StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,671
of 17,828 indexed, latest versions
Container images
5,406
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,671 of 17,828 indexed charts deploy, on 5,406 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,364
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+222 more0.55.03,790
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,671 by stars
ChartLatestAffected imagesRadar Score
csi-driver-nfsbook-k8sinfra-v24.12.16 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

6 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-snapshotter:v8.3.0bc7be893ecc3
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
golang.org/x/net@v0.37.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

6,308
grafanabook-k8sinfra-v28.8.21 of 1See more

grafana book-k8sinfra-v2 8.8.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

1,826
jaegerbook-k8sinfra-v23.4.04 of 5See more

jaeger book-k8sinfra-v2 3.4.0

4 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.25.13
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

19,460
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

8,396
kube-prometheus-stackbook-k8sinfra-v265.5.15 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

5 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

6,067
metallbbook-k8sinfra-v20.13.102 of 3See more

metallb book-k8sinfra-v2 0.13.10

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.55.0
1.25.13
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.55.0
1.25.13

Open the chart page →

3,859
nfs-subdir-external-provisionerbook-k8sinfra-v24.0.181 of 1See more

nfs-subdir-external-provisioner book-k8sinfra-v2 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.55.0
1.25.13

Open the chart page →

2,746
prometheusbook-k8sinfra-v226.0.16 of 6See more

prometheus book-k8sinfra-v2 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

5,327
pyroscopebook-k8sinfra-v21.10.03 of 3See more

pyroscope book-k8sinfra-v2 1.10.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.55.0
1.25.13
grafana/pyroscope:1.10.0319bf32ae06b
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.55.0
1.25.13
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.13

Open the chart page →

3,269
redisbook-k8sinfra-v21.0.01 of 1See more

redis book-k8sinfra-v2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.25.13

Open the chart page →

1,732
tempobook-k8sinfra-v21.10.31 of 1See more

tempo book-k8sinfra-v2 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/net@v0.24.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

1,878
boundary-softsciboundary-softsci0.2.41 of 1See more

boundary-softsci boundary-softsci 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hashicorp/boundary:latest76a201954ca0
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

879
branchdbbranch-dbVerified publisher0.1.42 of 3See more

branchdb branch-db 0.1.4

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/masucchi/branchdb:0.1.47ea1820c1da1
stdlib@go1.26.4
1.25.13
ghcr.io/masucchi/branchdb-operator:0.1.4c16578615a43
stdlib@go1.26.4
1.25.13

Open the chart page →

517
bitmagnetbrandan-schmitz-helm-chartsVerified publisher1.0.62 of 2See more

bitmagnet brandan-schmitz-helm-charts 1.0.6

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.25.13
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

1,685
Filebrowserbrandan-schmitz-helm-chartsVerified publisher1.3.11 of 1See more

Filebrowser brandan-schmitz-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.63.15-s6dbac07403040
stdlib@go1.26.4
1.25.13

Open the chart page →

989
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
tautullibryanalves0.1.01 of 1See more

tautulli bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
tautulli/tautulli:latest670e68dd9efc
stdlib@go1.24.4
1.25.13

Open the chart page →

1,952
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

72,281
plexbryopsida0.2.01 of 1See more

plex bryopsida 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
stdlib@go1.26.5
1.25.13

Open the chart page →

907
buildkitbuildkit0.1.01 of 1See more

buildkit buildkit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
moby/buildkit:master-rootless07115a67cd22
golang.org/x/net@v0.53.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

620
buildkit-privilegedbuildkit-privileged0.1.01 of 1See more

buildkit-privileged buildkit-privileged 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
moby/buildkit:masterbc964521ee58
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

403
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.26.5
1.25.13

Open the chart page →

11,660
pages-microservicebusi-adsVerified publisher1.0.01 of 3See more

pages-microservice busi-ads 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
butane-operatorbutane-operatorVerified publisher0.3.02 of 2See more

butane-operator butane-operator 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/naval-group/butane-operator:v0.1.1-rc285818b510780
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.55.0
1.25.13
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.55.0
1.25.13

Open the chart page →

1,411
butlercibutlerciVerified publisher0.1.01 of 1See more

butlerci butlerci 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

2,376
accelerationbuttahtoastVerified publisher0.1.01 of 1See more

acceleration buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
goharbor/harbor-acceld:0.2.13451103a6c8d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

1,409
fluobuttahtoastVerified publisher0.1.01 of 1See more

fluo buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.55.0
1.25.13

Open the chart page →

1,299
kubermatic-operatorbuttahtoastVerified publisher2.24.51 of 1See more

kubermatic-operator buttahtoast 2.24.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
golang.org/x/net@v0.19.0
stdlib@go1.20.6
0.55.0
1.25.13

Open the chart page →

2,782
kubevirt-managerbuttahtoastVerified publisher0.1.31 of 1See more

kubevirt-manager buttahtoast 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13

Open the chart page →

1,497
mariadbbysamioVerified publisher1.0.21 of 1See more

mariadb bysamio 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:12.0.2607835cd628b
stdlib@go1.24.6
1.25.13

Open the chart page →

3,009
miniobysamioVerified publisher1.0.31 of 1See more

minio bysamio 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

1,201
payloadboxbyteforkVerified publisher0.0.41 of 1See more

payloadbox bytefork 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/bytefork/payloadbox:0.0.73e0164e975b3
stdlib@go1.26.3
1.25.13

Open the chart page →

88
caddycaddyVerified publisher0.0.41 of 1See more

caddy caddy 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/caddy:2.11.2-alpine834468128c76
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

1,706
etcdcagriekinVerified publisher0.1.51 of 1See more

etcd cagriekin 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.16d967d98a12dc
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.55.0
1.25.13

Open the chart page →

907
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

2,404
rediscagriekinVerified publisher1.5.21 of 2See more

redis cagriekin 1.5.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.67.0120f7ec77293
stdlib@go1.23.4
1.25.13

Open the chart page →

1,425
ct-singlecalltelemetry0.8.44 of 7See more

ct-single calltelemetry 0.8.4

4 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.25.13
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.1
0.55.0
1.25.13
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.25.13
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.25.13

Open the chart page →

10,674
stablecalltelemetry0.7.14 of 9See more

stable calltelemetry 0.7.1

4 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.25.13
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.1
0.55.0
1.25.13
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.25.13
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.25.13

Open the chart page →

7,706
stable-hacalltelemetry0.11.43 of 7See more

stable-ha calltelemetry 0.11.4

3 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/nats:2.10.12-alpinebca70839d953
stdlib@go1.21.8
1.25.13
natsio/nats-box:0.14.2e808e0644ce1
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.55.0
1.25.13
natsio/nats-server-config-reloader:0.14.10d50270fa374
stdlib@go1.20.5
1.25.13

Open the chart page →

4,706
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:5.0fc5ecd863862
stdlib@go1.16.7
1.25.13

Open the chart page →

8,126
geoservercamptocamp20.0.31 of 12See more

geoserver camptocamp2 0.0.3

1 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.25.13

Open the chart page →

88,995
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

4,528
getconfigcamptocamp30.1.11 of 1See more

getconfig camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

2,203
prometheus-puppetdb-sdcamptocamp38.0.21 of 2See more

prometheus-puppetdb-sd camptocamp3 8.0.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/prometheus-puppetdb-sd:0.14.0414c0c99fd06
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.55.0
1.25.13

Open the chart page →

6,224
redisoperatorcamptocamp33.0.11 of 1See more

redisoperator camptocamp3 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/spotahome/redis-operator:latest8c772955184e
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.55.0
1.25.13

Open the chart page →

1,194
s3-exportercamptocamp32.2.01 of 1See more

s3-exporter camptocamp3 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ribbybibby/s3-exporter:v0.5.0998184c51a00
stdlib@go1.15.15
1.25.13

Open the chart page →

1,184
snyk-exportercamptocamp30.1.41 of 1See more

snyk-exporter camptocamp3 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/lunarway/snyk_exporter:v1.11.155e5cc5aaa0a
stdlib@go1.17.7
1.25.13

Open the chart page →

1,080

Container images carrying it

5,406 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
golang.org/x/net@v0.29.0
stdlib@go1.22.8
0.55.0
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16
0.55.0
1.25.13
1
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.5
0.55.0
1.25.13
1
quay.io/ohiosupercomputercenter/job-pod-reaper:v0.14.0775449888968
stdlib@go1.26.4
1.25.13
1
quay.io/ohiosupercomputercenter/k8-ldap-configmap:v0.16.040d0b67afd77
stdlib@go1.26.4
1.25.13
1
quay.io/ohiosupercomputercenter/k8-namespace-reaper:v0.11.0ead1f817e8c2
stdlib@go1.26.4
1.25.13
1
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
1
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.55.0
1.25.13
1
quay.io/open-cluster-management/dynamic-scoring-addon:latest7e571a08ec1a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
1
quay.io/open-cluster-management/dynamic-scoring-controller:latest587f5bc8f2ed
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
1
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13
1
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
golang.org/x/net@v0.52.0
stdlib@go1.26.4
0.55.0
1.25.13
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.13
0.55.0
1.25.13
1
quay.io/openshift/origin-cli:4.66722d5041b47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.55.0
1.25.13
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.55.0
1.25.13
1
quay.io/openshift/origin-csi-external-attacher:latest4f9b3d0f2c7f
stdlib@go1.26.5
1.25.13
1
quay.io/openshift/origin-csi-external-provisioner:lateste4074ec254f5
stdlib@go1.26.5
1.25.13
1
quay.io/openshift/origin-csi-node-driver-registrar:latestea08b5e5f4ab
stdlib@go1.26.5
1.25.13
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
git-lfs@2.13.3-3.el8_6
golang.org/x/net@v0.20.0
stdlib@go1.21.3
0:3.4.1-11.el8_10
0.55.0
1.25.13
1
quay.io/operator-framework/catalogd:v1.8.06ff40fa6257f
golang.org/x/net@v0.50.0
stdlib@go1.25.3
0.55.0
1.25.13
1
quay.io/operator-framework/olm1b6002156f56
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13
1
quay.io/operator-framework/olm40d0363f4aa6
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.55.0
1.25.13
1
quay.io/operator-framework/olm:v0.46.04404599eb7b7
stdlib@go1.26.3
1.25.13
1
quay.io/operator-framework/olmf9ea8cef95ac
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.55.0
1.25.13
1
quay.io/operator-framework/operator-controller:v1.8.0bca5dfcc67ca
golang.org/x/net@v0.50.0
stdlib@go1.25.3
0.55.0
1.25.13
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
stdlib@go1.17.2
1.25.13
1
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
stdlib@go1.16.15
1.25.13
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.55.0
1.25.13
1
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.19.1
0.55.0
1.25.13
1
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.55.0
1.25.13
1
quay.io/opsmxpublic/opa:1.12.084fb1af7401c
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
stdlib@go1.22.2
1.25.13
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.1
0.55.0
1.25.13
1
quay.io/opstree/druid-exporter:v0.83f6d9885cfe2
stdlib@go1.14.6
1.25.13
1
quay.io/opstree/druid-exporter:v0.119f01c9c5c2e3
stdlib@go1.15.15
1.25.13
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
1
quay.io/opstree/kube-state-metrics:2.18.0-debian1353525d253793
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.55.0
1.25.13
1
quay.io/opstree/logging-operator:v0.4.0fd8bb57ef3cf
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.10
0.55.0
1.25.13
1
quay.io/opstree/loki:3.6-debian13bdfee214c7ea
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
1
quay.io/opstree/memcached-exporter:0.15.5-debian13cf8f8410eaad
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.55.0
1.25.13
1
quay.io/opstree/mongodb-operator:v0.3.0879b9bead838
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.8
0.55.0
1.25.13
1
quay.io/opstree/node-exporter:1.11.1-alpine3.233b6b3a7eb001
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
1
quay.io/opstree/opentelemetry-operator:0.149.0-debian13a21405ab9a9a
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.55.0
1.25.13
1
quay.io/opstree/redis-operator:v0.26.01c6818e5e505
stdlib@go1.25.12
1.25.13
1
quay.io/opstree/tempo:2.10.4-debian13cb734024b3fd
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
1
quay.io/opstree/victoriametrics-operator:v0.69.066fe5216c278
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
1
quay.io/orc/openstack-resource-controller:v2.5.079f22af49612
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.55.0
1.25.13
1
quay.io/piraeusdatastore/nri-volume-qos:v0.1.3cbe3e1ea2b6a
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.55.0
1.25.13
1
quay.io/piraeusdatastore/piraeus-operator:v2.10.5dd68a66332de
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.55.0
1.25.13
1
quay.io/piraeusdatastore/piraeus-operator:v2.2.0ec4022c8b0e3
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.