StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,616
of 17,805 indexed, latest versions
Container images
5,324
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,616 of 17,805 indexed charts deploy, on 5,324 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+190 more1.25.135,284
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,716
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,616 by stars
ChartLatestAffected imagesRadar Score
astarte-operatorastarteOfficialVerified publisher26.5.21 of 1See more

astarte-operator astarte 26.5.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
astarte/astarte-kubernetes-operator:26.5.1e3ff1b3c0c98
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

709
awx-operatorawx-operator-helm3.2.12 of 2See more

awx-operator awx-operator-helm 3.2.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
golang.org/x/net@v0.20.0
stdlib@go1.20.12
0.55.0
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.15.02c7b120590cb
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

9,883
cerboscerbosVerified publisher0.55.01 of 1See more

cerbos cerbos 0.55.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cerbos/cerbos:0.55.04b9d3b58c4f1
stdlib@go1.26.5
1.25.13

Open the chart page →

115
cadvisorckotzbauerVerified publisher2.4.31 of 1See more

cadvisor ckotzbauer 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.52.1f40e65878e25
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.55.0
1.25.13

Open the chart page →

968
m365-exportercloudeteer-helm-chartsVerified publisher1.7.11 of 1See more

m365-exporter cloudeteer-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/cloudeteer/m365-exporter:3.9.3a13a11fe9558
stdlib@go1.26.5
1.25.13

Open the chart page →

84
passboltcnieg1.1.171 of 2See more

passbolt cnieg 1.1.17

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.25.13

Open the chart page →

3,560
codercoderOfficialVerified publisher1.44.61 of 2See more

coder coder 1.44.6

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.55.0
1.25.13

Open the chart page →

7,188
dronecommunity-chartsVerified publisher0.1.52 of 2See more

drone community-charts 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
drone/drone:2.28.255897c8fb22d
golang.org/x/net@v0.42.0
stdlib@go1.24.13
0.55.0
1.25.13
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.55.0
1.25.13

Open the chart page →

2,737
cloudflare-operatorcontainerooVerified publisher1.10.71 of 1See more

cloudflare-operator containeroo 1.10.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/containeroo/cloudflare-operator:v1.10.60eda6d237a84
stdlib@go1.26.0
1.25.13

Open the chart page →

222
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.13
getconvoy/convoy:v26.7.6f4934cc05e31
stdlib@go1.26.2
1.25.13

Open the chart page →

6,136
cortexcortex3.3.81 of 4See more

cortex cortex 3.3.8

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/cortexproject/cortex:v1.21.18577eb292a01
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

4,023
whoamicowboysysopVerified publisher6.0.01 of 1See more

whoami cowboysysop 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.25.13

Open the chart page →

353
doris-operatordorisVerified publisher25.8.01 of 1See more

doris-operator doris 25.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
apache/doris:operator-latest3a4422656592
golang.org/x/net@v0.33.0
stdlib@go1.23.12
0.55.0
1.25.13

Open the chart page →

438
uptime-kumaduyet0.1.81 of 1See more

uptime-kuma duyet 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.55.0
1.25.13

Open the chart page →

4,568
emqx-operatoremqx-operator2.3.22 of 2See more

emqx-operator emqx-operator 2.3.2

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/k8s:1.31.49c4976d47656
golang.org/x/net@v0.31.0
stdlib@go1.23.2
0.55.0
1.25.13
ghcr.io/emqx/emqx-operator:2.3.23333ed546165
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

4,707
kube-routerenixVerified publisher1.10.01 of 1See more

kube-router enix 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.55.0
1.25.13

Open the chart page →

2,352
gethethereum-helm-chartsVerified publisher1.1.41 of 2See more

geth ethereum-helm-charts 1.1.4

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ethereum/client-go:stableb8ab3451a117
golang.org/x/net@v0.50.0
stdlib@go1.26.5
0.55.0
1.25.13

Open the chart page →

633
gotifygotifyVerified publisher0.8.11 of 1See more

gotify gotify 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gotify/server:2.9.1a3af47067ce6
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

568
docmosthelmforgeVerified publisher1.2.121 of 4See more

docmost helmforge 1.2.12

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

4,213
wordpresshelmforgeVerified publisher3.0.61 of 3See more

wordpress helmforge 3.0.6

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
stdlib@go1.24.6
1.25.13

Open the chart page →

4,288
korkorVerified publisher0.2.161 of 1See more

kor kor 0.2.16

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
yonahdissen/kor:latest1a85158c82bb
stdlib@go1.26.0
1.25.13

Open the chart page →

222
kubelet-csr-approverkubelet-csr-approverOfficialVerified publisher1.2.151 of 1See more

kubelet-csr-approver kubelet-csr-approver 1.2.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/postfinance/kubelet-csr-approver:v1.2.156469ef517d2b
golang.org/x/net@v0.49.0
0.55.0

Open the chart page →

64
logging-operatorkube-loggingVerified publisher4.2.31 of 1See more

logging-operator kube-logging 4.2.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/logging-operator:4.2.20dd85dcb1f73
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

880
myipkuossOfficialVerified publisher0.2.21 of 1See more

myip kuoss 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kuoss/myip:v0.1.7760f5ccae493
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13

Open the chart page →

660
keptnlifecycle-toolkitOfficialVerified publisher0.11.03 of 3See more

keptn lifecycle-toolkit 0.11.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
golang.org/x/net@v0.37.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

1,957
lightrun-helm-chartlightrun-helm-chartOfficialVerified publisher3.52.01 of 9See more

lightrun-helm-chart lightrun-helm-chart 3.52.0

1 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.4.108dbcf531a03a
stdlib@go1.24.6
1.25.13

Open the chart page →

463
mattermost-operatormattermostVerified publisher1.0.51 of 1See more

mattermost-operator mattermost 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mattermost/mattermost-operator:v1.25.4bac00a2bbd33
golang.org/x/net@v0.41.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

273
meshery-operatormesheryOfficialVerified publisher1.0.702 of 2See more

meshery-operator meshery 1.0.70

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/k8s:1.35.6b7a12c5ddf26
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
meshery/meshery-operator:1.0.50d245bc8b5c6
stdlib@go1.26.4
1.25.13

Open the chart page →

2,462
missing-container-metricsmissing-container-metrics0.1.11 of 1See more

missing-container-metrics missing-container-metrics 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.55.0
1.25.13

Open the chart page →

2,419
tailscale-relaymvisonneau0.2.71 of 1See more

tailscale-relay mvisonneau 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mvisonneau/tailscale:v1.68.1fc45ad8abf10
golang.org/x/net@v0.24.0
stdlib@go1.22.4
0.55.0
1.25.13

Open the chart page →

1,358
system-upgrade-controllernimbolus0.7.01 of 1See more

system-upgrade-controller nimbolus 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/system-upgrade-controller:v0.18.09813f85653c8
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

318
olmolmVerified publisher0.45.01 of 1See more

olm olm 0.45.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/operator-framework/olm:v0.45.0f228c7a6b8c5
stdlib@go1.26.3
1.25.13

Open the chart page →

448
ketoory0.64.01 of 1See more

keto ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
oryd/keto:v26.2.0bfdb8b9e283a
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

979
oathkeeperory0.64.01 of 1See more

oathkeeper ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
oryd/oathkeeper:v26.2.0467329abde34
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

932
passboltpassbolt2.1.13 of 6See more

passbolt passbolt 2.1.1

3 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.25.13
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.13
library/mariadb:latestdd9b303aed4f
stdlib@go1.24.6
1.25.13

Open the chart page →

13,732
pmmpercona1.9.11 of 1See more

pmm percona 1.9.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
percona/pmm-server:3.9.1003f9c25f842
stdlib@go1.26.4
1.25.13

Open the chart page →

823
redis-enterprise-operatorredis-enterprise-operator-officialOfficialVerified publisher8.0.18-111 of 1See more

redis-enterprise-operator redis-enterprise-operator-official 8.0.18-11

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
redislabs/operator:8.0.18-119078e713bb6a
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.55.0
1.25.13

Open the chart page →

944
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
golang.org/x/net@v0.48.0
stdlib@go1.26.4
0.55.0
1.25.13

Open the chart page →

1,399
rekorsigstoreVerified publisher1.8.67 of 9See more

rekor sigstore 1.8.6

7 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redisdigest-pinned148bb5411c18
stdlib@go1.18.2
1.25.13
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.25.13
ghcr.io/sigstore/rekor/rekor-server:v1.5.4100d793d68d0
stdlib@go1.26.4
1.25.13
ghcr.io/sigstore/scaffolding/createdbdigest-pinned3cee6c78973b
golang.org/x/net@v0.46.0
stdlib@go1.25.0
0.55.0
1.25.13
ghcr.io/sigstore/scaffolding/createtreedigest-pinnede5232e8c9122
golang.org/x/net@v0.46.0
stdlib@go1.25.0
0.55.0
1.25.13
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
stdlib@go1.26.0
1.25.13
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
stdlib@go1.26.0
1.25.13

Open the chart page →

5,529
mssqlserver-2022simcube1.2.31 of 1See more

mssqlserver-2022 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
stdlib@go1.26.1
1.25.13

Open the chart page →

2,991
snyk-monitorsnyk2.23.261 of 2See more

snyk-monitor snyk 2.23.26

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
snyk/kubernetes-monitor:2.23.26fb5ad76ce84e
golang.org/x/net@v0.54.0
stdlib@go1.25.10
0.55.0
1.25.13

Open the chart page →

592
swo-k8s-collectorsolarwindsOfficialVerified publisher5.3.03 of 3See more

swo-k8s-collector solarwinds 5.3.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
stdlib@go1.26.4-X:boringcrypto
1.25.13
ghcr.io/open-telemetry/opentelemetry-ebpf-instrumentation/ebpf-instrument:v0.9.026f82b148dfe
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

2,441
sops-operatorsops-operatorVerified publisher0.10.12 of 2See more

sops-operator sops-operator 0.10.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13
ghcr.io/peak-scale/sops-operator:0.10.11da9b716b792
stdlib@go1.26.4
1.25.13

Open the chart page →

1,260
thehivestrangebee-helmOfficialVerified publisher1.0.74 of 7See more

thehive strangebee-helm 1.0.7

4 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.55.0
1.25.13
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.55.0
1.25.13
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.55.0
1.25.13
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

16,514
truenas-csptruenas-cspVerified publisher1.2.410 of 11See more

truenas-csp truenas-csp 1.2.4

10 of the 11 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/hpestorage/csi-driver:v3.2.0ef7f4e1544fa
golang.org/x/net@v0.48.0
stdlib@go1.25.10
0.55.0
1.25.13
quay.io/hpestorage/csi-extensions:v1.2.1189146672a7ac
golang.org/x/net@v0.48.0
stdlib@go1.26.3
0.55.0
1.25.13
quay.io/hpestorage/volume-group-provisioner:v1.0.107bf9d8f16a5d
golang.org/x/net@v0.48.0
stdlib@go1.26.3
0.55.0
1.25.13
quay.io/hpestorage/volume-group-snapshotter:v1.0.10caeaaffe7e2b
golang.org/x/net@v0.48.0
stdlib@go1.26.3
0.55.0
1.25.13
quay.io/hpestorage/volume-mutator:v1.3.109e98b2e697bd
golang.org/x/net@v0.48.0
stdlib@go1.26.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

6,027
uffizzi-controlleruffizzi-controller2.4.68 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

8 of the 11 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
stdlib@go1.20.14
0.55.0
1.25.13
uffizzi/uffizzi-cluster-operator:v1.6.55ca448a08783
golang.org/x/net@v0.8.0
stdlib@go1.19.13
0.55.0
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.14.54ffda7facb4d
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.14.59c0527cab629
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.55.0
1.25.13
quay.io/jetstack/cert-manager-startupapicheck:v1.14.50f5b104bdd1b
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.14.5ef419261a209
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

14,364
filebrowserutkuozdemirVerified publisher1.0.01 of 1See more

filebrowser utkuozdemir 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

3,076
vsphere-csivsphere-tmm3.8.17 of 7See more

vsphere-csi vsphere-tmm 3.8.1

7 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

3,960
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.55.0
1.25.13

Open the chart page →

6,264
aad-pod-identityaad-pod-identity4.1.182 of 2See more

aad-pod-identity aad-pod-identity 4.1.18

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/azure/aad-pod-identity/mic:v1.8.173004b93fcb74
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.55.0
1.25.13
mcr.microsoft.com/oss/azure/aad-pod-identity/nmi:v1.8.1777788bf38938
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.55.0
1.25.13

Open the chart page →

2,860

Container images carrying it

5,324 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.55.0
1.25.13
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.21.7
0.55.0
1.25.13
1
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.55.0
1.25.13
1
twinproduction/gatus:v5.34.03fff895e77d3
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
1
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.1
0.55.0
1.25.13
1
tykio/portal:v1.18.092509e00e618
stdlib@go1.25.11
1.25.13
1
tykio/tyk-operator:v1.4.2e13d37f298b7
stdlib@go1.25.12
1.25.13
1
uderelier19/pardus-nginx:25-nodeport8ab640b44e3f
stdlib@go1.24.4
1.25.13
1
udhos/apiping:1.5.041ab9bae6f3b
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13
1
udhos/eks-auto-pod-id-assoc:0.6.0196ef68af380
stdlib@go1.26.3
1.25.13
1
udhos/forward:1.1.312e120d39fdb
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13
1
udhos/gateboard:1.12.53acc0e7599bf
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.55.0
1.25.13
1
udhos/gateboard-discovery:1.9.55567c9363c4c
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.55.0
1.25.13
1
udhos/k8s-mutating-admission-webhook:1.15.1e588db500edf
stdlib@go1.26.3
1.25.13
1
udhos/kubecache:0.14.1f44ef986df49
stdlib@go1.26.5
1.25.13
1
udhos/lambdaping:1.0.46bd2cf2ac732
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
udhos/miniapi:1.3.28a7042db82ce
stdlib@go1.23.2
1.25.13
1
udhos/mongoping:1.3.103b08b63f524
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.55.0
1.25.13
1
udhos/prime:1.0.0e432012dd34a
stdlib@go1.20.4
1.25.13
1
udhos/rabbitping:1.3.0474c467bbf42
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
1
udhos/redis-enforce-expire:1.0.0615b6a7d742e
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.55.0
1.25.13
1
udhos/secrets:1.0.6daa2b4eaac09
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1
udhos/snsping:1.2.96ae70677b6a3
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
udhos/sqs-to-sns:2.0.15cf7979da82e1
stdlib@go1.26.3
1.25.13
1
udhos/token-server:1.0.9728013f2fac1
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.55.0
1.25.13
1
uffizzi/uffizzi-cluster-operator:v1.4.514e528bbd926
golang.org/x/net@v0.8.0
stdlib@go1.19.13
0.55.0
1.25.13
1
uffizzi/uffizzi-cluster-operator:v1.6.55ca448a08783
golang.org/x/net@v0.8.0
stdlib@go1.19.13
0.55.0
1.25.13
1
uptrace/uptrace:2.0.234a02c3b2d12
golang.org/x/net@v0.42.0
stdlib@go1.24.10
0.55.0
1.25.13
1
utho/utho-app-operator:0.1.46e8a690e8b7a
golang.org/x/net@v0.26.0
stdlib@go1.22.8
0.55.0
1.25.13
1
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17
0.55.0
1.25.13
1
v2fly/v2fly-core:latestd06727b221fe
golang.org/x/net@v0.46.0
stdlib@go1.24.2
0.55.0
1.25.13
1
vearch/vearch:3.3.40768af33f9d9
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.55.0
1.25.13
1
veecode/devportala72cf5cb47b8
golang.org/x/net@v0.48.0
stdlib@go1.26.4
0.55.0
1.25.13
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.55.0
1.25.13
1
velero/velero:v1.9.0277fbfaf8dcf
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.18
0.55.0
1.25.13
1
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.55.0
1.25.13
1
velero/velero:v1.18.0e4d1e79be2ee
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
1
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.11
0.55.0
1.25.13
1
velero/velero-plugin-for-aws:v1.14.07e82f717f44e
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
1
venturenox/redis:latest83b471c193ba
stdlib@go1.22.9
1.25.13
1
venturenox/sagawise:latestc11d32f18718
stdlib@go1.22.2
1.25.13
1
versity/versitygw:v1.0.145192635d0353
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
1
versity/versitygw:v1.6.0d6ec798f66ca
stdlib@go1.26.4
1.25.13
1
versity/versitygw:v1.1.0f730e0dbc1ef
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.55.0
1.25.13
1
vespaengine/vespa:8.526.1569b160f58211
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1
victoriametrics/operator:v0.65.0716b89a3ed79
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.55.0
1.25.13
1
victoriametrics/operator:v0.47.271be93cfafb6
golang.org/x/net@v0.26.0
stdlib@go1.23.0
0.55.0
1.25.13
1
victoriametrics/operator:v0.68.3f52e1bd679cb
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
victoriametrics/victoria-logs:v1.15.0-victorialogsd7435244eb19
stdlib@go1.24.0
1.25.13
1
victoriametrics/victoria-metrics:v1.93.577a9815d0640
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.