StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,556
of 17,790 indexed, latest versions
Container images
5,324
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,556 of 17,790 indexed charts deploy, on 5,324 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,288
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,695
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,556 by stars
ChartLatestAffected imagesRadar Score
akto-aws-api-gateway-connectorakto0.1.11 of 1See more

akto-aws-api-gateway-connector akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-multi-logging1a1bc76d50fe
stdlib@go1.23.3
1.25.13

Open the chart page →

413
akto-central-setupakto1.1.103 of 5See more

akto-central-setup akto 1.1.10

3 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
stdlib@go1.26.5
1.25.13
library/eclipse-temurin:211f79c73404fb
stdlib@go1.26.5
1.25.13
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
stdlib@go1.26.4
1.25.13

Open the chart page →

5,118
akto-hybrid-redactakto1.44.63 of 5See more

akto-hybrid-redact akto 1.44.6

3 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
stdlib@go1.26.5
1.25.13
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
stdlib@go1.25.4
1.25.13

Open the chart page →

4,098
akto-k8s-agentakto0.1.21 of 1See more

akto-k8s-agent akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_agentc1313b1ff2ed
stdlib@go1.25.12
1.25.13

Open the chart page →

269
akto-k8s-ebpfakto0.1.31 of 1See more

akto-k8s-ebpf akto 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_ebpffcf8be10bead
golang.org/x/net@v0.38.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

838
akto-k8s-ebpf-openshiftakto0.1.11 of 1See more

akto-k8s-ebpf-openshift akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.55.0
1.25.13

Open the chart page →

1,277
akto-mini-runtimeakto0.7.222 of 3See more

akto-mini-runtime akto 0.7.22

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
stdlib@go1.26.5
1.25.13
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.25.13

Open the chart page →

2,826
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
stdlib@go1.25.4
1.25.13

Open the chart page →

3,258
akto-mini-testingakto1.45.73 of 5See more

akto-mini-testing akto 1.45.7

3 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
stdlib@go1.26.5
1.25.13
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.25.13
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13

Open the chart page →

6,580
akto-mini-testing-kafkaakto1.42.11 of 5See more

akto-mini-testing-kafka akto 1.42.1

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13

Open the chart page →

6,404
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
stdlib@go1.24.6
1.25.13

Open the chart page →

1,852
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13

Open the chart page →

11,296
akto-regional-setupakto1.3.13 of 9See more

akto-regional-setup akto 1.3.1

3 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
stdlib@go1.26.5
1.25.13
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
stdlib@go1.26.5
1.25.13
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
stdlib@go1.26.4
1.25.13

Open the chart page →

7,828
akto-runtimeakto0.1.82 of 2See more

akto-runtime akto 0.1.8

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
stdlib@go1.26.5
1.25.13
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.25.13

Open the chart page →

1,474
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
stdlib@go1.22.5
1.25.13

Open the chart page →

4,886
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13

Open the chart page →

4,866
akto-threat-backendakto0.1.52 of 2See more

akto-threat-backend akto 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
stdlib@go1.26.5
1.25.13
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.25.13

Open the chart page →

1,553
akto-threat-clientakto0.2.02 of 2See more

akto-threat-client akto 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
stdlib@go1.26.5
1.25.13
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.25.13

Open the chart page →

1,585
api-gateway-loggingakto0.1.21 of 1See more

api-gateway-logging akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-openapi12ed2544756f
stdlib@go1.23.3
1.25.13

Open the chart page →

413
gitlab-runner-operatoralekcVerified publisher2.5.01 of 2See more

gitlab-runner-operator alekc 2.5.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.37.05ed410ebac5d
stdlib@go1.26.5
1.25.13

Open the chart page →

69
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.55.0
1.25.13

Open the chart page →

2,228
plexalekcVerified publisher2.10.11 of 1See more

plex alekc 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
linuxserver/plex:1.43.41f6f97d76e7b
stdlib@go1.26.5
1.25.13

Open the chart page →

647
rabbitmq-cluster-operatoralekcVerified publisher2.9.01 of 1See more

rabbitmq-cluster-operator alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

257
smokeping-exporteralekcVerified publisher0.3.01 of 1See more

smokeping-exporter alekc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/superq/smokeping-prober:v0.12.02524b895bdae
stdlib@go1.26.4
1.25.13

Open the chart page →

298
valkey-operatoralekcVerified publisher0.4.01 of 1See more

valkey-operator alekc 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/hyperspike/valkey-operator:v0.0.617d8c669f11a4
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.55.0
1.25.13

Open the chart page →

333
vault-operatoralekcVerified publisher1.26.11 of 1See more

vault-operator alekc 1.26.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-operator:v1.24.06f622c5fb8a9
stdlib@go1.26.3
1.25.13

Open the chart page →

542
mautrix-signalalexanderbadel0.1.11 of 2See more

mautrix-signal alexanderbadel 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.25.13

Open the chart page →

2,099
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/net@v0.17.0
stdlib@go1.20.2
0.55.0
1.25.13

Open the chart page →

889
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

1,624
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.25.13

Open the chart page →

1,732
wireguardalexpressoVerified publisher0.1.31 of 2See more

wireguard alexpresso 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
linuxserver/wireguard:latestbf03578ef731
golang.org/x/net@v0.47.0
stdlib@go1.26.3
0.55.0
1.25.13

Open the chart page →

786
gotifyalexvanderberkelVerified publisher0.7.01 of 1See more

gotify alexvanderberkel 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gotify/server:3.1.0be44495e4609
stdlib@go1.26.0
1.25.13

Open the chart page →

320
alluredeckalluredeckVerified publisher0.24.01 of 2See more

alluredeck alluredeck 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
stdlib@go1.26.4
1.25.13

Open the chart page →

1,280
book-serveral-masood-helm-charts0.1.01 of 1See more

book-server al-masood-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
almasood/book-server:latest6ffac9b63cdf
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

486
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.15
0.55.0
1.25.13

Open the chart page →

2,115
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

564
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

564
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

1,006
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
golang.org/x/net@v0.34.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

541
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.55.0
1.25.13
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

4,533
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

582
versitygwalpineworks0.1.21 of 1See more

versitygw alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
versity/versitygw:v1.0.145192635d0353
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

1,115
versitygw-webhook-pulsar-proxyalpineworks0.1.11 of 1See more

versitygw-webhook-pulsar-proxy alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

900
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,242
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.55.0
1.25.13
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
stdlib@go1.19.13
0.55.0
1.25.13
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.55.0
1.25.13
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.55.0
1.25.13
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.55.0
1.25.13
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.55.0
1.25.13
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

28,289
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.55.0
1.25.13

Open the chart page →

1,599
anchore-admission-controlleranchore-charts0.8.51 of 2See more

anchore-admission-controller anchore-charts 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.55.0
1.25.13

Open the chart page →

7,605
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.55.0
1.25.13

Open the chart page →

1,326
cert-manager-webhook-inwxandibraeuVerified publisher0.9.01 of 1See more

cert-manager-webhook-inwx andibraeu 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

599
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

5,865

Container images carrying it

5,324 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
envoyproxy/gateway:v1.7.5156b7d32c73b
stdlib@go1.26.5
1.25.13
3
ethpandaops/tracoor:latestd8514b9f4c59
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.55.0
1.25.13
3
goharbor/harbor-core:v2.15.2d7b780d23721
stdlib@go1.26.4
1.25.13
3
goharbor/harbor-jobservice:v2.15.2f71a4452a095
stdlib@go1.26.4
1.25.13
3
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.55.0
1.25.13
3
goharbor/registry-photon:v2.15.2c4ebef61ceb5
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.55.0
1.25.13
3
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
stdlib@go1.26.4
1.25.13
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.55.0
1.25.13
3
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.55.0
1.25.13
3
grafana/grafana:13.2.1-distroless3600073f45a9
golang.org/x/net@v0.51.0
stdlib@go1.26.4
0.55.0
1.25.13
3
grafana/grafana:13.1.17cb8c64c4d57
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.55.0
1.25.13
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.55.0
1.25.13
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13
3
grafana/loki:3.7.7:latestd70e4659623f
stdlib@go1.26.5
1.25.13
3
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.17.2
0.55.0
1.25.13
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.55.0
1.25.13
3
hashicorp/http-echo:1.0.0:latestfcb75f691c8b
stdlib@go1.21.1
1.25.13
3
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.13
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13
3
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/net@v0.19.0
stdlib@go1.24.10
0.55.0
1.25.13
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.55.0
1.25.13
3
library/ghost:6.63.0e05bc1169fb2
stdlib@go1.24.6
1.25.13
3
library/mariadb:12.3.3ab1c3dd38194
stdlib@go1.24.6
1.25.13
3
library/mongo:8.3.981a1c8842a09
stdlib@go1.26.5
1.25.13
3
library/mysql:latest66aec17cd21a
stdlib@go1.24.6
1.25.13
3
library/nats:2.10-alpineb83efabe3e7d
stdlib@go1.24.2
1.25.13
3
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.25.13
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.25.13
3
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.13
3
library/postgres:14-alpine727876d27466
stdlib@go1.24.6
1.25.13
3
library/rabbitmq:4.3.5-management:4-management:managementffd1b50c522a
stdlib@go1.22.2
1.25.13
3
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.13
3
louislam/uptime-kuma:2.5.4917318f9d7be
stdlib@go1.20.5
1.25.13
3
mcp/grafana:latest9362bcf6aa0e
stdlib@go1.26.5
1.25.13
3
migrate/migrate:latestcc4ad8e19d66
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.55.0
1.25.13
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.55.0
1.25.13
3
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.55.0
1.25.13
3
natsio/nats-box:0.19.7ffce8bd10338
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.25.13
3
neosmemo/memos:0.30.071a5b4738d1b
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
3
opencsghq/stakater-reloader:v1.4.190491782f7bac
stdlib@go1.26.4
1.25.13
3
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.55.0
1.25.13
3
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
3
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.55.0
1.25.13
3
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.55.0
1.25.13
3
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.25.13
3
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.13
3

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.