StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,610
of 17,821 indexed, latest versions
Container images
5,331
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,610 of 17,821 indexed charts deploy, on 5,331 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+191 more1.25.135,291
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,727
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,610 by stars
ChartLatestAffected imagesRadar Score
gpu-operatornvidia-gpu-operator26.7.01 of 2See more

gpu-operator nvidia-gpu-operator 26.7.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
stdlib@go1.26.3
1.25.13

Open the chart page →

245
dnscrypt-proxyobeoneVerified publisher1.4.51 of 1See more

dnscrypt-proxy obeone 1.4.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
klutchell/dnscrypt-proxy:2.1.18a98e8d13314f
stdlib@go1.25.12
1.25.13

Open the chart page →

71
firecrawlobeoneVerified publisher3.0.81See more

firecrawl obeone 3.0.8

1 container image this version deploys carries CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
stdlib@go1.24.6
1.25.13

Open the chart page →

observabilitysecobservabilitysec0.0.11 of 2See more

observabilitysec observabilitysec 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jdvalencia422/observabilitysec:latesta80b6e47a7b8
stdlib@go1.18.4
1.25.13

Open the chart page →

1,180
lensoci-ai-incubations0.1.1411 of 16See more

lens oci-ai-incubations 0.1.14

11 of the 16 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
golang.org/x/net@v0.19.0
stdlib@go1.22.7
0.55.0
1.25.13
grafana/grafana:12.1.1a1701c218024
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.55.0
1.25.13
library/postgres:134689940c6838
stdlib@go1.24.6
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.85.0ebb560bcb6bd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
quay.io/prometheus/prometheus:v3.5.063805ebb8d2b
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.55.0
1.25.13
quay.io/prometheus/pushgateway:v1.11.103738d278e08
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.2050a34002d5b
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

17,279
oci-prometheus-sd-proxyoci-prometheus-sd-proxy1.0.01 of 1See more

oci-prometheus-sd-proxy oci-prometheus-sd-proxy 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/amaanx86/oci-prometheus-sd-proxy:latest297a8379a328
stdlib@go1.26.4
1.25.13

Open the chart page →

285
ocisocis-community0.1.01 of 1See more

ocis ocis-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
owncloud/ocis:8.0.1b38fd8fdd58f
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

2,358
argocd-agent-addonocm-helm-chartsVerified publisher0.29.01 of 2See more

argocd-agent-addon ocm-helm-charts 0.29.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.18.0a09814522a72
golang.org/x/net@v0.49.0
stdlib@go1.25.10
0.55.0
1.25.13

Open the chart page →

671
cluster-gateway-addon-managerocm-helm-chartsVerified publisher1.4.01 of 1See more

cluster-gateway-addon-manager ocm-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

1,608
cluster-managerocm-helm-chartsVerified publisher1.3.11 of 1See more

cluster-manager ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.55.0
1.25.13

Open the chart page →

822
cluster-proxyocm-helm-chartsVerified publisher0.12.01 of 1See more

cluster-proxy ocm-helm-charts 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.55.0
1.25.13

Open the chart page →

1,351
dynamic-scoring-frameworkocm-helm-chartsVerified publisher0.1.02 of 2See more

dynamic-scoring-framework ocm-helm-charts 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/dynamic-scoring-addon:latest7e571a08ec1a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
quay.io/open-cluster-management/dynamic-scoring-controller:latest587f5bc8f2ed
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

996
klusterletocm-helm-chartsVerified publisher1.3.11 of 1See more

klusterlet ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.55.0
1.25.13

Open the chart page →

822
kueue-addonocm-helm-chartsVerified publisher0.1.41 of 1See more

kueue-addon ocm-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

1,619
multicluster-controlplaneocm-helm-chartsVerified publisher0.8.01 of 1See more

multicluster-controlplane ocm-helm-charts 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
golang.org/x/net@v0.52.0
stdlib@go1.26.4
0.55.0
1.25.13

Open the chart page →

626
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.13
0.55.0
1.25.13

Open the chart page →

2,132
octantoctant0.1.861 of 1See more

octant octant 0.1.86

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/mydecisive/octant:0.1.86ebbd44abae6c
golang.org/x/net@v0.52.0
0.55.0

Open the chart page →

566
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
golang.org/x/net@v0.21.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

5,852
aspromokgoloveVerified publisher2.0.01 of 1See more

asprom okgolove 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
okgolove/asprom:1.10.1974d2e5eb150
stdlib@go1.14.11
1.25.13

Open the chart page →

1,870
cmsmsoleds-helm-chartsVerified publisher0.1.61 of 1See more

cmsms oleds-helm-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
stdlib@go1.23.10
1.25.13

Open the chart page →

2,913
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.4
0.55.0
1.25.13

Open the chart page →

8,550
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.13

Open the chart page →

4,834
exposecontrollerolli-aiVerified publisher1.0.51 of 1See more

exposecontroller olli-ai 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
olliai/exposecontroller:1.0.5a470d96525e4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

2,862
k8s-replicatorolli-aiVerified publisher1.3.01 of 1See more

k8s-replicator olli-ai 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
olliai/k8s-replicator:1.3.05716f2a8bd4c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.17.2
0.55.0
1.25.13

Open the chart page →

2,826
apicurioone-acre-fundVerified publisher2.3.02 of 5See more

apicurio one-acre-fund 2.3.0

2 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.25.13
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

18,698
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
golang.org/x/net@v0.19.0
stdlib@go1.21.10
0.55.0
1.25.13

Open the chart page →

4,244
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13

Open the chart page →

6,190
one-green-coreone-green-coreVerified publisher0.0.73 of 8See more

one-green-core one-green-core 0.0.7

3 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:8.5.3ecc1b80b8ca2
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.17.9
0.55.0
1.25.13
library/influxdb:2.0.8ba10ac9ba17a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.5
0.55.0
1.25.13
library/telegraf:1.20.428e98eece020
golang.org/x/net@v0.0.0-20211005215030-d2e5035098b3
stdlib@go1.17.3
0.55.0
1.25.13

Open the chart page →

9,586
ontoserverontoserverVerified publisher0.5.21 of 2See more

ontoserver ontoserver 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
stdlib@go1.24.6
1.25.13

Open the chart page →

1,699
onyx-stackonyx0.3.14 of 12See more

onyx-stack onyx 0.3.1

4 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
vespaengine/vespa:8.526.1569b160f58211
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
ghcr.io/kedacore/keda:2.17.272dc058e478d
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
ghcr.io/kedacore/keda-admission-webhooks:2.17.2c8227c6edb4d
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
ghcr.io/kedacore/keda-metrics-apiserver:2.17.2f312f50ddc57
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13

Open the chart page →

6,759
oom-traceroom-tracerVerified publisher0.1.01 of 1See more

oom-tracer oom-tracer 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/eminaktas/oom-tracer:v0.1.0c90ca8389c87
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.55.0
1.25.13

Open the chart page →

1,126
opa-nginxopa-nginx0.0.32 of 2See more

opa-nginx opa-nginx 0.0.3

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
openpolicyagent/opa:0.53.16a58dea59933
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13
richardjennings/opa-nginx:0.0.366424aca125d
stdlib@go1.20.5
1.25.13

Open the chart page →

2,207
erigonop-chartsVerified publisher0.0.51See more

erigon op-charts 0.0.5

1 container image this version deploys carries CVE-2026-39821.

Container imageDigestPackageFixed in
testinprod/op-erigon:latest0a125bd77a2d
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

opds-shelfopds-shelfVerified publisher0.4.02 of 3See more

opds-shelf opds-shelf 0.4.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
stdlib@go1.17.8
1.25.13
ghcr.io/madeddie/opds-aggregator:latest60c56021c552
stdlib@go1.24.13
1.25.13

Open the chart page →

4,415
open-cacheopen-cacheVerified publisher0.1.01 of 1See more

open-cache open-cache 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/atolat/open-cache:latestd6105dd73eb4
stdlib@go1.25.8
1.25.13

Open the chart page →

448
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

2,443
basic-appopen-charts1.0.01 of 1See more

basic-app open-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ovhplatform/what-is-my-pod:1.0.16d4d455e9aba
stdlib@go1.16.14
1.25.13

Open the chart page →

1,598
jobopen-charts2.0.01 of 1See more

job open-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
stdlib@go1.26.5
1.25.13

Open the chart page →

761
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

18,035
bbsimopencord4.8.111 of 1See more

bbsim opencord 4.8.11

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
voltha/bbsim:1.16.7d90403d58016
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.13.8
0.55.0
1.25.13

Open the chart page →

3,926
bbsim-sadis-serveropencord0.3.51 of 1See more

bbsim-sadis-server opencord 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
voltha/bbsim-sadis-server:0.4.0762b272d439e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

3,740
nem-monitoringopencord1.3.221 of 9See more

nem-monitoring opencord 1.3.22

1 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.55.0
1.25.13

Open the chart page →

4,620
volthaopencord2.14.02 of 2See more

voltha opencord 2.14.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.55.0
1.25.13
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

3,825
voltha-adapter-openoltopencord2.14.01 of 1See more

voltha-adapter-openolt opencord 2.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
voltha/voltha-openolt-adapter:4.5.16d6d79c08350a
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

899
voltha-adapter-openonuopencord2.14.01 of 1See more

voltha-adapter-openonu opencord 2.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
voltha/voltha-openonu-adapter-go:2.12.25d8f2eb5f2a7e
golang.org/x/net@v0.33.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

844
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.5
0.55.0
1.25.13
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

41,189
voltha-stackopencord2.14.04 of 4See more

voltha-stack opencord 2.14.0

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.55.0
1.25.13
voltha/voltha-openolt-adapter:4.5.16d6d79c08350a
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13
voltha/voltha-openonu-adapter-go:2.12.25d8f2eb5f2a7e
golang.org/x/net@v0.33.0
stdlib@go1.23.1
0.55.0
1.25.13
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

5,568
everest-db-namespaceopeneverestVerified publisher1.16.21 of 1See more

everest-db-namespace openeverest 1.16.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

769
cron-connectoropenfaas0.6.161 of 1See more

cron-connector openfaas 0.6.16

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
stdlib@go1.23.5
1.25.13

Open the chart page →

887
federated-gatewayopenfaas0.1.01 of 1See more

federated-gateway openfaas 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/federated-gateway:0.2.39066d7b3e6a1
stdlib@go1.21.5
1.25.13

Open the chart page →

1,241

Container images carrying it

5,331 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
golang.org/x/net@v0.25.0
stdlib@go1.23.12
0.55.0
1.25.13
1
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/net@v0.10.0
stdlib@go1.21.13
0.55.0
1.25.13
1
eclipseaerios/openldap:2.6.30208743f315e
stdlib@go1.18.2
1.25.13
1
eginnovations/agent:7.5.4e4dfe242fe9f
stdlib@go1.26.4
1.25.13
1
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13
1
ekofr/pihole-exporter:0.0.109fdad6f352e0
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.7
0.55.0
1.25.13
1
elastic/apm-server:7.17.6c7a1c63257d0
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.2
0.55.0
1.25.13
1
elastiflow/flow-collector:7.26.0fee67842e16b
golang.org/x/net@v0.53.0
stdlib@go1.25.10
0.55.0
1.25.13
1
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.25.13
1
emirozbir/dashdns-admission-webhook:v2.0.56801ba2a3fc3
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.55.0
1.25.13
1
emirozbir/dashdns-controller:v2.0.5d3a5c1063425
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13
1
empathyco/cost-report:0.0.124f1e26eaacbf
stdlib@go1.15.15
1.25.13
1
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
golang.org/x/net@v0.23.0
stdlib@go1.23.3
0.55.0
1.25.13
1
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/net@v0.30.0
stdlib@go1.22.0
0.55.0
1.25.13
1
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.55.0
1.25.13
1
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
stdlib@go1.19.10
0.55.0
1.25.13
1
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.25.13
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.55.0
1.25.13
1
enketo/enketo-express:3.0.4dcad9c2273f6
stdlib@go1.17.1
1.25.13
1
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.55.0
1.25.13
1
envoyproxy/gateway:v0.5.02a9f99d28567
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.55.0
1.25.13
1
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.55.0
1.25.13
1
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14
0.55.0
1.25.13
1
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.13
0.55.0
1.25.13
1
envoyproxy/ratelimit:4d2efd61ede09a75a84c
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.15
0.55.0
1.25.13
1
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.19.6
0.55.0
1.25.13
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.55.0
1.25.13
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.18.3
0.55.0
1.25.13
1
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.4
0.55.0
1.25.13
1
epamedp/edp-headlamp:0.25.093417e18bb1a
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.55.0
1.25.13
1
epamedp/edp-tekton:0.2.4924939850655
golang.org/x/net@v0.1.0
stdlib@go1.18.3
0.55.0
1.25.13
1
epamedp/gerrit-operator:2.25.08de22fc5051c
stdlib@go1.25.12
1.25.13
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.55.0
1.25.13
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.55.0
1.25.13
1
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.55.0
1.25.13
1
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.55.0
1.25.13
1
epamedp/keycloak-operator:1.35.0a5398eaa7b80
stdlib@go1.25.12
1.25.13
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.2
0.55.0
1.25.13
1
epamedp/nexus-operator:3.6.09fede333ef27
stdlib@go1.25.12
1.25.13
1
epamedp/perf-operator:2.13.0bd2079b7bfcb
golang.org/x/net@v0.8.0
stdlib@go1.19.6
0.55.0
1.25.13
1
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.18.4
0.55.0
1.25.13
1
epamedp/sonar-operator:3.4.0661d1648a49a
stdlib@go1.25.12
1.25.13
1
epamedp/tekton-custom-task:0.2.067d896676f45
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.55.0
1.25.13
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.25.13
1
erenozcan17/go_backend:v4.250b4f23422b6
golang.org/x/net@v0.10.0
stdlib@go1.23.12
0.55.0
1.25.13
1
erigontech/erigon:v2.61.288706754b627
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.55.0
1.25.13
1
erudikaltd/para:latest_stable235e0bc53da2
stdlib@go1.26.5
1.25.13
1
escaping/core-keeper-dedicated:latest87fa79255962
stdlib@go1.24.4
1.25.13
1
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.55.0
1.25.13
1
ethereum/client-go:v1.15.101f36ca5922a5
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.