StackRadar

CVE-2021-3520

Critical

Advisory

Published 30 Apr 2021In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
753
of 17,787 indexed, latest versions
Container images
555
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: lz4 security update

Carried by container images the latest versions of 753 of 17,787 indexed charts deploy, on 555 images.

Affected packageAffected versionsFixed inImages
lz4deb0.0~r131-2+b1, 0.0~r131-2ubuntu2, 0.0~r131-2ubuntu3, 1.8.3-1+1 more0.0~r131-2+deb9u1, 0.0~r131-2ubuntu2+esm1, 0.0~r131-2ubuntu3.1, 1.8.3-1+deb10u1+1 more511
lz4apk1.9.2-r0, 1.9.3-r01.9.2-r1, 1.9.3-r15
lz4rpm1.8.0-3.5.1, 1.8.0-lp151.3.3.1, 1.8.1.2-4.el8, 1.8.3-2.el80:1.8.3-3.el8_4, 1.8.0-3.8.1, 1.9.3-2.139
OSV records
ALPINE-CVE-2021-3520UBUNTU-CVE-2021-3520RHSA-2021:2575DLA-2657-1DSA-4919-1openSUSE-SU-2024:11562-1SUSE-SU-2021:1647-1
Also known as
USN-4968-1, USN-4968-2

Charts affected

753 by stars
ChartLatestAffected imagesRadar Score
mychartyi-test-chart0.1.01 of 1See more

mychart yi-test-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1

Open the chart page →

702
helmexampleyunpeng-helmexample0.1.01 of 1See more

helmexample yunpeng-helmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1

Open the chart page →

702
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
lz4@1.8.3-1
1.8.3-1+deb10u1

Open the chart page →

1,138

Container images carrying it

555 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
yandex/clickhouse-server:19.17ab1738a64b70
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
yandex/clickhouse-server:19.14ccf9c2b5e3f2
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
yandex/clickhouse-server:19.16d210dc69321e
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
zooz/predator:1.6f491d1f7a865
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
gcr.io/gke-release/gcp-compute-persistent-disk-csi-driver:v0.6.2-gke.0cf3c3af0187e
lz4@1.8.3-1
1.8.3-1+deb10u1
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
gcr.io/google-containers/startup-script:v29d0006c93668
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
gcr.io/google-samples/microservices-demo/loadgenerator:v0.2.3360130ab5850
lz4@1.8.3-1
1.8.3-1+deb10u1
1
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
lz4@1.8.3-1
1.8.3-1+deb10u1
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
ghcr.io/cfcontainerizationbot/kubecf-kubectl:v1.19.261daa1bba5cb
lz4@1.8.0-3.5.1
1.8.0-3.8.1
1
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
lz4@1.8.0-3.5.1
1.8.0-3.8.1
1
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
lz4@1.8.0-3.5.1
1.8.0-3.8.1
1
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
lz4@1.8.0-3.5.1
1.8.0-3.8.1
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
lz4@1.8.0-3.5.1
1.8.0-3.8.1
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
lz4@1.8.0-3.5.1
1.8.0-3.8.1
1
ghcr.io/conductionnl/bisc-frontend:latestd8a0334cddfc
lz4@1.8.3-1
1.8.3-1+deb10u1
1
ghcr.io/grofers/legend:0.1d6e901ad0ebd
lz4@1.8.3-1
1.8.3-1+deb10u1
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
lz4@1.8.1.2-4.el8
0:1.8.3-3.el8_4
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
ghcr.io/k8s-at-home/leaf2mqtt:v0.1fc9f5aca6cf4
lz4@1.8.3-1
1.8.3-1+deb10u1
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
ghcr.io/leoquote/mergeable:latest451706815103
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
ghcr.io/wbstack/cradle:2.0.11c7a78c54f77
lz4@1.8.3-1
1.8.3-1+deb10u1
1
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
ghcr.io/wbstack/quickstatements:1.3.588423e422ea8
lz4@1.8.3-1
1.8.3-1+deb10u1
1
ghcr.io/wbstack/widar:1.31702fc9df79f
lz4@1.8.3-1
1.8.3-1+deb10u1
1
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
lz4@1.8.3-1
1.8.3-1+deb10u1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
lz4@1.8.3-2.el8
0:1.8.3-3.el8_4
1
quay.io/coreos/etcd:v3.4.17c2126f99e5c9
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
quay.io/coreos/etcd:v3.4.16ea7bb56278ab
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
quay.io/fairwinds/yelb-ui:v0.1.05ac114e567ed
lz4@1.8.3-1
1.8.3-1+deb10u1
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
lz4@1.8.1.2-4.el8
0:1.8.3-3.el8_4
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
quay.io/kube-ops/promtail:2.2.134de6387233b
lz4@1.8.3-1
1.8.3-1+deb10u1
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
lz4@1.8.1.2-4.el8
0:1.8.3-3.el8_4
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
lz4@1.8.3-2.el8
0:1.8.3-3.el8_4
1
quay.io/openshift/origin-cli:4.66722d5041b47
lz4@1.8.1.2-4.el8
0:1.8.3-3.el8_4
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
lz4@1.8.1.2-4.el8
0:1.8.3-3.el8_4
1
quay.io/opsmxpublic/bitnami-kubectl:1.18.5a8b21cec412c
lz4@1.8.3-1
1.8.3-1+deb10u1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.