quay.io/prometheus/node-exporter:v1.11.0

container image

Deployed by 0 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.

Radar Score

459
worst finding Medium
Critical
0
High
0
Medium
5
Low
48
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

53 findings on digest 2f0cc335ef9e · scanned 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of quay.io/prometheus/node-exporter:v1.11.0 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.

2 Sept 2026 · Radar Score 459 · OSV as of 2 Sept 2026 · digest 2f0cc335ef9e
history since 2 Sept 2026

Findings

showing 50 of 53

Findings for digest 2f0cc335ef9e as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.

AdvisoryPackageFixed inContributionEPSSSince
GHSA-5cgq-3rg8-m6cv

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

golang.org/x/crypto@v0.49.0golang0.52.038/1000.073 (94th pct)2 Sept 2026
GHSA-x527-x647-q7gg

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

golang.org/x/crypto@v0.49.0golang0.52.017/1000.005 (41th pct)2 Sept 2026
GHSA-vgwf-h737-ff37

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

golang.org/x/crypto@v0.49.0golang0.52.017/1000.006 (47th pct)2 Sept 2026
GHSA-f5wc-c3c7-36mc

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

golang.org/x/crypto@v0.49.0golang0.52.017/1000.006 (46th pct)2 Sept 2026
GHSA-rm3j-f69w-wqmq

golang.org/x/crypto vulnerable to infinite loop on large channel writes

golang.org/x/crypto@v0.49.0golang0.52.016/1000.005 (42th pct)2 Sept 2026
GHSA-89gr-r52h-f8rx

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

golang.org/x/crypto@v0.49.0golang0.52.015/1000.004 (35th pct)2 Sept 2026
GHSA-jppx-rxg9-jmrx

golang.org/x/crypto doesn't enforce invoking key constraints

golang.org/x/crypto@v0.49.0golang0.52.015/1000.004 (34th pct)2 Sept 2026
GHSA-q4h4-gmj2-qvw2

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

golang.org/x/crypto@v0.49.0golang0.52.013/1000.005 (39th pct)2 Sept 2026
GHSA-w879-237q-wc7r

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

golang.org/x/crypto@v0.49.0golang0.52.013/1000.005 (38th pct)2 Sept 2026
GHSA-45gg-vh54-h5m9

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

golang.org/x/crypto@v0.49.0golang0.52.010/1000.004 (30th pct)2 Sept 2026
GHSA-5cv4-jp36-h3mw

Go Net HTML parser is vulnerable to denial of service

golang.org/x/net@v0.52.0golang0.55.010/1000.003 (25th pct)2 Sept 2026
GHSA-qpw4-5x99-6vjp

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

golang.org/x/crypto@v0.49.0golang0.52.09/1000.003 (20th pct)2 Sept 2026
GHSA-78mq-xcr3-xm33

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

golang.org/x/crypto@v0.49.0golang0.52.09/1000.005 (41th pct)2 Sept 2026
GHSA-9m57-25v3-79x9

golang.org/x/crypto: Invoking pathological inputs can lead to client panic

golang.org/x/crypto@v0.49.0golang0.52.08/1000.004 (34th pct)2 Sept 2026
GO-2026-4981

Crash when handling long CNAME response in net

stdlib@go1.26.1golang1.25.108/1000.008 (54th pct)2 Sept 2026
GO-2026-4977

Quadratic string concatenation in consumePhrase in net/mail

stdlib@go1.26.1golang1.25.108/1000.008 (54th pct)2 Sept 2026
GO-2026-4986

Quadratic string concatentation in consumeComment in net/mail

stdlib@go1.26.1golang1.25.108/1000.008 (53th pct)2 Sept 2026
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

stdlib@go1.26.1golang1.25.108/1000.008 (53th pct)2 Sept 2026
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

golang.org/x/net@v0.52.0golang0.53.08/1000.008 (53th pct)2 Sept 2026
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

golang.org/x/net@v0.52.0golang0.55.08/1000.007 (50th pct)2 Sept 2026
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

stdlib@go1.26.1golang1.25.138/1000.007 (50th pct)2 Sept 2026
GO-2026-4870

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

stdlib@go1.26.1golang1.25.97/1000.006 (47th pct)2 Sept 2026
GO-2026-4947

Unexpected work during chain building in crypto/x509

stdlib@go1.26.1golang1.25.97/1000.006 (47th pct)2 Sept 2026
GO-2026-5037

Inefficient candidate hostname parsing in crypto/x509

stdlib@go1.26.1golang1.25.117/1000.006 (46th pct)2 Sept 2026
GO-2026-4971

Panic in Dial and LookupPort when handling NUL byte on Windows in net

stdlib@go1.26.1golang1.25.107/1000.006 (45th pct)2 Sept 2026
GO-2026-5972

Enforce maximum recursion depth in encoding/asn1

stdlib@go1.26.1golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-6088

Add recursion depth guard during decode in encoding/xml

stdlib@go1.26.1golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-6089

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

stdlib@go1.26.1golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-6090

Limit handshake messages we are willing to accept post-handshake in crypto/tls

stdlib@go1.26.1golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-5038

Quadratic complexity in WordDecoder.DecodeHeader in mime

stdlib@go1.26.1golang1.25.117/1000.006 (44th pct)2 Sept 2026
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

golang.org/x/net@v0.52.0golang0.56.07/1000.005 (44th pct)2 Sept 2026
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

stdlib@go1.26.1golang1.26.67/1000.005 (44th pct)2 Sept 2026
GO-2026-6218

Avoid quadratic complexity in resolvePath in net/url

stdlib@go1.26.1golang1.25.137/1000.005 (42th pct)2 Sept 2026
GO-2026-5970

Infinite loop on invalid input in golang.org/x/text

golang.org/x/text@v0.35.0golang0.39.07/1000.005 (39th pct)2 Sept 2026
GO-2026-4976

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

stdlib@go1.26.1golang1.25.106/1000.004 (32th pct)2 Sept 2026
GO-2026-5856

Invoking Encrypted Client Hello privacy leak in crypto/tls

stdlib@go1.26.1golang1.25.126/1000.004 (31th pct)2 Sept 2026
GO-2026-4980

Escaper bypass leads to XSS in html/template

stdlib@go1.26.1golang1.25.106/1000.004 (30th pct)2 Sept 2026
GO-2026-5039

Arbitrary inputs are included in errors without any escaping in net/textproto

stdlib@go1.26.1golang1.25.116/1000.004 (30th pct)2 Sept 2026
GO-2026-4946

Inefficient policy validation in crypto/x509

stdlib@go1.26.1golang1.25.96/1000.004 (28th pct)2 Sept 2026
GO-2026-4866

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

stdlib@go1.26.1golang1.26.26/1000.003 (27th pct)2 Sept 2026
GO-2026-6303

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

golang.org/x/crypto@v0.49.0golang0.55.06/1000.003 (25th pct)2 Sept 2026
GO-2026-4982

Bypass of meta content URL escaping causes XSS in html/template

stdlib@go1.26.1golang1.25.106/1000.003 (24th pct)2 Sept 2026
GO-2026-6091

Fix Javascript regexp context tracking in html/template

stdlib@go1.26.1golang1.25.136/1000.003 (23th pct)2 Sept 2026
GO-2026-4864

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

stdlib@go1.26.1golang1.25.96/1000.003 (21th pct)2 Sept 2026
GO-2026-4865

JsBraceDepth Context Tracking Bugs (XSS) in html/template

stdlib@go1.26.1golang1.25.96/1000.003 (21th pct)2 Sept 2026
GO-2026-4869

Unbounded allocation for old GNU sparse in archive/tar

stdlib@go1.26.1golang1.25.96/1000.003 (21th pct)2 Sept 2026
GO-2026-5025

Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

golang.org/x/net@v0.52.0golang0.55.05/1000.002 (14th pct)2 Sept 2026
GO-2026-4970

Root escape via symlink plus trailing slash in os

stdlib@go1.26.1golang1.25.125/1000.002 (14th pct)2 Sept 2026
GO-2026-5027

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

golang.org/x/net@v0.52.0golang0.55.05/1000.002 (13th pct)2 Sept 2026
GO-2026-5029

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

golang.org/x/net@v0.52.0golang0.55.05/1000.002 (13th pct)2 Sept 2026

All 53 findings

Tags and digests

Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.

TagDigestPlatformFirst seenLast seenRadar Score
v1.11.0current2f0cc335ef9elinux/amd642 Sept 20262 Sept 2026459

Used by

Charts whose default render references this repository, with the workload that carries it.

No indexed chart deploys this repository in its latest version.

Also in older indexed versions (1)

Not counted above: the chart’s latest version no longer references it, or the chart is no longer in the top N.

syft 1.42.1 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.