CVE-2026-25679
HighAdvisory
Published 6 Mar 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.007
- 53rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,750
- of 17,803 indexed, latest versions
- Container images
- 4,276
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: git-lfs security update
Carried by container images the latest versions of 3,750 of 17,803 indexed charts deploy, on 4,276 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| go-rpm-macrosrpm | 3.2.0-3.el9, 3.6.0-13.el9_7 | 0:3.6.0-14.el9_7 | 4 |
| git-lfsrpm | 2.13.3-3.el8_6 | 0:2.13.3-3.el8_6.7 | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+176 more | 1.25.8 | 4,273 |
- OSV records
- RHSA-2026:20582RHSA-2026:8841RLSA-2026:8841GO-2026-4601
- Also known as
- BIT-golang-2026-25679
Charts affected
3,750 by stars
Container images carrying it
4,276 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| breton/ | 41b1bb483aa2 | stdlib | 1.25.8 | 1 |
| bsgrigorov/ | 45ab095f09c8 | stdlib | 1.25.8 | 1 |
| btcpayserver/ | e9585b68dc6b | stdlib | 1.25.8 | 1 |
| buddyspencer/ | 6b656f19b0c1 | stdlib | 1.25.8 | 1 |
| buddyspencer/ | 9e7dbf923c12 | stdlib | 1.25.8 | 1 |
| buildkite/ | aec38cfaae0e | stdlib | 1.25.8 | 1 |
| bulich/ | 6d0b780f7c7b | stdlib | 1.25.8 | 1 |
| burganbank/ | 9259c34e4037 | stdlib | 1.25.8 | 1 |
| burningalchemist/ | b8e4757c7def | stdlib | 1.25.8 | 1 |
| bytesafe/ | ee287384c005 | stdlib | 1.25.8 | 1 |
| caarlos0/ | d11dec138900 | stdlib | 1.25.8 | 1 |
| calico/ | cef0c907b8f4 | stdlib | 1.25.8 | 1 |
| calico/ | e486870cfde8 | stdlib | 1.25.8 | 1 |
| calico/ | 8f04e4772a2b | stdlib | 1.25.8 | 1 |
| calico/ | eadb3a25109a | stdlib | 1.25.8 | 1 |
| calico/ | 385bf6391fea | stdlib | 1.25.8 | 1 |
| calico/ | d8c644a8a3ee | stdlib | 1.25.8 | 1 |
| camptocamp/ | acfafc308d88 | stdlib | 1.25.8 | 1 |
| captnbp/ | 1600c5a253e0 | stdlib | 1.25.8 | 1 |
| caroga/ | f3233882b3bd | stdlib | 1.25.8 | 1 |
| casbin/ | 66f836ef778b | stdlib | 1.25.8 | 1 |
| casbin/ | 770ad9ec3190 | stdlib | 1.25.8 | 1 |
| castopod/ | 1fd37280cbb2 | stdlib | 1.25.8 | 1 |
| castopod/ | 4e4f0440520f | stdlib | 1.25.8 | 1 |
| cbeneke/ | dc658078d7ba | stdlib | 1.25.8 | 1 |
| censedata/ | ebfffb9dd4c0 | stdlib | 1.25.8 | 1 |
| cesanta/ | 98e0307e0d2d | stdlib | 1.25.8 | 1 |
| cfcontainerization/ | 82fa261c18a8 | stdlib | 1.25.8 | 1 |
| cfcontainerization/ | 58fb1c173a46 | stdlib | 1.25.8 | 1 |
| cgtysylr/ | aec0f8a38a77 | stdlib | 1.25.8 | 1 |
| chaerr/ | 66833deec017 | stdlib | 1.25.8 | 1 |
| chainflag/ | ac642796bcb6 | stdlib | 1.25.8 | 1 |
| chainsafe/ | 5593f6e97912 | stdlib | 1.25.8 | 1 |
| chainsafe/ | 7b9fe4aa8073 | stdlib | 1.25.8 | 1 |
| chandanteekinavar/ | c96f759b6ce4 | stdlib | 1.25.8 | 1 |
| chaosnative/ | 72ee352bc333 | stdlib | 1.25.8 | 1 |
| chaosnative/ | 62cf6adc355e | stdlib | 1.25.8 | 1 |
| chaosnative/ | e7bcff4a20c0 | stdlib | 1.25.8 | 1 |
| charmcli/ | 39523c1a6ba8 | stdlib | 1.25.8 | 1 |
| chibisafe/ | 3da4fcbc1a18 | stdlib | 1.25.8 | 1 |
| chirpstack/ | e0b23dfd24d6 | stdlib | 1.25.8 | 1 |
| chirpstack/ | fb7667fe037f | stdlib | 1.25.8 | 1 |
| chirpstack/ | ce3f2cdca8a9 | stdlib | 1.25.8 | 1 |
| chirpstack/ | c0bbbb7a3f1e | stdlib | 1.25.8 | 1 |
| chirpstack/ | c98d7fe06bce | stdlib | 1.25.8 | 1 |
| chocobozzz/ | 052712130691 | stdlib | 1.25.8 | 1 |
| chriseaton/ | 54c3384ce701 | stdlib | 1.25.8 | 1 |
| chrislusf/ | 634b094b2183 | stdlib | 1.25.8 | 1 |
| chrislusf/ | ed80f00fde46 | stdlib | 1.25.8 | 1 |
| chriswells0/ | f3918ec8471c | stdlib | 1.25.8 | 1 |