StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,217
of 17,988 indexed, latest versions
Container images
4,746
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 4,217 of 17,988 indexed charts deploy, on 4,746 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+183 more1.25.104,746
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

4,217 by stars
ChartLatestAffected imagesRadar Score
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
stdlib@go1.17.8
1.25.10
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
stdlib@go1.17.5
1.25.10
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
stdlib@go1.17.8
1.25.10

Open the chart page →

10,331
livekit-serverbeeinventor1.0.01 of 2See more

livekit-server beeinventor 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.0.08391fd1b834f
stdlib@go1.17.10
1.25.10

Open the chart page →

3,635
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
stdlib@go1.17.12
1.25.10

Open the chart page →

2,296
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
stdlib@go1.20.8
1.25.10

Open the chart page →

3,455
yatai-image-builderbentomlVerified publisher3.0.441 of 1See more

yatai-image-builder bentoml 3.0.44

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-image-builder:3.0.4401d8538c4f48
stdlib@go1.24.13
1.25.10

Open the chart page →

694
aramid-indexerbiatec-repoVerified publisher3.9.04 of 5See more

aramid-indexer biatec-repo 3.9.0

4 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:14816cf7d06ec3
stdlib@go1.24.6
1.25.10
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
stdlib@go1.23.9
1.25.10
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
stdlib@go1.23.9
1.25.10
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
stdlib@go1.23.3
1.25.10

Open the chart page →

16,238
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
stdlib@go1.25.3
1.25.10

Open the chart page →

8,176
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
stdlib@go1.23.11
1.25.10

Open the chart page →

5,984
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
stdlib@go1.25.3
1.25.10

Open the chart page →

8,176
self-hostbitwarden2.5.11 of 11See more

self-host bitwarden 2.5.1

1 of the 11 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
stdlib@go1.23.1
1.25.10

Open the chart page →

4,447
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
stdlib@go1.21.6
1.25.10

Open the chart page →

3,445
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
stdlib@go1.21.8
1.25.10

Open the chart page →

2,069
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
stdlib@go1.13.10
1.25.10

Open the chart page →

9,584
btrfs-nfs-csibtrfs-nfs-csi0.4.06 of 7See more

btrfs-nfs-csi btrfs-nfs-csi 0.4.0

6 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
stdlib@go1.24.2
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
stdlib@go1.25.7
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
stdlib@go1.25.7
1.25.10

Open the chart page →

4,637
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
stdlib@go1.21.4
1.25.10

Open the chart page →

2,703
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
stdlib@go1.14.7
1.25.10

Open the chart page →

3,709
buildkite-agent-metricsbuildkite-agent-metrics0.1.01 of 1See more

buildkite-agent-metrics buildkite-agent-metrics 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
stdlib@go1.25.1
1.25.10

Open the chart page →

1,871
buildkit-fleetbuildkit-fleetVerified publisher0.1.21 of 1See more

buildkit-fleet buildkit-fleet 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
moby/buildkit:v0.33.0-rootless80b15f0735e8
stdlib@go1.25.7
1.25.10

Open the chart page →

1,120
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
stdlib@go1.24.2
1.25.10

Open the chart page →

2,085
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
stdlib@go1.24.2
1.25.10

Open the chart page →

2,085
pgcagriekinVerified publisher2.2.11 of 2See more

pg cagriekin 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.2-pg186559f9b476e1
stdlib@go1.24.4
1.25.10

Open the chart page →

2,186
pgvectorcagriekinVerified publisher2.2.12 of 3See more

pgvector cagriekin 2.2.1

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.0.2-pg186559f9b476e1
stdlib@go1.24.4
1.25.10
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
stdlib@go1.24.6
1.25.10

Open the chart page →

4,441
camel-dashboard-operatorcamel-dashboardVerified publisher0.1.01 of 1See more

camel-dashboard-operator camel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
stdlib@go1.25.9
1.25.10

Open the chart page →

716
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
stdlib@go1.22.2
1.25.10

Open the chart page →

1,299
capsulecapsuleOfficialVerified publisher0.14.61 of 2See more

capsule capsule 0.14.6

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.25.10

Open the chart page →

1,669
capsule-proxycapsule-proxyOfficialVerified publisher0.14.11 of 2See more

capsule-proxy capsule-proxy 0.14.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
stdlib@go1.22.5
1.25.10

Open the chart page →

1,693
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
stdlib@go1.16.2
1.25.10

Open the chart page →

4,555
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
stdlib@go1.23.0
1.25.10

Open the chart page →

2,194
cert-estuarycert-estuaryVerified publisher0.2.11 of 1See more

cert-estuary cert-estuary 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/hsn723/cert-estuary:0.2.00c4b6132b0ad
stdlib@go1.26.2
1.25.10

Open the chart page →

427
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
stdlib@go1.22.4
1.25.10
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
stdlib@go1.21.12
1.25.10
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
stdlib@go1.21.12
1.25.10
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
stdlib@go1.21.12
1.25.10
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
stdlib@go1.21.12
1.25.10
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
stdlib@go1.21.12
1.25.10
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
stdlib@go1.21.12
1.25.10

Open the chart page →

15,807
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
stdlib@go1.24.4
1.25.10

Open the chart page →

1,423
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
stdlib@go1.22.0
1.25.10

Open the chart page →

1,498
cert-vaultcert-vaultOfficialVerified publisher2.12.04 of 7See more

cert-vault cert-vault 2.12.0

4 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
stdlib@go1.23.7
1.25.10
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
stdlib@go1.23.7
1.25.10
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.25.10
library/postgres:17f4c66b820c6f
stdlib@go1.24.6
1.25.10

Open the chart page →

18,264
chatclichatcliVerified publisher1.212.11 of 2See more

chatcli chatcli 1.212.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
stdlib@go1.23.10
1.25.10

Open the chart page →

1,330
chatcli-operatorchatcli-operatorVerified publisher1.212.11 of 2See more

chatcli-operator chatcli-operator 1.212.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
stdlib@go1.23.10
1.25.10

Open the chart page →

1,342
passbolt-hachristianhuthVerified publisher6.0.13 of 4See more

passbolt-ha christianhuth 6.0.1

3 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.10
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
stdlib@go1.24.6
1.25.10
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.25.10

Open the chart page →

13,920
squestchristianhuthVerified publisher6.6.82 of 4See more

squest christianhuth 6.6.8

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.25.10
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.10

Open the chart page →

11,942
typo3christianhuthVerified publisher7.8.11 of 2See more

typo3 christianhuth 7.8.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.10

Open the chart page →

9,818
challengerchronicleVerified publisher0.1.21 of 1See more

challenger chronicle 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
stdlib@go1.22.12
1.25.10

Open the chart page →

1,263
spectrechronicleVerified publisher0.3.91 of 1See more

spectre chronicle 0.3.9

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
stdlib@go1.25.5
1.25.10

Open the chart page →

1,903
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
stdlib@go1.22.1
1.25.10

Open the chart page →

1,071
clairclair0.0.31 of 1See more

clair clair 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.7.28d38ffa8fad7
stdlib@go1.20.9
1.25.10

Open the chart page →

3,833
clamav-restclamav-rest-apiVerified publisher0.1.01 of 1See more

clamav-rest clamav-rest-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ajilaag/clamav-rest:latestad689c7b75b1
stdlib@go1.26.0
1.25.10

Open the chart page →

756
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:18-alpine6c538e7206ea
stdlib@go1.24.6
1.25.10

Open the chart page →

2,603
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
stdlib@go1.20.1
1.25.10
cloudbees/sidecar-injector:2.3.38f102ef0383a
stdlib@go1.20.1
1.25.10

Open the chart page →

4,474
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.25.10
prom/prometheus:v2.21.0d43417c260e5
stdlib@go1.15.2
1.25.10

Open the chart page →

6,263
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
stdlib@go1.17.6
1.25.10
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
stdlib@go1.18.6
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
stdlib@go1.17.6
1.25.10

Open the chart page →

10,052
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.25.10

Open the chart page →

3,829
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.25.10

Open the chart page →

2,809
grafanacloudposse0.2.61 of 1See more

grafana cloudposse 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:latestac461fb352ab
stdlib@go1.25.7
1.25.10

Open the chart page →

854

Container images carrying it

4,746 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-39820.

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.