StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,556
of 17,790 indexed, latest versions
Container images
5,324
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,556 of 17,790 indexed charts deploy, on 5,324 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,288
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,695
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,556 by stars
ChartLatestAffected imagesRadar Score
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.11
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.10
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

8,621
assemblylineassemblylineVerified publisher7.4.192 of 12See more

assemblyline assemblyline 7.4.19

2 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

12,666
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.25.13

Open the chart page →

5,537
dltkvassist-iot-data-integrity-verification0.2.05 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.55.0
1.25.13
hyperledger/fabric-ca:latesta70b6ba64a08
stdlib@go1.26.4
1.25.13
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

77,883
dltflassist-iot-dlt-based-fl0.2.05 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.55.0
1.25.13
hyperledger/fabric-ca:latesta70b6ba64a08
stdlib@go1.26.4
1.25.13
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

77,883
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

3,786
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.25.13

Open the chart page →

9,411
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

4,367
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.25.13

Open the chart page →

13,369
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.25.13

Open the chart page →

10,127
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.55.0
1.25.13
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18
0.55.0
1.25.13

Open the chart page →

18,357
performanceandusagediagnosisassist-iot-pud1.0.05 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

5 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.17.12
0.55.0
1.25.13
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.13
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.55.0
1.25.13

Open the chart page →

8,570
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

8,052
semantic-repositoryassist-iot-semantic-repository1.1.01 of 3See more

semantic-repository assist-iot-semantic-repository 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

1,084
smartorchestratorassist-iot-smart-orchestrator4.0.04 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

4 of the 14 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.22.1
1.25.13
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.55.0
1.25.13
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.13
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

45,656
astrotrekastria0.0.24 of 4See more

astrotrek astria 0.0.2

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.25.13
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.25.13

Open the chart page →

32,638
celestia-localastria9.0.02 of 2See more

celestia-local astria 9.0.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.55.0
1.25.13
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/net@v0.43.0
stdlib@go1.24.7
0.55.0
1.25.13

Open the chart page →

3,299
celestia-nodeastria0.7.11 of 1See more

celestia-node astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/net@v0.43.0
stdlib@go1.24.7
0.55.0
1.25.13

Open the chart page →

1,513
evm-faucetastria0.1.51 of 1See more

evm-faucet astria 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.25.13

Open the chart page →

1,764
evm-rollupastria4.1.01 of 2See more

evm-rollup astria 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

4,010
evm-stackastria5.0.31 of 2See more

evm-stack astria 5.0.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

4,010
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

3,710
graph-nodeastria0.2.23 of 3See more

graph-node astria 0.2.2

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
graphprotocol/graph-node:latestb0436347fb24
stdlib@go1.26.5
1.25.13
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/net@v0.1.0
stdlib@go1.19.1
0.55.0
1.25.13
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

5,547
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.55.0
1.25.13
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

6,335
sequencer-faucetastria0.9.21 of 1See more

sequencer-faucet astria 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
golang.org/x/net@v0.28.0
stdlib@go1.22.6
0.55.0
1.25.13

Open the chart page →

1,320
phonebook-chartasumankamberoglu0.1.51 of 3See more

phonebook-chart asumankamberoglu 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

3,176
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

9,429
hcloud-csi-driveratem181.5.12 of 6See more

hcloud-csi-driver atem18 1.5.1

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.3
0.55.0
1.25.13
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.55.0
1.25.13

Open the chart page →

6,509
bamboo-agentatlassian-data-centerVerified publisher2.0.151 of 1See more

bamboo-agent atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
stdlib@go1.22.2
1.25.13

Open the chart page →

1,657
alertmanager-discordatrox3.1.01 of 1See more

alertmanager-discord atrox 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/atrox/alertmanager-discord:v1.0.0ac011a4b6df1
stdlib@go1.20.5
1.25.13

Open the chart page →

587
attestkeepattestkeepVerified publisher1.1.02 of 2See more

attestkeep attestkeep 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16.4-alpine5660c2cbfea5
stdlib@go1.18.2
1.25.13
ghcr.io/attestkeep/attestkeep-k8s:1.1.040f46bb38d0f
stdlib@go1.26.4
1.25.13

Open the chart page →

1,598
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,570
okd-webhookav1o-chartsVerified publisher0.1.01 of 1See more

okd-webhook av1o-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16
0.55.0
1.25.13

Open the chart page →

1,727
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.55.0
1.25.13

Open the chart page →

5,082
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.55.0
1.25.13

Open the chart page →

6,958
kubeslice-workeraveshaVerified publisher1.5.02 of 14See more

kubeslice-worker avesha 1.5.0

2 of the 14 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.1f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13

Open the chart page →

1,644
amazon-ec2-metadata-mockaws1.11.21 of 1See more

amazon-ec2-metadata-mock aws 1.11.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/amazon-ec2-metadata-mock:v1.11.2dd02d3569da0
stdlib@go1.17.13
1.25.13

Open the chart page →

860
appmesh-jaegeraws1.0.31 of 1See more

appmesh-jaeger aws 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.17.3
0.55.0
1.25.13

Open the chart page →

2,487
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.55.0
1.25.13

Open the chart page →

2,946
aws-node-termination-handler-2aws0.2.02 of 2See more

aws-node-termination-handler-2 aws 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.3
0.55.0
1.25.13
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.3
0.55.0
1.25.13

Open the chart page →

2,966
aws-sigv4-proxy-admission-controlleraws0.1.21 of 1See more

aws-sigv4-proxy-admission-controller aws 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.55.0
1.25.13

Open the chart page →

2,140
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
stdlib@go1.21.2
1.25.13

Open the chart page →

9,728
axonops-developer-operatoraxonops-developer-operator0.1.01 of 1See more

axonops-developer-operator axonops-developer-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/axonops/axonops-developer-operator:v0.1.0b3d6600c8ba5
golang.org/x/net@v0.25.0
stdlib@go1.22.10
0.55.0
1.25.13

Open the chart page →

750
axonops-operatoraxonops-operator0.1.01 of 1See more

axonops-operator axonops-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/axonops/axonops-operator:0.1.0e0cdb993f0b1
golang.org/x/net@v0.51.0
stdlib@go1.25.9
0.55.0
1.25.13

Open the chart page →

302
azure-advanced-backupazure-advanced-backup0.4.11 of 1See more

azure-advanced-backup azure-advanced-backup 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.55.0
1.25.13

Open the chart page →

4,575
azurefile-csi-driverazurefile-csi-driverVerified publisher1.35.71 of 7See more

azurefile-csi-driver azurefile-csi-driver 1.35.7

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.76e43ba0bd009
stdlib@go1.25.11
1.25.13

Open the chart page →

1,151
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.55.0
1.25.13

Open the chart page →

5,528
helm-controllerazureorkestra0.1.12 of 2See more

helm-controller azureorkestra 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.55.0
1.25.13
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.55.0
1.25.13

Open the chart page →

7,723
keptn-addonsazureorkestra0.1.04 of 4See more

keptn-addons azureorkestra 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.55.0
1.25.13
keptn/distributor:0.8.472e17527a4f9
stdlib@go1.16.2
1.25.13
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.13.7
0.55.0
1.25.13
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.2
0.55.0
1.25.13

Open the chart page →

10,629
prometheusazureorkestra14.8.05 of 6See more

prometheus azureorkestra 14.8.0

5 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.13
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.13
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.55.0
1.25.13

Open the chart page →

9,669

Container images carrying it

5,324 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
envoyproxy/gateway:v1.7.5156b7d32c73b
stdlib@go1.26.5
1.25.13
3
ethpandaops/tracoor:latestd8514b9f4c59
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.55.0
1.25.13
3
goharbor/harbor-core:v2.15.2d7b780d23721
stdlib@go1.26.4
1.25.13
3
goharbor/harbor-jobservice:v2.15.2f71a4452a095
stdlib@go1.26.4
1.25.13
3
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.55.0
1.25.13
3
goharbor/registry-photon:v2.15.2c4ebef61ceb5
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.55.0
1.25.13
3
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
stdlib@go1.26.4
1.25.13
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.55.0
1.25.13
3
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.55.0
1.25.13
3
grafana/grafana:13.2.1-distroless3600073f45a9
golang.org/x/net@v0.51.0
stdlib@go1.26.4
0.55.0
1.25.13
3
grafana/grafana:13.1.17cb8c64c4d57
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.55.0
1.25.13
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.55.0
1.25.13
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13
3
grafana/loki:3.7.7:latestd70e4659623f
stdlib@go1.26.5
1.25.13
3
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.17.2
0.55.0
1.25.13
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.55.0
1.25.13
3
hashicorp/http-echo:1.0.0:latestfcb75f691c8b
stdlib@go1.21.1
1.25.13
3
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.13
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13
3
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/net@v0.19.0
stdlib@go1.24.10
0.55.0
1.25.13
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.55.0
1.25.13
3
library/ghost:6.63.0e05bc1169fb2
stdlib@go1.24.6
1.25.13
3
library/mariadb:12.3.3ab1c3dd38194
stdlib@go1.24.6
1.25.13
3
library/mongo:8.3.981a1c8842a09
stdlib@go1.26.5
1.25.13
3
library/mysql:latest66aec17cd21a
stdlib@go1.24.6
1.25.13
3
library/nats:2.10-alpineb83efabe3e7d
stdlib@go1.24.2
1.25.13
3
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.25.13
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.25.13
3
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.13
3
library/postgres:14-alpine727876d27466
stdlib@go1.24.6
1.25.13
3
library/rabbitmq:4.3.5-management:4-management:managementffd1b50c522a
stdlib@go1.22.2
1.25.13
3
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.13
3
louislam/uptime-kuma:2.5.4917318f9d7be
stdlib@go1.20.5
1.25.13
3
mcp/grafana:latest9362bcf6aa0e
stdlib@go1.26.5
1.25.13
3
migrate/migrate:latestcc4ad8e19d66
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.55.0
1.25.13
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.55.0
1.25.13
3
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.55.0
1.25.13
3
natsio/nats-box:0.19.7ffce8bd10338
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.25.13
3
neosmemo/memos:0.30.071a5b4738d1b
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
3
opencsghq/stakater-reloader:v1.4.190491782f7bac
stdlib@go1.26.4
1.25.13
3
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.55.0
1.25.13
3
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
3
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.55.0
1.25.13
3
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.55.0
1.25.13
3
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.25.13
3
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.13
3

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.