quay.io/argoproj/argocd:v3.4.4
container imageDeployed by 0 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 8
- Low
- 278
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
286 findings on digest 2fb3efa9eaa4 · scanned 2 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of quay.io/argoproj/argocd:v3.4.4 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.
Findings
286 distinct on the current digest
Findings for digest 2fb3efa9eaa4 as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.
| Advisory | Package | Fixed in | Contribution | EPSS | Since |
|---|---|---|---|---|---|
| GHSA-5cgq-3rg8-m6cv golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 38/100 | 0.073 (94th pct) | 2 Sept 2026 |
| GHSA-p77j-4mvh-x3m3 gRPC-Go has an authorization bypass via missing leading slash in :path | google.golang.org/grpc@v1.72.1golang | 1.79.3 | 23/100 | 0.016 (73th pct) | 2 Sept 2026 |
| GHSA-x527-x647-q7gg golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.005 (41th pct) | 2 Sept 2026 |
| GHSA-vgwf-h737-ff37 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GHSA-f5wc-c3c7-36mc golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 17/100 | 0.006 (46th pct) | 2 Sept 2026 |
| GHSA-pc3f-x583-g7j2 SpdyStream: DOS on CRI | github.com/moby/spdystream@v0.5.0golang | 0.5.1 | 16/100 | 0.007 (49th pct) | 2 Sept 2026 |
| GHSA-rm3j-f69w-wqmq golang.org/x/crypto vulnerable to infinite loop on large channel writes | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 16/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GHSA-r53h-jv2g-vpx6 Helm's Missing YAML Content Leads To Panic | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.14.2 | 16/100 | 0.009 (58th pct) | 2 Sept 2026 |
| GHSA-89gr-r52h-f8rx golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 15/100 | 0.004 (35th pct) | 2 Sept 2026 |
| GHSA-jppx-rxg9-jmrx golang.org/x/crypto doesn't enforce invoking key constraints | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 15/100 | 0.004 (34th pct) | 2 Sept 2026 |
| GHSA-7hfp-qfw3-5jxh Helm Vulnerable to denial of service through string value parsing | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.9.4 | 14/100 | 0.010 (61th pct) | 2 Sept 2026 |
| GHSA-56hp-xqp3-w2jf Helm passes repository credentials to alternate domain | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.6.1 | 13/100 | 0.014 (70th pct) | 2 Sept 2026 |
| GHSA-557j-xg8c-q2mm Helm vulnerable to Code Injection through malicious chart.yaml content | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.4 | 13/100 | 0.004 (29th pct) | 2 Sept 2026 |
| GHSA-q4h4-gmj2-qvw2 golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 13/100 | 0.005 (39th pct) | 2 Sept 2026 |
| GHSA-w879-237q-wc7r golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 13/100 | 0.005 (38th pct) | 2 Sept 2026 |
| GHSA-8xwf-rjm4-xvhv oras-go has file store write outside workingDir via symlink traversal | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 12/100 | 0.005 (41th pct) | 2 Sept 2026 |
| GHSA-qw64-3x98-g7q2 go-billy has path traversal vulnerabilities | github.com/go-git/go-billy/v5@v5.6.2golang | 5.9.0 | 12/100 | 0.003 (23th pct) | 2 Sept 2026 |
| GHSA-jxpm-75mh-9fp7 oras-go blob upload vulnerable to credential forwarding via unvalidated Location header | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 12/100 | 0.004 (31th pct) | 2 Sept 2026 |
| GHSA-fxhp-mv3v-67qp `oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution | oras.land/oras-go/v2@v2.6.0golang | 2.6.2 | 12/100 | 0.004 (36th pct) | 2 Sept 2026 |
| GHSA-v53g-5gjp-272r Helm dependency management path traversal | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.14.1 | 11/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GHSA-hc8v-wwc9-vgxm go-git: Worktree operations may follow symlinks | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.2 | 11/100 | 0.004 (29th pct) | 2 Sept 2026 |
| GO-2026-4341 Memory exhaustion in query parameter parsing in net/url | stdlib@go1.24.11golang | 1.24.12 | 11/100 | 0.020 (79th pct) | 2 Sept 2026 |
| GHSA-5xqw-8hwv-wg92 Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.3 | 11/100 | 0.005 (38th pct) | 2 Sept 2026 |
| GHSA-53c4-hhmh-vw5q Helm vulnerable to denial of service through through repository index file | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 11/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GHSA-67fx-wx78-jx33 Helm vulnerable to denial of service through schema file | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 11/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GHSA-4hfp-h4cw-hj8p Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.17.3 | 11/100 | 0.004 (36th pct) | 2 Sept 2026 |
| GHSA-6rx9-889q-vv2r Helm vulnerable to denial of service through string value parsing | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.10.3 | 10/100 | 0.008 (52th pct) | 2 Sept 2026 |
| GHSA-xhf5-7wjv-pqxp containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull | github.com/containerd/containerd@v1.7.29golang | 1.7.33 | 10/100 | 0.002 (6th pct) | 2 Sept 2026 |
| GHSA-m3xc-h892-ggx6 go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion | github.com/go-git/go-billy/v5@v5.6.2golang | 5.9.0 | 10/100 | 0.004 (32th pct) | 2 Sept 2026 |
| GHSA-qgq7-7hm3-q39j go-git: Malicious reference names may modify files outside the reference storage | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.2 | 10/100 | 0.004 (34th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2025-69720 | ncurses@6.5+20250216-2build1deb | 6.5+20250216-2ubuntu0.1 | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-10536 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.5 | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-11856 | curl@8.14.1-2ubuntu1.3deb | no fix listed | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-5450 | glibc@2.42-0ubuntu3.1deb | no fix listed | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8376 | perl@5.40.1-6build1deb | 5.40.1-6ubuntu0.1 | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8925 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 10/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-9079 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 10/100 | — | 2 Sept 2026 |
| GHSA-45gg-vh54-h5m9 golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 10/100 | 0.004 (30th pct) | 2 Sept 2026 |
| GHSA-9h84-qmv7-982p Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.18.5 | 10/100 | 0.003 (26th pct) | 2 Sept 2026 |
| GHSA-f9f8-9pmf-xv68 Helm May Panic Due To Incorrect YAML Content | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.18.5 | 10/100 | 0.003 (26th pct) | 2 Sept 2026 |
| GHSA-5cv4-jp36-h3mw Go Net HTML parser is vulnerable to denial of service | golang.org/x/net@v0.47.0golang | 0.55.0 | 10/100 | 0.003 (25th pct) | 2 Sept 2026 |
| GHSA-jpcc-p29g-p8mq containerd image-triggered runtime DoS via unbounded group parsing | github.com/containerd/containerd@v1.7.29golang | 1.7.33 | 10/100 | 0.003 (18th pct) | 2 Sept 2026 |
| GHSA-j5w8-q4qc-rx2x golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption | golang.org/x/crypto@v0.36.0golang | 0.45.0 | 9/100 | 0.006 (44th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-4739 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 9/100 | — | 2 Sept 2026 |
| GHSA-fqw6-gf59-qr4w containerd user ID handling bypass allows runAsNonRoot evasion | github.com/containerd/containerd@v1.7.29golang | 1.7.32 | 9/100 | 0.002 (6th pct) | 2 Sept 2026 |
| GHSA-qpw4-5x99-6vjp golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 9/100 | 0.003 (20th pct) | 2 Sept 2026 |
| GHSA-f6x5-jh6r-wrfv golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read | golang.org/x/crypto@v0.36.0golang | 0.45.0 | 9/100 | 0.005 (41th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-12087 | perl@5.40.1-6build1deb | no fix listed | 9/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-42496 | perl@5.40.1-6build1deb | 5.40.1-6ubuntu0.1 | 9/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8924 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 9/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8926 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 9/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8927 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 9/100 | — | 2 Sept 2026 |
| GHSA-78mq-xcr3-xm33 golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 9/100 | 0.005 (41th pct) | 2 Sept 2026 |
| GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | google.golang.org/grpc@v1.72.1golang | 1.82.1 | 9/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2024-52005 | git@1:2.51.0-1ubuntu1deb | no fix listed | 9/100 | — | 2 Sept 2026 |
| GHSA-vp52-pcj8-j9qc gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | google.golang.org/grpc@v1.72.1golang | 1.83.1 | 9/100 | — | 2 Sept 2026 |
| GHSA-9m57-25v3-79x9 golang.org/x/crypto: Invoking pathological inputs can lead to client panic | golang.org/x/crypto@v0.36.0golang | 0.52.0 | 8/100 | 0.004 (34th pct) | 2 Sept 2026 |
| GHSA-gxhx-2686-5h9g slack-go `SecretsVerifier` accepts empty signing secret without precondition | github.com/slack-go/slack@v0.16.0golang | 0.23.1 | 8/100 | — | 2 Sept 2026 |
| GHSA-389r-gv7p-r3rp go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.0 | 8/100 | 0.002 (5th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-55200 | libssh2@1.11.1-1ubuntu0.25.10.1deb | 1.11.1-1ubuntu0.25.10.2 | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8286 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 8/100 | — | 2 Sept 2026 |
| GO-2026-4981 Crash when handling long CNAME response in net | stdlib@go1.24.11golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GO-2026-4977 Quadratic string concatenation in consumePhrase in net/mail | stdlib@go1.24.11golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GO-2026-4986 Quadratic string concatentation in consumeComment in net/mail | stdlib@go1.24.11golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | stdlib@go1.24.11golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | golang.org/x/net@v0.47.0golang | 0.53.0 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2025-3563 Request smuggling due to acceptance of invalid chunked data in net/http | stdlib@go1.24.0golang | 1.23.8 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2023-1547 Information disclosure in helm.sh/helm/v3 | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.11.1 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-4337 Unexpected session resumption in crypto/tls | stdlib@go1.24.11golang | 1.24.13 | 8/100 | 0.008 (52th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-11822 | sqlite3@3.46.1-8deb | 3.46.1-8ubuntu0.1 | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-11824 | sqlite3@3.46.1-8deb | 3.46.1-8ubuntu0.1 | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35368 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 8/100 | — | 2 Sept 2026 |
| GHSA-crhj-59gh-8x96 go-git: Crafted repositories may modify main and submodule .git directories | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.1 | 8/100 | 0.003 (22th pct) | 2 Sept 2026 |
| GO-2026-4601 Incorrect parsing of IPv6 host literals in net/url | stdlib@go1.24.11golang | 1.25.8 | 8/100 | 0.007 (51th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-60002 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 8/100 | — | 2 Sept 2026 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | stdlib@go1.24.11golang | 1.25.13 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | golang.org/x/net@v0.47.0golang | 0.55.0 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 |
| GO-2026-4342 Excessive CPU consumption when building archive index in archive/zip | stdlib@go1.24.11golang | 1.24.12 | 8/100 | 0.007 (49th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-12064 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.5 | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-4046 | glibc@2.42-0ubuntu3.1deb | no fix listed | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-41992 | gzip@1.13-1ubuntu4deb | no fix listed | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-42497 | perl@5.40.1-6build1deb | no fix listed | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-4437 | glibc@2.42-0ubuntu3.1deb | no fix listed | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-48959 | perl@5.40.1-6build1deb | no fix listed | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-5928 | glibc@2.42-0ubuntu3.1deb | no fix listed | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8932 | curl@8.14.1-2ubuntu1.3deb | no fix listed | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-9538 | perl@5.40.1-6build1deb | no fix listed | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-9545 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 8/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-9547 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 7/100 | — | 2 Sept 2026 |
| GO-2025-4116 Potential denial of service in golang.org/x/crypto/ssh/agent | golang.org/x/crypto@v0.36.0golang | 0.43.0 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GO-2026-4870 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls | stdlib@go1.24.11golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GO-2025-4009 Quadratic complexity when parsing some invalid inputs in encoding/pem | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GO-2026-4947 Unexpected work during chain building in crypto/x509 | stdlib@go1.24.11golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-35338 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-48961 | perl@5.40.1-6build1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-48962 | perl@5.40.1-6build1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-5435 | glibc@2.42-0ubuntu3.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-9080 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 7/100 | — | 2 Sept 2026 |
| GO-2026-4599 Incorrect enforcement of email constraints in crypto/x509 | stdlib@go1.26.0golang | 1.26.1 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 |
| GO-2025-3751 Sensitive headers not cleared on cross-origin redirect in net/http | stdlib@go1.24.0golang | 1.23.10 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 |
| GO-2025-4006 Excessive CPU consumption in ParseAddress in net/mail | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 |
| GO-2026-5037 Inefficient candidate hostname parsing in crypto/x509 | stdlib@go1.24.11golang | 1.25.11 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 |
| GO-2026-4971 Panic in Dial and LookupPort when handling NUL byte on Windows in net | stdlib@go1.24.11golang | 1.25.10 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-5972 Enforce maximum recursion depth in encoding/asn1 | stdlib@go1.24.11golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-6088 Add recursion depth guard during decode in encoding/xml | stdlib@go1.24.11golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-6089 Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http | stdlib@go1.24.11golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-6090 Limit handshake messages we are willing to accept post-handshake in crypto/tls | stdlib@go1.24.11golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-5038 Quadratic complexity in WordDecoder.DecodeHeader in mime | stdlib@go1.24.11golang | 1.25.11 | 7/100 | 0.006 (44th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-35341 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-54369 | acl@2.3.2-2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-54371 | attr@1:2.5.2-3build1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-7017 | perl@5.40.1-6build1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | golang.org/x/net@v0.47.0golang | 0.56.0 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | stdlib@go1.26.0golang | 1.26.6 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 |
| GO-2025-3521 Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes | k8s.io/kubernetes@v1.34.2golang | no fix listed | 7/100 | 0.005 (43th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-35352 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-58050 | libssh2@1.11.1-1ubuntu0.25.10.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| GO-2025-4012 Lack of limit when parsing cookies can cause memory exhaustion in net/http | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GO-2025-3956 Unexpected paths returned from LookPath in os/exec | stdlib@go1.24.0golang | 1.23.12 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GO-2025-4011 Parsing DER payload can cause memory exhaustion in encoding/asn1 | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GO-2025-4015 Excessive CPU consumption in Reader.ReadResponse in net/textproto | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GO-2026-6218 Avoid quadratic complexity in resolvePath in net/url | stdlib@go1.24.11golang | 1.25.13 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GHSA-vh4v-2xq2-g5cg ORAS Go forwards registry credentials across registry redirects | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56132 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56403 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56404 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56405 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56406 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56407 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56408 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56410 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56411 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| GO-2026-4440 Quadratic parsing complexity in golang.org/x/net/html | golang.org/x/net@v0.38.0golang | 0.45.0 | 7/100 | 0.005 (41th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-13595 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| GO-2026-4441 Infinite parsing loop in golang.org/x/net | golang.org/x/net@v0.38.0golang | 0.45.0 | 7/100 | 0.005 (40th pct) | 2 Sept 2026 |
| GO-2026-5970 Infinite loop on invalid input in golang.org/x/text | golang.org/x/text@v0.28.0golang | 0.39.0 | 7/100 | 0.005 (39th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-35349 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| GO-2025-4155 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 | stdlib@go1.25.3golang | 1.24.11 | 7/100 | 0.005 (38th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-35350 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35365 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| GO-2025-4008 ALPN negotiation error contains attacker controlled information in crypto/tls | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.004 (36th pct) | 2 Sept 2026 |
| GO-2025-4010 Insufficient validation of bracketed IPv6 hostnames in net/url | stdlib@go1.24.0golang | 1.24.8 | 7/100 | 0.004 (36th pct) | 2 Sept 2026 |
| GHSA-w5pp-99ch-qj29 go-git: Malformed Git object data may cause panics or resource exhaustion | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.1 | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2016-2781 | coreutils@9.5-1ubuntu4.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2016-2781 | coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu24deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2025-15661 | libssh2@1.11.1-1ubuntu0.25.10.1deb | 1.11.1-1ubuntu0.25.10.2 | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56409 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-58051 | libssh2@1.11.1-1ubuntu0.25.10.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-60001 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-6238 | glibc@2.42-0ubuntu3.1deb | no fix listed | 7/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-8458 | curl@8.14.1-2ubuntu1.3deb | 8.14.1-2ubuntu1.4 | 7/100 | — | 2 Sept 2026 |
| GHSA-3xc5-wrhm-f963 go-git: Credential leak via cross-host redirect in smart HTTP transport | github.com/go-git/go-git/v5@v5.14.0golang | 5.18.0 | 6/100 | 0.003 (17th pct) | 2 Sept 2026 |
| GO-2025-4014 Unbounded allocation when parsing GNU sparse map in archive/tar | stdlib@go1.24.0golang | 1.24.8 | 6/100 | 0.004 (34th pct) | 2 Sept 2026 |
| GO-2025-3503 HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net | stdlib@go1.24.0golang | 1.23.7 | 6/100 | 0.004 (33th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-35355 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35356 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35360 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35364 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35374 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-54370 | acl@2.3.2-2deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| GO-2026-4976 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil | stdlib@go1.24.11golang | 1.25.10 | 6/100 | 0.004 (32th pct) | 2 Sept 2026 |
| GO-2026-5856 Invoking Encrypted Client Hello privacy leak in crypto/tls | stdlib@go1.24.11golang | 1.25.12 | 6/100 | 0.004 (31th pct) | 2 Sept 2026 |
| GO-2025-4007 Quadratic complexity when checking name constraints in crypto/x509 | stdlib@go1.24.0golang | 1.24.9 | 6/100 | 0.004 (31th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-13757 | p11-kit@0.25.5-3ubuntu1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| GO-2026-4980 Escaper bypass leads to XSS in html/template | stdlib@go1.24.11golang | 1.25.10 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 |
| GO-2026-5039 Arbitrary inputs are included in errors without any escaping in net/textproto | stdlib@go1.24.11golang | 1.25.11 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 |
| GO-2025-4013 Panic when validating certificates with DSA public keys in crypto/x509 | stdlib@go1.24.0golang | 1.24.8 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 |
| GO-2025-3849 Incorrect results returned from Rows.Scan in database/sql | stdlib@go1.24.0golang | 1.23.12 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 |
| GO-2026-4946 Inefficient policy validation in crypto/x509 | stdlib@go1.24.11golang | 1.25.9 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-50813 | sqlite3@3.46.1-8deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| GO-2026-4600 Panic in name constraint checking for malformed certificates in crypto/x509 | stdlib@go1.26.0golang | 1.26.1 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 |
| GO-2026-5064 containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd | github.com/containerd/containerd@v1.7.29golang | no fix listed | 6/100 | 0.003 (27th pct) | 2 Sept 2026 |
| GHSA-hr2v-4r36-88hr Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment | helm.sh/helm/v3@v0.0.0-20251211174049-7cfb6e486dacgolang | 3.20.2 | 6/100 | 0.002 (10th pct) | 2 Sept 2026 |
| GO-2026-4866 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 | stdlib@go1.26.0golang | 1.26.2 | 6/100 | 0.003 (27th pct) | 2 Sept 2026 |
| GO-2025-3749 Usage of ExtKeyUsageAny disables policy validation in crypto/x509 | stdlib@go1.24.0golang | 1.24.4 | 6/100 | 0.003 (27th pct) | 2 Sept 2026 |
| GO-2026-5158 Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel | go.opentelemetry.io/otel@v1.43.0golang | 1.42.0 | 6/100 | 0.003 (26th pct) | 2 Sept 2026 |
| GO-2026-4603 URLs in meta content attribute actions are not escaped in html/template | stdlib@go1.24.11golang | 1.25.8 | 6/100 | 0.003 (25th pct) | 2 Sept 2026 |
| GO-2026-6303 Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | golang.org/x/crypto@v0.36.0golang | 0.55.0 | 6/100 | 0.003 (25th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2024-2236 | libgcrypt20@1.11.0-7ubuntu0.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-40355 | krb5@1.21.3-5ubuntu2deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-40356 | krb5@1.21.3-5ubuntu2deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-54411 | pam@1.7.0-5ubuntu2deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-55199 | libssh2@1.11.1-1ubuntu0.25.10.1deb | 1.11.1-1ubuntu0.25.10.2 | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-59999 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| GO-2025-3547 Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes | k8s.io/kubernetes@v1.34.2golang | no fix listed | 6/100 | 0.003 (24th pct) | 2 Sept 2026 |
| GO-2026-4982 Bypass of meta content URL escaping causes XSS in html/template | stdlib@go1.24.11golang | 1.25.10 | 6/100 | 0.003 (24th pct) | 2 Sept 2026 |
| GO-2026-6091 Fix Javascript regexp context tracking in html/template | stdlib@go1.24.11golang | 1.25.13 | 6/100 | 0.003 (23th pct) | 2 Sept 2026 |
| GO-2026-5338 containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd | github.com/containerd/containerd@v1.7.29golang | no fix listed | 6/100 | 0.003 (22th pct) | 2 Sept 2026 |
| GO-2026-4864 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix | stdlib@go1.24.11golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 |
| GO-2026-4865 JsBraceDepth Context Tracking Bugs (XSS) in html/template | stdlib@go1.24.11golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 |
| GO-2026-4869 Unbounded allocation for old GNU sparse in archive/tar | stdlib@go1.24.11golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 |
| GHSA-jhf3-xxhw-2wpp go-git: Maliciously crafted idx file can cause asymmetric memory consumption | github.com/go-git/go-git/v5@v5.14.0golang | 5.17.1 | 6/100 | 0.001 (4th pct) | 2 Sept 2026 |
| GO-2026-4340 Handshake messages may be processed at the incorrect encryption level in crypto/tls | stdlib@go1.24.11golang | 1.24.12 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 |
| GO-2025-4175 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 | stdlib@go1.25.3golang | 1.24.11 | 6/100 | 0.003 (20th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-35363 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| GO-2025-3750 Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscall | stdlib@go1.24.0golang | 1.23.10 | 6/100 | 0.003 (18th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2025-15649 | perl@5.40.1-6build1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35339 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35340 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35348 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35369 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35380 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-50812 | sqlite3@3.46.1-8deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-53612 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-53613 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-53614 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-53615 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 6/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-4438 | glibc@2.42-0ubuntu3.1deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-58055 | nghttp2@1.64.0-1.1ubuntu1.1deb | 1.64.0-1.1ubuntu1.2 | 5/100 | — | 2 Sept 2026 |
| GO-2026-4403 Improper access to parent directory of root in os | stdlib@go1.24.0golang | 1.23.9 | 5/100 | 0.002 (15th pct) | 2 Sept 2026 |
| GO-2026-5025 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | golang.org/x/net@v0.47.0golang | 0.55.0 | 5/100 | 0.002 (14th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-35345 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| GO-2026-4970 Root escape via symlink plus trailing slash in os | stdlib@go1.24.11golang | 1.25.12 | 5/100 | 0.002 (14th pct) | 2 Sept 2026 |
| GO-2026-5027 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | golang.org/x/net@v0.47.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 |
| GO-2026-5029 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | golang.org/x/net@v0.47.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 |
| GO-2026-5030 Invoking duplicate attributes can cause XSS in golang.org/x/net/html | golang.org/x/net@v0.47.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 |
| GO-2026-4602 FileInfo can escape from a Root in os | stdlib@go1.24.11golang | 1.25.8 | 5/100 | 0.002 (10th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-11850 | krb5@1.21.3-5ubuntu2deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35372 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-55655 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-5704 | tar@1.35+dfsg-3.1build1deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-50219 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56131 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-56412 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| GO-2026-5622 Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd | github.com/containerd/containerd@v1.7.29golang | no fix listed | 5/100 | 0.002 (7th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-42250 | bzip2@1.0.8-6build1deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-59998 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| GHSA-37cx-329c-33x3 go-git improperly verifies data integrity values for .idx and .pack files | github.com/go-git/go-git/v5@v5.14.0golang | 5.16.5 | 5/100 | 0.001 (3th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-27456 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35354 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35357 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35359 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-41991 | gzip@1.13-1ubuntu4deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35376 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 5/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2025-5278 | coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu24deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2025-5278 | coreutils@9.5-1ubuntu4.1deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35347 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35358 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35366 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35370 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35351 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-59995 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-59996 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-59997 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| GO-2026-5024 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | golang.org/x/sys@v0.42.0golang | 0.44.0 | 4/100 | 0.001 (2th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2025-45582 | tar@1.35+dfsg-3.1build1deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| GO-2026-5410 SecretsVerifier accepts empty signing secret without precondition in github.com/slack-go/slack | github.com/slack-go/slack@v0.16.0golang | 0.23.1 | 4/100 | — | 2 Sept 2026 |
| GO-2026-5693 Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.1 | 4/100 | — | 2 Sept 2026 |
| GO-2026-5841 OOB read in github.com/klauspost/compress/s2 | github.com/klauspost/compress@v1.18.0golang | 1.18.7 | 4/100 | — | 2 Sept 2026 |
| GO-2026-5884 ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 4/100 | — | 2 Sept 2026 |
| GO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | golang.org/x/crypto@v0.36.0golang | no fix listed | 4/100 | — | 2 Sept 2026 |
| GO-2026-6061 Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc | google.golang.org/grpc@v1.72.1golang | 1.82.1 | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-32776 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-32777 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| USN-8467-2 perl vulnerabilities | perl@5.40.1-6build1deb | 5.40.1-6ubuntu0.1 | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-3184 | util-linux@2.41-4ubuntu4.2deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-55654 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-60000 | openssh@1:10.0p1-5ubuntu5.4deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2024-56433 | shadow@1:4.17.4-2ubuntu2deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35362 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 4/100 | — | 2 Sept 2026 |
| GHSA-m7cr-m3pv-hgrp go-git: Improper single-quote escaping in go-git SSH transport | github.com/go-git/go-git/v5@v5.14.0golang | 5.19.1 | 4/100 | 0.004 (29th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2026-35361 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2022-3219 | gnupg2@2.4.8-2ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2025-6141 | ncurses@6.5+20250216-2build1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35342 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35343 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35344 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35346 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35353 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35367 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35371 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35373 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35375 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35377 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35378 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35379 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-35381 | rust-coreutils@0.2.2-0ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| GHSA-gm2x-2g9h-ccm8 go-git missing validation decoding Index v4 files leads to panic | github.com/go-git/go-git/v5@v5.14.0golang | 5.17.1 | 3/100 | 0.002 (5th pct) | 2 Sept 2026 |
| UBUNTU-CVE-2025-66382 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-27171 | zlib@1:1.3.dfsg+really1.3.1-1ubuntu2deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-32778 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-40228 | systemd@257.9-0ubuntu2.5deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-41080 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-45186 | expat@2.7.1-2ubuntu0.2deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| UBUNTU-CVE-2026-57062 | gnupg2@2.4.8-2ubuntu2.1deb | no fix listed | 3/100 | — | 2 Sept 2026 |
| GHSA-xf85-363p-868w oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens | oras.land/oras-go/v2@v2.6.0golang | 2.6.1 | 3/100 | 0.003 (17th pct) | 2 Sept 2026 |
Tags and digests
Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.
| Tag | Digest | Platform | First seen | Last seen | Radar Score |
|---|---|---|---|---|---|
| v3.4.4current | 2fb3efa9eaa4 | linux/amd64 | 2 Sept 2026 | 2 Sept 2026 | 2,003 |
Used by
Charts whose default render references this repository, with the workload that carries it.
No indexed chart deploys this repository in its latest version.
Also in older indexed versions (1)
Not counted above: the chart’s latest version no longer references it, or the chart is no longer in the top N.
- argo-cdargo
- Deployment/candidate-argocd-applicationset-controller/applicationset-controller:v3.4.4
- Deployment/candidate-argocd-notifications-controller/notifications-controller:v3.4.4
- Deployment/candidate-argocd-repo-server/copyutilinit:v3.4.4
- Deployment/candidate-argocd-repo-server/repo-server:v3.4.4
- Deployment/candidate-argocd-server/server:v3.4.4
- Deployment/candidate-argocd-dex-server/copyutilinit:v3.4.4
- StatefulSet/candidate-argocd-application-controller/application-controller:v3.4.4
- Job/candidate-argocd-redis-secret-init/secret-inithook: pre-install,pre-upgrade:v3.4.4