StackRadar

CVE-2026-39821

High

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,507
of 17,803 indexed, latest versions
Container images
5,247
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 4,507 of 17,803 indexed charts deploy, on 5,247 images.

Affected packageAffected versionsFixed inImages
git-lfsrpm2.13.3-3.el8_60:3.4.1-11.el8_101
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.135,211
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,667
OSV records
RHSA-2026:30853GO-2026-5026

Charts affected

4,507 by stars
ChartLatestAffected imagesRadar Score
pet-battle-tournamentpetbattle1.0.402 of 3See more

pet-battle-tournament petbattle 1.0.40

2 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:latest605eaa5d469c
stdlib@go1.26.5
1.25.13
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.12
0.55.0
1.25.13

Open the chart page →

15,474
mariadbpetersandor15.2.51 of 1See more

mariadb petersandor 15.2.5

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/mariadb:11.7.216a7dae804fb
stdlib@go1.22.12
1.25.13

Open the chart page →

2,924
mongodbpetersandor14.1.81 of 1See more

mongodb petersandor 14.1.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/mongodb:8.0.8b3bd5b6be9a0
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.55.0
1.25.13

Open the chart page →

4,156
redispetersandor15.2.21 of 1See more

redis petersandor 15.2.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
bitnami/redis:7.4.24e65bf641805
stdlib@go1.23.8
1.25.13

Open the chart page →

2,762
lan-orangutanpeterweissdkVerified publisher0.1.01 of 1See more

lan-orangutan peterweissdk 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/291-group/lan-orangutan:3.3.886b55c80eeb1
stdlib@go1.25.12
1.25.13

Open the chart page →

251
whoamiphilippwaller1.0.31 of 1See more

whoami philippwaller 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
traefik/whoami:v1.8.08d0f943abdbf
stdlib@go1.17.7
1.25.13

Open the chart page →

1,007
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
stdlib@go1.16
1.25.13

Open the chart page →

6,527
container-agentphntom100.0.11 of 1See more

container-agent phntom 100.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
circleci/container-agent:34d8d0ae5efc3
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.55.0
1.25.13

Open the chart page →

1,974
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.55.0
1.25.13

Open the chart page →

4,644
goalertphntom0.0.291 of 1See more

goalert phntom 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
phntom/goalert:0.0.298ca4df55499b
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

1,050
kochiphntom1.1.41 of 1See more

kochi phntom 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
phntom/kochi:1.1.33b82358bd56e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.5
0.55.0
1.25.13

Open the chart page →

2,964
loki-stackphntom2.10.22 of 2See more

loki-stack phntom 2.10.2

2 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/loki:2.4.2b3af8ead67d7
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.17.2
0.55.0
1.25.13
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.17.2
0.55.0
1.25.13

Open the chart page →

5,724
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.16.2
0.55.0
1.25.13

Open the chart page →

4,159
npre-essentialsphntom0.1.6013 of 22See more

npre-essentials phntom 0.1.60

13 of the 22 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.25.13
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.55.0
1.25.13
grafana/promtail:2.7.0c16c710f7333
golang.org/x/net@v0.0.0-20220920203100-d0c6ba3f52d9
stdlib@go1.19.2
0.55.0
1.25.13
phntom/chartmuseum:v0.15.29242b4df9e65
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.18.5
0.55.0
1.25.13
phntom/kochi:1.1.33b82358bd56e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.5
0.55.0
1.25.13
phntom/oauth2-proxy:v7.3.48ea656a2a895
golang.org/x/net@v0.0.0-20221012135044-0b7e1fb9d458
stdlib@go1.19.2
0.55.0
1.25.13
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.55.0
1.25.13
quay.io/prometheus-operator/prometheus-operator:v0.61.1cd7d1a82ef00
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.55.0
1.25.13
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.55.0
1.25.13
quay.io/prometheuscommunity/elasticsearch-exporter:v1.5.013a41e8ac836
stdlib@go1.18.4
1.25.13
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.55.0
1.25.13
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.55.0
1.25.13
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
stdlib@go1.19.3
0.55.0
1.25.13

Open the chart page →

26,888
prometheus-elasticsearch-exporterphntom4.5.11 of 2See more

prometheus-elasticsearch-exporter phntom 4.5.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.25.13

Open the chart page →

2,030
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
stdlib@go1.19
1.25.13

Open the chart page →

22,165
picoclawpicoclawVerified publisher0.1.261 of 1See more

picoclaw picoclaw 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/mattn/picoclaw:latest517556c8b144
golang.org/x/net@v0.50.0
stdlib@go1.26.0
0.55.0
1.25.13

Open the chart page →

1,550
piepieVerified publisher0.11.11 of 1See more

pie pie 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/topolvm/pie:0.18.0aa467443e407
golang.org/x/net@v0.49.0
0.55.0

Open the chart page →

2,171
pagespighosh-pages1.0.01 of 3See more

pages pighosh-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13

Open the chart page →

20,262
blockmeta-servicepinaxVerified publisher0.0.31 of 1See more

blockmeta-service pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
golang.org/x/net@v0.19.0
stdlib@go1.22.1
0.55.0
1.25.13

Open the chart page →

1,688
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.55.0
1.25.13

Open the chart page →

3,544
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13

Open the chart page →

7,193
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.55.0
1.25.13

Open the chart page →

6,777
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.55.0
1.25.13

Open the chart page →

6,722
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.24.5
0.55.0
1.25.13

Open the chart page →

4,971
pipelockpipelockVerified publisher3.5.01 of 1See more

pipelock pipelock 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/luckypipewrench/pipelock:3.5.073e5d240f2ae
stdlib@go1.25.12
1.25.13

Open the chart page →

65
pixie-operator-chartpixie0.1.71 of 3See more

pixie-operator-chart pixie 0.1.7

1 of the 3 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned1b6002156f56
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13

Open the chart page →

1,907
pixie-operator-helm2-chartpixie0.1.21 of 2See more

pixie-operator-helm2-chart pixie 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinnedf9ea8cef95ac
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.55.0
1.25.13

Open the chart page →

1,762
planectlplanectlVerified publisher0.7.06 of 10See more

planectl planectl 0.7.0

6 of the 10 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
golang.org/x/net@v0.9.0
stdlib@go1.22.3
0.55.0
1.25.13
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
stdlib@go1.24.6
1.25.13
gitea/act_runner:0.2.11c57233403eff
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.55.0
1.25.13
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.25.13
pulumi/pulumi-kubernetes-operator:v2.5.17dace4491358
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.55.0
1.25.13
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/net@v0.34.0
stdlib@go1.22.2
0.55.0
1.25.13

Open the chart page →

26,158
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.12
0.55.0
1.25.13

Open the chart page →

11,162
pixiecorepnnl-miscscripts0.0.161 of 1See more

pixiecore pnnl-miscscripts 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
pnnlmiscscripts/pixiecore:1.0.1-1c6f17741a0d7
golang.org/x/net@v0.7.0
stdlib@go1.24.1
0.55.0
1.25.13

Open the chart page →

943
tenant-namespacepnnl-miscscripts0.6.231 of 1See more

tenant-namespace pnnl-miscscripts 0.6.23

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.55.0
1.25.13

Open the chart page →

2,578
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
golang.org/x/net@v0.48.0
stdlib@go1.19.13
0.55.0
1.25.13

Open the chart page →

13,089
podnat-controllerpodnat-controller0.5.21 of 1See more

podnat-controller podnat-controller 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
gutmensch/podnat-controller:0.5.2566979793fc4
golang.org/x/net@v0.4.0
stdlib@go1.22.3
0.55.0
1.25.13

Open the chart page →

984
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.25.13

Open the chart page →

11,255
static-sitepodzone-chartsVerified publisher0.1.11 of 2See more

static-site podzone-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
stdlib@go1.20.10
1.25.13

Open the chart page →

6,587
trainingjobspolyaxon2.1.01 of 1See more

trainingjobs polyaxon 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
polyaxon/training-operator:2.1.0b5b29deaec9a
golang.org/x/net@v0.17.0
stdlib@go1.20.13
0.55.0
1.25.13

Open the chart page →

726
portagerportager0.5.01 of 1See more

portager portager 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/jarodr47/portager:0.5.06a7a61b37568
stdlib@go1.26.5
1.25.13

Open the chart page →

144
beylaportefaix-hub0.1.01 of 1See more

beyla portefaix-hub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
grafana/beyla:1.3.336d07f8d276e
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.55.0
1.25.13

Open the chart page →

2,701
cloudflare-tunnelportefaix-hub0.4.01 of 1See more

cloudflare-tunnel portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.8.314d9c6b01b29
golang.org/x/net@v0.25.0
stdlib@go1.22.2-devel-cf
0.55.0
1.25.13

Open the chart page →

1,313
podtato-headportefaix-hub0.3.06 of 6See more

podtato-head portefaix-hub 0.3.0

6 of the 6 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/podtato-head/entry:latestc3d9d9c98be7
stdlib@go1.19
1.25.13
ghcr.io/podtato-head/hat:latestde37ff39a4c0
stdlib@go1.19
1.25.13
ghcr.io/podtato-head/left-arm:latest97596c95276a
stdlib@go1.19
1.25.13
ghcr.io/podtato-head/left-leg:latest00bb31622b1e
stdlib@go1.19
1.25.13
ghcr.io/podtato-head/right-arm:latest5f8f97a60558
stdlib@go1.19
1.25.13
ghcr.io/podtato-head/right-leg:latest03e125b9279e
stdlib@go1.19
1.25.13

Open the chart page →

5,279
prometheus-bbox-exporterportefaix-hub0.4.11 of 1See more

prometheus-bbox-exporter portefaix-hub 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nlamirault/bbox_exporter:1.0.0f5dd1f7794c6
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.18.3
0.55.0
1.25.13

Open the chart page →

2,014
prometheus-freebox-exporterportefaix-hub0.1.11 of 1See more

prometheus-freebox-exporter portefaix-hub 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/nlamirault/freebox-exporter:1.0.02d522b664e12
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.2
0.55.0
1.25.13

Open the chart page →

1,755
speedtest-exporterportefaix-hub0.5.01 of 1See more

speedtest-exporter portefaix-hub 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
stdlib@go1.16.6
1.25.13

Open the chart page →

1,209
unifi-pollerportefaix-hub0.1.01 of 1See more

unifi-poller portefaix-hub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
golift/unifi-poller:v2.9.5486a63339969
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.55.0
1.25.13

Open the chart page →

975
postgrespostgresVerified publisher0.1.11 of 1See more

postgres postgres 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:13.12ced3ba927f4c
stdlib@go1.18.2
1.25.13

Open the chart page →

4,951
svc-postgrespostgres-fiap-lanches0.1.01 of 1See more

svc-postgres postgres-fiap-lanches 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.13

Open the chart page →

1,667
liftbridgepozetron0.1.11 of 1See more

liftbridge pozetron 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
stdlib@go1.13.12
0.55.0
1.25.13

Open the chart page →

3,174
Practica_4_helmpr04helm0.1.03 of 7See more

Practica_4_helm pr04helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.13
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.13

Open the chart page →

27,697
practica-helmpractica-helm0.1.03 of 7See more

practica-helm practica-helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-39821.

Container imageDigestPackageFixed in
library/mongo:4.4-bionic3d0e6df9fd5b
stdlib@go1.16.3
1.25.13
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13
slagattollas/weatherservice-practica:latest68e7f56393fc
stdlib@go1.15.6
1.25.13

Open the chart page →

28,537

Container images carrying it

5,247 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.13
89
library/postgres:18:18.6:18.6-trixie:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.13
69
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.13
22
library/postgres:16.15-alpine:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.13
17
library/postgres:18.6-alpine:18-alpine:alpined3e1620b530c
stdlib@go1.24.6
1.25.13
17
library/mysql:8:8.4:8.4.11b3b90af2a655
stdlib@go1.24.6
1.25.13
16
minio/minio:latest:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.55.0
1.25.13
15
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.13
14
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.55.0
1.25.13
13
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13
13
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.55.0
1.25.13
13
grafana/grafana:latestf772d434e8fa
golang.org/x/net@v0.51.0
stdlib@go1.26.5
0.55.0
1.25.13
12
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.13
12
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.13
12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.55.0
1.25.13
12
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.55.0
1.25.13
12
library/mariadb:12.3.3:latest:ltsdd9b303aed4f
stdlib@go1.24.6
1.25.13
11
library/mongo:8:8.3.8:latest5211c51171f5
stdlib@go1.26.5
1.25.13
11
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.13
11
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.13
11
bitnami/mongodb:lateste46cffb66274
stdlib@go1.26.5
1.25.13
10
ethpandaops/xatu:latest74d4cf2c436c
golang.org/x/net@v0.54.0
stdlib@go1.26.5
0.55.0
1.25.13
10
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.55.0
1.25.13
10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.13
10
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.13
10
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
stdlib@go1.26.3
1.25.13
10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.55.0
1.25.13
9
library/rabbitmq:3.13-management:3-managemente582c0bc7766
stdlib@go1.22.2
1.25.13
8
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.55.0
1.25.13
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.55.0
1.25.13
8
quay.io/prometheus/node-exporter:latest:v1.12.11b4e4438faca
stdlib@go1.26.5
1.25.13
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.55.0
1.25.13
8
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.13
7
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.55.0
1.25.13
7
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.55.0
1.25.13
7
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.55.0
1.25.13
7
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.13
7
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.25.13
7
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.55.0
1.25.13
7
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.55.0
1.25.13
7
quay.io/openshift/origin-cli:latest605eaa5d469c
stdlib@go1.26.5
1.25.13
7
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
stdlib@go1.26.5
1.25.13
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/net@v0.30.0
stdlib@go1.23.4
0.55.0
1.25.13
7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
stdlib@go1.26.4
1.25.13
7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.55.0
1.25.13
7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.55.0
1.25.13
7
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.55.0
1.25.13
7
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.55.0
1.25.13
7
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.55.0
1.25.13
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.13
6

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.