StackRadar

CVE-2021-44716

Unscored

Advisory

Published 15 Jul 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
901
of 17,787 indexed, latest versions
Container images
950
deployed by those charts
Fix available
2 of 2
affected packages

Unbounded memory growth in net/http and golang.org/x/net/http2

Carried by container images the latest versions of 901 of 17,787 indexed charts deploy, on 950 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+57 more1.16.12797
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+116 more0.0.0-20211209124913-491a49abca63750
OSV records
GO-2022-0288
Also known as
BIT-golang-2021-44716, GHSA-vc3p-29h2-gpcp

Charts affected

901 by stars
ChartLatestAffected imagesRadar Score
aws-fsx-csi-driverkubesphere-testVerified publisher0.1.01 of 4See more

aws-fsx-csi-driver kubesphere-test 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
amazon/aws-fsx-csi-driver:latestc9b14856fd22
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

1,588
cni-hostnickubesphere-testVerified publisher0.1.01 of 1See more

cni-hostnic kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,437
csi-neonsankubesphere-testVerified publisher1.3.06 of 6See more

csi-neonsan kubesphere-test 1.3.0

6 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.0.0-20211209124913-491a49abca63
1.16.12
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.4
0.0.0-20211209124913-491a49abca63
1.16.12
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.0.0-20211209124913-491a49abca63
1.16.12
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.0.0-20211209124913-491a49abca63
1.16.12
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

18,482
csi-qingcloudkubesphere-testVerified publisher1.4.06 of 6See more

csi-qingcloud kubesphere-test 1.4.0

6 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.0.0-20211209124913-491a49abca63
1.16.12
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.0.0-20211209124913-491a49abca63
1.16.12
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.0.0-20211209124913-491a49abca63
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.0.0-20211209124913-491a49abca63
1.16.12
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

12,404
curvefs-csikubesphere-testVerified publisher0.1.01 of 3See more

curvefs-csi kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,824
mongodbkubesphere-testVerified publisher0.3.21 of 2See more

mongodb kubesphere-test 0.3.2

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
mikefarah/yq:2.4.16fc625c402de
stdlib@go1.13.3
1.16.12

Open the chart page →

9,628
online-boutiquekubesphere-testVerified publisher0.1.08 of 11See more

online-boutique kubesphere-test 0.1.0

8 of the 11 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.10
0.0.0-20211209124913-491a49abca63
1.16.12
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.0.0-20211209124913-491a49abca63
1.16.12
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.0.0-20211209124913-491a49abca63
1.16.12
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

26,019
openelbkubesphere-testVerified publisher0.2.42 of 2See more

openelb kubesphere-test 0.2.4

2 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.0.0-20211209124913-491a49abca63
1.16.12
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,329
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,784
snapshot-controllerkubesphere-testVerified publisher0.2.01 of 1See more

snapshot-controller kubesphere-test 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,220
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.1
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

16,537
metadockvalitetsitVerified publisher0.0.72 of 2See more

metadoc kvalitetsit 0.0.7

2 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-app:maine89e351733ad
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.0.0-20211209124913-491a49abca63
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,026
nsp-prometheus-exporterkvalitetsitVerified publisher1.0.191 of 2See more

nsp-prometheus-exporter kvalitetsit 1.0.19

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
kvalitetsit/nsp-prometheus-exporter:1.0.190b397ff954ec
stdlib@go1.15.3
1.16.12

Open the chart page →

2,063
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
golang.org/x/net@v0.0.0-20180906233101-161cd47e91fd
0.0.0-20211209124913-491a49abca63

Open the chart page →

7,842
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

8,534
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
golang.org/x/net@v0.0.0-20200519113804-d87ec0cfa476
stdlib@go1.14
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

26,371
metallblectures-k8sinfra0.10.22 of 2See more

metallb lectures-k8sinfra 0.10.2

2 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.5
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.5
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

5,406
prometheuslectures-k8sinfra15.8.54 of 6See more

prometheus lectures-k8sinfra 15.8.5

4 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.16.12
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

9,092
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,191
prometheusleechistest11.6.04 of 6See more

prometheus leechistest 11.6.0

4 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.0.0-20211209124913-491a49abca63
1.16.12
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.0.0-20211209124913-491a49abca63
1.16.12
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.16.12
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

8,484
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.13.8
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,456
op-scim-bridgelifen1.0.31 of 2See more

op-scim-bridge lifen 1.0.3

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
stdlib@go1.16.8
1.16.12

Open the chart page →

2,777
op-scim-bridgelifen-chartsVerified publisher1.0.31 of 2See more

op-scim-bridge lifen-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
stdlib@go1.16.8
1.16.12

Open the chart page →

2,777
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/net@v0.0.0-20211004195052-b30845b58a23
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,129
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,904
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,510
devspace-cloudloftVerified publisher0.3.32 of 8See more

devspace-cloud loft 0.3.3

2 of the 8 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.0.0-20211209124913-491a49abca63
1.16.12
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.16.12

Open the chart page →

9,880
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.7
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,086
loft-direct-cluster-endpointloftVerified publisher1.14.01 of 1See more

loft-direct-cluster-endpoint loft 1.14.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.6
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,112
vcluster-proloftVerified publisher0.0.0-ci-run.101 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.0.0-20211209124913-491a49abca63

Open the chart page →

5,085
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.101 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

1 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.0.0-20211209124913-491a49abca63

Open the chart page →

5,936
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.101 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

1 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.0.0-20211209124913-491a49abca63

Open the chart page →

8,206
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,986
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,492
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,498
apica-ascentlogiqai2.0.44 of 19See more

apica-ascent logiqai 2.0.4

4 of the 19 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.0.0-20211209124913-491a49abca63
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.7
0.0.0-20211209124913-491a49abca63
1.16.12
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.8
0.0.0-20211209124913-491a49abca63
1.16.12
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.9
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

23,255
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,342
fireflylsst-sqre0.3.71 of 2See more

firefly lsst-sqre 0.3.7

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/redis:5fc5ecd863862
stdlib@go1.16.7
1.16.12

Open the chart page →

1,731
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.17.2
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

9,332
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.5
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

6,623
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.6
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,764
xteveluiscajl0.1.61 of 1See more

xteve luiscajl 0.1.6

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
dnsforge/xteve:latest4d9a685c8c28
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,314
whoamimario-fVerified publisher1.0.11 of 1See more

whoami mario-f 1.0.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
containous/whoami:v1.5.07d6a3c8f9147
stdlib@go1.14
1.16.12

Open the chart page →

1,279
focalboardmattermostVerified publisher0.5.01 of 1See more

focalboard mattermost 0.5.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,014
mattermost-chaos-enginemattermostVerified publisher0.2.01 of 1See more

mattermost-chaos-engine mattermost 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.8
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,067
eoloplantmca-eoloplaner0.1.02 of 7See more

eoloplant mca-eoloplaner 0.1.0

2 of the 7 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.16.12
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.16.12

Open the chart page →

29,712
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,327
memo-componentmemo-component1.0.01 of 3See more

memo-component memo-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,510
flaggermesosphere0.21.02 of 2See more

flagger mesosphere 0.21.0

2 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
weaveworks/flagger:0.19.0a9c2e9df4227
golang.org/x/net@v0.0.0-20190206173232-65e2d4e15006
stdlib@go1.13.1
0.0.0-20211209124913-491a49abca63
1.16.12
weaveworks/flagger-loadtester:0.9.03cdac6928a63
golang.org/x/net@v0.0.0-20190206173232-65e2d4e15006
stdlib@go1.13.1
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

6,048
gatekeepermesosphere0.6.111 of 2See more

gatekeeper mesosphere 0.6.11

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,034

Container images carrying it

950 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
weaveworks/flagger:1.0.0-rc.5174307de1b36
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
weaveworks/flagger:0.19.0a9c2e9df4227
golang.org/x/net@v0.0.0-20190206173232-65e2d4e15006
stdlib@go1.13.1
0.0.0-20211209124913-491a49abca63
1.16.12
1
weaveworks/flagger-loadtester:0.9.03cdac6928a63
golang.org/x/net@v0.0.0-20190206173232-65e2d4e15006
stdlib@go1.13.1
0.0.0-20211209124913-491a49abca63
1.16.12
1
weblate/weblate:3.11.3-182848df56ecd
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.0.0-20211209124913-491a49abca63
1.16.12
1
wener/frpc:v0.37.0cc9fd4da44c0
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12
1
wener/frps:v0.37.05c92cc9e8597
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12
1
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.0.0-20211209124913-491a49abca63
1.16.12
1
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.13
0.0.0-20211209124913-491a49abca63
1.16.12
1
yandex/clickhouse-server:latest1cbf75aabe1e
stdlib@go1.16.7
1.16.12
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20211209124913-491a49abca63
1
zufardhiyaulhaq/kubernetesweekly:v2.1.0a287ada277c6
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.0.0-20211209124913-491a49abca63
1
zufardhiyaulhaq/ngrok-operator:v1.3.07cf2ae3fb1fb
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.0.0-20211209124913-491a49abca63
1
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.0.0-20211209124913-491a49abca63
1
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.13.15
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.5
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.0.0-20211209124913-491a49abca63
1
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.10
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhook873b968f02b5
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator1e3db4f2eeed
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/knative-releases/knative.dev/serving/cmd/activatora5de0fb75046
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler2ef460356b17
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdb6ceff2aab4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller30ce73388ae5
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerb2cd45b8a8a4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookd27b4495ccc3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookf16c0e022203
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.16.5
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12
1
gcr.io/ml-pipeline/mysql:5.7-debiandf28187b5455
stdlib@go1.16.7
1.16.12
1
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
stdlib@go1.16.3
1.16.12
1
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/andylibrian/terjang:latest20a46b199247
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.16.12
1
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.1
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
0.0.0-20211209124913-491a49abca63
1
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
golang.org/x/net@v0.0.0-20170114055629-f2499483f923
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.