StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,643
of 17,821 indexed, latest versions
Container images
5,380
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,643 of 17,821 indexed charts deploy, on 5,380 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,337
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,758
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,643 by stars
ChartLatestAffected imagesRadar Score
giteak8s-home-lab-repo2.6.01 of 1See more

gitea k8s-home-lab-repo 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gitea/gitea:1.26.27d13848af126
golang.org/x/net@v0.53.0
stdlib@go1.26.3-X:jsonv2
0.55.0
1.25.13

Open the chart page →

2,143
influxdb-exporterk8s-home-lab-repo1.1.31 of 1See more

influxdb-exporter k8s-home-lab-repo 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/influxdb-exporter:v0.11.427e33e18634a
stdlib@go1.19.9
1.25.13

Open the chart page →

624
maddyk8s-home-lab-repo4.2.11 of 1See more

maddy k8s-home-lab-repo 4.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
foxcpp/maddy:0.8.2eeb5813fc4d1
golang.org/x/net@v0.34.0
stdlib@go1.23.12
0.55.0
1.25.13

Open the chart page →

1,205
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
stdlib@go1.24.4
1.25.13

Open the chart page →

9,352
photoprismk8s-home-lab-repo10.0.11 of 1See more

photoprism k8s-home-lab-repo 10.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
photoprism/photoprism:231128-ce284de9cc4f9c
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.55.0
1.25.13

Open the chart page →

1,141
zurgk8s-home-lab-repo1.2.11 of 1See more

zurg k8s-home-lab-repo 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/debridmediamanager/zurg-testing:v0.9.3-final5c47ef99443a
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

1,734
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

2,447
k8s-mutating-admission-webhookk8s-mutating-admission-webhook1.15.11 of 1See more

k8s-mutating-admission-webhook k8s-mutating-admission-webhook 1.15.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
udhos/k8s-mutating-admission-webhook:1.15.1e588db500edf
stdlib@go1.26.3
1.25.13

Open the chart page →

940
k8s-mutating-webhookk8s-mutating-webhook0.3.01 of 2See more

k8s-mutating-webhook k8s-mutating-webhook 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

2,013
k8s-ondemand-proxyk8s-ondemand-proxy0.0.61 of 1See more

k8s-ondemand-proxy k8s-ondemand-proxy 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
golang.org/x/net@v0.13.0
stdlib@go1.21.1
0.55.0
1.25.13

Open the chart page →

815
github-exporterk8sonlabVerified publisher0.0.41 of 1See more

github-exporter k8sonlab 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
githubexporter/github-exporter:v2.3.1a36fbedeedf8
stdlib@go1.26.4
1.25.13

Open the chart page →

68
librephotosk8sonlabVerified publisher1.1.63 of 7See more

librephotos k8sonlab 1.1.6

3 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/k8s:1.22.600ac10bcb759
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.17.6
0.55.0
1.25.13
bitnamilegacy/redis:latest5927ff3702df
stdlib@go1.24.5
1.25.13
reallibrephotos/librephotos-frontend:1.0.358cdf5e93471
stdlib@go1.24.13
1.25.13

Open the chart page →

14,825
thanosk8sonlabVerified publisher1.1.71 of 1See more

thanos k8sonlab 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

602
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.13

Open the chart page →

7,481
k8s-pausek8s-pause0.1.41 of 1See more

k8s-pause k8s-pause 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.8
0.55.0
1.25.13

Open the chart page →

1,847
k8s-redirectsk8s-redirects1.0.01 of 1See more

k8s-redirects k8s-redirects 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
traefik/whoami:latestc4717a8d1f01
stdlib@go1.26.5
1.25.13

Open the chart page →

93
k8s-s3-bucket-operatork8s-s3-bucket-operator0.2.21 of 1See more

k8s-s3-bucket-operator k8s-s3-bucket-operator 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

535
k8s-ssh-bastionk8s-ssh-bastion0.5.41 of 1See more

k8s-ssh-bastion k8s-ssh-bastion 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
golang.org/x/net@v0.23.0
stdlib@go1.21.11
0.55.0
1.25.13

Open the chart page →

3,352
k8s-validating-webhookk8s-validating-webhook0.4.01 of 2See more

k8s-validating-webhook k8s-validating-webhook 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

2,013
kube-admission-controller-starterk8s-validating-webhook0.2.01 of 2See more

kube-admission-controller-starter k8s-validating-webhook 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

2,169
k8svault-controllerk8svault-controller0.1.21 of 1See more

k8svault-controller k8svault-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.16.15
0.55.0
1.25.13

Open the chart page →

1,886
kagentkagent0.10.13 of 6See more

kagent kagent 0.10.1

3 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mcp/grafana:latest9362bcf6aa0e
stdlib@go1.26.5
1.25.13
ghcr.io/kagent-dev/kagent/tools:0.2.150b431281d3e
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.55.0
1.25.13
ghcr.io/kagent-dev/kmcp/controller:0.3.086ab878da25a
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

3,014
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

4,655
postgresqlkagiso-me0.4.01 of 1See more

postgresql kagiso-me 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.25.13

Open the chart page →

1,636
rediskagiso-me0.1.61 of 1See more

redis kagiso-me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.25.13

Open the chart page →

1,435
kom-operatorkaisoVerified publisher1.3.01 of 2See more

kom-operator kaiso 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kaiso/kom-operator:v2.2.0e0e22b928bdd
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

710
gpu-provisionerkaitoVerified publisher0.2.01 of 1See more

gpu-provisioner kaito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mcr.microsoft.com/aks/kaito/gpu-provisioner:0.2.01204a7e948e9
golang.org/x/net@v0.20.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

1,045
workspacekaitoVerified publisher0.12.05 of 7See more

workspace kaito 0.12.0

5 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mcr.microsoft.com/acstor/local-csi-driver:v0.3.0f9af53a79fd1
stdlib@go1.26.5
1.25.13
mcr.microsoft.com/acstor/local-csi-manager:v0.3.04f464b52ba85
stdlib@go1.26.5
1.25.13
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v5.2.0afdfa3da79df
golang.org/x/net@v0.34.0
stdlib@go1.25.5
0.55.0
1.25.13
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v1.13.2fa8eba9843ff
golang.org/x/net@v0.34.0
stdlib@go1.25.7
0.55.0
1.25.13
mcr.microsoft.com/oss/v2/nvidia/k8s-device-plugin:v0.18.2-125a4e52c87bb9
stdlib@go1.26.5
1.25.13

Open the chart page →

2,551
jenkinskallakruparaju-jenkins1.0.01 of 1See more

jenkins kallakruparaju-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

2,451
crashlooping-pod-deleterkarljorgensen0.1.31 of 1See more

crashlooping-pod-deleter karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

1,155
dockerdkarljorgensen0.1.01 of 1See more

dockerd karljorgensen 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/docker:28.5.2-dind2a232a42256f
golang.org/x/net@v0.39.0
stdlib@go1.24.9
0.55.0
1.25.13

Open the chart page →

2,055
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
golang.org/x/net@v0.17.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

7,223
karpenter-provider-proxmoxkarpenter-provider-proxmox0.4.91 of 1See more

karpenter-provider-proxmox karpenter-provider-proxmox 0.4.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/karpenter-provider-proxmox:v0.12.0ea8b8e60a020
stdlib@go1.26.5
1.25.13

Open the chart page →

66
k10restorekastenVerified publisher8.0.141 of 1See more

k10restore kasten 8.0.14

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13

Open the chart page →

1,508
kbot-self-hostedkbot-self-hostedVerified publisher0.1.81 of 7See more

kbot-self-hosted kbot-self-hosted 0.1.8

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.30206a6c708fc6
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

33,120
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:latest66aec17cd21a
stdlib@go1.24.6
1.25.13

Open the chart page →

9,027
kcmkcm1.12.05 of 12See more

kcm kcm 1.12.0

5 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
velero/velero:v1.18.237396519f399
stdlib@go1.25.11
1.25.13
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.55.0
1.25.13
ghcr.io/fluxcd/helm-controller:v1.6.2e17ab0e5885d
stdlib@go1.26.4
1.25.13
ghcr.io/fluxcd/source-controller:v1.9.22b8d06650a1b
stdlib@go1.26.4
1.25.13
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

3,330
kcp-operatorkcp-devVerified publisher0.7.101 of 1See more

kcp-operator kcp-dev 0.7.10

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kcp-dev/kcp-operator:v0.9.0cd8bf46d98e0
stdlib@go1.26.4
1.25.13

Open the chart page →

141
keeper-injectorkeeper-injectorVerified publisher0.10.02 of 2See more

keeper-injector keeper-injector 0.10.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
keeper/injector-webhook:0.10.0aeb5476b95f0
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.55.0
1.25.13

Open the chart page →

758
keeper-injectorkeeper-securityVerified publisher0.11.31 of 2See more

keeper-injector keeper-security 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.55.0
1.25.13

Open the chart page →

505
nodevitalskeiailabVerified publisher0.8.61 of 1See more

nodevitals keiailab 0.8.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/keiailab/nodevitals:0.8.597107e46f0d3
stdlib@go1.26.5
1.25.13

Open the chart page →

442
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
stdlib@go1.20.7
1.25.13

Open the chart page →

5,295
kestra-starterkestraOfficialVerified publisher2.0.23 of 5See more

kestra-starter kestra 2.0.2

3 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/docker:dind-rootlessc876e00a0d81
golang.org/x/net@v0.50.0
0.55.0
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.25.13
versity/versitygw:v1.1.0f730e0dbc1ef
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

5,552
keycloak-operator-legacykeycloak-operator-legacy1.0.01 of 1See more

keycloak-operator-legacy keycloak-operator-legacy 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.55.0
1.25.13

Open the chart page →

5,071
csi-driver-nfskeyporttech0.1.41 of 2See more

csi-driver-nfs keyporttech 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
golang.org/x/net@v0.0.0-20190415100556-4a65cf94b679
stdlib@go1.14.2
0.55.0
1.25.13

Open the chart page →

3,365
gogskeyporttech0.1.31 of 3See more

gogs keyporttech 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gogs/gogs:0.12.30195b095d0b2
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.7
0.55.0
1.25.13

Open the chart page →

3,525
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.55.0
1.25.13

Open the chart page →

8,842
connectkfirfer1.15.02 of 2See more

connect kfirfer 1.15.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
1password/connect-api:1.7.26aa94cf713f9
golang.org/x/net@v0.14.0
stdlib@go1.20.6
0.55.0
1.25.13
1password/connect-sync:1.7.2fe527ed9d81f
golang.org/x/net@v0.14.0
stdlib@go1.20.6
0.55.0
1.25.13

Open the chart page →

2,787
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.55.0
1.25.13

Open the chart page →

2,793
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
stdlib@go1.17.1
1.25.13

Open the chart page →

6,519

Container images carrying it

5,380 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
optimizely/agent:4.0.09d0096cabd63
golang.org/x/net@v0.17.0
stdlib@go1.21.6
0.55.0
1.25.13
1
oranhack7/solidproject:77c6453942223f
stdlib@go1.21.7
1.25.13
1
orbitalreg/orbitalreg-api:0.1.045f2620337af
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.55.0
1.25.13
1
oryd/hydra:v2.3.0b94007e19a1f
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
1
oryd/keto:v26.2.0bfdb8b9e283a
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
1
oryd/kratos:v26.2.02a13bb8d362c
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
1
oryd/kratos:v1.1.08f15006a080d
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.55.0
1.25.13
1
oryd/oathkeeper:v26.2.0467329abde34
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
1
oryd/oathkeeper-maester:v0.1.140942e9fe9b1a
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13
1
otel/opentelemetry-collector:0.153.06ed874ea083d
stdlib@go1.26.3
1.25.13
1
otel/opentelemetry-collector:0.100.09e36620d6c2c
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.55.0
1.25.13
1
otel/opentelemetry-collector:0.59.0ee9da0b08d83
golang.org/x/net@v0.0.0-20220809184613-07c6da5e1ced
stdlib@go1.18.5
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.156.0125bdbeb7590
stdlib@go1.26.4
1.25.13
1
otel/opentelemetry-collector-contrib:0.128.01ab0baba0ee3
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.143.03bc07732530c
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.113.05ac3e0ba2b0b
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.108.0923eb1cfae32
golang.org/x/net@v0.28.0
stdlib@go1.23.0
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.89.0995f17004231
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.154.0b3079f45e19b
stdlib@go1.26.4
1.25.13
1
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.7
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.55.0
1.25.13
1
otel/opentelemetry-collector-contrib:0.157.0f2f01157055a
stdlib@go1.26.5
1.25.13
1
otel/opentelemetry-collector-contrib:0.139.0faf125d656fa
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.55.0
1.25.13
1
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.55.0
1.25.13
1
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
golang.org/x/net@v0.7.0
stdlib@go1.20
0.55.0
1.25.13
1
outcoldsolutions/collectorforopenshift:26.04.45000a5f27bbb
stdlib@go1.26.4
1.25.13
1
outlinewiki/outline:0.82.0494dfb9249a6
stdlib@go1.20.12
1.25.13
1
ovhplatform/what-is-my-pod:1.0.16d4d455e9aba
stdlib@go1.16.14
1.25.13
1
owncloud/ocis:7.1.388e7c854517d
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.55.0
1.25.13
1
owncloud/ocis:8.0.1b38fd8fdd58f
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13
1
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.5
0.55.0
1.25.13
1
owncloud/server:10.15.051d9b74fc2a8
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
1
owncloud/server:10.16.274c53d341076
golang.org/x/net@v0.52.0
stdlib@go1.26.3
0.55.0
1.25.13
1
owncloud/server:10.16.3b3f9efdcd7f7
stdlib@go1.26.5
1.25.13
1
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17
0.55.0
1.25.13
1
oxynozeta/prometheus-cachethq:1.1.131f11669d597
stdlib@go1.15.1
1.25.13
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.25.13
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.25.13
1
pannoi/kollektor:1.0.59559617788fc
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.55.0
1.25.13
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
stdlib@go1.14.4
1.25.13
1
penpotapp/backend:2.17.2770b55f6e51b
stdlib@go1.26.5
1.25.13
1
penpotapp/exporter:2.17.272a8061e8806
stdlib@go1.26.5
1.25.13
1
penpotapp/mcp:2.17.284f3f07ead11
stdlib@go1.26.5
1.25.13
1
percona/mongodb_exporter:0.53.00214e482b2cd
stdlib@go1.26.2
1.25.13
1
percona/percona-postgresql-operator:2.8.06cce2698d3f5
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.55.0
1.25.13
1
percona/percona-server-mongodb-operator:1.20.1d09453ce7886
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.