StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,555
of 17,787 indexed, latest versions
Container images
5,321
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,555 of 17,787 indexed charts deploy, on 5,321 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,287
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,690
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,555 by stars
ChartLatestAffected imagesRadar Score
aws-calicoaws0.3.111 of 1See more

aws-calico aws 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.55.0
1.25.13

Open the chart page →

2,250
aws-node-termination-handleraws-node-termination-handler0.27.61 of 1See more

aws-node-termination-handler aws-node-termination-handler 0.27.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.25.69ad31fb4e5be
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

525
snapschedulerbackube-helm-chartsVerified publisher3.5.02 of 2See more

snapscheduler backube-helm-charts 3.5.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/backube/snapscheduler:3.5.035ac95c51780
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.55.0
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

1,224
yataibentomlVerified publisher1.1.131 of 1See more

yatai bentoml 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.55.0
1.25.13

Open the chart page →

1,917
yatai-deploymentbentomlVerified publisher1.1.211 of 2See more

yatai-deployment bentoml 1.1.21

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.55.0
1.25.13

Open the chart page →

1,160
boundaryboundaryVerified publisher0.1.01 of 1See more

boundary boundary 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hashicorp/boundary:0.21.037bf86488b74
golang.org/x/net@v0.47.0
stdlib@go1.25.1
0.55.0
1.25.13

Open the chart page →

1,438
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.19.12
1.25.13

Open the chart page →

8,007
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.55.0
1.25.13

Open the chart page →

1,884
geoservercloudcamptocamp23.0.17 of 7See more

geoservercloud camptocamp2 3.0.1

7 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
stdlib@go1.26.5
1.25.13
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
stdlib@go1.26.5
1.25.13

Open the chart page →

10,819
version-checkercert-managerVerified publisher0.11.01 of 1See more

version-checker cert-manager 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.11.0eae9a374d22f
stdlib@go1.26.4
1.25.13

Open the chart page →

257
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.55.0
1.25.13
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.55.0
1.25.13

Open the chart page →

7,775
popeyechristianhuthVerified publisher2.4.31 of 1See more

popeye christianhuth 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.55.0
1.25.13

Open the chart page →

1,196
hellocloudechoVerified publisher0.1.21 of 1See more

hello cloudecho 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.25.13

Open the chart page →

1,817
cloudflare-exportercloudflare-exporter0.2.31 of 1See more

cloudflare-exporter cloudflare-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/lablabs/cloudflare_exporter:0.0.1670d74ec46602
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.55.0
1.25.13

Open the chart page →

791
ghostcloudpirates-ghostVerified publisher0.20.223 of 3See more

ghost cloudpirates-ghost 0.20.22

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
stdlib@go1.24.6
1.25.13
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.25.13
library/mariadb:12.3.3ab1c3dd38194
stdlib@go1.24.6
1.25.13

Open the chart page →

7,182
dumpscriptcloudscriptVerified publisher1.8.31 of 1See more

dumpscript cloudscript 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

2,126
clowardenclowarden0.2.32 of 4See more

clowarden clowarden 0.2.3

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.25.13
ghcr.io/cncf/clowarden/dbmigrator:v0.2.3c022fd42de45
stdlib@go1.25.3
1.25.13

Open the chart page →

5,620
cluster-manager-servercluster-manager-server1.8.01 of 1See more

cluster-manager-server cluster-manager-server 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.55.0
1.25.13

Open the chart page →

746
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
golang.org/x/net@v0.7.0
stdlib@go1.18
0.55.0
1.25.13

Open the chart page →

1,707
coder-observabilitycoder-observabilityVerified publisher0.7.314 of 21See more

coder-observability coder-observability 0.7.3

14 of the 21 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.55.0
1.25.13
grafana/grafana:10.4.19a9043254ba16
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
grafana/loki:3.1.0d947e68a84d9
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.55.0
1.25.13
grafana/loki-canary:3.1.039baf6d67f85
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.55.0
1.25.13
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.55.0
1.25.13
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.13
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.55.0
1.25.13
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.6
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.55.0
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
quay.io/prometheuscommunity/postgres-exporter:latestac5ec343104f
stdlib@go1.26.4
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

24,698
convertigoconvertigoOfficialVerified publisher8.4.32 of 5See more

convertigo convertigo 8.4.3

2 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.55.0
1.25.13
timescale/timescaledb:latest-pg16289d55704b1b
stdlib@go1.24.6
1.25.13

Open the chart page →

17,475
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

3,081
cosmocosmo-platformOfficialVerified publisher0.20.06 of 10See more

cosmo cosmo-platform 0.20.0

6 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.25.13
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.55.0
1.25.13
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.55.0
1.25.13
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
golang.org/x/net@v0.26.0
stdlib@go1.23.6
0.55.0
1.25.13
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
stdlib@go1.20.7
1.25.13

Open the chart page →

27,984
crossviewcrossviewOfficialVerified publisher4.6.01 of 2See more

crossview crossview 4.6.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

1,803
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
golang.org/x/net@v0.25.0
stdlib@go1.21.13
0.55.0
1.25.13

Open the chart page →

1,301
defensia-agentdefensia-agentOfficialVerified publisher0.6.01 of 1See more

defensia-agent defensia-agent 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/defensia/agent:1.4.57e9d40ae44711
golang.org/x/net@v0.47.0
0.55.0

Open the chart page →

64
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
golang.org/x/net@v0.17.0
stdlib@go1.21.10
0.55.0
1.25.13

Open the chart page →

3,451
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13

Open the chart page →

1,623
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.55.0
1.25.13

Open the chart page →

2,537
prometheus-locust-exporterdeliveryheroVerified publisher1.2.31 of 1See more

prometheus-locust-exporter deliveryhero 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.25.13

Open the chart page →

1,276
distrdistrOfficialVerified publisher4.0.01 of 4See more

distr distr 4.0.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/loki:3.7.7d70e4659623f
stdlib@go1.26.5
1.25.13

Open the chart page →

379
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.25.13

Open the chart page →

4,194
navidromedjjudas21Verified publisher6.8.41 of 1See more

navidrome djjudas21 6.8.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
deluan/navidrome:0.63.17c43af9f6516
stdlib@go1.26.5
1.25.13

Open the chart page →

160
bscdysnixVerified publisher0.6.591 of 4See more

bsc dysnix 0.6.59

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.55.0
1.25.13

Open the chart page →

2,012
element-callelement-callVerified publisher0.1.441 of 2See more

element-call element-call 0.1.44

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/element-hq/lk-jwt-service:0.6.0822f0c03a3bd
stdlib@go1.26.4
1.25.13

Open the chart page →

156
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.55.0
1.25.13

Open the chart page →

2,271
postgres-pgdump-backupeugen0.7.61 of 1See more

postgres-pgdump-backup eugen 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.25.13

Open the chart page →

353
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13

Open the chart page →

12,042
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13

Open the chart page →

14,545
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13

Open the chart page →

13,874
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.25.13

Open the chart page →

5,302
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.13

Open the chart page →

4,563
flyte-coreflyte2.0.481 of 3See more

flyte-core flyte 2.0.48

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.13

Open the chart page →

1,179
frp-operatorfrpVerified publisher1.0.41 of 1See more

frp-operator frp 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/aureum-cloud/frp-operator:v1.0.196b01d7e7025
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

368
frp-operatorfrp-operator1.9.01 of 1See more

frp-operator frp-operator 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
golang.org/x/net@v0.23.0
stdlib@go1.23.12
0.55.0
1.25.13

Open the chart page →

528
ascii-moviegabe565Verified publisher0.16.41 of 1See more

ascii-movie gabe565 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
stdlib@go1.24.0
1.25.13

Open the chart page →

986
domain-watchgabe565Verified publisher1.1.01 of 1See more

domain-watch gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/gabe565/domain-watch:latest34c5a1e351d6
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.55.0
1.25.13

Open the chart page →

789
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.7
0.55.0
1.25.13

Open the chart page →

3,030
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.25.13

Open the chart page →

1,110
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

7,579

Container images carrying it

5,321 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
anujdatar/cups:25.07.01685df04a643b
stdlib@go1.19.8
1.25.13
1
apache/airflow:2.8.4-python3.964e58748b6b9
stdlib@go1.21.8
1.25.13
1
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
stdlib@go1.23.7
1.25.13
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
stdlib@go1.22.7
1.25.13
1
apache/airflow:2.8.1e5560ad0b86e
stdlib@go1.19.8
1.25.13
1
apache/answer:2.0.2a0d71b0e30a5
stdlib@go1.25.12
1.25.13
1
apache/apisix-dashboard:2.9.0c010ea7d1694
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.15
0.55.0
1.25.13
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.13.8
0.55.0
1.25.13
1
apache/camel-k:1.10.43bb13d14f64a
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.13
0.55.0
1.25.13
1
apache/camel-k:2.11.0d173e7efe258
stdlib@go1.26.5
1.25.13
1
apache/doris:operator-latest3a4422656592
golang.org/x/net@v0.33.0
stdlib@go1.23.12
0.55.0
1.25.13
1
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.55.0
1.25.13
1
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.55.0
1.25.13
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.55.0
1.25.13
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.55.0
1.25.13
1
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.55.0
1.25.13
1
apache/solr-operator:v0.9.14db34508137f
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.55.0
1.25.13
1
apache/tika:latest-full80072bb73dd3
stdlib@go1.26.5
1.25.13
1
apache/tika:3.3.1.090b7fa1dc018
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.55.0
1.25.13
1
apache/yunikorn:web-1.9.0288e9c2db7f7
stdlib@go1.26.4
1.25.13
1
apache/yunikorn:scheduler-1.9.096832082e9cf
stdlib@go1.26.4
1.25.13
1
apache/yunikorn:admission-1.9.0fe8f5ec91f6c
stdlib@go1.26.4
1.25.13
1
apecloud/dt-platform:0.1.1d48bcbd38066
golang.org/x/net@v0.8.0
stdlib@go1.19.11
0.55.0
1.25.13
1
apecloud/gemini-scheduler:0.1.15832d1a9097a
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.55.0
1.25.13
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.55.0
1.25.13
1
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.13
0.55.0
1.25.13
1
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.55.0
1.25.13
1
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
stdlib@go1.19.6
0.55.0
1.25.13
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/net@v0.5.0
stdlib@go1.19.13
0.55.0
1.25.13
1
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/net@v0.40.0
stdlib@go1.25.7
0.55.0
1.25.13
1
appwrite/appwrite:1.9.6adc7d0e7ec23
golang.org/x/net@v0.40.0
stdlib@go1.25.10
0.55.0
1.25.13
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.55.0
1.25.13
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.55.0
1.25.13
1
aquasec/kube-bench:v0.6.176672264accce
stdlib@go1.20.4
1.25.13
1
aquasec/kube-bench:v0.15.07a8fa32dce21
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.55.0
1.25.13
1
aquasec/kube-bench:v0.6.9c329d73fea58
stdlib@go1.19
1.25.13
1
aquasec/postee:2.12.0-amd640795cba777e7
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
1
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.55.0
1.25.13
1
aquasec/starboard-operator:0.15.38e0b1c7ddc843
golang.org/x/net@v0.41.0
stdlib@go1.26.3
0.55.0
1.25.13
1
aquasec/tracee:0.24.1cfbbfee972e6
golang.org/x/net@v0.42.0
stdlib@go1.24.9
0.55.0
1.25.13
1
aquasec/trivy:0.43.1944a04445179
golang.org/x/net@v0.11.0
stdlib@go1.19.10
0.55.0
1.25.13
1
aquasec/trivy:0.32.0973d0df16189
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.55.0
1.25.13
1
aquasec/trivy:0.69.3bcc376de8d77
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13
1
archivebox/archivebox:0.7.41a5a37331091
stdlib@go1.24.6
1.25.13
1
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
golang.org/x/net@v0.34.0
stdlib@go1.22.10
0.55.0
1.25.13
1
aristidetm/basic-notebook:3.6.5469dbc951224
golang.org/x/net@v0.7.0
stdlib@go1.22.5
0.55.0
1.25.13
1
artifacthub/db-migrator:v1.23.028c13565ac5c
stdlib@go1.26.4
1.25.13
1
artifacthub/db-migrator:v1.19.02a746b289fcd
stdlib@go1.22.4
1.25.13
1
artifacthub/hub:v1.19.0111918d8c399
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.