Package
jaeger-1-tracegen-compat
Component
stdlib
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
GO-2026-6091 (CVE-2026-56858, medium severity) is a vulnerability in the Go standard library's html/template package: under certain pathological inputs an unescaped '/' can be closed early, allowing attacker-controlled content to be injected and potentially leading to cross-site scripting (XSS). It is fixed in the Go toolchain at versions 1.25.13, 1.26.6, and 1.27.0-rc.3.
The jaeger 1.x binaries in the affected images were compiled with Go 1.25.11, which is within the vulnerable range, so this detection is accurate. However, the jaeger 1.x release line has reached end of life and is no longer maintained. Remediating this finding would require rebuilding the affected binaries against a patched Go toolchain (Go 1.25.13 or later); this is not planned for the end-of-life jaeger 1.x line. Users should migrate to a supported jaeger 2.x release, which is built against a current, patched Go toolchain.
References:
Status