StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,549
of 17,805 indexed, latest versions
Container images
5,253
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,549 of 17,805 indexed charts deploy, on 5,253 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+190 more1.25.135,215
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,675
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,549 by stars
ChartLatestAffected imagesRadar Score
tenant-operatorappscodeVerified publisher2026.7.151 of 1See more

tenant-operator appscode 2026.7.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/tenant-operator:v0.0.2787f6de2b620
golang.org/x/net@v0.53.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

183
thanos-operatorappscodeVerified publisher2026.6.21 of 1See more

thanos-operator appscode 2026.6.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/thanos-operator:v2026.4.24e05a3e701291
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

385
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

1,227
vcd-lb-gcappscodeVerified publisher2026.6.251 of 1See more

vcd-lb-gc appscode 2026.6.25

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/net@v0.23.0
stdlib@go1.25.11
0.55.0
1.25.13

Open the chart page →

178
voyagerappscodeVerified publisher2026.3.231 of 1See more

voyager appscode 2026.3.23

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/voyager:v17.5.04964ceaf9d35
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

728
voyager-gatewayappscodeVerified publisher2026.7.212 of 2See more

voyager-gateway appscode 2026.7.21

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13
ghcr.io/voyagermesh/gateway:v1.8.24237fd16a3cb
stdlib@go1.26.4
1.25.13

Open the chart page →

1,373
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
golang.org/x/net@v0.11.0
stdlib@go1.21.1
0.55.0
1.25.13

Open the chart page →

5,704
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/net@v0.19.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

1,205
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.26.5
1.25.13

Open the chart page →

8,931
appwriteappwrite-helmVerified publisher1.3.24 of 8See more

appwrite appwrite-helm 1.3.2

4 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/net@v0.40.0
stdlib@go1.25.7
0.55.0
1.25.13
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.25.13
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.25.13
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.25.13

Open the chart page →

9,855
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

5,212
arcadearcadeVerified publisher1.10.11 of 10See more

arcade arcade 1.10.1

1 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.13

Open the chart page →

991
argocd-ecr-updaterargocd-aws-ecr-updater0.3.391 of 1See more

argocd-ecr-updater argocd-aws-ecr-updater 0.3.39

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/karlderkaefer/argocd-ecr-updater:1.4.6ed5d4b74792c
stdlib@go1.26.5
1.25.13

Open the chart page →

86
argocd-bitbucket-proxyargocd-bitbucket-proxy1.1.11 of 1See more

argocd-bitbucket-proxy argocd-bitbucket-proxy 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/salemgolemugoo/argocd-bitbucket-proxy:latesta72df069095b
stdlib@go1.26.1
1.25.13

Open the chart page →

189
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.55.0
1.25.13
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.13
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/net@v0.34.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

7,697
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

1,845
argo-zombiesargo-zombies0.1.521 of 1See more

argo-zombies argo-zombies 0.1.52

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.55.0
1.25.13

Open the chart page →

254
otel-collectorarieotechVerified publisher0.1.01 of 1See more

otel-collector arieotech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.154.0b3079f45e19b
stdlib@go1.26.4
1.25.13

Open the chart page →

384
arlas-aiasarlas-stackVerified publisher28.9.06See more

arlas-aias arlas-stack 28.9.0

6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.55.0
1.25.13
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.25.13
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.55.0
1.25.13
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
golang.org/x/net@v0.33.0
stdlib@go1.23.8
0.55.0
1.25.13
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.25.13

Open the chart page →

arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.55.0
1.25.13
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.55.0
1.25.13
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
stdlib@go1.19.5
1.25.13
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13

Open the chart page →

23,461
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.55.0
1.25.13

Open the chart page →

1,780
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.11
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.10
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

8,630
assemblylineassemblylineVerified publisher7.4.202 of 12See more

assemblyline assemblyline 7.4.20

2 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

12,862
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.25.13

Open the chart page →

5,538
dltkvassist-iot-data-integrity-verification0.2.05 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.55.0
1.25.13
hyperledger/fabric-ca:latesta70b6ba64a08
stdlib@go1.26.4
1.25.13
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

185,703
dltflassist-iot-dlt-based-fl0.2.05 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.55.0
1.25.13
hyperledger/fabric-ca:latesta70b6ba64a08
stdlib@go1.26.4
1.25.13
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

185,703
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

3,789
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.25.13

Open the chart page →

9,428
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

4,371
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.25.13

Open the chart page →

13,413
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.25.13

Open the chart page →

10,179
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.55.0
1.25.13
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18
0.55.0
1.25.13

Open the chart page →

83,638
performanceandusagediagnosisassist-iot-pud1.0.05 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

5 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.17.12
0.55.0
1.25.13
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.13
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.55.0
1.25.13

Open the chart page →

8,589
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

8,072
semantic-repositoryassist-iot-semantic-repository1.1.01 of 3See more

semantic-repository assist-iot-semantic-repository 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

1,201
smartorchestratorassist-iot-smart-orchestrator4.0.04 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

4 of the 14 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.22.1
1.25.13
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.55.0
1.25.13
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.13
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

45,972
astrotrekastria0.0.24 of 4See more

astrotrek astria 0.0.2

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.25.13
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.25.13

Open the chart page →

32,715
celestia-localastria9.0.02 of 2See more

celestia-local astria 9.0.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.55.0
1.25.13
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/net@v0.43.0
stdlib@go1.24.7
0.55.0
1.25.13

Open the chart page →

3,309
celestia-nodeastria0.7.11 of 1See more

celestia-node astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/net@v0.43.0
stdlib@go1.24.7
0.55.0
1.25.13

Open the chart page →

1,520
evm-faucetastria0.1.51 of 1See more

evm-faucet astria 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.25.13

Open the chart page →

1,764
evm-rollupastria4.1.01 of 2See more

evm-rollup astria 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

4,038
evm-stackastria5.0.31 of 2See more

evm-stack astria 5.0.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

4,038
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

3,881
graph-nodeastria0.2.23 of 3See more

graph-node astria 0.2.2

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
graphprotocol/graph-node:latestb0436347fb24
stdlib@go1.26.5
1.25.13
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/net@v0.1.0
stdlib@go1.19.1
0.55.0
1.25.13
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

5,623
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.55.0
1.25.13
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

6,506
sequencer-faucetastria0.9.21 of 1See more

sequencer-faucet astria 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
golang.org/x/net@v0.28.0
stdlib@go1.22.6
0.55.0
1.25.13

Open the chart page →

1,320
phonebook-chartasumankamberoglu0.1.51 of 3See more

phonebook-chart asumankamberoglu 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

3,176
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

9,469
hcloud-csi-driveratem181.5.12 of 6See more

hcloud-csi-driver atem18 1.5.1

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.3
0.55.0
1.25.13
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.55.0
1.25.13

Open the chart page →

6,509
bamboo-agentatlassian-data-centerVerified publisher2.0.151 of 1See more

bamboo-agent atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
stdlib@go1.22.2
1.25.13

Open the chart page →

1,721

Container images carrying it

5,253 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/postgres:16.11468e1f126ca5
stdlib@go1.24.6
1.25.13
1
library/postgres:18.3-alpine54451ecb8ab3
stdlib@go1.24.6
1.25.13
1
library/postgres:16.6557fea37a744
stdlib@go1.18.2
1.25.13
1
library/postgres:13.11-bullseye5c265bf1fd30
stdlib@go1.18.2
1.25.13
1
library/postgres:17.5-alpine6567bca8d7bc
stdlib@go1.18.2
1.25.13
1
library/postgres:18.369e8582b781c
stdlib@go1.24.6
1.25.13
1
library/postgres:15.186eb0add3b77c
stdlib@go1.24.6
1.25.13
1
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.25.13
1
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.25.13
1
library/postgres:17.2-alpine7e5df973a748
stdlib@go1.18.2
1.25.13
1
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.25.13
1
library/postgres:18.48ff36f3c6637
stdlib@go1.24.6
1.25.13
1
library/postgres:18.4-alpine3.249a8afca54e78
stdlib@go1.24.6
1.25.13
1
library/postgres:18.3a9abf4275f9e
stdlib@go1.24.6
1.25.13
1
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.25.13
1
library/postgres:13.12ced3ba927f4c
stdlib@go1.18.2
1.25.13
1
library/postgres:15.18-bookworme8db9bd3e9e1
stdlib@go1.24.6
1.25.13
1
library/postgres:14.22eba8ddbdd837
stdlib@go1.24.6
1.25.13
1
library/postgres:17.10ebba4f4de37f
stdlib@go1.24.6
1.25.13
1
library/postgres:17.6-alpineef257d85f76e
stdlib@go1.24.6
1.25.13
1
library/postgres:17-alpinef02121de6f74
stdlib@go1.24.6
1.25.13
1
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.25.13
1
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.25.13
1
library/rabbitmq:4.3.6-management534e4fefc5f0
stdlib@go1.22.2
1.25.13
1
library/rabbitmq:4.3.667bad329974a
stdlib@go1.22.2
1.25.13
1
library/rabbitmq:4.2.87561d672fae4
stdlib@go1.22.2
1.25.13
1
library/rabbitmq:4.3.4-managementeb5295d08332
stdlib@go1.22.2
1.25.13
1
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.25.13
1
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.25.13
1
library/redis:7.2.5-alpine6aaf3f5e6bc8
stdlib@go1.18.2
1.25.13
1
library/redis:6.2.20-alpine77697a75da9f
stdlib@go1.18.2
1.25.13
1
library/redis83edc2b8e9ff
stdlib@go1.18.2
1.25.13
1
library/redis:7.0.1092b8b307ee28
stdlib@go1.18.2
1.25.13
1
library/redis:7.4.1bb142a9c18ac
stdlib@go1.18.2
1.25.13
1
library/redis:7.4.1-alpinec1e88455c852
stdlib@go1.18.2
1.25.13
1
library/redis:7.0-alpinec9d92d840fd0
stdlib@go1.18.2
1.25.13
1
library/redmine:6.1.204ac44a2595b
stdlib@go1.24.6
1.25.13
1
library/telegraf:1.20.428e98eece020
golang.org/x/net@v0.0.0-20211005215030-d2e5035098b3
stdlib@go1.17.3
0.55.0
1.25.13
1
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.55.0
1.25.13
1
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.5
0.55.0
1.25.13
1
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.6
0.55.0
1.25.13
1
library/traefik:v2.11.00a5157f742d2
golang.org/x/net@v0.20.0
stdlib@go1.22.0
0.55.0
1.25.13
1
library/traefik:3.3.5104204dadedf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.55.0
1.25.13
1
library/traefik:v2.10.11489caffaedb
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.55.0
1.25.13
1
library/traefik:2.10.61957e3314f43
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.55.0
1.25.13
1
library/traefik:2.5.62f603f8d3abe
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.5
0.55.0
1.25.13
1
library/traefik:v3.6.1334d5089d0b41
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.55.0
1.25.13
1
library/traefik:v1.7.345d47b7bb2546
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16.12
0.55.0
1.25.13
1
library/traefik:2.5.47d0228d19042
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.3
0.55.0
1.25.13
1
library/traefik:v3.7.109c3b91d5fb77
stdlib@go1.26.5
1.25.13
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.