StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,519
of 17,797 indexed, latest versions
Container images
5,266
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,519 of 17,797 indexed charts deploy, on 5,266 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,230
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,673
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,519 by stars
ChartLatestAffected imagesRadar Score
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.25.13

Open the chart page →

4,623
iotaeclipse-aeriosVerified publisher1.0.23 of 4See more

iota eclipse-aerios 1.0.2

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
eclipseaerios/iota-tangle-peerer:latest99d7ff18d416
golang.org/x/net@v0.30.0
stdlib@go1.22.12
0.55.0
1.25.13
iotaledger/hornet:2.001206f1ba89c
golang.org/x/net@v0.14.0
stdlib@go1.21.10
0.55.0
1.25.13
iotaledger/inx-dashboard:1.012c669cb8748
golang.org/x/net@v0.14.0
stdlib@go1.21.1
0.55.0
1.25.13

Open the chart page →

13,613
llo-apieclipse-aeriosVerified publisher1.0.01 of 1See more

llo-api eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
eclipseaerios/llo-api:1.2.0ab7a04182191
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.55.0
1.25.13

Open the chart page →

931
llo-docker-operatoreclipse-aeriosVerified publisher1.0.02 of 2See more

llo-docker-operator eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
golang.org/x/net@v0.25.0
stdlib@go1.23.12
0.55.0
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.55.0
1.25.13

Open the chart page →

2,193
llo-k8seclipse-aeriosVerified publisher1.1.02 of 2See more

llo-k8s eclipse-aerios 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/net@v0.10.0
stdlib@go1.21.13
0.55.0
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.55.0
1.25.13

Open the chart page →

2,164
llo-natseclipse-aeriosVerified publisher1.0.01 of 1See more

llo-nats eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/nats:2.11.4c8cd23806eef
stdlib@go1.24.3
1.25.13

Open the chart page →

837
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
timescale/timescaledb-postgis:latest-pg127758704d4a14
stdlib@go1.14
1.25.13

Open the chart page →

11,483
openfaas2eclipse-aeriosVerified publisher12.0.56 of 6See more

openfaas2 eclipse-aerios 12.0.5

6 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/nats-streaming:0.25.5ced93c701875
stdlib@go1.19.10
1.25.13
prom/prometheus:v2.51.24f6c47e39a90
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.55.0
1.25.13
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.55.0
1.25.13
ghcr.io/openfaas/gateway:0.27.1382b15393116e
stdlib@go1.24.6
1.25.13
ghcr.io/openfaasltd/jetstream-queue-worker:0.3.37d96366e208b1
stdlib@go1.22.1
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13

Open the chart page →

6,688
openldap-stack-haeclipse-aeriosVerified publisher4.1.21 of 4See more

openldap-stack-ha eclipse-aerios 4.1.2

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
eclipseaerios/openldap:2.6.30208743f315e
stdlib@go1.18.2
1.25.13

Open the chart page →

7,535
orion-ldeclipse-aeriosVerified publisher1.0.01 of 2See more

orion-ld eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.21.12
1.25.13

Open the chart page →

9,815
chartecr-toke-renew0.1.51 of 1See more

chart ecr-toke-renew 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

2,818
edge-accessedge-accessVerified publisher0.1.01 of 1See more

edge-access edge-access 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.13.056e3daedf765
golang.org/x/net@v0.42.0
stdlib@go1.25.4
0.55.0
1.25.13

Open the chart page →

677
continuum-proxyedgelesssysVerified publisher1.5.11 of 1See more

continuum-proxy edgelesssys 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/continuum/continuum-proxydigest-pinned24c76f294a80
golang.org/x/net@v0.32.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

859
marblerunedgelesssysVerified publisher1.9.21 of 1See more

marblerun edgelesssys 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
stdlib@go1.26.1
1.25.13

Open the chart page →

1,860
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.55.0
1.25.13

Open the chart page →

11,019
pagesedgwarepages1.0.01 of 3See more

pages edgwarepages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,262
grafanaedu5.3.01 of 1See more

grafana edu 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.55.0
1.25.13

Open the chart page →

3,198
prometheusedu11.6.04 of 6See more

prometheus edu 11.6.0

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.55.0
1.25.13
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.55.0
1.25.13
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.25.13
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.55.0
1.25.13

Open the chart page →

8,492
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,337
cert-manager-cpanel-dns-webhookegebackVerified publisher1.0.61 of 1See more

cert-manager-cpanel-dns-webhook egeback 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/net@v0.29.0
stdlib@go1.22.8
0.55.0
1.25.13

Open the chart page →

1,292
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

2,160
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.13

Open the chart page →

7,407
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.25.13

Open the chart page →

30,529
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
golang.org/x/net@v0.33.0
stdlib@go1.24.4
0.55.0
1.25.13
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
golang.org/x/net@v0.33.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

3,976
eg-universal-agent-operatoreg-universal-agent-operatorVerified publisher0.0.51 of 1See more

eg-universal-agent-operator eg-universal-agent-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

573
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,519
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
golang.org/x/net@v0.30.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

903
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.13

Open the chart page →

8,057
eks-auto-pod-id-assoceks-auto-pod-id-assoc0.6.01 of 1See more

eks-auto-pod-id-assoc eks-auto-pod-id-assoc 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
udhos/eks-auto-pod-id-assoc:0.6.0196ef68af380
stdlib@go1.26.3
1.25.13

Open the chart page →

950
postgresqleks-storageclass0.1.01 of 1See more

postgresql eks-storageclass 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13

Open the chart page →

1,667
elastic-agentelasticVerified publisher9.5.41 of 2See more

elastic-agent elastic 9.5.4

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

760
kube-state-metricselasticVerified publisher6.1.01 of 1See more

kube-state-metrics elastic 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

760
netobserv-flowelastiflowVerified publisher0.11.01 of 1See more

netobserv-flow elastiflow 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
elastiflow/flow-collector:7.26.0fee67842e16b
golang.org/x/net@v0.53.0
stdlib@go1.25.10
0.55.0
1.25.13

Open the chart page →

1,496
seafileeleksbai0.1.12 of 3See more

seafile eleksbai 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:10.692e50059ea0a
stdlib@go1.24.6
1.25.13
seafileltd/seafile-mc:9.0.106693911bcc40
stdlib@go1.19
1.25.13

Open the chart page →

25,285
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
stdlib@go1.23.12
1.25.13

Open the chart page →

2,971
elsaelsa0.1.01 of 4See more

elsa elsa 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/stakater/reloader:v1.4.4a571c5b32c0f
golang.org/x/net@v0.39.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

398
rabbitmqemberstackVerified publisher1.0.211 of 1See more

rabbitmq emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/rabbitmq:managementffd1b50c522a
stdlib@go1.22.2
1.25.13

Open the chart page →

1,056
emissary-ingressemissary-ingress4.1.01 of 1See more

emissary-ingress emissary-ingress 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

962
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.55.0
1.25.13

Open the chart page →

2,837
parrot-mirroremmas-chartsVerified publisher1.0.01 of 1See more

parrot-mirror emmas-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.55.0
1.25.13

Open the chart page →

2,243
cost-reportempathyco0.7.81 of 1See more

cost-report empathyco 0.7.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
empathyco/cost-report:0.0.124f1e26eaacbf
stdlib@go1.15.15
1.25.13

Open the chart page →

1,167
deadman-switchempathyco0.0.21 of 1See more

deadman-switch empathyco 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
stdlib@go1.16.3
1.25.13

Open the chart page →

1,259
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.25.13

Open the chart page →

10,618
yace-exporterempathyco0.1.01 of 1See more

yace-exporter empathyco 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
stdlib@go1.17.3
1.25.13

Open the chart page →

1,642
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
stdlib@go1.19.10
0.55.0
1.25.13

Open the chart page →

1,329
kube-ecp-stackemqx-operator2.5.111 of 16See more

kube-ecp-stack emqx-operator 2.5.1

11 of the 16 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
golang.org/x/net@v0.23.0
stdlib@go1.23.3
0.55.0
1.25.13
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/net@v0.30.0
stdlib@go1.22.0
0.55.0
1.25.13
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.55.0
1.25.13
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.55.0
1.25.13
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.1e2dc5623bcdd
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

23,844
cnpg-monitoringenixVerified publisher0.3.01 of 1See more

cnpg-monitoring enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

824
kube-packetloss-exporterenixVerified publisher0.2.12 of 2See more

kube-packetloss-exporter enix 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.55.0
1.25.13
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

6,183
mariadb-operator-monitoringenixVerified publisher0.1.01 of 1See more

mariadb-operator-monitoring enix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

738
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.55.0
1.25.13

Open the chart page →

3,971

Container images carrying it

5,266 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
alpine/k8s:1.35.5d870622d0040
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
1
alpine/k8s:1.28.13e5c0b053fed7
golang.org/x/net@v0.12.0
stdlib@go1.22.5
0.55.0
1.25.13
1
alpine/k8s:1.32.3eec354133193
golang.org/x/net@v0.37.0
stdlib@go1.23.6
0.55.0
1.25.13
1
alpine/k8s:1.28.2fc059f056ad0
golang.org/x/net@v0.9.0
stdlib@go1.20.8
0.55.0
1.25.13
1
alpine/kubectl:1.36.01ee9df6316d4
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.55.0
1.25.13
1
alpine/kubectl:1.33.32c59a3f0726c
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
1
alpine/kubectl:1.35.0862d86046bbc
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
1
alpine/kubectl:1.35.3c4a11ae9a1cb
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
1
altinity/clickhouse-operator:0.27.30520bfb8015d
stdlib@go1.26.5
1.25.13
1
altinity/clickhouse-operator:0.25.41d6f18dbd599
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.55.0
1.25.13
1
altinity/clickhouse-operator:0.23.34baec90b20cd
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.55.0
1.25.13
1
altinity/clickhouse-operator:0.23.774315beb57db
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.55.0
1.25.13
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.13
0.55.0
1.25.13
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.55.0
1.25.13
1
altinity/clickhouse-operator:0.27.1a802b3a19d20
stdlib@go1.26.3
1.25.13
1
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.13.15
0.55.0
1.25.13
1
altinity/metrics-exporter:0.20.01a46d104406d
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.55.0
1.25.13
1
altinity/metrics-exporter:0.27.31e7c1d8167aa
stdlib@go1.26.5
1.25.13
1
altinity/metrics-exporter:0.23.32912a6c15b44
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.55.0
1.25.13
1
altinity/metrics-exporter:0.25.46ecf67edfb71
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.55.0
1.25.13
1
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.13.15
0.55.0
1.25.13
1
altinity/metrics-exporter:latest8940ecadae65
stdlib@go1.26.5
1.25.13
1
altinity/metrics-exporter:0.23.7a4d7ff0c727e
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.55.0
1.25.13
1
amaanx86/oci-native-ingress-controller:masterd7206ac7a319
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.55.0
1.25.13
1
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.55.0
1.25.13
1
amazon/aws-fsx-csi-driver:latestc9b14856fd22
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.55.0
1.25.13
1
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.55.0
1.25.13
1
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.55.0
1.25.13
1
amazon/cloudwatch-agent:latest-arm649dea6643715a
stdlib@go1.26.5
1.25.13
1
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.15
0.55.0
1.25.13
1
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
golang.org/x/net@v0.11.0
stdlib@go1.20.6
0.55.0
1.25.13
1
ambassador/aes-eg-ext:v4.0.0-preview.1b7eb1be3345d
golang.org/x/net@v0.11.0
stdlib@go1.20.6
0.55.0
1.25.13
1
ambassador/aes-wafsvc:v4.0.0-preview.15fc571509b8c
golang.org/x/net@v0.11.0
stdlib@go1.20.6
0.55.0
1.25.13
1
ambassador/ambassador-agent:1.0.227a1ea0d934fb
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
1
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.25.13
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
stdlib@go1.20.12
1.25.13
1
anchore/anchore-engine:v0.10.0bde9eedf639d
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.16.3
0.55.0
1.25.13
1
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.55.0
1.25.13
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.55.0
1.25.13
1
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.55.0
1.25.13
1
andreacioni/kube-workload-restarter:0.0.242938b310090a
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.55.0
1.25.13
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.25.13
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
stdlib@go1.18.2
1.25.13
1
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.25.13
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.55.0
1.25.13
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.25.13
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
stdlib@go1.25.7
1.25.13
1
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.25.13
1
anujdatar/cups:25.07.01685df04a643b
stdlib@go1.19.8
1.25.13
1
apache/airflow:2.8.4-python3.964e58748b6b9
stdlib@go1.21.8
1.25.13
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.