StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,536
of 17,790 indexed, latest versions
Container images
5,286
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,536 of 17,790 indexed charts deploy, on 5,286 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,253
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,680
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,536 by stars
ChartLatestAffected imagesRadar Score
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.13.8
0.55.0
1.25.13

Open the chart page →

4,456
linkerd-jaegerlinkerd2-edgeVerified publisher30.14.11-edge2 of 4See more

linkerd-jaeger linkerd2-edge 30.14.11-edge

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.6
0.55.0
1.25.13
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.55.0
1.25.13

Open the chart page →

4,389
halitesql0.1.51 of 2See more

ha litesql 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/litesql/ha:latest4029479b8ea7
stdlib@go1.26.5
1.25.13

Open the chart page →

1,111
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
golang.org/x/net@v0.40.0
stdlib@go1.23.8
0.55.0
1.25.13

Open the chart page →

7,915
go-hello-worldloafoe0.14.01 of 1See more

go-hello-world loafoe 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/go-hello-world:v2.13.0d3fb171f20e1
golang.org/x/net@v0.43.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

672
jspolicyloftVerified publisher0.2.21 of 1See more

jspolicy loft 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
loftsh/jspolicy:0.2.225deb9bd2683
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.55.0
1.25.13

Open the chart page →

2,309
vcluster-eksloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-eks loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.55.0
1.25.13
public.ecr.aws/eks-distro/kubernetes/kube-apiserver:v1.24.9-eks-1-24-772e06b605692
stdlib@go1.18.9
1.25.13
public.ecr.aws/eks-distro/kubernetes/kube-controller-manager:v1.24.9-eks-1-24-7eaea8c230432
stdlib@go1.18.9
1.25.13

Open the chart page →

3,304
vcluster-k0sloftVerified publisher0.0.0-ci.31 of 2See more

vcluster-k0s loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.55.0
1.25.13

Open the chart page →

3,138
log2rbac-operatorlog2rbac-operator0.0.51 of 1See more

log2rbac-operator log2rbac-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jkremser/log2rbac:v0.0.5e35cf56ef183
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.55.0
1.25.13

Open the chart page →

1,938
logclilogcliVerified publisher0.1.01 of 1See more

logcli logcli 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/logcli:main-c90366d-amd643d85bb66e39b
golang.org/x/net@v0.0.0-20210505214959-0714010a04ed
stdlib@go1.16.2
0.55.0
1.25.13

Open the chart page →

2,947
logging-operatorlogging-operator6.8.01 of 1See more

logging-operator logging-operator 6.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/logging-operator:6.8.09ab8a00662de
stdlib@go1.26.4
1.25.13

Open the chart page →

68
lokxylokxyVerified publisher0.2.01 of 1See more

lokxy lokxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
lokxy/lokxy:v0.9.0e4ac800dc55d
stdlib@go1.26.4
1.25.13

Open the chart page →

157
plexluiscajl1.0.11 of 2See more

plex luiscajl 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
stdlib@go1.26.5
1.25.13

Open the chart page →

848
lumenvoxlumenvox7.1.011 of 11See more

lumenvox lumenvox 7.1.0

11 of the 11 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
lumenvox/admin-portal:7.112310cf52f79
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
lumenvox/archive:7.15114f08ab8ef
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
lumenvox/cloud-init-tools:7.1de940e2ec601
stdlib@go1.26.2
1.25.13
lumenvox/configuration:7.182bf01d9ebec
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
lumenvox/deployment:7.1dadac2a74be6
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
lumenvox/deployment-portal:7.19d83efc340cf
stdlib@go1.26.4
1.25.13
lumenvox/file-store:7.138aa8711c9ef
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
lumenvox/license:7.135d0b1ac053e
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
lumenvox/management-api:7.16420a6e7d6c2
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
lumenvox/resource:7.193fd6ff1d62c
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
lumenvox/storage:7.1c961fe78e2ca
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

4,284
voice-biometricslumenvox2.0.18 of 26See more

voice-biometrics lumenvox 2.0.1

8 of the 26 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.13
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.55.0
1.25.13
lumenvox/cloud-init-tools:2.0.07ff037a71c50
stdlib@go1.17.3
1.25.13
lumenvox/cloud-license:2.0.09a69862e1248
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.3
0.55.0
1.25.13
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.13
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.55.0
1.25.13

Open the chart page →

71,216
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/luzilla/dnsbl_exporter:v0.12.0ecba7360ff12
golang.org/x/net@v0.53.0
stdlib@go1.25.0
0.55.0
1.25.13

Open the chart page →

1,147
lynqlynqVerified publisher1.1.221 of 1See more

lynq lynq 1.1.22

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-lynq/lynq:1.1.22229b05e3c717
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

621
cert-manager-webhook-infomaniakm0nsterrr-cert-manager-webhook-infomaniakVerified publisher1.1.21 of 1See more

cert-manager-webhook-infomaniak m0nsterrr-cert-manager-webhook-infomaniak 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/cert-manager-webhook-infomaniak:v0.1.5990dbf506d41
stdlib@go1.26.4
1.25.13

Open the chart page →

169
magentomagento3.2.35 of 12See more

magento magento 3.2.3

5 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
stdlib@go1.18.2
1.25.13
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.25.13
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.55.0
1.25.13
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
longhornio/longhorn-ui:v1.10.0e60f36161511
stdlib@go1.24.6
1.25.13

Open the chart page →

13,582
mcp-orchestratormagertronVerified publisher3.8.281See more

mcp-orchestrator magertron 3.8.28

1 container image this version deploys carries CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.13

Open the chart page →

goblackholemainVerified publisher0.0.41 of 1See more

goblackhole main 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bedag/goblackhole:0.2.0447a88598f4c
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

1,972
plane-enterprisemakeplaneOfficialVerified publisher3.7.23 of 13See more

plane-enterprise makeplane 3.7.2

3 of the 13 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.25.13
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.55.0
1.25.13
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

4,942
mattermost-enterprise-editionmattermostVerified publisher2.6.1031 of 3See more

mattermost-enterprise-edition mattermost 2.6.103

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-04-25T00-43-23Z1806872732e1
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

3,606
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.13

Open the chart page →

19,192
mcpmcp-chartsVerified publisher0.0.233 of 7See more

mcp mcp-charts 0.0.23

3 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
golang.org/x/net@v0.43.0
stdlib@go1.25.4
0.55.0
1.25.13
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
golang.org/x/net@v0.44.0
stdlib@go1.25.4
0.55.0
1.25.13
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
stdlib@go1.26.5
1.25.13

Open the chart page →

6,994
traefik-forward-authmesosphere0.3.102 of 2See more

traefik-forward-auth mesosphere 0.3.10

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.11
0.55.0
1.25.13
mesosphere/traefik-forward-auth:3.1.05456581d7b76
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.15
0.55.0
1.25.13

Open the chart page →

5,308
metadata-injectormetadata-injector-operator0.0.11 of 1See more

metadata-injector metadata-injector-operator 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ruslanguns/metadata-injector-operator:v0.0.16c77e4675e07
golang.org/x/net@v0.26.0
stdlib@go1.22.11
0.55.0
1.25.13

Open the chart page →

561
metrics-server-exportermetrics-server-exporterVerified publisher2.4.01 of 1See more

metrics-server-exporter metrics-server-exporter 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mrnim94/metrics-server-exporter:v2.4.086c4807a4bca
golang.org/x/net@v0.47.0
stdlib@go1.26.3
0.55.0
1.25.13

Open the chart page →

1,273
subspacemglants0.1.01 of 1See more

subspace mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
subspacecommunity/subspace:1.5.0e2042b63fb35
golang.org/x/net@v0.0.0-20200519113804-d87ec0cfa476
stdlib@go1.14.6
0.55.0
1.25.13

Open the chart page →

3,254
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.55.0
1.25.13

Open the chart page →

4,184
librenmsmidokura-communityVerified publisher0.3.21 of 6See more

librenms midokura-community 0.3.2

1 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
librenms/librenms:22.4.14f1f3d667cc7
stdlib@go1.16.12
1.25.13

Open the chart page →

8,967
chartmuseummike75151.2.01 of 1See more

chartmuseum mike7515 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
stdlib@go1.17.8
0.55.0
1.25.13

Open the chart page →

3,168
miniomilvus8.0.171 of 1See more

minio milvus 8.0.17

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.55.0
1.25.13

Open the chart page →

6,915
mimir-syncmimir-sync3.1.01 of 1See more

mimir-sync mimir-sync 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/antnsn/mal-sync:v1.0.52f06e72cef36
golang.org/x/net@v0.38.0
stdlib@go1.23.7
0.55.0
1.25.13

Open the chart page →

1,293
minecraft-exporterminecraft-exporterVerified publisher0.16.01 of 1See more

minecraft-exporter minecraft-exporter 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/dirien/minecraft-exporter:0.24.061d89bf99ff7
golang.org/x/net@v0.51.0
stdlib@go1.25.10
0.55.0
1.25.13

Open the chart page →

362
miniapiminiapi1.3.21 of 1See more

miniapi miniapi 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
udhos/miniapi:1.3.28a7042db82ce
stdlib@go1.23.2
1.25.13

Open the chart page →

854
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

5,804
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13

Open the chart page →

11,108
model-manager-loadermodel-manager-loader1.27.01 of 1See more

model-manager-loader model-manager-loader 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
golang.org/x/net@v0.38.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

2,678
model-manager-servermodel-manager-server1.27.01 of 1See more

model-manager-server model-manager-server 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-server:1.27.0c057dcdd9ef3
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13

Open the chart page →

733
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.55.0
1.25.13

Open the chart page →

13,763
redminemt1905027.3.42 of 3See more

redmine mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
stdlib@go1.24.6
1.25.13
library/redmine:6.1.204ac44a2595b
stdlib@go1.24.6
1.25.13

Open the chart page →

7,552
podsyncmy0nVerified publisher1.5.41 of 2See more

podsync my0n 1.5.4

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
tdeutsch/podsync:v2.4.2b67186f4c9a5
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.19.3
0.55.0
1.25.13

Open the chart page →

2,059
maddymyaVerified publisher22.4.121 of 2See more

maddy mya 22.4.12

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
foxcpp/maddy:0.7.16ab538e2f28b
golang.org/x/net@v0.20.0
stdlib@go1.19.13
0.55.0
1.25.13

Open the chart page →

1,412
registrymyaVerified publisher22.4.111 of 1See more

registry mya 22.4.11

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
distribution/distribution:2.8.3f84b2078238f
stdlib@go1.20.8
1.25.13

Open the chart page →

899
simple-gowikimy-helm-chartsVerified publisher0.2.01 of 1See more

simple-gowiki my-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
forchaladtest/mygowiki:1.0.170827eaecad1
stdlib@go1.22.6
1.25.13

Open the chart page →

399
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
stdlib@go1.18.1
1.25.13

Open the chart page →

3,729
nats-account-servernatsVerified publisher0.8.11 of 1See more

nats-account-server nats 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
stdlib@go1.16.6
1.25.13

Open the chart page →

2,634
surveyornatsVerified publisher0.20.91 of 1See more

surveyor nats 0.20.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
natsio/nats-surveyor:0.9.9104a3e938b23
stdlib@go1.26.1
1.25.13

Open the chart page →

909
natz-operatornatz-operatorVerified publisher0.9.51 of 1See more

natz-operator natz-operator 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/zeiss/natz-operator/operator:0.9.5187007974540
golang.org/x/net@v0.35.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

745

Container images carrying it

5,286 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/jcmoraisjr/haproxy-ingress:v0.16.16fd744191ef6
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-cainjector:v1.17.2ec56edb1161d
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-startupapicheck:v1.17.2e18989b4f912
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
2
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
2
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.55.0
1.25.13
2
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.55.0
1.25.13
2
quay.io/kubevirt/kubevirt-csi-driver:latest7b31b21b3f1e
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.55.0
1.25.13
2
quay.io/metallb/controller:v0.16.1f51ab515de9c
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.55.0
1.25.13
2
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
golang.org/x/net@v0.39.0
stdlib@go1.25.8
0.55.0
1.25.13
2
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.55.0
1.25.13
2
quay.io/metallb/speaker:v0.16.116561e96531e
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.55.0
1.25.13
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.55.0
1.25.13
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.55.0
1.25.13
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
golang.org/x/net@v0.12.0
stdlib@go1.19.11
0.55.0
1.25.13
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.55.0
1.25.13
2
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.10
0.55.0
1.25.13
2
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.55.0
1.25.13
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.14
0.55.0
1.25.13
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.12
0.55.0
1.25.13
2
quay.io/openshift/origin-csi-livenessprobe:lateste9236513d24a
stdlib@go1.26.5
1.25.13
2
quay.io/opstree/redis-operator:v0.22.2464ac61a6eb4
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13
2
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.55.0
1.25.13
2
quay.io/prometheuscommunity/elasticsearch-exporter:v1.11.0a056739b095d
stdlib@go1.26.5
1.25.13
2
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.55.0
1.25.13
2
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.55.0
1.25.13
2
quay.io/prometheus/node-exporter:v1.11.1-distroless6112664fd761
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.55.0
1.25.13
2
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.3
0.55.0
1.25.13
2
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.55.0
1.25.13
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.55.0
1.25.13
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.55.0
1.25.13
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.