StackRadar

CVE-2021-3520

Critical

Advisory

Published 30 Apr 2021In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
751
of 17,787 indexed, latest versions
Container images
553
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: lz4 security update

Carried by container images the latest versions of 751 of 17,787 indexed charts deploy, on 553 images.

Affected packageAffected versionsFixed inImages
lz4deb0.0~r131-2+b1, 0.0~r131-2ubuntu2, 0.0~r131-2ubuntu3, 1.8.3-1+1 more0.0~r131-2+deb9u1, 0.0~r131-2ubuntu2+esm1, 0.0~r131-2ubuntu3.1, 1.8.3-1+deb10u1+1 more509
lz4apk1.9.2-r0, 1.9.3-r01.9.2-r1, 1.9.3-r15
lz4rpm1.8.0-3.5.1, 1.8.0-lp151.3.3.1, 1.8.1.2-4.el8, 1.8.3-2.el80:1.8.3-3.el8_4, 1.8.0-3.8.1, 1.9.3-2.139
OSV records
ALPINE-CVE-2021-3520UBUNTU-CVE-2021-3520RHSA-2021:2575DLA-2657-1DSA-4919-1openSUSE-SU-2024:11562-1SUSE-SU-2021:1647-1
Also known as
USN-4968-1, USN-4968-2

Charts affected

751 by stars
ChartLatestAffected imagesRadar Score
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
lz4@1.8.3-1
1.8.3-1+deb10u1

Open the chart page →

1,138

Container images carrying it

553 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/ttyd:latestd79c1c5881c0
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
codaprotocol/buildkite-exporter:0.2.137c68e67a401
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
codaprotocol/coda-user-agent:0.1.54ba4dd3a041f
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
codercom/code-server:3.10.247605610ad8d
lz4@1.8.3-1
1.8.3-1+deb10u1
1
codeskyblue/gohttpserver:latestcaa862590e34
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/agendaservice-nginx:lateste1c176458aaf
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/balance-registration-nginx:dev9e24264ea8f3
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/balance-registration-varnish:dev07c44005da9d
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/betaalservice-nginx:latestd3577ddd5c67
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/cgrc-nginx:devd8e23f10e882
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/cgrc-varnish:deve154d5781c8a
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/checkin-component-nginx:dev583d2cd8476c
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/checkin-component-varnish:devef3a3fb0ad47
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/conduction-ui-nginx:devd9b38e234de9
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/conduction-ui-varnish:dev5f5add2c12e0
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/contactmoment-component-nginx:dev353dc46303ac
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/contactmoment-component-varnish:deve3546b97faea
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/docparser-nginx:dev08524d8327b8
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/docparser-varnish:dev45f20c4cd2fa
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/kvk-nginx:devcf163d2b95b5
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/kvk-varnish:dev8722700f1768
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/pan-nginx:devaf3e9f551ad1
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
conduction/pan-varnish:devc3e5737ae68f
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
lz4@1.8.3-2.el8
0:1.8.3-3.el8_4
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
lz4@1.8.3-2.el8
0:1.8.3-3.el8_4
1
confluentinc/cp-kafkacat:4.1.25f990b0f43c9
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
lz4@1.8.3-2.el8
0:1.8.3-3.el8_4
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
lz4@1.8.3-2.el8
0:1.8.3-3.el8_4
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
lz4@1.8.3-2.el8
0:1.8.3-3.el8_4
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
lz4@1.8.3-2.el8
0:1.8.3-3.el8_4
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
lz4@1.8.3-2.el8
0:1.8.3-3.el8_4
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
craftypath/sops-operator:v0.8.0402a0024c732
lz4@1.8.3-2.el8
0:1.8.3-3.el8_4
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
ctron/hawkbit-operator:0.1.48fdea8f76499
lz4@1.8.1.2-4.el8
0:1.8.3-3.el8_4
1
daedalusproject/base_kubectl:latest6f72b5119eda
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
daskdev/dask:1.1.04ecd7bc35500
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
daskdev/dask-notebook:1.1.0052630f5ca04
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
datalust/seq:5.0.832-pre9c731bb207a6
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
datarhei/restreamer:0.6.4655e12f9eeed
lz4@1.8.3-1
1.8.3-1+deb10u1
1
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
dellcloud/category:distributed02fc234353a9
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
dellcloud/pages:1.04d2eb25b9225
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
digitsy/kafka-magic:2.0.3.4f91d7f56b55d
lz4@1.8.3-1
1.8.3-1+deb10u1
1
dnationcloud/kubernetes-linter:0.2.1dee6376560f5
lz4@1.8.3-1
1.8.3-1+deb10u1
1
dniel/api-posts:master45a667852f2a
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
douz/helpdesk-frontend:latestfa6a57de2b72
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
douz/overlord:latestf2bc7fc068c1
lz4@1.8.3-1
1.8.3-1+deb10u1
1
drgrove/mtls-server:v0.14.2361721759a2b
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.