StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,607
of 17,828 indexed, latest versions
Container images
5,326
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,607 of 17,828 indexed charts deploy, on 5,326 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,287
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,735
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,607 by stars
ChartLatestAffected imagesRadar Score
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.55.0
1.25.13

Open the chart page →

2,488
go-ocpp-serverloafoe0.2.11 of 1See more

go-ocpp-server loafoe 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/go-ocpp-server:v0.2.145bb960674ab
stdlib@go1.21.13
1.25.13

Open the chart page →

399
mcp-notifierloafoe0.2.01 of 1See more

mcp-notifier loafoe 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/mcp-notifier:v0.2.0ea958b832415
stdlib@go1.26.4
1.25.13

Open the chart page →

72
mt-mcp-grafanaloafoe0.10.02 of 2See more

mt-mcp-grafana loafoe 0.10.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/mcp-grafana:0.14.042f541f22063
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.55.0
1.25.13
ghcr.io/loafoe/mt-mcp-grafana:v0.1.12332d9b47475
stdlib@go1.26.2
1.25.13

Open the chart page →

1,989
mt-mcp-proxyloafoe0.3.01 of 2See more

mt-mcp-proxy loafoe 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/mt-mcp-proxy:v0.1.0221835f9340f
stdlib@go1.26.4
1.25.13

Open the chart page →

505
otlp-gatewayloafoe0.0.22 of 2See more

otlp-gateway loafoe 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/jimmidyson/configmap-reload:v0.13.1ca0c14eef541
stdlib@go1.22.4
1.25.13
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
golang.org/x/net@v0.27.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

2,180
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.55.0
1.25.13

Open the chart page →

4,915
picoclawloafoe0.1.11 of 2See more

picoclaw loafoe 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/picoclaw:v0.0.1942e1b6862913
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

479
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.55.0
1.25.13

Open the chart page →

2,126
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.55.0
1.25.13

Open the chart page →

2,038
local-path-exporterlocal-path-exporterVerified publisher0.2.31 of 1See more

local-path-exporter local-path-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/tmusial99/local-path-exporter:1.1.082476692c680
stdlib@go1.26.4
1.25.13

Open the chart page →

68
weather-app-chartlocal-weatherapp0.1.02 of 4See more

weather-app-chart local-weatherapp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:8.0.36-debian-11-r38aad73aa0c6d
stdlib@go1.21.6
1.25.13
youssef11gaber10/deployment-auth-go:latest6597b26959d2
golang.org/x/net@v0.10.0
stdlib@go1.26.1
0.55.0
1.25.13

Open the chart page →

5,916
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,521
locust-pluginslocust-pluginsVerified publisher0.0.42 of 3See more

locust-plugins locust-plugins 0.0.4

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.55.0
1.25.13
sky5367/locust-plugins-timescale:latestd3150f201471
stdlib@go1.18.7
1.25.13

Open the chart page →

7,513
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

33,946
central-hostpath-mapperloftVerified publisher0.2.91 of 1See more

central-hostpath-mapper loft 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
golang.org/x/net@v0.26.0
stdlib@go1.23.2
0.55.0
1.25.13

Open the chart page →

932
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/net@v0.21.0
stdlib@go1.20.10
0.55.0
1.25.13

Open the chart page →

3,242
devspace-cloudloftVerified publisher0.3.32 of 8See more

devspace-cloud loft 0.3.3

2 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.55.0
1.25.13
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.13

Open the chart page →

9,892
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.7
0.55.0
1.25.13

Open the chart page →

3,096
license-serverloftVerified publisher0.6.01 of 1See more

license-server loft 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
golang.org/x/net@v0.53.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

804
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/net@v0.6.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

2,461
loft-direct-cluster-endpointloftVerified publisher1.14.01 of 1See more

loft-direct-cluster-endpoint loft 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

3,120
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.55.0
1.25.13

Open the chart page →

3,242
vcluster-headloftVerified publisher0.0.0-035ec6e1 of 2See more

vcluster-head loft 0.0.0-035ec6e

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/kubernetes:v1.35.090097a08b87c
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.55.0
1.25.13

Open the chart page →

1,309
vcluster-hpmloftVerified publisher0.2.71 of 1See more

vcluster-hpm loft 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-hpm:0.2.7f65f6810ea23
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

841
vcluster-proloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
stdlib@go1.19.4
0.55.0
1.25.13
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

5,144
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.104 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.55.0
1.25.13
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.55.0
1.25.13
public.ecr.aws/eks-distro/kubernetes/kube-apiserver:v1.24.9-eks-1-24-772e06b605692
stdlib@go1.18.9
1.25.13
public.ecr.aws/eks-distro/kubernetes/kube-controller-manager:v1.24.9-eks-1-24-7eaea8c230432
stdlib@go1.18.9
1.25.13

Open the chart page →

5,988
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.55.0
1.25.13
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

5,828
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.104 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.55.0
1.25.13
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.55.0
1.25.13
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.55.0
1.25.13
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.55.0
1.25.13

Open the chart page →

8,286
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.55.0
1.25.13

Open the chart page →

2,994
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
golang.org/x/net@v0.46.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

2,546
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,504
nightingalelogic3579Verified publisher0.3.13 of 6See more

nightingale logic3579 0.3.1

3 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.55.0
1.25.13
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.55.0
1.25.13

Open the chart page →

9,105
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,511
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
stdlib@go1.22.5
1.25.13

Open the chart page →

6,623
apica-ascentlogiqai2.0.47 of 19See more

apica-ascent logiqai 2.0.4

7 of the 19 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.55.0
1.25.13
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.18.9
0.55.0
1.25.13
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.7
0.55.0
1.25.13
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.55.0
1.25.13
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.55.0
1.25.13
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.8
0.55.0
1.25.13
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.9
0.55.0
1.25.13

Open the chart page →

23,824
logtidelogtideVerified publisher2.1.141 of 4See more

logtide logtide 2.1.14

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg156343bdc87ca1
stdlib@go1.24.6
1.25.13

Open the chart page →

2,823
loki-proxyloki-proxyVerified publisher0.4.11 of 1See more

loki-proxy loki-proxy 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/peak-scale/observability-tenancy/loki-proxy:0.4.1548e962d0061
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

789
corednslovemew67Verified publisher1.36.01 of 1See more

coredns lovemew67 1.36.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
coredns/coredns:1.11.39caabbf6238b
golang.org/x/net@v0.25.0
stdlib@go1.21.11
0.55.0
1.25.13

Open the chart page →

1,183
oncall-hobbylovemew67Verified publisher0.0.51 of 2See more

oncall-hobby lovemew67 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:7.0.15352c1fdadc91
stdlib@go1.18.2
1.25.13

Open the chart page →

5,911
loxilbloxilbVerified publisher0.1.02 of 2See more

loxilb loxilb 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.55.0
1.25.13
ghcr.io/loxilb-io/loxilb:latesta475b43946b3
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

4,440
lsdisklsdiskVerified publisher2.0.73 of 4See more

lsdisk lsdisk 2.0.7

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
golang.org/x/net@v0.25.0
stdlib@go1.22.5
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.55.0
1.25.13

Open the chart page →

5,016
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

2,350
fireflylsst-sqre0.3.71 of 2See more

firefly lsst-sqre 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:5fc5ecd863862
stdlib@go1.16.7
1.25.13

Open the chart page →

1,732
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.17.2
0.55.0
1.25.13
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

9,350
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.5
0.55.0
1.25.13

Open the chart page →

6,595
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

3,775
filebrowserluiscajl0.0.11 of 1See more

filebrowser luiscajl 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
filebrowser/filebrowser:latesta469ea076d4a
stdlib@go1.26.5
1.25.13

Open the chart page →

133
plex-rclone-wireguardluiscajl1.0.191 of 2See more

plex-rclone-wireguard luiscajl 1.0.19

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
stdlib@go1.26.5
1.25.13

Open the chart page →

876
xteveluiscajl0.1.61 of 1See more

xteve luiscajl 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dnsforge/xteve:latest4d9a685c8c28
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.16.2
0.55.0
1.25.13

Open the chart page →

4,316

Container images carrying it

5,326 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.6
0.55.0
1.25.13
1
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.55.0
1
ghcr.io/defensia/agent:1.4.57e9d40ae44711
golang.org/x/net@v0.47.0
0.55.0
1
ghcr.io/deliveryhero/field-exporter:v1.4.06b71ba4f9297
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.55.0
1.25.13
1
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
golang.org/x/net@v0.48.0
stdlib@go1.25.10
0.55.0
1.25.13
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
stdlib@go1.24.4
1.25.13
1
ghcr.io/desuuuu/cluster-network-policy-operator:v1.1.0d943d13c5281
stdlib@go1.26.0
1.25.13
1
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.55.0
1.25.13
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
golang.org/x/net@v0.25.0
stdlib@go1.20.14
0.55.0
1.25.13
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
stdlib@go1.25.4
1.25.13
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.55.0
1.25.13
1
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.17
0.55.0
1.25.13
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
stdlib@go1.16.6
1.25.13
1
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
golang.org/x/net@v0.37.0
stdlib@go1.24.3
0.55.0
1.25.13
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.2
0.55.0
1.25.13
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.55.0
1.25.13
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.55.0
1.25.13
1
ghcr.io/dexidp/dex:v2.38.0b1d793440a98
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.55.0
1.25.13
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/net@v0.11.0
stdlib@go1.19.6
0.55.0
1.25.13
1
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
1
ghcr.io/dirien/minecraft-exporter:0.24.061d89bf99ff7
golang.org/x/net@v0.51.0
stdlib@go1.25.10
0.55.0
1.25.13
1
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.55.0
1.25.13
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
stdlib@go1.17.5
0.55.0
1.25.13
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/net@v0.10.0
stdlib@go1.21.0
0.55.0
1.25.13
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.25.13
1
ghcr.io/dntosas/capi2argo-cluster-operator:v1.5.0fb8c6457ef6e
golang.org/x/net@v0.40.0
stdlib@go1.25.6
0.55.0
1.25.13
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.55.0
1.25.13
1
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
stdlib@go1.18.1
1.25.13
1
ghcr.io/donkie/spoolman:0.24.042135965c42d
stdlib@go1.19.8
1.25.13
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.8
0.55.0
1.25.13
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.16.15
0.55.0
1.25.13
1
ghcr.io/doodlescheduling/saml-exporter:v0.5.03d5a99841bc2
stdlib@go1.22.3
1.25.13
1
ghcr.io/douban/aliyun-exporter:mainb7c694331362
stdlib@go1.24.2
1.25.13
1
ghcr.io/douban/qiniu-exporter:maind1da3bcfad7d
stdlib@go1.19.5
1.25.13
1
ghcr.io/douban/ucloud-exporter:mainb4bb8a9021a2
stdlib@go1.24.2
1.25.13
1
ghcr.io/douban/upyun-exporter:main6810900c9c4a
stdlib@go1.25.5
1.25.13
1
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.55.0
1.25.13
1
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
stdlib@go1.25.12
1.25.13
1
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
golang.org/x/net@v0.35.0
stdlib@go1.26.3
0.55.0
1.25.13
1
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.55.0
1.25.13
1
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
stdlib@go1.26.5
1.25.13
1
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
stdlib@go1.16.12
1.25.13
1
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
stdlib@go1.22.2
1.25.13
1
ghcr.io/edgelesssys/continuum/continuum-proxy24c76f294a80
golang.org/x/net@v0.32.0
stdlib@go1.23.3
0.55.0
1.25.13
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.55.0
1.25.13
1
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
stdlib@go1.26.1
1.25.13
1
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.55.0
1.25.13
1
ghcr.io/element-hq/ess-helm/matrix-tools:0.3.20eac0521be29
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.55.0
1.25.13
1
ghcr.io/element-hq/lk-jwt-service:0.6.0822f0c03a3bd
stdlib@go1.26.4
1.25.13
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
stdlib@go1.19.8
1.25.13
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.