StackRadar

CVE-2026-41506

Medium

Advisory

Published 17 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
156
of 17,781 indexed, latest versions
Container images
163
deployed by those charts
Fix available
1 of 1
affected package

go-git: Credential leak via cross-host redirect in smart HTTP transport

Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 163 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+20 more5.18.0163
OSV records
GHSA-3xc5-wrhm-f963
Also known as
GO-2026-5105

Charts affected

156 by stars
ChartLatestAffected imagesRadar Score
screenersynapse0.2.51 of 4See more

screener synapse 0.2.5

1 of the 4 container images this version deploys carry CVE-2026-41506.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
github.com/go-git/go-git/v5@v5.12.0
5.18.0

Open the chart page →

1,091
scribesynapse0.2.162 of 7See more

scribe synapse 0.2.16

2 of the 7 container images this version deploys carry CVE-2026-41506.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.18.0
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
github.com/go-git/go-git/v5@v5.12.0
5.18.0

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-41506.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
github.com/go-git/go-git/v5@v5.11.0
5.18.0

Open the chart page →

1,955
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-41506.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/go-git/go-git/v5@v5.11.0
5.18.0

Open the chart page →

2,477
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-41506.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/go-git/go-git/v5@v5.13.2
5.18.0

Open the chart page →

45,239
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-41506.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/go-git/go-git/v5@v5.16.0
5.18.0

Open the chart page →

969

Container images carrying it

163 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
github.com/go-git/go-git/v5@v5.14.0
5.18.0
1
quay.io/argoprojlabs/argocd-operator:v0.18.0a09814522a72
github.com/go-git/go-git/v5@v5.16.5
5.18.0
1
quay.io/argoprojlabs/argocd-rbac-operator:v0.2.451dded00137a
github.com/go-git/go-git/v5@v5.14.0
5.18.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/go-git/go-git/v5@v5.3.0
5.18.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/go-git/go-git/v5@v5.3.0
5.18.0
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/go-git/go-git/v5@v5.6.1
5.18.0
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/go-git/go-git/v5@v5.11.0
5.18.0
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
github.com/go-git/go-git/v5@v5.11.0
5.18.0
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/go-git/go-git/v5@v5.11.0
5.18.0
1
quay.io/operator-framework/catalogd:v1.8.06ff40fa6257f
github.com/go-git/go-git/v5@v5.16.5
5.18.0
1
quay.io/operator-framework/operator-controller:v1.8.0bca5dfcc67ca
github.com/go-git/go-git/v5@v5.16.5
5.18.0
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-git/go-git/v5@v5.3.0
5.18.0
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/go-git/go-git/v5@v5.16.2
5.18.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.