StackRadar

CVE-2026-71557

Medium

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
205
of 17,781 indexed, latest versions
Container images
207
deployed by those charts
Fix available
2 of 2
affected packages

go-git: Malicious reference names may modify files outside the reference storage

Carried by container images the latest versions of 205 of 17,781 indexed charts deploy, on 207 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+23 more5.19.2205
github.com/go-git/go-git/v6golangv6.0.0-alpha.3, v6.0.0-alpha.4.0.20260520124234-0860a7d8a1646.0.0-alpha.52
OSV records
GHSA-qgq7-7hm3-q39j
Also known as
GO-2026-6214

Charts affected

205 by stars
ChartLatestAffected imagesRadar Score
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-71557.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/go-git/go-git/v5@v5.13.2
5.19.2

Open the chart page →

45,239
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-71557.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/go-git/go-git/v5@v5.16.0
5.19.2

Open the chart page →

969
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-71557.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,650
mesherywenerme1.0.691 of 1See more

meshery wenerme 1.0.69

1 of the 1 container images this version deploys carry CVE-2026-71557.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest9b68e81d392e
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,407
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-71557.

Container imageDigestPackageFixed in
rancher/shell:v0.8.1f293af9c635f
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,456

Container images carrying it

207 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
datawire/aes:3.11.195ec30b3c732
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
devopstales/trivy-operator:2.575136aa7a26e
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
dexidp/dex:v2.39.1-distroless43655afd1a8f
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
eceasy/cli-proxy-api:v7.2.15918f370d73b4d
github.com/go-git/go-git/v6@v6.0.0-alpha.4.0.20260520124234-0860a7d8a164
6.0.0-alpha.5
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
github.com/go-git/go-git/v5@v5.4.3-0.20210630082519-b4368b2a2ca4
5.19.2
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
epamedp/reconciler:2.12.0d33e938b6d59
github.com/go-git/go-git/v5@v5.4.3-0.20210630082519-b4368b2a2ca4
5.19.2
1
flanksource/apm-hub:v0.0.471dacc3195bf9
github.com/go-git/go-git/v5@v5.6.1
5.19.2
1
flanksource/batch-runner:v1.0.44689687a7cf95
github.com/go-git/go-git/v5@v5.16.2
5.19.2
1
fluxcd/flux-cli:v2.9.5704d55295355
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
fluxcd/source-controller:v0.10.031a8c79a6803
github.com/go-git/go-git/v5@v5.2.0
5.19.2
1
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
gitea/act_runner:nightly7940221bcfc9
github.com/go-git/go-git/v5@v5.18.0
5.19.2
1
gitea/act_runner:0.3.1c2a169c5e998
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
gitea/act_runner:0.2.11c57233403eff
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
gitea/gitea:1.27.3-rootless1c17ecaead42
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
gitea/gitea:1.27.134e3f6b75f5c
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
gitea/gitea:1.22.376f516a1a8c2
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
gitea/gitea:1.26.27d13848af126
github.com/go-git/go-git/v5@v5.19.0
5.19.2
1
gitea/gitea:1.12.485416d6f65fe
github.com/go-git/go-git/v5@v5.1.0
5.19.2
1
gitea/gitea:1.27.387a67ee09d3a
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
gitea/gitea:1.21.6ac73e0da341f
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
gitea/gitea:1.13.0d5ab14cd29af
github.com/go-git/go-git/v5@v5.1.0
5.19.2
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/go-git/go-git/v5@v5.7.0
5.19.2
1
grafana/agent:v0.44.23364714a2f64
github.com/go-git/go-git/v5@v5.13.1
5.19.2
1
grafana/agent:v0.40.3f6cbec9409be
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
grafana/alloy:v1.5.101a63f4e032c
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
grafana/alloy:v1.4.306bdcbb51fc2
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
grafana/alloy:v1.18.10f4434c92b3e
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
grafana/alloy:v1.18.0491b0578c049
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
grafana/alloy:v1.16.384b76d56c594
github.com/go-git/go-git/v5@v5.18.0
5.19.2
1
grafana/alloy:v1.11.38c7256f412fe
github.com/go-git/go-git/v5@v5.16.2
5.19.2
1
grafana/alloy:v1.1.1c3dac4e26471
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
grafana/alloy:v1.14.0f50931848bd8
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
grafana/grafana:10.1.50679e877ba20
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
grafana/grafana:9.4.71a359d92f40e
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
grafana/grafana:9.5.239c849cebccc
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
grafana/grafana:9.4.376dcf36e7d2a
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
grafana/grafana:9.1.19746858c20e6
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
grafana/grafana:12.1.1a1701c218024
github.com/go-git/go-git/v5@v5.14.0
5.19.2
1
grafana/grafana:12.0.2b5b59bfc7561
github.com/go-git/go-git/v5@v5.14.0
5.19.2
1
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
github.com/go-git/go-git/v5@v5.14.0
5.19.2
1
hashicorp/waypoint:0.11.397d521a27498
github.com/go-git/go-git/v5@v5.2.0
5.19.2
1
invisibl/gravity-init:v1.0.91a970f84178b
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
ispras/svacer:11-2-042aa9fa9f189
github.com/go-git/go-git/v5@v5.14.0
5.19.2
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
kusionstack/kusion:v0.14.0126c8f0b0976
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.