StackRadar

CVE-2026-71557

Medium

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
205
of 17,781 indexed, latest versions
Container images
207
deployed by those charts
Fix available
2 of 2
affected packages

go-git: Malicious reference names may modify files outside the reference storage

Carried by container images the latest versions of 205 of 17,781 indexed charts deploy, on 207 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+23 more5.19.2205
github.com/go-git/go-git/v6golangv6.0.0-alpha.3, v6.0.0-alpha.4.0.20260520124234-0860a7d8a1646.0.0-alpha.52
OSV records
GHSA-qgq7-7hm3-q39j
Also known as
GO-2026-6214

Charts affected

205 by stars
ChartLatestAffected imagesRadar Score
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-71557.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/go-git/go-git/v5@v5.13.2
5.19.2

Open the chart page →

45,239
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-71557.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/go-git/go-git/v5@v5.16.0
5.19.2

Open the chart page →

969
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-71557.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,650
mesherywenerme1.0.691 of 1See more

meshery wenerme 1.0.69

1 of the 1 container images this version deploys carry CVE-2026-71557.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest9b68e81d392e
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,407
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-71557.

Container imageDigestPackageFixed in
rancher/shell:v0.8.1f293af9c635f
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,456

Container images carrying it

207 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
quay.io/operator-framework/catalogd:v1.8.06ff40fa6257f
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
quay.io/operator-framework/operator-controller:v1.8.0bca5dfcc67ca
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-git/go-git/v5@v5.3.0
5.19.2
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.