StackRadar

CVE-2021-29482

High

Advisory

Published 14 Apr 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
72nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
13
deployed by those charts
Fix available
1 of 1
affected package

github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
github.com/ulikunitz/xzgolangv0.5.5, v0.5.6, v0.5.70.5.813
OSV records
GHSA-25xm-hr59-7c27
Also known as
GO-2020-0016

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
github.com/ulikunitz/xz@v0.5.7
0.5.8

Open the chart page →

4,568
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
github.com/ulikunitz/xz@v0.5.6
0.5.8

Open the chart page →

3,474
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
github.com/ulikunitz/xz@v0.5.7
0.5.8

Open the chart page →

10,701
atlantistrozz3.12.111 of 1See more

atlantis trozz 3.12.11

1 of the 1 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.16.145fbaf7e207c
github.com/ulikunitz/xz@v0.5.5
0.5.8

Open the chart page →

5,280
electric-mailcryptexlabsVerified publisher0.0.11 of 5See more

electric-mail cryptexlabs 0.0.1

1 of the 5 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
github.com/ulikunitz/xz@v0.5.7
0.5.8

Open the chart page →

5,973
purple-piecryptexlabsVerified publisher0.0.11 of 4See more

purple-pie cryptexlabs 0.0.1

1 of the 4 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
github.com/ulikunitz/xz@v0.5.7
0.5.8

Open the chart page →

5,973
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
github.com/ulikunitz/xz@v0.5.6
0.5.8

Open the chart page →

7,486
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
github.com/ulikunitz/xz@v0.5.5
0.5.8

Open the chart page →

10,466
argocddevtron-labs1.8.11 of 3See more

argocd devtron-labs 1.8.1

1 of the 3 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
github.com/ulikunitz/xz@v0.5.5
0.5.8

Open the chart page →

10,466
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
github.com/ulikunitz/xz@v0.5.6
0.5.8

Open the chart page →

3,046
pipecdkrzwiatrzyk0.39.01 of 3See more

pipecd krzwiatrzyk 0.39.0

1 of the 3 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
github.com/ulikunitz/xz@v0.5.6
0.5.8

Open the chart page →

3,812
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
github.com/ulikunitz/xz@v0.5.6
0.5.8

Open the chart page →

4,861
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
github.com/ulikunitz/xz@v0.5.7
0.5.8

Open the chart page →

18,023
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
github.com/ulikunitz/xz@v0.5.5
0.5.8

Open the chart page →

10,466
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
github.com/ulikunitz/xz@v0.5.7
0.5.8

Open the chart page →

5,864
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-29482.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
github.com/ulikunitz/xz@v0.5.6
0.5.8

Open the chart page →

3,174

Container images carrying it

13 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
argoproj/argocd:v1.8.1830e86cacefd
github.com/ulikunitz/xz@v0.5.5
0.5.8
3
hashicorp/vault:1.8.34db614d40d0e
github.com/ulikunitz/xz@v0.5.7
0.5.8
2
anchore/anchore-engine:v0.10.0bde9eedf639d
github.com/ulikunitz/xz@v0.5.7
0.5.8
1
datadog/agent:7.22.08f20e56b5311
github.com/ulikunitz/xz@v0.5.7
0.5.8
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
github.com/ulikunitz/xz@v0.5.6
0.5.8
1
dollarshaveclub/furan2:master14a257836529
github.com/ulikunitz/xz@v0.5.6
0.5.8
1
filebrowser/filebrowser:v2.18.04fcd47af573c
github.com/ulikunitz/xz@v0.5.6
0.5.8
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
github.com/ulikunitz/xz@v0.5.6
0.5.8
1
gitea/gitea:1.13.0d5ab14cd29af
github.com/ulikunitz/xz@v0.5.6
0.5.8
1
hashicorp/vault:1.8.4dfc3500beb0e
github.com/ulikunitz/xz@v0.5.7
0.5.8
1
istio/operator:1.10.3655eefa11c84
github.com/ulikunitz/xz@v0.5.7
0.5.8
1
runatlantis/atlantis:v0.16.145fbaf7e207c
github.com/ulikunitz/xz@v0.5.5
0.5.8
1
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
github.com/ulikunitz/xz@v0.5.6
0.5.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.