StackRadar

CVE-2026-71556

High

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
205
of 17,781 indexed, latest versions
Container images
207
deployed by those charts
Fix available
2 of 2
affected packages

go-git: Worktree operations may follow symlinks

Carried by container images the latest versions of 205 of 17,781 indexed charts deploy, on 207 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+23 more5.19.2205
github.com/go-git/go-git/v6golangv6.0.0-alpha.3, v6.0.0-alpha.4.0.20260520124234-0860a7d8a1646.0.0-alpha.52
OSV records
GHSA-hc8v-wwc9-vgxm
Also known as
GO-2026-6213

Charts affected

205 by stars
ChartLatestAffected imagesRadar Score
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/go-git/go-git/v5@v5.13.2
5.19.2

Open the chart page →

45,239
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/go-git/go-git/v5@v5.16.0
5.19.2

Open the chart page →

969
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,650
mesherywenerme1.0.691 of 1See more

meshery wenerme 1.0.69

1 of the 1 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest9b68e81d392e
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,407
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
rancher/shell:v0.8.1f293af9c635f
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,456

Container images carrying it

207 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/external-secrets/external-secrets:v2.4.19440a40b3947
github.com/go-git/go-git/v5@v5.18.0
5.19.2
1
ghcr.io/external-secrets/external-secrets:v2.1.0ec40c3d9c48f
github.com/go-git/go-git/v5@v5.16.3
5.19.2
1
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
github.com/go-git/go-git/v5@v5.13.2
5.19.2
1
ghcr.io/fluxcd/image-automation-controller:v1.2.26b0b16ab2115
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
ghcr.io/fluxcd/notification-controller:v1.9.29ce503e7bcb8
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/go-git/go-git/v5@v5.13.2
5.19.2
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
ghcr.io/lockdep/stackradar-scanner:0.3.0dd8a35d50c2d
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
ghcr.io/mydecisive/octant:0.1.86ebbd44abae6c
github.com/go-git/go-git/v5@v5.18.0
5.19.2
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
github.com/go-git/go-git/v5@v5.2.0
5.19.2
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
github.com/go-git/go-git/v5@v5.16.2
5.19.2
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
github.com/go-git/go-git/v5@v5.16.2
5.19.2
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
github.com/go-git/go-git/v5@v5.17.1
5.19.2
1
ghcr.io/okteto/backend:0.0.0-2026-08-03244f87e8c52d
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
ghcr.io/okteto/okteto:3.22.0-beta.1e787b6bce27d
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
ghcr.io/openclarity/grype-server:v0.6.079412399f301
github.com/go-git/go-git/v5@v5.8.1
5.19.2
1
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
ghcr.io/peak-scale/capsule-argo-addon:0.7.5087a80163971
github.com/go-git/go-git/v5@v5.16.2
5.19.2
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/go-git/go-git/v5@v5.5.2
5.19.2
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/go-git/go-git/v5@v5.5.2
5.19.2
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/go-git/go-git/v5@v5.5.2
5.19.2
1
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/go-git/go-git/v5@v5.5.2
5.19.2
1
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
github.com/go-git/go-git/v5@v5.13.0
5.19.2
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
github.com/go-git/go-git/v5@v5.14.0
5.19.2
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
github.com/go-git/go-git/v5@v5.16.2
5.19.2
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/go-git/go-git/v5@v5.7.0
5.19.2
1
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
github.com/go-git/go-git/v5@v5.16.0
5.19.2
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
github.com/go-git/go-git/v5@v5.16.0
5.19.2
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
github.com/go-git/go-git/v5@v5.14.0
5.19.2
1
quay.io/argoprojlabs/argocd-operator:v0.18.0a09814522a72
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
quay.io/argoprojlabs/argocd-rbac-operator:v0.2.451dded00137a
github.com/go-git/go-git/v5@v5.14.0
5.19.2
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/go-git/go-git/v5@v5.3.0
5.19.2
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/go-git/go-git/v5@v5.3.0
5.19.2
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/go-git/go-git/v5@v5.6.1
5.19.2
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/go-git/go-git/v5@v5.19.0
5.19.2
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.