StackRadar

CVE-2026-71556

High

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
205
of 17,781 indexed, latest versions
Container images
207
deployed by those charts
Fix available
2 of 2
affected packages

go-git: Worktree operations may follow symlinks

Carried by container images the latest versions of 205 of 17,781 indexed charts deploy, on 207 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+23 more5.19.2205
github.com/go-git/go-git/v6golangv6.0.0-alpha.3, v6.0.0-alpha.4.0.20260520124234-0860a7d8a1646.0.0-alpha.52
OSV records
GHSA-hc8v-wwc9-vgxm
Also known as
GO-2026-6213

Charts affected

205 by stars
ChartLatestAffected imagesRadar Score
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/go-git/go-git/v5@v5.13.2
5.19.2

Open the chart page →

45,239
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/go-git/go-git/v5@v5.16.0
5.19.2

Open the chart page →

969
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,650
mesherywenerme1.0.691 of 1See more

meshery wenerme 1.0.69

1 of the 1 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest9b68e81d392e
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,407
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
rancher/shell:v0.8.1f293af9c635f
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,456

Container images carrying it

207 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/openshift/origin-cli:latest605eaa5d469c
github.com/go-git/go-git/v5@v5.19.1
5.19.2
7
quay.io/devtron/dex:v2.30.22e4c14d1b444
github.com/go-git/go-git/v5@v5.2.0
5.19.2
6
quay.io/devtron/kubectl:latest2ad610626658
github.com/go-git/go-git/v5@v5.4.2
5.19.2
6
rancher/shell:v0.8.1f293af9c635f
github.com/go-git/go-git/v5@v5.19.1
5.19.2
4
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/go-git/go-git/v5@v5.12.0
5.19.2
4
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/go-git/go-git/v5@v5.19.1
5.19.2
3
tykio/tyk-dashboard:v5.13.10e03b94c153d
github.com/go-git/go-git/v5@v5.19.1
5.19.2
3
ghcr.io/dexidp/dex:v2.45.18499afd690c4
github.com/go-git/go-git/v5@v5.16.4
5.19.2
3
quay.io/argoproj/argocd:v3.5.2e2aadfae709d
github.com/go-git/go-git/v5@v5.19.1
5.19.2
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
github.com/go-git/go-git/v5@v5.13.2
5.19.2
3
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
github.com/go-git/go-git/v5@v5.16.0
5.19.2
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
github.com/go-git/go-git/v5@v5.13.2
5.19.2
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/go-git/go-git/v5@v5.7.0
5.19.2
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/go-git/go-git/v5@v5.16.5
5.19.2
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/go-git/go-git/v5@v5.6.1
5.19.2
3
grafana/alloy:v1.8.17790f6f7fbd8
github.com/go-git/go-git/v5@v5.13.0
5.19.2
2
grafana/alloy:v1.12.2f94b1c82957a
github.com/go-git/go-git/v5@v5.16.2
5.19.2
2
grafana/grafana:9.2.4057896e23443
github.com/go-git/go-git/v5@v5.4.2
5.19.2
2
meshery/meshery:stable-latest9b68e81d392e
github.com/go-git/go-git/v5@v5.19.1
5.19.2
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
github.com/go-git/go-git/v5@v5.1.0
5.19.2
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/go-git/go-git/v5@v5.13.2
5.19.2
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/go-git/go-git/v5@v5.4.2
5.19.2
2
ghcr.io/appscode/fargocd:v0.0.31f5c791fc54d
github.com/go-git/go-git/v5@v5.19.1
5.19.2
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
github.com/go-git/go-git/v5@v5.2.0
5.19.2
2
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
github.com/go-git/go-git/v5@v5.19.1
5.19.2
2
ghcr.io/fluxcd/source-controller:v1.9.22b8d06650a1b
github.com/go-git/go-git/v5@v5.19.1
5.19.2
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
github.com/go-git/go-git/v5@v5.13.2
5.19.2
2
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/go-git/go-git/v5@v5.16.0
5.19.2
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/go-git/go-git/v5@v5.4.2
5.19.2
2
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
github.com/go-git/go-git/v5@v5.13.0
5.19.2
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
github.com/go-git/go-git/v5@v5.0.0
5.19.2
1
aquasec/trivy:0.43.1944a04445179
github.com/go-git/go-git/v5@v5.7.0
5.19.2
1
aquasec/trivy:0.32.0973d0df16189
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
aquasec/trivy:0.69.3bcc376de8d77
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
artifacthub/hub:v1.19.0111918d8c399
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
artifacthub/hub:v1.23.07d3a91c539dc
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
artifacthub/scanner:v1.23.02d8365601f0e
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
artifacthub/tracker:v1.23.05368d21a6e5c
github.com/go-git/go-git/v5@v5.16.2
5.19.2
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
bluenviron/mediamtx:1.17.19e39256d1ba3
github.com/go-git/go-git/v5@v5.17.2
5.19.2
1
buddyspencer/gickup:0.10.386b656f19b0c1
github.com/go-git/go-git/v5@v5.14.0
5.19.2
1
buddyspencer/gickup:0.10.309e7dbf923c12
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
casbin/casdoor:v1.753.0770ad9ec3190
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
casbin/casdoor:3.62.17729da148c61
github.com/go-git/go-git/v5@v5.16.3
5.19.2
1
casbin/casdoor:3.62.0e08231f16c00
github.com/go-git/go-git/v5@v5.16.3
5.19.2
1
chaosnative/cle-server:2.7.0e7bcff4a20c0
github.com/go-git/go-git/v5@v5.3.0
5.19.2
1
charmcli/soft-serve:v0.4.039523c1a6ba8
github.com/go-git/go-git/v5@v5.4.3-0.20210630082519-b4368b2a2ca4
5.19.2
1
datadog/agent:6aad9994de6a7
github.com/go-git/go-git/v5@v5.13.0
5.19.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.