CVE-2021-3580
HighAdvisory
Published 10 Jun 2021In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.027
- 85th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 261
- of 17,781 indexed, latest versions
- Container images
- 167
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Security update for libnettle
Carried by container images the latest versions of 261 of 17,781 indexed charts deploy, on 167 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nettledeb | 3.2-1ubuntu0.16.04.1, 3.2-1ubuntu0.16.04.2, 3.4-1, 3.4-1ubuntu0.1+2 more | 3.4.1-0ubuntu0.18.04.1, 3.5.1+really3.5.1-2ubuntu0.2 | 143 |
| nettleapk | 3.5.1-r1, 3.7-r0, 3.7.2-r0 | 3.5.1-r2, 3.7.3-r0 | 16 |
| libnettlerpm | 3.4.1-4.12.1 | 3.4.1-4.18.1 | 8 |
- OSV records
- ALPINE-CVE-2021-3580UBUNTU-CVE-2021-3580SUSE-SU-2021:2143-1
- Also known as
- USN-4990-1
Charts affected
261 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| istio-ingresstemp-charts | 0.3.3 | 1 of 1See more | 10,514 |
| pagestest4322 | 1.0.0 | 2 of 3See more | 20,190 |
| standard-applicationthebitgram | 1.0.12 | 1 of 1See more | 11,007 |
| trafficlight-apithecampagnards | 0.1.1 | 1 of 1See more | 4,357 |
| pagesthiru-pages | 1.0.0 | 2 of 3See more | 20,190 |
| pagesthuy-pages | 1.0.0 | 2 of 3See more | 20,190 |
| lightstepupdater-lightstep-satellite | 1.2.2 | 1 of 1See more | 15,330 |
| pagesvictor-pages | 1.0.0 | 2 of 3See more | 20,190 |
| pageswalter | 1.0.0 | 2 of 3See more | 20,190 |
| emissary-ingresswenerme | 8.12.2 | 1 of 2See more | 10,843 |
| sambawenerme | 1.0.0 | 1 of 1See more | 2,555 |
Container images carrying it
167 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 6a1432b0d503 | libnettle | 3.4.1-4.18.1 | 1 |
| ghcr.io/ | f059af4de8ed | libnettle | 3.4.1-4.18.1 | 1 |
| ghcr.io/ | c7c70b527255 | libnettle | 3.4.1-4.18.1 | 1 |
| ghcr.io/ | e24a9e0a21b6 | libnettle | 3.4.1-4.18.1 | 1 |
| ghcr.io/ | 5c6b8f91f1c4 | nettle | 3.5.1+really3.5.1-2ubuntu0.2 | 1 |
| ghcr.io/ | cbd5d4cc1245 | nettle | 3.5.1+really3.5.1-2ubuntu0.2 | 1 |
| ghcr.io/ | ef3670f7e0a8 | nettle | 3.5.1+really3.5.1-2ubuntu0.2 | 1 |
| ghcr.io/ | ad943e9309e4 | nettle | 3.5.1+really3.5.1-2ubuntu0.2 | 1 |
| ghcr.io/ | c2d6e775db5a | nettle | 3.5.1+really3.5.1-2ubuntu0.2 | 1 |
| ghcr.io/ | 448045c4270b | nettle | 3.5.1+really3.5.1-2ubuntu0.2 | 1 |
| public.ecr.aws/ | 573779e57fae | nettle | 3.5.1+really3.5.1-2ubuntu0.2 | 1 |
| quay.io/ | a1c3843b03bc | nettle | no fix listed | 1 |
| quay.io/ | c6a934439421 | nettle | no fix listed | 1 |
| quay.io/ | 3207f957e80c | nettle | 3.7.3-r0 | 1 |
| quay.io/ | 4b188259267e | nettle | 3.7.3-r0 | 1 |
| quay.io/ | cad83090c58f | nettle | 3.5.1-r2 | 1 |
| registry.gitlab.com/ | f6385712935f | nettle | 3.5.1+really3.5.1-2ubuntu0.2 | 1 |