StackRadar

CVE-2026-39820

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,221
of 17,966 indexed, latest versions
Container images
4,754
deployed by those charts
Fix available
1 of 2
affected packages

Quadratic string concatentation in consumeComment in net/mail

Carried by container images the latest versions of 4,221 of 17,966 indexed charts deploy, on 4,754 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+183 more1.25.104,754
OSV records
DEBIAN-CVE-2026-39820GO-2026-4986
Also known as
BIT-golang-2026-39820

Charts affected

4,221 by stars
ChartLatestAffected imagesRadar Score
mimirmimir0.1.101 of 1See more

mimir mimir 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
stdlib@go1.24.13
1.25.10

Open the chart page →

385
zkapps-dashboardminaVerified publisher0.1.21 of 2See more

zkapps-dashboard mina 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.25.10

Open the chart page →

1,783
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
stdlib@go1.24.6
1.25.10

Open the chart page →

13,740
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
stdlib@go1.17.4
1.25.10

Open the chart page →

6,151
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:13-alpinefb9065b6e3e2
stdlib@go1.24.6
1.25.10

Open the chart page →

116,845
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
stdlib@go1.19.7
1.25.10

Open the chart page →

11,248
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
stdlib@go1.19.7
1.25.10

Open the chart page →

11,248
helmmirasys-chart0.1.01 of 4See more

helm mirasys-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.10

Open the chart page →

4,077
jupyterhubmizzoukube0.0.1-set.by.chartpress1 of 7See more

jupyterhub mizzoukube 0.0.1-set.by.chartpress

1 of the 7 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
stdlib@go1.21.7
1.25.10

Open the chart page →

1,907
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
stdlib@go1.15.13
1.25.10

Open the chart page →

2,857
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
stdlib@go1.13.14
1.25.10

Open the chart page →

7,951
echoperatormmontesVerified publisher0.0.21 of 1See more

echoperator mmontes 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
stdlib@go1.18.3
1.25.10

Open the chart page →

1,834
mariadbmmontesVerified publisher0.3.01 of 1See more

mariadb mmontes 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mariadb:10.7.307e06f2e7ae9
stdlib@go1.16.7
1.25.10

Open the chart page →

10,387
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.25.10

Open the chart page →

7,334
basic-git-servermoikot0.0.21 of 1See more

basic-git-server moikot 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
moikot/basic-git-server:0.0.20d941bd30ffa
stdlib@go1.14.9
1.25.10

Open the chart page →

2,959
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
stdlib@go1.14.4
1.25.10

Open the chart page →

2,562
smartthings-metricsmoikot0.1.01 of 1See more

smartthings-metrics moikot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:0.1.08625f53aa9b7
stdlib@go1.14.13
1.25.10

Open the chart page →

1,750
smartthings-metrics-feat-log-detailsmoikot0.0.921 of 1See more

smartthings-metrics-feat-log-details moikot 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:feat-log-detailsfb8565140106
stdlib@go1.14.15
1.25.10

Open the chart page →

1,738
docker-registrymoinologics0.1.11 of 1See more

docker-registry moinologics 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/registry:2a3d8aaa63ed8
stdlib@go1.20.8
1.25.10

Open the chart page →

553
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
stdlib@go1.18.7
1.25.10

Open the chart page →

2,508
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.10

Open the chart page →

12,383
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.10

Open the chart page →

12,383
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.10

Open the chart page →

12,805
backendmojaloop0.1.05 of 6See more

backend mojaloop 0.1.0

5 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
stdlib@go1.18.2
1.25.10
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
stdlib@go1.17
1.25.10
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
stdlib@go1.23.8
1.25.10
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
stdlib@go1.16.4
1.25.10
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
stdlib@go1.21.5
1.25.10

Open the chart page →

16,787
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.10

Open the chart page →

20,144
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.25.10

Open the chart page →

6,403
mollysocketmollysocket-wrenixVerified publisher0.1.141 of 2See more

mollysocket mollysocket-wrenix 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.3c4a11ae9a1cb
stdlib@go1.25.7
1.25.10

Open the chart page →

2,641
eks-pod-identity-webhookmondu-aiVerified publisher0.3.11 of 1See more

eks-pod-identity-webhook mondu-ai 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
stdlib@go1.26.2
1.25.10

Open the chart page →

469
gar-credential-providermondu-aiVerified publisher0.2.11 of 1See more

gar-credential-provider mondu-ai 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
stdlib@go1.26.0
1.25.10

Open the chart page →

737
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
stdlib@go1.25.9
1.25.10

Open the chart page →

5,505
enterprise-operatormongodb-helm-charts1.33.01 of 1See more

enterprise-operator mongodb-helm-charts 1.33.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
stdlib@go1.24.2
1.25.10

Open the chart page →

1,646
mongodb-query-exportermongodb-query-exporterVerified publisher5.1.01 of 1See more

mongodb-query-exporter mongodb-query-exporter 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/raffis/mongodb-query-exporter:v5.1.0ca6ac8a5b329
stdlib@go1.20.5
1.25.10

Open the chart page →

984
mongodb-secure-backupmongodb-secure-backup1.0.01 of 2See more

mongodb-secure-backup mongodb-secure-backup 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
stdlib@go1.22.10
1.25.10

Open the chart page →

1,037
mongopingmongoping1.3.11 of 1See more

mongoping mongoping 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
udhos/mongoping:1.3.103b08b63f524
stdlib@go1.24.2
1.25.10

Open the chart page →

1,390
monitoringmonitoring0.1.01 of 1See more

monitoring monitoring 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
jkaninda/grafana:11.0.08cfda26ecb7d
stdlib@go1.21.10
1.25.10

Open the chart page →

1,941
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
stdlib@go1.17.10
1.25.10

Open the chart page →

12,447
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
stdlib@go1.17.10
1.25.10

Open the chart page →

9,354
mqtt-loggermoreillonVerified publisher0.3.12 of 5See more

mqtt-logger moreillon 0.3.1

2 of the 5 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
stdlib@go1.19.6
1.25.10
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
stdlib@go1.17.10
1.25.10

Open the chart page →

11,416
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
stdlib@go1.19.12
1.25.10

Open the chart page →

27,219
backupmorremeyer4.0.01 of 1See more

backup morremeyer 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
restic/restic:0.15.2579e4e6a4931
stdlib@go1.19.8
1.25.10

Open the chart page →

2,308
hcloud-ccm-networksmorremeyer2.0.01 of 1See more

hcloud-ccm-networks morremeyer 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
stdlib@go1.20.5
1.25.10

Open the chart page →

1,760
hcloud-csi-drivermorremeyer3.0.06 of 6See more

hcloud-csi-driver morremeyer 3.0.0

6 of the 6 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
stdlib@go1.19.7
1.25.10
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
stdlib@go1.19
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
stdlib@go1.19
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.10

Open the chart page →

7,248
chirpstackmosquitto-helm-chart0.5.03 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

3 of the 8 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3fb7667fe037f
stdlib@go1.19.3
1.25.10
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
stdlib@go1.19.3
1.25.10
oliver006/redis_exporter:v1.14.0d55e056987af
stdlib@go1.15.6
1.25.10

Open the chart page →

103,204
chirpstack-event-forwardmosquitto-helm-chart0.1.21 of 1See more

chirpstack-event-forward mosquitto-helm-chart 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
stdlib@go1.17.10
1.25.10

Open the chart page →

1,850
replacermosquitto-helm-chart0.2.02 of 3See more

replacer mosquitto-helm-chart 0.2.0

2 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
stdlib@go1.17.7
1.25.10
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
stdlib@go1.17.7
1.25.10

Open the chart page →

3,936
configmapsecretsmozilla0.0.11 of 1See more

configmapsecrets mozilla 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
stdlib@go1.16.1
1.25.10

Open the chart page →

2,105
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
stdlib@go1.20.12
1.25.10

Open the chart page →

4,801
ms-hello-webms-hello-test0.1.01 of 1See more

ms-hello-web ms-hello-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
irakli/ms-web-hello:latest966a4bfefe27
stdlib@go1.19.2
1.25.10

Open the chart page →

758
adguard-homemt1905024.0.121 of 2See more

adguard-home mt190502 4.0.12

1 of the 2 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.737fbf01d73ecb
stdlib@go1.25.7
1.25.10

Open the chart page →

1,201
codimdmt1905027.2.21 of 3See more

codimd mt190502 7.2.2

1 of the 3 container images this version deploys carry CVE-2026-39820.

Container imageDigestPackageFixed in
library/postgres:1886c951e05bf5
stdlib@go1.24.6
1.25.10

Open the chart page →

1,446

Container images carrying it

4,754 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.10
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.10
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.