StackRadar

CVE-2021-44716

Unscored

Advisory

Published 15 Jul 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
898
of 17,787 indexed, latest versions
Container images
946
deployed by those charts
Fix available
2 of 2
affected packages

Unbounded memory growth in net/http and golang.org/x/net/http2

Carried by container images the latest versions of 898 of 17,787 indexed charts deploy, on 946 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+57 more1.16.12796
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+116 more0.0.0-20211209124913-491a49abca63746
OSV records
GO-2022-0288
Also known as
BIT-golang-2021-44716, GHSA-vc3p-29h2-gpcp

Charts affected

898 by stars
ChartLatestAffected imagesRadar Score
prometheus-node-exporterprometheus-worawutchan1.12.01 of 1See more

prometheus-node-exporter prometheus-worawutchan 1.12.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,188
prometheus-pushgatewayprometheus-worawutchan1.5.01 of 1See more

prometheus-pushgateway prometheus-worawutchan 1.5.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.16.12

Open the chart page →

1,285
prometheus-redis-exporterprometheus-worawutchan4.0.01 of 1See more

prometheus-redis-exporter prometheus-worawutchan 4.0.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.11.104d958d209ab
stdlib@go1.15
1.16.12

Open the chart page →

1,315
prometheus-statsd-exporterprometheus-worawutchan0.1.01 of 1See more

prometheus-statsd-exporter prometheus-worawutchan 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.16.12

Open the chart page →

1,315
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

8,725
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,510
kspanpuckpuck0.2.41 of 1See more

kspan puckpuck 0.2.4

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.0.0-20211209124913-491a49abca63

Open the chart page →

1,681
seashellpuckpuck1.2.01 of 1See more

seashell puckpuck 1.2.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/puckpuck/seashell:1.2ef5e31333821
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.0.0-20211209124913-491a49abca63

Open the chart page →

4,215
loki-stackpyalive-cdmswebappVerified publisher2.6.51 of 4See more

loki-stack pyalive-cdmswebapp 2.6.5

1 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.17.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

6,525
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.3
0.0.0-20211209124913-491a49abca63
1.16.12
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.4
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

11,942
quarksquarks7.0.1+0.g5396b114 of 5See more

quarks quarks 7.0.1+0.g5396b11

4 of the 5 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.7
0.0.0-20211209124913-491a49abca63
1.16.12
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.13.15
0.0.0-20211209124913-491a49abca63
1.16.12
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.14.7
0.0.0-20211209124913-491a49abca63
1.16.12
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.7
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

18,197
quarks-statefulsetquarks0.0.1304-g4b4f2ac51 of 1See more

quarks-statefulset quarks 0.0.1304-g4b4f2ac5

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.7
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

4,010
saleorrc-helm-charts0.1.11 of 5See more

saleor rc-helm-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.22.0ca6b73330616
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15.8
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,738
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.14
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

15,291
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.14
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

15,291
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

11,437
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.16
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

29,227
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
reportportal/migrations:5.7.0da5d8e1395fe
golang.org/x/net@v0.0.0-20190424112056-4829fb13d2c6
stdlib@go1.13.6
0.0.0-20211209124913-491a49abca63
1.16.12
reportportal/service-index:5.0.112b27a2d7a87d
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.17.1
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

25,737
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

7,491
whoamirgnu1.0.01 of 1See more

whoami rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
traefik/whoami:v1.6.0d38496bf0900
stdlib@go1.15.2
1.16.12

Open the chart page →

1,229
security-sample-chartrimusz0.2.11 of 3See more

security-sample-chart rimusz 0.2.1

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
rimusz/security-sample-app:0.2.0b9a178ca76ef
stdlib@go1.14.4
1.16.12

Open the chart page →

1,348
rke2-calicorke2-charts3.18.1-1011 of 1See more

rke2-calico rke2-charts 3.18.1-101

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.15.1c6591da87aa8
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,250
rke2-canal-1.19-1.20rke2-charts3.13.3-build20211022022 of 2See more

rke2-canal-1.19-1.20 rke2-charts 3.13.3-build2021102202

2 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.0.0-20211209124913-491a49abca63
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.0.0-20211209124913-491a49abca63

Open the chart page →

5,942
kubernetes-diff-loggerrlex0.1.21 of 1See more

kubernetes-diff-logger rlex 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
grafana/kubernetes-diff-logger:0.0.598f6d1cd1e25
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,454
runtimeclass-controllerrlex0.1.01 of 1See more

runtimeclass-controller rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
ghcr.io/jlclx/runtimeclass-controller:latestb3a87f92a963
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.0.0-20211209124913-491a49abca63

Open the chart page →

2,155
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.0.0-20211209124913-491a49abca63

Open the chart page →

3,051
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.0.0-20211209124913-491a49abca63

Open the chart page →

5,422
argocdromholdings1.8.12 of 3See more

argocd romholdings 1.8.1

2 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
stdlib@go1.14.12
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.9
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

10,466
calicoromholdings0.1.14 of 4See more

calico romholdings 0.1.1

4 of the 4 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.16.12

Open the chart page →

10,071
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.0.0-20211209124913-491a49abca63

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.05 of 28See more

devtron-enterprise romholdings 48.0.0

5 of the 28 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.15
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.0.0-20211209124913-491a49abca63
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.16.12
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.0.0-20211209124913-491a49abca63

Open the chart page →

68,240
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

5,039
devtron-operatorromholdings0.23.33 of 11See more

devtron-operator romholdings 0.23.3

3 of the 11 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.0.0-20211209124913-491a49abca63
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.0.0-20211209124913-491a49abca63

Open the chart page →

32,902
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

11,909
kube-prometheus-stackromholdings19.3.03 of 6See more

kube-prometheus-stack romholdings 19.3.0

3 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

8,645
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
stdlib@go1.16.10
1.16.12

Open the chart page →

2,435
operatorrookout0.0.201 of 2See more

operator rookout 0.0.20

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
rookout/k8s-operator:latest0d083f3ef1a7
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,209
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
stdlib@go1.16.7
1.16.12

Open the chart page →

6,890
caddysagikazarmarkVerified publisher0.0.141 of 1See more

caddy sagikazarmark 0.0.14

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/caddy:2.4.5874405536b3e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,960
hellowsamarthya2.0.01 of 1See more

hellow samarthya 2.0.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
samarthya/spinnaker:v1.0ef06d81036af
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
0.0.0-20211209124913-491a49abca63

Open the chart page →

2,121
ed-traefikscaleway-charts0.2.01 of 1See more

ed-traefik scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/traefik:v1.7.345d47b7bb2546
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.0.0-20211209124913-491a49abca63

Open the chart page →

2,133
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
stdlib@go1.17
1.16.12

Open the chart page →

5,582
icinga2-masterschmitzis0.2.01 of 6See more

icinga2-master schmitzis 0.2.0

1 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
grafana/grafana:8.0.3696823fbc561
golang.org/x/net@v0.0.0-20210521195947-fe42d452be8f
stdlib@go1.16.1
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,731
version-checkerschmitzis0.2.21 of 1See more

version-checker schmitzis 0.2.2

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,023
openldapschoolguys-helmcharts0.1.31 of 1See more

openldap schoolguys-helmcharts 0.1.3

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,313
cernboxsciencebox0.0.41 of 6See more

cernbox sciencebox 0.0.4

1 of the 6 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
stdlib@go1.17.3
1.16.12

Open the chart page →

2,330
ldap-instance-configsciencebox0.0.11 of 1See more

ldap-instance-config sciencebox 0.0.1

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

3,313
centralbrainsciencemeshVerified publisher0.0.34 of 5See more

centralbrain sciencemesh 0.0.3

4 of the 5 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
grafana/grafana:7.3.315b977f5207d
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.0.0-20211209124913-491a49abca63
1.16.12
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.16.12
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.0.0-20211209124913-491a49abca63
1.16.12
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

9,754
searchpesearchpe4.1.01 of 2See more

searchpe searchpe 4.1.0

1 of the 2 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.16.12

Open the chart page →

2,637
aws-secretssecretsprovider0.1.01 of 1See more

aws-secrets secretsprovider 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-44716.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r1-10-g1942553-2021.06.04.00.07-linux-amd64b32c99e7bc45
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.8
0.0.0-20211209124913-491a49abca63
1.16.12

Open the chart page →

2,213

Container images carrying it

946 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.14.12
0.0.0-20211209124913-491a49abca63
1.16.12
2
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.0.0-20211209124913-491a49abca63
1.16.12
2
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.0.0-20211209124913-491a49abca63
2
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.0.0-20211209124913-491a49abca63
1.16.12
2
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
stdlib@go1.17.3
1.16.12
2
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
stdlib@go1.17.3
1.16.12
2
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.0.0-20211209124913-491a49abca63
1.16.12
2
absaoss/terraform-controller:v0.0.20ad538a1285a0
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.14.8
0.0.0-20211209124913-491a49abca63
1.16.12
1
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
alex6021710/ai-scale-auth:latest6c7a47e470c3
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.17.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
alex6021710/ai-scale-doer:latest31e533cf7cd3
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.16.10
0.0.0-20211209124913-491a49abca63
1.16.12
1
alex6021710/ai-scale-migrator:latest744b8a924f35
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
alex6021710/ai-scale-provider:latest5837d9b30cc7
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.15.8
0.0.0-20211209124913-491a49abca63
1.16.12
1
alex6021710/ai-scale-saver:latestf73e8d60fd03
golang.org/x/net@v0.0.0-20211105192438-b53810dc28af
stdlib@go1.17
0.0.0-20211209124913-491a49abca63
1.16.12
1
almir/webhook:2.8.01698346f6077
stdlib@go1.14.7
1.16.12
1
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.15
0.0.0-20211209124913-491a49abca63
1.16.12
1
alpine/git:2.36.366b210a97bc0
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.0.0-20211209124913-491a49abca63
1
alpine/k8s:1.22.600ac10bcb759
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12
1
alpine/k8s:1.18.16a41efe02a041
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.0.0-20211209124913-491a49abca63
1.16.12
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.0.0-20211209124913-491a49abca63
1
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.13.15
0.0.0-20211209124913-491a49abca63
1.16.12
1
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.13.15
0.0.0-20211209124913-491a49abca63
1.16.12
1
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.0.0-20211209124913-491a49abca63
1.16.12
1
amazon/aws-fsx-csi-driver:latestc9b14856fd22
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.0.0-20211209124913-491a49abca63
1.16.12
1
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.15
0.0.0-20211209124913-491a49abca63
1.16.12
1
anchore/anchore-engine:v0.10.0bde9eedf639d
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.16.3
0.0.0-20211209124913-491a49abca63
1.16.12
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.0.0-20211209124913-491a49abca63
1.16.12
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.16.12
1
apache/apisix-dashboard:2.9.0c010ea7d1694
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.15
0.0.0-20211209124913-491a49abca63
1.16.12
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.13.8
0.0.0-20211209124913-491a49abca63
1.16.12
1
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.0.0-20211209124913-491a49abca63
1.16.12
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.0.0-20211209124913-491a49abca63
1.16.12
1
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.0.0-20211209124913-491a49abca63
1.16.12
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.0.0-20211209124913-491a49abca63
1.16.12
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.0.0-20211209124913-491a49abca63
1.16.12
1
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.0.0-20211209124913-491a49abca63
1
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.0.0-20211209124913-491a49abca63
1
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.0.0-20211209124913-491a49abca63
1
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.0.0-20211209124913-491a49abca63
1
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.13
1.16.12
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.0.0-20211209124913-491a49abca63
1
bedag/goblackhole:0.2.0447a88598f4c
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.6
0.0.0-20211209124913-491a49abca63
1.16.12
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.16.12
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
stdlib@go1.16.7
1.16.12
1
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.0.0-20211209124913-491a49abca63
1.16.12
1
bitnamilegacy/mongodb:5.0.103bb1deeaf9d0
stdlib@go1.16.7
1.16.12
1
bitnamilegacy/mongodb:3.6.213e51da56fc54
stdlib@go1.15.1
1.16.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.