StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,218
of 17,985 indexed, latest versions
Container images
4,748
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 4,218 of 17,985 indexed charts deploy, on 4,748 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+183 more1.25.104,748
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

4,218 by stars
ChartLatestAffected imagesRadar Score
kubeservice-custom-limitrangekubservice-chartsVerified publisher1.3.05 of 5See more

kubeservice-custom-limitrange kubservice-charts 1.3.0

5 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kubeservice-stack/customlimitrange-manager:v1.3.0d3ed97d142d4
stdlib@go1.24.1
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
stdlib@go1.20.8
1.25.10
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
stdlib@go1.20.8
1.25.10
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
stdlib@go1.20.8
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
stdlib@go1.20.8
1.25.10

Open the chart page →

8,503
kubeservice-ebpf-exporterkubservice-chartsVerified publisher1.2.11 of 1See more

kubeservice-ebpf-exporter kubservice-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cloudflare/ebpf_exporter:v2.3.075370b2ec2bb
stdlib@go1.21.5
1.25.10

Open the chart page →

906
kubeservice-namespace-node-affinitykubservice-chartsVerified publisher1.1.25 of 5See more

kubeservice-namespace-node-affinity kubservice-charts 1.1.2

5 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
dongjiang1989/ns-node-affinity:latest451f7823723c
stdlib@go1.18.5
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
stdlib@go1.20.8
1.25.10
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
stdlib@go1.20.8
1.25.10
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
stdlib@go1.20.8
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
stdlib@go1.20.8
1.25.10

Open the chart page →

9,547
kubeservice-scheduler-pluskubservice-chartsVerified publisher0.2.11 of 2See more

kubeservice-scheduler-plus kubservice-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
stdlib@go1.19.9
1.25.10

Open the chart page →

2,337
ingress-annotatorkuossOfficialVerified publisher0.3.01 of 1See more

ingress-annotator kuoss 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kuoss/ingress-annotator:v0.3.0ae179f65d869
stdlib@go1.24.6
1.25.10

Open the chart page →

763
kube-fencingkvaps2.4.12 of 2See more

kube-fencing kvaps 2.4.1

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
stdlib@go1.18.8
1.25.10
ghcr.io/kvaps/kube-fencing-switcher:v2.4.0f8c378e63b78
stdlib@go1.18.8
1.25.10

Open the chart page →

3,748
linstorkvaps1.14.04 of 11See more

linstor kvaps 1.14.0

4 of the 11 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
stdlib@go1.15.14
1.25.10
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
stdlib@go1.15.14
1.25.10
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
stdlib@go1.15.14
1.25.10
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
stdlib@go1.15.14
1.25.10

Open the chart page →

21,514
kymaroskymarosVerified publisher0.6.91 of 1See more

kymaros kymaros 0.6.9

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/kymaroshq/kymaros:0.6.9fb3b88633381
stdlib@go1.25.9
1.25.10

Open the chart page →

442
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
stdlib@go1.20.12
1.25.10

Open the chart page →

5,979
authz-pdplabs64io-helm-chartsVerified publisher0.8.31 of 1See more

authz-pdp labs64io-helm-charts 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/cerbos/cerbos:0.51.08d35a64e4a99
stdlib@go1.25.6
1.25.10

Open the chart page →

1,038
checkoutlabs64io-helm-chartsVerified publisher0.11.31 of 3See more

checkout labs64io-helm-charts 0.11.3

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:185a5a84b19854
stdlib@go1.24.6
1.25.10

Open the chart page →

1,693
payment-gatewaylabs64io-helm-chartsVerified publisher0.10.31 of 2See more

payment-gateway labs64io-helm-charts 0.10.3

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:185a5a84b19854
stdlib@go1.24.6
1.25.10

Open the chart page →

3,168
lagoon-remotelagoon-chartsVerified publisher0.107.01 of 1See more

lagoon-remote lagoon-charts 0.107.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
stdlib@go1.24.3
1.25.10

Open the chart page →

2,906
landelijketabellencataloguslandelijketabellencatalogus1.0.01 of 3See more

landelijketabellencatalogus landelijketabellencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
stdlib@go1.13.10
1.25.10

Open the chart page →

9,277
lgtmlgtmVerified publisher0.28.01 of 9See more

lgtm lgtm 0.28.0

1 of the 9 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:13.2.2-distroless69a5d2d957ca
stdlib@go1.25.7
1.25.10

Open the chart page →

1,358
lgtm-stacklgtm-stackVerified publisher0.1.31 of 8See more

lgtm-stack lgtm-stack 0.1.3

1 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/grafana:13.1.0121a7a9ece6d
stdlib@go1.25.7
1.25.10

Open the chart page →

3,319
keptn-cert-managerlifecycle-toolkitVerified publisher0.3.01 of 1See more

keptn-cert-manager lifecycle-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
stdlib@go1.23.3
1.25.10

Open the chart page →

826
keptn-lifecycle-operatorlifecycle-toolkitVerified publisher0.6.01 of 1See more

keptn-lifecycle-operator lifecycle-toolkit 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
stdlib@go1.23.3
1.25.10

Open the chart page →

943
keptn-metrics-operatorlifecycle-toolkitVerified publisher0.5.01 of 1See more

keptn-metrics-operator lifecycle-toolkit 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
stdlib@go1.23.3
1.25.10

Open the chart page →

1,179
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
stdlib@go1.13.8
1.25.10

Open the chart page →

5,653
linkerd-jaegerlinkerd2-edgeVerified publisher30.14.11-edge2 of 4See more

linkerd-jaeger linkerd2-edge 30.14.11-edge

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
stdlib@go1.17.6
1.25.10
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
stdlib@go1.20.7
1.25.10

Open the chart page →

5,791
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
stdlib@go1.23.8
1.25.10

Open the chart page →

9,506
go-hello-worldloafoe0.17.01 of 1See more

go-hello-world loafoe 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/loafoe/go-hello-world:v2.16.022d94845e317
stdlib@go1.26.0
1.25.10

Open the chart page →

408
home-assistantloeken-at-homeVerified publisher2026.5.11 of 1See more

home-assistant loeken-at-home 2026.5.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
loeken/home-assistant:2026.5.14ce6abc553b3
stdlib@go1.23.3
1.25.10

Open the chart page →

3,841
jspolicyloftVerified publisher0.2.21 of 1See more

jspolicy loft 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
loftsh/jspolicy:0.2.225deb9bd2683
stdlib@go1.17.13
1.25.10

Open the chart page →

3,143
vcluster-eksloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-eks loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
stdlib@go1.16.15
1.25.10
public.ecr.aws/eks-distro/kubernetes/kube-apiserver:v1.24.9-eks-1-24-772e06b605692
stdlib@go1.18.9
1.25.10
public.ecr.aws/eks-distro/kubernetes/kube-controller-manager:v1.24.9-eks-1-24-7eaea8c230432
stdlib@go1.18.9
1.25.10

Open the chart page →

5,214
vcluster-k0sloftVerified publisher0.0.0-ci.31 of 2See more

vcluster-k0s loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
stdlib@go1.19.4
1.25.10

Open the chart page →

3,844
log2rbac-operatorlog2rbac-operator0.0.51 of 1See more

log2rbac-operator log2rbac-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jkremser/log2rbac:v0.0.5e35cf56ef183
stdlib@go1.17.6
1.25.10

Open the chart page →

2,815
logclilogcliVerified publisher0.1.01 of 1See more

logcli logcli 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
grafana/logcli:main-c90366d-amd643d85bb66e39b
stdlib@go1.16.2
1.25.10

Open the chart page →

3,947
voice-biometricslumenvox2.0.18 of 26See more

voice-biometrics lumenvox 2.0.1

8 of the 26 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.10
library/traefik:v2.57d5a6ae66572
stdlib@go1.17.6
1.25.10
lumenvox/cloud-init-tools:2.0.07ff037a71c50
stdlib@go1.17.3
1.25.10
lumenvox/cloud-license:2.0.09a69862e1248
stdlib@go1.17.3
1.25.10
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.10
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.25.10
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
stdlib@go1.15.8
1.25.10
quay.io/prometheus/prometheus:v2.26.038d40a760569
stdlib@go1.16.2
1.25.10

Open the chart page →

81,405
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/luzilla/dnsbl_exporter:v0.12.0ecba7360ff12
stdlib@go1.25.0
1.25.10

Open the chart page →

1,880
lynqlynqVerified publisher1.1.221 of 1See more

lynq lynq 1.1.22

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/k8s-lynq/lynq:1.1.22229b05e3c717
stdlib@go1.24.13
1.25.10

Open the chart page →

837
magentomagento3.2.35 of 12See more

magento magento 3.2.3

5 of the 12 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
stdlib@go1.18.2
1.25.10
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.25.10
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
stdlib@go1.24.6
1.25.10
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
stdlib@go1.24.6
1.25.10
longhornio/longhorn-ui:v1.10.0e60f36161511
stdlib@go1.24.6
1.25.10

Open the chart page →

16,967
mcp-orchestratormagertronVerified publisher4.0.131 of 7See more

mcp-orchestrator magertron 4.0.13

1 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.25.10

Open the chart page →

1,798
goblackholemainVerified publisher0.0.41 of 1See more

goblackhole main 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bedag/goblackhole:0.2.0447a88598f4c
stdlib@go1.16.6
1.25.10

Open the chart page →

3,052
plane-enterprisemakeplaneOfficialVerified publisher3.10.21 of 13See more

plane-enterprise makeplane 3.10.2

1 of the 13 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.25.10

Open the chart page →

5,662
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:885b9bf2e29cf
stdlib@go1.24.6
1.25.10

Open the chart page →

22,279
mcpmcp-chartsVerified publisher0.0.232 of 7See more

mcp mcp-charts 0.0.23

2 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
stdlib@go1.25.4
1.25.10
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
stdlib@go1.25.4
1.25.10

Open the chart page →

8,307
traefik-forward-authmesosphere0.3.102 of 2See more

traefik-forward-auth mesosphere 0.3.10

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
stdlib@go1.15.11
1.25.10
mesosphere/traefik-forward-auth:3.1.05456581d7b76
stdlib@go1.14.15
1.25.10

Open the chart page →

7,597
metadata-injectormetadata-injector-operator0.0.11 of 1See more

metadata-injector metadata-injector-operator 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ruslanguns/metadata-injector-operator:v0.0.16c77e4675e07
stdlib@go1.22.11
1.25.10

Open the chart page →

893
subspacemglants0.1.01 of 1See more

subspace mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
subspacecommunity/subspace:1.5.0e2042b63fb35
stdlib@go1.14.6
1.25.10

Open the chart page →

4,299
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
stdlib@go1.23.4
1.25.10

Open the chart page →

4,932
librenmsmidokura-communityVerified publisher0.3.21 of 6See more

librenms midokura-community 0.3.2

1 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
librenms/librenms:22.4.14f1f3d667cc7
stdlib@go1.16.12
1.25.10

Open the chart page →

9,845
chartmuseummike75151.2.01 of 1See more

chartmuseum mike7515 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
stdlib@go1.17.8
1.25.10

Open the chart page →

4,019
miniapiminiapi1.3.21 of 1See more

miniapi miniapi 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
udhos/miniapi:1.3.28a7042db82ce
stdlib@go1.23.2
1.25.10

Open the chart page →

1,144
miropsmirops-operatorVerified publisher0.2.02 of 2See more

mirops mirops-operator 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/miropshq/mirops/operator:v0.2.04b0b5fef9a6a
stdlib@go1.24.13
1.25.10
ghcr.io/miropshq/mirops/remediation:v0.2.0976a7319ff4a
stdlib@go1.24.13
1.25.10

Open the chart page →

1,447
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
stdlib@go1.25.5
1.25.10

Open the chart page →

7,135
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
stdlib@go1.25.4
1.25.10

Open the chart page →

36,842
model-manager-loadermodel-manager-loader1.27.01 of 1See more

model-manager-loader model-manager-loader 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
stdlib@go1.24.0
1.25.10

Open the chart page →

3,388
model-manager-servermodel-manager-server1.27.01 of 1See more

model-manager-server model-manager-server 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-server:1.27.0c057dcdd9ef3
stdlib@go1.23.12
1.25.10

Open the chart page →

1,032

Container images carrying it

4,748 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-39820.

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.