StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,643
of 17,821 indexed, latest versions
Container images
5,380
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,643 of 17,821 indexed charts deploy, on 5,380 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,337
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,758
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,643 by stars
ChartLatestAffected imagesRadar Score
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.25.13

Open the chart page →

1,756
wireguardalexpressoVerified publisher0.1.71 of 2See more

wireguard alexpresso 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
linuxserver/wireguard:latestdca67384e3e9
golang.org/x/net@v0.47.0
0.55.0

Open the chart page →

478
gotifyalexvanderberkelVerified publisher0.7.11 of 1See more

gotify alexvanderberkel 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/gotify/server:3.1.144fc5bbd1c06
stdlib@go1.26.0
1.25.13

Open the chart page →

320
alibaba-rsocket-brokeralibaba-rsocket-brokerVerified publisher0.1.31 of 1See more

alibaba-rsocket-broker alibaba-rsocket-broker 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17.7
0.55.0
1.25.13

Open the chart page →

92,754
alluredeckalluredeckVerified publisher0.24.01 of 2See more

alluredeck alluredeck 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
stdlib@go1.26.4
1.25.13

Open the chart page →

1,301
book-serveral-masood-helm-charts0.1.01 of 1See more

book-server al-masood-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
almasood/book-server:latest6ffac9b63cdf
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

494
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.15
0.55.0
1.25.13

Open the chart page →

2,116
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

572
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

572
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

1,152
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
golang.org/x/net@v0.34.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

549
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.55.0
1.25.13
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.55.0
1.25.13

Open the chart page →

4,577
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

590
versitygwalpineworks0.1.21 of 1See more

versitygw alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
versity/versitygw:v1.0.145192635d0353
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

1,261
versitygw-webhook-pulsar-proxyalpineworks0.1.11 of 1See more

versitygw-webhook-pulsar-proxy alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

908
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,287
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.55.0
1.25.13
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
stdlib@go1.19.13
0.55.0
1.25.13
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.55.0
1.25.13
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.55.0
1.25.13
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.55.0
1.25.13
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.55.0
1.25.13
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13

Open the chart page →

28,438
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.55.0
1.25.13

Open the chart page →

1,607
anchore-admission-controlleranchore-charts0.9.01 of 2See more

anchore-admission-controller anchore-charts 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.55.0
1.25.13

Open the chart page →

7,547
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.55.0
1.25.13

Open the chart page →

1,326
cert-manager-webhook-inwxandibraeuVerified publisher0.9.01 of 1See more

cert-manager-webhook-inwx andibraeu 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

607
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

5,814
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
golang.org/x/net@v0.35.0
stdlib@go1.26.4
0.55.0
1.25.13

Open the chart page →

1,300
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,287
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

1,986
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.25.13

Open the chart page →

2,240
dnsmadeeasy-webhookangelnu6.0.71 of 1See more

dnsmadeeasy-webhook angelnu 6.0.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/angelnu/dnsmadeeasy-webhook:v1.9.0a5ca158b1f02
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.55.0
1.25.13

Open the chart page →

818
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.25.13

Open the chart page →

118,418
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
golang.org/x/net@v0.34.0
stdlib@go1.23.12
0.55.0
1.25.13

Open the chart page →

919
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.55.0
1.25.13

Open the chart page →

2,496
ddosifyanteonVerified publisher1.7.55 of 13See more

ddosify anteon 1.7.5

5 of the 13 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.55.0
1.25.13
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.55.0
1.25.13
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.55.0
1.25.13
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.13
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
stdlib@go1.19.11
0.55.0
1.25.13

Open the chart page →

26,169
antmediaantmediaVerified publisher3.1.03 of 4See more

antmedia antmedia 3.1.0

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:8.002a0cc7939f5
stdlib@go1.26.5
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.55.0
1.25.13

Open the chart page →

4,644
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.55.0
1.25.13

Open the chart page →

3,324
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:latestac461fb352ab
golang.org/x/net@v0.51.0
stdlib@go1.26.4
0.55.0
1.25.13

Open the chart page →

2,336
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.55.0
1.25.13

Open the chart page →

2,732
glauthanza-labsVerified publisher1.0.11 of 1See more

glauth anza-labs 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/glauth/glauth:v2.5.209c782ca5984
golang.org/x/net@v0.17.0
stdlib@go1.25.0
0.55.0
1.25.13

Open the chart page →

1,245
apipingapiping1.5.01 of 1See more

apiping apiping 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
udhos/apiping:1.5.041ab9bae6f3b
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13

Open the chart page →

1,151
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/net@v0.25.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

2,997
api-usage-cleanerapi-usage-cleaner1.16.01 of 1See more

api-usage-cleaner api-usage-cleaner 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.25.13

Open the chart page →

596
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.13
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.13

Open the chart page →

19,832
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.5
0.55.0
1.25.13
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.55.0
1.25.13
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

12,568
app-movies-seriesapp-movies-seriesVerified publisher0.1.01 of 2See more

app-movies-series app-movies-series 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.25.13

Open the chart page →

3,170
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

2,635
aceappscodeVerified publisher2026.9.112 of 2See more

ace appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

2,937
ace-installerappscodeVerified publisher2026.9.112 of 2See more

ace-installer appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.55.0
1.25.13
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

3,293
ace-installer-certifiedappscodeVerified publisher2026.9.112 of 2See more

ace-installer-certified appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.55.0
1.25.13
ghcr.io/appscode/b3:v2026.9.1178a9fb785ec5
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

3,143
acerproxyappscodeVerified publisher2026.9.111 of 1See more

acerproxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

1,332
aceshifterappscodeVerified publisher2026.9.111 of 1See more

aceshifter appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/aceshifter:v0.0.3e5f5c254a55a
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

1,046
appcatalogappscodeVerified publisher2023.3.231 of 1See more

appcatalog appscode 2023.3.23

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/appscode/appcatalog:v0.0.109709a346888
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

1,670
appscode-otel-stackappscodeVerified publisher2026.7.153 of 3See more

appscode-otel-stack appscode 2026.7.15

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.150.089490ef63b72
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.55.0
1.25.13

Open the chart page →

1,460

Container images carrying it

5,380 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
1
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
1
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/net@v0.26.0
stdlib@go1.20.2
0.55.0
1.25.13
1
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/net@v0.23.0
stdlib@go1.25.11
0.55.0
1.25.13
1
ghcr.io/appscode/virtual-secrets-server:v0.4.0efa03f4c9551
stdlib@go1.25.12
1.25.13
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.55.0
1.25.13
1
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.55.0
1.25.13
1
ghcr.io/argonix-io/argonix-api:1.0.0951622ae173b
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.55.0
1.25.13
1
ghcr.io/argonix-io/argonix-api-frontend:1.0.0593c1b0f73cb
stdlib@go1.23.12
1.25.13
1
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
1
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1
ghcr.io/ashvinbambhaniya/nexus-tasks-backend:2.0.0f80349eb018b
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.55.0
1.25.13
1
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.55.0
1.25.13
1
ghcr.io/astradns/astradns-operator:v0.2.909e58b62416a
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.55.0
1.25.13
1
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13
1
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.55.0
1.25.13
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.25.13
1
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.55.0
1.25.13
1
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.25.13
1
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
golang.org/x/net@v0.28.0
stdlib@go1.22.6
0.55.0
1.25.13
1
ghcr.io/atolat/open-cache:latestd6105dd73eb4
stdlib@go1.25.8
1.25.13
1
ghcr.io/atrox/alertmanager-discord:v1.0.0ac011a4b6df1
stdlib@go1.20.5
1.25.13
1
ghcr.io/attestkeep/attestkeep-k8s:1.1.110ce4cac41c4
stdlib@go1.26.4
1.25.13
1
ghcr.io/aureum-cloud/cloudflare-ddns:latestaeb75d1605f4
stdlib@go1.23.12
1.25.13
1
ghcr.io/aureum-cloud/frp-operator:v1.0.196b01d7e7025
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13
1
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.55.0
1.25.13
1
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
1
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
golang.org/x/net@v0.26.0
stdlib@go1.22.1
0.55.0
1.25.13
1
ghcr.io/automation64/toolbox/oraclelinux-9-toolbox:latest7af2216c7b9e
golang.org/x/net@v0.52.0
stdlib@go1.26.4
0.55.0
1.25.13
1
ghcr.io/avistotelecom/kubebrowser:0.10.0a354b8dc7e6a
golang.org/x/net@v0.47.0
stdlib@go1.24.1
0.55.0
1.25.13
1
ghcr.io/axonops/axonops-developer-operator:v0.1.0b3d6600c8ba5
golang.org/x/net@v0.25.0
stdlib@go1.22.10
0.55.0
1.25.13
1
ghcr.io/axonops/axonops-operator:0.1.0e0cdb993f0b1
golang.org/x/net@v0.51.0
stdlib@go1.25.9
0.55.0
1.25.13
1
ghcr.io/b100to/idle-reaper:0.1.447b4a0e091f0
golang.org/x/net@v0.49.0
0.55.0
1
ghcr.io/bamaas/gofit:0.0.132b6a174b419
stdlib@go1.22.11
1.25.13
1
ghcr.io/bank-vaults/bank-vaults:v1.33.198b6ea2ed319
stdlib@go1.26.3
1.25.13
1
ghcr.io/bank-vaults/vault-secrets-webhook:v1.23.198baf045a1c9
stdlib@go1.26.4
1.25.13
1
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
golang.org/x/net@v0.8.0
stdlib@go1.19.11
0.55.0
1.25.13
1
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.6
0.55.0
1.25.13
1
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.9
0.55.0
1.25.13
1
ghcr.io/banzaicloud/log-socket:latesta514736d2d4d
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.18.6
0.55.0
1.25.13
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/net@v0.30.0
stdlib@go1.22.10
0.55.0
1.25.13
1
ghcr.io/bbdsoftware/litellm-operator:1.1.2167a51113d90
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.55.0
1.25.13
1
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.55.0
1.25.13
1
ghcr.io/behappy-project/behappy-tencentcloud-exporter:0.1.3a0ba56e1501b
stdlib@go1.21.13
1.25.13
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/net@v0.10.0
stdlib@go1.20.8
0.55.0
1.25.13
1
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.2
0.55.0
1.25.13
1
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
stdlib@go1.26.3
1.25.13
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10b6373349a301
golang.org/x/net@v0.43.0
stdlib@go1.23.6
0.55.0
1.25.13
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13
1
ghcr.io/bitwarden/admin:2026.9.05686674f2c35
stdlib@go1.26.5
1.25.13
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.