StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,519
of 17,797 indexed, latest versions
Container images
5,266
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,519 of 17,797 indexed charts deploy, on 5,266 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,230
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,673
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,519 by stars
ChartLatestAffected imagesRadar Score
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18.64ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

1,667
keelkeel1.2.21 of 1See more

keel keel 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/keel-hq/keel:0.22.3315e188a07c2
stdlib@go1.26.5
1.25.13

Open the chart page →

818
community-operatormongodb-helm-charts0.13.01 of 1See more

community-operator mongodb-helm-charts 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

1,126
prometheus-kafka-exporterprometheus-communityVerified publisher4.0.01 of 1See more

prometheus-kafka-exporter prometheus-community 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

716
prometheus-mongodb-exporterprometheus-communityVerified publisher3.22.01 of 1See more

prometheus-mongodb-exporter prometheus-community 3.22.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
percona/mongodb_exporter:0.53.00214e482b2cd
stdlib@go1.26.2
1.25.13

Open the chart page →

238
node-local-dnsdeliveryheroVerified publisher2.9.21 of 1See more

node-local-dns deliveryhero 2.9.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
golang.org/x/net@v0.46.0
stdlib@go1.24.8
0.55.0
1.25.13

Open the chart page →

1,715
fission-allfission-chartsOfficialVerified publisher1.27.03 of 3See more

fission-all fission-charts 1.27.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/fission/fission-bundle:v1.27.0d353720b037a
stdlib@go1.26.4
1.25.13
ghcr.io/fission/pre-upgrade-checks:v1.27.0b053fc3539b4
stdlib@go1.26.4
1.25.13
ghcr.io/fission/reporter:v1.27.0c77cc925debe
stdlib@go1.26.4
1.25.13

Open the chart page →

302
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
stdlib@go1.19.8
1.25.13

Open the chart page →

4,823
rancherrancher-latest2.15.12 of 2See more

rancher rancher-latest 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/net@v0.52.0
stdlib@go1.26.5
0.55.0
1.25.13
rancher/shell:v0.8.1f293af9c635f
golang.org/x/net@v0.49.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

1,487
nacosygqygq2Verified publisher2.1.102 of 4See more

nacos ygqygq2 2.1.10

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.25.13
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.25.13

Open the chart page →

4,987
sealed-secretsbitnamiVerified publisher2.5.191 of 1See more

sealed-secrets bitnami 2.5.19

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

643
mariadbcloudpirates-mariadbVerified publisher0.16.141 of 1See more

mariadb cloudpirates-mariadb 0.16.14

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:12.3.3ab1c3dd38194
stdlib@go1.24.6
1.25.13

Open the chart page →

1,677
difydoubanVerified publisher0.10.04 of 6See more

dify douban 0.10.0

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.25.13
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.55.0
1.25.13
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.55.0
1.25.13
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.25.13

Open the chart page →

19,654
dragonflydragonflyVerified publisher1.8.52 of 3See more

dragonfly dragonfly 1.8.5

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
stdlib@go1.26.5
1.25.13
dragonflyoss/scheduler:v2.5.2d5dea9e662cd
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

4,083
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.4.02 of 3See more

kubeshark kubeshark-helm-charts 53.4.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubeshark/hub:v53.46d3f22525a0e
stdlib@go1.26.5
1.25.13
kubeshark/worker:v53.4b226490dfa11
stdlib@go1.26.5
1.25.13

Open the chart page →

839
secrets-store-csi-driversecret-store-csi-driver1.6.13 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver-crds:v1.6.1cdacfdbe8966
stdlib@go1.26.5
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

1,810
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.11 of 2See more

stackgres-operator stackgres-charts 1.19.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13

Open the chart page →

2,139
victoria-logs-singlevictoriametricsVerified publisher0.13.91 of 1See more

victoria-logs-single victoriametrics 0.13.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.52.047b820890d64
stdlib@go1.26.5
1.25.13

Open the chart page →

60
mongodbcloudpirates-mongodbVerified publisher0.18.131 of 1See more

mongodb cloudpirates-mongodb 0.18.13

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:8.3.981a1c8842a09
stdlib@go1.26.5
1.25.13

Open the chart page →

975
opensearch-operatoropensearch-operatorVerified publisher3.0.21 of 1See more

opensearch-operator opensearch-operator 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
opensearchproject/opensearch-operator:3.0.0-alphaf78bbdd1a386
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.55.0
1.25.13

Open the chart page →

610
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
stdlib@go1.26.4
1.25.13

Open the chart page →

417
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
stdlib@go1.26.5
1.25.13

Open the chart page →

1,605
pulsarapache4.7.06 of 10See more

pulsar apache 4.7.0

6 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.55.0
1.25.13
victoriametrics/operator:v0.68.3f52e1bd679cb
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

9,885
miniocloudpirates-minioVerified publisher0.13.41 of 1See more

minio cloudpirates-minio 0.13.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

968
vertical-pod-autoscalercowboysysopVerified publisher11.1.14 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.55.0
1.25.13
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

6,978
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.25.13
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
stdlib@go1.26.5
1.25.13
langgenius/dify-api:1.16.1dcefa5f7c47c
stdlib@go1.26.4
1.25.13
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
stdlib@go1.26.4
1.25.13
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

22,306
eclipse-cheeclipse-cheVerified publisher7.122.01 of 1See more

eclipse-che eclipse-che 7.122.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
stdlib@go1.26.5
1.25.13

Open the chart page →

931
pyroscopegrafana2.3.12 of 3See more

pyroscope grafana 2.3.1

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
golang.org/x/net@v0.46.0
stdlib@go1.25.5
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.55.0
1.25.13

Open the chart page →

3,225
botkubeinfracloudioVerified publisher1.14.01 of 1See more

botkube infracloudio 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.55.0
1.25.13

Open the chart page →

1,104
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

874
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
stdlib@go1.24.6
1.25.13

Open the chart page →

2,061
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.55.0
1.25.13

Open the chart page →

4,093
k6-operatorgrafana4.6.01 of 1See more

k6-operator grafana 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/grafana/k6-operator:controller-v1.6.0ba7f0fc1e22e
stdlib@go1.26.5
1.25.13

Open the chart page →

93
k8tzk8tzOfficialVerified publisher0.20.01 of 1See more

k8tz k8tz 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/k8tz/k8tz:0.20.0361628e53fc8
stdlib@go1.25.12
1.25.13

Open the chart page →

49
kiali-serverkiali2.32.01 of 1See more

kiali-server kiali 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/kiali/kiali:v2.32.0b171d679be27
stdlib@go1.26.3
1.25.13

Open the chart page →

247
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
stdlib@go1.25.12
1.25.13

Open the chart page →

1,199
oktetooktetoOfficialVerified publisher0.0.0-2026-08-177 of 10See more

okteto okteto 0.0.0-2026-08-17

7 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/okteto/backend:0.0.0-2026-08-17629bdce31b4d
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13
ghcr.io/okteto/buildkit:0.0.0-2026-08-1714527ca5d2a9
golang.org/x/net@v0.35.0
stdlib@go1.25.7
0.55.0
1.25.13
ghcr.io/okteto/daemon:0.0.0-2026-08-17c6e716a3fbbe
stdlib@go1.26.5
1.25.13
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-17265eedb3954b
stdlib@go1.26.4
1.25.13
ghcr.io/okteto/okteto:3.22.04585017f52f6
golang.org/x/net@v0.47.0
stdlib@go1.26.5
0.55.0
1.25.13
ghcr.io/okteto/registry:0.0.0-2026-08-1769131511501f
stdlib@go1.26.5
1.25.13
ghcr.io/okteto/reloader:0.0.0-2026-08-1704a3fce657c4
stdlib@go1.26.4
1.25.13

Open the chart page →

5,527
hydraory0.64.02 of 2See more

hydra ory 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
stdlib@go1.26.3
1.25.13

Open the chart page →

1,163
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
stdlib@go1.24.9
0.55.0
1.25.13

Open the chart page →

941
proxmox-csi-pluginproxmox-csi0.5.127 of 7See more

proxmox-csi-plugin proxmox-csi 0.5.12

7 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-csi-controller:v0.20.095ef74cce03e
stdlib@go1.26.5
1.25.13
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
stdlib@go1.26.5
1.25.13
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13

Open the chart page →

1,835
thanosthanos-communityOfficialVerified publisher0.44.01 of 1See more

thanos thanos-community 0.44.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
stdlib@go1.26.5
1.25.13

Open the chart page →

203
apisix-ingress-controllerapisix1.4.01See more

apisix-ingress-controller apisix 1.4.0

1 container image this version deploys carries CVE-2026-39821.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
stdlib@go1.26.5
1.25.13

Open the chart page →

volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/net@v0.40.0
stdlib@go1.25.11
0.55.0
1.25.13

Open the chart page →

1,386
concourseconcourseVerified publisher20.3.02 of 2See more

concourse concourse 20.3.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
concourse/concourse:8.3.040a143ce5873
golang.org/x/net@v0.50.0
stdlib@go1.26.5
0.55.0
1.25.13
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13

Open the chart page →

2,060
dynatrace-operatordynatraceVerified publisher1.10.21 of 1See more

dynatrace-operator dynatrace 1.10.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.10.252281db48c93
stdlib@go1.26.5
1.25.13

Open the chart page →

172
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.55.0
1.25.13

Open the chart page →

4,177
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.55.0
1.25.13

Open the chart page →

2,010
oncallgrafana1.16.57 of 12See more

oncall grafana 1.16.5

7 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.55.0
1.25.13

Open the chart page →

16,290
k8sgpt-operatork8sgptOfficialVerified publisher0.2.292 of 2See more

k8sgpt-operator k8sgpt 0.2.29

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.2982d0adcce816
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.55.0
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

980
node-feature-discoverynode-feature-discoveryOfficialVerified publisher0.19.01 of 1See more

node-feature-discovery node-feature-discovery 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
stdlib@go1.26.3
1.25.13

Open the chart page →

213

Container images carrying it

5,266 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.25.13
1
library/mongo:8.3.115d7043a4ffe0
stdlib@go1.26.5
1.25.13
1
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.25.13
1
library/mongo:4.2699d652ed674
stdlib@go1.18.2
1.25.13
1
library/mongo:noble6ede2806c78e
stdlib@go1.26.5
1.25.13
1
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.25.13
1
library/mongo:5.0.217c81758cb295
stdlib@go1.19.12
1.25.13
1
library/mongo:7.0-jammy84c4a18b60a0
stdlib@go1.24.6
1.25.13
1
library/mongo:7.0.28-jammy88785f6f665a
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.55.0
1.25.13
1
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.21.12
1.25.13
1
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.25.13
1
library/mongo:8.0.11dca8d11fe467
golang.org/x/net@v0.40.0
stdlib@go1.23.8
0.55.0
1.25.13
1
library/mysql:8.4.3106d5197fd8e
stdlib@go1.18.2
1.25.13
1
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.25.13
1
library/mysql:8.4.108dbcf531a03a
stdlib@go1.24.6
1.25.13
1
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.25.13
1
library/mysql:8.0-debian9382e4f6f7f0
stdlib@go1.24.6
1.25.13
1
library/mysql:8.0.41bf577825b52a
stdlib@go1.18.2
1.25.13
1
library/mysql:8.0.39ccb8f749bb5e
stdlib@go1.18.2
1.25.13
1
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.25.13
1
library/nats:2.12.150764f1952d72
stdlib@go1.25.12
1.25.13
1
library/nats:2.12.2-alpine2d5fce3229ae
stdlib@go1.25.4
1.25.13
1
library/nats:2.11.9-alpine777787bbb4c7
stdlib@go1.24.7
1.25.13
1
library/nats:2.12.3-alpine88fe8e0e09d6
stdlib@go1.25.5
1.25.13
1
library/nats:2.14.2-alpine952d157e28d5
stdlib@go1.26.3
1.25.13
1
library/nats:2.12-alpineb270f5e24283
stdlib@go1.25.12
1.25.13
1
library/nats:2.10.17-alpineb7752304692b
stdlib@go1.22.4
1.25.13
1
library/nats:2.10.12-alpinebca70839d953
stdlib@go1.21.8
1.25.13
1
library/nats:2.11.4c8cd23806eef
stdlib@go1.24.3
1.25.13
1
library/nats:2.9.11-alpineccbe811b8575
stdlib@go1.19.4
1.25.13
1
library/nats:2.9-alpined402af4147fc
stdlib@go1.20.14
1.25.13
1
library/nats:2.14.5-alpined4ac35882ac6
stdlib@go1.26.5
1.25.13
1
library/nats:2.9.20-alpined6c6ae7df4a0
stdlib@go1.19.11
1.25.13
1
library/nats:2.9.6-alpine3.16f576cdc17cc3
stdlib@go1.19.3
1.25.13
1
library/nats-streaming:0.25.60ad6861379c9
stdlib@go1.20.11
1.25.13
1
library/nats-streaming:0.25.5ced93c701875
stdlib@go1.19.10
1.25.13
1
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.25.13
1
library/postgres:18.0073e7c8b84e2
stdlib@go1.24.6
1.25.13
1
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.25.13
1
library/postgres:17.4304ab8135187
stdlib@go1.18.2
1.25.13
1
library/postgres:18.43a82e1f56c8f
stdlib@go1.24.6
1.25.13
1
library/postgres:18.1-alpine3.2144d837eb4c2e
stdlib@go1.24.6
1.25.13
1
library/postgres:16.11468e1f126ca5
stdlib@go1.24.6
1.25.13
1
library/postgres:18.3-alpine54451ecb8ab3
stdlib@go1.24.6
1.25.13
1
library/postgres:16.6557fea37a744
stdlib@go1.18.2
1.25.13
1
library/postgres:13.11-bullseye5c265bf1fd30
stdlib@go1.18.2
1.25.13
1
library/postgres:17.5-alpine6567bca8d7bc
stdlib@go1.18.2
1.25.13
1
library/postgres:18.369e8582b781c
stdlib@go1.24.6
1.25.13
1
library/postgres:15.186eb0add3b77c
stdlib@go1.24.6
1.25.13
1
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.25.13
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.