StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,519
of 17,797 indexed, latest versions
Container images
5,266
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,519 of 17,797 indexed charts deploy, on 5,266 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,230
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,673
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,519 by stars
ChartLatestAffected imagesRadar Score
openstack-manila-csicloud-provider-openstack2.36.35 of 5See more

openstack-manila-csi cloud-provider-openstack 2.36.3

5 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

3,778
cloudttycloudtty0.8.92 of 2See more

cloudtty cloudtty 0.8.9

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell:v0.8.900984ba0f0eb
golang.org/x/net@v0.45.0
stdlib@go1.24.9
0.55.0
1.25.13
ghcr.io/cloudtty/cloudshell-operator:v0.8.9e43ad91f0684
golang.org/x/net@v0.25.0
stdlib@go1.21.11
0.55.0
1.25.13

Open the chart page →

3,994
cluster-api-provider-oxidecluster-api-provider-oxide0.2.31 of 1See more

cluster-api-provider-oxide cluster-api-provider-oxide 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/oxidecomputer/cluster-api-provider-oxide:0.2.37b05d3bbfbfa
stdlib@go1.26.4
1.25.13

Open the chart page →

122
cluster-api-visualizercluster-api-visualizer1.5.01 of 1See more

cluster-api-visualizer cluster-api-visualizer 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.55.0
1.25.13

Open the chart page →

558
clustereye-stackclustereyeVerified publisher0.1.12 of 5See more

clustereye-stack clustereye 0.1.1

2 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
johnblack77/clustereye-api:latest9b8dbc0264ac
golang.org/x/net@v0.50.0
0.55.0
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.13

Open the chart page →

4,913
clusternet-hubclusternet1.0.01 of 1See more

clusternet-hub clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-hub:v1.0.059f75504c5d4
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.55.0
1.25.13

Open the chart page →

1,403
clusternet-schedulerclusternet1.0.01 of 1See more

clusternet-scheduler clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-scheduler:v1.0.0a6ae5aff81ce
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.55.0
1.25.13

Open the chart page →

1,403
cluster-setupcluster-setup1.5.07 of 8See more

cluster-setup cluster-setup 1.5.0

7 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
golang.org/x/net@v0.37.0
stdlib@go1.24.3
0.55.0
1.25.13
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.13
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
golang.org/x/net@v0.33.0
stdlib@go1.22.7
0.55.0
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.17.2ec56edb1161d
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-startupapicheck:v1.17.2e18989b4f912
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13

Open the chart page →

10,121
cockroachdb-chartcockroachdbv226.3.11 of 1See more

cockroachdb-chart cockroachdbv2 26.3.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13

Open the chart page →

703
istio-allcode4devsVerified publisher1.2.04 of 6See more

istio-all code4devs 1.2.0

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.55.0
1.25.13

Open the chart page →

4,812
istio-control-planecode4devsVerified publisher1.0.02 of 3See more

istio-control-plane code4devs 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.55.0
1.25.13

Open the chart page →

2,374
maintenancecodewithemadVerified publisher0.1.61 of 1See more

maintenance codewithemad 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/caddy:2.9-alpineb4e3952384eb
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13

Open the chart page →

1,477
dawarichcogitriVerified publisher2.8.41 of 3See more

dawarich cogitri 2.8.4

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
freikin/dawarich:1.14.511826c67e4b1
stdlib@go1.24.4
1.25.13

Open the chart page →

5,858
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,313
cortex-tenantcortex-tenantVerified publisher0.8.11 of 1See more

cortex-tenant cortex-tenant 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/blind-oracle/cortex-tenant:v2.0.09f8896ffc15b
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.55.0
1.25.13

Open the chart page →

786
cosmo-controller-managercosmoVerified publisher0.9.01 of 2See more

cosmo-controller-manager cosmo 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-controller-manager:v0.9.08c7fa5552028
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

1,926
cosmo-dashboardcosmoVerified publisher0.9.11 of 1See more

cosmo-dashboard cosmo 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-dashboard:v0.9.16a1c4a81a924
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

1,938
cp-schema-registrycp-schema-registryVerified publisher1.0.01 of 1See more

cp-schema-registry cp-schema-registry 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
stdlib@go1.25.4
1.25.13

Open the chart page →

1,883
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

6,480
chalk-operatorcrashoverride-helm-chartsVerified publisher0.1.11 of 1See more

chalk-operator crashoverride-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/chalk-operator:v0.1.128eee62e9bfa
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

375
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.25.13

Open the chart page →

3,026
cronjob-scale-down-operatorcronschedules0.4.41 of 1See more

cronjob-scale-down-operator cronschedules 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cronschedules/cronjob-scale-down-operator:0.4.41c4e803d7169
golang.org/x/net@v0.52.0
stdlib@go1.25.0
0.55.0
1.25.13

Open the chart page →

444
cruisekubecruisekubeOfficialVerified publisher0.3.41 of 5See more

cruisekube cruisekube 0.3.4

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.55.0
1.25.13

Open the chart page →

440
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
stdlib@go1.19.8
1.25.13

Open the chart page →

13,816
revadcs3orgOfficialVerified publisher1.6.11 of 1See more

revad cs3org 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.55.0
1.25.13

Open the chart page →

1,711
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.55.0
1.25.13
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.4
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.55.0
1.25.13

Open the chart page →

15,933
CubeUniversecubeuniverseVerified publisher0.1.01 of 1See more

CubeUniverse cubeuniverse 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20.3
0.55.0
1.25.13

Open the chart page →

1,837
cview-issuercview-issuerVerified publisher0.0.421 of 1See more

cview-issuer cview-issuer 0.0.42

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
devsecurely/cview-issuer:0.0.42eecd4314e933
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.55.0
1.25.13

Open the chart page →

419
cyphernetes-operatorcyphernetes-operatorVerified publisher0.1.01 of 1See more

cyphernetes-operator cyphernetes-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

505
dagrondagron-workflowVerified publisher0.9.21 of 3See more

dagron dagron-workflow 0.9.2

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.13

Open the chart page →

1,206
dagster-cloud-agentdagster-cloudVerified publisher1.13.231 of 1See more

dagster-cloud-agent dagster-cloud 1.13.23

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dagster/dagster-cloud-agent:1.13.2322036fc83927
stdlib@go1.25.7
1.25.13

Open the chart page →

1,116
aibrixdanchevVerified publisher0.7.02 of 5See more

aibrix danchev 0.7.0

2 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aibrix/controller-manager:v0.7.076aabbbfda79
golang.org/x/net@v0.34.0
stdlib@go1.22.12
0.55.0
1.25.13
aibrix/gateway-plugins:v0.7.05b93ea4c753a
golang.org/x/net@v0.34.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

5,365
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.25.13

Open the chart page →

38,495
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
stdlib@go1.22.2
1.25.13

Open the chart page →

4,942
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.15
0.55.0
1.25.13

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.11
0.55.0
1.25.13

Open the chart page →

4,570
dbrepodbrepo1.13.311 of 25See more

dbrepo dbrepo 1.13.3

11 of the 25 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.55.0
1.25.13
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
stdlib@go1.23.8
1.25.13
bitnamilegacy/mariadb-galera:11.3.2-debian-12-r9aee9c668098f
stdlib@go1.22.5
1.25.13
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
golang.org/x/net@v0.17.0
stdlib@go1.21.12
0.55.0
1.25.13
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
stdlib@go1.23.8
1.25.13
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
golang.org/x/net@v0.27.0
stdlib@go1.22.8
0.55.0
1.25.13
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
golang.org/x/net@v0.27.0
stdlib@go1.22.8
0.55.0
1.25.13
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
golang.org/x/net@v0.17.0
stdlib@go1.22.8
0.55.0
1.25.13
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.55.0
1.25.13
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
golang.org/x/net@v0.39.0
stdlib@go1.24.1
0.55.0
1.25.13
bitnamilegacy/valkey:latest0384ca2eec63
stdlib@go1.23.10
1.25.13

Open the chart page →

53,282
deckarddeckardOfficial0.1.11 of 3See more

deckard deckard 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/mongodb:latest9aa916500f02
stdlib@go1.26.5
1.25.13

Open the chart page →

92
mealiedeimosfr-charts1.0.151 of 1See more

mealie deimosfr-charts 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
stdlib@go1.24.4
1.25.13

Open the chart page →

4,071
dregsydeliveryheroVerified publisher0.1.51 of 1See more

dregsy deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

2,977
gripmockdeliveryheroVerified publisher1.1.31 of 1See more

gripmock deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
stdlib@go1.14.6
1.25.13

Open the chart page →

2,794
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.55.0
1.25.13

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.55.0
1.25.13

Open the chart page →

7,987
snapshot-controllerdemocratic-csiVerified publisher0.3.01 of 1See more

snapshot-controller democratic-csi 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

467
developer-operatordeveloper-operatorVerified publisher2.1.21 of 1See more

developer-operator developer-operator 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.55.0
1.25.13

Open the chart page →

1,862
kube-bench-metricsdevopstalesVerified publisher0.1.01 of 1See more

kube-bench-metrics devopstales 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.25.13

Open the chart page →

2,112
kubedashdevopstalesOfficialVerified publisher4.0.05 of 8See more

kubedash devopstales 4.0.0

5 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18.3a9abf4275f9e
stdlib@go1.24.6
1.25.13
oliver006/redis_exporter:v1.82.0-alpineda9e89ee4e75
stdlib@go1.26.1
1.25.13
prom/statsd-exporter:v0.22.48be660470961
stdlib@go1.17.3
1.25.13
sosedoff/pgweb:latesta5256d416e2e
golang.org/x/net@v0.47.0
stdlib@go1.24.6
0.55.0
1.25.13
quay.io/prometheuscommunity/postgres-exporter:v0.19.1e96064f87622
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

9,305
permission-managerdevopstalesVerified publisher1.8.01 of 1See more

permission-manager devopstales 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.55.0
1.25.13

Open the chart page →

2,267
trivy-operatordevopstalesVerified publisher2.5.01 of 1See more

trivy-operator devopstales 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
devopstales/trivy-operator:2.575136aa7a26e
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

5,608
dnsmasqdevplayer0Verified publisher0.1.51 of 2See more

dnsmasq devplayer0 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

3,392

Container images carrying it

5,266 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
kvalitetsit/stakit-adapter-alertmanager:0.2.6838db1e90c6b
stdlib@go1.26.5
1.25.13
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
golang.org/x/net@v0.0.0-20180906233101-161cd47e91fd
stdlib@go1.19.3
0.55.0
1.25.13
1
l7mp/stunner-auth-server:1.1.02f8114477ba6
golang.org/x/net@v0.36.0
stdlib@go1.23.8
0.55.0
1.25.13
1
l7mp/stunner-gateway-operator:1.2.10ea40a1d42d5
stdlib@go1.26.4
1.25.13
1
l7mp/stunner-gateway-operator:1.1.0c34f7c931491
golang.org/x/net@v0.36.0
stdlib@go1.23.8
0.55.0
1.25.13
1
l7mp/stunner-gateway-operator-premium:1.2.14383766e66c5
stdlib@go1.26.4
1.25.13
1
labs64/auditflowc7b26d3ca11c
stdlib@go1.26.5
1.25.13
1
labs64/payment-gateway:0.0.10c66feefca17
stdlib@go1.26.5
1.25.13
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
stdlib@go1.26.5
1.25.13
1
langgenius/dify-api:1.16.1dcefa5f7c47c
stdlib@go1.26.4
1.25.13
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
stdlib@go1.26.2
1.25.13
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
stdlib@go1.26.4
1.25.13
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.55.0
1.25.13
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.55.0
1.25.13
1
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.25.13
1
langgenius/dify-web:1.0.0d64914ff0d6d
stdlib@go1.22.5
1.25.13
1
layer5/meshery:stable-latest78a8be21bef3
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.55.0
1.25.13
1
layer5/meshery-app-mesh:stable-latest77d59943b3d6
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.55.0
1.25.13
1
layer5/meshery-consul:stable-latest25a4cc38abcd
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.55.0
1.25.13
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b297
stdlib@go1.13.1
0.55.0
1.25.13
1
layer5/meshery-istio:stable-latestfde47c141ec6
golang.org/x/net@v0.36.0
stdlib@go1.23.9
0.55.0
1.25.13
1
layer5/meshery-kuma:stable-latest9d25f029a8a2
golang.org/x/net@v0.17.0
stdlib@go1.23.4
0.55.0
1.25.13
1
layer5/meshery-linkerd:stable-latestb99c73bac1f5
golang.org/x/net@v0.19.0
stdlib@go1.23.6
0.55.0
1.25.13
1
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.55.0
1.25.13
1
layer5/meshery-nsm:stable-latestebd6a8faf21f
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.12
0.55.0
1.25.13
1
layer5/meshery-operator:stable-latest6f58a28fe422
golang.org/x/net@v0.33.0
stdlib@go1.23.9
0.55.0
1.25.13
1
layer5/meshery-osm:stable-latestec898e5786c6
golang.org/x/net@v0.5.0
stdlib@go1.19.8
0.55.0
1.25.13
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.55.0
1.25.13
1
lbenicio/kubernetes-dashboard-api:1.14.951d3d30206c8
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13
1
lbenicio/kubernetes-dashboard-auth:1.4.1378c63efd9dcd
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13
1
lbenicio/kubernetes-dashboard-scraper:1.2.69202e96ad403
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13
1
lbenicio/kubernetes-dashboard-web:1.7.142797937bc2a5
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13
1
leonardomulticloud/svc-vault:v1.0.0e4acd2fbb7b1
stdlib@go1.23.1
1.25.13
1
leonardomulticloud/webhook:v1.0.0d119918900e8
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.55.0
1.25.13
1
library/caddy:latest13ba145cba2f
stdlib@go1.26.3
1.25.13
1
library/caddy:2.660fb54d36b4b
golang.org/x/net@v0.7.0
stdlib@go1.20
0.55.0
1.25.13
1
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.55.0
1.25.13
1
library/caddy:2.11.2-alpine834468128c76
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.55.0
1.25.13
1
library/caddy:2.4.5874405536b3e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17
0.55.0
1.25.13
1
library/caddy:2.9-alpineb4e3952384eb
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.5
0.55.0
1.25.13
1
library/cassandra:4.0093ee8ee5eb2
stdlib@go1.24.6
1.25.13
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.