StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,616
of 17,805 indexed, latest versions
Container images
5,324
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,616 of 17,805 indexed charts deploy, on 5,324 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+190 more1.25.135,284
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,716
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,616 by stars
ChartLatestAffected imagesRadar Score
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.13
0.55.0
1.25.13

Open the chart page →

6,680
stakefishstakefish0.1.06 of 8See more

stakefish stakefish 0.1.0

6 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.55.0
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.55.0
1.25.13
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

20,381
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

2,998
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

1,262
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.25.13

Open the chart page →

4,116
mev-booststakewise1.7.41 of 1See more

mev-boost stakewise 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
flashbots/mev-boost:1.8.07c486b5789da
stdlib@go1.22.6
1.25.13

Open the chart page →

1,261
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.55.0
1.25.13

Open the chart page →

6,609
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.55.0
1.25.13

Open the chart page →

7,035
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

1,262
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

576
open-appsec-injectorstartechnicaVerified publisher1.1.22 of 3See more

open-appsec-injector startechnica 1.1.2

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/openappsec/smartsync:latest580d68c50cc7
stdlib@go1.18.10
1.25.13
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
stdlib@go1.18.10
1.25.13

Open the chart page →

4,358
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.25.13

Open the chart page →

14,627
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
stdlib@go1.18.4
0.55.0
1.25.13

Open the chart page →

1,985
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.1
0.55.0
1.25.13
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.5
0.55.0
1.25.13
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.55.0
1.25.13
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

16,542
fluentd-operatorstatcan0.5.11 of 1See more

fluentd-operator statcan 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
vmware/kube-fluentd-operator:latestf028c138a5f4
golang.org/x/net@v0.17.0
stdlib@go1.21.7
0.55.0
1.25.13

Open the chart page →

1,960
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

1,584
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

6,598
prometheus-operatorstatcan0.2.24 of 7See more

prometheus-operator statcan 0.2.2

4 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.55.0
1.25.13
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
stdlib@go1.13.11
0.55.0
1.25.13
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
stdlib@go1.13.4
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.3
0.55.0
1.25.13

Open the chart page →

12,254
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.10
0.55.0
1.25.13

Open the chart page →

1,316
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.55.0
1.25.13

Open the chart page →

1,828
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.13.5
0.55.0
1.25.13

Open the chart page →

4,224
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.25.13

Open the chart page →

13,678
steadybit-agentsteadybit3.1.1682 of 6See more

steadybit-agent steadybit 3.1.168

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/steadybit/extension-container:v1.8.1ae79f958b479
golang.org/x/net@v0.50.0
stdlib@go1.25.12
0.55.0
1.25.13
ghcr.io/steadybit/extension-host:v1.8.103a5ef26aac5
golang.org/x/net@v0.50.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

3,812
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,279
snapshot-controllerstevehipwellVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

495
vertical-pod-autoscalerstevehipwellVerified publisher1.12.13 of 3See more

vertical-pod-autoscaler stevehipwell 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
stdlib@go1.26.5
1.25.13

Open the chart page →

228
snapshot-controllerstevehipwell-helm-charts-snapshot-controllerVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell-helm-charts-snapshot-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

495
its-mytabsstone0.3.01 of 1See more

its-mytabs stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.25.13

Open the chart page →

1,528
meerkat-crmstone0.3.01 of 1See more

meerkat-crm stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/fbuchner/meerkat-crm:1.7.0d513bdd3ae80
stdlib@go1.26.5
1.25.13

Open the chart page →

104
pulsar-resources-operatorstreamnative0.21.11 of 1See more

pulsar-resources-operator streamnative 0.21.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
streamnative/pulsar-resources-operator:v0.21.11886043c24d0
stdlib@go1.25.12
1.25.13

Open the chart page →

128
sn-platform-slimstreamnative1.11.443 of 6See more

sn-platform-slim streamnative 1.11.44

3 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.13
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.55.0
1.25.13

Open the chart page →

66,712
supabase-operatorstrrl-helm2026.7.251 of 1See more

supabase-operator strrl-helm 2026.7.25

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/strrl/supabase-operator:2026.7.2587d083ab8980
golang.org/x/net@v0.46.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

237
wonder-mesh-netstrrl-helm2026.629.02 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
headscale/headscale:0.27.1cd37b3001857
golang.org/x/net@v0.46.0
stdlib@go1.25.1
0.55.0
1.25.13
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13

Open the chart page →

5,193
stunner-devstunner1.2.12 of 2See more

stunner-dev stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13

Open the chart page →

136
stunner-gateway-operator-devstunner1.1.12 of 2See more

stunner-gateway-operator-dev stunner 1.1.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13

Open the chart page →

136
stunner-premiumstunner1.2.12 of 2See more

stunner-premium stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:1.2.10d2094060b72
stdlib@go1.26.4
1.25.13
l7mp/stunner-gateway-operator-premium:1.2.14383766e66c5
stdlib@go1.26.4
1.25.13

Open the chart page →

267
stunner-prometheusstunner0.2.14 of 4See more

stunner-prometheus stunner 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
golang.org/x/net@v0.51.0
stdlib@go1.26.5
0.55.0
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
golang.org/x/net@v0.28.0
stdlib@go1.23.0
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

3,066
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/net@v0.41.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

2,626
orchestratorsubstraVerified publisher8.8.02 of 3See more

orchestrator substra 8.8.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
golang.org/x/net@v0.28.0
stdlib@go1.21.13
0.55.0
1.25.13

Open the chart page →

3,060
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13

Open the chart page →

4,862
lingosubstratusVerified publisher0.2.11 of 1See more

lingo substratus 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
golang.org/x/net@v0.22.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

1,596
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.55.0
1.25.13

Open the chart page →

2,354
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.8
0.55.0
1.25.13

Open the chart page →

2,071
stresssudermanjr0.2.01 of 1See more

stress sudermanjr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
stdlib@go1.26.5
1.25.13

Open the chart page →

761
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/net@v0.17.0
stdlib@go1.20.2
0.55.0
1.25.13

Open the chart page →

2,132
ingress-nginx-external-lbsuminhong1.0.02 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
golang.org/x/net@v0.21.0
stdlib@go1.21.6
0.55.0
1.25.13

Open the chart page →

2,094
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
stdlib@go1.20.7
1.25.13

Open the chart page →

1,804
hello-worldsumudu-repo1.0.01 of 1See more

hello-world sumudu-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sumuduliya/hello-world:latestb7788a2984a3
stdlib@go1.19.13
1.25.13

Open the chart page →

940
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,279
supabase-operatorsupabse0.1.31 of 1See more

supabase-operator supabse 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/supabase-community/supabase-operator:v0.1.3253a6dcbf4f0
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

237

Container images carrying it

5,324 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.25.13
2
library/mariadb:12.0.2:12.0-noble607835cd628b
stdlib@go1.24.6
1.25.13
2
library/mariadb:11.4611a2fcc5fa7
stdlib@go1.24.6
1.25.13
2
library/mariadb:10.692e50059ea0a
stdlib@go1.24.6
1.25.13
2
library/mariadb:13.0.2d4fdec0510ad
stdlib@go1.24.6
1.25.13
2
library/mariadb:11.3.2e101f9db3191
stdlib@go1.18.2
1.25.13
2
library/mongo:8.0.20098862b1339f
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
2
library/mongo:5.041108d183e97
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.55.0
1.25.13
2
library/mongo:8.3.115d7043a4ffe0
stdlib@go1.26.5
1.25.13
2
library/mongo:7b096b4cb9269
stdlib@go1.26.5
1.25.13
2
library/mongo:7.0b6421fd6d1c5
stdlib@go1.26.5
1.25.13
2
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.25.13
2
library/mysql:8:8.4.1185b9bf2e29cf
stdlib@go1.24.6
1.25.13
2
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.25.13
2
library/mysql:9.7.2b2cf29815e62
stdlib@go1.24.6
1.25.13
2
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.25.13
2
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.25.13
2
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.25.13
2
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.25.13
2
library/postgres:17-bookworm051f7b7b3abd
stdlib@go1.24.6
1.25.13
2
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.25.13
2
library/postgres:18:18.6-trixie10037cee1d5e
stdlib@go1.24.6
1.25.13
2
library/postgres:18.11090bc3a8ccf
stdlib@go1.24.6
1.25.13
2
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.25.13
2
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.25.13
2
library/postgres:15-alpinea46e076249ce
stdlib@go1.24.6
1.25.13
2
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.25.13
2
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.25.13
2
library/postgres:13-alpinefb9065b6e3e2
stdlib@go1.24.6
1.25.13
2
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.25.13
2
library/rabbitmq:4.3.5-management:4-management:managementffd1b50c522a
stdlib@go1.22.2
1.25.13
2
library/redis148bb5411c18
stdlib@go1.18.2
1.25.13
2
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.25.13
2
library/redmine:6.1.3-trixief474a901faec
stdlib@go1.24.6
1.25.13
2
library/traefik:v3.7.16b9cbca6fac4
golang.org/x/net@v0.53.0
stdlib@go1.25.10
0.55.0
1.25.13
2
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.55.0
1.25.13
2
library/traefik:2.2.8f5af5a5ce17f
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.14.6
0.55.0
1.25.13
2
library/zookeeper:3.9.5f258365d4882
stdlib@go1.18.1
1.25.13
2
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
2
linuxserver/cloud9:latest:version-1.29.245c5fe102ff3
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.11
0.55.0
1.25.13
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.55.0
1.25.13
2
listmonk/listmonk:latest:v6.2.0f535d59e1499
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.55.0
1.25.13
2
longhornio/longhorn-manager:v1.12.183b79f57043f
stdlib@go1.26.5
1.25.13
2
longhornio/longhorn-manager:v1.2.3dca34321452c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.1
0.55.0
1.25.13
2
longhornio/longhorn-share-manager:v1.12.1efaf47aeb4e8
stdlib@go1.26.5
1.25.13
2
longhornio/longhorn-ui:v1.12.103a3ce6673df
stdlib@go1.25.12
1.25.13
2
louislam/uptime-kuma:2.3.29aeb4e51d038
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.55.0
1.25.13
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.25.13
2
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.55.0
1.25.13
2
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.25.13
2

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.