StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,643
of 17,821 indexed, latest versions
Container images
5,380
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,643 of 17,821 indexed charts deploy, on 5,380 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,337
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,758
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,643 by stars
ChartLatestAffected imagesRadar Score
hive-operatorkubedoopVerified publisher0.4.01 of 1See more

hive-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/zncdatadev/hive-operator:0.4.0d66ba9149c22
golang.org/x/net@v0.53.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

381
kafka-operatorkubedoopVerified publisher0.4.01 of 1See more

kafka-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/zncdatadev/kafka-operator:0.4.00a0b4c39c1ba
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

464
listener-operatorkubedoopVerified publisher0.4.06 of 6See more

listener-operator kubedoop 0.4.0

6 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/zncdatadev/listener-csi-driver:0.4.0b69bed123b02
golang.org/x/net@v0.53.0
stdlib@go1.25.8
0.55.0
1.25.13
quay.io/zncdatadev/listener-operator:0.4.068b92dae8d75
golang.org/x/net@v0.53.0
stdlib@go1.25.8
0.55.0
1.25.13
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

4,537
nifi-operatorkubedoopVerified publisher0.4.01 of 1See more

nifi-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/zncdatadev/nifi-operator:0.4.0bb4e26ff5e2f
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

388
secret-operatorkubedoopVerified publisher0.4.05 of 5See more

secret-operator kubedoop 0.4.0

5 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/zncdatadev/secret-csi-driver:0.4.0604a7d98ab58
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.55.0
1.25.13
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

4,456
spark-k8s-operatorkubedoopVerified publisher0.4.01 of 1See more

spark-k8s-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/zncdatadev/spark-k8s-operator:0.4.0d3f2b10c4a6d
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

411
superset-operatorkubedoopVerified publisher0.4.01 of 1See more

superset-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/zncdatadev/superset-operator:0.4.0102e66e32218
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

388
trino-operatorkubedoopVerified publisher0.4.01 of 1See more

trino-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/zncdatadev/trino-operator:0.4.04f516757aee3
golang.org/x/net@v0.54.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

376
zookeeper-operatorkubedoopVerified publisher0.4.01 of 1See more

zookeeper-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/zncdatadev/zookeeper-operator:0.4.0b4f33d89ac45
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

388
kube-ecr-secrets-operatorkube-ecr-secrets-operatorVerified publisher0.4.01 of 2See more

kube-ecr-secrets-operator kube-ecr-secrets-operator 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/zak905/kube-ecr-secrets-operator/controller-manager:0.2.11d078e45bac70
golang.org/x/net@v0.49.0
0.55.0

Open the chart page →

64
kube-fledgedkube-fledged0.11.02 of 2See more

kube-fledged kube-fledged 0.11.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
senthilrch/kubefledged-controller:v0.11.0bf336912a191
stdlib@go1.26.5
1.25.13
senthilrch/kubefledged-webhook-server:v0.11.0836a8bbe7cfb
stdlib@go1.26.5
1.25.13

Open the chart page →

438
cephfs-csikubegems1.0.81 of 6See more

cephfs-csi kubegems 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.5
0.55.0
1.25.13

Open the chart page →

4,454
chartmuseumkubegems3.8.01 of 1See more

chartmuseum kubegems 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/net@v0.0.0-20220121210141-e204ce36a2ba
stdlib@go1.17.6
0.55.0
1.25.13

Open the chart page →

3,527
gatewaykubegems0.3.22 of 2See more

gateway kubegems 0.3.2

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubegems/ingress-nginx-operator:v0.2.0cc67357beeeb
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.22.5
0.55.0
1.25.13
kubegems/kube-rbac-proxy:v0.8.0941f557ed1ee
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.13.15
0.55.0
1.25.13

Open the chart page →

3,507
giteakubegems5.0.81 of 2See more

gitea kubegems 5.0.8

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gitea/gitea:1.16.8b0bdf102b485
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.55.0
1.25.13

Open the chart page →

3,403
juicefs-csi-driverkubegems0.19.22 of 6See more

juicefs-csi-driver kubegems 0.19.2

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.55.0
1.25.13
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.55.0
1.25.13

Open the chart page →

4,867
juicefs-tenantkubegems1.0.11 of 3See more

juicefs-tenant kubegems 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubegems/redis:7.2.5-debian-12-r2870ee3a77add
stdlib@go1.21.11
1.25.13

Open the chart page →

4,345
knative-servingkubegems1.0.17 of 8See more

knative-serving kubegems 1.0.1

7 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned197fbb71d1f1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned08315309da4b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned105bdd14ecaa
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedbac158dfb0c7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mappingdigest-pinnede384a295069b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhookdigest-pinned15f1ce7f35b4
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned1282a399cbb9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

10,476
kubegems-edgekubegems1.24.101 of 1See more

kubegems-edge kubegems 1.24.10

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/net@v0.19.0
stdlib@go1.24.10
0.55.0
1.25.13

Open the chart page →

3,399
kubegems-multus-cnikubegems2.4.11 of 2See more

kubegems-multus-cni kubegems 2.4.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.16bebbda31416
golang.org/x/net@v0.28.0
stdlib@go1.23.9
0.55.0
1.25.13

Open the chart page →

1,408
kubegems-paikubegems1.0.181 of 1See more

kubegems-pai kubegems 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubegems/mysql:8.0.33-debian-11-r019cb195b9a50
stdlib@go1.19.8
1.25.13

Open the chart page →

1,053
logging-operatorkubegems3.17.61 of 1See more

logging-operator kubegems 3.17.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.9
0.55.0
1.25.13

Open the chart page →

1,801
prometheus-adapterkubegems4.14.11 of 1See more

prometheus-adapter kubegems 4.14.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

945
prometheus-blackbox-exporterkubegems7.1.31 of 1See more

prometheus-blackbox-exporter kubegems 7.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.22.0608acee5704a
golang.org/x/net@v0.0.0-20220728211354-c7608f3a8462
stdlib@go1.18.5
0.55.0
1.25.13

Open the chart page →

1,636
volcanokubegems1.12.13 of 3See more

volcano kubegems 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
volcanosh/vc-controller-manager:v1.12.13815883c32f6
golang.org/x/net@v0.38.0
stdlib@go1.23.7
0.55.0
1.25.13
volcanosh/vc-scheduler:v1.12.1b24ea8af2d16
golang.org/x/net@v0.38.0
stdlib@go1.23.7
0.55.0
1.25.13
volcanosh/vc-webhook-manager:v1.12.1f8b50088a732
golang.org/x/net@v0.30.0
stdlib@go1.23.7
0.55.0
1.25.13

Open the chart page →

5,050
xpai-schedulerkubegems1.12.11 of 2See more

xpai-scheduler kubegems 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
stdlib@go1.19.3
0.55.0
1.25.13

Open the chart page →

2,325
gptchat-api-feishubotkubegemsapp0.1.13 of 3See more

gptchat-api-feishubot kubegemsapp 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubegems/chatgpt-api:latestf3c492a938ad
stdlib@go1.19.3
1.25.13
kubegems/chatgpt-api-feishubot:latest7c93c84b2055
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13
kubegems/chatgpt-api-proxy:latest8905c9dbbb5d
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13

Open the chart page →

8,495
kube-insightkube-insight0.1.31 of 1See more

kube-insight kube-insight 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nowakeai/kube-insight:v0.1.475849fe6548a
stdlib@go1.26.4
1.25.13

Open the chart page →

427
kubeintellectkubeintellectVerified publisher2.5.01 of 2See more

kubeintellect kubeintellect 2.5.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
golang.org/x/net@v0.30.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

1,917
kubelet-summary-exporterkubelet-summary-exporter1.0.01 of 1See more

kubelet-summary-exporter kubelet-summary-exporter 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/salesforce/kubelet-summary-exporter:sha-c2bf90d377e09d2dd72
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

1,016
log-generatorkube-loggingVerified publisher0.6.01 of 1See more

log-generator kube-logging 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/log-generator:v0.6.08324bbc0ec08
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.55.0
1.25.13

Open the chart page →

1,270
logging-demokube-loggingVerified publisher4.0.31 of 1See more

logging-demo kube-logging 4.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/log-generator:v0.4.105aa441b20aa
stdlib@go1.20.1
1.25.13

Open the chart page →

1,268
log-socketkube-loggingVerified publisher0.1.21 of 1See more

log-socket kube-logging 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/log-socket:latesta514736d2d4d
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.18.6
0.55.0
1.25.13

Open the chart page →

1,221
kubemacpoolkubemacpoolVerified publisher0.3.01 of 1See more

kubemacpool kubemacpool 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubemacpool:v0.45.0eebb65b8a12c
golang.org/x/net@v0.23.0
stdlib@go1.22.0
0.55.0
1.25.13

Open the chart page →

1,641
kube-netlagkube-netlagVerified publisher1.1.01 of 1See more

kube-netlag kube-netlag 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/net@v0.33.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

1,512
kube-node-readykube-node-ready0.5.01 of 1See more

kube-node-ready kube-node-ready 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/imunhatep/kube-node-ready:0.5.07439f6f9f85c
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

545
apm-serverkube-opsVerified publisher0.1.21 of 1See more

apm-server kube-ops 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
elastic/apm-server:7.17.6c7a1c63257d0
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.2
0.55.0
1.25.13

Open the chart page →

7,231
lokikube-opsVerified publisher1.7.31 of 1See more

loki kube-ops 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/kube-ops/loki:2.2.14fbd63194674
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.3
0.55.0
1.25.13

Open the chart page →

2,654
promtailkube-opsVerified publisher1.5.11 of 2See more

promtail kube-ops 1.5.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/kube-ops/promtail:2.2.134de6387233b
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.3
0.55.0
1.25.13

Open the chart page →

4,160
kube-ovnkube-ovn-test1.14.01 of 1See more

kube-ovn kube-ovn-test 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubeovn/kube-ovn:v1.14.06722b54eb5c0
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

5,288
kuberay-apiserverkuberay-operator1.7.11 of 2See more

kuberay-apiserver kuberay-operator 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/kuberay/security-proxy:nightly4525b5acd23c
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.55.0
1.25.13

Open the chart page →

202
kuberecordkuberecordVerified publisher0.4.01 of 1See more

kuberecord kuberecord 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kuberecord/kuberecord:v0.4.02a19792ad2ec
golang.org/x/net@v0.50.0
0.55.0

Open the chart page →

190
kubereportkubereport1.1.01 of 1See more

kubereport kubereport 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubesuite/kubereport:latest0262424ee702
golang.org/x/net@v0.29.0
stdlib@go1.22.0
0.55.0
1.25.13

Open the chart page →

1,121
adguard-homekubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

adguard-home kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.767157eb1dc3b2
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13

Open the chart page →

726
cloudflaredkubernetes-homelab-helm-chartsVerified publisher0.1.11 of 1See more

cloudflared kubernetes-homelab-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

1,399
firefly-iiikubernetes-homelab-helm-chartsVerified publisher0.1.31 of 3See more

firefly-iii kubernetes-homelab-helm-charts 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.25.13

Open the chart page →

4,396
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.22 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
stdlib@go1.24.6
1.25.13
library/mysql:885b9bf2e29cf
stdlib@go1.24.6
1.25.13

Open the chart page →

2,772
navidromekubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

navidrome kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
deluan/navidrome:0.61.29fa40b3d8dec
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.55.0
1.25.13

Open the chart page →

901
pocket-idkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

pocket-id kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
golang.org/x/net@v0.53.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

1,532
portfolio-trackerkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

portfolio-tracker kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.13

Open the chart page →

1,513

Container images carrying it

5,380 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
golang.org/x/net@v0.0.0-20180906233101-161cd47e91fd
stdlib@go1.19.3
0.55.0
1.25.13
1
l7mp/stunner-auth-server:1.1.02f8114477ba6
golang.org/x/net@v0.36.0
stdlib@go1.23.8
0.55.0
1.25.13
1
l7mp/stunner-gateway-operator:1.2.10ea40a1d42d5
stdlib@go1.26.4
1.25.13
1
l7mp/stunner-gateway-operator:1.1.0c34f7c931491
golang.org/x/net@v0.36.0
stdlib@go1.23.8
0.55.0
1.25.13
1
l7mp/stunner-gateway-operator-premium:1.2.14383766e66c5
stdlib@go1.26.4
1.25.13
1
labs64/auditflowc7b26d3ca11c
stdlib@go1.26.5
1.25.13
1
labs64/payment-gateway:0.0.10c66feefca17
stdlib@go1.26.5
1.25.13
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
stdlib@go1.26.5
1.25.13
1
langgenius/dify-api:1.16.1dcefa5f7c47c
stdlib@go1.26.4
1.25.13
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
stdlib@go1.26.2
1.25.13
1
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
stdlib@go1.26.2
1.25.13
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
stdlib@go1.26.4
1.25.13
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.55.0
1.25.13
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.55.0
1.25.13
1
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.25.13
1
langgenius/dify-web:1.0.0d64914ff0d6d
stdlib@go1.22.5
1.25.13
1
lavr/express-botx:0.39.0-rootlessf5035e0f1434
golang.org/x/net@v0.38.0
0.55.0
1
layer5/meshery:stable-latest78a8be21bef3
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.55.0
1.25.13
1
layer5/meshery-app-mesh:stable-latest77d59943b3d6
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.55.0
1.25.13
1
layer5/meshery-consul:stable-latest25a4cc38abcd
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.55.0
1.25.13
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b297
stdlib@go1.13.1
0.55.0
1.25.13
1
layer5/meshery-istio:stable-latestfde47c141ec6
golang.org/x/net@v0.36.0
stdlib@go1.23.9
0.55.0
1.25.13
1
layer5/meshery-kuma:stable-latest9d25f029a8a2
golang.org/x/net@v0.17.0
stdlib@go1.23.4
0.55.0
1.25.13
1
layer5/meshery-linkerd:stable-latestb99c73bac1f5
golang.org/x/net@v0.19.0
stdlib@go1.23.6
0.55.0
1.25.13
1
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.55.0
1.25.13
1
layer5/meshery-nsm:stable-latestebd6a8faf21f
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.12
0.55.0
1.25.13
1
layer5/meshery-operator:stable-latest6f58a28fe422
golang.org/x/net@v0.33.0
stdlib@go1.23.9
0.55.0
1.25.13
1
layer5/meshery-osm:stable-latestec898e5786c6
golang.org/x/net@v0.5.0
stdlib@go1.19.8
0.55.0
1.25.13
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.55.0
1.25.13
1
lbenicio/kubernetes-dashboard-api:1.14.951d3d30206c8
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13
1
lbenicio/kubernetes-dashboard-auth:1.4.1378c63efd9dcd
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13
1
lbenicio/kubernetes-dashboard-scraper:1.2.69202e96ad403
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13
1
lbenicio/kubernetes-dashboard-web:1.7.142797937bc2a5
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13
1
leonardomulticloud/svc-vault:v1.0.0e4acd2fbb7b1
stdlib@go1.23.1
1.25.13
1
leonardomulticloud/webhook:v1.0.0d119918900e8
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.55.0
1.25.13
1
library/caddy:latest13ba145cba2f
stdlib@go1.26.3
1.25.13
1
library/caddy:2.660fb54d36b4b
golang.org/x/net@v0.7.0
stdlib@go1.20
0.55.0
1.25.13
1
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.55.0
1.25.13
1
library/caddy:2.11.2-alpine834468128c76
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.55.0
1.25.13
1
library/caddy:2.4.5874405536b3e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17
0.55.0
1.25.13
1
library/caddy:2.9-alpineb4e3952384eb
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.5
0.55.0
1.25.13
1
library/cassandra:4.0093ee8ee5eb2
stdlib@go1.24.6
1.25.13
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.