StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,647
of 17,832 indexed, latest versions
Container images
5,366
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,647 of 17,832 indexed charts deploy, on 5,366 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,327
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+222 more0.55.03,770
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,647 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

5,366 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.25.13
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.25.13
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.25.13
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
stdlib@go1.18.4
1.25.13
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.25.13
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.25.13
1
ghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.2982d0adcce816
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.55.0
1.25.13
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.25.13
1
ghcr.io/k8s-lynq/lynq:1.1.22229b05e3c717
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.4-thick3c20900b5381
golang.org/x/net@v0.43.0
stdlib@go1.24.13
0.55.0
1.25.13
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.16bebbda31416
golang.org/x/net@v0.28.0
stdlib@go1.23.9
0.55.0
1.25.13
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.39751856cacc8
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.55.0
1.25.13
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.13.10
0.55.0
1.25.13
1
ghcr.io/k8snetworkplumbingwg/multus-cni:stableec4e5dfe12b6
golang.org/x/net@v0.48.0
stdlib@go1.25.11
0.55.0
1.25.13
1
ghcr.io/k8snetworkplumbingwg/multus-dynamic-networks-controller:v0.3.72a2bb32c0ea8
golang.org/x/net@v0.30.0
stdlib@go1.22.12
0.55.0
1.25.13
1
ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.4f279fd7dc112
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.55.0
1.25.13
1
ghcr.io/k8up-io/k8up:v2.16.029458113b8b6
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.55.0
1.25.13
1
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.55.0
1.25.13
1
ghcr.io/kagent-dev/kagent/tools:0.2.150b431281d3e
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.55.0
1.25.13
1
ghcr.io/kagent-dev/kagent/tools:0.0.13c8882543f693
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.55.0
1.25.13
1
ghcr.io/kagent-dev/kmcp/controller:0.2.283276357d448
golang.org/x/net@v0.30.0
stdlib@go1.24.11
0.55.0
1.25.13
1
ghcr.io/kagent-dev/kmcp/controller:0.3.086ab878da25a
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.55.0
1.25.13
1
ghcr.io/kalgurn/grl-exporter:v3.2.0bd109b2bda38
stdlib@go1.23.5
1.25.13
1
ghcr.io/kamu-data/kamu-api-server:0.90.0e61435d44913
stdlib@go1.15.2
1.25.13
1
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
golang.org/x/net@v0.41.0
stdlib@go1.25.6
0.55.0
1.25.13
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
stdlib@go1.23.10
1.25.13
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
stdlib@go1.20.7
1.25.13
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
stdlib@go1.23.10
1.25.13
1
ghcr.io/karlderkaefer/argocd-ecr-updater:1.4.6ed5d4b74792c
stdlib@go1.26.5
1.25.13
1
ghcr.io/kcp-dev/kcp-operator:v0.9.0cd8bf46d98e0
stdlib@go1.26.4
1.25.13
1
ghcr.io/kedacore/keda:2.16.002348a19aeae
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
1
ghcr.io/kedacore/keda:2.17.0112fc427d933
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
1
ghcr.io/kedacore/keda:2.17.272dc058e478d
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
1
ghcr.io/kedacore/keda:2.20.2fe74c7b88495
stdlib@go1.26.2
1.25.13
1
ghcr.io/kedacore/keda-admission-webhooks:2.20.241f74102aba7
stdlib@go1.26.2
1.25.13
1
ghcr.io/kedacore/keda-admission-webhooks:2.17.0a87c42275757
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
1
ghcr.io/kedacore/keda-admission-webhooks:2.17.2c8227c6edb4d
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
1
ghcr.io/kedacore/keda-metrics-apiserver:2.17.0167fd532bd43
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
1
ghcr.io/kedacore/keda-metrics-apiserver:2.20.227286536a8a7
stdlib@go1.26.2
1.25.13
1
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
1
ghcr.io/kedacore/keda-metrics-apiserver:2.17.2f312f50ddc57
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.55.0
1.25.13
1
ghcr.io/kedify/otel-add-on:v0.1.4a6f2155bd822
golang.org/x/net@v0.47.0
stdlib@go1.24.3
0.55.0
1.25.13
1
ghcr.io/keel-hq/keel:0.22.3315e188a07c2
stdlib@go1.26.5
1.25.13
1
ghcr.io/keiailab/mongodb-operator:v1.16.9cf6d86e057bb
stdlib@go1.26.5
1.25.13
1
ghcr.io/keiailab/nodevitals:0.8.597107e46f0d3
stdlib@go1.26.5
1.25.13
1
ghcr.io/keiailab/valkey-operator:1.5.249b5aef82877
stdlib@go1.26.5
1.25.13
1
ghcr.io/keptn/certificate-operator:v1.1.08fdd311a6d33
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.55.0
1.25.13
1
ghcr.io/keptn/lifecycle-operator:v0.8.2487bfc37c4b4
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.55.0
1.25.13
1
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.55.0
1.25.13
1
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.