StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,651
of 17,832 indexed, latest versions
Container images
5,368
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,651 of 17,832 indexed charts deploy, on 5,368 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,329
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+222 more0.55.03,771
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,651 by stars
ChartLatestAffected imagesRadar Score
gloo-meshsolo-gloo-mesh1.1.21 of 1See more

gloo-mesh solo-gloo-mesh 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

3,265
buildkitsomaz94Verified publisher0.1.41 of 1See more

buildkit somaz94 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
moby/buildkit:v0.33.06c2fa84a6b61
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

717
redis-high-availabilitysomeblackmagic1.3.102 of 3See more

redis-high-availability someblackmagic 1.3.10

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.8-debian-11-r0bf01d031ba8c
stdlib@go1.18.2
1.25.13
haproxytech/haproxy-alpine:2.9.57f3dc8c7e031
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.55.0
1.25.13

Open the chart page →

3,152
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18.2
0.55.0
1.25.13

Open the chart page →

99,493
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

12,126
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
golang.org/x/net@v0.33.0
stdlib@go1.22.8
0.55.0
1.25.13

Open the chart page →

3,337
spire-ha-agentspiffeVerified publisher0.3.21 of 2See more

spire-ha-agent spiffe 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-ha-agent:0.5.0307cf2d05afe
stdlib@go1.25.0
1.25.13

Open the chart page →

368
spire-identity-exchangespiffeVerified publisher0.2.22 of 3See more

spire-identity-exchange spiffe 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-identity-exchange-server:v0.5.0239bc70c1988
stdlib@go1.26.0
1.25.13
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

1,441
spiffile-operatorspiffile-operatorVerified publisher0.1.41 of 1See more

spiffile-operator spiffile-operator 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/petersr/spiffile-operator:0.1.4411070249287
stdlib@go1.26.4
1.25.13

Open the chart page →

81
spinnakerspinnakerVerified publisher2.2.132 of 4See more

spinnaker spinnaker 2.2.13

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.15.5
0.55.0
1.25.13
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.5
0.55.0
1.25.13

Open the chart page →

6,878
spoolmanspoolmanVerified publisher0.2.61 of 1See more

spoolman spoolman 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.25.13

Open the chart page →

1,843
ocean-admission-controllerspot1.0.32 of 3See more

ocean-admission-controller spot 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gcr.io/spotit-today/spot-ocean-admission-controller:0.1.64f634aeb31b8
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.55.0
1.25.13

Open the chart page →

773
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

50,457
ocean-vpaspot1.0.73 of 4See more

ocean-vpa spot 1.0.7

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

1,195
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.5
0.55.0
1.25.13

Open the chart page →

63,404
airflowsqream-chartsVerified publisher1.17.01 of 4See more

airflow sqream-charts 1.17.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/prometheus/statsd-exporter:v0.27.29ed70604d941
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.55.0
1.25.13

Open the chart page →

1,829
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.55.0
1.25.13

Open the chart page →

2,427
sqs-prometheus-exportersqs-prometheus-exporterVerified publisher2.0.31 of 1See more

sqs-prometheus-exporter sqs-prometheus-exporter 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/jmriebold/sqs-prometheus-exporter:1.1.07564828ab7cb
stdlib@go1.24.0
1.25.13

Open the chart page →

368
sqs-to-snssqs-to-sns2.0.151 of 1See more

sqs-to-sns sqs-to-sns 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
udhos/sqs-to-sns:2.0.15cf7979da82e1
stdlib@go1.26.3
1.25.13

Open the chart page →

951
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
sshpipersshpiperVerified publisher0.4.71 of 1See more

sshpiper sshpiper 0.4.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
farmer1992/sshpiperd:v1.5.4e0064b824403
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13

Open the chart page →

190
servicexssl-hep1.8.52 of 16See more

servicex ssl-hep 1.8.5

2 of the 16 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/net@v0.4.0
stdlib@go1.18.9
0.55.0
1.25.13
sslhep/servicex_app:v1.8.51d12f943cec5
stdlib@go1.26.5
1.25.13

Open the chart page →

70,029
ecr-cleanersstarcher0.1.1+d13a1ab1 of 1See more

ecr-cleaner sstarcher 0.1.1+d13a1ab

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sstarcher/ecr-cleaner:0.1.12d43c390cb19
stdlib@go1.14.2
1.25.13

Open the chart page →

2,577
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.9
0.55.0
1.25.13

Open the chart page →

3,098
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

3,077
retail-store-sample-catalog-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-catalog-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-catalog:1.3.0b654b266fa32
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

773
stageset-controllerstageset-controllerOfficialVerified publisher2026.6.15+1543421 of 1See more

stageset-controller stageset-controller 2026.6.15+154342

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/metio/stageset-controller:2026.6.14234b66bb3319
stdlib@go1.26.4
1.25.13

Open the chart page →

313
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.6
0.55.0
1.25.13

Open the chart page →

28,628
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.55.0
1.25.13

Open the chart page →

2,090
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13

Open the chart page →

2,545
k8scostoptimizerstakaterVerified publisher0.0.51 of 1See more

k8scostoptimizer stakater 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.55.0
1.25.13

Open the chart page →

1,410
konfiguratorstakaterVerified publisher0.1.391 of 1See more

konfigurator stakater 0.1.39

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stakater/konfigurator:v0.1.393409565b1ef5
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.55.0
1.25.13

Open the chart page →

1,280
mongodbstakaterVerified publisher1.0.31 of 1See more

mongodb stakater 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/mongodb:latest84254ace18df
stdlib@go1.26.5
1.25.13

Open the chart page →

82
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.55.0
1.25.13

Open the chart page →

2,854
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.55.0
1.25.13

Open the chart page →

2,174
vaultstakaterVerified publisher0.8.42 of 2See more

vault stakater 0.8.4

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.55.0
1.25.13
hashicorp/vault-k8s:0.14.0aff47b5ba39c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.2
0.55.0
1.25.13

Open the chart page →

5,874
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.1
0.55.0
1.25.13

Open the chart page →

2,566
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.13
0.55.0
1.25.13

Open the chart page →

6,696
stakefishstakefish0.1.06 of 8See more

stakefish stakefish 0.1.0

6 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.55.0
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.55.0
1.25.13
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

20,481
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.55.0
1.25.13

Open the chart page →

2,992
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

1,263
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.25.13

Open the chart page →

4,113
mev-booststakewise1.7.41 of 1See more

mev-boost stakewise 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
flashbots/mev-boost:1.8.07c486b5789da
stdlib@go1.22.6
1.25.13

Open the chart page →

1,261
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.55.0
1.25.13

Open the chart page →

6,630
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.55.0
1.25.13

Open the chart page →

7,070
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.55.0
1.25.13

Open the chart page →

1,263
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

576
open-appsec-injectorstartechnicaVerified publisher1.1.22 of 3See more

open-appsec-injector startechnica 1.1.2

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/openappsec/smartsync:latest580d68c50cc7
stdlib@go1.18.10
1.25.13
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
stdlib@go1.18.10
1.25.13

Open the chart page →

4,362
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.25.13

Open the chart page →

14,673
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
stdlib@go1.18.4
0.55.0
1.25.13

Open the chart page →

1,986

Container images carrying it

5,368 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/glauth/glauth:v2.5.209c782ca5984
golang.org/x/net@v0.17.0
stdlib@go1.25.0
0.55.0
1.25.13
1
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
stdlib@go1.26.4
1.25.13
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
1
ghcr.io/gochain/rpc-proxy/rpc-proxy:latestca01f5ab95f7
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.55.0
1.25.13
1
ghcr.io/gomenhashai/gomenhashai:v1.3.36f031172a5ec
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.55.0
1.25.13
1
ghcr.io/gotify/server:2.6.104f4c4bb7cdd
golang.org/x/net@v0.25.0
stdlib@go1.23.3
0.55.0
1.25.13
1
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.18.3
0.55.0
1.25.13
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.55.0
1.25.13
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
golang.org/x/net@v0.46.0
stdlib@go1.24.10
0.55.0
1.25.13
1
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
stdlib@go1.26.4
1.25.13
1
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
ghcr.io/grafana/grafana-operator:v5.18.00af2faec9d6f
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.55.0
1.25.13
1
ghcr.io/grafana/grafana-operator:v5.22.2d45fc24e8f43
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.55.0
1.25.13
1
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
golang.org/x/net@v0.30.0
stdlib@go1.24.9
0.55.0
1.25.13
1
ghcr.io/grafana/k6-operator:controller-v1.6.0ba7f0fc1e22e
stdlib@go1.26.5
1.25.13
1
ghcr.io/grafana/k8s-injection-controller:0.2.0c5bad40655a3
stdlib@go1.26.5
1.25.13
1
ghcr.io/grafana/tempo-operator/tempo-operator:v0.4.02627be646391
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.55.0
1.25.13
1
ghcr.io/grycap/oscar:latest0c58ff972451
golang.org/x/net@v0.51.0
stdlib@go1.25.11
0.55.0
1.25.13
1
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
golang.org/x/net@v0.42.0
stdlib@go1.25.8
0.55.0
1.25.13
1
ghcr.io/guydavis/machinaris:test50a71a30f18e
stdlib@go1.26.5
1.25.13
1
ghcr.io/haedalwang/kubescout:0.1.107d51f838f0d
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13
1
ghcr.io/happymooguild/wardn-backend:0.1.023ee1b8cfc3c
stdlib@go1.26.5
1.25.13
1
ghcr.io/haydercyber/secrets-bridge:0.2.04709f1bb3039
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
1
ghcr.io/hay-kot/homebox:v0.9.2e6e0fbd7cca9
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.55.0
1.25.13
1
ghcr.io/headlamp-k8s/headlamp:v0.43.05d03caa26df7
stdlib@go1.26.3
1.25.13
1
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
golang.org/x/net@v0.17.0
stdlib@go1.24.13
0.55.0
1.25.13
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/net@v0.0.0-20220121210141-e204ce36a2ba
stdlib@go1.17.6
0.55.0
1.25.13
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
stdlib@go1.17.8
0.55.0
1.25.13
1
ghcr.io/helm/chartmuseum:v0.16.3c81f105c3682
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.55.0
1.25.13
1
ghcr.io/helmfile/helmfile:v1.8.01808ffb76f37
golang.org/x/net@v0.39.0
stdlib@go1.26.4
0.55.0
1.25.13
1
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.55.0
1.25.13
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
stdlib@go1.23.3
1.25.13
1
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.55.0
1.25.13
1
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.55.0
1.25.13
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.55.0
1.25.13
1
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.55.0
1.25.13
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.25.13
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
stdlib@go1.17.1
1.25.13
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.55.0
1.25.13
1
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.20.1
0.55.0
1.25.13
1
ghcr.io/hsn723/cert-estuary:0.2.00c4b6132b0ad
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
1
ghcr.io/hsn723/dkim-manager:1.4.00312232b31a2
golang.org/x/net@v0.50.0
stdlib@go1.26.0
0.55.0
1.25.13
1
ghcr.io/hsn723/postfix_exporter:0.20.0b7da7c554018
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
1
ghcr.io/huseyinbabal/kubetag:lateste161eddc59a0
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
1
ghcr.io/hyperspike/valkey-operator:v0.0.617d8c669f11a4
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.55.0
1.25.13
1
ghcr.io/idebeijer/gameserver-operator:latest1b099cfe9e5e
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
golang.org/x/net@v0.33.0
stdlib@go1.23.1
0.55.0
1.25.13
1
ghcr.io/igrikus/garm-operator:4.2.09e24d8a6a3b2
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.