StackRadar

CVE-2021-44716

Unscored

Advisory

Published 15 Jul 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
901
of 17,787 indexed, latest versions
Container images
950
deployed by those charts
Fix available
2 of 2
affected packages

Unbounded memory growth in net/http and golang.org/x/net/http2

Carried by container images the latest versions of 901 of 17,787 indexed charts deploy, on 950 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+57 more1.16.12797
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+116 more0.0.0-20211209124913-491a49abca63750
OSV records
GO-2022-0288
Also known as
BIT-golang-2021-44716, GHSA-vc3p-29h2-gpcp

Charts affected

901 by stars
ChartLatestAffected imagesRadar Score
nfs-subdir-external-provisionernfs-subdir-external-provisioner4.0.181 of 1See more

nfs-subdir-external-provisioner nfs-subdir-external-provisioner 4.0.18

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,745
nfs-server-provisionerkvaps1.8.01 of 1See more

nfs-server-provisioner kvaps 1.8.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,315
terraformhashicorpVerified publisher1.1.21 of 1See more

terraform hashicorp 1.1.2

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.0.0-20211209124913-491a49abca63

Open the chart page →

2,059
chaos-meshchaos-meshVerified publisher2.8.41 of 4See more

chaos-mesh chaos-mesh 2.8.4

1 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.0.0-20211209124913-491a49abca63

Open the chart page →

6,362
vclusterloftVerified publisher0.0.0-ci.31 of 2See more

vcluster loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.0.0-20211209124913-491a49abca63

Open the chart page →

2,453
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.0.0-20211209124913-491a49abca63

Open the chart page →

32,353
nacosygqygq2Verified publisher2.1.101 of 4See more

nacos ygqygq2 2.1.10

1 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.16.12

Open the chart page →

4,984
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,086
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,159
oncallgrafana1.16.55 of 12See more

oncall grafana 1.16.5

5 of the 12 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20211209124913-491a49abca63
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20211209124913-491a49abca63
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20211209124913-491a49abca63
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20211209124913-491a49abca63
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

16,251
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

11,402
zabbixcetic3.1.31 of 5See more

zabbix cetic 3.1.3

1 of the 5 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20211209124913-491a49abca63

Open the chart page →

33,907
chatwootchatwootVerified publisher2.0.242 of 3See more

chatwoot chatwoot 2.0.24

2 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.16.7
1.16.12
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
stdlib@go1.16.7
1.16.12

Open the chart page →

9,204
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,918
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.16.12

Open the chart page →

7,706
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,039
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

6,219
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
stdlib@go1.17.1
1.16.12

Open the chart page →

6,040
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

6,853
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

5,173
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
stdlib@go1.17.1
1.16.12

Open the chart page →

3,004
kube-prometheuschoerodon9.3.14 of 7See more

kube-prometheus choerodon 9.3.1

4 of the 7 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.0.0-20211209124913-491a49abca63
1.16.12
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
stdlib@go1.13.11
0.0.0-20211209124913-491a49abca63
1.16.12
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
stdlib@go1.13.4
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

12,237
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,896
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,412
dex-k8s-authenticatorsagikazarmarkVerified publisher0.0.31 of 1See more

dex-k8s-authenticator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,791
kubeviewcowboysysopVerified publisher6.0.01 of 1See more

kubeview cowboysysop 6.0.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

1,513
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.16.12

Open the chart page →

4,577
devtron-operatordevtron0.23.33 of 11See more

devtron-operator devtron 0.23.3

3 of the 11 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.0.0-20211209124913-491a49abca63
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.0.0-20211209124913-491a49abca63

Open the chart page →

31,447
temporallemontechVerified publisher0.37.05 of 13See more

temporal lemontech 0.37.0

5 of the 13 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.0.0-20211209124913-491a49abca63
1.16.12
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.16.12
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

14,893
netris-controllernetrisai2.8.23 of 14See more

netris-controller netrisai 2.8.2

3 of the 14 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.11
0.0.0-20211209124913-491a49abca63
1.16.12
netrisai/controller-web-session-generator:0.2.0a030a31289f4
stdlib@go1.14.15
1.16.12
netrisai/mongodb:4.4.4-debian-10-r095abfb776bb4
stdlib@go1.15.1
1.16.12

Open the chart page →

30,481
nfs-server-provisionernfs-ganesha-server-and-external-provisioner1.8.01 of 1See more

nfs-server-provisioner nfs-ganesha-server-and-external-provisioner 1.8.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,315
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12
platform9community/api-gateway:latest40a4970de568
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12
platform9community/customers-service:latest2089811e5cc6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.11
0.0.0-20211209124913-491a49abca63
1.16.12
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

41,902
helm-exportersstarcher0.5.01 of 1See more

helm-exporter sstarcher 0.5.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
sstarcher/helm-exporter:0.5.011769d01ba35
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.6
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,154
passboltcnieg1.1.171 of 2See more

passbolt cnieg 1.1.17

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.16.12

Open the chart page →

3,544
missing-container-metricsmissing-container-metrics0.1.11 of 1See more

missing-container-metrics missing-container-metrics 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,409
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

6,168
cert-manager-webhook-hetznercert-manager-webhook-hetznerVerified publisher0.2.11 of 1See more

cert-manager-webhook-hetzner cert-manager-webhook-hetzner 0.2.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,080
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.5
0.0.0-20211209124913-491a49abca63
1.16.12
library/traefik:2.5.47d0228d19042
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

53,012
csi-wekafsplugincsi-wekafsOfficialVerified publisher0.6.2-01 of 6See more

csi-wekafsplugin csi-wekafs 0.6.2-0

1 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,824
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.0.0-20211209124913-491a49abca63

Open the chart page →

27,358
drone-runner-dockerdroneVerified publisher0.7.01 of 3See more

drone-runner-docker drone 0.7.0

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.0.0-20211209124913-491a49abca63

Open the chart page →

5,674
loadtesterflagger0.39.01 of 1See more

loadtester flagger 0.39.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.0.0-20181017193950-04a2e542c03f
0.0.0-20211209124913-491a49abca63

Open the chart page →

1,760
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.1
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,282
lndfold0.3.152 of 4See more

lnd fold 0.3.15

2 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.0.0-20211209124913-491a49abca63
1.16.12
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

8,834
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

1,738
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
stdlib@go1.15.2
1.16.12

Open the chart page →

6,354
permission-managerkfirfer1.0.71 of 1See more

permission-manager kfirfer 1.0.7

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,266
kubeflowkubeflow1.6.28 of 45See more

kubeflow kubeflow 1.6.2

8 of the 45 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.13
0.0.0-20211209124913-491a49abca63
1.16.12
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/net@v0.0.0-20211205041911-012df41ee64c
0.0.0-20211209124913-491a49abca63
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.0.0-20211209124913-491a49abca63
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.0.0-20211209124913-491a49abca63
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.0.0-20211209124913-491a49abca63
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12
gcr.io/ml-pipeline/mysql:5.7-debiandf28187b5455
stdlib@go1.16.7
1.16.12
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

97,040
openelbkubesphere-stable0.5.02 of 2See more

openelb kubesphere-stable 0.5.0

2 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.0.0-20211209124913-491a49abca63
1.16.12
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,329
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
stdlib@go1.15.1
1.16.12

Open the chart page →

9,300

Container images carrying it

950 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.16.12
1
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.6
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.17
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
stdlib@go1.16.6
1.16.12
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
0.0.0-20211209124913-491a49abca63
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.0.0-20211209124913-491a49abca63
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
0.0.0-20211209124913-491a49abca63
1
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
stdlib@go1.16.7
1.16.12
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.0.0-20211209124913-491a49abca63
1
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.0.0-20181017193950-04a2e542c03f
0.0.0-20211209124913-491a49abca63
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.0.0-20211209124913-491a49abca63
1
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20211209124913-491a49abca63
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.16.12
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
stdlib@go1.17.1
1.16.12
1
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.0.0-20211209124913-491a49abca63
1
ghcr.io/jlclx/runtimeclass-controller:latestb3a87f92a963
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.0.0-20211209124913-491a49abca63
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
stdlib@go1.16.8
1.16.12
1
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.16.12
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
stdlib@go1.15
1.16.12
1
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
stdlib@go1.15
1.16.12
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
stdlib@go1.16.7
1.16.12
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.16.12
1
ghcr.io/k8s-at-home/nullserv:v1.3.00792c7e6d814
stdlib@go1.16.5
1.16.12
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
stdlib@go1.15
1.16.12
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.16.12
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.16.12
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.16.12
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.16.12
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.16.12
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.16.12
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.16.12
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.0.0-20211209124913-491a49abca63
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
stdlib@go1.15.2
1.16.12
1
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.0.0-20211209124913-491a49abca63
1
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15.14
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.15.14
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.14
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.0.0-20211209124913-491a49abca63
1
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.0.0-20211209124913-491a49abca63
1
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.0.0-20211209124913-491a49abca63
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20211209124913-491a49abca63
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.4
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20211209124913-491a49abca63
1
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12
1
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
stdlib@go1.17.3
1.16.12
1
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.6
0.0.0-20211209124913-491a49abca63
1.16.12
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.