StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,556
of 17,790 indexed, latest versions
Container images
5,324
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,556 of 17,790 indexed charts deploy, on 5,324 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,288
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,695
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,556 by stars
ChartLatestAffected imagesRadar Score
generic-appb3oVerified publisher0.1.61 of 1See more

generic-app b3o 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.25.13

Open the chart page →

1,280
vault-unsealbabykart-helm-chartsVerified publisher1.0.51 of 1See more

vault-unseal babykart-helm-charts 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/lrstanley/vault-unseal:1.0.1dd873930b6df
stdlib@go1.26.5
1.25.13

Open the chart page →

205
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

4,821
music-assistantbdclark-helm-chartsVerified publisher0.4.131 of 1See more

music-assistant bdclark-helm-charts 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.3885872224fa5
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

3,702
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.8
0.55.0
1.25.13
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.17.5
0.55.0
1.25.13
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.17.8
0.55.0
1.25.13

Open the chart page →

7,821
livekit-serverbeeinventor1.0.01 of 2See more

livekit-server beeinventor 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

2,609
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.55.0
1.25.13

Open the chart page →

1,595
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/net@v0.10.0
stdlib@go1.20.8
0.55.0
1.25.13

Open the chart page →

2,908
yatai-image-builderbentomlVerified publisher3.0.441 of 1See more

yatai-image-builder bentoml 3.0.44

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-image-builder:3.0.4401d8538c4f48
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

492
aramid-indexerbiatec-repoVerified publisher3.9.04 of 5See more

aramid-indexer biatec-repo 3.9.0

4 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.13
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.55.0
1.25.13
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.55.0
1.25.13
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.55.0
1.25.13

Open the chart page →

13,544
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

7,246
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
golang.org/x/net@v0.39.0
stdlib@go1.23.11
0.55.0
1.25.13

Open the chart page →

5,117
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

7,246
self-hostbitwarden2.4.110 of 11See more

self-host bitwarden 2.4.1

10 of the 11 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/bitwarden/admin:2026.8.2eb950aea1b34
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/api:2026.8.28b3774af74b4
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/attachments:2026.8.2754553d14aa0
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/events:2026.8.2eb836d99a14e
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/icons:2026.8.2183d536d0186
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/identity:2026.8.2738553de549c
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/notifications:2026.8.2f280dda4fbee
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/sso:2026.8.2727314be4cb1
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/web:2026.8.1dd1df8408daf
stdlib@go1.26.5
1.25.13
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
stdlib@go1.23.1
1.25.13

Open the chart page →

5,269
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
stdlib@go1.21.6
1.25.13

Open the chart page →

2,919
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

1,630
syncthingbrandan-schmitz-helm-chartsVerified publisher2.1.01 of 1See more

syncthing brandan-schmitz-helm-charts 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
syncthing/syncthing:2.1.1775c4aac4862
stdlib@go1.26.3
1.25.13

Open the chart page →

1,230
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,839
btrfs-nfs-csibtrfs-nfs-csi0.4.06 of 7See more

btrfs-nfs-csi btrfs-nfs-csi 0.4.0

6 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

3,226
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.55.0
1.25.13

Open the chart page →

2,049
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.55.0
1.25.13

Open the chart page →

2,670
buildkite-agent-metricsbuildkite-agent-metrics0.1.01 of 1See more

buildkite-agent-metrics buildkite-agent-metrics 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.55.0
1.25.13

Open the chart page →

1,541
buildkit-fleetbuildkit-fleetVerified publisher0.1.21 of 1See more

buildkit-fleet buildkit-fleet 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
moby/buildkit:v0.33.0-rootless80b15f0735e8
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

910
static-httpserverbyjgVerified publisher0.2.01 of 1See more

static-httpserver byjg 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
byjg/static-httpserver:latest562cc8b9c40b
stdlib@go1.26.1
1.25.13

Open the chart page →

677
nacosbytectl0.1.61 of 1See more

nacos bytectl 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.25.13

Open the chart page →

1,827
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

1,490
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

1,490
pgcagriekinVerified publisher2.1.01 of 2See more

pg cagriekin 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.13

Open the chart page →

2,309
pgvectorcagriekinVerified publisher2.1.02 of 3See more

pgvector cagriekin 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.13
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
stdlib@go1.24.6
1.25.13

Open the chart page →

4,056
camel-dashboard-operatorcamel-dashboardVerified publisher0.1.01 of 1See more

camel-dashboard-operator camel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.55.0
1.25.13

Open the chart page →

520
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

913
capsulecapsuleOfficialVerified publisher0.14.62 of 2See more

capsule capsule 0.14.6

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
stdlib@go1.26.4
1.25.13

Open the chart page →

1,238
capsule-proxycapsule-proxyOfficialVerified publisher0.14.12 of 2See more

capsule-proxy capsule-proxy 0.14.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
ghcr.io/projectcapsule/capsule-proxy:v0.14.17c90292e3172
stdlib@go1.26.4
1.25.13

Open the chart page →

1,224
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.2
0.55.0
1.25.13

Open the chart page →

3,509
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/net@v0.27.0
stdlib@go1.23.0
0.55.0
1.25.13

Open the chart page →

1,810
cert-estuarycert-estuaryVerified publisher0.2.11 of 1See more

cert-estuary cert-estuary 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/hsn723/cert-estuary:0.2.00c4b6132b0ad
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

268
cert-manager-approver-policycert-managerOfficialVerified publisher0.27.01 of 1See more

cert-manager-approver-policy cert-manager 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-approver-policy:v0.27.074799ce00f47
stdlib@go1.26.5
1.25.13

Open the chart page →

78
cert-manager-google-cas-issuercert-managerOfficialVerified publisher0.12.01 of 1See more

cert-manager-google-cas-issuer cert-manager 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-google-cas-issuer:v0.12.08bd9cdb714a6
stdlib@go1.26.4
1.25.13

Open the chart page →

164
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13

Open the chart page →

12,611
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/net@v0.9.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

1,074
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
golang.org/x/net@v0.26.0
stdlib@go1.22.0
0.55.0
1.25.13

Open the chart page →

1,031
cert-vaultcert-vaultOfficialVerified publisher2.12.04 of 7See more

cert-vault cert-vault 2.12.0

4 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/net@v0.33.0
stdlib@go1.23.7
0.55.0
1.25.13
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
stdlib@go1.23.7
1.25.13
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.25.13
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13

Open the chart page →

16,056
chatclichatcliVerified publisher1.205.01 of 2See more

chatcli chatcli 1.205.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/net@v0.26.0
stdlib@go1.23.10
0.55.0
1.25.13

Open the chart page →

1,028
etcd-defragchristianhuthVerified publisher1.6.11 of 1See more

etcd-defrag christianhuth 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.7.13c66a5191d37
stdlib@go1.26.5
1.25.13

Open the chart page →

135
passbolt-hachristianhuthVerified publisher6.0.13 of 4See more

passbolt-ha christianhuth 6.0.1

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.13
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.55.0
1.25.13
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.25.13

Open the chart page →

10,931
shlink-backendchristianhuthVerified publisher11.11.11 of 1See more

shlink-backend christianhuth 11.11.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
shlinkio/shlink:5.1.6666cc24edf72
stdlib@go1.26.4
1.25.13

Open the chart page →

195
squestchristianhuthVerified publisher6.6.72 of 4See more

squest christianhuth 6.6.7

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.25.13
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.13

Open the chart page →

10,039
typo3christianhuthVerified publisher7.7.11 of 2See more

typo3 christianhuth 7.7.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.13

Open the chart page →

8,597
challengerchronicleVerified publisher0.1.11 of 1See more

challenger chronicle 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
stdlib@go1.22.12
1.25.13

Open the chart page →

977
erpcchronicleVerified publisher0.7.01 of 1See more

erpc chronicle 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/erpc/erpc:0.1.18bfed3d49a08
stdlib@go1.26.4
1.25.13

Open the chart page →

382

Container images carrying it

5,324 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/net@v0.17.0
stdlib@go1.21.9
0.55.0
1.25.13
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.55.0
1.25.13
1
bluenviron/mediamtx:1.17.19e39256d1ba3
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.55.0
1.25.13
1
bolkedebruin/rdpgw:masterc0dc0589373a
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.55.0
1.25.13
1
bonovoo/secrethor:1.1.2bb93b68fcd17
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.55.0
1.25.13
1
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.55.0
1.25.13
1
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.12
0.55.0
1.25.13
1
btcpayserver/tor:0.4.8.10e9585b68dc6b
stdlib@go1.16.5
1.25.13
1
buddyspencer/gickup:0.10.386b656f19b0c1
golang.org/x/net@v0.37.0
stdlib@go1.22.5
0.55.0
1.25.13
1
buddyspencer/gickup:0.10.309e7dbf923c12
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.55.0
1.25.13
1
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.55.0
1.25.13
1
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13
1
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.55.0
1.25.13
1
burningalchemist/sql_exporter:0.16.0b8e4757c7def
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.55.0
1.25.13
1
byjg/static-httpserver:latest562cc8b9c40b
stdlib@go1.26.1
1.25.13
1
bytebase/bytebase:latest9fcde38c0d5f
stdlib@go1.26.5
1.25.13
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13
1
caarlos0/domain_exporter:v1.23.0d11dec138900
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.55.0
1.25.13
1
calico/cni:v3.28.0cef0c907b8f4
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.55.0
1.25.13
1
calico/cni:v3.28.1e486870cfde8
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
1
calico/kube-controllers:v3.28.08f04e4772a2b
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.55.0
1.25.13
1
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
1
calico/node:v3.28.0385bf6391fea
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.55.0
1.25.13
1
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
1
camptocamp/bucket-cloner:latestacfafc308d88
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.5
0.55.0
1.25.13
1
captnbp/freebox-exporter:1.0.0-r01600c5a253e0
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13
1
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.15
0.55.0
1.25.13
1
casbin/casdoor:v1.224.066f836ef778b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.5
0.55.0
1.25.13
1
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/net@v0.21.0
stdlib@go1.20.12
0.55.0
1.25.13
1
casbin/casdoor:3.62.17729da148c61
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
casbin/casdoor:4.4.08511c0757ac3
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
casbin/casdoor:3.62.0e08231f16c00
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
castopod/castopod:1.12.101fd37280cbb2
stdlib@go1.21.13
1.25.13
1
castopod/castopod:1.15.54e4f0440520f
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.55.0
1.25.13
1
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.15.3
0.55.0
1.25.13
1
censedata/floating-server:v1.6.3ebfffb9dd4c0
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
1
cesanta/docker_auth:1.14.098e0307e0d2d
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.3
0.55.0
1.25.13
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.4
0.55.0
1.25.13
1
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.55.0
1.25.13
1
chaerr/kridge:demo-operator-v0.1.266833deec017
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.55.0
1.25.13
1
chainflag/eth-faucet:latestac642796bcb6
stdlib@go1.17.13
1.25.13
1
chainsafe/lodestar:latest5593f6e97912
stdlib@go1.23.1
1.25.13
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.25.13
1
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
golang.org/x/net@v0.25.0
stdlib@go1.19.13
0.55.0
1.25.13
1
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.15
0.55.0
1.25.13
1
chaosnative/cle-license-module:2.7.062cf6adc355e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.15
0.55.0
1.25.13
1
chaosnative/cle-server:2.7.0e7bcff4a20c0
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.16.15
0.55.0
1.25.13
1
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.55.0
1.25.13
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.