StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,671
of 17,828 indexed, latest versions
Container images
5,406
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,671 of 17,828 indexed charts deploy, on 5,406 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,364
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+222 more0.55.03,790
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,671 by stars
ChartLatestAffected imagesRadar Score
cert-managerhomeenterpriseinc1.10.13 of 3See more

cert-manager homeenterpriseinc 1.10.1

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.55.0
1.25.13

Open the chart page →

4,738
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
stdlib@go1.19.8
1.25.13

Open the chart page →

16,645
honeydipperhoneydipperVerified publisher0.1.111 of 2See more

honeydipper honeydipper 0.1.11

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/redis:5fc5ecd863862
stdlib@go1.16.7
1.25.13

Open the chart page →

1,732
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
golang.org/x/net@v0.17.0
stdlib@go1.21.10
0.55.0
1.25.13

Open the chart page →

3,646
universal-web-apphotrungnhanVerified publisher0.2.61 of 2See more

universal-web-app hotrungnhan 0.2.6

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
traefik/whoami:latestc4717a8d1f01
stdlib@go1.26.5
1.25.13

Open the chart page →

93
paperlesshpVerified publisher0.1.23 of 5See more

paperless hp 0.1.2

3 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.55.0
1.25.13
gotenberg/gotenberg:8.3467097317623a
stdlib@go1.26.2
1.25.13
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.13

Open the chart page →

27,556
wallabaghpVerified publisher0.1.71 of 1See more

wallabag hp 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.25.13

Open the chart page →

1,134
hammerspace-csihscsi1.2.86 of 6See more

hammerspace-csi hscsi 1.2.8

6 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

4,519
eoloplanthttpd-eoloplant0.1.03 of 7See more

eoloplant httpd-eoloplant 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.13
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.13

Open the chart page →

32,681
http-headershttp-headers1.2.11 of 1See more

http-headers http-headers 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/k8start/http-headers:1.2.0c7a9987f2ac5
stdlib@go1.19.2
1.25.13

Open the chart page →

2,010
cac-systemhuangchengwu-helm-chart0.1.07 of 9See more

cac-system huangchengwu-helm-chart 0.1.0

7 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.55.0
1.25.13
quay.io/jetstack/cert-manager-cainjector:v1.12.0e0a5b06b231c
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.55.0
1.25.13
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.55.0
1.25.13
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.55.0
1.25.13
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.55.0
1.25.13
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.55.0
1.25.13
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.55.0
1.25.13

Open the chart page →

11,269
mariadbhuangchengwu-helm-chart0.1.01 of 1See more

mariadb huangchengwu-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mariadb:latestd4fdec0510ad
stdlib@go1.24.6
1.25.13

Open the chart page →

1,435
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.55.0
1.25.13

Open the chart page →

16,648
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.55.0
1.25.13

Open the chart page →

20,861
tdenginehuangchengwu-helm-chart3.0.21 of 1See more

tdengine huangchengwu-helm-chart 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
tdengine/tdengine:3.0.2.24140a4021ddb
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.6
0.55.0
1.25.13

Open the chart page →

3,798
sing-boxhuscker-chartsVerified publisher1.0.71 of 1See more

sing-box huscker-charts 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.55.0
1.25.13

Open the chart page →

1,446
s-uihuscker-chartsVerified publisher1.0.31 of 1See more

s-ui huscker-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alireza7/s-ui:1.5.302aa86983cdb
stdlib@go1.26.4
1.25.13

Open the chart page →

532
jaegerhuseyinbabalVerified publisher0.1.01 of 3See more

jaeger huseyinbabal 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13

Open the chart page →

1,486
kubetaghuseyinbabalVerified publisher1.0.21 of 2See more

kubetag huseyinbabal 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/huseyinbabal/kubetag:lateste161eddc59a0
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

1,279
mocktailhuseyinnurbaki0.2.11 of 1See more

mocktail huseyinnurbaki 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hhaluk/mocktail:2.0.3350d19360038
stdlib@go1.17.7
1.25.13

Open the chart page →

1,607
vcbackendi4trustVerified publisher0.0.81 of 1See more

vcbackend i4trust 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
wistefan/vcbackend:0.0.13bd436164b51
stdlib@go1.18.3
1.25.13

Open the chart page →

1,849
vcverifieri4trustVerified publisher1.0.231 of 1See more

vcverifier i4trust 1.0.23

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/fiware/vcverifier:2.0.1cd36290dc849
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.55.0
1.25.13

Open the chart page →

1,784
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.55.0
1.25.13

Open the chart page →

8,121
stoloniamalryz0.10.01 of 2See more

stolon iamalryz 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.55.0
1.25.13

Open the chart page →

4,054
ibexaibexaVerified publisher3.11.12 of 10See more

ibexa ibexa 3.11.1

2 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.0.41bf577825b52a
stdlib@go1.18.2
1.25.13
registry.gitlab.com/xrow-public/ci-tools/kubectl:main9357cfeef63c
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.55.0
1.25.13

Open the chart page →

6,114
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.25.13

Open the chart page →

115,064
ibm-ucv-prodibm-helm5.3.01 of 16See more

ibm-ucv-prod ibm-helm 5.3.0

1 of the 16 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.27.1934d1acd5ca8
stdlib@go1.22.7
1.25.13

Open the chart page →

12,249
metamcpicoretechVerified publisher0.3.111 of 2See more

metamcp icoretech 0.3.11

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
stdlib@go1.24.6
1.25.13

Open the chart page →

1,268
multicaicoretechVerified publisher0.5.11 of 4See more

multica icoretech 0.5.1

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
pgvector/pgvector:pg17cf134a767f47
stdlib@go1.24.6
1.25.13

Open the chart page →

2,000
tolgeeicoretechVerified publisher0.49.32 of 3See more

tolgee icoretech 0.49.3

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:18.369e8582b781c
stdlib@go1.24.6
1.25.13
tolgee/tolgee:v3.224.52e9c2e57829d
stdlib@go1.24.6
1.25.13

Open the chart page →

2,800
monitoring-stackict-platformVerified publisher0.4.010 of 13See more

monitoring-stack ict-platform 0.4.0

10 of the 13 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/loki:3.6.73c8fd3570dd9
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.55.0
1.25.13
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
golang.org/x/net@v0.46.0
stdlib@go1.24.10
0.55.0
1.25.13
ghcr.io/grafana/grafana-operator:v5.22.2d45fc24e8f43
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.55.0
1.25.13
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
golang.org/x/net@v0.30.0
stdlib@go1.24.9
0.55.0
1.25.13
ghcr.io/jkroepke/kube-webhook-certgen:1.8.043401e216e89
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.55.0
1.25.13

Open the chart page →

9,707
ingress-nginxifmethod-helm-charts4.12.12 of 2See more

ingress-nginx ifmethod-helm-charts 4.12.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.55.0
1.25.13

Open the chart page →

1,624
eoloserverihuertas2021-vmartinp2021-helm0.1.03 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.13
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.13

Open the chart page →

28,034
bluesky-pdsijmacd1.0.02 of 2See more

bluesky-pds ijmacd 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
golang.org/x/net@v0.24.0
stdlib@go1.23.8
0.55.0
1.25.13
ghcr.io/bluesky-social/pds:0.405e164855fa1
stdlib@go1.25.10
1.25.13

Open the chart page →

9,255
ikigaiikigai-chartVerified publisher0.0.93 of 58See more

ikigai ikigai-chart 0.0.9

3 of the 58 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
kuberay/operator:v1.0.04e6ac8a3a2c4
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.55.0
1.25.13
rabbitmqoperator/cluster-operator:2.6.08651dd3cec51
golang.org/x/net@v0.18.0
stdlib@go1.20.11
0.55.0
1.25.13
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
stdlib@go1.17.3
0.55.0
1.25.13

Open the chart page →

111,073
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.55.0
1.25.13

Open the chart page →

2,250
ilum-jupyterhubilumVerified publisher4.3.11 of 6See more

ilum-jupyterhub ilum 4.3.1

1 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/net@v0.23.0
stdlib@go1.23.10
0.55.0
1.25.13

Open the chart page →

1,996
ilum-otel-collectorilumVerified publisher0.1.01 of 1See more

ilum-otel-collector ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.113.05ac3e0ba2b0b
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.55.0
1.25.13

Open the chart page →

1,526
plausible-analyticsimioVerified publisher0.4.21 of 5See more

plausible-analytics imio 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:17.6-alpineef257d85f76e
stdlib@go1.24.6
1.25.13

Open the chart page →

10,803
apexkube-agentimprowisedVerified publisher1.4.01 of 2See more

apexkube-agent improwised 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
masipcat/wireguard-go:0.0.20230223769f7bb64694
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.20.14
0.55.0
1.25.13

Open the chart page →

3,397
frigateimprowisedVerified publisher1.1.01 of 1See more

frigate improwised 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.55.0
1.25.13

Open the chart page →

2,161
kore-boardimprowisedVerified publisher0.5.83 of 4See more

kore-board improwised 0.5.8

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.backend:v0.5.5455f6e7a26fd
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.4
0.55.0
1.25.13
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.4
0.55.0
1.25.13
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.9
0.55.0
1.25.13

Open the chart page →

16,462
fpga-cloudinaccelVerified publisher1.2.23 of 3See more

fpga-cloud inaccel 1.2.2

3 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
inaccel/cloud-init:latesta5d3d0af05c1
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.55.0
1.25.13
inaccel/device-selector:latest44b4f274f40b
golang.org/x/net@v0.21.0
stdlib@go1.21.9
0.55.0
1.25.13
inaccel/kubevirt-hack:latestbdfd61803a70
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13

Open the chart page →

3,167
fpga-operatorinaccelVerified publisher2.8.23 of 7See more

fpga-operator inaccel 2.8.2

3 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
inaccel/daemon:latest093e1ea90ab8
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.55.0
1.25.13
inaccel/mkrt:latest187fd448b6f2
stdlib@go1.21.5
1.25.13
inaccel/reef:latestc967218739f3
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.55.0
1.25.13

Open the chart page →

5,785
infisical-agent-injectorinfisical-charts0.1.121 of 1See more

infisical-agent-injector infisical-charts 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
infisical/infisical-agent-injector:v0.1.12718dd5bee7cb
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

762
infisical-csi-providerinfisical-charts0.2.31 of 1See more

infisical-csi-provider infisical-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
infisical/infisical-csi-provider:v0.0.9e3390e677db6
golang.org/x/net@v0.33.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

637
infisical-gatewayinfisical-charts1.4.01 of 1See more

infisical-gateway infisical-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
infisical/cli:0.43.1230941c1293b77
stdlib@go1.25.12
1.25.13

Open the chart page →

293
infisical-pki-issuerinfisical-charts1.0.01 of 1See more

infisical-pki-issuer infisical-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
infisical/pki-issuer:latestff38294270e3
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

580
chronografinfluxdata1.2.61 of 1See more

chronograf influxdata 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/chronograf:1.9.496d8a3f65a4f
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.55.0
1.25.13

Open the chart page →

2,206
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
stdlib@go1.24.13
1.25.13
library/influxdb:1.12.3-datab0f9fc41ed79
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13

Open the chart page →

6,036

Container images carrying it

5,406 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.55.0
1.25.13
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.55.0
1.25.13
1
ghcr.io/strrl/supabase-operator:2026.7.2587d083ab8980
golang.org/x/net@v0.46.0
stdlib@go1.25.12
0.55.0
1.25.13
1
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.55.0
1.25.13
1
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.55.0
1.25.13
1
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
golang.org/x/net@v0.28.0
stdlib@go1.21.13
0.55.0
1.25.13
1
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
golang.org/x/net@v0.22.0
stdlib@go1.22.5
0.55.0
1.25.13
1
ghcr.io/supabase-community/supabase-operator:v0.1.3253a6dcbf4f0
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.55.0
1.25.13
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.55.0
1.25.13
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.55.0
1.25.13
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
golang.org/x/net@v0.35.0
stdlib@go1.22.4
0.55.0
1.25.13
1
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.55.0
1.25.13
1
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
golang.org/x/net@v0.35.0
stdlib@go1.22.4
0.55.0
1.25.13
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.55.0
1.25.13
1
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
golang.org/x/net@v0.35.0
stdlib@go1.22.4
0.55.0
1.25.13
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/net@v0.19.0
stdlib@go1.20.14
0.55.0
1.25.13
1
ghcr.io/syself/hetzner-cloud-controller-manager:v2.0.77d4a5e29c387
golang.org/x/net@v0.49.0
stdlib@go1.24.5
0.55.0
1.25.13
1
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
golang.org/x/net@v0.1.0
stdlib@go1.19.2-ts3fd24dee31
0.55.0
1.25.13
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
stdlib@go1.23.4
1.25.13
1
ghcr.io/tale/headplane:0.6.39476cc5adb12
golang.org/x/net@v0.42.0
stdlib@go1.25.1
0.55.0
1.25.13
1
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.25.13
1
ghcr.io/tarampampam/webhook-tester:2.3.085818267b450
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.55.0
1.25.13
1
ghcr.io/taskmedia/kubectl-gpg-ncftp:main0fb2b5584f7c
golang.org/x/net@v0.23.0
stdlib@go1.22.10
0.55.0
1.25.13
1
ghcr.io/techarohq/anubis:v1.21.3940ac71ef6fc
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.55.0
1.25.13
1
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
1
ghcr.io/telepresenceio/tel2:2.31.26f1d705594ba
stdlib@go1.26.5-X:jsonv2
1.25.13
1
ghcr.io/terminus-io/enforcer:v1.1.0f21b905610d6
golang.org/x/net@v0.51.0
stdlib@go1.25.5
0.55.0
1.25.13
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
stdlib@go1.24.4
1.25.13
1
ghcr.io/thetredev/steamcmd:srcds-20240309dbb0f042cb31
stdlib@go1.18.2
1.25.13
1
ghcr.io/thomiceli/opengist:1.15.1038d47937d3b
stdlib@go1.26.5
1.25.13
1
ghcr.io/tikalk/resource-manager:latest7f21d50e69cb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19
0.55.0
1.25.13
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.55.0
1.25.13
1
ghcr.io/tmusial99/local-path-exporter:1.1.082476692c680
stdlib@go1.26.4
1.25.13
1
ghcr.io/topolvm/pie:0.18.0aa467443e407
golang.org/x/net@v0.49.0
0.55.0
1
ghcr.io/topolvm/pvc-autoresizer:0.21.1078d3527f38b
golang.org/x/net@v0.47.0
0.55.0
1
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
golang.org/x/net@v0.49.0
0.55.0
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
golang.org/x/net@v0.24.0
stdlib@go1.22.8
0.55.0
1.25.13
1
ghcr.io/traefik/hub-manager:v0.45.1d1cff2560c67
stdlib@go1.26.0
1.25.13
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.55.0
1.25.13
1
ghcr.io/transparency-dev/tesseract/posix:v0.1.2b044edd23888
stdlib@go1.25.8
1.25.13
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
stdlib@go1.23.7
1.25.13
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
stdlib@go1.23.7
1.25.13
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
stdlib@go1.23.7
1.25.13
1
ghcr.io/tsouza/cerberus:1.21.1242b56dcb5c7
stdlib@go1.26.2
1.25.13
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
golang.org/x/net@v0.26.0
stdlib@go1.22.8
0.55.0
1.25.13
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
golang.org/x/net@v0.50.0
stdlib@go1.24.6
0.55.0
1.25.13
1
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/net@v0.26.0
stdlib@go1.24.1
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.