StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,556
of 17,790 indexed, latest versions
Container images
5,324
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,556 of 17,790 indexed charts deploy, on 5,324 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,288
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,695
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,556 by stars
ChartLatestAffected imagesRadar Score
mealiedeimosfr-charts1.0.151 of 1See more

mealie deimosfr-charts 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
stdlib@go1.24.4
1.25.13

Open the chart page →

4,059
dregsydeliveryheroVerified publisher0.1.51 of 1See more

dregsy deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

2,977
gripmockdeliveryheroVerified publisher1.1.31 of 1See more

gripmock deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
stdlib@go1.14.6
1.25.13

Open the chart page →

2,793
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.55.0
1.25.13

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.55.0
1.25.13

Open the chart page →

7,987
snapshot-controllerdemocratic-csiVerified publisher0.3.01 of 1See more

snapshot-controller democratic-csi 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

467
developer-operatordeveloper-operatorVerified publisher2.1.21 of 1See more

developer-operator developer-operator 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.55.0
1.25.13

Open the chart page →

1,862
kube-bench-metricsdevopstalesVerified publisher0.1.01 of 1See more

kube-bench-metrics devopstales 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.25.13

Open the chart page →

2,111
kubedashdevopstalesOfficialVerified publisher4.0.05 of 8See more

kubedash devopstales 4.0.0

5 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18.3a9abf4275f9e
stdlib@go1.24.6
1.25.13
oliver006/redis_exporter:v1.82.0-alpineda9e89ee4e75
stdlib@go1.26.1
1.25.13
prom/statsd-exporter:v0.22.48be660470961
stdlib@go1.17.3
1.25.13
sosedoff/pgweb:latesta5256d416e2e
golang.org/x/net@v0.47.0
stdlib@go1.24.6
0.55.0
1.25.13
quay.io/prometheuscommunity/postgres-exporter:v0.19.1e96064f87622
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

9,271
permission-managerdevopstalesVerified publisher1.8.01 of 1See more

permission-manager devopstales 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.55.0
1.25.13

Open the chart page →

2,266
trivy-operatordevopstalesVerified publisher2.5.01 of 1See more

trivy-operator devopstales 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
devopstales/trivy-operator:2.575136aa7a26e
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

5,607
dnsmasqdevplayer0Verified publisher0.1.51 of 2See more

dnsmasq devplayer0 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

3,392
whoamidevplayer0Verified publisher0.1.21 of 1See more

whoami devplayer0 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
traefik/whoami:v1.6.12c52bb2c8480
stdlib@go1.15.6
1.25.13

Open the chart page →

1,216
calicodevtron0.1.14 of 4See more

calico devtron 0.1.1

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.55.0
1.25.13
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.55.0
1.25.13
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.55.0
1.25.13
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.25.13

Open the chart page →

10,094
clairdevtron0.1.141 of 2See more

clair devtron 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.6
0.55.0
1.25.13

Open the chart page →

6,237
discord-alertmanagerdevtron-labs0.10.01 of 1See more

discord-alertmanager devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.25.13

Open the chart page →

951
dex-serverdex-server1.19.12 of 3See more

dex-server dex-server 1.19.1

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dexidp/dex:v2.39.1-distroless43655afd1a8f
golang.org/x/net@v0.24.0
stdlib@go1.21.6
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/database-creator:1.19.162375abc3c56
stdlib@go1.23.12
1.25.13

Open the chart page →

2,245
digispoof-interfacedigispoof-interface1.0.01 of 3See more

digispoof-interface digispoof-interface 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,788
matomodigitalist-open-cloud-matomo12.0.201 of 3See more

matomo digitalist-open-cloud-matomo 12.0.20

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hipages/php-fpm_exporter:2.2.09b5be9d3d955
stdlib@go1.17.10
1.25.13

Open the chart page →

3,539
directusdirectus-io2.1.03 of 3See more

directus directus-io 2.1.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.13
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.13
directus/directus:12.0.29c8470ea465c
stdlib@go1.23.12
1.25.13

Open the chart page →

7,565
alertmanager-ntfydjjudas21Verified publisher0.1.21 of 1See more

alertmanager-ntfy djjudas21 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alexbakker/alertmanager-ntfy:1.0.12f4db8064595
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

641
dkim-managerdkim-managerVerified publisher0.2.01 of 1See more

dkim-manager dkim-manager 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/hsn723/dkim-manager:1.4.00312232b31a2
golang.org/x/net@v0.50.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

293
dnation-pingdnationcloud0.1.94 of 5See more

dnation-ping dnationcloud 0.1.9

4 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.5
0.55.0
1.25.13
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.25.13
prom/blackbox-exporter:v0.18.01ffc3f109eb3
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.15.2
0.55.0
1.25.13
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.2
0.55.0
1.25.13

Open the chart page →

10,469
docker-in-dockerdocker-in-docker0.0.31 of 2See more

docker-in-docker docker-in-docker 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/docker:24.0.2-dind1d148deae16a
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.55.0
1.25.13

Open the chart page →

2,585
docker-registrydocker-repository0.1.01 of 1See more

docker-registry docker-repository 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/registry:latest1be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.55.0
1.25.13

Open the chart page →

641
dockyarddockyardVerified publisher0.4.01 of 1See more

dockyard dockyard 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kgma74/dockyard:0.4.0b40439329191
golang.org/x/net@v0.29.0
stdlib@go1.26.5
0.55.0
1.25.13

Open the chart page →

1,551
thermitedollarshaveclubOfficialVerified publisher0.1.171 of 1See more

thermite dollarshaveclub 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dollarshaveclub/thermite:0.0.31663cbf25fcfe
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.1
0.55.0
1.25.13

Open the chart page →

2,739
domain-lockerdomain-locker0.2.81 of 3See more

domain-locker domain-locker 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.13

Open the chart page →

1,884
dominodominoVerified publisher0.1.111 of 3See more

domino domino 0.1.11

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
stdlib@go1.24.6
1.25.13

Open the chart page →

8,864
archerydoubanVerified publisher0.4.32 of 6See more

archery douban 0.4.3

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hanchuanchuan/goinception:latestb3c0dd26fb50
golang.org/x/net@v0.23.0
stdlib@go1.22.1
0.55.0
1.25.13
hhyo/archery:v1.9.11aa41843419e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.6
0.55.0
1.25.13

Open the chart page →

5,861
karmadoubanVerified publisher1.9.21 of 1See more

karma douban 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/prymitive/karma:v0.85d06892218680
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

2,017
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
stdlib@go1.21.4
1.25.13

Open the chart page →

10,911
dragonfly-stackdragonflyVerified publisher0.1.24 of 7See more

dragonfly-stack dragonfly 0.1.2

4 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
dragonflyoss/manager:v2.1.49c3ef7f10698d
golang.org/x/net@v0.19.0
stdlib@go1.21.1
0.55.0
1.25.13
dragonflyoss/scheduler:v2.1.49523785c77787
golang.org/x/net@v0.19.0
stdlib@go1.21.1
0.55.0
1.25.13
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

18,480
nydus-snapshotterdragonflyVerified publisher0.0.101 of 2See more

nydus-snapshotter dragonfly 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

3,668
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
stdlib@go1.20.12
1.25.13

Open the chart page →

5,754
dyff-operatordyff-operatorVerified publisher0.24.201 of 1See more

dyff-operator dyff-operator 0.24.20

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-operator:0.24.20e9ca51627601
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

273
gethdysnixVerified publisher1.1.21 of 1See more

geth dysnix 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ethereum/client-go:v1.14.8886ec69b35b0
golang.org/x/net@v0.24.0
stdlib@go1.22.6
0.55.0
1.25.13

Open the chart page →

1,625
jenkinsedu2.7.11 of 2See more

jenkins edu 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

4,445
glpieftechcombr-glpiVerified publisher2.12.01 of 5See more

glpi eftechcombr-glpi 2.12.0

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:12.3.2a02fe89cb597
stdlib@go1.24.6
1.25.13

Open the chart page →

4,415
egagenteginnovationsVerified publisher0.10.01 of 1See more

egagent eginnovations 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
eginnovations/agent:7.5.4e4dfe242fe9f
stdlib@go1.26.4
1.25.13

Open the chart page →

1,347
glideeinstackOfficialVerified publisher0.0.21 of 1See more

glide einstack 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.55.0
1.25.13

Open the chart page →

1,335
elchi-discoveryelchi1.0.01 of 1See more

elchi-discovery elchi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jhonbrownn/elchi-discovery:latest8f6551ecc98c
golang.org/x/net@v0.13.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

638
elchi-stackelchi1.13.06 of 10See more

elchi-stack elchi 1.13.0

6 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:12.2.074144189b384
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
jhonbrownn/elchi-backend:v1.6.14-v0.14.0-envoy1.39.031aee9ba2c63
stdlib@go1.25.12
1.25.13
jhonbrownn/elchi-collector:v0.1.119fdd0724865e
stdlib@go1.26.4
1.25.13
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.25.13
otel/opentelemetry-collector-contrib:0.89.0995f17004231
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.55.0
1.25.13
victoriametrics/victoria-metrics:v1.93.577a9815d0640
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.55.0
1.25.13

Open the chart page →

15,540
navidromeemmas-chartsVerified publisher0.0.61 of 1See more

navidrome emmas-charts 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
deluan/navidrome:0.50.02cf4442b0099
golang.org/x/net@v0.18.0
stdlib@go1.21.0
0.55.0
1.25.13

Open the chart page →

2,129
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.25.13

Open the chart page →

31,674
eoapieoapiOfficialVerified publisher0.16.21 of 7See more

eoapi eoapi 0.16.2

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

6,453
nexus-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

nexus-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.2
0.55.0
1.25.13

Open the chart page →

2,266
paraerudikaVerified publisher0.3.01 of 1See more

para erudika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
erudikaltd/para:latest_stable235e0bc53da2
stdlib@go1.26.5
1.25.13

Open the chart page →

1,130
httpbingoestahnVerified publisher0.1.11 of 1See more

httpbingo estahn 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mccutchen/go-httpbin:v2.2.25994403ef75b
stdlib@go1.16.2
1.25.13

Open the chart page →

1,359
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.55.0
1.25.13

Open the chart page →

3,096

Container images carrying it

5,324 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/net@v0.17.0
stdlib@go1.21.9
0.55.0
1.25.13
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.55.0
1.25.13
1
bluenviron/mediamtx:1.17.19e39256d1ba3
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.55.0
1.25.13
1
bolkedebruin/rdpgw:masterc0dc0589373a
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.55.0
1.25.13
1
bonovoo/secrethor:1.1.2bb93b68fcd17
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.55.0
1.25.13
1
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.55.0
1.25.13
1
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.12
0.55.0
1.25.13
1
btcpayserver/tor:0.4.8.10e9585b68dc6b
stdlib@go1.16.5
1.25.13
1
buddyspencer/gickup:0.10.386b656f19b0c1
golang.org/x/net@v0.37.0
stdlib@go1.22.5
0.55.0
1.25.13
1
buddyspencer/gickup:0.10.309e7dbf923c12
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.55.0
1.25.13
1
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.55.0
1.25.13
1
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13
1
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.55.0
1.25.13
1
burningalchemist/sql_exporter:0.16.0b8e4757c7def
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.55.0
1.25.13
1
byjg/static-httpserver:latest562cc8b9c40b
stdlib@go1.26.1
1.25.13
1
bytebase/bytebase:latest9fcde38c0d5f
stdlib@go1.26.5
1.25.13
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13
1
caarlos0/domain_exporter:v1.23.0d11dec138900
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.55.0
1.25.13
1
calico/cni:v3.28.0cef0c907b8f4
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.55.0
1.25.13
1
calico/cni:v3.28.1e486870cfde8
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
1
calico/kube-controllers:v3.28.08f04e4772a2b
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.55.0
1.25.13
1
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
1
calico/node:v3.28.0385bf6391fea
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.55.0
1.25.13
1
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
1
camptocamp/bucket-cloner:latestacfafc308d88
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.5
0.55.0
1.25.13
1
captnbp/freebox-exporter:1.0.0-r01600c5a253e0
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13
1
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.15
0.55.0
1.25.13
1
casbin/casdoor:v1.224.066f836ef778b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.5
0.55.0
1.25.13
1
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/net@v0.21.0
stdlib@go1.20.12
0.55.0
1.25.13
1
casbin/casdoor:3.62.17729da148c61
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
casbin/casdoor:4.4.08511c0757ac3
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
casbin/casdoor:3.62.0e08231f16c00
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
castopod/castopod:1.12.101fd37280cbb2
stdlib@go1.21.13
1.25.13
1
castopod/castopod:1.15.54e4f0440520f
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.55.0
1.25.13
1
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.15.3
0.55.0
1.25.13
1
censedata/floating-server:v1.6.3ebfffb9dd4c0
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
1
cesanta/docker_auth:1.14.098e0307e0d2d
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.3
0.55.0
1.25.13
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.4
0.55.0
1.25.13
1
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.55.0
1.25.13
1
chaerr/kridge:demo-operator-v0.1.266833deec017
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.55.0
1.25.13
1
chainflag/eth-faucet:latestac642796bcb6
stdlib@go1.17.13
1.25.13
1
chainsafe/lodestar:latest5593f6e97912
stdlib@go1.23.1
1.25.13
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.25.13
1
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
golang.org/x/net@v0.25.0
stdlib@go1.19.13
0.55.0
1.25.13
1
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.15
0.55.0
1.25.13
1
chaosnative/cle-license-module:2.7.062cf6adc355e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.15
0.55.0
1.25.13
1
chaosnative/cle-server:2.7.0e7bcff4a20c0
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.16.15
0.55.0
1.25.13
1
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.55.0
1.25.13
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.