StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,642
of 17,813 indexed, latest versions
Container images
5,366
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,642 of 17,813 indexed charts deploy, on 5,366 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+191 more1.25.135,324
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,744
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,642 by stars
ChartLatestAffected imagesRadar Score
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

3,925
agent-control-bootstrapnewrelic1.8.161 of 1See more

agent-control-bootstrap newrelic 1.8.16

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:1.24.047520b65d6b2
stdlib@go1.26.5
1.25.13

Open the chart page →

998
agent-control-cdnewrelic1.0.03 of 3See more

agent-control-cd newrelic 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
golang.org/x/net@v0.35.0
stdlib@go1.23.6
0.55.0
1.25.13
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

5,519
nexus-freenexus-freeVerified publisher1.0.31 of 1See more

nexus-free nexus-free 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/fossa/postgres:17.2-15af45ac79f38
stdlib@go1.18.2
1.25.13

Open the chart page →

1,123
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-backend:2.0.0f80349eb018b
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

3,932
nginx-examplengrok-ingress-helm0.3.01 of 2See more

nginx-example ngrok-ingress-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
wernight/ngrok:latestd211f29ebcfe
golang.org/x/net@v0.17.0
stdlib@go1.21.6
0.55.0
1.25.13

Open the chart page →

3,089
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.9
0.55.0
1.25.13

Open the chart page →

24,394
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.9
0.55.0
1.25.13

Open the chart page →

25,572
filezillanicholaswildeVerified publisher1.0.11 of 1See more

filezilla nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/filezilla:version-3.51.0-r15103cdd266ce
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.12
0.55.0
1.25.13

Open the chart page →

3,178
golinksnicholaswildeVerified publisher1.0.01 of 1See more

golinks nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/golinks:version-154c5818e67b26324c5
stdlib@go1.16.5
1.25.13

Open the chart page →

1,118
notesnicholaswildeVerified publisher1.0.01 of 1See more

notes nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/notes:version-ee287b9ab9bc16465bc
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

1,482
olivetinnicholaswildeVerified publisher1.0.21 of 1See more

olivetin nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/olivetin:version-2021-07-19e1d5c8a01008
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

1,670
podgrabnicholaswildeVerified publisher0.1.01 of 1See more

podgrab nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.2
0.55.0
1.25.13

Open the chart page →

2,402
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.11
0.55.0
1.25.13

Open the chart page →

22,445
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.12
0.55.0
1.25.13

Open the chart page →

23,648
staticnicholaswildeVerified publisher1.0.01 of 1See more

static nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/static:version-ee8a20cd1d47c730bc4
stdlib@go1.16.5
1.25.13

Open the chart page →

1,155
todonicholaswildeVerified publisher0.1.01 of 1See more

todo nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/todo:941c0d3-ls1d7ba1341a940
stdlib@go1.14.15
1.25.13

Open the chart page →

1,230
twtxtnicholaswildeVerified publisher1.0.01 of 1See more

twtxt nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/twtxt:version-0.1.158736a73ca10
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

2,334
wikinicholaswildeVerified publisher1.0.01 of 1See more

wiki nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/wiki:version-900b76a6c4f261d8f5e
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

1,789
cert-managernicklasfrahm-cert-managerVerified publisher0.1.24 of 4See more

cert-manager nicklasfrahm-cert-manager 0.1.2

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.18.2af59e01ad975
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.18.281316365dc0b
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
quay.io/jetstack/cert-manager-startupapicheck:v1.18.21075e0974151
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.18.29431f0d8b510
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

2,856
ciliumnicklasfrahm-ciliumVerified publisher0.7.45 of 6See more

cilium nicklasfrahm-cilium 0.7.4

5 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
golang.org/x/net@v0.41.0
stdlib@go1.24.2
0.55.0
1.25.13
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
golang.org/x/net@v0.41.0
stdlib@go1.24.7
0.55.0
1.25.13
quay.io/cilium/hubble-relay:v1.18.26079308ee15e
golang.org/x/net@v0.42.0
stdlib@go1.24.7
0.55.0
1.25.13
quay.io/cilium/hubble-ui-backend:v0.13.3db1454e45dc3
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.55.0
1.25.13
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
golang.org/x/net@v0.42.0
stdlib@go1.24.7
0.55.0
1.25.13

Open the chart page →

7,265
metrics-servernicklasfrahm-metrics-serverVerified publisher0.1.11 of 1See more

metrics-server nicklasfrahm-metrics-server 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

799
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
stdlib@go1.21.5
1.25.13

Open the chart page →

2,294
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.6
0.55.0
1.25.13

Open the chart page →

2,063
terraform-backendnimbolus0.3.21 of 2See more

terraform-backend nimbolus 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/terraform-backend:0.2.2bf876252fbe1
golang.org/x/net@v0.46.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

2,519
yopassnimbolus0.6.11 of 2See more

yopass nimbolus 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jhaals/yopass:11.17.026873480863b
stdlib@go1.20.5
1.25.13

Open the chart page →

1,841
airflownineinfra-charts1.12.12 of 4See more

airflow nineinfra-charts 1.12.1

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.25.13
quay.io/prometheus/statsd-exporter:v0.22.8f53cca722a03
stdlib@go1.18.6
1.25.13

Open the chart page →

2,260
cloudnative-pgnineinfra-charts0.19.11 of 1See more

cloudnative-pg nineinfra-charts 0.19.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

1,188
doris-operatornineinfra-charts1.3.11 of 1See more

doris-operator nineinfra-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
selectdb/doris.k8s-operator:1.3.1919210765cb8
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.55.0
1.25.13

Open the chart page →

870
hdfs-operatornineinfra-charts0.7.01 of 1See more

hdfs-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nineinfra/hdfs-operator:v0.7.0debb1e3410e2
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

724
kyuubi-operatornineinfra-charts0.7.01 of 1See more

kyuubi-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nineinfra/kyuubi-operator:v0.7.08d8ed87ef77c
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.55.0
1.25.13

Open the chart page →

815
metastore-operatornineinfra-charts0.7.01 of 1See more

metastore-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nineinfra/metastore-operator:v0.7.011259032fb04
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.55.0
1.25.13

Open the chart page →

815
minio-directpvnineinfra-charts4.0.85 of 5See more

minio-directpv nineinfra-charts 4.0.8

5 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/minio/csi-node-driver-registrardigest-pinnedc805fdc16676
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13
quay.io/minio/csi-provisionerdigest-pinned7b5c070ec70d
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13
quay.io/minio/csi-resizerdigest-pinned819f68a4daf7
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13
quay.io/minio/directpv:v4.0.84560083eb77d
golang.org/x/net@v0.8.0
stdlib@go1.21.0
0.55.0
1.25.13
quay.io/minio/livenessprobedigest-pinnedf3bc9a84f149
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13

Open the chart page →

7,071
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
golang.org/x/net@v0.13.0
stdlib@go1.21.1
0.55.0
1.25.13

Open the chart page →

3,426
nineinfranineinfra-charts0.7.01 of 1See more

nineinfra nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nineinfra/nineinfra:v0.7.0d4aad414eccd
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

1,120
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.25.13

Open the chart page →

3,978
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13

Open the chart page →

1,440
zookeeper-operatornineinfra-charts0.7.01 of 1See more

zookeeper-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nineinfra/zookeeper-operator:v0.7.0af6eb2f37bfc
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

724
base-jobnn-coVerified publisher0.1.01 of 4See more

base-job nn-co 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
stdlib@go1.26.5
1.25.13

Open the chart page →

761
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

7,069
cosmoshub-rpcnodeifyVerified publisher1.0.71 of 2See more

cosmoshub-rpc nodeify 1.0.7

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.55.0
1.25.13

Open the chart page →

2,019
cosmos-nodenodeifyVerified publisher2.6.01 of 2See more

cosmos-node nodeify 2.6.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.55.0
1.25.13

Open the chart page →

2,019
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/net@v0.41.0
stdlib@go1.24.10
0.55.0
1.25.13

Open the chart page →

6,627
firehose-ethereumnodeifyVerified publisher1.7.11 of 2See more

firehose-ethereum nodeify 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

5,742
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
stdlib@go1.19.3
1.25.13

Open the chart page →

2,921
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.55.0
1.25.13

Open the chart page →

4,785
nodejsweeklynodejsweekly1.1.01 of 1See more

nodejsweekly nodejsweekly 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.16.15
0.55.0
1.25.13

Open the chart page →

1,490
node-labels-exporternode-labels-exporter0.1.91 of 1See more

node-labels-exporter node-labels-exporter 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/node-labels-exporter:v0.5.1dd6875a0a963
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

292
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/net@v0.19.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

2,985
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.55.0
1.25.13
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.55.0
1.25.13
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.55.0
1.25.13

Open the chart page →

7,759

Container images carrying it

5,366 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
buddyspencer/gickup:0.10.386b656f19b0c1
golang.org/x/net@v0.37.0
stdlib@go1.22.5
0.55.0
1.25.13
1
buddyspencer/gickup:0.10.309e7dbf923c12
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.55.0
1.25.13
1
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.55.0
1.25.13
1
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13
1
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.55.0
1.25.13
1
burningalchemist/sql_exporter:0.16.0b8e4757c7def
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.55.0
1.25.13
1
bytebase/bytebase:latesta6d845773b60
stdlib@go1.26.5
1.25.13
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13
1
caarlos0/domain_exporter:v1.23.0d11dec138900
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.55.0
1.25.13
1
calico/cni:v3.28.0cef0c907b8f4
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.55.0
1.25.13
1
calico/cni:v3.28.1e486870cfde8
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
1
calico/kube-controllers:v3.28.08f04e4772a2b
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.55.0
1.25.13
1
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
1
calico/node:v3.28.0385bf6391fea
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.55.0
1.25.13
1
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
1
camptocamp/bucket-cloner:latestacfafc308d88
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.5
0.55.0
1.25.13
1
captnbp/freebox-exporter:1.0.0-r01600c5a253e0
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13
1
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.15
0.55.0
1.25.13
1
casbin/casdoor:v1.224.066f836ef778b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.5
0.55.0
1.25.13
1
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/net@v0.21.0
stdlib@go1.20.12
0.55.0
1.25.13
1
casbin/casdoor:4.7.09d015582847d
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
castopod/castopod:1.12.101fd37280cbb2
stdlib@go1.21.13
1.25.13
1
castopod/castopod:1.15.54e4f0440520f
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.55.0
1.25.13
1
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.15.3
0.55.0
1.25.13
1
censedata/floating-server:v1.6.3ebfffb9dd4c0
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
1
cesanta/docker_auth:1.14.098e0307e0d2d
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.3
0.55.0
1.25.13
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.4
0.55.0
1.25.13
1
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.55.0
1.25.13
1
chaerr/kridge:demo-operator-v0.1.266833deec017
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.55.0
1.25.13
1
chainflag/eth-faucet:latestac642796bcb6
stdlib@go1.17.13
1.25.13
1
chainsafe/lodestar:latest5593f6e97912
stdlib@go1.23.1
1.25.13
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.25.13
1
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
golang.org/x/net@v0.25.0
stdlib@go1.19.13
0.55.0
1.25.13
1
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.15
0.55.0
1.25.13
1
chaosnative/cle-license-module:2.7.062cf6adc355e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.15
0.55.0
1.25.13
1
chaosnative/cle-server:2.7.0e7bcff4a20c0
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.16.15
0.55.0
1.25.13
1
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.55.0
1.25.13
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
stdlib@go1.20.12
1.25.13
1
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.8
0.55.0
1.25.13
1
chirpstack/chirpstack-application-server:3fb7667fe037f
golang.org/x/net@v0.0.0-20220726230323-06994584191e
stdlib@go1.19.3
0.55.0
1.25.13
1
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.17.5
0.55.0
1.25.13
1
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
golang.org/x/net@v0.8.0
stdlib@go1.19.3
0.55.0
1.25.13
1
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.17.8
0.55.0
1.25.13
1
chocobozzz/peertube:v8.1.5052712130691
stdlib@go1.24.4
1.25.13
1
chriseaton/adventureworks:latest54c3384ce701
stdlib@go1.23.1
1.25.13
1
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.55.0
1.25.13
1
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.55.0
1.25.13
1
chriswells0/first-mate:1.0.5f3918ec8471c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.