StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,642
of 17,813 indexed, latest versions
Container images
5,366
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,642 of 17,813 indexed charts deploy, on 5,366 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+191 more1.25.135,324
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,744
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,642 by stars
ChartLatestAffected imagesRadar Score
snapshot-controllerstevehipwellVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

495
vertical-pod-autoscalerstevehipwellVerified publisher1.12.13 of 3See more

vertical-pod-autoscaler stevehipwell 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
stdlib@go1.26.5
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
stdlib@go1.26.5
1.25.13

Open the chart page →

228
snapshot-controllerstevehipwell-helm-charts-snapshot-controllerVerified publisher0.1.01 of 1See more

snapshot-controller stevehipwell-helm-charts-snapshot-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

495
its-mytabsstone0.3.01 of 1See more

its-mytabs stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.25.13

Open the chart page →

1,532
meerkat-crmstone0.3.01 of 1See more

meerkat-crm stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/fbuchner/meerkat-crm:1.7.0d513bdd3ae80
stdlib@go1.26.5
1.25.13

Open the chart page →

104
pulsar-resources-operatorstreamnative0.21.21 of 1See more

pulsar-resources-operator streamnative 0.21.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
streamnative/pulsar-resources-operator:v0.21.282434bb2a8ad
stdlib@go1.25.12
1.25.13

Open the chart page →

128
sn-platform-slimstreamnative1.11.443 of 6See more

sn-platform-slim streamnative 1.11.44

3 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.13
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.55.0
1.25.13

Open the chart page →

66,879
supabase-operatorstrrl-helm2026.7.251 of 1See more

supabase-operator strrl-helm 2026.7.25

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/strrl/supabase-operator:2026.7.2587d083ab8980
golang.org/x/net@v0.46.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

237
wonder-mesh-netstrrl-helm2026.629.02 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
headscale/headscale:0.27.1cd37b3001857
golang.org/x/net@v0.46.0
stdlib@go1.25.1
0.55.0
1.25.13
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13

Open the chart page →

5,201
stunner-devstunner1.2.12 of 2See more

stunner-dev stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13

Open the chart page →

136
stunner-gateway-operator-devstunner1.1.12 of 2See more

stunner-gateway-operator-dev stunner 1.1.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:dev58c775671b00
stdlib@go1.26.5
1.25.13
l7mp/stunner-gateway-operator:dev1cadc92fdb49
stdlib@go1.26.5
1.25.13

Open the chart page →

136
stunner-premiumstunner1.2.12 of 2See more

stunner-premium stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:1.2.10d2094060b72
stdlib@go1.26.4
1.25.13
l7mp/stunner-gateway-operator-premium:1.2.14383766e66c5
stdlib@go1.26.4
1.25.13

Open the chart page →

269
stunner-prometheusstunner0.2.14 of 4See more

stunner-prometheus stunner 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
golang.org/x/net@v0.51.0
stdlib@go1.26.5
0.55.0
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
golang.org/x/net@v0.28.0
stdlib@go1.23.0
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

3,066
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/net@v0.41.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

2,626
orchestratorsubstraVerified publisher8.8.02 of 3See more

orchestrator substra 8.8.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
golang.org/x/net@v0.28.0
stdlib@go1.21.13
0.55.0
1.25.13

Open the chart page →

3,071
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13

Open the chart page →

4,874
lingosubstratusVerified publisher0.2.11 of 1See more

lingo substratus 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
golang.org/x/net@v0.22.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

1,597
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.55.0
1.25.13

Open the chart page →

2,354
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.8
0.55.0
1.25.13

Open the chart page →

2,071
stresssudermanjr0.2.01 of 1See more

stress sudermanjr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
stdlib@go1.26.5
1.25.13

Open the chart page →

761
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/net@v0.17.0
stdlib@go1.20.2
0.55.0
1.25.13

Open the chart page →

2,132
ingress-nginx-external-lbsuminhong1.0.02 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
golang.org/x/net@v0.21.0
stdlib@go1.21.6
0.55.0
1.25.13

Open the chart page →

2,094
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
stdlib@go1.20.7
1.25.13

Open the chart page →

1,806
hello-worldsumudu-repo1.0.01 of 1See more

hello-world sumudu-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sumuduliya/hello-world:latestb7788a2984a3
stdlib@go1.19.13
1.25.13

Open the chart page →

940
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,285
supabase-operatorsupabse0.1.31 of 1See more

supabase-operator supabse 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/supabase-community/supabase-operator:v0.1.3253a6dcbf4f0
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

237
cludodsuperorbitalVerified publisher0.0.51 of 1See more

cludod superorbital 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
superorbital/cludod:0.0.2-alphad59732f61d6e
golang.org/x/net@v0.0.0-20220111093109-d55c255bac03
stdlib@go1.17.6
0.55.0
1.25.13

Open the chart page →

2,372
superset-operatorsuperset-kubernetes-operatorVerified publisher0.2.01 of 1See more

superset-operator superset-kubernetes-operator 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/apache/superset-kubernetes-operator:0.2.04351831f757f
stdlib@go1.26.5
1.25.13

Open the chart page →

111
do-database-metrics-adaptersupporttools1.0.21 of 1See more

do-database-metrics-adapter supporttools 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
supporttools/do-database-metrics-adapter:1.0.2ab55fd5a69c3
stdlib@go1.22.3
1.25.13

Open the chart page →

430
do-operatorsupporttools0.1.71 of 2See more

do-operator supporttools 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
digitalocean/do-operator:v0.1.65e5deb4db76e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

1,063
go-redis-proxysupporttools0.0.71 of 1See more

go-redis-proxy supporttools 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
supporttools/go-redis-proxy:0.0.7cbd45f6b02b8
stdlib@go1.21.6
1.25.13

Open the chart page →

529
go-web-cachesupporttools1.3.21 of 1See more

go-web-cache supporttools 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
supporttools/go-web-cache:v1.3.2f4f775dd43b9
stdlib@go1.21.6
1.25.13

Open the chart page →

511
nfs-provisionersupporttools0.11.01 of 1See more

nfs-provisioner supporttools 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
openebs/provisioner-nfs:0.11.04f41dd782761
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.55.0
1.25.13

Open the chart page →

2,681
powerdns-admin-proxysupporttools0.1.51 of 1See more

powerdns-admin-proxy supporttools 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
supporttools/powerdns-admin-proxy:5e3687d66bcfa
stdlib@go1.21.3
1.25.13

Open the chart page →

558
push-to-k8ssupporttools1.1.21 of 1See more

push-to-k8s supporttools 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cube8021/push-to-k8s:v1.1.21be9baf096ff
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13

Open the chart page →

531
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
golang.org/x/net@v0.43.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

3,522
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.25.13

Open the chart page →

12,748
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.55.0
1.25.13

Open the chart page →

11,020
icinga2svtech-public-helm-charts1.0.02 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.25.13
svtechnmaa/svtech_icingadb:v1.1.26d91c2e4e882
stdlib@go1.21.5
1.25.13

Open the chart page →

5,570
icingawebsvtech-public-helm-charts1.0.01 of 2See more

icingaweb svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
stdlib@go1.21.6
1.25.13

Open the chart page →

2,053
ingress-nginxsvtech-public-helm-charts1.0.01 of 1See more

ingress-nginx svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

1,480
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.25.13

Open the chart page →

75,790
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

76,156
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

2,337
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
golang.org/x/net@v0.21.0
stdlib@go1.23.9
0.55.0
1.25.13

Open the chart page →

1,369
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
golang.org/x/net@v0.47.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

2,417
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.55.0
1.25.13

Open the chart page →

8,312
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

1,971
agentssynapse0.1.304 of 9See more

agents synapse 0.1.30

4 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.42.07d32a4eddec7
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.55.0
1.25.13
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.55.0
1.25.13
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
golang.org/x/net@v0.35.0
stdlib@go1.22.4
0.55.0
1.25.13
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.55.0
1.25.13

Open the chart page →

7,288
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

1,826

Container images carrying it

5,366 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.55.0
1.25.13
2
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.55.0
1.25.13
2
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.55.0
1.25.13
2
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.55.0
1.25.13
2
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.55.0
1.25.13
2
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.55.0
1.25.13
2
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/net@v0.10.0
stdlib@go1.21.1
0.55.0
1.25.13
2
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.55.0
1.25.13
2
quay.io/thanos/thanos:v0.39.21d022ef4b8ef
golang.org/x/net@v0.41.0
stdlib@go1.24.0
0.55.0
1.25.13
2
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13
2
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.55.0
1.25.13
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.55.0
1.25.13
2
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.55.0
1.25.13
2
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.55.0
1.25.13
2
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.55.0
1.25.13
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.55.0
1.25.13
2
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.55.0
1.25.13
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.55.0
1.25.13
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.55.0
1.25.13
2
registry.k8s.io/kubectl:v1.37.05ed410ebac5d
stdlib@go1.26.5
1.25.13
2
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/net@v0.23.0
stdlib@go1.23.10
0.55.0
1.25.13
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
stdlib@go1.19.3
0.55.0
1.25.13
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.55.0
1.25.13
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0db384bf43222
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.55.0
1.25.13
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.55.0
1.25.13
2
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.55.0
1.25.13
2
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
stdlib@go1.26.3
1.25.13
2
registry.k8s.io/sig-storage/csi-attacher:v4.9.05aaefc24f315
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.0cd21e19cd8bb
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-snapshotter:v8.3.0bc7be893ecc3
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.55.0
1.25.13
2
registry.k8s.io/sig-storage/livenessprobe:v2.12.05baeb4a6d7d5
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.55.0
1.25.13
2

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.