StackRadar

CVE-2021-3520

Critical

Advisory

Published 30 Apr 2021In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
753
of 17,787 indexed, latest versions
Container images
555
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: lz4 security update

Carried by container images the latest versions of 753 of 17,787 indexed charts deploy, on 555 images.

Affected packageAffected versionsFixed inImages
lz4deb0.0~r131-2+b1, 0.0~r131-2ubuntu2, 0.0~r131-2ubuntu3, 1.8.3-1+1 more0.0~r131-2+deb9u1, 0.0~r131-2ubuntu2+esm1, 0.0~r131-2ubuntu3.1, 1.8.3-1+deb10u1+1 more511
lz4apk1.9.2-r0, 1.9.3-r01.9.2-r1, 1.9.3-r15
lz4rpm1.8.0-3.5.1, 1.8.0-lp151.3.3.1, 1.8.1.2-4.el8, 1.8.3-2.el80:1.8.3-3.el8_4, 1.8.0-3.8.1, 1.9.3-2.139
OSV records
ALPINE-CVE-2021-3520UBUNTU-CVE-2021-3520RHSA-2021:2575DLA-2657-1DSA-4919-1openSUSE-SU-2024:11562-1SUSE-SU-2021:1647-1
Also known as
USN-4968-1, USN-4968-2

Charts affected

753 by stars
ChartLatestAffected imagesRadar Score
mychartyi-test-chart0.1.01 of 1See more

mychart yi-test-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1

Open the chart page →

702
helmexampleyunpeng-helmexample0.1.01 of 1See more

helmexample yunpeng-helmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1

Open the chart page →

702
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3520.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
lz4@1.8.3-1
1.8.3-1+deb10u1

Open the chart page →

1,138

Container images carrying it

555 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
onosproject/onos:2.2.144914a8d4b3f
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
opencord/voltha-kafka-dump:6.1.31d9ee8ce7fab
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
opendatacube/pipelines:wofs-1.225d810e8504b8
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
opendatacube/restcube:latest91870111837c
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
opendatacube/wms:latest1b90cdf68831
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
openelevation/open-elevation:latest82fb21612e86
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
openwhisk/kafkaprovider:2.1.063dc3d2a0904
lz4@1.8.3-1
1.8.3-1+deb10u1
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
oscarsotosanchez/planner:v1.0730c00a099b8
lz4@1.8.3-1
1.8.3-1+deb10u1
1
osixia/phpldapadmin:0.7.058cce1b08592
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
osrm/osrm-backend:v5.22.0c5c86a5b15ce
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
lz4@1.9.3-r0
1.9.3-r1
1
pachyderm/dash:1.9.094e9a281e5a4
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
lz4@1.8.3-1
1.8.3-1+deb10u1
1
pecan/monitor:1.7.273b2074f3fec
lz4@1.8.3-1
1.8.3-1+deb10u1
1
pedrocesarti/jmeter-docker:3.314851f144f57
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
phntom/binaryvision-static-wordpress:0.0.385a2dfb83b11
lz4@1.8.3-1
1.8.3-1+deb10u1
1
phntom/codimd:2.4.31b9aafbb62e6
lz4@1.8.3-1
1.8.3-1+deb10u1
1
pietrom/learning-quarkus:1.0.5061a84362926
lz4@1.8.3-1
1.8.3-1+deb10u1
1
pihole/pihole:v4.48c172c4cf344
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
lz4@1.8.1.2-4.el8
0:1.8.3-3.el8_4
1
pozetroninc/keydb:v6.0.1653ae64f29da8
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
pposkrobko/risk-advisor:v1.0.0eaf260341dba
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
prom/cloudwatch-exporter:cloudwatch_exporter-0.8.0fc4b9b9f5e15
lz4@1.8.3-1
1.8.3-1+deb10u1
1
qoveryrd/digital-mobius:0.1.4b30a9398a83c
lz4@1.8.3-1
1.8.3-1+deb10u1
1
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
radondb/zookeeper:3.6.216981604f1a0
lz4@1.8.3-1
1.8.3-1+deb10u1
1
rakii8585/angular-node-webapp:latest026082a515ac
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
raykrueger/riemann:0.2.14c8baf3de57bb
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
richardchesterwood/k8s-fleetman-position-simulator:release20b540a28f5a6
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
rodolpheche/wiremock:2.27.22328a9fce2bf
lz4@1.8.3-1
1.8.3-1+deb10u1
1
royalwang/sentinel-dashboard:1.8.4df99e2499f91
lz4@0.0~r131-2+b1
0.0~r131-2+deb9u1
1
rundeck/rundeck:3.2.74d64fe56f767
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
rundeck/rundeck:3.0.16b13e8059ad72
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
samueldg/snappass:latest3987195edbe6
lz4@1.8.3-1
1.8.3-1+deb10u1
1
scrapinghub/splash:3.4.1a5f89bc84606
lz4@0.0~r131-2ubuntu3
0.0~r131-2ubuntu3.1
1
seafileltd/seafile-mc:9.0.106693911bcc40
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
seafileltd/seafile-mc:9.0.97ac833196f60
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
lz4@1.9.2-2
1.9.2-2ubuntu0.20.04.1
1
seldonio/locust-core:0.81d0da98a2d76
lz4@0.0~r131-2ubuntu2
0.0~r131-2ubuntu2+esm1
1
shadow228/accountingcollege:0.0.28fcea5b71906
lz4@1.8.3-1
1.8.3-1+deb10u1
1
shinobisystems/shinobi:dev3ca746937856
lz4@1.8.3-1
1.8.3-1+deb10u1
1
shinobisystems/shinobi:latestc2f5ce2e1067
lz4@1.8.3-1
1.8.3-1+deb10u1
1
sinusbot/docker:1.0.0-beta.14-dc94a7cc7a4f3cc4393
lz4@1.8.3-1
1.8.3-1+deb10u1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.