StackRadar

CVE-2026-25679

High

Advisory

Published 6 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,971
of 17,844 indexed, latest versions
Container images
4,474
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 3,971 of 17,844 indexed charts deploy, on 4,474 images.

Affected packageAffected versionsFixed inImages
go-rpm-macrosrpm3.2.0-3.el9, 3.6.0-13.el9_70:3.6.0-14.el9_74
git-lfsrpm2.13.3-3.el8_60:2.13.3-3.el8_6.71
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+178 more1.25.84,471
OSV records
RHSA-2026:20582RHSA-2026:8841RLSA-2026:8841GO-2026-4601
Also known as
BIT-golang-2026-25679

Charts affected

3,971 by stars
ChartLatestAffected imagesRadar Score
ilum-otel-collectorilumVerified publisher0.1.01 of 1See more

ilum-otel-collector ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.113.05ac3e0ba2b0b
stdlib@go1.23.2
1.25.8

Open the chart page →

1,547
plausible-analyticsimioVerified publisher0.4.21 of 5See more

plausible-analytics imio 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
library/postgres:17.6-alpineef257d85f76e
stdlib@go1.24.6
1.25.8

Open the chart page →

11,212
apexkube-agentimprowisedVerified publisher1.4.01 of 2See more

apexkube-agent improwised 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
masipcat/wireguard-go:0.0.20230223769f7bb64694
stdlib@go1.20.14
1.25.8

Open the chart page →

3,483
frigateimprowisedVerified publisher1.1.01 of 1See more

frigate improwised 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
stdlib@go1.20.3
1.25.8

Open the chart page →

2,187
kore-boardimprowisedVerified publisher0.5.83 of 4See more

kore-board improwised 0.5.8

3 of the 4 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.backend:v0.5.5455f6e7a26fd
stdlib@go1.19.4
1.25.8
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
stdlib@go1.19.4
1.25.8
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
stdlib@go1.18.9
1.25.8

Open the chart page →

16,682
fpga-cloudinaccelVerified publisher1.2.23 of 3See more

fpga-cloud inaccel 1.2.2

3 of the 3 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
inaccel/cloud-init:latesta5d3d0af05c1
stdlib@go1.21.6
1.25.8
inaccel/device-selector:latest44b4f274f40b
stdlib@go1.21.9
1.25.8
inaccel/kubevirt-hack:latestbdfd61803a70
stdlib@go1.21.7
1.25.8

Open the chart page →

3,182
fpga-operatorinaccelVerified publisher2.8.23 of 7See more

fpga-operator inaccel 2.8.2

3 of the 7 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
inaccel/daemon:latest093e1ea90ab8
stdlib@go1.21.6
1.25.8
inaccel/mkrt:latest187fd448b6f2
stdlib@go1.21.5
1.25.8
inaccel/reef:latestc967218739f3
stdlib@go1.21.6
1.25.8

Open the chart page →

5,782
infisical-agent-injectorinfisical-charts0.1.121 of 1See more

infisical-agent-injector infisical-charts 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
infisical/infisical-agent-injector:v0.1.12718dd5bee7cb
stdlib@go1.24.13
1.25.8

Open the chart page →

776
infisical-csi-providerinfisical-charts0.2.31 of 1See more

infisical-csi-provider infisical-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
infisical/infisical-csi-provider:v0.0.9e3390e677db6
stdlib@go1.24.13
1.25.8

Open the chart page →

637
infisical-pki-issuerinfisical-charts1.0.01 of 1See more

infisical-pki-issuer infisical-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
infisical/pki-issuer:latestff38294270e3
stdlib@go1.24.13
1.25.8

Open the chart page →

580
chronografinfluxdata1.2.61 of 1See more

chronograf influxdata 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
library/chronograf:1.9.496d8a3f65a4f
stdlib@go1.16.4
1.25.8

Open the chart page →

2,206
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
stdlib@go1.24.13
1.25.8
library/influxdb:1.12.3-datab0f9fc41ed79
stdlib@go1.24.13
1.25.8

Open the chart page →

6,254
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
stdlib@go1.19.3
1.25.8

Open the chart page →

5,028
erigoninfradao0.0.51 of 2See more

erigon infradao 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
testinprod/op-erigon:latest0a125bd77a2d
stdlib@go1.22.12
1.25.8

Open the chart page →

3,032
l2gethinfradao0.0.11 of 1See more

l2geth infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
ethereumoptimism/l2geth:0.5.315577036dc36d
stdlib@go1.18
1.25.8

Open the chart page →

2,659
registry-container-webhookinnagoVerified publisher2.0.21 of 1See more

registry-container-webhook innago 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
ghcr.io/indeedeng/harbor-container-webhook:main45ca15fc294f
stdlib@go1.24.1
1.25.8

Open the chart page →

608
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
stdlib@go1.15.7
1.25.8

Open the chart page →

10,883
lakefsinseefrlab0.0.61 of 2See more

lakefs inseefrlab 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
treeverse/lakefs:0.69.0478f37a6cffc
stdlib@go1.17.8
1.25.8

Open the chart page →

2,668
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
stdlib@go1.13.10
1.25.8

Open the chart page →

7,555
consulintelVerified publisher0.8.12 of 2See more

consul intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
stdlib@go1.19.2
1.25.8
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
stdlib@go1.19.2
1.25.8

Open the chart page →

5,436
evi-consulintelVerified publisher3.0.32 of 2See more

evi-consul intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
stdlib@go1.19.2
1.25.8
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
stdlib@go1.19.2
1.25.8

Open the chart page →

5,436
evi-miniointelVerified publisher3.0.32 of 2See more

evi-minio intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
stdlib@go1.19.4
1.25.8
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
stdlib@go1.19.4
1.25.8

Open the chart page →

7,713
evi-vaultintelVerified publisher3.0.32 of 2See more

evi-vault intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
stdlib@go1.19.2
1.25.8
hashicorp/vault-k8s:1.1.0844337076b72
stdlib@go1.19.3
1.25.8

Open the chart page →

4,484
intel-gaudi-resource-driverintelVerified publisher0.3.01 of 1See more

intel-gaudi-resource-driver intel 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
intel/intel-gaudi-resource-driver:v0.3.0ac758c14c2de
stdlib@go1.23.4
1.25.8

Open the chart page →

575
intel-qat-resource-driverintelVerified publisher0.1.01 of 1See more

intel-qat-resource-driver intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
intel/intel-qat-resource-driver:v0.1.0ac7616986a2b
stdlib@go1.22.4
1.25.8

Open the chart page →

618
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization:3.03426deb77337
stdlib@go1.17.11
1.25.8

Open the chart page →

82,237
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
stdlib@go1.19.3
1.25.8

Open the chart page →

6,179
vaultintelVerified publisher0.8.12 of 2See more

vault intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
stdlib@go1.19.2
1.25.8
hashicorp/vault-k8s:1.1.0844337076b72
stdlib@go1.19.3
1.25.8

Open the chart page →

4,484
gravity-initinvisiblVerified publisher1.0.91 of 1See more

gravity-init invisibl 1.0.9

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
invisibl/gravity-init:v1.0.91a970f84178b
stdlib@go1.17.12
1.25.8

Open the chart page →

2,011
identity-managerinvisiblVerified publisher1.0.01 of 1See more

identity-manager invisibl 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
invisibl/identity-manager:1.0.01029f4fe20eb
stdlib@go1.17.11
1.25.8

Open the chart page →

2,159
identity-manager-demoinvisiblVerified publisher0.1.11 of 1See more

identity-manager-demo invisibl 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
invisibl/identity-manager-demo:v1.0.0cf5400cb935a
stdlib@go1.19.2
1.25.8

Open the chart page →

1,007
karpenteriometeVerified publisher0.19.31 of 1See more

karpenter iomete 0.19.3

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
stdlib@go1.19.3
1.25.8

Open the chart page →

1,557
server-monitoringiserversupport-helm--charts1.0.02 of 2See more

server-monitoring iserversupport-helm--charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
prom/node-exporter:v1.10.23ac34ce007ac
stdlib@go1.25.3
1.25.8
prom/prometheus:v3.8.0d936808bdea5
stdlib@go1.25.4
1.25.8

Open the chart page →

1,316
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
stdlib@go1.20.4
1.25.8

Open the chart page →

5,724
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
stdlib@go1.20.4
1.25.8

Open the chart page →

5,724
istio-ratelimit-operatoristio-ratelimit-operator2.16.11 of 1See more

istio-ratelimit-operator istio-ratelimit-operator 2.16.1

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
zufardhiyaulhaq/istio-ratelimit-operator:v2.15.0692cfc9d6614
stdlib@go1.19.13
1.25.8

Open the chart page →

749
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
stdlib@go1.24.3
1.25.8

Open the chart page →

3,970
daveit-at-mOfficialVerified publisher0.2.171 of 9See more

dave it-at-m 0.2.17

1 of the 9 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
stdlib@go1.24.6
1.25.8

Open the chart page →

13,230
traefikitscontainedVerified publisher9.18.41 of 1See more

traefik itscontained 9.18.4

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
stdlib@go1.16.2
1.25.8

Open the chart page →

3,342
hetzner-dyndnsitsmethemojoVerified publisher1.4.01 of 1See more

hetzner-dyndns itsmethemojo 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
hashicorp/terraform:1.9.7b77efab1a448
stdlib@go1.22.7
1.25.8

Open the chart page →

1,882
thehiveittrident-oss0.1.02 of 6See more

thehive ittrident-oss 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
library/cassandra:4.03a4876cc7f18
stdlib@go1.24.6
1.25.8
minio/minio:latest14cea493d9a3
stdlib@go1.24.6
1.25.8

Open the chart page →

5,928
adguard-homejacobcolvinVerified publisher0.4.01 of 2See more

adguard-home jacobcolvin 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.3843ec119419a9
stdlib@go1.20.8
1.25.8

Open the chart page →

1,602
inlets-clientjacobcolvinVerified publisher0.1.21 of 1See more

inlets-client jacobcolvin 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.25.8

Open the chart page →

1,757
inlets-serverjacobcolvinVerified publisher0.1.11 of 1See more

inlets-server jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.25.8

Open the chart page →

1,757
opencloudjacobcolvinVerified publisher0.2.32 of 13See more

opencloud jacobcolvin 0.2.3

2 of the 13 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.25.8
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
stdlib@go1.24.2
1.25.8

Open the chart page →

46,049
osrs-ge-exporterjacobcolvinVerified publisher0.4.01 of 1See more

osrs-ge-exporter jacobcolvin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
macropower/osrs_ge_exporter:v0.3c77ab5ea955c
stdlib@go1.21.0
1.25.8

Open the chart page →

609
rclonejacobcolvinVerified publisher1.0.11 of 1See more

rclone jacobcolvin 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
rclone/rclone:1.63.008e1af3c8814
stdlib@go1.20.5
1.25.8

Open the chart page →

2,129
twitch-predictions-recorderjacobcolvinVerified publisher0.1.01 of 1See more

twitch-predictions-recorder jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
stdlib@go1.19.2
1.25.8

Open the chart page →

3,160
wakatime-exporterjacobcolvinVerified publisher0.1.11 of 1See more

wakatime-exporter jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
macropower/wakatime-exporter:0.1.0dbb05debb785
stdlib@go1.14.6
1.25.8

Open the chart page →

1,315
wireguard-operatorjacobcolvinVerified publisher0.2.01 of 2See more

wireguard-operator jacobcolvin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-25679.

Container imageDigestPackageFixed in
ghcr.io/jodevsa/wireguard-operator/manager:v2.0.2839412bdd403b
stdlib@go1.22.2
1.25.8

Open the chart page →

836

Container images carrying it

4,474 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.25.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.25.8
1
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
stdlib@go1.24.6
1.25.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.25.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.8
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.8
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.8
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.8
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.8
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.