StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,639
of 17,832 indexed, latest versions
Container images
5,351
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,639 of 17,832 indexed charts deploy, on 5,351 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,312
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+222 more0.55.03,762
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,639 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

5,351 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.55.0
1.25.13
1
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.55.0
1.25.13
1
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.55.0
1.25.13
1
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.10
0.55.0
1.25.13
1
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.10
0.55.0
1.25.13
1
kubestar/event-exporter:latest656606941255
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.55.0
1.25.13
1
kubesuite/kubereport:latest0262424ee702
golang.org/x/net@v0.29.0
stdlib@go1.22.0
0.55.0
1.25.13
1
kubevious/ui:1.2.16233e84bdd59
golang.org/x/net@v0.0.0-20220812165438-1d4ff48094d1
stdlib@go1.19.1
0.55.0
1.25.13
1
kubevip/kube-vip-cloud-provider:v0.0.12f8f4e3401f76
golang.org/x/net@v0.37.0
stdlib@go1.24.2
0.55.0
1.25.13
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.55.0
1.25.13
1
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
1
kudobuilder/controller:v0.9.069072d979708
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13
0.55.0
1.25.13
1
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.55.0
1.25.13
1
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.55.0
1.25.13
1
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/net@v0.19.0
stdlib@go1.22.12
0.55.0
1.25.13
1
kusionstack/kuperator:v0.7.4d2f72ae1d2f2
golang.org/x/net@v0.28.0
stdlib@go1.24.13
0.55.0
1.25.13
1
kusionstack/kusion:v0.14.0126c8f0b0976
golang.org/x/net@v0.31.0
stdlib@go1.22.10
0.55.0
1.25.13
1
kusionstack/operating:v0.5.0c28bd96b986b
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.55.0
1.25.13
1
kvalitetsit/go-loop:1.1.0d07f449d75ed
stdlib@go1.25.1
1.25.13
1
kvalitetsit/kitargus:2026-03-09-091234-10013c4c5cde2d9371c
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
kvalitetsit/metadoc-app:maine89e351733ad
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.19.5
0.55.0
1.25.13
1
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.55.0
1.25.13
1
kvalitetsit/myra-cert-manager-webhook:1.2.184ab59a1434e
stdlib@go1.26.4
1.25.13
1
kvalitetsit/nsp-prometheus-exporter:1.0.190b397ff954ec
stdlib@go1.15.3
1.25.13
1
kvalitetsit/oauth2-proxy-injector:1.5.00c906908d632
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.55.0
1.25.13
1
kvalitetsit/stakit-adapter-alertmanager:0.2.6838db1e90c6b
stdlib@go1.26.5
1.25.13
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
golang.org/x/net@v0.0.0-20180906233101-161cd47e91fd
stdlib@go1.19.3
0.55.0
1.25.13
1
l7mp/stunner-auth-server:1.1.02f8114477ba6
golang.org/x/net@v0.36.0
stdlib@go1.23.8
0.55.0
1.25.13
1
l7mp/stunner-gateway-operator:1.2.10ea40a1d42d5
stdlib@go1.26.4
1.25.13
1
l7mp/stunner-gateway-operator:1.1.0c34f7c931491
golang.org/x/net@v0.36.0
stdlib@go1.23.8
0.55.0
1.25.13
1
l7mp/stunner-gateway-operator-premium:1.2.14383766e66c5
stdlib@go1.26.4
1.25.13
1
labs64/auditflowc7b26d3ca11c
stdlib@go1.26.5
1.25.13
1
labs64/payment-gateway:0.0.10c66feefca17
stdlib@go1.26.5
1.25.13
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
stdlib@go1.26.5
1.25.13
1
langgenius/dify-api:1.16.1dcefa5f7c47c
stdlib@go1.26.4
1.25.13
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
stdlib@go1.26.2
1.25.13
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
stdlib@go1.26.4
1.25.13
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.55.0
1.25.13
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.55.0
1.25.13
1
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.25.13
1
langgenius/dify-web:1.0.0d64914ff0d6d
stdlib@go1.22.5
1.25.13
1
layer5/meshery:stable-latest78a8be21bef3
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.