StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,528
of 17,803 indexed, latest versions
Container images
5,282
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,528 of 17,803 indexed charts deploy, on 5,282 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+190 more1.25.135,243
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,683
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,528 by stars
ChartLatestAffected imagesRadar Score
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.55.0
1.25.13

Open the chart page →

1,596
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/net@v0.10.0
stdlib@go1.20.8
0.55.0
1.25.13

Open the chart page →

2,908
yatai-image-builderbentomlVerified publisher3.0.441 of 1See more

yatai-image-builder bentoml 3.0.44

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-image-builder:3.0.4401d8538c4f48
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

492
aramid-indexerbiatec-repoVerified publisher3.9.04 of 5See more

aramid-indexer biatec-repo 3.9.0

4 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.13
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.55.0
1.25.13
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.55.0
1.25.13
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.55.0
1.25.13

Open the chart page →

14,007
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

7,392
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
golang.org/x/net@v0.39.0
stdlib@go1.23.11
0.55.0
1.25.13

Open the chart page →

5,263
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

7,392
self-hostbitwarden2.4.210 of 11See more

self-host bitwarden 2.4.2

10 of the 11 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/bitwarden/admin:2026.9.05686674f2c35
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/api:2026.9.0d5964b4c9563
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/attachments:2026.9.0f019c2d14ca7
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/events:2026.9.0ffb067562d07
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/icons:2026.9.013d351a6cb08
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/identity:2026.9.090453408f338
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/notifications:2026.9.051f843ae35e3
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/sso:2026.9.09a2e89605b82
stdlib@go1.26.5
1.25.13
ghcr.io/bitwarden/web:2026.9.08aa9f4258378
stdlib@go1.26.5
1.25.13
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
stdlib@go1.23.1
1.25.13

Open the chart page →

3,549
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
stdlib@go1.21.6
1.25.13

Open the chart page →

2,945
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

1,630
syncthingbrandan-schmitz-helm-chartsVerified publisher2.1.01 of 1See more

syncthing brandan-schmitz-helm-charts 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
syncthing/syncthing:2.1.1775c4aac4862
stdlib@go1.26.3
1.25.13

Open the chart page →

1,224
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,842
btrfs-nfs-csibtrfs-nfs-csi0.4.06 of 7See more

btrfs-nfs-csi btrfs-nfs-csi 0.4.0

6 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

3,249
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.55.0
1.25.13

Open the chart page →

2,049
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.55.0
1.25.13

Open the chart page →

2,671
buildkite-agent-metricsbuildkite-agent-metrics0.1.01 of 1See more

buildkite-agent-metrics buildkite-agent-metrics 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.55.0
1.25.13

Open the chart page →

1,551
buildkit-fleetbuildkit-fleetVerified publisher0.1.21 of 1See more

buildkit-fleet buildkit-fleet 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
moby/buildkit:v0.33.0-rootless80b15f0735e8
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

903
nacosbytectl0.1.61 of 1See more

nacos bytectl 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.25.13

Open the chart page →

1,888
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

1,658
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

1,658
pgcagriekinVerified publisher2.1.01 of 2See more

pg cagriekin 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.13

Open the chart page →

2,426
pgvectorcagriekinVerified publisher2.1.02 of 3See more

pgvector cagriekin 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.13
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
stdlib@go1.24.6
1.25.13

Open the chart page →

4,210
camel-dashboard-operatorcamel-dashboardVerified publisher0.1.01 of 1See more

camel-dashboard-operator camel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.55.0
1.25.13

Open the chart page →

521
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

913
capsulecapsuleOfficialVerified publisher0.14.62 of 2See more

capsule capsule 0.14.6

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
stdlib@go1.26.4
1.25.13

Open the chart page →

1,239
capsule-proxycapsule-proxyOfficialVerified publisher0.14.12 of 2See more

capsule-proxy capsule-proxy 0.14.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
ghcr.io/projectcapsule/capsule-proxy:v0.14.17c90292e3172
stdlib@go1.26.4
1.25.13

Open the chart page →

1,227
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.2
0.55.0
1.25.13

Open the chart page →

3,512
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/net@v0.27.0
stdlib@go1.23.0
0.55.0
1.25.13

Open the chart page →

1,817
cert-estuarycert-estuaryVerified publisher0.2.11 of 1See more

cert-estuary cert-estuary 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/hsn723/cert-estuary:0.2.00c4b6132b0ad
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

276
cert-manager-google-cas-issuercert-managerOfficialVerified publisher0.12.01 of 1See more

cert-manager-google-cas-issuer cert-manager 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-google-cas-issuer:v0.12.08bd9cdb714a6
stdlib@go1.26.4
1.25.13

Open the chart page →

164
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.55.0
1.25.13

Open the chart page →

12,804
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/net@v0.9.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

1,082
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
golang.org/x/net@v0.26.0
stdlib@go1.22.0
0.55.0
1.25.13

Open the chart page →

1,039
cert-vaultcert-vaultOfficialVerified publisher2.12.04 of 7See more

cert-vault cert-vault 2.12.0

4 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/net@v0.33.0
stdlib@go1.23.7
0.55.0
1.25.13
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
stdlib@go1.23.7
1.25.13
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.25.13
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13

Open the chart page →

16,224
chatclichatcliVerified publisher1.205.11 of 2See more

chatcli chatcli 1.205.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/net@v0.26.0
stdlib@go1.23.10
0.55.0
1.25.13

Open the chart page →

1,028
etcd-defragchristianhuthVerified publisher1.6.11 of 1See more

etcd-defrag christianhuth 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.7.13c66a5191d37
stdlib@go1.26.5
1.25.13

Open the chart page →

143
passbolt-hachristianhuthVerified publisher6.0.13 of 4See more

passbolt-ha christianhuth 6.0.1

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.13
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.55.0
1.25.13
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.25.13

Open the chart page →

11,031
shlink-backendchristianhuthVerified publisher11.11.11 of 1See more

shlink-backend christianhuth 11.11.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
shlinkio/shlink:5.1.6666cc24edf72
stdlib@go1.26.4
1.25.13

Open the chart page →

322
squestchristianhuthVerified publisher6.6.82 of 4See more

squest christianhuth 6.6.8

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.25.13
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.13

Open the chart page →

10,173
typo3christianhuthVerified publisher7.7.11 of 2See more

typo3 christianhuth 7.7.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.13

Open the chart page →

8,689
challengerchronicleVerified publisher0.1.11 of 1See more

challenger chronicle 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
stdlib@go1.22.12
1.25.13

Open the chart page →

978
erpcchronicleVerified publisher0.7.01 of 1See more

erpc chronicle 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/erpc/erpc:0.1.18bfed3d49a08
stdlib@go1.26.4
1.25.13

Open the chart page →

391
spectrechronicleVerified publisher0.3.81 of 1See more

spectre chronicle 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

1,548
validatorchronicleVerified publisher0.8.01 of 1See more

validator chronicle 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/ghost:0.78.5951d71162065
stdlib@go1.26.5
1.25.13

Open the chart page →

507
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.55.0
1.25.13

Open the chart page →

643
clamav-restclamav-rest-apiVerified publisher0.1.01 of 1See more

clamav-rest clamav-rest-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ajilaag/clamav-rest:latestad689c7b75b1
stdlib@go1.26.0
1.25.13

Open the chart page →

515
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
stdlib@go1.24.6
1.25.13

Open the chart page →

2,360
clickhouse-operator-helmclickhouse-operator0.0.71 of 1See more

clickhouse-operator-helm clickhouse-operator 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/clickhouse/clickhouse-operator:v0.0.7d51ca53f0967
stdlib@go1.26.5
1.25.13

Open the chart page →

118
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.55.0
1.25.13
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.55.0
1.25.13

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.25.13
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.2
0.55.0
1.25.13

Open the chart page →

4,265

Container images carrying it

5,282 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
prom/graphite-exporter:v0.16.0e54bca6645ea
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.55.0
1.25.13
1
prom/influxdb-exporter:v0.11.427e33e18634a
stdlib@go1.19.9
1.25.13
1
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.25.13
1
prom/memcached-exporter:v0.9.001267317c95d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.16.2
0.55.0
1.25.13
1
prom/memcached-exporter:v0.15.592a6ad5a3d3e
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.55.0
1.25.13
1
prom/memcached-exporter:v0.15.0bb01ad25e9fc
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.55.0
1.25.13
1
prom/node-exporter:v1.10.23ac34ce007ac
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.55.0
1.25.13
1
prom/node-exporter:v1.6.0d2e48098c364
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13
1
prom/prometheus:v2.51.24f6c47e39a90
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.55.0
1.25.13
1
prom/prometheus:v2.18.15880ec936055
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
stdlib@go1.14.2
0.55.0
1.25.13
1
prom/prometheus:v3.12.069f524141883
stdlib@go1.26.3
1.25.13
1
prom/prometheus:v2.48.0b440bc0e8aa5
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.55.0
1.25.13
1
prom/prometheus:v2.19.2cd134bd4fca0
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.55.0
1.25.13
1
prom/prometheus:v3.8.0d936808bdea5
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.55.0
1.25.13
1
prom/prometheus:v2.16.0e4ca62c0d62f
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.8
0.55.0
1.25.13
1
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.5
0.55.0
1.25.13
1
prom/promlens:v0.4.04a377d1a0eaa
stdlib@go1.26.5
1.25.13
1
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.55.0
1.25.13
1
prom/pushgateway:v1.4.33496e0f85943
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.55.0
1.25.13
1
prom/snmp-exporter:v0.20.09d226d7de223
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.15.8
0.55.0
1.25.13
1
prom/statsd-exporter:v0.24.061d866e93b56
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.55.0
1.25.13
1
prom/statsd-exporter:v0.29.0632f70580492
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
1
prom/statsd-exporter:v0.22.48be660470961
stdlib@go1.17.3
1.25.13
1
promzeus/redis-sentinel-gateway:v182f6d56e280b
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.55.0
1.25.13
1
prowlercloud/prowler-api:5.31.14f252d579be2
golang.org/x/net@v0.54.0
stdlib@go1.26.3-X:jsonv2
0.55.0
1.25.13
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
stdlib@go1.21.5
1.25.13
1
pschiffe/pdns-mysql:alpined196c796cafb
stdlib@go1.21.5
1.25.13
1
pschiffe/pdns-pgsql:5.0a227d41bc665
stdlib@go1.21.5
1.25.13
1
pubeldev/prusa_exporter:2.0.01091665a020a
stdlib@go1.25.5
1.25.13
1
pulumi/pulumi-kubernetes-operator:v2.5.17dace4491358
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.55.0
1.25.13
1
pysga1996/redis:latest3af6d0c7db19
stdlib@go1.18.2
1.25.13
1
qichenxu4pd/mysqlweb:1.2d758d41d9c6b
stdlib@go1.18.2
1.25.13
1
qmcgaw/gluetun:v3.41.11a5bf4b4820a
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
1
qmcgaw/gluetun:v3.40.02b42bfa04675
golang.org/x/net@v0.31.0
stdlib@go1.23.4
0.55.0
1.25.13
1
qonstrukt/php:8.4-v8-apache089af7925aa1
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.26.4
0.55.0
1.25.13
1
qoveryrd/digital-mobius:0.1.4b30a9398a83c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.5
0.55.0
1.25.13
1
qualys/qscanner:5.1.0-59ff255352422
stdlib@go1.26.5-X:jsonv2
1.25.13
1
quiq/docker-registry-ui:0.9.491281da47036
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.18
0.55.0
1.25.13
1
qumine/ingress-controller:v0.8.5f2c8a2148381
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.55.0
1.25.13
1
qumine/minecraft-server:v0.1.15c0b650d51132
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.4
0.55.0
1.25.13
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.17
0.55.0
1.25.13
1
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.55.0
1.25.13
1
rabbitmqoperator/cluster-operator:2.6.08651dd3cec51
golang.org/x/net@v0.18.0
stdlib@go1.20.11
0.55.0
1.25.13
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
stdlib@go1.23.7
1.25.13
1
ralexstokes/eth2-fork-mon:latestc0d4bbefd31f
stdlib@go1.16.7
1.25.13
1
rancher/hardened-calico:v3.13.36d2cd61a338b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.55.0
1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.55.0
1
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.55.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.