CVE-2026-25679
HighAdvisory
Published 6 Mar 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.007
- 53rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,789
- of 17,813 indexed, latest versions
- Container images
- 4,301
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: git-lfs security update
Carried by container images the latest versions of 3,789 of 17,813 indexed charts deploy, on 4,301 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| go-rpm-macrosrpm | 3.2.0-3.el9, 3.6.0-13.el9_7 | 0:3.6.0-14.el9_7 | 4 |
| git-lfsrpm | 2.13.3-3.el8_6 | 0:2.13.3-3.el8_6.7 | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+176 more | 1.25.8 | 4,298 |
- OSV records
- RHSA-2026:20582RHSA-2026:8841RLSA-2026:8841GO-2026-4601
- Also known as
- BIT-golang-2026-25679
Charts affected
3,789 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
4,301 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| aerokube/ | da76ca51220d | stdlib | 1.25.8 | 1 |
| aerokube/ | 6b6323e75785 | stdlib | 1.25.8 | 1 |
| aerokube/ | 3f3e299509fd | stdlib | 1.25.8 | 1 |
| aerospike/ | be40d709c583 | stdlib | 1.25.8 | 1 |
| afgane/ | 457173db5640 | stdlib | 1.25.8 | 1 |
| agentarea/ | efe23cef3727 | stdlib | 1.25.8 | 1 |
| agentarea/ | d3c209a5d531 | stdlib | 1.25.8 | 1 |
| aibrix/ | 76aabbbfda79 | stdlib | 1.25.8 | 1 |
| aibrix/ | 5b93ea4c753a | stdlib | 1.25.8 | 1 |
| airbyte/ | 00cc017f0393 | stdlib | 1.25.8 | 1 |
| airbyte/ | fdae972eaf0e | stdlib | 1.25.8 | 1 |
| airbyte/ | 98d2c39d512e | stdlib | 1.25.8 | 1 |
| ajilaag/ | ad689c7b75b1 | stdlib | 1.25.8 | 1 |
| akeyless/ | 4ba8900a0061 | stdlib | 1.25.8 | 1 |
| aktosecurity/ | 853e37321e6e | stdlib | 1.25.8 | 1 |
| aktosecurity/ | 12ed2544756f | stdlib | 1.25.8 | 1 |
| aktosecurity/ | 1a1bc76d50fe | stdlib | 1.25.8 | 1 |
| alazidis/ | 602d4f7f090c | stdlib | 1.25.8 | 1 |
| alcounit/ | 93b7cdbab14b | stdlib | 1.25.8 | 1 |
| alcounit/ | 4bd10defc324 | stdlib | 1.25.8 | 1 |
| alcounit/ | 6a977c92ef27 | stdlib | 1.25.8 | 1 |
| alcounit/ | d01a9dbbd943 | stdlib | 1.25.8 | 1 |
| alex6021710/ | 6c7a47e470c3 | stdlib | 1.25.8 | 1 |
| alex6021710/ | 31e533cf7cd3 | stdlib | 1.25.8 | 1 |
| alex6021710/ | 744b8a924f35 | stdlib | 1.25.8 | 1 |
| alex6021710/ | 5837d9b30cc7 | stdlib | 1.25.8 | 1 |
| alex6021710/ | f73e8d60fd03 | stdlib | 1.25.8 | 1 |
| allegroai/ | 772827a01bb5 | stdlib | 1.25.8 | 1 |
| almasood/ | 6ffac9b63cdf | stdlib | 1.25.8 | 1 |
| almir/ | 1698346f6077 | stdlib | 1.25.8 | 1 |
| almorgv/ | 5f2a7d2b44d8 | stdlib | 1.25.8 | 1 |
| alpine/ | 062a01ad7a0e | stdlib | 1.25.8 | 1 |
| alpine/ | 66b210a97bc0 | stdlib | 1.25.8 | 1 |
| alpine/ | c0280cf95723 | stdlib | 1.25.8 | 1 |
| alpine/ | 105741fa6621 | stdlib | 1.25.8 | 1 |
| alpine/ | 905a068da431 | stdlib | 1.25.8 | 1 |
| alpine/ | 00ac10bcb759 | stdlib | 1.25.8 | 1 |
| alpine/ | 21b24e6bf801 | stdlib | 1.25.8 | 1 |
| alpine/ | 44ef4942e171 | stdlib | 1.25.8 | 1 |
| alpine/ | 6dbe6f391eda | stdlib | 1.25.8 | 1 |
| alpine/ | 7a319b15cfc9 | stdlib | 1.25.8 | 1 |
| alpine/ | 7e1e7d5b7a96 | stdlib | 1.25.8 | 1 |
| alpine/ | 9c4976d47656 | stdlib | 1.25.8 | 1 |
| alpine/ | a41efe02a041 | stdlib | 1.25.8 | 1 |
| alpine/ | b421c2e9419e | stdlib | 1.25.8 | 1 |
| alpine/ | b7a12c5ddf26 | stdlib | 1.25.8 | 1 |
| alpine/ | bd01dae02676 | stdlib | 1.25.8 | 1 |
| alpine/ | cd560fce90f7 | stdlib | 1.25.8 | 1 |
| alpine/ | d870622d0040 | stdlib | 1.25.8 | 1 |
| alpine/ | e5c0b053fed7 | stdlib | 1.25.8 | 1 |