StackRadar

CVE-2021-3520

Critical

Advisory

Published 30 Apr 2021In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
753
of 17,787 indexed, latest versions
Container images
555
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: lz4 security update

Carried by container images the latest versions of 753 of 17,787 indexed charts deploy, on 555 images.

Affected packageAffected versionsFixed inImages
lz4deb0.0~r131-2+b1, 0.0~r131-2ubuntu2, 0.0~r131-2ubuntu3, 1.8.3-1+1 more0.0~r131-2+deb9u1, 0.0~r131-2ubuntu2+esm1, 0.0~r131-2ubuntu3.1, 1.8.3-1+deb10u1+1 more511
lz4apk1.9.2-r0, 1.9.3-r01.9.2-r1, 1.9.3-r15
lz4rpm1.8.0-3.5.1, 1.8.0-lp151.3.3.1, 1.8.1.2-4.el8, 1.8.3-2.el80:1.8.3-3.el8_4, 1.8.0-3.8.1, 1.9.3-2.139
OSV records
ALPINE-CVE-2021-3520UBUNTU-CVE-2021-3520RHSA-2021:2575DLA-2657-1DSA-4919-1openSUSE-SU-2024:11562-1SUSE-SU-2021:1647-1
Also known as
USN-4968-1, USN-4968-2

Charts affected

753 by stars
ChartLatestAffected imagesRadar Score
mychartyi-test-chart0.1.01 of 1See more

mychart yi-test-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1

Open the chart page →

702
helmexampleyunpeng-helmexample0.1.01 of 1See more

helmexample yunpeng-helmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1

Open the chart page →

702
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
lz4@1.8.3-1
1.8.3-1+deb10u1

Open the chart page →

1,138

Container images carrying it

555 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
sirfragalot/hyperion.ng:2.0.0-alpha.9-x86_6434577843cb7b
lz4@1.8.3-1
1.8.3-1+deb10u1
1
siscc/dotstatsuite-core-auth-management:9a653e82bb1e9a45b6fa
lz4@1.8.3-1
1.8.3-1+deb10u1
1
siscc/dotstatsuite-core-sdmxri-nsi:master00d73f06edcf
lz4@1.8.3-1
1.8.3-1+deb10u1
1
sismics/docs:v1.10f4b0ef019cf1
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu3.1
1
slagattollas/planner-practica:latestcecd95e31486
lz4@1.8.3-1
1.8.3-1+deb10u1
1
slagattollas/server-practica:latest6dd8ead8e2b1
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
slagattollas/weatherservice-practica:latest68e7f56393fc
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
lz4@1.8.3-1
1.8.3-1+deb10u1
1
softonic/kube-gcp-disks-roomba:latestd9c57e76e669
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
softonic/kubewatch:v0.4.0f0d3dcecce5e
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
softonic/node-policy-webhook:0.1.2ab6098c04a53
lz4@1.8.3-1
1.8.3-1+deb10u1
1
softonic/pod-defaulter:0.1.072017aed5902
lz4@1.8.3-1
1.8.3-1+deb10u1
1
softonic/preemptible-killer:1.2.6-294b87f1fb362
lz4@1.8.3-1
1.8.3-1+deb10u1
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
lz4@1.8.3-1
1.8.3-1+deb10u1
1
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
lz4@1.8.3-1
1.8.3-1+deb10u1
1
stacksimplify/kube-nginxapp1:1.0.0ead648280067
lz4@1.8.3-1
1.8.3-1+deb10u1
1
stacksimplify/kube-nginxapp2:1.0.0ce2b15139aca
lz4@1.8.3-1
1.8.3-1+deb10u1
1
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
lz4@1.8.3-1
1.8.3-1+deb10u1
1
stashapp/stash:latest24dbd7607174
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
subsquid/hydra-indexer-gateway:5.0.0-alpha.37a0d9dea6a9c2
lz4@1.8.3-1
1.8.3-1+deb10u1
1
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
lz4@1.8.3-1
1.8.3-1+deb10u1
1
svtechnmaa/svtech_gitlist:v1.0.0d5a1390b5b75
lz4@1.8.3-1
1.8.3-1+deb10u1
1
svtechnmaa/svtech_http_thruk:v1.0.2e19aba397c1f
lz4@1.8.3-1
1.8.3-1+deb10u1
1
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
lz4@1.8.3-1
1.8.3-1+deb10u1
1
taigaio/taiga-protected:6.4.036318831b3e7
lz4@1.8.3-1
1.8.3-1+deb10u1
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
teslamate/teslamate:1.23.449db95fbf2a1
lz4@1.8.3-1
1.8.3-1+deb10u1
1
testhubio/testhub-api:on-prem56badee134b9
lz4@1.8.3-1
1.8.3-1+deb10u1
1
thecampagnards/trafficlight-api:main7dca9d973837
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
tpdock/freeradius:2.2.93da600c95a49
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
lz4@1.8.3-1
1.8.3-1+deb10u1
1
typesense/typesense:0.23.03accb727cbe2
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
ubercadence/web:v3.29.58564a5b44a6d
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
vexorian/dizquetv:1.4.37e2b99844a5c
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
vikunja/frontend:0.17.0863a426a8e49
lz4@1.8.3-1
1.8.3-1+deb10u1
1
voltha/voltha-cli:1.6.0c4e41e92f046
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
voltha/voltha-netconf:1.6.037f80524c207
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
voltha/voltha-onos:5.1.8e038acb950d3
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
voltha/voltha-tester:1.7.0655c3048a602
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
voltha/voltha-voltha:1.6.0ff596b62de59
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
vromero/activemq-artemis:2.16.0408d6a46b153
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
wavefronthq/proxy:9.2d1064d28f6eb
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
weblate/weblate:3.11.3-182848df56ecd
lz4@1.8.3-1
1.8.3-1+deb10u1
1
wekanteam/wekan:v4.2268a51f0327df
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
wener/samba:4.13.39a42bae466d4
lz4@1.9.2-r0
1.9.2-r1
1
wiremind/pghoard:12-2019-11-264dea42c8166c
lz4@1.8.3-1
1.8.3-1+deb10u1
1
woojoong/wowza:latestec230db19652
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.