StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,528
of 17,803 indexed, latest versions
Container images
5,282
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,528 of 17,803 indexed charts deploy, on 5,282 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+190 more1.25.135,243
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,683
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,528 by stars
ChartLatestAffected imagesRadar Score
service-gatewayappscodeVerified publisher2026.9.113 of 3See more

service-gateway appscode 2026.9.11

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13
ghcr.io/voyagermesh/echoserver:v20221109fa56a9251de6
stdlib@go1.19
1.25.13
ghcr.io/voyagermesh/gateway:v1.8.24237fd16a3cb
stdlib@go1.26.4
1.25.13

Open the chart page →

2,197
service-presetsappscodeVerified publisher2024.2.111 of 1See more

service-presets appscode 2024.2.11

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.25.13

Open the chart page →

824
service-providerappscodeVerified publisher2026.9.112 of 2See more

service-provider appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.55.0
1.25.13
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

2,252
sidekickappscodeVerified publisher2026.7.101 of 1See more

sidekick appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/sidekick:v0.0.16d8d2a3c22ee7
stdlib@go1.25.12
1.25.13

Open the chart page →

286
stash-communityappscodeVerified publisher0.42.04 of 4See more

stash-community appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.55.0
1.25.13
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
stdlib@go1.24.9
0.55.0
1.25.13
ghcr.io/stashed/stash:v0.42.03a98245a7667
golang.org/x/net@v0.26.0
stdlib@go1.25.3
0.55.0
1.25.13
ghcr.io/stashed/stash-crd-installer:v0.42.076f0a650e44b
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

3,677
stash-opscenterappscodeVerified publisher2025.10.171 of 1See more

stash-opscenter appscode 2025.10.17

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

686
stash-ui-serverappscodeVerified publisher0.23.01 of 1See more

stash-ui-server appscode 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

686
statefulsetappscodeVerified publisher0.0.12 of 3See more

statefulset appscode 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.55.0
1.25.13
ghcr.io/appscode/kubectl-nonroot:v1.248ee5bdd68977
stdlib@go1.20.7
1.25.13

Open the chart page →

2,739
storage-metrics-serverappscodeVerified publisher2026.7.81 of 1See more

storage-metrics-server appscode 2026.7.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/storage-metrics-server:v0.1.09cb4acb742a9
golang.org/x/net@v0.48.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

560
supervisorappscodeVerified publisher2026.2.161 of 1See more

supervisor appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/supervisor:v0.0.1223affde10a92
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

237
taskqueueappscodeVerified publisher2026.2.161 of 1See more

taskqueue appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

1,091
tenant-operatorappscodeVerified publisher2026.7.151 of 1See more

tenant-operator appscode 2026.7.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/tenant-operator:v0.0.2787f6de2b620
golang.org/x/net@v0.53.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

183
thanos-operatorappscodeVerified publisher2026.6.21 of 1See more

thanos-operator appscode 2026.6.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/thanos-operator:v2026.4.24e05a3e701291
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

385
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

1,227
vcd-lb-gcappscodeVerified publisher2026.6.251 of 1See more

vcd-lb-gc appscode 2026.6.25

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/net@v0.23.0
stdlib@go1.25.11
0.55.0
1.25.13

Open the chart page →

178
voyagerappscodeVerified publisher2026.3.231 of 1See more

voyager appscode 2026.3.23

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/voyager:v17.5.04964ceaf9d35
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

728
voyager-gatewayappscodeVerified publisher2026.7.212 of 2See more

voyager-gateway appscode 2026.7.21

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13
ghcr.io/voyagermesh/gateway:v1.8.24237fd16a3cb
stdlib@go1.26.4
1.25.13

Open the chart page →

1,373
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
golang.org/x/net@v0.11.0
stdlib@go1.21.1
0.55.0
1.25.13

Open the chart page →

5,704
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/net@v0.19.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

1,205
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.26.5
1.25.13

Open the chart page →

8,931
appwriteappwrite-helmVerified publisher1.3.24 of 8See more

appwrite appwrite-helm 1.3.2

4 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/net@v0.40.0
stdlib@go1.25.7
0.55.0
1.25.13
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.25.13
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.25.13
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.25.13

Open the chart page →

9,855
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

5,212
arcadearcadeVerified publisher1.10.11 of 10See more

arcade arcade 1.10.1

1 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.13

Open the chart page →

991
argocd-ecr-updaterargocd-aws-ecr-updater0.3.391 of 1See more

argocd-ecr-updater argocd-aws-ecr-updater 0.3.39

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/karlderkaefer/argocd-ecr-updater:1.4.6ed5d4b74792c
stdlib@go1.26.5
1.25.13

Open the chart page →

86
argocd-bitbucket-proxyargocd-bitbucket-proxy1.1.11 of 1See more

argocd-bitbucket-proxy argocd-bitbucket-proxy 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/salemgolemugoo/argocd-bitbucket-proxy:latesta72df069095b
stdlib@go1.26.1
1.25.13

Open the chart page →

189
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.55.0
1.25.13
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.13
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/net@v0.34.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

7,697
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

1,845
argonix-apiargonix0.2.92 of 4See more

argonix-api argonix 0.2.9

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0aa679ddf5c3a
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.55.0
1.25.13
ghcr.io/argonix-io/argonix-api-frontend:1.0.0a584153dfae5
stdlib@go1.23.12
1.25.13

Open the chart page →

4,999
argo-zombiesargo-zombies0.1.521 of 1See more

argo-zombies argo-zombies 0.1.52

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.55.0
1.25.13

Open the chart page →

254
otel-collectorarieotechVerified publisher0.1.01 of 1See more

otel-collector arieotech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.154.0b3079f45e19b
stdlib@go1.26.4
1.25.13

Open the chart page →

384
arlas-aiasarlas-stackVerified publisher28.8.06 of 22See more

arlas-aias arlas-stack 28.8.0

6 of the 22 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.55.0
1.25.13
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.25.13
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.55.0
1.25.13
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
golang.org/x/net@v0.33.0
stdlib@go1.23.8
0.55.0
1.25.13
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.25.13

Open the chart page →

41,099
arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.55.0
1.25.13
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.55.0
1.25.13
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
stdlib@go1.19.5
1.25.13
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.55.0
1.25.13

Open the chart page →

23,461
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.55.0
1.25.13

Open the chart page →

1,780
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.11
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.10
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

8,630
assemblylineassemblylineVerified publisher7.4.202 of 12See more

assemblyline assemblyline 7.4.20

2 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

12,862
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.25.13

Open the chart page →

5,538
dltkvassist-iot-data-integrity-verification0.2.05 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.55.0
1.25.13
hyperledger/fabric-ca:latesta70b6ba64a08
stdlib@go1.26.4
1.25.13
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

185,703
dltflassist-iot-dlt-based-fl0.2.05 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.55.0
1.25.13
hyperledger/fabric-ca:latesta70b6ba64a08
stdlib@go1.26.4
1.25.13
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

185,703
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

3,789
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.25.13

Open the chart page →

9,428
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

4,371
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.25.13

Open the chart page →

13,413
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.25.13

Open the chart page →

10,179
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.55.0
1.25.13
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18
0.55.0
1.25.13

Open the chart page →

83,638
performanceandusagediagnosisassist-iot-pud1.0.05 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

5 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.17.12
0.55.0
1.25.13
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.13
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.55.0
1.25.13

Open the chart page →

8,589
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

8,072
semantic-repositoryassist-iot-semantic-repository1.1.01 of 3See more

semantic-repository assist-iot-semantic-repository 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

1,201
smartorchestratorassist-iot-smart-orchestrator4.0.04 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

4 of the 14 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.22.1
1.25.13
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.55.0
1.25.13
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.13
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

45,972
astrotrekastria0.0.24 of 4See more

astrotrek astria 0.0.2

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.25.13
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.25.13

Open the chart page →

32,715
celestia-localastria9.0.02 of 2See more

celestia-local astria 9.0.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.55.0
1.25.13
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/net@v0.43.0
stdlib@go1.24.7
0.55.0
1.25.13

Open the chart page →

3,309

Container images carrying it

5,282 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.55.0
1.25.13
1
mavrick1/kubestellar-b:latest45ca0429a1d4
golang.org/x/net@v0.26.0
stdlib@go1.20.3
0.55.0
1.25.13
1
maxrocketinternet/k8s-event-logger:2.70234bdec4626
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13
1
maxrocketinternet/k8s-event-logger:2.111224534789d
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13
1
mbround18/valheim:3.1.070bd4da591cd
stdlib@go1.18.1
1.25.13
1
mccutchen/go-httpbin:latest20739736d4eb
stdlib@go1.26.5
1.25.13
1
mccutchen/go-httpbin:v2.15.024528cf5229d
stdlib@go1.23.1
1.25.13
1
mccutchen/go-httpbin:v2.2.25994403ef75b
stdlib@go1.16.2
1.25.13
1
megaease/easegress:latestfad1c7452958
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.55.0
1.25.13
1
meshery/meshery-operator:1.0.50d245bc8b5c6
stdlib@go1.26.4
1.25.13
1
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
golang.org/x/net@v0.11.0
stdlib@go1.20.4
0.55.0
1.25.13
1
mesosphere/dex-controller:v0.16.11b2dd9c0b0fc
golang.org/x/net@v0.25.0
stdlib@go1.22.7
0.55.0
1.25.13
1
mesosphere/dex-k8s-authenticator:v1.4.1-d2iqf3d9982cc2fd
golang.org/x/net@v0.13.0
stdlib@go1.23.0
0.55.0
1.25.13
1
mesosphere/karma:v0.55-d2iq-proxy4693bb4e0814
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.7
0.55.0
1.25.13
1
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.14.5
0.55.0
1.25.13
1
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.14.5
0.55.0
1.25.13
1
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.14.5
0.55.0
1.25.13
1
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.14.5
0.55.0
1.25.13
1
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.14.5
0.55.0
1.25.13
1
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.14.5
0.55.0
1.25.13
1
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.11
0.55.0
1.25.13
1
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.13.7
0.55.0
1.25.13
1
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.13.8
0.55.0
1.25.13
1
mesosphere/kubefed:proxyurl4fd8889195fe
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.55.0
1.25.13
1
mesosphere/traefik-forward-auth:3.1.05456581d7b76
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.15
0.55.0
1.25.13
1
metacontrollerio/metacontroller:v2.1.10336993b88e4
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.6
0.55.0
1.25.13
1
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.55.0
1.25.13
1
metacubex/mihomo:v1.19.29e1d7dadaa936
golang.org/x/net@v0.35.0
stdlib@go1.26.5
0.55.0
1.25.13
1
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
golang.org/x/net@v0.0.0-20181213202711-891ebc4b82d6
stdlib@go1.13.15
0.55.0
1.25.13
1
metalmatze/transmission-exporter:0.3.090d6acb6d47d
stdlib@go1.13
1.25.13
1
middlewareeng/middleware:0.3.1747d880812f1
stdlib@go1.17.13
1.25.13
1
mikefarah/yq:4.45.12c100efaca06
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
mikefarah/yq:2.4.16fc625c402de
stdlib@go1.13.3
1.25.13
1
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
golang.org/x/net@v0.30.0
stdlib@go1.23.4
0.55.0
1.25.13
1
mikejoh/imagine:0.1.078737d7345f9
golang.org/x/net@v0.26.0
stdlib@go1.23.3
0.55.0
1.25.13
1
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.2
0.55.0
1.25.13
1
milvusdb/etcd:3.5.25-r1fededb2f2d63
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.55.0
1.25.13
1
milvusdb/milvus:v2.2.13a3a55e1c1497
golang.org/x/net@v0.10.0
stdlib@go1.18.3
0.55.0
1.25.13
1
milvusdb/milvus-config-tool:v0.1.12212dfb61401
golang.org/x/net@v0.0.0-20220706163947-c90051bbdb60
stdlib@go1.16.15
0.55.0
1.25.13
1
mindsdb/mindsdb:latest163011c09299
stdlib@go1.20.13
1.25.13
1
miniflux/miniflux:2.3.349d7b6098761
stdlib@go1.26.5
1.25.13
1
miniflux/miniflux:2.2.18a3ca6bbc1f74
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.55.0
1.25.13
1
miniflux/miniflux:2.0.36e2fb990dae74
golang.org/x/net@v0.0.0-20210916014120-12bc252f5db8
stdlib@go1.17.8
0.55.0
1.25.13
1
minio/kes:v0.22.255f3aef5803e
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
stdlib@go1.19.3
0.55.0
1.25.13
1
minio/kes:2023-04-03T16-41-28Zf93c2d9088df
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.55.0
1.25.13
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.55.0
1.25.13
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.55.0
1.25.13
1
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.8
0.55.0
1.25.13
1
minio/mc:RELEASE.2024-01-16T16-06-34Z591b097ea2d4
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.55.0
1.25.13
1
minio/mc:RELEASE.2025-04-16T18-13-26Zaead63c77f9d
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.