CVE-2026-33811
HighAdvisory
Published 7 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.008
- 55th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 4,006
- of 17,805 indexed, latest versions
- Container images
- 4,576
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
Red Hat Security Advisory: git-lfs security update
Carried by container images the latest versions of 4,006 of 17,805 indexed charts deploy, on 4,576 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| git-lfsrpm | 2.13.3-3.el8_6 | 0:3.4.1-12.el8_10 | 1 |
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+180 more | 1.25.10 | 4,576 |
- OSV records
- DEBIAN-CVE-2026-33811RHSA-2026:39266GO-2026-4981
- Also known as
- BIT-golang-2026-33811
Charts affected
4,006 by stars
Container images carrying it
4,576 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.k8s.io/ | 5baeb4a6d7d5 | stdlib | 1.25.10 | 2 |
| registry.k8s.io/ | 9b75b9ade162 | stdlib | 1.25.10 | 2 |
| registry.k8s.io/ | cacee2b5c36d | stdlib | 1.25.10 | 2 |
| registry.k8s.io/ | 12c2da094b02 | stdlib | 1.25.10 | 2 |
| 0xpolygon/ | 396d3de26d8b | stdlib | 1.25.10 | 1 |
| 0xpolygon/ | 34ddf259993c | stdlib | 1.25.10 | 1 |
| 1dev/ | cd5b12fe5471 | stdlib | 1.25.10 | 1 |
| 1password/ | 6aa94cf713f9 | stdlib | 1.25.10 | 1 |
| 1password/ | e915c0c84397 | stdlib | 1.25.10 | 1 |
| 1password/ | 6297ca6136c0 | stdlib | 1.25.10 | 1 |
| 1password/ | fe527ed9d81f | stdlib | 1.25.10 | 1 |
| 1password/ | 5884757f7879 | stdlib | 1.25.10 | 1 |
| aavishay/ | 3d7c4d79595c | stdlib | 1.25.10 | 1 |
| abiondevelopment/ | c741988fbd23 | stdlib | 1.25.10 | 1 |
| abohatyrenko/ | fa98af15a13e | stdlib | 1.25.10 | 1 |
| aboogie/ | 9c41a4483ac8 | stdlib | 1.25.10 | 1 |
| absaoss/ | ad538a1285a0 | stdlib | 1.25.10 | 1 |
| activepieces/ | 58414dfc94c4 | stdlib | 1.25.10 | 1 |
| adguard/ | 3a143e6c071c | stdlib | 1.25.10 | 1 |
| adguard/ | 43ec119419a9 | stdlib | 1.25.10 | 1 |
| adguard/ | 5d5e3aef39a8 | stdlib | 1.25.10 | 1 |
| adguard/ | 7fbf01d73ecb | stdlib | 1.25.10 | 1 |
| adguard/ | b9974aed13d0 | stdlib | 1.25.10 | 1 |
| adguard/ | c64a0b37f7b9 | stdlib | 1.25.10 | 1 |
| adguard/ | d765078d2140 | stdlib | 1.25.10 | 1 |
| adrianberger/ | 76848c0d2780 | stdlib | 1.25.10 | 1 |
| adyanth/ | 6b168dc237d5 | stdlib | 1.25.10 | 1 |
| aerokube/ | da76ca51220d | stdlib | 1.25.10 | 1 |
| aerokube/ | 6b6323e75785 | stdlib | 1.25.10 | 1 |
| aerokube/ | 3f3e299509fd | stdlib | 1.25.10 | 1 |
| aerospike/ | be40d709c583 | stdlib | 1.25.10 | 1 |
| afgane/ | 457173db5640 | stdlib | 1.25.10 | 1 |
| agentarea/ | efe23cef3727 | stdlib | 1.25.10 | 1 |
| agentarea/ | d3c209a5d531 | stdlib | 1.25.10 | 1 |
| aibrix/ | 76aabbbfda79 | stdlib | 1.25.10 | 1 |
| aibrix/ | 5b93ea4c753a | stdlib | 1.25.10 | 1 |
| airbyte/ | 00cc017f0393 | stdlib | 1.25.10 | 1 |
| airbyte/ | fdae972eaf0e | stdlib | 1.25.10 | 1 |
| airbyte/ | 98d2c39d512e | stdlib | 1.25.10 | 1 |
| ajilaag/ | ad689c7b75b1 | stdlib | 1.25.10 | 1 |
| akeyless/ | 4ba8900a0061 | stdlib | 1.25.10 | 1 |
| aktosecurity/ | 853e37321e6e | stdlib | 1.25.10 | 1 |
| aktosecurity/ | 12ed2544756f | stdlib | 1.25.10 | 1 |
| aktosecurity/ | 1a1bc76d50fe | stdlib | 1.25.10 | 1 |
| aktosecurity/ | fcf8be10bead | stdlib | 1.25.10 | 1 |
| alazidis/ | 602d4f7f090c | stdlib | 1.25.10 | 1 |
| alcounit/ | 93b7cdbab14b | stdlib | 1.25.10 | 1 |
| alcounit/ | 4bd10defc324 | stdlib | 1.25.10 | 1 |
| alcounit/ | 6a977c92ef27 | stdlib | 1.25.10 | 1 |
| alcounit/ | d01a9dbbd943 | stdlib | 1.25.10 | 1 |