StackRadar

CVE-2021-44716

Unscored

Advisory

Published 15 Jul 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
898
of 17,781 indexed, latest versions
Container images
946
deployed by those charts
Fix available
2 of 2
affected packages

Unbounded memory growth in net/http and golang.org/x/net/http2

Carried by container images the latest versions of 898 of 17,781 indexed charts deploy, on 946 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+57 more1.16.12796
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+116 more0.0.0-20211209124913-491a49abca63746
OSV records
GO-2022-0288
Also known as
BIT-golang-2021-44716, GHSA-vc3p-29h2-gpcp

Charts affected

898 by stars
ChartLatestAffected imagesRadar Score
kubefedmesosphere0.5.21 of 1See more

kubefed mesosphere 0.5.2

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
mesosphere/kubefed:proxyurl4fd8889195fe
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,144
kube-oidc-proxymesosphere0.3.41 of 1See more

kube-oidc-proxy mesosphere 0.3.4

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.1
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,144
kudomesosphere0.1.41 of 1See more

kudo mesosphere 0.1.4

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
kudobuilder/controller:v0.9.069072d979708
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

5,682
local-path-provisionermesosphere0.0.221 of 1See more

local-path-provisioner mesosphere 0.0.22

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.0.0-20211209124913-491a49abca63

Open the chart page →

2,317
nfs-server-provisionermesosphere0.6.11 of 1See more

nfs-server-provisioner mesosphere 0.6.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,806
nvidiamesosphere0.4.41 of 2See more

nvidia mesosphere 0.4.4

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
nvidia/dcgm-exporter:2.2.9-2.4.1-ubuntu20.0491b20b66d1cd
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

10,436
prometheus-operatormesosphere12.11.133 of 8See more

prometheus-operator mesosphere 12.11.13

3 of the 8 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.14.12
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

11,689
traefik2mesosphere9.18.01 of 1See more

traefik2 mesosphere 9.18.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
golang.org/x/net@v0.0.0-20210220033124-5f55cee0dc0d
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,341
azuredisk-csi-drivermesosphere-stable0.8.16 of 6See more

azuredisk-csi-driver mesosphere-stable 0.8.1

6 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.4
0.0.0-20211209124913-491a49abca63
1.16.12
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14
0.0.0-20211209124913-491a49abca63
1.16.12
mcr.microsoft.com/oss/kubernetes-csi/csi-node-driver-registrar:v2.0.1fc5d14e9f26f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12
mcr.microsoft.com/oss/kubernetes-csi/livenessprobe:v2.2.0b7d82802cca8
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

14,065
gatekeepermesosphere-stable0.6.111 of 2See more

gatekeeper mesosphere-stable 0.6.11

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,034
gcpdisk-csi-drivermesosphere-stable0.7.31 of 7See more

gcpdisk-csi-driver mesosphere-stable 0.7.3

1 of the 7 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,603
karmamesosphere-stable2.0.31 of 1See more

karma mesosphere-stable 2.0.3

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
lmierzwa/karma:v0.70d417abe7ddb5
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

1,966
kommandermesosphere-stable0.39.219 of 29See more

kommander mesosphere-stable 0.39.2

19 of the 29 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.0.0-20211209124913-491a49abca63
1.16.12
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.16.12
mesosphere/karma:v0.55-d2iq-proxy4693bb4e0814
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.7
0.0.0-20211209124913-491a49abca63
1.16.12
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.14.5
0.0.0-20211209124913-491a49abca63
1.16.12
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.14.5
0.0.0-20211209124913-491a49abca63
1.16.12
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.14.5
0.0.0-20211209124913-491a49abca63
1.16.12
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.14.5
0.0.0-20211209124913-491a49abca63
1.16.12
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.14.5
0.0.0-20211209124913-491a49abca63
1.16.12
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.14.5
0.0.0-20211209124913-491a49abca63
1.16.12
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.13.8
0.0.0-20211209124913-491a49abca63
1.16.12
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12
prom/prometheus:v2.19.2cd134bd4fca0
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.0.0-20211209124913-491a49abca63
1.16.12
thanosio/thanos:v0.19.088276fcd1491
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15.10
0.0.0-20211209124913-491a49abca63
1.16.12
thanosio/thanos:v0.15.0b12d5c31bf5a
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.2
0.0.0-20211209124913-491a49abca63
1.16.12
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.3
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/thanos/thanos:v0.17.1e362f02ed304
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.13.7
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,027
cortexmetakube0.6.01 of 2See more

cortex metakube 0.6.0

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,107
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

8,902
wg-access-servermglants0.4.71 of 1See more

wg-access-server mglants 0.4.7

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.13.8
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,745
gogsmhio0.9.21 of 2See more

gogs mhio 0.9.2

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
gogs/gogs:0.12.1420d53bb7277
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.7
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,230
pulsarv2milvus-helm2.7.82 of 4See more

pulsarv2 milvus-helm 2.7.8

2 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

15,855
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.17.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

6,085
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.13
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,847
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,775
echoperatormmontesVerified publisher0.0.21 of 1See more

echoperator mmontes 0.0.2

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20211209124913-491a49abca63

Open the chart page →

1,826
mariadbmmontesVerified publisher0.3.01 of 1See more

mariadb mmontes 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/mariadb:10.7.307e06f2e7ae9
stdlib@go1.16.7
1.16.12

Open the chart page →

10,065
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.16.12

Open the chart page →

7,109
basic-git-servermoikot0.0.21 of 1See more

basic-git-server moikot 0.0.2

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
moikot/basic-git-server:0.0.20d941bd30ffa
stdlib@go1.14.9
1.16.12

Open the chart page →

2,954
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,547
smartthings-metricsmoikot0.1.01 of 1See more

smartthings-metrics moikot 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:0.1.08625f53aa9b7
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.13
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

1,744
smartthings-metrics-feat-log-detailsmoikot0.0.921 of 1See more

smartthings-metrics-feat-log-details moikot 0.0.92

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:feat-log-detailsfb8565140106
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

1,732
backendmojaloop0.1.03 of 6See more

backend mojaloop 0.1.0

3 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
stdlib@go1.16.7
1.16.12
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.0.0-20211209124913-491a49abca63
1.16.12
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

16,198
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.14.0d55e056987af
stdlib@go1.15.6
1.16.12

Open the chart page →

25,933
chirpstack-event-forwardmosquitto-helm-chart0.1.21 of 1See more

chirpstack-event-forward mosquitto-helm-chart 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.0.0-20211209124913-491a49abca63

Open the chart page →

1,854
replacermosquitto-helm-chart0.2.01 of 3See more

replacer mosquitto-helm-chart 0.2.0

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.0.0-20211209124913-491a49abca63

Open the chart page →

3,929
configmapsecretsmozilla0.0.11 of 1See more

configmapsecrets mozilla 0.0.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.1
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,109
approuvezmvisonneau0.1.11 of 1See more

approuvez mvisonneau 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.15.6
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

1,971
authmyaVerified publisher22.4.31 of 1See more

auth mya 22.4.3

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,374
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.0.0-20211209124913-491a49abca63

Open the chart page →

3,359
Practica_4_helmmy-heml-appVerified publisher0.1.02 of 7See more

Practica_4_helm my-heml-app 0.1.0

2 of the 7 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.16.12
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.16.12

Open the chart page →

27,721
victoria-metrics-singlenaps0.0.61 of 1See more

victoria-metrics-single naps 0.0.6

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
victoriametrics/victoria-metrics:v1.34.7b50d5c0153f9
stdlib@go1.14.1
1.16.12

Open the chart page →

1,315
traefik-forward-auth-openidnas-helm-chartsVerified publisher1.0.11 of 1See more

traefik-forward-auth-openid nas-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:latestb364aa6a4117
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,197
nats-operatornatsVerified publisher0.8.31 of 1See more

nats-operator nats 0.8.3

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
natsio/nats-operator:0.8.31261dae38389
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,352
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:4.4.5e3c9d6b4bc92
stdlib@go1.15.8
1.16.12

Open the chart page →

15,369
iamdnetsocVerified publisher0.6.11 of 2See more

iamd netsoc 0.6.1

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.6
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,890
shhdnetsocVerified publisher0.1.71 of 1See more

shhd netsoc 0.1.7

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.17
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,986
webspacednetsocVerified publisher0.2.82 of 2See more

webspaced netsoc 0.2.8

2 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.0.0-20211209124913-491a49abca63
1.16.12
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
stdlib@go1.16.8
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

5,193
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.0.0-20211209124913-491a49abca63

Open the chart page →

2,062
nodejsweeklynodejsweekly1.1.01 of 1See more

nodejsweekly nodejsweekly 1.1.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.0.0-20211209124913-491a49abca63

Open the chart page →

1,489
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
robjuz/postgresql-nominatim:latest805c7bab76df
stdlib@go1.16.5
1.16.12

Open the chart page →

22,658
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,527
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.5
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,861

Container images carrying it

946 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.0.0-20211209124913-491a49abca63
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
stdlib@go1.16.10
1.16.12
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.15
0.0.0-20211209124913-491a49abca63
1.16.12
3
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.16.12
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.9
0.0.0-20211209124913-491a49abca63
1.16.12
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.0.0-20211209124913-491a49abca63
1.16.12
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.0.0-20211209124913-491a49abca63
1.16.12
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.0.0-20211209124913-491a49abca63
1.16.12
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.0.0-20211209124913-491a49abca63
1.16.12
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.0.0-20211209124913-491a49abca63
1.16.12
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12
3
1password/scim:v2.3.129d0c6cb67eb
stdlib@go1.16.8
1.16.12
2
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.16.12
2
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
stdlib@go1.15.1
1.16.12
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.16.12
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.0.0-20211209124913-491a49abca63
1.16.12
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.5
0.0.0-20211209124913-491a49abca63
1.16.12
2
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.16.12
2
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.0.0-20211209124913-491a49abca63
1.16.12
2
cs3org/revad:v1.19.03b57a34a7dfd
stdlib@go1.17.3
1.16.12
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.0.0-20211209124913-491a49abca63
2
danielfm/aws-limits-exporter:0.6.07152b84e57cb
stdlib@go1.17.2
1.16.12
2
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12
2
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12
2
eqalpha/keydb:latest6537505c4235
stdlib@go1.16.7
1.16.12
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.16.12
2
friendsofgo/killgrave:0.4.139cfbecca342
stdlib@go1.16.3
1.16.12
2
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.0.0-20211209124913-491a49abca63
1.16.12
2
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.0.0-20211209124913-491a49abca63
2
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.5
0.0.0-20211209124913-491a49abca63
1.16.12
2
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.0.0-20211209124913-491a49abca63
1.16.12
2
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.0.0-20211209124913-491a49abca63
1.16.12
2
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.0.0-20211209124913-491a49abca63
2
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12
2
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.0.0-20211209124913-491a49abca63
1.16.12
2
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.13.8
0.0.0-20211209124913-491a49abca63
1.16.12
2
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12
2
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12
2
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.1
0.0.0-20211209124913-491a49abca63
1.16.12
2
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.7
0.0.0-20211209124913-491a49abca63
1.16.12
2
istio/proxyv2:1.10.3a78b7a165744
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.0.0-20211209124913-491a49abca63
1.16.12
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
stdlib@go1.13.11
0.0.0-20211209124913-491a49abca63
1.16.12
2
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.0.0-20211209124913-491a49abca63
1.16.12
2
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17
0.0.0-20211209124913-491a49abca63
1.16.12
2
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.1
0.0.0-20211209124913-491a49abca63
1.16.12
2
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12
2
library/mariadb:10.8.30abf60f81588
stdlib@go1.16.7
1.16.12
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.