quay.io/prometheus-operator/prometheus-config-reloader:v0.90.1
container imageDeployed by 0 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 6
- Low
- 49
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
55 findings on digest 693faa0b8724 · scanned 2 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of quay.io/prometheus-operator/prometheus-config-reloader:v0.90.1 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.
Findings
55 distinct on the current digest
Findings for digest 693faa0b8724 as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.
| Advisory | Package | Fixed in | Contribution | EPSS | Since |
|---|---|---|---|---|---|
| GHSA-5cgq-3rg8-m6cv golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 38/100 | 0.073 (94th pct) | 2 Sept 2026 |
| GHSA-x527-x647-q7gg golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 17/100 | 0.005 (41th pct) | 2 Sept 2026 |
| GHSA-vgwf-h737-ff37 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 17/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GHSA-f5wc-c3c7-36mc golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 17/100 | 0.006 (46th pct) | 2 Sept 2026 |
| GHSA-rm3j-f69w-wqmq golang.org/x/crypto vulnerable to infinite loop on large channel writes | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 16/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GHSA-8rm2-7qqf-34qm Prometheus: Remote read endpoint allows denial of service via crafted snappy payload | github.com/prometheus/prometheus@v0.310.0golang | 0.311.3 | 15/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GHSA-89gr-r52h-f8rx golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 15/100 | 0.004 (35th pct) | 2 Sept 2026 |
| GHSA-jppx-rxg9-jmrx golang.org/x/crypto doesn't enforce invoking key constraints | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 15/100 | 0.004 (34th pct) | 2 Sept 2026 |
| GHSA-q4h4-gmj2-qvw2 golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 13/100 | 0.005 (39th pct) | 2 Sept 2026 |
| GHSA-w879-237q-wc7r golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 13/100 | 0.005 (38th pct) | 2 Sept 2026 |
| GHSA-wg65-39gg-5wfj Prometheus Azure AD remote write OAuth client secret exposed via config API | github.com/prometheus/prometheus@v0.310.0golang | 0.311.3 | 11/100 | 0.004 (28th pct) | 2 Sept 2026 |
| GHSA-45gg-vh54-h5m9 golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 10/100 | 0.004 (30th pct) | 2 Sept 2026 |
| GHSA-5cv4-jp36-h3mw Go Net HTML parser is vulnerable to denial of service | golang.org/x/net@v0.52.0golang | 0.55.0 | 10/100 | 0.003 (25th pct) | 2 Sept 2026 |
| GHSA-qpw4-5x99-6vjp golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 9/100 | 0.003 (20th pct) | 2 Sept 2026 |
| GHSA-78mq-xcr3-xm33 golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 9/100 | 0.005 (41th pct) | 2 Sept 2026 |
| GHSA-9m57-25v3-79x9 golang.org/x/crypto: Invoking pathological inputs can lead to client panic | golang.org/x/crypto@v0.49.0golang | 0.52.0 | 8/100 | 0.004 (34th pct) | 2 Sept 2026 |
| GHSA-vffh-x6r8-xx99 Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer | github.com/prometheus/prometheus@v0.310.0golang | 0.311.2-0.20260410083055-07c6232d159b | 8/100 | 0.003 (17th pct) | 2 Sept 2026 |
| GO-2026-4981 Crash when handling long CNAME response in net | stdlib@go1.25.8golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GO-2026-4977 Quadratic string concatenation in consumePhrase in net/mail | stdlib@go1.25.8golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GO-2026-4986 Quadratic string concatentation in consumeComment in net/mail | stdlib@go1.25.8golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | stdlib@go1.25.8golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | golang.org/x/net@v0.52.0golang | 0.53.0 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GHSA-fw8g-cg8f-9j28 Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display | github.com/prometheus/prometheus@v0.310.0golang | 0.311.3 | 8/100 | 0.002 (10th pct) | 2 Sept 2026 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | golang.org/x/net@v0.52.0golang | 0.55.0 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | stdlib@go1.25.8golang | 1.25.13 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 |
| GO-2026-4870 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls | stdlib@go1.25.8golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GO-2026-4947 Unexpected work during chain building in crypto/x509 | stdlib@go1.25.8golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GO-2026-5037 Inefficient candidate hostname parsing in crypto/x509 | stdlib@go1.25.8golang | 1.25.11 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 |
| GO-2026-4971 Panic in Dial and LookupPort when handling NUL byte on Windows in net | stdlib@go1.25.8golang | 1.25.10 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-5972 Enforce maximum recursion depth in encoding/asn1 | stdlib@go1.25.8golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-6088 Add recursion depth guard during decode in encoding/xml | stdlib@go1.25.8golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-6089 Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http | stdlib@go1.25.8golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-6090 Limit handshake messages we are willing to accept post-handshake in crypto/tls | stdlib@go1.25.8golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 |
| GO-2026-5038 Quadratic complexity in WordDecoder.DecodeHeader in mime | stdlib@go1.25.8golang | 1.25.11 | 7/100 | 0.006 (44th pct) | 2 Sept 2026 |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | golang.org/x/net@v0.52.0golang | 0.56.0 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 |
| GO-2026-6218 Avoid quadratic complexity in resolvePath in net/url | stdlib@go1.25.8golang | 1.25.13 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GO-2026-5970 Infinite loop on invalid input in golang.org/x/text | golang.org/x/text@v0.35.0golang | 0.39.0 | 7/100 | 0.005 (39th pct) | 2 Sept 2026 |
| GO-2026-4976 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil | stdlib@go1.25.8golang | 1.25.10 | 6/100 | 0.004 (32th pct) | 2 Sept 2026 |
| GO-2026-5856 Invoking Encrypted Client Hello privacy leak in crypto/tls | stdlib@go1.25.8golang | 1.25.12 | 6/100 | 0.004 (31th pct) | 2 Sept 2026 |
| GO-2026-4980 Escaper bypass leads to XSS in html/template | stdlib@go1.25.8golang | 1.25.10 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 |
| GO-2026-5039 Arbitrary inputs are included in errors without any escaping in net/textproto | stdlib@go1.25.8golang | 1.25.11 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 |
| GO-2026-4946 Inefficient policy validation in crypto/x509 | stdlib@go1.25.8golang | 1.25.9 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 |
| GO-2026-6303 Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | golang.org/x/crypto@v0.49.0golang | 0.55.0 | 6/100 | 0.003 (25th pct) | 2 Sept 2026 |
| GO-2026-4982 Bypass of meta content URL escaping causes XSS in html/template | stdlib@go1.25.8golang | 1.25.10 | 6/100 | 0.003 (24th pct) | 2 Sept 2026 |
| GO-2026-6091 Fix Javascript regexp context tracking in html/template | stdlib@go1.25.8golang | 1.25.13 | 6/100 | 0.003 (23th pct) | 2 Sept 2026 |
| GO-2026-4864 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix | stdlib@go1.25.8golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 |
| GO-2026-4865 JsBraceDepth Context Tracking Bugs (XSS) in html/template | stdlib@go1.25.8golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 |
| GO-2026-4869 Unbounded allocation for old GNU sparse in archive/tar | stdlib@go1.25.8golang | 1.25.9 | 6/100 | 0.003 (21th pct) | 2 Sept 2026 |
| GO-2026-5025 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | golang.org/x/net@v0.52.0golang | 0.55.0 | 5/100 | 0.002 (14th pct) | 2 Sept 2026 |
| GO-2026-4970 Root escape via symlink plus trailing slash in os | stdlib@go1.25.8golang | 1.25.12 | 5/100 | 0.002 (14th pct) | 2 Sept 2026 |
| GO-2026-5027 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | golang.org/x/net@v0.52.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 |
| GO-2026-5029 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | golang.org/x/net@v0.52.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 |
| GO-2026-5030 Invoking duplicate attributes can cause XSS in golang.org/x/net/html | golang.org/x/net@v0.52.0golang | 0.55.0 | 5/100 | 0.002 (13th pct) | 2 Sept 2026 |
| GO-2026-5024 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | golang.org/x/sys@v0.42.0golang | 0.44.0 | 4/100 | 0.001 (2th pct) | 2 Sept 2026 |
| GO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | golang.org/x/crypto@v0.49.0golang | no fix listed | 4/100 | — | 2 Sept 2026 |
Tags and digests
Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.
| Tag | Digest | Platform | First seen | Last seen | Radar Score |
|---|---|---|---|---|---|
| v0.90.1current | 693faa0b8724 | linux/amd64 | 2 Sept 2026 | 2 Sept 2026 | 488 |
Used by
Charts whose default render references this repository, with the workload that carries it.
No indexed chart deploys this repository in its latest version.
Also in older indexed versions (1)
Not counted above: the chart’s latest version no longer references it, or the chart is no longer in the top N.
- prometheusprometheus-community