StackRadar

CVE-2026-21438

Medium

Advisory

Published 12 Feb 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
29
of 17,781 indexed, latest versions
Container images
25
deployed by those charts
Fix available
1 of 1
affected package

webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map

Carried by container images the latest versions of 29 of 17,781 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
github.com/quic-go/webtransport-gogolangv0.5.3, v0.6.0, v0.8.0, v0.8.1-0.20241018022711-4ac2c9250e66+1 more0.10.025
OSV records
GHSA-2f2x-8mwp-p2gc
Also known as
GO-2026-4483

Charts affected

29 by stars
ChartLatestAffected imagesRadar Score
bscdysnixVerified publisher0.6.591 of 4See more

bsc dysnix 0.6.59

1 of the 4 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

2,012
aramid-indexerbiatec-repoVerified publisher3.9.01 of 5See more

aramid-indexer biatec-repo 3.9.0

1 of the 5 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

13,357
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

7,190
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

5,059
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

7,190
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
github.com/quic-go/webtransport-go@v0.8.0
0.10.0

Open the chart page →

1,799
spectrechronicleVerified publisher0.3.81 of 1See more

spectre chronicle 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

1,515
evccevccVerified publisher1.0.471 of 1See more

evcc evcc 1.0.47

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
evcc/evcc:0.300.8ddf2a25afce5
github.com/quic-go/webtransport-go@v0.9.0
0.10.0

Open the chart page →

1,181
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
github.com/quic-go/webtransport-go@v0.9.0
0.10.0

Open the chart page →

6,929
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ipfs/kubo:v0.24.0e3de33bd746b
github.com/quic-go/webtransport-go@v0.6.0
0.10.0

Open the chart page →

4,661
celestia-localastria9.0.01 of 2See more

celestia-local astria 9.0.0

1 of the 2 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
github.com/quic-go/webtransport-go@v0.9.0
0.10.0

Open the chart page →

3,281
celestia-nodeastria0.7.11 of 1See more

celestia-node astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
github.com/quic-go/webtransport-go@v0.9.0
0.10.0

Open the chart page →

1,502
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

7,190
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

5,059
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

7,405
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
github.com/quic-go/webtransport-go@v0.8.0
0.10.0

Open the chart page →

4,810
spirechronicleVerified publisher0.3.61 of 1See more

spire chronicle 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

1,515
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
iotaledger/hornet:2.001206f1ba89c
github.com/quic-go/webtransport-go@v0.5.3
0.10.0

Open the chart page →

13,391
armiarmaethereum-helm-chartsVerified publisher0.1.21 of 2See more

armiarma ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ethpandaops/armiarma:master1a9c3264f0a9
github.com/quic-go/webtransport-go@v0.6.0
0.10.0

Open the chart page →

1,155
forkyethereum-helm-chartsVerified publisher0.2.01 of 1See more

forky ethereum-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ethpandaops/forky:debian-latestc937f4ba737c
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

1,703
beeethersphereVerified publisher0.17.41 of 1See more

bee ethersphere 0.17.4

1 of the 1 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ethersphere/bee:2.2.0a884fd84b72f
github.com/quic-go/webtransport-go@v0.6.0
0.10.0

Open the chart page →

3,456
edgemeshkubesphere-stable0.1.01 of 2See more

edgemesh kubesphere-stable 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
kubeedge/edgemesh-agent:latest460c6061b608
github.com/quic-go/webtransport-go@v0.5.3
0.10.0

Open the chart page →

4,096
chainrss30.1.281 of 8See more

chain rss3 0.1.28

1 of the 8 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/webtransport-go@v0.6.0
0.10.0

Open the chart page →

8,528
vsl-chainrss30.1.01 of 7See more

vsl-chain rss3 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
github.com/quic-go/webtransport-go@v0.6.0
0.10.0

Open the chart page →

6,044
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/webtransport-go@v0.6.0
0.10.0

Open the chart page →

4,610
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/webtransport-go@v0.6.0
0.10.0

Open the chart page →

4,610
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

1,239
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/quic-go/webtransport-go@v0.8.0
0.10.0

Open the chart page →

6,779
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-21438.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0

Open the chart page →

1,239

Container images carrying it

25 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/webtransport-go@v0.6.0
0.10.0
3
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
2
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
github.com/quic-go/webtransport-go@v0.9.0
0.10.0
2
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/quic-go/webtransport-go@v0.8.0
0.10.0
1
ethersphere/bee:2.2.0a884fd84b72f
github.com/quic-go/webtransport-go@v0.6.0
0.10.0
1
ethpandaops/armiarma:master1a9c3264f0a9
github.com/quic-go/webtransport-go@v0.6.0
0.10.0
1
ethpandaops/forky:debian-latestc937f4ba737c
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
evcc/evcc:0.300.8ddf2a25afce5
github.com/quic-go/webtransport-go@v0.9.0
0.10.0
1
iotaledger/hornet:2.001206f1ba89c
github.com/quic-go/webtransport-go@v0.5.3
0.10.0
1
ipfs/kubo:v0.24.0e3de33bd746b
github.com/quic-go/webtransport-go@v0.6.0
0.10.0
1
kubeedge/edgemesh-agent:latest460c6061b608
github.com/quic-go/webtransport-go@v0.5.3
0.10.0
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
github.com/quic-go/webtransport-go@v0.6.0
0.10.0
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
github.com/quic-go/webtransport-go@v0.8.0
0.10.0
1
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
github.com/quic-go/webtransport-go@v0.8.0
0.10.0
1
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
github.com/quic-go/webtransport-go@v0.8.1-0.20241018022711-4ac2c9250e66
0.10.0
1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
github.com/quic-go/webtransport-go@v0.9.0
0.10.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.