StackRadar

CVE-2021-3520

Critical

Advisory

Published 30 Apr 2021In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
753
of 17,787 indexed, latest versions
Container images
555
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: lz4 security update

Carried by container images the latest versions of 753 of 17,787 indexed charts deploy, on 555 images.

Affected packageAffected versionsFixed inImages
lz4deb0.0~r131-2+b1, 0.0~r131-2ubuntu2, 0.0~r131-2ubuntu3, 1.8.3-1+1 more0.0~r131-2+deb9u1, 0.0~r131-2ubuntu2+esm1, 0.0~r131-2ubuntu3.1, 1.8.3-1+deb10u1+1 more511
lz4apk1.9.2-r0, 1.9.3-r01.9.2-r1, 1.9.3-r15
lz4rpm1.8.0-3.5.1, 1.8.0-lp151.3.3.1, 1.8.1.2-4.el8, 1.8.3-2.el80:1.8.3-3.el8_4, 1.8.0-3.8.1, 1.9.3-2.139
OSV records
ALPINE-CVE-2021-3520UBUNTU-CVE-2021-3520RHSA-2021:2575DLA-2657-1DSA-4919-1openSUSE-SU-2024:11562-1SUSE-SU-2021:1647-1
Also known as
USN-4968-1, USN-4968-2

Charts affected

753 by stars
ChartLatestAffected imagesRadar Score
mychartyi-test-chart0.1.01 of 1See more

mychart yi-test-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1

Open the chart page →

702
helmexampleyunpeng-helmexample0.1.01 of 1See more

helmexample yunpeng-helmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1

Open the chart page →

702
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
lz4@1.8.3-1
1.8.3-1+deb10u1

Open the chart page →

1,138

Container images carrying it

555 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
lz4@1.8.3-1
1.8.3-1+deb10u1
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
lz4@1.8.3-1
1.8.3-1+deb10u1
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
lz4@1.8.3-1
1.8.3-1+deb10u1
1
lavandadelpatio/tmdb:0.0.2f36af885e915
lz4@1.8.3-1
1.8.3-1+deb10u1
1
ldapaccountmanager/lam:7.295533a96a4c1
lz4@1.8.3-1
1.8.3-1+deb10u1
1
leeyoongti/first-app:1.0.021d66cb76352
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/cassandra:3.11.598531a31f213
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/cassandra:2.1.20cb079c0d7a57
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/couchdb:2.3.0ee75c9a737e7
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/elasticsearch:2.4.641ed3a1a16b6
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/flink:1.11.2-scala_2.121fe4fb22a2a5
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/influxdb:1.8.472b1b24a0288
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/memcached:1.5.12d723943be12c
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/mongo:3.6146c1fd999a6
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
library/mongo:4.2.16ca49afbcb2b
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
library/mysql:5.7.21691c55aabb3c
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/mysql:8.0.176d95fa56e008
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/mysql:5.7.32e08834258fcc
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/mysql:5.7.33e42a18d0bd0a
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/nextcloud:17.0.0-apache96104cb965fc
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/nginx:1.19.68e1095642250
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/nginx:1.17.6b2d89d0a2103
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/nginx:1.16.1d20aa6d1cae5
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/nginx:1.18.0e90ac5331fe0
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/nginx:1.14.2f7988fb6c02e
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/postgres:9.6.182f75145ad077
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/postgres:14.1-alpine578ca5c8452c
lz4@1.9.3-r0
1.9.3-r1
1
library/postgres:9.575ebf479151a
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/postgres:10.49625c2fb3498
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/postgres:11.10bb024e990f4f
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/postgres:12.2d96835c90329
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/rabbitmq:3.6-management05bd722c6b0c
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/rabbitmq:3.7-managementb6dd45cc35b3
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
library/redis:6.0.609c33840ec47
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/redis:4.02e03fdd159f4
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/redis:6.0.948c1431bed43
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/redis:5.0.34be7fdb131e7
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/redis:6.0.10f29bcfb89167
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/sonarqube:6.7.6-community0ae5169e3d0f
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
library/sonarqube:8.2-communitya246bc64207e
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/varnish:6.6.05b41623edd33
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/zookeeper:3.43882d9493d38
lz4@1.8.3-1
1.8.3-1+deb10u1
1
library/zookeeper:3.6.24c8a6d3b2338
lz4@1.8.3-1
1.8.3-1+deb10u1
1
lightbend/curl:7.47.0b0c9894ac8dd
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
linuxserver/codimd:latestb801bbcf6386
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
litmuschaos/mongo:4.2.899961210d467
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
lmenezes/cerebro:0.8.36684131caf5f
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
lncm/specter-desktop:v0.10.4bca14d04397d
lz4@1.8.3-1
1.8.3-1+deb10u1
1
loicsharma/baget:0b46f0ec87216e1dc6839277712ee07c1c2b611aa880c78ae80b
lz4@1.8.3-1
1.8.3-1+deb10u1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.