StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,642
of 17,813 indexed, latest versions
Container images
5,366
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,642 of 17,813 indexed charts deploy, on 5,366 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+191 more1.25.135,324
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,744
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,642 by stars
ChartLatestAffected imagesRadar Score
gotifygabe565Verified publisher0.4.01 of 1See more

gotify gabe565 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/gotify/server:2.6.104f4c4bb7cdd
golang.org/x/net@v0.25.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

763
hammondgabe565Verified publisher0.6.41 of 1See more

hammond gabe565 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.20.6
0.55.0
1.25.13

Open the chart page →

1,807
limogabe565Verified publisher0.8.01 of 1See more

limo gabe565 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/gabe565/limo:latest6dfdbc9853bb
stdlib@go1.20.12
1.25.13

Open the chart page →

1,331
matrimonygabe565Verified publisher0.7.01 of 1See more

matrimony gabe565 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/gabe565/matrimony:latestd39a9d7c3e1b
stdlib@go1.22.0
1.25.13

Open the chart page →

1,136
podgrabgabe565Verified publisher0.5.21 of 1See more

podgrab gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.2
0.55.0
1.25.13

Open the chart page →

2,402
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
stdlib@go1.19.8
1.25.13

Open the chart page →

13,459
smarter-device-managergabe565Verified publisher0.5.21 of 1See more

smarter-device-manager gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.1
0.55.0
1.25.13

Open the chart page →

1,227
transsmutegabe565Verified publisher1.1.01 of 1See more

transsmute gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.55.0
1.25.13

Open the chart page →

801
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
stdlib@go1.24.6
1.25.13

Open the chart page →

6,489
galoygaloymoney0.34.74 of 24See more

galoy galoymoney 0.34.7

4 of the 24 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.55.0
1.25.13
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.55.0
1.25.13
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

8,731
galoy-depsgaloymoney0.10.208 of 9See more

galoy-deps galoymoney 0.10.20

8 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.9
0.55.0
1.25.13
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.55.0
1.25.13

Open the chart page →

12,015
lndgaloymoney0.10.61 of 3See more

lnd galoymoney 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

2,162
monitoringgaloymoney0.12.215 of 6See more

monitoring galoymoney 0.12.21

5 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

5,339
galoygaloymoney20.34.74 of 24See more

galoy galoymoney2 0.34.7

4 of the 24 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.55.0
1.25.13
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.55.0
1.25.13
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

8,731
galoy-depsgaloymoney20.10.208 of 9See more

galoy-deps galoymoney2 0.10.20

8 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.9
0.55.0
1.25.13
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.55.0
1.25.13

Open the chart page →

12,015
lndgaloymoney20.10.61 of 3See more

lnd galoymoney2 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

2,162
monitoringgaloymoney20.12.215 of 6See more

monitoring galoymoney2 0.12.21

5 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

5,339
gameserver-operatorgameserver-operator0.3.01 of 1See more

gameserver-operator gameserver-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/idebeijer/gameserver-operator:latest1b099cfe9e5e
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

383
pagesgary-pages1.0.01 of 3See more

pages gary-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,285
alertmanager-discordgeek-cookbookVerified publisher1.3.21 of 1See more

alertmanager-discord geek-cookbook 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rogerrum/alertmanager-discord:1.0.3827593369625
stdlib@go1.17.4
1.25.13

Open the chart page →

1,046
anonaddygeek-cookbookVerified publisher6.0.01 of 1See more

anonaddy geek-cookbook 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.25.13

Open the chart page →

4,792
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
stdlib@go1.18.4
1.25.13

Open the chart page →

14,889
autobrrgeek-cookbookVerified publisher1.1.31 of 1See more

autobrr geek-cookbook 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.55.0
1.25.13

Open the chart page →

2,237
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
stdlib@go1.16.7
1.25.13

Open the chart page →

16,257
dendritegeek-cookbookVerified publisher6.4.01 of 1See more

dendrite geek-cookbook 6.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.5
0.55.0
1.25.13

Open the chart page →

2,144
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:latesta792931146b4
stdlib@go1.24.9
1.25.13

Open the chart page →

1,813
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
stdlib@go1.15
1.25.13

Open the chart page →

8,611
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.1
0.55.0
1.25.13

Open the chart page →

1,882
gonicgeek-cookbookVerified publisher6.4.21 of 1See more

gonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

3,526
gotifygeek-cookbookVerified publisher1.2.21 of 1See more

gotify geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.55.0
1.25.13

Open the chart page →

3,133
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
stdlib@go1.15
1.25.13

Open the chart page →

11,078
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
stdlib@go1.18.3
1.25.13

Open the chart page →

9,921
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
stdlib@go1.16.7
1.25.13

Open the chart page →

14,490
maddygeek-cookbookVerified publisher3.2.01 of 1See more

maddy geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
foxcpp/maddy:v0.5.28fa2bd8f6830
golang.org/x/net@v0.0.0-20211011170408-caeb26a5c8c0
stdlib@go1.17.2
0.55.0
1.25.13

Open the chart page →

2,631
minifluxgeek-cookbookVerified publisher5.2.01 of 2See more

miniflux geek-cookbook 5.2.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
miniflux/miniflux:2.0.36e2fb990dae74
golang.org/x/net@v0.0.0-20210916014120-12bc252f5db8
stdlib@go1.17.8
0.55.0
1.25.13

Open the chart page →

2,431
navidromegeek-cookbookVerified publisher6.4.21 of 1See more

navidrome geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

3,598
nullservgeek-cookbookVerified publisher2.4.21 of 1See more

nullserv geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nullserv:v1.3.00792c7e6d814
stdlib@go1.16.5
1.25.13

Open the chart page →

1,118
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
stdlib@go1.18.4
1.25.13

Open the chart page →

12,328
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
stdlib@go1.15
1.25.13

Open the chart page →

17,822
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

3,244
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

19,608
pod-gatewaygeek-cookbookVerified publisher5.6.21 of 2See more

pod-gateway geek-cookbook 5.6.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v3.5.0175512bb3f61
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

2,361
pod-gateway-settergeek-cookbookVerified publisher1.0.01 of 1See more

pod-gateway-setter geek-cookbook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

1,642
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.25.13

Open the chart page →

12,048
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
stdlib@go1.18.4
1.25.13

Open the chart page →

10,606
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.25.13

Open the chart page →

7,831
rtsp-to-webgeek-cookbookVerified publisher2.2.21 of 1See more

rtsp-to-web geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.55.0

Open the chart page →

1,468
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
stdlib@go1.18.1
1.25.13

Open the chart page →

3,490
searxgeek-cookbookVerified publisher5.6.23 of 4See more

searx geek-cookbook 5.6.2

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.25.13
dalf/morty:latest248a4849c350
golang.org/x/net@v0.0.0-20220421235706-1d1ef9303861
stdlib@go1.18.2
0.55.0
1.25.13
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.55.0
1.25.13

Open the chart page →

7,507
skypilotgeek-cookbookVerified publisher0.0.13 of 3See more

skypilot geek-cookbook 0.0.1

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
golang.org/x/net@v0.38.0
stdlib@go1.23.5
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

9,103

Container images carrying it

5,366 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.55.0
1.25.13
1
haproxytech/haproxy-unified-gateway:1.0.7b9bffe2d0fd1
stdlib@go1.26.5
1.25.13
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.55.0
1.25.13
1
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.55.0
1.25.13
1
hashicorp/boundary:0.21.037bf86488b74
golang.org/x/net@v0.47.0
stdlib@go1.25.1
0.55.0
1.25.13
1
hashicorp/boundary:latest76a201954ca0
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13
1
hashicorp/boundary:0.8.1fb70bd9210ff
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.10
0.55.0
1.25.13
1
hashicorp/consul:1.17.0712fe02d2f84
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
1
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.55.0
1.25.13
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.55.0
1.25.13
1
hashicorp/hcp-terraform-operator:2.12.15a15932f6838
stdlib@go1.26.5
1.25.13
1
hashicorp/terraform:1.44dcb45513699
golang.org/x/net@v0.6.0
stdlib@go1.19.6
0.55.0
1.25.13
1
hashicorp/terraform:1.9.7b77efab1a448
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.55.0
1.25.13
1
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
golang.org/x/net@v0.24.0
stdlib@go1.22.4
0.55.0
1.25.13
1
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.18.8
0.55.0
1.25.13
1
hashicorp/vault:1.15.40b01ed3924e6
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.55.0
1.25.13
1
hashicorp/vault:2.0.1755355002715
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
1
hashicorp/vault:1.14.0b2177a8bfe85
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13
1
hashicorp/vault:1.19.0bbb7f98dc67d
golang.org/x/net@v0.35.0
stdlib@go1.23.6
0.55.0
1.25.13
1
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.55.0
1.25.13
1
hashicorp/vault-k8s:1.6.2103a2d817a74
golang.org/x/net@v0.35.0
stdlib@go1.23.6
0.55.0
1.25.13
1
hashicorp/vault-k8s:1.2.14500e988b7ce
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.55.0
1.25.13
1
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.13.5
0.55.0
1.25.13
1
hashicorp/vault-k8s:1.7.2ae3d307658b7
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
1
hashicorp/vault-k8s:0.14.0aff47b5ba39c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.2
0.55.0
1.25.13
1
hashicorp/vault-secrets-operator:1.5.1458c842add32
stdlib@go1.26.5
1.25.13
1
hashicorp/waypoint:0.11.397d521a27498
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.55.0
1.25.13
1
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.6
0.55.0
1.25.13
1
headscale/headscale:0.25.1a7a8ae9616bb
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.55.0
1.25.13
1
headscale/headscale:0.27.1cd37b3001857
golang.org/x/net@v0.46.0
stdlib@go1.25.1
0.55.0
1.25.13
1
helga09/my_sql_shoes:v1.1.1a03657d97897
stdlib@go1.18.2
1.25.13
1
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.55.0
1.25.13
1
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19
0.55.0
1.25.13
1
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17
0.55.0
1.25.13
1
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.3
0.55.0
1.25.13
1
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.55.0
1.25.13
1
hhaluk/mocktail:2.0.3350d19360038
stdlib@go1.17.7
1.25.13
1
hhyo/archery:v1.9.11aa41843419e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.6
0.55.0
1.25.13
1
hibiken/asynqmon:latestac80bcffd2f9
stdlib@go1.18.10
1.25.13
1
hipages/php-fpm_exporter:2.2.09b5be9d3d955
stdlib@go1.17.10
1.25.13
1
hivemq/hivemq-platform-operator:2.2.2a919f990141b
stdlib@go1.26.5
1.25.13
1
hiversh/antigravity:0.1.45-microvm0e36d98402bc
stdlib@go1.26.5
1.25.13
1
hiversh/browser:0.1.45-microvmb5048c6342ce
stdlib@go1.26.5
1.25.13
1
hiversh/claude:0.1.45-microvm2fbf9f264498
stdlib@go1.26.5
1.25.13
1
hiversh/codex:0.1.45-microvm4f43130f51e5
stdlib@go1.26.5
1.25.13
1
hiversh/controller:0.1.45b0b85f8942c7
stdlib@go1.19.8
1.25.13
1
hiversh/copilot:0.1.45-microvm50c07b84f298
stdlib@go1.26.5
1.25.13
1
hiversh/node:0.1.45-alpine-microvm836a37641941
stdlib@go1.26.5
1.25.13
1
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
stdlib@go1.19.8
1.25.13
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.