StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,519
of 17,797 indexed, latest versions
Container images
5,266
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,519 of 17,797 indexed charts deploy, on 5,266 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,230
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,673
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,519 by stars
ChartLatestAffected imagesRadar Score
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18.64ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

1,667
keelkeel1.2.21 of 1See more

keel keel 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/keel-hq/keel:0.22.3315e188a07c2
stdlib@go1.26.5
1.25.13

Open the chart page →

818
community-operatormongodb-helm-charts0.13.01 of 1See more

community-operator mongodb-helm-charts 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

1,126
prometheus-kafka-exporterprometheus-communityVerified publisher4.0.01 of 1See more

prometheus-kafka-exporter prometheus-community 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

716
prometheus-mongodb-exporterprometheus-communityVerified publisher3.22.01 of 1See more

prometheus-mongodb-exporter prometheus-community 3.22.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
percona/mongodb_exporter:0.53.00214e482b2cd
stdlib@go1.26.2
1.25.13

Open the chart page →

238
node-local-dnsdeliveryheroVerified publisher2.9.21 of 1See more

node-local-dns deliveryhero 2.9.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
golang.org/x/net@v0.46.0
stdlib@go1.24.8
0.55.0
1.25.13

Open the chart page →

1,715
fission-allfission-chartsOfficialVerified publisher1.27.03 of 3See more

fission-all fission-charts 1.27.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/fission/fission-bundle:v1.27.0d353720b037a
stdlib@go1.26.4
1.25.13
ghcr.io/fission/pre-upgrade-checks:v1.27.0b053fc3539b4
stdlib@go1.26.4
1.25.13
ghcr.io/fission/reporter:v1.27.0c77cc925debe
stdlib@go1.26.4
1.25.13

Open the chart page →

302
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
stdlib@go1.19.8
1.25.13

Open the chart page →

4,823
rancherrancher-latest2.15.12 of 2See more

rancher rancher-latest 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/net@v0.52.0
stdlib@go1.26.5
0.55.0
1.25.13
rancher/shell:v0.8.1f293af9c635f
golang.org/x/net@v0.49.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

1,487
nacosygqygq2Verified publisher2.1.102 of 4See more

nacos ygqygq2 2.1.10

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.25.13
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.25.13

Open the chart page →

4,987
sealed-secretsbitnamiVerified publisher2.5.191 of 1See more

sealed-secrets bitnami 2.5.19

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

643
mariadbcloudpirates-mariadbVerified publisher0.16.141 of 1See more

mariadb cloudpirates-mariadb 0.16.14

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:12.3.3ab1c3dd38194
stdlib@go1.24.6
1.25.13

Open the chart page →

1,677
difydoubanVerified publisher0.10.04 of 6See more

dify douban 0.10.0

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.25.13
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.55.0
1.25.13
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.55.0
1.25.13
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.25.13

Open the chart page →

19,654
dragonflydragonflyVerified publisher1.8.52 of 3See more

dragonfly dragonfly 1.8.5

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
stdlib@go1.26.5
1.25.13
dragonflyoss/scheduler:v2.5.2d5dea9e662cd
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

4,083
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.4.02 of 3See more

kubeshark kubeshark-helm-charts 53.4.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubeshark/hub:v53.46d3f22525a0e
stdlib@go1.26.5
1.25.13
kubeshark/worker:v53.4b226490dfa11
stdlib@go1.26.5
1.25.13

Open the chart page →

839
secrets-store-csi-driversecret-store-csi-driver1.6.13 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver-crds:v1.6.1cdacfdbe8966
stdlib@go1.26.5
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

1,810
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.11 of 2See more

stackgres-operator stackgres-charts 1.19.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13

Open the chart page →

2,139
victoria-logs-singlevictoriametricsVerified publisher0.13.91 of 1See more

victoria-logs-single victoriametrics 0.13.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.52.047b820890d64
stdlib@go1.26.5
1.25.13

Open the chart page →

60
mongodbcloudpirates-mongodbVerified publisher0.18.131 of 1See more

mongodb cloudpirates-mongodb 0.18.13

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:8.3.981a1c8842a09
stdlib@go1.26.5
1.25.13

Open the chart page →

975
opensearch-operatoropensearch-operatorVerified publisher3.0.21 of 1See more

opensearch-operator opensearch-operator 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
opensearchproject/opensearch-operator:3.0.0-alphaf78bbdd1a386
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.55.0
1.25.13

Open the chart page →

610
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
stdlib@go1.26.4
1.25.13

Open the chart page →

417
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
stdlib@go1.26.5
1.25.13

Open the chart page →

1,605
pulsarapache4.7.06 of 10See more

pulsar apache 4.7.0

6 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.55.0
1.25.13
victoriametrics/operator:v0.68.3f52e1bd679cb
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

9,885
miniocloudpirates-minioVerified publisher0.13.41 of 1See more

minio cloudpirates-minio 0.13.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

968
vertical-pod-autoscalercowboysysopVerified publisher11.1.14 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.55.0
1.25.13
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

6,978
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.25.13
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
stdlib@go1.26.5
1.25.13
langgenius/dify-api:1.16.1dcefa5f7c47c
stdlib@go1.26.4
1.25.13
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
stdlib@go1.26.4
1.25.13
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

22,306
eclipse-cheeclipse-cheVerified publisher7.122.01 of 1See more

eclipse-che eclipse-che 7.122.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
stdlib@go1.26.5
1.25.13

Open the chart page →

931
pyroscopegrafana2.3.12 of 3See more

pyroscope grafana 2.3.1

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
golang.org/x/net@v0.46.0
stdlib@go1.25.5
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.55.0
1.25.13

Open the chart page →

3,225
botkubeinfracloudioVerified publisher1.14.01 of 1See more

botkube infracloudio 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.55.0
1.25.13

Open the chart page →

1,104
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

874
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
stdlib@go1.24.6
1.25.13

Open the chart page →

2,061
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.55.0
1.25.13

Open the chart page →

4,093
k6-operatorgrafana4.6.01 of 1See more

k6-operator grafana 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/grafana/k6-operator:controller-v1.6.0ba7f0fc1e22e
stdlib@go1.26.5
1.25.13

Open the chart page →

93
k8tzk8tzOfficialVerified publisher0.20.01 of 1See more

k8tz k8tz 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/k8tz/k8tz:0.20.0361628e53fc8
stdlib@go1.25.12
1.25.13

Open the chart page →

49
kiali-serverkiali2.32.01 of 1See more

kiali-server kiali 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/kiali/kiali:v2.32.0b171d679be27
stdlib@go1.26.3
1.25.13

Open the chart page →

247
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
stdlib@go1.25.12
1.25.13

Open the chart page →

1,199
oktetooktetoOfficialVerified publisher0.0.0-2026-08-177 of 10See more

okteto okteto 0.0.0-2026-08-17

7 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/okteto/backend:0.0.0-2026-08-17629bdce31b4d
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13
ghcr.io/okteto/buildkit:0.0.0-2026-08-1714527ca5d2a9
golang.org/x/net@v0.35.0
stdlib@go1.25.7
0.55.0
1.25.13
ghcr.io/okteto/daemon:0.0.0-2026-08-17c6e716a3fbbe
stdlib@go1.26.5
1.25.13
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-17265eedb3954b
stdlib@go1.26.4
1.25.13
ghcr.io/okteto/okteto:3.22.04585017f52f6
golang.org/x/net@v0.47.0
stdlib@go1.26.5
0.55.0
1.25.13
ghcr.io/okteto/registry:0.0.0-2026-08-1769131511501f
stdlib@go1.26.5
1.25.13
ghcr.io/okteto/reloader:0.0.0-2026-08-1704a3fce657c4
stdlib@go1.26.4
1.25.13

Open the chart page →

5,527
hydraory0.64.02 of 2See more

hydra ory 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
stdlib@go1.26.3
1.25.13

Open the chart page →

1,163
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
stdlib@go1.24.9
0.55.0
1.25.13

Open the chart page →

941
proxmox-csi-pluginproxmox-csi0.5.127 of 7See more

proxmox-csi-plugin proxmox-csi 0.5.12

7 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-csi-controller:v0.20.095ef74cce03e
stdlib@go1.26.5
1.25.13
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
stdlib@go1.26.5
1.25.13
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13

Open the chart page →

1,835
thanosthanos-communityOfficialVerified publisher0.44.01 of 1See more

thanos thanos-community 0.44.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
stdlib@go1.26.5
1.25.13

Open the chart page →

203
apisix-ingress-controllerapisix1.4.01See more

apisix-ingress-controller apisix 1.4.0

1 container image this version deploys carries CVE-2026-39821.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
stdlib@go1.26.5
1.25.13

Open the chart page →

volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/net@v0.40.0
stdlib@go1.25.11
0.55.0
1.25.13

Open the chart page →

1,386
concourseconcourseVerified publisher20.3.02 of 2See more

concourse concourse 20.3.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
concourse/concourse:8.3.040a143ce5873
golang.org/x/net@v0.50.0
stdlib@go1.26.5
0.55.0
1.25.13
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13

Open the chart page →

2,060
dynatrace-operatordynatraceVerified publisher1.10.21 of 1See more

dynatrace-operator dynatrace 1.10.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.10.252281db48c93
stdlib@go1.26.5
1.25.13

Open the chart page →

172
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.55.0
1.25.13

Open the chart page →

4,177
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.55.0
1.25.13

Open the chart page →

2,010
oncallgrafana1.16.57 of 12See more

oncall grafana 1.16.5

7 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.55.0
1.25.13

Open the chart page →

16,290
k8sgpt-operatork8sgptOfficialVerified publisher0.2.292 of 2See more

k8sgpt-operator k8sgpt 0.2.29

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.2982d0adcce816
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.55.0
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

980
node-feature-discoverynode-feature-discoveryOfficialVerified publisher0.19.01 of 1See more

node-feature-discovery node-feature-discovery 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
stdlib@go1.26.3
1.25.13

Open the chart page →

213

Container images carrying it

5,266 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.55.0
1.25.13
1
linode/linode-blockstorage-csi-driver:v1.1.409f3282bf53d
stdlib@go1.26.5
1.25.13
1
linode/linode-cloud-controller-manager:v0.9.8cd8c17512206
stdlib@go1.26.4
1.25.13
1
linuxserver/calibre-web:0.6.24241009026e6f
stdlib@go1.17.8
1.25.13
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
stdlib@go1.16.7
1.25.13
1
linuxserver/cloud9:latest45c5fe102ff3
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.11
0.55.0
1.25.13
1
linuxserver/plex:1.43.41f6f97d76e7b
stdlib@go1.26.5
1.25.13
1
linuxserver/smokeping:2.9.02f4488c9afcd
golang.org/x/net@v0.6.0
stdlib@go1.24.12
0.55.0
1.25.13
1
linuxserver/smokeping:2.8.2b7f906899cd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.22.5
0.55.0
1.25.13
1
linuxserver/unifi-network-application:10.6.101-ls145ccadcad5c640
stdlib@go1.26.5
1.25.13
1
linuxserver/wireguard:latestbf03578ef731
golang.org/x/net@v0.47.0
stdlib@go1.26.3
0.55.0
1.25.13
1
linuxserver/wireguard:1.0.20260223-r0-ls122dca67384e3e9
golang.org/x/net@v0.47.0
0.55.0
1
lishimeng/hufu:v1.2.13d5752dac834
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.55.0
1.25.13
1
lishimeng/owl-console:v0.11.2c79a67657baf
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13
1
lishimeng/owl-messager:v0.11.23d00485e64dc
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13
1
lishimeng/passport:v0.2.163e7d05ded625
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.55.0
1.25.13
1
lishimeng/passport-profile:v0.2.160970dfe5dc8f
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.55.0
1.25.13
1
lishimeng/tabby:v1.0.48145c3dc83c8
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.55.0
1.25.13
1
lishimeng/tree:v0.2.89b2f8be6c7d3
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.55.0
1.25.13
1
lishimeng/zoo:v0.4.0e0b8d2d8ca28
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.55.0
1.25.13
1
listmonk/listmonk:v6.0.0bf3903d54a46
golang.org/x/net@v0.47.0
stdlib@go1.24.1
0.55.0
1.25.13
1
litestream/litestream:0.3c5a1e1b01916
golang.org/x/net@v0.14.0
stdlib@go1.21.3
0.55.0
1.25.13
1
livekit/ingress:v1.2.21ab01641b366
golang.org/x/net@v0.18.0
stdlib@go1.20.7
0.55.0
1.25.13
1
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/net@v0.0.0-20211004195052-b30845b58a23
stdlib@go1.16.2
0.55.0
1.25.13
1
livekit/livekit-server:v1.9.03602a85840d5
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
1
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.10
0.55.0
1.25.13
1
lmierzwa/karma:v0.503751e5eed656
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.55.0
1.25.13
1
lmierzwa/karma:v0.70d417abe7ddb5
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.55.0
1.25.13
1
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.10
0.55.0
1.25.13
1
loeken/home-assistant:2026.5.14ce6abc553b3
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.55.0
1.25.13
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.6
0.55.0
1.25.13
1
loftsh/jspolicy:0.2.225deb9bd2683
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.55.0
1.25.13
1
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.55.0
1.25.13
1
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.55.0
1.25.13
1
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.18.9
0.55.0
1.25.13
1
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.7
0.55.0
1.25.13
1
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.55.0
1.25.13
1
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.55.0
1.25.13
1
lokxy/lokxy:v0.9.0e4ac800dc55d
stdlib@go1.26.4
1.25.13
1
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.55.0
1.25.13
1
longhornio/longhorn-manager:v1.2.3dca34321452c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.1
0.55.0
1.25.13
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.1
0.55.0
1.25.13
1
longhornio/longhorn-manager:v1.12.0fd245bae2e82
golang.org/x/net@v0.53.0
stdlib@go1.25.10
0.55.0
1.25.13
1
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
1
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.55.0
1.25.13
1
longhornio/longhorn-ui:v1.12.03870d52a2b0a
stdlib@go1.25.10
1.25.13
1
longhornio/longhorn-ui:v1.10.0e60f36161511
stdlib@go1.24.6
1.25.13
1
longhornio/upgrade-responder:v0.2.05875cef29348
stdlib@go1.17.13
1.25.13
1
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.25.13
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.