StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,643
of 17,821 indexed, latest versions
Container images
5,380
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,643 of 17,821 indexed charts deploy, on 5,380 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,337
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,758
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,643 by stars
ChartLatestAffected imagesRadar Score
grgatefikaworks0.3.41 of 1See more

grgate fikaworks 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
stdlib@go1.20.2
1.25.13

Open the chart page →

1,080
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
golang.org/x/net@v0.25.0
stdlib@go1.19.13
0.55.0
1.25.13

Open the chart page →

7,853
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
stdlib@go1.24.6
1.25.13

Open the chart page →

7,914
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

5,841
first-matefirst-mateVerified publisher1.0.51 of 1See more

first-mate first-mate 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
chriswells0/first-mate:1.0.5f3918ec8471c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

1,723
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:3.6.213e51da56fc54
stdlib@go1.15.1
1.25.13

Open the chart page →

113,233
dsba-pdpfiware0.1.22 of 2See more

dsba-pdp fiware 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
golang.org/x/net@v0.1.0
stdlib@go1.18.10
0.55.0
1.25.13
quay.io/wi_stefan/dsba-db-migrations:0.0.125b986cd14a08
stdlib@go1.18.9
1.25.13

Open the chart page →

4,106
endpoint-auth-servicefiware0.1.43 of 4See more

endpoint-auth-service fiware 0.1.4

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.3
0.55.0
1.25.13
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.55.0
1.25.13
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
stdlib@go1.18.5
1.25.13

Open the chart page →

11,852
vcverifierfiware4.12.261 of 1See more

vcverifier fiware 4.12.26

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/fiware/vcverifier:6.21.251ed1e979094
golang.org/x/net@v0.38.0
0.55.0

Open the chart page →

559
grafanaflagger1.7.01 of 1See more

grafana flagger 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.5
0.55.0
1.25.13

Open the chart page →

3,374
podinfoflagger6.1.41 of 1See more

podinfo flagger 6.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.9
0.55.0
1.25.13

Open the chart page →

2,817
apm-hubflanksourceVerified publisher0.0.472 of 2See more

apm-hub flanksource 0.0.47

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.55.0
1.25.13
library/postgres:14816cf7d06ec3
stdlib@go1.24.6
1.25.13

Open the chart page →

5,794
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
golang.org/x/net@v0.41.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

5,545
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
stdlib@go1.20.7
1.25.13

Open the chart page →

4,633
facetflanksourceVerified publisher0.1.721 of 1See more

facet flanksource 0.1.72

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.7237237038be15
stdlib@go1.23.12
1.25.13

Open the chart page →

21,582
flanksource-uiflanksourceVerified publisher1.4.3191 of 1See more

flanksource-ui flanksource 1.4.319

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.319953948a194c9
stdlib@go1.23.5
1.25.13

Open the chart page →

2,617
mission-controlflanksourceVerified publisher0.1.3383 of 8See more

mission-control flanksource 0.1.338

3 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.55.0
1.25.13
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
stdlib@go1.23.5
1.25.13
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.55.0
1.25.13

Open the chart page →

9,061
mission-control-tenantflanksourceVerified publisher1.0.923 of 3See more

mission-control-tenant flanksource 1.0.92

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
golang.org/x/net@v0.7.0
stdlib@go1.17.13
0.55.0
1.25.13
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.55.0
1.25.13
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.55.0
1.25.13

Open the chart page →

5,726
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

5,841
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13

Open the chart page →

4,045
floating-serverfloating-server1.6.31 of 2See more

floating-server floating-server 1.6.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
censedata/floating-server:v1.6.3ebfffb9dd4c0
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

1,598
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.13

Open the chart page →

8,070
fluent-operatorfluent-operatorVerified publisher0.1.01 of 2See more

fluent-operator fluent-operator 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubesphere/fluent-operator:v1.0.2702df77228c6
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

2,632
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

3,531
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
golang.org/x/net@v0.41.0
stdlib@go1.25.9
0.55.0
1.25.13

Open the chart page →

2,450
fluxer-helmfluxer-helm0.3.04 of 18See more

fluxer-helm fluxer-helm 0.3.0

4 of the 18 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:4.346620371e8af8
golang.org/x/net@v0.54.0
stdlib@go1.25.11
0.55.0
1.25.13
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.25.13
livekit/livekit-server:v1.12.0b1281e66e35e
golang.org/x/net@v0.53.0
stdlib@go1.26.4
0.55.0
1.25.13
ghcr.io/fluxerapp/fluxer-static:2026.812.125337cfe98ae544df
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.55.0
1.25.13

Open the chart page →

27,662
flyte-depsflyte1.16.81 of 3See more

flyte-deps flyte 1.16.8

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.1
0.55.0
1.25.13

Open the chart page →

2,246
flyte-devboxflyte0.1.07 of 13See more

flyte-devbox flyte 0.1.0

7 of the 13 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.55.0
1.25.13
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

4,672
csp-reporterfoomoVerified publisher2.2.01 of 1See more

csp-reporter foomo 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
foomo/csp-reporter:1.3.0e436da524785
stdlib@go1.18
1.25.13

Open the chart page →

1,409
forkliftforklift0.1.42 of 2See more

forklift forklift 0.1.4

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
wuhan005/forklift:daemon4e6da210e449
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.55.0
1.25.13
wuhan005/forklift:controllerbfbe82d59850
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.55.0
1.25.13

Open the chart page →

1,816
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

4,682
forwardforward1.3.11 of 1See more

forward forward 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
udhos/forward:1.1.312e120d39fdb
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

2,215
maxscalefour-allportalVerified publisher4.1.162 of 3See more

maxscale four-allportal 4.1.16

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:10.6.12-debian-11-r1643a70df0e7c6
stdlib@go1.19.7
1.25.13
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.8
0.55.0
1.25.13

Open the chart page →

6,614
readium-lcpserverfpetr0.0.51 of 3See more

readium-lcpserver fpetr 0.0.5

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
golang.org/x/net@v0.17.0
stdlib@go1.22.0
0.55.0
1.25.13

Open the chart page →

1,373
readium-lsdserverfpetr0.0.11 of 2See more

readium-lsdserver fpetr 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
golang.org/x/net@v0.17.0
stdlib@go1.22.0
0.55.0
1.25.13

Open the chart page →

1,373
ff-testfrankframework0.7.61 of 2See more

ff-test frankframework 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
stdlib@go1.24.6
1.25.13

Open the chart page →

1,809
frank2examplefrankframework0.7.41 of 2See more

frank2example frankframework 0.7.4

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
stdlib@go1.24.6
1.25.13

Open the chart page →

1,809
free5gc-amffree5gc-amfVerified publisher0.1.31 of 1See more

free5gc-amf free5gc-amf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

903
free5gc-ausffree5gc-ausfVerified publisher0.1.31 of 1See more

free5gc-ausf free5gc-ausf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

911
free5gc-chffree5gc-chfVerified publisher0.1.31 of 1See more

free5gc-chf free5gc-chf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

1,004
free5gc-nrffree5gc-nrfVerified publisher0.1.31 of 1See more

free5gc-nrf free5gc-nrf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

920
free5gc-nssffree5gc-nssfVerified publisher0.1.31 of 1See more

free5gc-nssf free5gc-nssf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

911
free5gc-pcffree5gc-pcfVerified publisher0.1.31 of 1See more

free5gc-pcf free5gc-pcf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

904
free5gc-smffree5gc-smfVerified publisher0.1.31 of 1See more

free5gc-smf free5gc-smf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

919
free5gc-udmfree5gc-udmVerified publisher0.1.31 of 1See more

free5gc-udm free5gc-udm 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/udm:v3.4.32f68df062a50
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

911
free5gc-udrfree5gc-udrVerified publisher0.1.31 of 1See more

free5gc-udr free5gc-udr 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

920
free5gc-upffree5gc-upfVerified publisher0.1.31 of 1See more

free5gc-upf free5gc-upf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/upf:v3.4.3b6b362a39fdd
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

1,075
free5gc-webuifree5gc-webuiVerified publisher0.1.31 of 1See more

free5gc-webui free5gc-webui 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

1,257
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
pschiffe/pdns-mysql:alpined196c796cafb
stdlib@go1.21.5
1.25.13

Open the chart page →

1,960
aptlyg0dscookie0.4.01 of 2See more

aptly g0dscookie 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
stdlib@go1.18.3
1.25.13

Open the chart page →

3,483

Container images carrying it

5,380 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/bitwarden/api:2026.9.0d5964b4c9563
stdlib@go1.26.5
1.25.13
1
ghcr.io/bitwarden/attachments:2026.9.0f019c2d14ca7
stdlib@go1.26.5
1.25.13
1
ghcr.io/bitwarden/events:2026.9.0ffb067562d07
stdlib@go1.26.5
1.25.13
1
ghcr.io/bitwarden/icons:2026.9.013d351a6cb08
stdlib@go1.26.5
1.25.13
1
ghcr.io/bitwarden/identity:2026.9.090453408f338
stdlib@go1.26.5
1.25.13
1
ghcr.io/bitwarden/notifications:2026.9.051f843ae35e3
stdlib@go1.26.5
1.25.13
1
ghcr.io/bitwarden/sm-operator:2.1.0846624161f32
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.55.0
1.25.13
1
ghcr.io/bitwarden/sso:2026.9.09a2e89605b82
stdlib@go1.26.5
1.25.13
1
ghcr.io/bitwarden/web:2026.9.08aa9f4258378
stdlib@go1.26.5
1.25.13
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
golang.org/x/net@v0.8.0
stdlib@go1.17.1
0.55.0
1.25.13
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13
1
ghcr.io/blind-oracle/cortex-tenant:v2.0.09f8896ffc15b
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.55.0
1.25.13
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
stdlib@go1.25.7
1.25.13
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
stdlib@go1.25.6
1.25.13
1
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
stdlib@go1.25.10
1.25.13
1
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.55.0
1.25.13
1
ghcr.io/bodgit/nri-plugin-runtime:v0.0.3130c0b1b6fa3
stdlib@go1.26.4
1.25.13
1
ghcr.io/bojanzelic/cloudflare-zero-trust-operator:0.7.1f4b2dbc19a78
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.55.0
1.25.13
1
ghcr.io/borchero/switchboard:0.7.454a193b757da
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.55.0
1.25.13
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
stdlib@go1.23.5
1.25.13
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
stdlib@go1.21.6
1.25.13
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
1
ghcr.io/browsersec/kubebrowse:sha-09dfa1fb853e9e6372a
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
1
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.55.0
1.25.13
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
stdlib@go1.19.8
1.25.13
1
ghcr.io/buoyantio/linkerd-dashboard-server:0.11.1dd6a29588242
stdlib@go1.26.5
1.25.13
1
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
golang.org/x/net@v0.35.0
stdlib@go1.24.2
0.55.0
1.25.13
1
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1
ghcr.io/bytefork/payloadbox:0.0.73e0164e975b3
stdlib@go1.26.3
1.25.13
1
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.2
0.55.0
1.25.13
1
ghcr.io/caas-team/gokubedownscaler:1.3.4cea3dd2f1312
golang.org/x/net@v0.49.0
stdlib@go1.25.10
0.55.0
1.25.13
1
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1
ghcr.io/camilorivera/cert-manager-acm-sync:0.7.489a83796a550
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.55.0
1.25.13
1
ghcr.io/camptocamp/prometheus-puppetdb-sd:0.14.0414c0c99fd06
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.55.0
1.25.13
1
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13
1
ghcr.io/caninehq/canine:latesta058034ca006
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.55.0
1.25.13
1
ghcr.io/cedar2025/xboard:latest896e4926e0d7
stdlib@go1.25.10
1.25.13
1
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13
1
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.55.0
1.25.13
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/net@v0.27.0
stdlib@go1.23.0
0.55.0
1.25.13
1
ghcr.io/cerbos/cerbos:0.55.04b9d3b58c4f1
stdlib@go1.26.5
1.25.13
1
ghcr.io/cerbos/cerbos:0.51.08d35a64e4a99
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.55.0
1.25.13
1
ghcr.io/cfgate/cfgate:0.2.0-alpha.5c7025330acec
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
stdlib@go1.22.10
1.25.13
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
golang.org/x/net@v0.52.0
stdlib@go1.25.11
0.55.0
1.25.13
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
golang.org/x/net@v0.52.0
stdlib@go1.25.11
0.55.0
1.25.13
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
golang.org/x/net@v0.17.0
stdlib@go1.16.2
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.