StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,671
of 17,828 indexed, latest versions
Container images
5,406
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,671 of 17,828 indexed charts deploy, on 5,406 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+193 more1.25.135,364
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+222 more0.55.03,790
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,671 by stars
ChartLatestAffected imagesRadar Score
prometheus-operator-admission-webhookgpg-dev0.18.12 of 2See more

prometheus-operator-admission-webhook gpg-dev 0.18.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/admission-webhook:v0.79.2d4c97a1b2d67
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.55.0
1.25.13

Open the chart page →

1,687
thanosgpg-dev0.5.31 of 1See more

thanos gpg-dev 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

602
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.55.0
1.25.13

Open the chart page →

1,309
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13

Open the chart page →

1,582
whoami-demogpg-dev0.1.01 of 1See more

whoami-demo gpg-dev 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.25.13

Open the chart page →

1,280
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/graphite-exporter:latestc1a266f63a84
stdlib@go1.26.5
1.25.13

Open the chart page →

6,142
cloudcost-exportergrafana1.1.131 of 1See more

cloudcost-exporter grafana 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/cloudcost-exporter:v1.12.0eeb2cfecb23e
stdlib@go1.26.4
1.25.13

Open the chart page →

162
grafana-cloud-onboardinggrafana0.4.75 of 5See more

grafana-cloud-onboarding grafana 0.4.7

5 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/beyla-k8s-cache:253b2f561cb1b
golang.org/x/net@v0.48.0
stdlib@go1.25.3
0.55.0
1.25.13
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
stdlib@go1.23.6
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

4,737
grafana-samplinggrafana1.1.72 of 2See more

grafana-sampling grafana 1.1.7

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.55.0
1.25.13

Open the chart page →

3,435
k8s-injection-controllergrafana0.2.11 of 1See more

k8s-injection-controller grafana 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/grafana/k8s-injection-controller:0.2.0c5bad40655a3
stdlib@go1.26.5
1.25.13

Open the chart page →

138
mimir-openshift-experimentalgrafana2.1.03 of 4See more

mimir-openshift-experimental grafana 2.1.0

3 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.8
0.55.0
1.25.13
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.55.0
1.25.13
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.55.0
1.25.13

Open the chart page →

17,824
pyroscope-monitoringgrafana0.1.15 of 6See more

pyroscope-monitoring grafana 0.1.1

5 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.55.0
1.25.13
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.55.0
1.25.13
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
stdlib@go1.23.6
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.55.0
1.25.13

Open the chart page →

8,531
snyk-exportergrafana0.1.01 of 1See more

snyk-exporter grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/snyk_exporter:v1.4.1d3c9093401ca
stdlib@go1.21.0
1.25.13

Open the chart page →

670
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.55.0
1.25.13
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.55.0
1.25.13

Open the chart page →

5,327
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.55.0
1.25.13

Open the chart page →

7,518
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/net@v0.26.0
stdlib@go1.18.10
0.55.0
1.25.13

Open the chart page →

82,839
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:85d7043a4ffe0
stdlib@go1.26.5
1.25.13

Open the chart page →

5,083
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/net@v0.24.0
stdlib@go1.21.10
0.55.0
1.25.13

Open the chart page →

1,399
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.55.0
1.25.13

Open the chart page →

14,305
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.55.0
1.25.13

Open the chart page →

2,609
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.55.0
1.25.13

Open the chart page →

2,183
routergroundcover1.12.3784 of 7See more

router groundcover 1.12.378

4 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/net@v0.52.0
stdlib@go1.26.3
0.55.0
1.25.13
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.55.0
1.25.13
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
stdlib@go1.25.7
1.25.13
quay.io/groundcover/tools:20260719b705e0cbe171
stdlib@go1.24.4
1.25.13

Open the chart page →

6,256
temporalgroundcover1.12.3781 of 2See more

temporal groundcover 1.12.378

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
stdlib@go1.26.5
1.25.13

Open the chart page →

1,219
mysqlgroundhog2k3.1.41 of 1See more

mysql groundhog2k 3.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:9.7.230a0abfa7b50
stdlib@go1.24.6
1.25.13

Open the chart page →

463
tailscale-subnet-routergtaylor1.2.11 of 1See more

tailscale-subnet-router gtaylor 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
golang.org/x/net@v0.1.0
stdlib@go1.19.2-ts3fd24dee31
0.55.0
1.25.13

Open the chart page →

1,835
minifluxhajowielandVerified publisher1.0.01 of 1See more

miniflux hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

1,259
hakoniwahakoniwa0.1.01 of 1See more

hakoniwa hakoniwa 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/aplulu/hakoniwa:0.1.0accf0b921388
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13

Open the chart page →

338
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.55.0
1.25.13

Open the chart page →

2,382
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.3
0.55.0
1.25.13

Open the chart page →

4,464
mautrix-signalhalkeye0.3.01 of 2See more

mautrix-signal halkeye 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
signald/signald:0.23.2edbff058278c
stdlib@go1.18.10
1.25.13

Open the chart page →

1,500
thunderdome-planning-pokerhalkeye0.1.11 of 1See more

thunderdome-planning-poker halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
golang.org/x/net@v0.52.0
stdlib@go1.26.4
0.55.0
1.25.13

Open the chart page →

432
whoamihalkeye1.0.11 of 1See more

whoami halkeye 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
containous/whoami:v1.5.07d6a3c8f9147
stdlib@go1.14
1.25.13

Open the chart page →

1,280
hcp-terraform-operatorhashicorpVerified publisher2.12.12 of 2See more

hcp-terraform-operator hashicorp 2.12.1

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hashicorp/hcp-terraform-operator:2.12.15a15932f6838
stdlib@go1.26.5
1.25.13
quay.io/brancz/kube-rbac-proxy:v0.20.1f5fbfec6a2b2
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13

Open the chart page →

692
hatchet-apihatchetOfficialVerified publisher0.19.01 of 4See more

hatchet-api hatchet 0.19.0

1 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

1,736
hatchet-hahatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-ha hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

7,672
hatchet-stackhatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-stack hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

7,672
hawk-envoy-pluginhawk0.1.02 of 4See more

hawk-envoy-plugin hawk 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/collector-go:main7217f1a4fa28
stdlib@go1.17.13
1.25.13
ghcr.io/privacyengineering/consumer:main73f59c032812
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.13
0.55.0
1.25.13

Open the chart page →

64,356
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.6
0.55.0
1.25.13

Open the chart page →

3,031
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/net@v0.0.0-20200520182314-0ba52f642ac2
stdlib@go1.14.7
0.55.0
1.25.13

Open the chart page →

2,638
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.25.13

Open the chart page →

6,792
headcniheadcni1.0.101 of 1See more

headcni headcni 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
binrc/headcni:1.0.10e199c334b957
golang.org/x/net@v0.53.0
stdlib@go1.22.10
0.55.0
1.25.13

Open the chart page →

725
heliconehelicone0.1.422 of 14See more

helicone helicone 0.1.42

2 of the 14 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
stdlib@go1.19.5
1.25.13
supabase/gotrue:v2.91.07174d551d720
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.55.0
1.25.13

Open the chart page →

74,483
hello-gohello-goVerified publisher0.2.21 of 1See more

hello-go hello-go 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.25.13

Open the chart page →

1,316
hello_worldcharthellohelm0.1.01 of 1See more

hello_worldchart hellohelm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
dockerdaemon0901/rolldice:v14e5bfe179c7e
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.55.0
1.25.13

Open the chart page →

863
helm-airportshelm-airports0.1.02 of 7See more

helm-airports helm-airports 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.13
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

12,683
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

4,559
airports-postgreshelm-airports-dan0.1.01 of 1See more

airports-postgres helm-airports-dan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.13

Open the chart page →

1,027
helm-airportshelm-airports-dan0.1.02 of 7See more

helm-airports helm-airports-dan 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.13
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

5,586
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.55.0
1.25.13

Open the chart page →

4,559
airports-postgreshelm-airports-postgres0.1.01 of 1See more

airports-postgres helm-airports-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.13

Open the chart page →

1,027

Container images carrying it

5,406 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.55.0
1.25.13
1
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.55.0
1.25.13
1
quay.io/bentoml/yatai-image-builder:3.0.4401d8538c4f48
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.55.0
1.25.13
1
quay.io/brancz/kube-rbac-proxy:v0.15.02c7b120590cb
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.55.0
1.25.13
1
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.55.0
1.25.13
1
quay.io/brancz/kube-rbac-proxy:v0.18.0754ab2a723c8
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.55.0
1.25.13
1
quay.io/brancz/kube-rbac-proxy:v0.20.1f5fbfec6a2b2
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.55.0
1.25.13
1
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.55.0
1.25.13
1
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.5
0.55.0
1.25.13
1
quay.io/cephcsi/ceph-csi-operator:v0.5.014fe2f1bffc3
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
1
quay.io/cephcsi/ceph-csi-operator:v1.0.4c62933fd4083
stdlib@go1.25.11
1.25.13
1
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
stdlib@go1.15.7
1.25.13
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.55.0
1.25.13
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
golang.org/x/net@v0.41.0
stdlib@go1.24.2
0.55.0
1.25.13
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.55.0
1.25.13
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
golang.org/x/net@v0.41.0
stdlib@go1.24.7
0.55.0
1.25.13
1
quay.io/cilium/hubble-relay:v1.18.26079308ee15e
golang.org/x/net@v0.42.0
stdlib@go1.24.7
0.55.0
1.25.13
1
quay.io/cilium/hubble-ui-backend:v0.13.3db1454e45dc3
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.55.0
1.25.13
1
quay.io/cilium/operator-generic:v1.17.14773886ec9337
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.55.0
1.25.13
1
quay.io/cilium/operator-generic:v1.15.1819c7281f5a4
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.55.0
1.25.13
1
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
golang.org/x/net@v0.42.0
stdlib@go1.24.7
0.55.0
1.25.13
1
quay.io/cilium/tetragon:v1.1.096fac2482898
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.55.0
1.25.13
1
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.19.2
0.55.0
1.25.13
1
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.18.3
0.55.0
1.25.13
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18.1
0.55.0
1.25.13
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/net@v0.14.0
stdlib@go1.19.10
0.55.0
1.25.13
1
quay.io/codefresh/dind:3.0.250885ab519dac
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.55.0
1.25.13
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
stdlib@go1.23.8
1.25.13
1
quay.io/coreos/etcd:v3.5.11842975891182
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.55.0
1.25.13
1
quay.io/coreos/etcd:v3.5.16d967d98a12dc
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.55.0
1.25.13
1
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.3
0.55.0
1.25.13
1
quay.io/cortexproject/cortex:v1.21.18577eb292a01
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.55.0
1.25.13
1
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.23.0
0.55.0
1.25.13
1
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
stdlib@go1.26.5
1.25.13
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.6
0.55.0
1.25.13
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
1
quay.io/enix/x509-certificate-exporter:4.2.0afef14dc3862
stdlib@go1.26.5
1.25.13
1
quay.io/enix/zfs-exporter:2.3.1223b053f1cbd0
golang.org/x/net@v0.47.0
stdlib@go1.24.2
0.55.0
1.25.13
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/net@v0.25.0
stdlib@go1.23.6
0.55.0
1.25.13
1
quay.io/evl.ms/pgbouncer-exporter:0.4.074f919b78494
stdlib@go1.14.4
1.25.13
1
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
golang.org/x/net@v0.12.0
stdlib@go1.21.1
0.55.0
1.25.13
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
stdlib@go1.20.4
1.25.13
1
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
golang.org/x/net@v0.33.0
stdlib@go1.25.7
0.55.0
1.25.13
1
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
golang.org/x/net@v0.1.0
stdlib@go1.18.10
0.55.0
1.25.13
1
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.55.0
1.25.13
1
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
stdlib@go1.18.5
1.25.13
1
quay.io/fiware/vcverifier:6.21.251ed1e979094
golang.org/x/net@v0.38.0
0.55.0
1
quay.io/fiware/vcverifier:2.0.1cd36290dc849
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.55.0
1.25.13
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.55.0
1.25.13
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.