StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,619
of 17,828 indexed, latest versions
Container images
5,342
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,619 of 17,828 indexed charts deploy, on 5,342 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,303
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,740
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,619 by stars
ChartLatestAffected imagesRadar Score
natz-operatornatz-operatorVerified publisher0.9.51 of 1See more

natz-operator natz-operator 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/zeiss/natz-operator/operator:0.9.5187007974540
golang.org/x/net@v0.35.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

746
spring-helmnaveenalla-springboot1.0.01 of 2See more

spring-helm naveenalla-springboot 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.13

Open the chart page →

1,272
clowder2ncsaVerified publisher1.9.76 of 12See more

clowder2 ncsa 1.9.7

6 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.55.0
1.25.13
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
stdlib@go1.18.2
1.25.13
bitnamilegacy/minio:2023.12.230b60b6565ab2
golang.org/x/net@v0.19.0
stdlib@go1.20.13
0.55.0
1.25.13
bitnamilegacy/mongodb:5.0.103bb1deeaf9d0
golang.org/x/net@v0.0.0-20220708220712-1185a9018129
stdlib@go1.18.4
0.55.0
1.25.13
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.55.0
1.25.13
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
stdlib@go1.16.7
1.25.13

Open the chart page →

37,558
netobserv-operatornetobservOfficialVerified publisher1.12.01 of 1See more

netobserv-operator netobserv 1.12.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/netobserv/network-observability-operator:1.12.0-communityb05d21a015b0
stdlib@go1.26.5
1.25.13

Open the chart page →

370
cluster-issuersnginx-cert-charts0.3.04 of 4See more

cluster-issuers nginx-cert-charts 0.3.0

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.19.3eb1df56668b6
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.19.3a07125af5e83
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.55.0
1.25.13
quay.io/jetstack/cert-manager-startupapicheck:v1.19.3e51a06251338
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.19.32625754083d5
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.55.0
1.25.13

Open the chart page →

2,282
ngrok-operatorngrok-operator1.1.01 of 2See more

ngrok-operator ngrok-operator 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
zufardhiyaulhaq/ngrok-operator:v1.3.07cf2ae3fb1fb
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.15
0.55.0
1.25.13

Open the chart page →

1,897
cloud9nicholaswildeVerified publisher1.0.01 of 1See more

cloud9 nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
linuxserver/cloud9:version-1.29.245c5fe102ff3
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.11
0.55.0
1.25.13

Open the chart page →

11,745
gotifynicholaswildeVerified publisher1.0.01 of 1See more

gotify nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gotify/server-arm7:2.0.23d91e302ad1d0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.55.0
1.25.13

Open the chart page →

2,519
installernicholaswildeVerified publisher1.0.01 of 1See more

installer nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/installer:version-0.2.947d8ecd310a9
stdlib@go1.15.3
1.25.13

Open the chart page →

1,219
shiorinicholaswildeVerified publisher1.0.11 of 1See more

shiori nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/shiori:version-v1.5.0e0645abe6777
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

2,305
writefreelynicholaswildeVerified publisher1.0.01 of 1See more

writefreely nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/writefreely:version-0.13.1c3c8481b7e56
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.12
0.55.0
1.25.13

Open the chart page →

8,107
node-exporternode-exporterVerified publisher0.1.101 of 1See more

node-exporter node-exporter 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/node-exporter:v1.6.0d2e48098c364
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13

Open the chart page →

1,229
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:10.8.2-focal490f01279be1
stdlib@go1.16.7
1.25.13

Open the chart page →

13,651
nri-resource-policy-balloonsnri-pluginsOfficialVerified publisher0.14.01 of 1See more

nri-resource-policy-balloons nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resource-policy-balloons:v0.14.0a8c8297c7274
stdlib@go1.26.0
1.25.13

Open the chart page →

303
nri-resource-policy-topology-awarenri-pluginsOfficialVerified publisher0.14.01 of 1See more

nri-resource-policy-topology-aware nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resource-policy-topology-aware:v0.14.0e2443833726a
stdlib@go1.26.0
1.25.13

Open the chart page →

303
nutanix-csi-snapshotnutanix-helm-releasesOfficialVerified publisher8.3.01 of 1See more

nutanix-csi-snapshot nutanix-helm-releases 8.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.3.012c2da094b02
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

423
octopuso7studios-octopus-helm-chartsOfficialVerified publisher1.2.34 of 5See more

octopus o7studios-octopus-helm-charts 1.2.3

4 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/nats:2.11.9-alpine777787bbb4c7
stdlib@go1.24.7
1.25.13
natsio/nats-box:0.18.0abdc9f9f0120
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
natsio/nats-server-config-reloader:0.19.181edf32a3680
stdlib@go1.24.5
1.25.13
percona/percona-server-mongodb-operator:1.20.1d09453ce7886
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

6,142
oadaoadaVerified publisher5.0.61 of 11See more

oada oada 5.0.6

1 of the 11 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.55.0
1.25.13

Open the chart page →

13,380
opengistobeoneVerified publisher1.1.61 of 1See more

opengist obeone 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/thomiceli/opengist:1.15.1038d47937d3b
stdlib@go1.26.5
1.25.13

Open the chart page →

415
transfer.shobeoneVerified publisher1.0.51 of 1See more

transfer.sh obeone 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dutchcoders/transfer.sh:v1.6.1-noroot8db9ade72a0d
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.55.0
1.25.13

Open the chart page →

1,179
oci-native-ingress-controlleroci-native-ingress-controller1.0.01 of 1See more

oci-native-ingress-controller oci-native-ingress-controller 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
amaanx86/oci-native-ingress-controller:masterd7206ac7a319
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.55.0
1.25.13

Open the chart page →

434
growthbookone-acre-fundVerified publisher0.3.01 of 3See more

growthbook one-acre-fund 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

1,164
open5gs-hssopen5gs-hssVerified publisher2.3.01 of 2See more

open5gs-hss open5gs-hss 2.3.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/mongodb:lateste46cffb66274
stdlib@go1.26.5
1.25.13

Open the chart page →

217
open5gs-pcrfopen5gs-pcrfVerified publisher2.3.01 of 2See more

open5gs-pcrf open5gs-pcrf 2.3.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/mongodb:lateste46cffb66274
stdlib@go1.26.5
1.25.13

Open the chart page →

217
open5gs-scpopen5gs-scpVerified publisher2.3.11 of 2See more

open5gs-scp open5gs-scp 2.3.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/mongodb:lateste46cffb66274
stdlib@go1.26.5
1.25.13

Open the chart page →

217
open5gs-udropen5gs-udrVerified publisher2.3.11 of 2See more

open5gs-udr open5gs-udr 2.3.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/mongodb:lateste46cffb66274
stdlib@go1.26.5
1.25.13

Open the chart page →

217
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
stdlib@go1.15.1
1.25.13

Open the chart page →

5,315
kruiseopenkruise1.9.12 of 2See more

kruise openkruise 1.9.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
golang.org/x/net@v0.24.0
stdlib@go1.20.14
0.55.0
1.25.13
openkruise/kruise-manager:v1.9.1f81ae78a36a4
golang.org/x/net@v0.38.0
stdlib@go1.23.9
0.55.0
1.25.13

Open the chart page →

1,656
openrouter-botopenrouter-botVerified publisher0.2.01 of 1See more

openrouter-bot openrouter-bot 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
lifailon/openrouter-bot:latestea37e4b6b952
stdlib@go1.25.0
1.25.13

Open the chart page →

1,061
librechatopenshift1.9.01 of 3See more

librechat openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

5,824
openstack-kamaji-clusteropenstack-kamaji-clusterVerified publisher0.2.41 of 1See more

openstack-kamaji-cluster openstack-kamaji-cluster 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
golang.org/x/net@v0.38.0
stdlib@go1.24.7
0.55.0
1.25.13

Open the chart page →

770
opentelemetry-demoopentelemetry-helmOfficialVerified publisher0.42.04 of 34See more

opentelemetry-demo opentelemetry-helm 0.42.0

4 of the 34 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:13.2.2-distroless69a5d2d957ca
golang.org/x/net@v0.51.0
stdlib@go1.26.4
0.55.0
1.25.13
jaegertracing/jaeger:2.20.046a886260e04
stdlib@go1.26.5
1.25.13
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.13
ghcr.io/open-feature/flagd:v0.16.032234e63c1d0
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.55.0
1.25.13

Open the chart page →

20,109
opentelemetry-ebpf-instrumentationopentelemetry-helmOfficialVerified publisher0.13.11 of 1See more

opentelemetry-ebpf-instrumentation opentelemetry-helm 0.13.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/opentelemetry-ebpf-instrumentation/ebpf-instrument:v0.13.05e89d7478b5f
stdlib@go1.25.11
1.25.13

Open the chart page →

77
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
stdlib@go1.23.7
1.25.13

Open the chart page →

6,939
opikopikOfficialVerified publisher2.2.725See more

opik opik 2.2.72

5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.0862d86046bbc
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
altinity/clickhouse-operator:0.27.1a802b3a19d20
stdlib@go1.26.3
1.25.13
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.25.13
library/zookeeper:3.9.4dfa9ba46d14b
stdlib@go1.18.1
1.25.13

Open the chart page →

opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest35575d4f2bfe
golang.org/x/net@v0.39.0
stdlib@go1.24.13
0.55.0
1.25.13
shaowenchen/ops-server:latest6bac5cebd125
golang.org/x/net@v0.39.0
stdlib@go1.24.9
0.55.0
1.25.13

Open the chart page →

94,475
orbitalregorbitalregVerified publisher0.3.02 of 4See more

orbitalreg orbitalreg 0.3.0

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.13
orbitalreg/orbitalreg-api:0.1.045f2620337af
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

2,589
kubernetes-dashboard-proxyosc0.7.23 of 4See more

kubernetes-dashboard-proxy osc 0.7.2

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.7.02e500d29e9d5
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.55.0
1.25.13
kubernetesui/metrics-scraper:v1.0.876049887f07a
golang.org/x/net@v0.0.0-20220524220425-1d687d428aca
stdlib@go1.18.2
0.55.0
1.25.13
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16
0.55.0
1.25.13

Open the chart page →

6,015
osc-bsu-csi-driverosc-bsu-csi-driverVerified publisher2.2.05 of 6See more

osc-bsu-csi-driver osc-bsu-csi-driver 2.2.0

5 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

2,391
httpbinowan-charts0.1.91 of 1See more

httpbin owan-charts 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mccutchen/go-httpbin:latest20739736d4eb
stdlib@go1.26.5
1.25.13

Open the chart page →

56
hlf-caowkin2.1.02 of 2See more

hlf-ca owkin 2.1.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.7
0.55.0
1.25.13
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

3,432
hlf-ordowkin3.1.01 of 1See more

hlf-ord owkin 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hyperledger/fabric-orderer:2.2.137294e05209b
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.4
0.55.0
1.25.13

Open the chart page →

3,358
hlf-peerowkin5.1.01 of 1See more

hlf-peer owkin 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hyperledger/fabric-peer:2.2.1bf4995c86af6
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.4
0.55.0
1.25.13

Open the chart page →

3,696
prometheus-cachethqoxyno-zetaVerified publisher1.1.11 of 1See more

prometheus-cachethq oxyno-zeta 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
oxynozeta/prometheus-cachethq:1.1.131f11669d597
stdlib@go1.15.1
1.25.13

Open the chart page →

1,713
ngrok-operatorpaganuzzi0.0.21 of 1See more

ngrok-operator paganuzzi 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/paganuzzi/ngrokoperator:latest5a10cd095699
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.12
0.55.0
1.25.13

Open the chart page →

2,812
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
stdlib@go1.25.12
1.25.13

Open the chart page →

3,702
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
stdlib@go1.24.4
1.25.13

Open the chart page →

8,593
pardus-nginx-nodeportpardus-charts0.5.01 of 1See more

pardus-nginx-nodeport pardus-charts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
uderelier19/pardus-nginx:25-nodeport8ab640b44e3f
stdlib@go1.24.4
1.25.13

Open the chart page →

320
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

6,904
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.55.0
1.25.13
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.21.9
0.55.0
1.25.13

Open the chart page →

7,861

Container images carrying it

5,342 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/metallb/speaker:v0.14.437611bde45a2
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.55.0
1.25.13
1
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.5
0.55.0
1.25.13
1
quay.io/minio/csi-node-driver-registrarc805fdc16676
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13
1
quay.io/minio/csi-provisioner7b5c070ec70d
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13
1
quay.io/minio/csi-resizer819f68a4daf7
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13
1
quay.io/minio/directpv:v4.0.84560083eb77d
golang.org/x/net@v0.8.0
stdlib@go1.21.0
0.55.0
1.25.13
1
quay.io/minio/livenessprobef3bc9a84f149
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13
1
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
golang.org/x/net@v0.0.0-20221017152216-f25eb7ecb193
stdlib@go1.19.2
0.55.0
1.25.13
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.55.0
1.25.13
1
quay.io/minio/mc:RELEASE.2024-04-29T09-56-05Zc574fac67f60
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.55.0
1.25.13
1
quay.io/minio/minio:RELEASE.2023-12-20T01-00-02Z5702ea361420
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
1
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.55.0
1.25.13
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.6
0.55.0
1.25.13
1
quay.io/minio/minio:RELEASE.2024-06-04T19-20-08Zc6b68f158628
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.55.0
1.25.13
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.55.0
1.25.13
1
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.55.0
1.25.13
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
golang.org/x/net@v0.15.0
stdlib@go1.19.13
0.55.0
1.25.13
1
quay.io/mittwald/harbor-operator:v1.6.365a38180e27a
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.55.0
1.25.13
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
1
quay.io/mittwald/kubernetes-replicator:v2.11.13185496b3af3
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.55.0
1.25.13
1
quay.io/mittwald/kubernetes-replicator:v2.12.45dc9fc5ff59a
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13
1
quay.io/mittwald/kubernetes-replicator:v2.10.0b79e77d421d0
golang.org/x/net@v0.23.0
stdlib@go1.20.14
0.55.0
1.25.13
1
quay.io/mittwald/kubernetes-replicator:v2.9.1baf5f784398b
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13
1
quay.io/mittwald/kubernetes-secret-generator:v3.4.1465b8e6d0462
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13
1
quay.io/mittwald/servicegateway:v2.3.3fa948df30d44
stdlib@go1.21.5
1.25.13
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.55.0
1.25.13
1
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.10
0.55.0
1.25.13
1
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.55.0
1.25.13
1
quay.io/netobserv/network-observability-operator:1.12.0-communityb05d21a015b0
stdlib@go1.26.5
1.25.13
1
quay.io/nmstate/kubernetes-nmstate-operator:v0.87.04dce694f01ea
stdlib@go1.26.0
1.25.13
1
quay.io/nuclio/dashboard:1.17.8-amd64b5f5bd4efbee
golang.org/x/net@v0.53.0
stdlib@go1.26.1
0.55.0
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.15.310a1165743a1
stdlib@go1.26.4
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.13.056e3daedf765
golang.org/x/net@v0.42.0
stdlib@go1.25.4
0.55.0
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.14.368336da945bd
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.14.4
0.55.0
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
golang.org/x/net@v0.29.0
stdlib@go1.22.8
0.55.0
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16
0.55.0
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.5
0.55.0
1.25.13
1
quay.io/ohiosupercomputercenter/job-pod-reaper:v0.14.0775449888968
stdlib@go1.26.4
1.25.13
1
quay.io/ohiosupercomputercenter/k8-ldap-configmap:v0.16.040d0b67afd77
stdlib@go1.26.4
1.25.13
1
quay.io/ohiosupercomputercenter/k8-namespace-reaper:v0.11.0ead1f817e8c2
stdlib@go1.26.4
1.25.13
1
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
1
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.55.0
1.25.13
1
quay.io/open-cluster-management/dynamic-scoring-addon:latest7e571a08ec1a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
1
quay.io/open-cluster-management/dynamic-scoring-controller:latest587f5bc8f2ed
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
1
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13
1
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
golang.org/x/net@v0.52.0
stdlib@go1.26.4
0.55.0
1.25.13
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.13
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.