StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,218
of 17,985 indexed, latest versions
Container images
4,748
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 4,218 of 17,985 indexed charts deploy, on 4,748 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+183 more1.25.104,748
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

4,218 by stars
ChartLatestAffected imagesRadar Score
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
stdlib@go1.15.15
1.25.10
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
stdlib@go1.21.9
1.25.10

Open the chart page →

9,318
pbuf-registrypbuf-registry0.4.12 of 2See more

pbuf-registry pbuf-registry 0.4.1

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:18.1-alpine3.2144d837eb4c2e
stdlib@go1.24.6
1.25.10
ghcr.io/pbufio/registry:v0.4.177a36c035b4b
stdlib@go1.25.5
1.25.10

Open the chart page →

2,690
pdf-editor-helmpdf-editor-web1.0.02 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
stdlib@go1.18.7
1.25.10
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
stdlib@go1.18.7
1.25.10

Open the chart page →

5,403
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
stdlib@go1.24.4
1.25.10

Open the chart page →

8,324
periscopeperiscopeVerified publisher1.1.61 of 1See more

periscope periscope 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
stdlib@go1.26.2
1.25.10

Open the chart page →

1,145
pgbouncerpgbouncer-helm0.6.01 of 2See more

pgbouncer pgbouncer-helm 0.6.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
stdlib@go1.23.7
1.25.10

Open the chart page →

728
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
stdlib@go1.20.1
1.25.10
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
stdlib@go1.20.1
1.25.10
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
stdlib@go1.20.1
1.25.10
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
stdlib@go1.20.1
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
stdlib@go1.19
1.25.10

Open the chart page →

10,335
chadbotphntom0.2.31 of 1See more

chadbot phntom 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
phntom/chadbot:0.2.397c28e4178ad
stdlib@go1.21.5
1.25.10

Open the chart page →

1,557
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
stdlib@go1.19.3
1.25.10

Open the chart page →

3,620
phonebook-chartphonebook-chart0.1.01 of 3See more

phonebook-chart phonebook-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10

Open the chart page →

3,745
phpipamphpipam-helmVerified publisher1.0.121 of 3See more

phpipam phpipam-helm 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.25.10

Open the chart page →

4,590
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
stdlib@go1.15.8
1.25.10

Open the chart page →

3,121
matomopockostVerified publisher1.4.01 of 3See more

matomo pockost 1.4.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mariadb:12.3.3dd9b303aed4f
stdlib@go1.24.6
1.25.10

Open the chart page →

6,033
podtracepodtraceOfficialVerified publisher0.14.81 of 2See more

podtrace podtrace 0.14.8

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
alpine/k8s:1.37.0b421c2e9419e
stdlib@go1.24.0
1.25.10

Open the chart page →

1,053
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Open the chart page →

3,193
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.25.10

Open the chart page →

35,779
postfix-exporterpostfix-exporterVerified publisher0.2.01 of 1See more

postfix-exporter postfix-exporter 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/hsn723/postfix_exporter:0.20.0b7da7c554018
stdlib@go1.26.2
1.25.10

Open the chart page →

579
postgres-backuppostgres-backup0.3.02 of 2See more

postgres-backup postgres-backup 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.25.10
nerzhul/mc-arm64:2020.10.034215df511f31
stdlib@go1.15.2
1.25.10

Open the chart page →

5,471
postgresqlpostgresqlVerified publisher0.3.172 of 2See more

postgresql postgresql 0.3.17

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:18.6-alpine77f585114c32
stdlib@go1.24.6
1.25.10
pgautoupgrade/pgautoupgrade:18-alpine2245aabc5b80
stdlib@go1.24.6
1.25.10

Open the chart page →

1,090
postgresqlpostgresql-helm0.1.21 of 1See more

postgresql postgresql-helm 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
stdlib@go1.24.6
1.25.10

Open the chart page →

1,693
rethinkdbpozetron1.1.91 of 1See more

rethinkdb pozetron 1.1.9

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
stdlib@go1.16.9
1.25.10

Open the chart page →

4,310
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.10

Open the chart page →

3,140
home-assistantpree-helm-chartsVerified publisher1.82.01 of 1See more

home-assistant pree-helm-charts 1.82.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.43e6710a7ab2a
stdlib@go1.23.3
1.25.10

Open the chart page →

2,897
preparrpreparr0.19.71 of 6See more

preparr preparr 0.19.7

1 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.25.10

Open the chart page →

1,165
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.25.10

Open the chart page →

6,705
prometheus-druid-exporterprometheus-communityVerified publisher1.2.01 of 1See more

prometheus-druid-exporter prometheus-community 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/opstree/druid-exporter:v0.119f01c9c5c2e3
stdlib@go1.15.15
1.25.10

Open the chart page →

1,996
prometheus-pingmesh-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-pingmesh-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:v1.2.2c82de0272da0
stdlib@go1.22.9
1.25.10

Open the chart page →

1,196
prometheus-sql-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-sql-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/justwatchcom/sql_exporter:v0.8c4b1d3d0f052
stdlib@go1.24.4
1.25.10

Open the chart page →

1,775
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.25.10
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.25.10
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.25.10
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.25.10
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
stdlib@go1.15.3
1.25.10

Open the chart page →

14,949
operatorpunchplatform8.1.131 of 1See more

operator punchplatform 8.1.13

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
stdlib@go1.22.0
1.25.10

Open the chart page →

1,169
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
stdlib@go1.19
1.25.10

Open the chart page →

2,354
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
stdlib@go1.14.2
1.25.10

Open the chart page →

62,586
qt-vaultqt-vaultVerified publisher0.1.21 of 1See more

qt-vault qt-vault 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/mcman2017/qt-vault:v0.1.2852edf54c850
stdlib@go1.24.11
1.25.10

Open the chart page →

526
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
stdlib@go1.19.4
1.25.10

Open the chart page →

7,783
rabbitmqrabbitmq-magefleet1.2.01 of 1See more

rabbitmq rabbitmq-magefleet 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.25.10

Open the chart page →

3,465
velero-s3-deploymentradar-baseVerified publisher0.4.33 of 4See more

velero-s3-deployment radar-base 0.4.3

3 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
velero/velero:v1.9.0277fbfaf8dcf
stdlib@go1.18
1.25.10
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
stdlib@go1.17.11
1.25.10
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
stdlib@go1.23.4
1.25.10

Open the chart page →

6,940
rbac-serverrbac-server1.19.11 of 1See more

rbac-server rbac-server 1.19.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/rbac-server:1.19.1df1adeb86679
stdlib@go1.23.12
1.25.10

Open the chart page →

999
rclonercloneVerified publisher2.2.01 of 1See more

rclone rclone 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
rclone/rclone:1.6874c51b8817e5
stdlib@go1.23.3
1.25.10

Open the chart page →

2,043
redis-enterprise-operatorredis-enterprise-operatorVerified publisher7.13.4-121 of 1See more

redis-enterprise-operator redis-enterprise-operator 7.13.4-12

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
redislabs/operator:7.4.2-2ecb101af0506
stdlib@go1.21.5
1.25.10

Open the chart page →

3,170
redis-sentinel-gatewayredis-sentinel-gatewayVerified publisher1.0.21 of 1See more

redis-sentinel-gateway redis-sentinel-gateway 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
promzeus/redis-sentinel-gateway:v182f6d56e280b
stdlib@go1.22.6
1.25.10

Open the chart page →

3,233
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
stdlib@go1.24.6
1.25.10

Open the chart page →

5,134
docker-registry-mirrorregistry-mirror1.0.11 of 1See more

docker-registry-mirror registry-mirror 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.25.10

Open the chart page →

940
reportportalreportportal-ioOfficialVerified publisher26.8.125 of 15See more

reportportal reportportal-io 26.8.12

5 of the 15 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
stdlib@go1.24.2
1.25.10
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.10
library/rabbitmq:4.3.4-managementeb5295d08332
stdlib@go1.22.2
1.25.10
reportportal/migrations:5.15.4464468240d7b
stdlib@go1.24.6
1.25.10
reportportal/service-index:5.15.1b1860ed33071
stdlib@go1.26.2
1.25.10

Open the chart page →

15,203
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.25.10

Open the chart page →

8,496
resurfaceresurfaceioVerified publisher3.9.02 of 3See more

resurface resurfaceio 3.9.0

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
stdlib@go1.22.2
1.25.10
resurfaceio/resurface:3.7.84d5cda2f64109
stdlib@go1.23.0
1.25.10

Open the chart page →

8,580
right-sizerright-sizer0.6.21 of 1See more

right-sizer right-sizer 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
aavishay/right-sizer:0.6.23d7c4d79595c
stdlib@go1.25.8
1.25.10

Open the chart page →

470
backup-repository-serverriotkit-org4.0.01 of 1See more

backup-repository-server riotkit-org 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
stdlib@go1.17.13
1.25.10

Open the chart page →

2,838
rke2-ingress-nginxrke2-charts4.15.1102 of 2See more

rke2-ingress-nginx rke2-charts 4.15.110

2 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
rancher/kube-webhook-certgen:v1.14.5-hardened26bb869baf40b
stdlib@go1.26.2
1.25.10
rancher/nginx-ingress-controller:v1.14.5-hardened26cbc1e932b5b
stdlib@go1.24.13
1.25.10

Open the chart page →

1,302
cloudflare-tunnelrlex0.8.01 of 1See more

cloudflare-tunnel rlex 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2023.10.0c18744ae1767
stdlib@go1.20.6
1.25.10

Open the chart page →

2,289
hcloud-fip-controllerrlex0.2.51 of 1See more

hcloud-fip-controller rlex 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
stdlib@go1.15.3
1.25.10

Open the chart page →

3,985

Container images carrying it

4,748 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-39820.

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.