StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,528
of 17,803 indexed, latest versions
Container images
5,282
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,528 of 17,803 indexed charts deploy, on 5,282 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+190 more1.25.135,243
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,683
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,528 by stars
ChartLatestAffected imagesRadar Score
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.05 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

5 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs-webhook:latestc1f19557bdcb
stdlib@go1.26.0
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.55.0
1.25.13

Open the chart page →

54,520
prometheus-pingmesh-exporterkubservice-chartsVerified publisher1.1.11 of 1See more

prometheus-pingmesh-exporter kubservice-charts 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:latest355fa4be8e97
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.55.0
1.25.13

Open the chart page →

855
karporkusionstackVerified publisher0.7.62 of 3See more

karpor kusionstack 0.7.6

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/net@v0.19.0
stdlib@go1.22.12
0.55.0
1.25.13
quay.io/coreos/etcd:v3.5.11842975891182
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.55.0
1.25.13

Open the chart page →

3,326
kwokkwokOfficialVerified publisher0.3.01 of 1See more

kwok kwok 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

716
litellm-operatorlitellm-operatorVerified publisher1.1.21 of 1See more

litellm-operator litellm-operator 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/bbdsoftware/litellm-operator:1.1.2167a51113d90
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

284
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.55.0
1.25.13

Open the chart page →

3,693
vcluster-k8sloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-k8s loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.55.0
1.25.13
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.55.0
1.25.13
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.55.0
1.25.13

Open the chart page →

5,610
vcluster-platformloftVerified publisher4.12.01 of 1See more

vcluster-platform loft 4.12.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-platform:4.12.0ef92da4621e6
golang.org/x/net@v0.52.0
stdlib@go1.26.4
0.55.0
1.25.13

Open the chart page →

794
lxcfs-on-kuberneteslxcfs-on-kubernetes0.2.71 of 2See more

lxcfs-on-kubernetes lxcfs-on-kubernetes 0.2.7

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cndoit18/lxcfs-agent:latest9853bb613cd0
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.55.0
1.25.13

Open the chart page →

2,103
mariadbmariadbVerified publisher0.4.01 of 1See more

mariadb mariadb 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
stdlib@go1.24.6
1.25.13

Open the chart page →

2,469
marmotmarmotOfficialVerified publisher1.5.11 of 2See more

marmot marmot 1.5.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/marmotdata/marmot:0.10.0bd2a49f86486
stdlib@go1.26.5
1.25.13

Open the chart page →

333
mattermost-rtcdmattermostVerified publisher1.4.11 of 1See more

mattermost-rtcd mattermost 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mattermost/rtcd:latesta27058aaa53a
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

595
veleromesosphere3.2.51 of 1See more

velero mesosphere 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.55.0
1.25.13

Open the chart page →

1,871
kubecostmesosphere-stable0.37.57 of 9See more

kubecost mesosphere-stable 0.37.5

7 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.55.0
1.25.13
grafana/grafana:9.4.71a359d92f40e
golang.org/x/net@v0.4.0
stdlib@go1.20.1
0.55.0
1.25.13
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.55.0
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.55.0
1.25.13
quay.io/thanos/thanos:v0.36.1e542959e1b36
golang.org/x/net@v0.26.0
stdlib@go1.21.13
0.55.0
1.25.13

Open the chart page →

17,879
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.2
0.55.0
1.25.13

Open the chart page →

2,750
helm-ai-kernelmindburn-labsOfficialVerified publisher0.8.51 of 2See more

helm-ai-kernel mindburn-labs 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

2,183
mortalgpumortalgpuOfficialVerified publisher1.3.71 of 1See more

mortalgpu mortalgpu 1.3.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/maxiv/mortalgpu:1.3.7e1c5c194bbf0
golang.org/x/net@v0.54.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

379
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.19
0.55.0
1.25.13

Open the chart page →

3,828
nacknatsVerified publisher0.35.01 of 1See more

nack nats 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
natsio/jetstream-controller:0.24.058862daca582
stdlib@go1.26.5
1.25.13

Open the chart page →

227
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

4,259
netbird-operatornetbird-operator0.8.01 of 1See more

netbird-operator netbird-operator 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/netbirdio/netbird-operator:v0.8.0ae2c26cfc547
stdlib@go1.26.5
1.25.13

Open the chart page →

63
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.55.0
1.25.13

Open the chart page →

5,068
gateway-apinicklasfrahm-gateway-apiVerified publisher0.2.01 of 1See more

gateway-api nicklasfrahm-gateway-api 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/kubectl:1.33.32c59a3f0726c
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

1,258
observalobservalVerified publisher1.13.11 of 8See more

observal observal 1.13.1

1 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.13

Open the chart page →

6,171
aws-xrayokgoloveVerified publisher5.0.01 of 1See more

aws-xray okgolove 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/xray/aws-xray-daemon:3.6.243d051eed000
golang.org/x/net@v0.38.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

273
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

6,881
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
stdlib@go1.17.1
1.25.13
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

18,554
secrets-injectoronepassword-connect1.2.01 of 1See more

secrets-injector onepassword-connect 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
1password/kubernetes-secrets-injector:1.0.25884757f7879
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

891
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/git:2.47.2062a01ad7a0e
golang.org/x/net@v0.23.0
stdlib@go1.23.9
0.55.0
1.25.13

Open the chart page →

5,532
opentelemetry-ebpfopentelemetry-helmOfficialVerified publisher0.1.71 of 4See more

opentelemetry-ebpf opentelemetry-helm 0.1.7

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
golang.org/x/net@v0.7.0
stdlib@go1.20
0.55.0
1.25.13

Open the chart page →

2,582
oesopsmxVerified publisher4.0.3210 of 25See more

oes opsmx 4.0.32

10 of the 25 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.15.5
0.55.0
1.25.13
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.5
0.55.0
1.25.13
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
stdlib@go1.17.2
1.25.13
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
stdlib@go1.16.15
1.25.13
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.55.0
1.25.13
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.19.1
0.55.0
1.25.13
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.55.0
1.25.13
quay.io/opsmxpublic/opa:1.12.084fb1af7401c
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
stdlib@go1.22.2
1.25.13
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.1
0.55.0
1.25.13

Open the chart page →

108,589
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
golang.org/x/net@v0.0.0-20220517181318-183a9ca12b87
stdlib@go1.18.3
0.55.0
1.25.13
ipfs/ipfs-cluster:1.0.21511f6d57994
golang.org/x/net@v0.0.0-20220517181318-183a9ca12b87
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

3,783
psmdb-operatorpercona1.23.11 of 1See more

psmdb-operator percona 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
percona/percona-server-mongodb-operator:1.23.0feaff989e253
stdlib@go1.26.5
1.25.13

Open the chart page →

281
permifypermifyVerified publisher0.5.01 of 1See more

permify permify 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/permify/permify:v1.3.5f0c6f7d7daa6
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13

Open the chart page →

1,016
persespersesOfficialVerified publisher0.23.21 of 1See more

perses perses 0.23.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
persesdev/perses:v0.54.0a0e34ddaf9d7
stdlib@go1.26.5
1.25.13

Open the chart page →

147
platzioplatz-ioVerified publisher0.6.51 of 2See more

platzio platz-io 0.6.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
platzio/backend:v0.6.5d5e5972f344b
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

2,903
plecopleco0.24.01 of 1See more

pleco pleco 0.24.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/net@v0.39.0
stdlib@go1.21.6
0.55.0
1.25.13

Open the chart page →

1,356
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
stdlib@go1.13.10
1.25.13

Open the chart page →

2,995
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/net@v0.9.0
stdlib@go1.20.3
0.55.0
1.25.13

Open the chart page →

1,949
prometheus-pgbouncer-exporterprometheus-communityVerified publisher0.10.11 of 1See more

prometheus-pgbouncer-exporter prometheus-community 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/pgbouncer-exporter:v0.12.130f31b6c2efd
stdlib@go1.26.4
1.25.13

Open the chart page →

298
prometheus-systemd-exporterprometheus-communityVerified publisher0.5.21 of 1See more

prometheus-systemd-exporter prometheus-community 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/systemd-exporter:v0.7.078c03f875dfb
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.55.0
1.25.13

Open the chart page →

725
prometheus-yet-another-cloudwatch-exporterprometheus-communityVerified publisher0.47.01 of 1See more

prometheus-yet-another-cloudwatch-exporter prometheus-community 0.47.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/yet-another-cloudwatch-exporter:v0.67.0404791bf0b2f
stdlib@go1.26.4
1.25.13

Open the chart page →

68
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.55.0
1.25.13
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.14.12
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.55.0
1.25.13

Open the chart page →

12,134
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

5,440
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.55.0
1.25.13

Open the chart page →

2,731
repoflowrepoflow-helm-public0.9.12 of 8See more

repoflow repoflow-helm-public 0.9.1

2 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.25.13
minio/minio:RELEASE.2025-07-23T15-54-02Zd249d1fb6966
golang.org/x/net@v0.39.0
stdlib@go1.24.5
0.55.0
1.25.13

Open the chart page →

13,839
backrestrobertobochetVerified publisher0.7.01 of 1See more

backrest robertobochet 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
garethgeorge/backrest:v1.14.1b85297975428
stdlib@go1.26.0
1.25.13

Open the chart page →

869
supabaserock8sVerified publisher0.0.61 of 1See more

supabase rock8s 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.13

Open the chart page →

494
rqliterqliteOfficialVerified publisher2.0.01 of 1See more

rqlite rqlite 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rqlite/rqlite:9.1.37b992a526eee
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

1,319
qbittorrent-vpnrtomik-helm-chartsVerified publisher0.0.21 of 2See more

qbittorrent-vpn rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.40.02b42bfa04675
golang.org/x/net@v0.31.0
stdlib@go1.23.4
0.55.0
1.25.13

Open the chart page →

1,219

Container images carrying it

5,282 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
stdlib@go1.19.8
1.25.13
1
opencsghq/csgbot:v0.6.9-ee7d0271e26521
stdlib@go1.24.4
1.25.13
1
opencsghq/csghub-portal:v2.5.0-ee1cb36b49151e
golang.org/x/net@v0.28.0
stdlib@go1.23.3
0.55.0
1.25.13
1
opencsghq/csghub-server:v2.5.0-ee587046575c2c
stdlib@go1.26.0
1.25.13
1
opencsghq/csghub-xnet:v2.5.0-ee86ea22f495c7
golang.org/x/net@v0.39.0
stdlib@go1.24.10
0.55.0
1.25.13
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.55.0
1.25.13
1
opencsghq/gitlab-shell:v19.2.580a65ac370da
golang.org/x/net@v0.48.0
stdlib@go1.26.4
0.55.0
1.25.13
1
opencsghq/kube-state-metrics:v2.19.15ea147562ec8
stdlib@go1.26.4
1.25.13
1
opencsghq/lws:v0.6.1de15437db41b
golang.org/x/net@v0.37.0
stdlib@go1.24.0
0.55.0
1.25.13
1
opencsghq/prometheus:v3.13.00aac0d04749e
stdlib@go1.26.4
1.25.13
1
opencsghq/prometheus-config-reloader:v0.92.144e6ec00729b
stdlib@go1.26.4
1.25.13
1
opendatacube/explorer:latest120457ffcd69
stdlib@go1.22.2
1.25.13
1
openebs/lvm-driver:1.10.141f73aba7f31
golang.org/x/net@v0.48.0
stdlib@go1.24.7
0.55.0
1.25.13
1
openebs/provisioner-nfs:0.11.04f41dd782761
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.55.0
1.25.13
1
openebs/zfs-driver:2.11.116f1a74bb249
stdlib@go1.26.2
1.25.13
1
openenergyprojects/modbus_exporter:20230617_a14455158990f24fb25
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13
1
openfga/openfga:v1.18.036097b960f66
stdlib@go1.26.4
1.25.13
1
openfga/openfga:v1.9.25e94966c11df
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.55.0
1.25.13
1
openkruise/agent-sandbox-controller:v0.3.0e0a3bf7c0dc5
golang.org/x/net@v0.47.0
stdlib@go1.25.10
0.55.0
1.25.13
1
openkruise/kruise-game-manager:v1.1.0d3c6d69d2c39
golang.org/x/net@v0.43.0
stdlib@go1.23.4
0.55.0
1.25.13
1
openkruise/kruise-manager:v1.8.30482722b4e56
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.55.0
1.25.13
1
openkruise/kruise-manager:v1.9.1f81ae78a36a4
golang.org/x/net@v0.38.0
stdlib@go1.23.9
0.55.0
1.25.13
1
openkruise/kruise-rollout:v0.6.2a75e6739ea7d
golang.org/x/net@v0.7.0
stdlib@go1.19.13
0.55.0
1.25.13
1
openkruise/kruise-state-metrics:v0.2.0a8108f771287
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.55.0
1.25.13
1
openmined/syft-frontend:0.9.5d11524a3854a
stdlib@go1.20.5
1.25.13
1
openmined/syft-seaweedfs:0.9.53a4144c0bb82
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.55.0
1.25.13
1
opennms/sentinel:36.0.288869082a14f
golang.org/x/net@v0.29.0
stdlib@go1.22.2
0.55.0
1.25.13
1
openpolicyagent/gatekeeper:v3.17.1b7b4d7cfdd52
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.55.0
1.25.13
1
openpolicyagent/gatekeeper-crds:v3.17.177bc9bf3d163
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13
1
openpolicyagent/kube-mgmt:11.0.123a8b1bacbcd8
stdlib@go1.25.0
1.25.13
1
openpolicyagent/opa:0.53.16a58dea59933
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13
1
openpolicyagent/opa:1.19.0852359995443
stdlib@go1.26.5
1.25.13
1
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.25.13
1
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.25.13
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
stdlib@go1.20.6
1.25.13
1
opensearchproject/opensearch-operator:3.0.0-alphaf78bbdd1a386
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.55.0
1.25.13
1
openvino/model_server:2025.2.11e7cd1d70cc1
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
1
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/net@v0.0.0-20200520182314-0ba52f642ac2
stdlib@go1.14.7
0.55.0
1.25.13
1
optimizely/agent:4.0.09d0096cabd63
golang.org/x/net@v0.17.0
stdlib@go1.21.6
0.55.0
1.25.13
1
oranhack7/solidproject:77c6453942223f
stdlib@go1.21.7
1.25.13
1
orbitalreg/orbitalreg-api:0.1.045f2620337af
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.55.0
1.25.13
1
oryd/hydra:v2.3.0b94007e19a1f
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
1
oryd/keto:v26.2.0bfdb8b9e283a
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
1
oryd/kratos:v26.2.02a13bb8d362c
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
1
oryd/kratos:v1.1.08f15006a080d
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.55.0
1.25.13
1
oryd/oathkeeper:v26.2.0467329abde34
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
1
oryd/oathkeeper-maester:v0.1.140942e9fe9b1a
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13
1
otel/opentelemetry-collector:0.153.06ed874ea083d
stdlib@go1.26.3
1.25.13
1
otel/opentelemetry-collector:0.100.09e36620d6c2c
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.