StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,651
of 17,832 indexed, latest versions
Container images
5,368
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,651 of 17,832 indexed charts deploy, on 5,368 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,329
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+222 more0.55.03,771
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,651 by stars
ChartLatestAffected imagesRadar Score
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.012 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

12 of the 40 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.55.0
1.25.13
library/arangodb:3.11.81e75d74954a4
stdlib@go1.21.5
1.25.13
library/mariadb:11.3.2e101f9db3191
stdlib@go1.18.2
1.25.13
library/postgres:17.5-alpine6567bca8d7bc
stdlib@go1.18.2
1.25.13
library/postgres:17.2-alpine7e5df973a748
stdlib@go1.18.2
1.25.13
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.25.13
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
yetiplatform/bloomcheck:dev85683ddfccbb
stdlib@go1.24.2
1.25.13
gcr.io/kaniko-project/executor:latest4e7a52dd1f14
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
stdlib@go1.25.11
1.25.13
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

200,900
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
stdlib@go1.21.5
1.25.13

Open the chart page →

6,893
osm-edgeosm-edgeVerified publisher1.3.94 of 7See more

osm-edge osm-edge 1.3.9

4 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
golang.org/x/net@v0.5.0
stdlib@go1.19.13
0.55.0
1.25.13
flomesh/osm-edge-controller:1.3.9add7a4da4622
golang.org/x/net@v0.5.0
stdlib@go1.19.13
0.55.0
1.25.13
flomesh/osm-edge-injector:1.3.947287e3ad324
golang.org/x/net@v0.5.0
stdlib@go1.19.13
0.55.0
1.25.13
flomesh/osm-edge-preinstall:1.3.9bd224d55ed0f
golang.org/x/net@v0.5.0
stdlib@go1.19.13
0.55.0
1.25.13

Open the chart page →

5,614
logging-operatorot-container-kit0.4.01 of 1See more

logging-operator ot-container-kit 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/opstree/logging-operator:v0.4.0fd8bb57ef3cf
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

1,803
lokiot-container-kit1.0.13 of 5See more

loki ot-container-kit 1.0.1

3 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/loki:3.1.0d947e68a84d9
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.55.0
1.25.13
grafana/promtail:3.0.0d3de3da9431c
golang.org/x/net@v0.22.0
stdlib@go1.21.9
0.55.0
1.25.13
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

4,846
loki-standaloneot-container-kit1.0.22 of 5See more

loki-standalone ot-container-kit 1.0.2

2 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/opstree/loki:3.6-debian13bdfee214c7ea
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
quay.io/opstree/memcached-exporter:0.15.5-debian13cf8f8410eaad
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

3,661
mongodb-operatorot-container-kit0.3.11 of 1See more

mongodb-operator ot-container-kit 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/opstree/mongodb-operator:v0.3.0879b9bead838
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.8
0.55.0
1.25.13

Open the chart page →

1,874
mysqlot-container-kit0.1.01 of 1See more

mysql ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

463
otel-operatorot-container-kit1.0.11 of 1See more

otel-operator ot-container-kit 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/opstree/opentelemetry-operator:0.149.0-debian13a21405ab9a9a
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.55.0
1.25.13

Open the chart page →

290
ot-karpenterot-container-kit0.3.01 of 1See more

ot-karpenter ot-container-kit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:1.1.1fe383abf1dbc
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.55.0
1.25.13

Open the chart page →

495
pgaot-container-kit1.0.34 of 6See more

pga ot-container-kit 1.0.3

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.1.0079600c9517b
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.75.1a7cc63108511
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.55.0
1.25.13

Open the chart page →

5,155
tempo-standaloneot-container-kit1.0.11 of 1See more

tempo-standalone ot-container-kit 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/opstree/tempo:2.10.4-debian13cb734024b3fd
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

612
vmot-container-kit0.0.34 of 7See more

vm ot-container-kit 0.0.3

4 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
victoriametrics/operator:v0.47.271be93cfafb6
golang.org/x/net@v0.26.0
stdlib@go1.23.0
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

5,431
vm-standaloneot-container-kit0.0.44 of 6See more

vm-standalone ot-container-kit 0.0.4

4 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/opstree/grafana:12.4.3b61c1ed2f015
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.55.0
1.25.13
quay.io/opstree/kube-state-metrics:2.18.0-debian1353525d253793
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.55.0
1.25.13
quay.io/opstree/node-exporter:1.11.1-alpine3.233b6b3a7eb001
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13
quay.io/opstree/victoriametrics-operator:v0.69.066fe5216c278
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.55.0
1.25.13

Open the chart page →

3,501
otel-add-onotel-add-onVerified publisher0.1.41 of 1See more

otel-add-on otel-add-on 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kedify/otel-add-on:v0.1.4a6f2155bd822
golang.org/x/net@v0.47.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

734
otsotsVerified publisher1.8.41 of 2See more

ots ots 1.8.4

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/luzifer/ots:v1.21.5c94f6c9ed173
stdlib@go1.26.2
1.25.13

Open the chart page →

367
akash-hostname-operatorovrclk-211.5.11 of 1See more

akash-hostname-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
golang.org/x/net@v0.30.0
stdlib@go1.23.5
0.55.0
1.25.13

Open the chart page →

3,561
akash-inventory-operatorovrclk-211.5.11 of 1See more

akash-inventory-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
golang.org/x/net@v0.30.0
stdlib@go1.23.5
0.55.0
1.25.13

Open the chart page →

3,561
akash-ip-operatorovrclk-211.5.11 of 1See more

akash-ip-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
golang.org/x/net@v0.30.0
stdlib@go1.23.5
0.55.0
1.25.13

Open the chart page →

3,561
akash-nodeovrclk-211.1.31 of 1See more

akash-node ovrclk-2 11.1.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/akash-network/node:0.36.08763983b31f1
golang.org/x/net@v0.24.0
stdlib@go1.21.10
0.55.0
1.25.13

Open the chart page →

1,338
adotowan-charts0.1.01 of 1See more

adot owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.55.0
1.25.13

Open the chart page →

1,033
httpbunowan-charts0.1.01 of 1See more

httpbun owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sharat87/httpbun:latest405332d9050a
stdlib@go1.25.1
1.25.13

Open the chart page →

314
minioowan-charts0.1.22 of 2See more

minio owan-charts 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cleanstart/minio:latest544bdb8811e1
stdlib@go1.26.4
1.25.13
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13

Open the chart page →

1,083
shlinkowan-charts0.1.01 of 1See more

shlink owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
shlinkio/shlink:stable666cc24edf72
stdlib@go1.26.4
1.25.13

Open the chart page →

322
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17
0.55.0
1.25.13

Open the chart page →

1,826
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

1,998
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
golang.org/x/net@v0.26.0
stdlib@go1.22.1
0.55.0
1.25.13

Open the chart page →

3,726
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

3,353
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
golang.org/x/net@v0.24.0
stdlib@go1.21.1
0.55.0
1.25.13
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
golang.org/x/net@v0.24.0
stdlib@go1.21.1
0.55.0
1.25.13

Open the chart page →

2,338
predicatep2p-avs0.1.41 of 1See more

predicate p2p-avs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.55.0
1.25.13

Open the chart page →

893
p4p40.1.03 of 7See more

p4 p4 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.55.0
1.25.13
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.13

Open the chart page →

28,008
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:80744ee5ef89c
stdlib@go1.24.6
1.25.13

Open the chart page →

19,773
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.55.0
1.25.13

Open the chart page →

3,649
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-andromeda1.0.01 of 3See more

pages pages-andromeda 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespagesbadami1.0.01 of 3See more

pages pagesbadami 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-blackburn1.0.01 of 3See more

pages pages-blackburn 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-botes1.0.01 of 3See more

pages pages-botes 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-brian1.0.01 of 3See more

pages pages-brian 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-buckll1.0.01 of 3See more

pages pages-buckll 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-camden1.0.01 of 3See more

pages pages-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-camden7711.0.01 of 3See more

pages pages-camden771 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350
pagespages-diarmuidkeane1.0.01 of 3See more

pages pages-diarmuidkeane 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,350

Container images carrying it

5,368 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
golang.org/x/net@v0.38.0
stdlib@go1.24.7
0.55.0
1.25.13
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.55.0
1.25.13
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.55.0
1.25.13
1
ghcr.io/okteto/backend:0.0.0-2026-08-2406f2f6f4ed76
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13
1
ghcr.io/okteto/buildkit:0.0.0-2026-08-03:0.0.0-2026-08-17:0.0.0-2026-08-2414527ca5d2a9
golang.org/x/net@v0.35.0
stdlib@go1.25.7
0.55.0
1.25.13
1
ghcr.io/okteto/daemon:0.0.0-2026-08-17:0.0.0-2026-08-24c6e716a3fbbe
stdlib@go1.26.5
1.25.13
1
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-17:0.0.0-2026-08-24265eedb3954b
stdlib@go1.26.4
1.25.13
1
ghcr.io/okteto/okteto:3.22.04585017f52f6
golang.org/x/net@v0.47.0
stdlib@go1.26.5
0.55.0
1.25.13
1
ghcr.io/okteto/registry:0.0.0-2026-08-17:0.0.0-2026-08-2469131511501f
stdlib@go1.26.5
1.25.13
1
ghcr.io/okteto/reloader:0.0.0-2026-08-03:0.0.0-2026-08-17:0.0.0-2026-08-2404a3fce657c4
stdlib@go1.26.4
1.25.13
1
ghcr.io/oliverbaehler/cloudflare-tunnel-ingress-controller:0.2.30aec31e36d95
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.55.0
1.25.13
1
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
golang.org/x/net@v0.33.0
stdlib@go1.22.0
0.55.0
1.25.13
1
ghcr.io/omkar-shelke25/admission-webhook-no-latest:sha-33165455976a1d3236a
golang.org/x/net@v0.38.0
stdlib@go1.26.3
0.55.0
1.25.13
1
ghcr.io/onedr0p/exportarr:v1.6.160cf3d44aa0b
stdlib@go1.21.6
1.25.13
1
ghcr.io/openappsec/smartsync:latest580d68c50cc7
stdlib@go1.18.10
1.25.13
1
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
stdlib@go1.18.10
1.25.13
1
ghcr.io/openclarity/grype-server:v0.6.079412399f301
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.55.0
1.25.13
1
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.55.0
1.25.13
1
ghcr.io/openclarity/kubeclarity-sbom-db:v2.23.3cef2b88bfc76
golang.org/x/net@v0.17.0
stdlib@go1.21.6
0.55.0
1.25.13
1
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
golang.org/x/net@v0.50.0
stdlib@go1.24.12
0.55.0
1.25.13
1
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
stdlib@go1.23.5
1.25.13
1
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.55.0
1.25.13
1
ghcr.io/openfaas/faas-netes:0.18.176cfe35401d25
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
1
ghcr.io/openfaas/gateway:0.27.1382b15393116e
stdlib@go1.24.6
1.25.13
1
ghcr.io/openfaas/gateway:0.27.14ee0eaecc490c
stdlib@go1.24.13
1.25.13
1
ghcr.io/openfaasltd/federated-gateway:0.2.39066d7b3e6a1
stdlib@go1.21.5
1.25.13
1
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
golang.org/x/net@v0.35.0
stdlib@go1.23.8
0.55.0
1.25.13
1
ghcr.io/openfaasltd/headroom-controller:v0.0.467d587cc2c39
golang.org/x/net@v0.38.0
stdlib@go1.26.4
0.55.0
1.25.13
1
ghcr.io/openfaasltd/jetstream-queue-worker:0.3.37d96366e208b1
stdlib@go1.22.1
1.25.13
1
ghcr.io/openfaasltd/kafka-connector:0.7.160e58eac0e2f7
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.55.0
1.25.13
1
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
stdlib@go1.23.5
1.25.13
1
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
golang.org/x/net@v0.53.0
stdlib@go1.24.4
0.55.0
1.25.13
1
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
stdlib@go1.23.5
1.25.13
1
ghcr.io/openfaasltd/sns-connector:0.2.0e9ab76a4ec77
stdlib@go1.21.7
1.25.13
1
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
stdlib@go1.23.5
1.25.13
1
ghcr.io/openfaas/mqtt-connector:0.4.33311a30b8fe6
golang.org/x/net@v0.0.0-20200425230154-ff2c4b7c35a0
stdlib@go1.18.5
0.55.0
1.25.13
1
ghcr.io/openfaas/nats-connector:0.3.0315e57c0a8d8
stdlib@go1.18.5
1.25.13
1
ghcr.io/openfaas/queue-worker:0.14.2c18da04d70f6
stdlib@go1.23.4
1.25.13
1
ghcr.io/open-feature/flagd:v0.16.032234e63c1d0
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.55.0
1.25.13
1
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
golang.org/x/net@v0.27.0
stdlib@go1.22.5
0.55.0
1.25.13
1
ghcr.io/open-feature/open-feature-operator:v0.9.3b37a442c0497
golang.org/x/net@v0.52.0
0.55.0
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.55.0
1.25.13
1
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
stdlib@go1.24.13
1.25.13
1
ghcr.io/openlit/openlit-operator:0.0.2457bb5ada68b
golang.org/x/net@v0.43.0
stdlib@go1.24.13
0.55.0
1.25.13
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
stdlib@go1.25.11
1.25.13
1
ghcr.io/openstack-exporter/openstack-exporter:1.7.0e5146a7dd515
golang.org/x/net@v0.10.0
stdlib@go1.18.10
0.55.0
1.25.13
1
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
golang.org/x/net@v0.25.0
stdlib@go1.22.8
0.55.0
1.25.13
1
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
golang.org/x/net@v0.25.0
stdlib@go1.22.8
0.55.0
1.25.13
1
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.