StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,086
of 17,837 indexed, latest versions
Container images
4,643
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 4,086 of 17,837 indexed charts deploy, on 4,643 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,643
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

4,086 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

4,643 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-39820.

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.