registry.k8s.io/ingress-nginx/controller

container image
on Kubernetes registry

Deployed by 1 of 300 indexed charts (latest versions).Counts say nothing about images outside the indexed set.

Radar Score

611
worst finding Low
Critical
0
High
0
Medium
0
Low
90
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

90 findings on digest 594ceea76b01 · scanned 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of registry.k8s.io/ingress-nginx/controller across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.

2 Sept 2026 · Radar Score 611 · OSV as of 2 Sept 2026 · digest 594ceea76b01
history since 2 Sept 2026

Findings

90 distinct on the current digest

Findings for digest 594ceea76b01 as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.

AdvisoryPackageFixed inContributionEPSSSince
ALPINE-CVE-2026-31789openssl@3.5.5-r0apk3.5.6-r010/1002 Sept 2026
ALPINE-CVE-2026-63073openssl@3.5.5-r0apk3.5.8-r010/1002 Sept 2026
GHSA-5cv4-jp36-h3mw

Go Net HTML parser is vulnerable to denial of service

golang.org/x/net@v0.52.0golang0.55.010/1000.003 (25th pct)2 Sept 2026
ALPINE-CVE-2026-34182openssl@3.5.5-r0apk3.5.7-r09/1002 Sept 2026
ALPINE-CVE-2026-75803openssl@3.5.5-r0apk3.5.8-r09/1002 Sept 2026
ALPINE-CVE-2026-45447openssl@3.5.5-r0apk3.5.7-r09/1002 Sept 2026
ALPINE-CVE-2026-28387openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 2026
ALPINE-CVE-2026-40200musl@1.2.5-r21apk1.2.5-r238/1002 Sept 2026
ALPINE-CVE-2026-7383openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 2026
GO-2026-4981

Crash when handling long CNAME response in net

stdlib@go1.26.1golang1.25.108/1000.008 (54th pct)2 Sept 2026
GO-2026-4977

Quadratic string concatenation in consumePhrase in net/mail

stdlib@go1.26.1golang1.25.108/1000.008 (54th pct)2 Sept 2026
GO-2026-4986

Quadratic string concatentation in consumeComment in net/mail

stdlib@go1.26.1golang1.25.108/1000.008 (53th pct)2 Sept 2026
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

golang.org/x/net@v0.52.0golang0.53.08/1000.008 (53th pct)2 Sept 2026
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

stdlib@go1.26.1golang1.25.108/1000.008 (53th pct)2 Sept 2026
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

stdlib@go1.26.1golang1.25.138/1000.007 (50th pct)2 Sept 2026
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

golang.org/x/net@v0.52.0golang0.55.08/1000.007 (50th pct)2 Sept 2026
ALPINE-CVE-2026-14456openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 2026
ALPINE-CVE-2026-14457openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 2026
ALPINE-CVE-2026-18798openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 2026
ALPINE-CVE-2026-27135nghttp2@1.68.0-r0apk1.68.18/1002 Sept 2026
ALPINE-CVE-2026-28388openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 2026
ALPINE-CVE-2026-28389openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 2026
ALPINE-CVE-2026-28390openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 2026
ALPINE-CVE-2026-31790openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 2026
ALPINE-CVE-2026-34180openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 2026
ALPINE-CVE-2026-34183openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 2026
ALPINE-CVE-2026-3805curl@8.17.0-r1apk8.19.0-r08/1002 Sept 2026
ALPINE-CVE-2026-42764openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 2026
ALPINE-CVE-2026-45445openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 2026
ALPINE-CVE-2026-54874openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 2026
ALPINE-CVE-2026-5773curl@8.17.0-r1apk8.20.0-r08/1002 Sept 2026
ALPINE-CVE-2026-6276curl@8.17.0-r1apk8.20.0-r08/1002 Sept 2026
ALPINE-CVE-2026-63072openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 2026
ALPINE-CVE-2026-63075openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 2026
ALPINE-CVE-2026-63076openssl@3.5.5-r0apk3.5.8-r08/1002 Sept 2026
ALPINE-CVE-2026-6732libxml2@2.13.9-r0apk2.13.9-r18/1002 Sept 2026
ALPINE-CVE-2026-9076openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 2026
ALPINE-CVE-2026-34181openssl@3.5.5-r0apk3.5.7-r07/1002 Sept 2026
GO-2026-4870

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

stdlib@go1.26.1golang1.25.97/1000.006 (47th pct)2 Sept 2026
GO-2026-4947

Unexpected work during chain building in crypto/x509

stdlib@go1.26.1golang1.25.97/1000.006 (47th pct)2 Sept 2026
GO-2026-5037

Inefficient candidate hostname parsing in crypto/x509

stdlib@go1.26.1golang1.25.117/1000.006 (46th pct)2 Sept 2026
GO-2026-4971

Panic in Dial and LookupPort when handling NUL byte on Windows in net

stdlib@go1.26.1golang1.25.107/1000.006 (45th pct)2 Sept 2026
GO-2026-5972

Enforce maximum recursion depth in encoding/asn1

stdlib@go1.26.1golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-6088

Add recursion depth guard during decode in encoding/xml

stdlib@go1.26.1golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-6089

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

stdlib@go1.26.1golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-6090

Limit handshake messages we are willing to accept post-handshake in crypto/tls

stdlib@go1.26.1golang1.25.137/1000.006 (45th pct)2 Sept 2026
GO-2026-5038

Quadratic complexity in WordDecoder.DecodeHeader in mime

stdlib@go1.26.1golang1.25.117/1000.006 (44th pct)2 Sept 2026
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

stdlib@go1.26.1golang1.26.67/1000.005 (44th pct)2 Sept 2026
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

golang.org/x/net@v0.52.0golang0.56.07/1000.005 (44th pct)2 Sept 2026
GO-2026-6218

Avoid quadratic complexity in resolvePath in net/url

stdlib@go1.26.1golang1.25.137/1000.005 (42th pct)2 Sept 2026
GO-2026-5970

Infinite loop on invalid input in golang.org/x/text

golang.org/x/text@v0.35.0golang0.39.07/1000.005 (39th pct)2 Sept 2026
ALPINE-CVE-2026-1965curl@8.17.0-r1apk8.19.0-r07/1002 Sept 2026
ALPINE-CVE-2026-2673openssl@3.5.5-r0apk3.5.6-r07/1002 Sept 2026
ALPINE-CVE-2026-3784curl@8.17.0-r1apk8.19.0-r07/1002 Sept 2026
ALPINE-CVE-2026-5545curl@8.17.0-r1apk8.20.0-r07/1002 Sept 2026
ALPINE-CVE-2025-14017curl@8.17.0-r1apk8.19.0-r06/1002 Sept 2026
GO-2026-4976

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

stdlib@go1.26.1golang1.25.106/1000.004 (32th pct)2 Sept 2026
GO-2026-5856

Invoking Encrypted Client Hello privacy leak in crypto/tls

stdlib@go1.26.1golang1.25.126/1000.004 (31th pct)2 Sept 2026
GO-2026-4980

Escaper bypass leads to XSS in html/template

stdlib@go1.26.1golang1.25.106/1000.004 (30th pct)2 Sept 2026
GO-2026-5039

Arbitrary inputs are included in errors without any escaping in net/textproto

stdlib@go1.26.1golang1.25.116/1000.004 (30th pct)2 Sept 2026
GO-2026-4946

Inefficient policy validation in crypto/x509

stdlib@go1.26.1golang1.25.96/1000.004 (28th pct)2 Sept 2026
GO-2026-4866

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

stdlib@go1.26.1golang1.26.26/1000.003 (27th pct)2 Sept 2026
ALPINE-CVE-2026-42766openssl@3.5.5-r0apk3.5.7-r06/1002 Sept 2026
ALPINE-CVE-2026-42767openssl@3.5.5-r0apk3.5.7-r06/1002 Sept 2026
ALPINE-CVE-2026-4873curl@8.17.0-r1apk8.20.0-r06/1002 Sept 2026
ALPINE-CVE-2026-6253curl@8.17.0-r1apk8.20.0-r06/1002 Sept 2026
ALPINE-CVE-2026-63074openssl@3.5.5-r0apk3.5.8-r06/1002 Sept 2026
GO-2026-4982

Bypass of meta content URL escaping causes XSS in html/template

stdlib@go1.26.1golang1.25.106/1000.003 (24th pct)2 Sept 2026
GO-2026-6091

Fix Javascript regexp context tracking in html/template

stdlib@go1.26.1golang1.25.136/1000.003 (23th pct)2 Sept 2026
GO-2026-4864

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

stdlib@go1.26.1golang1.25.96/1000.003 (21th pct)2 Sept 2026
GO-2026-4865

JsBraceDepth Context Tracking Bugs (XSS) in html/template

stdlib@go1.26.1golang1.25.96/1000.003 (21th pct)2 Sept 2026
GO-2026-4869

Unbounded allocation for old GNU sparse in archive/tar

stdlib@go1.26.1golang1.25.96/1000.003 (21th pct)2 Sept 2026
GO-2026-5025

Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

golang.org/x/net@v0.52.0golang0.55.05/1000.002 (14th pct)2 Sept 2026
ALPINE-CVE-2025-14524curl@8.17.0-r1apk8.19.0-r05/1002 Sept 2026
ALPINE-CVE-2025-14819curl@8.17.0-r1apk8.19.0-r05/1002 Sept 2026
ALPINE-CVE-2026-34743xz@5.8.2-r0apk5.8.3-r05/1002 Sept 2026
ALPINE-CVE-2026-3783curl@8.17.0-r1apk8.19.0-r05/1002 Sept 2026
ALPINE-CVE-2026-42769openssl@3.5.5-r0apk3.5.7-r05/1002 Sept 2026
ALPINE-CVE-2026-6429curl@8.17.0-r1apk8.20.0-r05/1002 Sept 2026
ALPINE-CVE-2026-7009curl@8.17.0-r1apk8.20.0-r05/1002 Sept 2026
ALPINE-CVE-2026-7168curl@8.17.0-r1apk8.20.0-r05/1002 Sept 2026
GO-2026-4970

Root escape via symlink plus trailing slash in os

stdlib@go1.26.1golang1.25.125/1000.002 (14th pct)2 Sept 2026
GO-2026-5027

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

golang.org/x/net@v0.52.0golang0.55.05/1000.002 (13th pct)2 Sept 2026
GO-2026-5029

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

golang.org/x/net@v0.52.0golang0.55.05/1000.002 (13th pct)2 Sept 2026
GO-2026-5030

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

golang.org/x/net@v0.52.0golang0.55.05/1000.002 (13th pct)2 Sept 2026
ALPINE-CVE-2026-45446openssl@3.5.5-r0apk3.5.7-r05/1002 Sept 2026
ALPINE-CVE-2026-6042musl@1.2.5-r21apk1.2.5-r225/1002 Sept 2026
GO-2026-5024

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

golang.org/x/sys@v0.42.0golang0.44.04/1000.001 (2th pct)2 Sept 2026
ALPINE-CVE-2026-42768openssl@3.5.5-r0apk3.5.7-r04/1002 Sept 2026
ALPINE-CVE-2026-42770openssl@3.5.5-r0apk3.5.7-r04/1002 Sept 2026

Tags and digests

Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.

TagDigestPlatformFirst seenLast seenRadar Score
v1.15.1current594ceea76b01linux/amd642 Sept 20262 Sept 2026611

Used by

Charts whose default render references this repository, with the workload that carries it.

syft 1.42.1 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.