StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,643
of 17,821 indexed, latest versions
Container images
5,380
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,643 of 17,821 indexed charts deploy, on 5,380 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,337
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,758
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,643 by stars
ChartLatestAffected imagesRadar Score
haproxy-loadbalanced-redisrivals-spaceVerified publisher0.1.21 of 3See more

haproxy-loadbalanced-redis rivals-space 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
haproxytech/haproxy-alpine:2.6.614e4afa90dfd
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.55.0
1.25.13

Open the chart page →

1,425
harvester-cloud-providerrke2-charts0.2.15002 of 2See more

harvester-cloud-provider rke2-charts 0.2.1500

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/harvester-cloud-provider:v0.2.8199961f11ba6
stdlib@go1.26.5
1.25.13
rancher/mirrored-kube-vip-kube-vip-iptables:v1.2.389c3f898ac5a
stdlib@go1.26.5
1.25.13

Open the chart page →

460
harvester-csi-driverrke2-charts0.1.32005 of 6See more

harvester-csi-driver rke2-charts 0.1.3200

5 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/mirrored-longhornio-csi-attacher:v4.11.0-20260428fe417c28a6b8
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.55.0
1.25.13
rancher/mirrored-longhornio-csi-node-driver-registrar:v2.16.0-20260428e82a8c8f800d
golang.org/x/net@v0.49.0
stdlib@go1.25.9
0.55.0
1.25.13
rancher/mirrored-longhornio-csi-provisioner:v5.3.0-202604289e519a21a77c
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.55.0
1.25.13
rancher/mirrored-longhornio-csi-resizer:v2.1.0-2026042841cb674d1154
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.55.0
1.25.13
rancher/mirrored-longhornio-csi-snapshotter:v8.5.0-202604281975fac3890f
golang.org/x/net@v0.49.0
stdlib@go1.25.9
0.55.0
1.25.13

Open the chart page →

2,131
rancher-vsphere-cpirke2-charts1.16.2001 of 1See more

rancher-vsphere-cpi rke2-charts 1.16.200

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/mirrored-cloud-provider-vsphere:v1.31.1febfd0517838
golang.org/x/net@v0.26.0
stdlib@go1.22.8
0.55.0
1.25.13

Open the chart page →

920
rke2-calicorke2-charts3.18.1-1011 of 1See more

rke2-calico rke2-charts 3.18.1-101

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.15.1c6591da87aa8
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.55.0
1.25.13

Open the chart page →

2,251
rke2-canal-1.19-1.20rke2-charts3.13.3-build20211022022 of 2See more

rke2-canal-1.19-1.20 rke2-charts 3.13.3-build2021102202

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.55.0

Open the chart page →

5,959
rke2-ciliumrke2-charts1.20.2001 of 3See more

rke2-cilium rke2-charts 1.20.200

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.22939231d0d3e
stdlib@go1.26.5
1.25.13

Open the chart page →

632
kubernetes-diff-loggerrlex0.1.21 of 1See more

kubernetes-diff-logger rlex 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/kubernetes-diff-logger:0.0.598f6d1cd1e25
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

2,455
runtimeclass-controllerrlex0.1.01 of 1See more

runtimeclass-controller rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/jlclx/runtimeclass-controller:latestb3a87f92a963
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.13
0.55.0
1.25.13

Open the chart page →

2,190
yopassrlex0.8.01 of 2See more

yopass rlex 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jhaals/yopass:11.15.16bca8d5a4914
stdlib@go1.20.5
1.25.13

Open the chart page →

1,096
memosrm3lVerified publisher0.1.11 of 1See more

memos rm3l 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
neosmemo/memos:0.24c6defc2dfb98
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

1,624
ntfyrm3lVerified publisher0.1.11 of 1See more

ntfy rm3l 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
golang.org/x/net@v0.25.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

1,283
olivetinrm3lVerified publisher0.2.01 of 1See more

olivetin rm3l 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
golang.org/x/net@v0.33.0
stdlib@go1.22.0
0.55.0
1.25.13

Open the chart page →

1,378
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
stdlib@go1.20.7
1.25.13

Open the chart page →

2,972
krr-enforcerrobusta0.3.51 of 2See more

krr-enforcer robusta 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/k8s:1.30.0bd01dae02676
golang.org/x/net@v0.23.0
stdlib@go1.21.1
0.55.0
1.25.13

Open the chart page →

4,049
kubewatchrobusta3.5.01 of 1See more

kubewatch robusta 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
robustadev/kubewatch:v2.9.00457a51e36e8
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

1,857
pagesroccohiggins-pages1.0.01 of 3See more

pages roccohiggins-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,287
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.13
0.55.0
1.25.13

Open the chart page →

3,040
easy-olm-operatorrock8sVerified publisher0.0.11 of 1See more

easy-olm-operator rock8s 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/bitspur/rock8s/easy-olm-operator:0.0.1779454fea06c
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.10
0.55.0
1.25.13

Open the chart page →

953
fleet-vendoredrock8sVerified publisher6.5.11 of 1See more

fleet-vendored rock8s 6.5.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
fleetdm/fleet:v4.66.012e644b7f40e
golang.org/x/net@v0.36.0
stdlib@go1.23.4
0.55.0
1.25.13

Open the chart page →

1,742
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.16.14
0.55.0
1.25.13

Open the chart page →

5,435
imgproxyrock8sVerified publisher0.8.301 of 1See more

imgproxy rock8s 0.8.30

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/net@v0.7.0
stdlib@go1.20
0.55.0
1.25.13

Open the chart page →

2,039
mailserverrock8sVerified publisher0.1.21 of 1See more

mailserver rock8s 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.55.0
1.25.13

Open the chart page →

1,955
matrix-stackrock8sVerified publisher0.8.14 of 7See more

matrix-stack rock8s 0.8.1

4 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.25.13
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
stdlib@go1.19.8
1.25.13
prometheuscommunity/postgres-exporter:v0.17.0f8381eb4326a
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.55.0
1.25.13
ghcr.io/element-hq/ess-helm/matrix-tools:0.3.20eac0521be29
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.55.0
1.25.13

Open the chart page →

9,166
resource-binding-operatorrock8sVerified publisher0.1.01 of 1See more

resource-binding-operator rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.063cf51392ce7
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.13
0.55.0
1.25.13

Open the chart page →

917
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
stdlib@go1.18.1
1.25.13

Open the chart page →

6,250
zentaorock8sVerified publisher0.0.11 of 1See more

zentao rock8s 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
easysoft/quickon-zentao:18.5592ad5df1f8b
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.20.3
0.55.0
1.25.13

Open the chart page →

1,535
monitoringrocketchat-server0.0.177 of 9See more

monitoring rocketchat-server 0.0.17

7 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/loki:3.6.3cd6e176883a9
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.55.0
1.25.13
otel/opentelemetry-collector-contrib:0.143.03bc07732530c
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13
ghcr.io/grafana/grafana-operator:v5.18.00af2faec9d6f
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.83.0b6a89b8ec08f
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

7,049
jaegerromanow-helm-chartsVerified publisher1.7.31 of 1See more

jaeger romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jaegertracing/jaeger:2.9.0e128b9adbb29
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.55.0
1.25.13

Open the chart page →

1,624
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.55.0
1.25.13

Open the chart page →

9,797
argocdromholdings1.8.12 of 3See more

argocd romholdings 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
stdlib@go1.14.12
0.55.0
1.25.13
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.9
0.55.0
1.25.13

Open the chart page →

10,487
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.17.13
0.55.0
1.25.13

Open the chart page →

13,206
argo-workflowromholdings0.1.61 of 1See more

argo-workflow romholdings 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
stdlib@go1.19.8
0.55.0
1.25.13

Open the chart page →

1,587
caddy-reverse-proxyromholdings0.10.11 of 1See more

caddy-reverse-proxy romholdings 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/caddy:latestdf7f1c2fb114
stdlib@go1.26.3
1.25.13

Open the chart page →

863
calertromholdings0.0.11 of 1See more

calert romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
stdlib@go1.18
1.25.13

Open the chart page →

4,713
calicoromholdings0.1.14 of 4See more

calico romholdings 0.1.1

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.55.0
1.25.13
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.55.0
1.25.13
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.55.0
1.25.13
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.25.13

Open the chart page →

10,099
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.6
0.55.0
1.25.13

Open the chart page →

6,242
devtron-enterpriseromholdings48.0.022 of 28See more

devtron-enterprise romholdings 48.0.0

22 of the 28 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.55.0
1.25.13
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
golang.org/x/net@v0.48.0
stdlib@go1.24.0
0.55.0
1.25.13
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.55.0
1.25.13
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.55.0
1.25.13
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.55.0
1.25.13
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.25.13
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.55.0
1.25.13
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
stdlib@go1.25.5
0.55.0
1.25.13
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.15
0.55.0
1.25.13
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.55.0
1.25.13
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.55.0
1.25.13
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.55.0
1.25.13
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.25.13
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.19.2
0.55.0
1.25.13
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.25.13
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.25.13
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.55.0
1.25.13
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.25.13
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

69,789
devtron-in-clustercdromholdings0.10.22 of 2See more

devtron-in-clustercd romholdings 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.55.0
1.25.13
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.55.0
1.25.13

Open the chart page →

5,057
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.55.0
1.25.13

Open the chart page →

4,993
devtron-operatorromholdings0.23.310 of 11See more

devtron-operator romholdings 0.23.3

10 of the 11 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.55.0
1.25.13
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.55.0
1.25.13
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.25.13
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.55.0
1.25.13
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.55.0
1.25.13
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.55.0
1.25.13
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.55.0
1.25.13
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.55.0
1.25.13
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.25.13
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.55.0
1.25.13

Open the chart page →

33,425
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.17.3
0.55.0
1.25.13

Open the chart page →

12,001
discord-alertmanagerromholdings0.10.01 of 1See more

discord-alertmanager romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.25.13

Open the chart page →

952
jcmhproxy-ingressromholdings0.14.61 of 1See more

jcmhproxy-ingress romholdings 0.14.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.55.0
1.25.13

Open the chart page →

1,380
kube-prometheus-stackromholdings19.3.03 of 6See more

kube-prometheus-stack romholdings 19.3.0

3 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.55.0
1.25.13

Open the chart page →

8,664
migrantromholdings0.0.31 of 1See more

migrant romholdings 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
migrate/migrate:latestcc4ad8e19d66
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13

Open the chart page →

743
migration-incluster-cdromholdings0.10.01 of 1See more

migration-incluster-cd romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.25.13

Open the chart page →

3,963
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.16.10
0.55.0
1.25.13

Open the chart page →

2,443
winter-soldierromholdings0.10.61 of 1See more

winter-soldier romholdings 0.10.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

1,177
zincromholdings0.1.21 of 1See more

zinc romholdings 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.7
0.55.0
1.25.13

Open the chart page →

1,514

Container images carrying it

5,380 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
darkobas/tokenexporter:latesta0349a0eedf0
stdlib@go1.19.1
1.25.13
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.55.0
1.25.13
1
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/net@v0.7.0
stdlib@go1.20
0.55.0
1.25.13
1
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.55.0
1.25.13
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/net@v0.41.0
stdlib@go1.24.3
0.55.0
1.25.13
1
dashops/dash-ops:latest23537693ff05
golang.org/x/net@v0.46.0
stdlib@go1.25.10
0.55.0
1.25.13
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
stdlib@go1.16.9
1.25.13
1
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.11
0.55.0
1.25.13
1
datadog/agent:6aad9994de6a7
golang.org/x/net@v0.33.0
stdlib@go1.21.11
0.55.0
1.25.13
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.15
0.55.0
1.25.13
1
datadog/operator:0.3.117f08a860090
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.2
0.55.0
1.25.13
1
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.21.4
0.55.0
1.25.13
1
datappeal/hive-metastore:lateste38c085a3567
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.4
0.55.0
1.25.13
1
datappeal/trino-exporter:latest325b91c2b09e
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.15
0.55.0
1.25.13
1
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.17.13
0.55.0
1.25.13
1
datasaker/dsk-container-agent:latest08b52999f67b
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.55.0
1.25.13
1
datasaker/dsk-k8s-agent:latest2542ee73be51
golang.org/x/net@v0.17.0
stdlib@go1.19.1
0.55.0
1.25.13
1
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.55.0
1.25.13
1
datasaker/dsk-node-agent:latest1b95913b6729
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.55.0
1.25.13
1
datasaker/dsk-process-agent:latest2f38720a637d
golang.org/x/net@v0.15.0
stdlib@go1.21.0
0.55.0
1.25.13
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.55.0
1.25.13
1
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.55.0
1.25.13
1
datawire/aes:3.11.195ec30b3c732
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.55.0
1.25.13
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.16.5
0.55.0
1.25.13
1
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.55.0
1.25.13
1
ddefrancesco/scoperunner-server:0.2.1daaac6657600
stdlib@go1.21.10
1.25.13
1
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.55.0
1.25.13
1
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.55.0
1.25.13
1
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.55.0
1.25.13
1
ddvk/rmfakecloud:latest2f5c45cbf0c5
golang.org/x/net@v0.38.0
stdlib@go1.26.3
0.55.0
1.25.13
1
deconzcommunity/deconz:2.29.2062de2362641
stdlib@go1.19.8
1.25.13
1
deepflowce/deepflow-init-grafana:v6.2.27cd16719eb57
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.3
0.55.0
1.25.13
1
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
golang.org/x/net@v0.8.0
stdlib@go1.19.1
0.55.0
1.25.13
1
deepflowce/deepflow-server:v6.2.21477e7334d13
golang.org/x/net@v0.2.0
stdlib@go1.18.10
0.55.0
1.25.13
1
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
1
defactops/defactops-ui:1.0.16825cdf9ba706
golang.org/x/net@v0.25.0
stdlib@go1.21.10
0.55.0
1.25.13
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.5
0.55.0
1.25.13
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.55.0
1.25.13
1
dellnoantechnp/cloudeye-exporter:v2.0.316873356c882d
stdlib@go1.19.6
1.25.13
1
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.55.0
1.25.13
1
deluan/navidrome:0.50.02cf4442b0099
golang.org/x/net@v0.18.0
stdlib@go1.21.0
0.55.0
1.25.13
1
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.55.0
1.25.13
1
deluan/navidrome:0.63.17c43af9f6516
stdlib@go1.26.5
1.25.13
1
deluan/navidrome:0.61.29fa40b3d8dec
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.55.0
1.25.13
1
deluan/navidrome:0.41.1fc4d8b6ad9f9
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.55.0
1.25.13
1
denniswitt/yas3p:0.2.488a235619af6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.55.0
1.25.13
1
devopsfaith/krakend:2.6.34c678c224f67
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.55.0
1.25.13
1
devopsfaith/krakend:2.7.09219cda867e2
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
1
devopstales/trivy-operator:2.575136aa7a26e
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.