StackRadar

CVE-2026-33811

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,079
of 17,828 indexed, latest versions
Container images
4,668
deployed by those charts
Fix available
2 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,079 of 17,828 indexed charts deploy, on 4,668 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-12.el8_101
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,668
OSV records
DEBIAN-CVE-2026-33811RHSA-2026:39266GO-2026-4981
Also known as
BIT-golang-2026-33811

Charts affected

4,079 by stars
ChartLatestAffected imagesRadar Score
fpga-operatorinaccelVerified publisher2.8.23 of 7See more

fpga-operator inaccel 2.8.2

3 of the 7 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
inaccel/daemon:latest093e1ea90ab8
stdlib@go1.21.6
1.25.10
inaccel/mkrt:latest187fd448b6f2
stdlib@go1.21.5
1.25.10
inaccel/reef:latestc967218739f3
stdlib@go1.21.6
1.25.10

Open the chart page →

5,785
infisical-agent-injectorinfisical-charts0.1.121 of 1See more

infisical-agent-injector infisical-charts 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
infisical/infisical-agent-injector:v0.1.12718dd5bee7cb
stdlib@go1.24.13
1.25.10

Open the chart page →

762
infisical-csi-providerinfisical-charts0.2.31 of 1See more

infisical-csi-provider infisical-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
infisical/infisical-csi-provider:v0.0.9e3390e677db6
stdlib@go1.24.13
1.25.10

Open the chart page →

637
infisical-pki-issuerinfisical-charts1.0.01 of 1See more

infisical-pki-issuer infisical-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
infisical/pki-issuer:latestff38294270e3
stdlib@go1.24.13
1.25.10

Open the chart page →

580
chronografinfluxdata1.2.61 of 1See more

chronograf influxdata 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
library/chronograf:1.9.496d8a3f65a4f
stdlib@go1.16.4
1.25.10

Open the chart page →

2,206
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
stdlib@go1.24.13
1.25.10
library/influxdb:1.12.3-datab0f9fc41ed79
stdlib@go1.24.13
1.25.10

Open the chart page →

6,036
influxdbinfluxdb20.1.01 of 1See more

influxdb influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
library/influxdb:latest05d6fb735bc2
stdlib@go1.25.9
1.25.10

Open the chart page →

2,257
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
stdlib@go1.19.3
1.25.10

Open the chart page →

4,963
erigoninfradao0.0.51 of 2See more

erigon infradao 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
testinprod/op-erigon:latest0a125bd77a2d
stdlib@go1.22.12
1.25.10

Open the chart page →

2,922
l2gethinfradao0.0.11 of 1See more

l2geth infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
ethereumoptimism/l2geth:0.5.315577036dc36d
stdlib@go1.18
1.25.10

Open the chart page →

2,662
registry-container-webhookinnagoVerified publisher2.0.21 of 1See more

registry-container-webhook innago 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
ghcr.io/indeedeng/harbor-container-webhook:main45ca15fc294f
stdlib@go1.24.1
1.25.10

Open the chart page →

600
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
stdlib@go1.15.7
1.25.10

Open the chart page →

10,633
lakefsinseefrlab0.0.61 of 2See more

lakefs inseefrlab 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
treeverse/lakefs:0.69.0478f37a6cffc
stdlib@go1.17.8
1.25.10

Open the chart page →

2,655
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
stdlib@go1.13.10
1.25.10

Open the chart page →

7,518
consulintelVerified publisher0.8.12 of 2See more

consul intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
stdlib@go1.19.2
1.25.10
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
stdlib@go1.19.2
1.25.10

Open the chart page →

5,432
evi-consulintelVerified publisher3.0.32 of 2See more

evi-consul intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
stdlib@go1.19.2
1.25.10
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
stdlib@go1.19.2
1.25.10

Open the chart page →

5,432
evi-miniointelVerified publisher3.0.32 of 2See more

evi-minio intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
stdlib@go1.19.4
1.25.10
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
stdlib@go1.19.4
1.25.10

Open the chart page →

7,616
evi-vaultintelVerified publisher3.0.32 of 2See more

evi-vault intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
stdlib@go1.19.2
1.25.10
hashicorp/vault-k8s:1.1.0844337076b72
stdlib@go1.19.3
1.25.10

Open the chart page →

4,489
intel-gaudi-resource-driverintelVerified publisher0.3.01 of 1See more

intel-gaudi-resource-driver intel 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
intel/intel-gaudi-resource-driver:v0.3.0ac758c14c2de
stdlib@go1.23.4
1.25.10

Open the chart page →

566
intel-qat-resource-driverintelVerified publisher0.1.01 of 1See more

intel-qat-resource-driver intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
intel/intel-qat-resource-driver:v0.1.0ac7616986a2b
stdlib@go1.22.4
1.25.10

Open the chart page →

610
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization:3.03426deb77337
stdlib@go1.17.11
1.25.10

Open the chart page →

79,472
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
stdlib@go1.19.3
1.25.10

Open the chart page →

6,040
vaultintelVerified publisher0.8.12 of 2See more

vault intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
stdlib@go1.19.2
1.25.10
hashicorp/vault-k8s:1.1.0844337076b72
stdlib@go1.19.3
1.25.10

Open the chart page →

4,489
gravity-initinvisiblVerified publisher1.0.91 of 1See more

gravity-init invisibl 1.0.9

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
invisibl/gravity-init:v1.0.91a970f84178b
stdlib@go1.17.12
1.25.10

Open the chart page →

2,008
identity-managerinvisiblVerified publisher1.0.01 of 1See more

identity-manager invisibl 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
invisibl/identity-manager:1.0.01029f4fe20eb
stdlib@go1.17.11
1.25.10

Open the chart page →

2,164
identity-manager-demoinvisiblVerified publisher0.1.11 of 1See more

identity-manager-demo invisibl 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
invisibl/identity-manager-demo:v1.0.0cf5400cb935a
stdlib@go1.19.2
1.25.10

Open the chart page →

1,007
karpenteriometeVerified publisher0.19.31 of 1See more

karpenter iomete 0.19.3

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
stdlib@go1.19.3
1.25.10

Open the chart page →

1,556
server-monitoringiserversupport-helm--charts1.0.02 of 2See more

server-monitoring iserversupport-helm--charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
prom/node-exporter:v1.10.23ac34ce007ac
stdlib@go1.25.3
1.25.10
prom/prometheus:v3.8.0d936808bdea5
stdlib@go1.25.4
1.25.10

Open the chart page →

1,331
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
stdlib@go1.20.4
1.25.10

Open the chart page →

5,614
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
stdlib@go1.20.4
1.25.10

Open the chart page →

5,614
istio-ratelimit-operatoristio-ratelimit-operator2.16.11 of 1See more

istio-ratelimit-operator istio-ratelimit-operator 2.16.1

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
zufardhiyaulhaq/istio-ratelimit-operator:v2.15.0692cfc9d6614
stdlib@go1.19.13
1.25.10

Open the chart page →

746
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
stdlib@go1.24.3
1.25.10

Open the chart page →

3,864
daveit-at-mOfficialVerified publisher0.2.171 of 9See more

dave it-at-m 0.2.17

1 of the 9 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
stdlib@go1.24.6
1.25.10

Open the chart page →

12,522
traefikitscontainedVerified publisher9.18.41 of 1See more

traefik itscontained 9.18.4

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
stdlib@go1.16.2
1.25.10

Open the chart page →

3,350
hetzner-dyndnsitsmethemojoVerified publisher1.4.01 of 1See more

hetzner-dyndns itsmethemojo 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
hashicorp/terraform:1.9.7b77efab1a448
stdlib@go1.22.7
1.25.10

Open the chart page →

1,854
thehiveittrident-oss0.1.02 of 6See more

thehive ittrident-oss 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
library/cassandra:4.0093ee8ee5eb2
stdlib@go1.24.6
1.25.10
minio/minio:latest14cea493d9a3
stdlib@go1.24.6
1.25.10

Open the chart page →

6,350
adguard-homejacobcolvinVerified publisher0.4.01 of 2See more

adguard-home jacobcolvin 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.3843ec119419a9
stdlib@go1.20.8
1.25.10

Open the chart page →

1,605
inlets-clientjacobcolvinVerified publisher0.1.21 of 1See more

inlets-client jacobcolvin 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.25.10

Open the chart page →

1,754
inlets-serverjacobcolvinVerified publisher0.1.11 of 1See more

inlets-server jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.25.10

Open the chart page →

1,754
opencloudjacobcolvinVerified publisher0.2.32 of 13See more

opencloud jacobcolvin 0.2.3

2 of the 13 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.25.10
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
stdlib@go1.24.2
1.25.10

Open the chart page →

44,581
osrs-ge-exporterjacobcolvinVerified publisher0.4.01 of 1See more

osrs-ge-exporter jacobcolvin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
macropower/osrs_ge_exporter:v0.3c77ab5ea955c
stdlib@go1.21.0
1.25.10

Open the chart page →

608
rclonejacobcolvinVerified publisher1.0.11 of 1See more

rclone jacobcolvin 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
rclone/rclone:1.63.008e1af3c8814
stdlib@go1.20.5
1.25.10

Open the chart page →

2,151
twitch-predictions-recorderjacobcolvinVerified publisher0.1.01 of 1See more

twitch-predictions-recorder jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
stdlib@go1.19.2
1.25.10

Open the chart page →

2,671
wakatime-exporterjacobcolvinVerified publisher0.1.11 of 1See more

wakatime-exporter jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
macropower/wakatime-exporter:0.1.0dbb05debb785
stdlib@go1.14.6
1.25.10

Open the chart page →

1,314
wireguard-operatorjacobcolvinVerified publisher0.2.01 of 2See more

wireguard-operator jacobcolvin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
ghcr.io/jodevsa/wireguard-operator/manager:v2.0.2839412bdd403b
stdlib@go1.22.2
1.25.10

Open the chart page →

840
koptimizejaconiVerified publisher0.5.42 of 2See more

koptimize jaconi 0.5.4

2 of the 2 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
alpine/k8s:1.27.321b24e6bf801
stdlib@go1.20.4
1.25.10
ghcr.io/jaconi-io/koptimize:1.2.5aca1bbd609b6
stdlib@go1.20.7
1.25.10

Open the chart page →

5,741
mini-infrajaeki0.1.01 of 4See more

mini-infra jaeki 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
stdlib@go1.19.5
1.25.10

Open the chart page →

1,747
todo-operatorjakuboskera0.1.11 of 1See more

todo-operator jakuboskera 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
jakuboskera/todo-operator:v0.1.0a305b8ce5bff
stdlib@go1.25.3
1.25.10

Open the chart page →

304
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
stdlib@go1.19.8
1.25.10

Open the chart page →

10,892
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33811.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
stdlib@go1.23.12
1.25.10

Open the chart page →

3,494

Container images carrying it

4,668 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.10
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.10
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.10
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.10
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.10
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.10
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.10
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.10
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.10
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.10
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.