9qc

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

google.golang.org/grpc@v1.78.0golang1.83.19/1002 Sept 2026131bf4c9d8a01545919b72e388b605de9aba
GHSA-9m57-25v3-79x9

golang.org/x/crypto: Invoking pathological inputs can lead to client panic

golang.org/x/crypto@v0.43.0golang0.52.08/1000.004 (34th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-cp6g-7hqx-qxhp

mongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling

go.mongodb.org/mongo-driver@v1.17.6golang1.17.78/1000.002 (13th pct)2 Sept 202688b605de9aba
GHSA-x86f-5xw2-fm2r

Docker: `PUT /containers/{id}/archive` executes container binary on the host

github.com/docker/docker@v28.5.2+incompatiblegolangno fix listed8/1000.002 (6th pct)2 Sept 2026131bf4c9d8a0
GHSA-vffh-x6r8-xx99

Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer

github.com/prometheus/prometheus@v0.307.3golang0.311.2-0.20260410083055-07c6232d159b8/1000.003 (17th pct)2 Sept 2026131bf4c9d8a049ed9fdf3780693faa0b8724
GHSA-9h8m-3fm2-qjrq

OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking

go.opentelemetry.io/otel/sdk@v1.39.0golang1.40.08/1000.002 (5th pct)2 Sept 20261545919b72e388b605de9aba
GO-2026-4981

Crash when handling long CNAME response in net

stdlib@go1.25.3golang1.25.108/1000.008 (54th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4977

Quadratic string concatenation in consumePhrase in net/mail

stdlib@go1.25.3golang1.25.108/1000.008 (54th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4986

Quadratic string concatentation in consumeComment in net/mail

stdlib@go1.25.3golang1.25.108/1000.008 (53th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

golang.org/x/net@v0.46.0golang0.53.08/1000.008 (53th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

stdlib@go1.25.3golang1.25.108/1000.008 (53th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4337

Unexpected session resumption in crypto/tls

stdlib@go1.25.3golang1.24.138/1000.008 (52th pct)2 Sept 20261545919b72e349ed9fdf3780
GO-2026-4601

Incorrect parsing of IPv6 host literals in net/url

stdlib@go1.25.3golang1.25.88/1000.007 (51th pct)2 Sept 20261545919b72e349ed9fdf378088b605de9aba
GHSA-fw8g-cg8f-9j28

Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display

github.com/prometheus/prometheus@v0.307.3golang0.311.38/1000.002 (10th pct)2 Sept 2026131bf4c9d8a049ed9fdf3780693faa0b8724
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

stdlib@go1.25.3golang1.25.138/1000.007 (50th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

golang.org/x/net@v0.46.0golang0.55.08/1000.007 (50th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4342

Excessive CPU consumption when building archive index in archive/zip

stdlib@go1.25.3golang1.24.128/1000.007 (49th pct)2 Sept 20261545919b72e349ed9fdf3780
GO-2026-4870

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

stdlib@go1.25.3golang1.25.97/1000.006 (47th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4947

Unexpected work during chain building in crypto/x509

stdlib@go1.25.3golang1.25.97/1000.006 (47th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-rg2x-37c3-w2rh

Docker: Race condition in docker cp allows bind mount redirection to host path

github.com/docker/docker@v28.5.2+incompatiblegolangno fix listed7/1000.001 (1th pct)2 Sept 2026131bf4c9d8a0
GO-2026-5037

Inefficient candidate hostname parsing in crypto/x509

stdlib@go1.25.3golang1.25.117/1000.006 (46th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4971

Panic in Dial and LookupPort when handling NUL byte on Windows in net

stdlib@go1.25.3golang1.25.107/1000.006 (45th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-5972

Enforce maximum recursion depth in encoding/asn1

stdlib@go1.25.3golang1.25.137/1000.006 (45th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-6088

Add recursion depth guard during decode in encoding/xml

stdlib@go1.25.3golang1.25.137/1000.006 (45th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-6089

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

stdlib@go1.25.3golang1.25.137/1000.006 (45th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-6090

Limit handshake messages we are willing to accept post-handshake in crypto/tls

stdlib@go1.25.3golang1.25.137/1000.006 (45th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-5038

Quadratic complexity in WordDecoder.DecodeHeader in mime

stdlib@go1.25.3golang1.25.117/1000.006 (44th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

golang.org/x/net@v0.46.0golang0.56.07/1000.005 (44th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

stdlib@go1.26.1golang1.26.67/1000.005 (44th pct)2 Sept 2026131bf4c9d8a02f0cc335ef9e
GO-2026-6218

Avoid quadratic complexity in resolvePath in net/url

stdlib@go1.25.3golang1.25.137/1000.005 (42th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-5970

Infinite loop on invalid input in golang.org/x/text

golang.org/x/text@v0.30.0golang0.39.07/1000.005 (39th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2025-4155

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

stdlib@go1.25.3golang1.24.117/1000.005 (38th pct)2 Sept 202649ed9fdf3780
GHSA-w8rr-5gcm-pp58

opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies

go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.39.0golang1.43.07/1000.002 (9th pct)2 Sept 2026131bf4c9d8a088b605de9aba
GHSA-gcjh-h69q-9w9g

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

github.com/google/cel-go@v0.26.0golang0.29.06/1002 Sept 20261545919b72e3
GO-2026-4976

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

stdlib@go1.25.3golang1.25.106/1000.004 (32th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GHSA-vp62-88p7-qqf5

Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

github.com/docker/docker@v28.5.2+incompatiblegolangno fix listed6/1000.001 (1th pct)2 Sept 2026131bf4c9d8a0
GO-2026-5856

Invoking Encrypted Client Hello privacy leak in crypto/tls

stdlib@go1.25.3golang1.25.126/1000.004 (31th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4980

Escaper bypass leads to XSS in html/template

stdlib@go1.25.3golang1.25.106/1000.004 (30th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-5039

Arbitrary inputs are included in errors without any escaping in net/textproto

stdlib@go1.25.3golang1.25.116/1000.004 (30th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4946

Inefficient policy validation in crypto/x509

stdlib@go1.25.3golang1.25.96/1000.004 (28th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4866

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

stdlib@go1.26.1golang1.26.26/1000.003 (27th pct)2 Sept 2026131bf4c9d8a02f0cc335ef9e
GO-2026-4603

URLs in meta content attribute actions are not escaped in html/template

stdlib@go1.25.3golang1.25.86/1000.003 (25th pct)2 Sept 20261545919b72e349ed9fdf378088b605de9aba
GO-2026-6303

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

golang.org/x/crypto@v0.43.0golang0.55.06/1000.003 (25th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4982

Bypass of meta content URL escaping causes XSS in html/template

stdlib@go1.25.3golang1.25.106/1000.003 (24th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-6091

Fix Javascript regexp context tracking in html/template

stdlib@go1.25.3golang1.25.136/1000.003 (23th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-6180

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

golang.org/x/mod@v0.32.0golang0.40.06/1000.003 (22th pct)2 Sept 202688b605de9aba
GO-2026-4864

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

stdlib@go1.25.3golang1.25.96/1000.003 (21th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4865

JsBraceDepth Context Tracking Bugs (XSS) in html/template

stdlib@go1.25.3golang1.25.96/1000.003 (21th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4869

Unbounded allocation for old GNU sparse in archive/tar

stdlib@go1.25.3golang1.25.96/1000.003 (21th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4340

Handshake messages may be processed at the incorrect encryption level in crypto/tls

stdlib@go1.25.3golang1.24.126/1000.003 (21th pct)2 Sept 20261545919b72e349ed9fdf3780
GO-2025-4175

Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509

stdlib@go1.25.3golang1.24.116/1000.003 (20th pct)2 Sept 202649ed9fdf3780
GO-2026-5025

Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

golang.org/x/net@v0.46.0golang0.55.05/1000.002 (14th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4970

Root escape via symlink plus trailing slash in os

stdlib@go1.25.3golang1.25.125/1000.002 (14th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-5027

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

golang.org/x/net@v0.46.0golang0.55.05/1000.002 (13th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-5029

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

golang.org/x/net@v0.46.0golang0.55.05/1000.002 (13th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-5030

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

golang.org/x/net@v0.46.0golang0.55.05/1000.002 (13th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-4602

FileInfo can escape from a Root in os

stdlib@go1.25.3golang1.25.85/1000.002 (10th pct)2 Sept 20261545919b72e349ed9fdf378088b605de9aba
GO-2026-5024

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

golang.org/x/sys@v0.37.0golang0.44.04/1000.001 (2th pct)2 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-6179

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

golang.org/x/mod@v0.32.0golang0.40.04/1000.001 (1th pct)2 Sept 202688b605de9aba
GO-2026-5841

OOB read in github.com/klauspost/compress/s2

github.com/klauspost/compress@v1.18.5golang1.18.74/1002 Sept 2026131bf4c9d8a0
GO-2026-5932

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

golang.org/x/crypto@v0.43.0golangno fix listed4/1002 Sept 2026131bf4c9d8a01545919b72e32f0cc335ef9e49ed9fdf3780693faa0b872488b605de9aba
GO-2026-6061

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

google.golang.org/grpc@v1.78.0golang1.82.14/1002 Sept 2026131bf4c9d8a01545919b72e388b605de9aba
GO-2026-6094

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

github.com/google/cel-go@v0.26.0golang0.30.04/1002 Sept 20261545919b72e3

Workloads and images

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

ContainerImageTagDigestRadar Score
DaemonSet candidate-prometheus-node-exporter
node-exporterquay.io/prometheus/node-exporterv1.11.02f0cc335ef9e459
Deployment candidate-kube-state-metrics
kube-state-metricsregistry.k8s.io/kube-state-metrics/kube-state-metricsv2.18.01545919b72e3583
Deployment candidate-prometheus-pushgateway
pushgatewayquay.io/prometheus/pushgatewayv1.11.249ed9fdf3780570
Deployment candidate-prometheus-server
prometheus-server-configmap-reloadquay.io/prometheus-operator/prometheus-config-reloaderv0.90.1693faa0b8724488
prometheus-serverquay.io/prometheus/prometheusv3.11.0131bf4c9d8a0597
StatefulSet candidate-alertmanager
alertmanagerquay.io/prometheus/alertmanagerv0.31.188b605de9aba566

Unmeasured images (0)

Every image the render resolved has a scan.

Indexed versions

The latest version and the previous major, as selected nightly from the repository’s index.

VersionApp versionRadar ScoreBandMeasuredRender
29.27.0latestv3.14.0254Low4 / 6rendered 2 Sept 2026
28.16.0previous majorv3.11.03,263Medium6 / 6rendered 2 Sept 2026

helm v3.16.4 · syft 1.42.1 · rendered 2 Sept 2026 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.