StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,642
of 17,813 indexed, latest versions
Container images
5,366
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,642 of 17,813 indexed charts deploy, on 5,366 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+191 more1.25.135,324
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,744
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,642 by stars
ChartLatestAffected imagesRadar Score
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.55.0
1.25.13

Open the chart page →

10,817
local-path-provisionercontainerooVerified publisher0.0.381 of 1See more

local-path-provisioner containeroo 0.0.38

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.37e757967a5ec3
stdlib@go1.26.5
1.25.13

Open the chart page →

60
penpotpenpotOfficialVerified publisher1.9.03 of 4See more

penpot penpot 1.9.0

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
penpotapp/backend:2.17.2770b55f6e51b
stdlib@go1.26.5
1.25.13
penpotapp/exporter:2.17.272a8061e8806
stdlib@go1.26.5
1.25.13
penpotapp/mcp:2.17.284f3f07ead11
stdlib@go1.26.5
1.25.13

Open the chart page →

4,482
signozsignoz0.142.15 of 5See more

signoz signoz 0.142.1

5 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.55.0
1.25.13
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.55.0
1.25.13
signoz/signoz:v0.142.149501b04d77a
stdlib@go1.25.7
1.25.13
signoz/signoz-otel-collector:v0.144.1034ecb436b687
stdlib@go1.25.0
1.25.13
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.25.13

Open the chart page →

7,634
weblateweblateOfficialVerified publisher0.5.372 of 3See more

weblate weblate 0.5.37

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/redis:latest5927ff3702df
stdlib@go1.24.5
1.25.13
weblate/weblate:2026.9.1.1dc2d291144a2
stdlib@go1.26.5
1.25.13

Open the chart page →

6,772
tempografana-communityVerified publisher3.0.01 of 1See more

tempo grafana-community 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/tempo:3.0.30296560ac66f
stdlib@go1.26.5
1.25.13

Open the chart page →

172
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18.686c951e05bf5
stdlib@go1.24.6
1.25.13

Open the chart page →

1,270
keelkeel1.2.21 of 1See more

keel keel 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/keel-hq/keel:0.22.3315e188a07c2
stdlib@go1.26.5
1.25.13

Open the chart page →

821
community-operatormongodb-helm-charts0.13.01 of 1See more

community-operator mongodb-helm-charts 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

1,127
prometheus-kafka-exporterprometheus-communityVerified publisher4.0.01 of 1See more

prometheus-kafka-exporter prometheus-community 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

716
prometheus-mongodb-exporterprometheus-communityVerified publisher3.22.01 of 1See more

prometheus-mongodb-exporter prometheus-community 3.22.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
percona/mongodb_exporter:0.53.00214e482b2cd
stdlib@go1.26.2
1.25.13

Open the chart page →

240
node-local-dnsdeliveryheroVerified publisher2.9.21 of 1See more

node-local-dns deliveryhero 2.9.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
golang.org/x/net@v0.46.0
stdlib@go1.24.8
0.55.0
1.25.13

Open the chart page →

1,766
fission-allfission-chartsOfficialVerified publisher1.27.03 of 3See more

fission-all fission-charts 1.27.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/fission/fission-bundle:v1.27.0d353720b037a
stdlib@go1.26.4
1.25.13
ghcr.io/fission/pre-upgrade-checks:v1.27.0b053fc3539b4
stdlib@go1.26.4
1.25.13
ghcr.io/fission/reporter:v1.27.0c77cc925debe
stdlib@go1.26.4
1.25.13

Open the chart page →

318
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
stdlib@go1.19.8
1.25.13

Open the chart page →

4,850
rancherrancher-latest2.15.12 of 2See more

rancher rancher-latest 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/net@v0.52.0
stdlib@go1.26.5
0.55.0
1.25.13
rancher/shell:v0.8.1f293af9c635f
golang.org/x/net@v0.49.0
stdlib@go1.25.12
0.55.0
1.25.13

Open the chart page →

1,534
nacosygqygq2Verified publisher2.1.102 of 4See more

nacos ygqygq2 2.1.10

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.25.13
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.25.13

Open the chart page →

5,002
sealed-secretsbitnamiVerified publisher2.5.191 of 1See more

sealed-secrets bitnami 2.5.19

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

643
mariadbcloudpirates-mariadbVerified publisher0.16.151 of 1See more

mariadb cloudpirates-mariadb 0.16.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:13.0.2d4fdec0510ad
stdlib@go1.24.6
1.25.13

Open the chart page →

1,391
difydoubanVerified publisher0.10.04 of 6See more

dify douban 0.10.0

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.25.13
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.55.0
1.25.13
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.55.0
1.25.13
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.25.13

Open the chart page →

74,815
dragonflydragonflyVerified publisher1.8.52 of 3See more

dragonfly dragonfly 1.8.5

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
stdlib@go1.26.5
1.25.13
dragonflyoss/scheduler:v2.5.2d5dea9e662cd
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

4,178
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.4.02 of 3See more

kubeshark kubeshark-helm-charts 53.4.0

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kubeshark/hub:v53.46d3f22525a0e
stdlib@go1.26.5
1.25.13
kubeshark/worker:v53.4b226490dfa11
stdlib@go1.26.5
1.25.13

Open the chart page →

845
secrets-store-csi-driversecret-store-csi-driver1.6.13 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver-crds:v1.6.1cdacfdbe8966
stdlib@go1.26.5
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

1,824
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.11 of 2See more

stackgres-operator stackgres-charts 1.19.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.55.0
1.25.13

Open the chart page →

2,154
victoria-logs-singlevictoriametricsVerified publisher0.13.91 of 1See more

victoria-logs-single victoriametrics 0.13.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.52.047b820890d64
stdlib@go1.26.5
1.25.13

Open the chart page →

60
mongodbcloudpirates-mongodbVerified publisher0.18.141 of 1See more

mongodb cloudpirates-mongodb 0.18.14

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:8.3.115d7043a4ffe0
stdlib@go1.26.5
1.25.13

Open the chart page →

935
code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
stdlib@go1.16.4
1.25.13

Open the chart page →

16,375
opensearch-operatoropensearch-operatorVerified publisher3.0.21 of 1See more

opensearch-operator opensearch-operator 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
opensearchproject/opensearch-operator:3.0.0-alphaf78bbdd1a386
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.55.0
1.25.13

Open the chart page →

618
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
stdlib@go1.26.4
1.25.13

Open the chart page →

433
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
stdlib@go1.26.5
1.25.13

Open the chart page →

1,620
pulsarapache4.7.06 of 10See more

pulsar apache 4.7.0

6 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.55.0
1.25.13
victoriametrics/operator:v0.68.3f52e1bd679cb
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

9,950
miniocloudpirates-minioVerified publisher0.13.41 of 1See more

minio cloudpirates-minio 0.13.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

1,230
vertical-pod-autoscalercowboysysopVerified publisher11.1.14 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

4 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.55.0
1.25.13
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

7,012
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.25.13
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
stdlib@go1.26.5
1.25.13
langgenius/dify-api:1.16.1dcefa5f7c47c
stdlib@go1.26.4
1.25.13
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
stdlib@go1.26.4
1.25.13
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

64,141
eclipse-cheeclipse-cheVerified publisher7.122.01 of 1See more

eclipse-che eclipse-che 7.122.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
stdlib@go1.26.5
1.25.13

Open the chart page →

932
pyroscopegrafana2.3.12 of 3See more

pyroscope grafana 2.3.1

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
golang.org/x/net@v0.46.0
stdlib@go1.25.5
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.55.0
1.25.13

Open the chart page →

3,275
botkubeinfracloudioVerified publisher1.14.01 of 1See more

botkube infracloudio 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.55.0
1.25.13

Open the chart page →

1,104
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

874
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18-alpine6c538e7206ea
stdlib@go1.24.6
1.25.13

Open the chart page →

1,752
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.55.0
1.25.13

Open the chart page →

4,130
k6-operatorgrafana4.6.01 of 1See more

k6-operator grafana 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/grafana/k6-operator:controller-v1.6.0ba7f0fc1e22e
stdlib@go1.26.5
1.25.13

Open the chart page →

103
rabbitmqgroundhog2k2.3.91 of 2See more

rabbitmq groundhog2k 2.3.9

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.667bad329974a
stdlib@go1.22.2
1.25.13

Open the chart page →

824
k8tzk8tzOfficialVerified publisher0.20.01 of 1See more

k8tz k8tz 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/k8tz/k8tz:0.20.0361628e53fc8
stdlib@go1.25.12
1.25.13

Open the chart page →

49
kiali-serverkiali2.32.01 of 1See more

kiali-server kiali 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/kiali/kiali:v2.32.0b171d679be27
stdlib@go1.26.3
1.25.13

Open the chart page →

256
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
stdlib@go1.25.12
1.25.13

Open the chart page →

833
vela-corekubevela1.11.03 of 3See more

vela-core kubevela 1.11.0

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
oamdev/cluster-gateway:v1.9.0-alpha.25591e29d66a2
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.55.0
1.25.13
oamdev/kube-webhook-certgen:v2.4.1231c423c2b17
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.11
0.55.0
1.25.13
oamdev/vela-core:v1.11.095fa412c934e
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.55.0
1.25.13

Open the chart page →

4,604
oktetooktetoOfficialVerified publisher0.0.0-2026-08-177 of 10See more

okteto okteto 0.0.0-2026-08-17

7 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/okteto/backend:0.0.0-2026-08-17629bdce31b4d
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13
ghcr.io/okteto/buildkit:0.0.0-2026-08-1714527ca5d2a9
golang.org/x/net@v0.35.0
stdlib@go1.25.7
0.55.0
1.25.13
ghcr.io/okteto/daemon:0.0.0-2026-08-17c6e716a3fbbe
stdlib@go1.26.5
1.25.13
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-17265eedb3954b
stdlib@go1.26.4
1.25.13
ghcr.io/okteto/okteto:3.22.04585017f52f6
golang.org/x/net@v0.47.0
stdlib@go1.26.5
0.55.0
1.25.13
ghcr.io/okteto/registry:0.0.0-2026-08-1769131511501f
stdlib@go1.26.5
1.25.13
ghcr.io/okteto/reloader:0.0.0-2026-08-1704a3fce657c4
stdlib@go1.26.4
1.25.13

Open the chart page →

5,591
hydraory0.64.02 of 2See more

hydra ory 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.55.0
1.25.13
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
stdlib@go1.26.3
1.25.13

Open the chart page →

1,318
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
stdlib@go1.24.9
0.55.0
1.25.13

Open the chart page →

941
proxmox-csi-pluginproxmox-csi0.5.127 of 7See more

proxmox-csi-plugin proxmox-csi 0.5.12

7 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-csi-controller:v0.20.095ef74cce03e
stdlib@go1.26.5
1.25.13
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
stdlib@go1.26.5
1.25.13
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
stdlib@go1.26.3
1.25.13
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13

Open the chart page →

1,864
thanosthanos-communityOfficialVerified publisher0.44.01 of 1See more

thanos thanos-community 0.44.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
stdlib@go1.26.5
1.25.13

Open the chart page →

212

Container images carrying it

5,366 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/eumel8/rancher-servicemonitor:0.2.1f34428cac187
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.55.0
1.25.13
1
ghcr.io/evilgn0me/ingressmonitorcontroller:v0.0.50bbfa4db14b9
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
1
ghcr.io/exalsius/exalsius-operator:0.12.0d24a579a3c75
golang.org/x/net@v0.50.0
0.55.0
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.55.0
1.25.13
1
ghcr.io/external-secrets/external-secrets:v2.4.19440a40b3947
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
1
ghcr.io/external-secrets/external-secrets:v2.1.0ec40c3d9c48f
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.55.0
1.25.13
1
ghcr.io/fabioluciano/tekton-events-relay:0.10.184cb5a2b8b81
stdlib@go1.26.4
1.25.13
1
ghcr.io/fbuchner/meerkat-crm:1.7.0d513bdd3ae80
stdlib@go1.26.5
1.25.13
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.55.0
1.25.13
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.55.0
1.25.13
1
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.55.0
1.25.13
1
ghcr.io/ferretdb/ferretdb:2.7.05706414241eb
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.55.0
1.25.13
1
ghcr.io/ferro-labs/ai-gateway:1.2.0baa285ec0fc9
stdlib@go1.25.12
1.25.13
1
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
stdlib@go1.20.2
1.25.13
1
ghcr.io/firecrawl/firecrawl:2.11.35987ebe1dc85b0
golang.org/x/net@v0.41.0
stdlib@go1.26.4
0.55.0
1.25.13
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
stdlib@go1.24.6
1.25.13
1
ghcr.io/fission/fission-bundle:v1.27.0d353720b037a
stdlib@go1.26.4
1.25.13
1
ghcr.io/fission/pre-upgrade-checks:v1.27.0b053fc3539b4
stdlib@go1.26.4
1.25.13
1
ghcr.io/fission/reporter:v1.27.0c77cc925debe
stdlib@go1.26.4
1.25.13
1
ghcr.io/fjogeleit/trivy-operator-polr-adapter:0.11.537029b4d464f
stdlib@go1.26.4
1.25.13
1
ghcr.io/flanksource/facet:0.1.7237237038be15
stdlib@go1.23.12
1.25.13
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.55.0
1.25.13
1
ghcr.io/flannel-io/flannel:v0.28.9708a2c9c1cfb
stdlib@go1.26.5
1.25.13
1
ghcr.io/flannel-io/flannel-cni-plugin:v1.9.1-flannel39fccdf677e6e
stdlib@go1.26.5
1.25.13
1
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.55.0
1.25.13
1
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.55.0
1.25.13
1
ghcr.io/flohansen/dasher-server:latest7cde8c3fa2d1
golang.org/x/net@v0.22.0
stdlib@go1.22.5
0.55.0
1.25.13
1
ghcr.io/fluent/fluent-operator/fluent-operator:3.10.03108194a4ecc
stdlib@go1.26.3
1.25.13
1
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.28.0
stdlib@go1.24.12
0.55.0
1.25.13
1
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.55.0
1.25.13
1
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
golang.org/x/net@v0.35.0
stdlib@go1.23.6
0.55.0
1.25.13
1
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13
1
ghcr.io/fluxcd/helm-controller:v1.6.2e17ab0e5885d
stdlib@go1.26.4
1.25.13
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13
1
ghcr.io/fluxcd/source-controller:v1.9.22b8d06650a1b
stdlib@go1.26.4
1.25.13
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
stdlib@go1.20.12
1.25.13
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
stdlib@go1.23.8
1.25.13
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.1
0.55.0
1.25.13
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.55.0
1.25.13
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.55.0
1.25.13
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
stdlib@go1.23.8
1.25.13
1
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
golang.org/x/net@v0.34.0
stdlib@go1.23.12
0.55.0
1.25.13
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
golang.org/x/net@v0.17.0
stdlib@go1.22.0
0.55.0
1.25.13
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
golang.org/x/net@v0.17.0
stdlib@go1.22.0
0.55.0
1.25.13
1
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
stdlib@go1.18.3
1.25.13
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.18.1
0.55.0
1.25.13
1
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
stdlib@go1.24.0
1.25.13
1
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.55.0
1.25.13
1
ghcr.io/gabe565/domain-watch:latest34c5a1e351d6
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.