StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,610
of 17,821 indexed, latest versions
Container images
5,331
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,610 of 17,821 indexed charts deploy, on 5,331 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+191 more1.25.135,291
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,727
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,610 by stars
ChartLatestAffected imagesRadar Score
pagesliviu884422-pages1.0.01 of 3See more

pages liviu884422-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,285
llmarinerllmariner1.53.115 of 21See more

llmariner llmariner 1.53.1

15 of the 21 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.25.13
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/database-creator:1.17.097065ced2942
stdlib@go1.23.11
1.25.13
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/inference-manager-engine:1.46.0c46f109c3d0b
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/inference-manager-server:1.45.090b890f800ab
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/job-manager-server:1.27.0fe9de719f91e
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
golang.org/x/net@v0.38.0
stdlib@go1.24.0
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/model-manager-server:1.27.0c057dcdd9ef3
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/rbac-server:1.19.1df1adeb86679
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/session-manager-server:1.9.0f24ecd37fbaa
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.55.0
1.25.13
public.ecr.aws/cloudnatix/llmariner/user-manager-server:1.27.1628a14449241
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13

Open the chart page →

12,185
llm-dllm-dVerified publisher1.0.231 of 2See more

llm-d llm-d 1.0.23

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

2,564
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.55.0
1.25.13

Open the chart page →

2,488
go-ocpp-serverloafoe0.2.11 of 1See more

go-ocpp-server loafoe 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/go-ocpp-server:v0.2.145bb960674ab
stdlib@go1.21.13
1.25.13

Open the chart page →

399
mcp-notifierloafoe0.2.01 of 1See more

mcp-notifier loafoe 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/mcp-notifier:v0.2.0ea958b832415
stdlib@go1.26.4
1.25.13

Open the chart page →

72
mt-mcp-grafanaloafoe0.10.02 of 2See more

mt-mcp-grafana loafoe 0.10.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/mcp-grafana:0.14.042f541f22063
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13
ghcr.io/loafoe/mt-mcp-grafana:v0.1.12332d9b47475
stdlib@go1.26.2
1.25.13

Open the chart page →

1,988
mt-mcp-proxyloafoe0.3.01 of 2See more

mt-mcp-proxy loafoe 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/mt-mcp-proxy:v0.1.0221835f9340f
stdlib@go1.26.4
1.25.13

Open the chart page →

505
otlp-gatewayloafoe0.0.22 of 2See more

otlp-gateway loafoe 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/jimmidyson/configmap-reload:v0.13.1ca0c14eef541
stdlib@go1.22.4
1.25.13
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
golang.org/x/net@v0.27.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

2,180
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.55.0
1.25.13

Open the chart page →

4,912
picoclawloafoe0.1.11 of 2See more

picoclaw loafoe 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/picoclaw:v0.0.1942e1b6862913
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

479
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.55.0
1.25.13

Open the chart page →

2,126
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.55.0
1.25.13

Open the chart page →

2,038
local-path-exporterlocal-path-exporterVerified publisher0.2.31 of 1See more

local-path-exporter local-path-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/tmusial99/local-path-exporter:1.1.082476692c680
stdlib@go1.26.4
1.25.13

Open the chart page →

68
weather-app-chartlocal-weatherapp0.1.02 of 4See more

weather-app-chart local-weatherapp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:8.0.36-debian-11-r38aad73aa0c6d
stdlib@go1.21.6
1.25.13
youssef11gaber10/deployment-auth-go:latest6597b26959d2
golang.org/x/net@v0.10.0
stdlib@go1.26.1
0.55.0
1.25.13

Open the chart page →

5,915
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,521
locust-pluginslocust-pluginsVerified publisher0.0.42 of 3See more

locust-plugins locust-plugins 0.0.4

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.55.0
1.25.13
sky5367/locust-plugins-timescale:latestd3150f201471
stdlib@go1.18.7
1.25.13

Open the chart page →

7,581
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

33,925
central-hostpath-mapperloftVerified publisher0.2.91 of 1See more

central-hostpath-mapper loft 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
golang.org/x/net@v0.26.0
stdlib@go1.23.2
0.55.0
1.25.13

Open the chart page →

931
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/net@v0.21.0
stdlib@go1.20.10
0.55.0
1.25.13

Open the chart page →

3,242
devspace-cloudloftVerified publisher0.3.32 of 8See more

devspace-cloud loft 0.3.3

2 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.55.0
1.25.13
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.13

Open the chart page →

9,893
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.7
0.55.0
1.25.13

Open the chart page →

3,096
license-serverloftVerified publisher0.6.01 of 1See more

license-server loft 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
golang.org/x/net@v0.53.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

804
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/net@v0.6.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

2,460
loft-direct-cluster-endpointloftVerified publisher1.14.01 of 1See more

loft-direct-cluster-endpoint loft 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

3,120
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.55.0
1.25.13

Open the chart page →

3,242
vcluster-headloftVerified publisher0.0.0-035ec6e1 of 2See more

vcluster-head loft 0.0.0-035ec6e

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/kubernetes:v1.35.090097a08b87c
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.55.0
1.25.13

Open the chart page →

1,309
vcluster-hpmloftVerified publisher0.2.71 of 1See more

vcluster-hpm loft 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-hpm:0.2.7f65f6810ea23
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

841
vcluster-proloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
stdlib@go1.19.4
0.55.0
1.25.13
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

5,144
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.104 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.55.0
1.25.13
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.55.0
1.25.13
public.ecr.aws/eks-distro/kubernetes/kube-apiserver:v1.24.9-eks-1-24-772e06b605692
stdlib@go1.18.9
1.25.13
public.ecr.aws/eks-distro/kubernetes/kube-controller-manager:v1.24.9-eks-1-24-7eaea8c230432
stdlib@go1.18.9
1.25.13

Open the chart page →

5,986
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.55.0
1.25.13
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

5,828
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.104 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.55.0
1.25.13
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.55.0
1.25.13
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.55.0
1.25.13
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.55.0
1.25.13

Open the chart page →

8,286
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.55.0
1.25.13

Open the chart page →

2,994
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
golang.org/x/net@v0.46.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

2,546
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,504
nightingalelogic3579Verified publisher0.3.13 of 6See more

nightingale logic3579 0.3.1

3 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.55.0
1.25.13
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.55.0
1.25.13

Open the chart page →

9,172
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,511
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
stdlib@go1.22.5
1.25.13

Open the chart page →

6,610
apica-ascentlogiqai2.0.47 of 19See more

apica-ascent logiqai 2.0.4

7 of the 19 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.55.0
1.25.13
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.18.9
0.55.0
1.25.13
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.7
0.55.0
1.25.13
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.55.0
1.25.13
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.55.0
1.25.13
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.8
0.55.0
1.25.13
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.9
0.55.0
1.25.13

Open the chart page →

23,806
logtidelogtideVerified publisher2.1.141 of 4See more

logtide logtide 2.1.14

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg156343bdc87ca1
stdlib@go1.24.6
1.25.13

Open the chart page →

2,968
loki-proxyloki-proxyVerified publisher0.4.11 of 1See more

loki-proxy loki-proxy 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/peak-scale/observability-tenancy/loki-proxy:0.4.1548e962d0061
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

788
corednslovemew67Verified publisher1.36.01 of 1See more

coredns lovemew67 1.36.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
coredns/coredns:1.11.39caabbf6238b
golang.org/x/net@v0.25.0
stdlib@go1.21.11
0.55.0
1.25.13

Open the chart page →

1,183
oncall-hobbylovemew67Verified publisher0.0.51 of 2See more

oncall-hobby lovemew67 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:7.0.15352c1fdadc91
stdlib@go1.18.2
1.25.13

Open the chart page →

5,909
loxilbloxilbVerified publisher0.1.01 of 2See more

loxilb loxilb 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13

Open the chart page →

4,563
lsdisklsdiskVerified publisher2.0.73 of 4See more

lsdisk lsdisk 2.0.7

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
golang.org/x/net@v0.25.0
stdlib@go1.22.5
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

5,084
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

2,350
fireflylsst-sqre0.3.71 of 2See more

firefly lsst-sqre 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:5fc5ecd863862
stdlib@go1.16.7
1.25.13

Open the chart page →

1,732
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.17.2
0.55.0
1.25.13
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

9,351
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.5
0.55.0
1.25.13

Open the chart page →

6,675
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

3,774

Container images carrying it

5,331 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
golang.org/x/net@v0.0.0-20210907225631-ff17edfbf26d
stdlib@go1.17.2
0.55.0
1.25.13
1
huzafach/aws-cli-k8:1.0.06e271d43ea48
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.55.0
1.25.13
1
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.7
0.55.0
1.25.13
1
hyperledger/fabric-ca:1.5.0f270dfeee91d
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.7
0.55.0
1.25.13
1
hyperledger/fabric-orderer:2.2.137294e05209b
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.4
0.55.0
1.25.13
1
hyperledger/fabric-peer:2.2.1bf4995c86af6
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.4
0.55.0
1.25.13
1
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.55.0
1.25.13
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.55.0
1.25.13
1
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.4
0.55.0
1.25.13
1
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.55.0
1.25.13
1
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18.7
0.55.0
1.25.13
1
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18.7
0.55.0
1.25.13
1
iamdorsah/bastillion:v0.1db83a0254d81
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.13
0.55.0
1.25.13
1
ianw/quickchart:v1.7.1dc49dd460c37
stdlib@go1.13.1
1.25.13
1
ibarreche/cloud-reporting-ci:latest1f45af91da6a
stdlib@go1.16.15
1.25.13
1
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
golang.org/x/net@v0.17.0
stdlib@go1.18.8
0.55.0
1.25.13
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
stdlib@go1.21.1
1.25.13
1
inaccel/cloud-init:latesta5d3d0af05c1
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.55.0
1.25.13
1
inaccel/device-selector:latest44b4f274f40b
golang.org/x/net@v0.21.0
stdlib@go1.21.9
0.55.0
1.25.13
1
inaccel/kubevirt-hack:latestbdfd61803a70
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
1
inbucket/inbucket:3.0.01f10a0efea69
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.1
0.55.0
1.25.13
1
indevlab/ejabberd:24.12-k8s8bc689d093a7
golang.org/x/net@v0.30.0
stdlib@go1.23.6
0.55.0
1.25.13
1
infisical/cli:0.43.1230941c1293b77
stdlib@go1.25.12
1.25.13
1
infisical/infisical-agent-injector:v0.1.12718dd5bee7cb
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13
1
infisical/infisical-csi-provider:v0.0.9e3390e677db6
golang.org/x/net@v0.33.0
stdlib@go1.24.13
0.55.0
1.25.13
1
infisical/pki-issuer:latestff38294270e3
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.55.0
1.25.13
1
inseefrlab/shelly:cloudshell31f04ca7436b
golang.org/x/net@v0.13.0
stdlib@go1.15.7
0.55.0
1.25.13
1
instill/api-gateway:9bfdc88b53eaa51c523
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.55.0
1.25.13
1
instill/artifact-backend:b28766ac4a393e601ed
golang.org/x/net@v0.33.0
stdlib@go1.25.6
0.55.0
1.25.13
1
instill/console:0.68.54cd70e2df5c6
stdlib@go1.23.10
1.25.13
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.55.0
1.25.13
1
instill/model-backend:611f0f2e980125e5ba5
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.55.0
1.25.13
1
intel/intel-deviceplugin-operator:0.36.09879685d0b5b
stdlib@go1.26.3
1.25.13
1
intel/intel-gaudi-resource-driver:v0.3.0ac758c14c2de
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
intel/intel-gpu-plugin:0.20.0143f0a45e174
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.55.0
1.25.13
1
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
intel/intel-qat-resource-driver:v0.1.0ac7616986a2b
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
1
intel/multimodal-data-visualization:3.03426deb77337
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.11
0.55.0
1.25.13
1
intel/trusted-certificate-issuer:0.5.0591a9db4a427
golang.org/x/net@v0.7.0
stdlib@go1.19.3
0.55.0
1.25.13
1
invisibl/gravity-init:v1.0.91a970f84178b
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.12
0.55.0
1.25.13
1
invisibl/identity-manager:1.0.01029f4fe20eb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.11
0.55.0
1.25.13
1
invisibl/identity-manager-demo:v1.0.0cf5400cb935a
stdlib@go1.19.2
1.25.13
1
iofog/router:2.0.17260cf861479
stdlib@go1.15
1.25.13
1
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.21.5
0.55.0
1.25.13
1
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.20.3
0.55.0
1.25.13
1
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.21.5
0.55.0
1.25.13
1
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.20.3
0.55.0
1.25.13
1
iomesh/csi-driver:v2.8.01a151f602451
golang.org/x/net@v0.8.0
stdlib@go1.21.11
0.55.0
1.25.13
1
iomesh/csi-driver:v2.7.25d3f9bf9240b
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.16.7
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.