StackRadar

CVE-2026-39822

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,463
of 17,911 indexed, latest versions
Container images
5,073
deployed by those charts
Fix available
1 of 1
affected package

Root escape via symlink plus trailing slash in os

Carried by container images the latest versions of 4,463 of 17,911 indexed charts deploy, on 5,073 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.125,073
OSV records
GO-2026-4970
Also known as
BIT-golang-2026-39822

Charts affected

4,463 by stars
ChartLatestAffected imagesRadar Score
connectkfirfer1.15.02 of 2See more

connect kfirfer 1.15.0

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
1password/connect-api:1.7.26aa94cf713f9
stdlib@go1.20.6
1.25.12
1password/connect-sync:1.7.2fe527ed9d81f
stdlib@go1.20.6
1.25.12

Open the chart page →

2,775
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
stdlib@go1.13.11
1.25.12

Open the chart page →

2,787
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
stdlib@go1.17.1
1.25.12

Open the chart page →

6,657
keelkfirfer1.0.51 of 1See more

keel kfirfer 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
keelhq/keel:0.19.202ac4ea616c4
stdlib@go1.20.5
1.25.12

Open the chart page →

2,079
kubernetes-replicatorkfirfer2.9.11 of 1See more

kubernetes-replicator kfirfer 2.9.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.9.1baf5f784398b
stdlib@go1.20.5
1.25.12

Open the chart page →

868
mysqldumpkfirfer2.8.01 of 1See more

mysqldump kfirfer 2.8.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
stdlib@go1.21.5
1.25.12

Open the chart page →

3,533
pod-cleanupkfirfer0.0.41 of 1See more

pod-cleanup kfirfer 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
stdlib@go1.25.0
1.25.12

Open the chart page →

757
prometheus-elasticsearch-exporterkfirfer6.5.11 of 1See more

prometheus-elasticsearch-exporter kfirfer 6.5.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.8.0073dd360de2c
stdlib@go1.22.7
1.25.12

Open the chart page →

773
scriptskfirfer0.1.361 of 1See more

scripts kfirfer 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
kfirfer/scripts:0.0.2481e5c4e5d70e
stdlib@go1.17.10
1.25.12

Open the chart page →

2,333
kiaekiae0.1.66 of 9See more

kiae kiae 0.1.6

6 of the 9 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.25.12
grafana/promtail:2.6.1072527b12cdf
stdlib@go1.17.9
1.25.12
istio/pilot:1.15.2db08d6963975
stdlib@go1.19.2
1.25.12
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
stdlib@go1.19.2
1.25.12
ghcr.io/dexidp/dex:v2.35.313964b29d63e
stdlib@go1.19.2
1.25.12
ghcr.io/kiaedev/kiae:latestebd03028ff6a
stdlib@go1.18.9
1.25.12

Open the chart page →

19,411
kimai-helmchartkimai2tet0.1.01 of 2See more

kimai-helmchart kimai2tet 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.12

Open the chart page →

1,527
local-path-provisionerkir4hVerified publisher0.0.351 of 1See more

local-path-provisioner kir4h 0.0.35

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.3534ff0847cc47
stdlib@go1.26.1
1.25.12

Open the chart page →

784
process-exporterkir4hVerified publisher1.0.11 of 1See more

process-exporter kir4h 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ncabatoff/process-exporterdigest-pinned6f0549dc24e9
stdlib@go1.23.1
1.25.12

Open the chart page →

736
typebotiokitsune-itopsVerified publisher0.1.41 of 4See more

typebotio kitsune-itops 0.1.4

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.25.12

Open the chart page →

312
cdashkitwareVerified publisher0.20.01 of 3See more

cdash kitware 0.20.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
stdlib@go1.22.10
1.25.12

Open the chart page →

11,929
kloudlite-platformkloudlite1.1.51 of 3See more

kloudlite-platform kloudlite 1.1.5

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
stdlib@go1.21.3
1.25.12

Open the chart page →

1,982
klumklumVerified publisher1.17.11 of 1See more

klum klum 1.17.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/jadolg/klum:v0.8.17c66cc93f9d03
stdlib@go1.26.3
1.25.12

Open the chart page →

351
klustre-csi-pluginklustre-csi-plugin0.1.11 of 2See more

klustre-csi-plugin klustre-csi-plugin 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
stdlib@go1.21.5
1.25.12

Open the chart page →

1,517
knative-servingknative-servingVerified publisher1.18.37 of 7See more

knative-serving knative-serving 1.18.3

7 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
stdlib@go1.24.6
1.25.12
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
stdlib@go1.24.6
1.25.12
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
stdlib@go1.24.3
1.25.12
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
stdlib@go1.24.3
1.25.12
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
stdlib@go1.24.3
1.25.12
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
stdlib@go1.24.3
1.25.12
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
stdlib@go1.24.3
1.25.12

Open the chart page →

3,824
kollektorkollektorVerified publisher1.0.51 of 1See more

kollektor kollektor 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
pannoi/kollektor:1.0.59559617788fc
stdlib@go1.20.14
1.25.12

Open the chart page →

721
ingress-nginxkomailo-helm-charts1.0.02 of 2See more

ingress-nginx komailo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
stdlib@go1.22.8
1.25.12
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
stdlib@go1.22.8
1.25.12

Open the chart page →

1,576
k8s-metrics-serverkomailo-helm-charts1.2.01 of 1See more

k8s-metrics-server komailo-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
stdlib@go1.26.4
1.25.12

Open the chart page →

178
metallbkomailo-helm-charts1.2.43 of 4See more

metallb komailo-helm-charts 1.2.4

3 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.16.1f51ab515de9c
stdlib@go1.25.9
1.25.12
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
stdlib@go1.25.8
1.25.12
quay.io/metallb/speaker:v0.16.116561e96531e
stdlib@go1.25.9
1.25.12

Open the chart page →

2,268
komiserkomiser-eks3.1.101 of 1See more

komiser komiser-eks 3.1.10

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
tailwarden/komiser:3.1.103f68c8ae7993
stdlib@go1.22.0
1.25.12

Open the chart page →

1,274
komoplanekomodorVerified publisher0.1.81 of 1See more

komoplane komodor 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
komodorio/komoplane:0.2.19678d02c3f2e
stdlib@go1.26.2
1.25.12

Open the chart page →

977
simple-oauth2-proxykostiantyn-matsebora-helm-chartsVerified publisher0.3.71 of 1See more

simple-oauth2-proxy kostiantyn-matsebora-helm-charts 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
stdlib@go1.22.8
1.25.12

Open the chart page →

927
kovi-tile38kovi-charts0.1.11 of 1See more

kovi-tile38 kovi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
tile38/tile38:1.33.4afb7e82f9485
stdlib@go1.23.2
1.25.12

Open the chart page →

1,207
kpingkpingOfficialVerified publisher0.3.51 of 1See more

kping kping 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
kayrosuno/kping:latestf3bd44b29b0d
stdlib@go1.26.1
1.25.12

Open the chart page →

2,364
cadvisorkrakazyabraVerified publisher1.0.11 of 1See more

cadvisor krakazyabra 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
stdlib@go1.13.15
1.25.12

Open the chart page →

3,191
krakenkraken0.2.01 of 7See more

kraken kraken 0.2.0

1 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/redis:5.0fc5ecd863862
stdlib@go1.16.7
1.25.12

Open the chart page →

1,733
aggregation-layer-examplekrateo0.1.11 of 1See more

aggregation-layer-example krateo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/aggregation-layer-example:0.1.06a0ed8196346
stdlib@go1.19.5
1.25.12

Open the chart page →

1,504
appkrateo1.2.861 of 1See more

app krateo 1.2.86

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/app:1.2.86aaa3fe7d5c74
stdlib@go1.22.9
1.25.12

Open the chart page →

3,397
authnkrateo0.23.01 of 1See more

authn krateo 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/authn:0.23.0791c8f9d885a
stdlib@go1.24.2
1.25.12

Open the chart page →

673
autopilotkrateo1.0.01 of 2See more

autopilot krateo 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
stdlib@go1.24.6
1.25.12

Open the chart page →

1,316
azuredevops-providerkrateo0.23.11 of 2See more

azuredevops-provider krateo 0.23.1

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/azuredevops-provider:0.23.150f8f704df3d
stdlib@go1.23.12
1.25.12

Open the chart page →

401
azuredevops-provider-chartkrateo0.16.11 of 2See more

azuredevops-provider-chart krateo 0.16.1

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/azuredevops-provider:0.16.1d251f3e44714
stdlib@go1.19.5
1.25.12

Open the chart page →

1,032
azuredevops-provider-kogkrateo0.1.01 of 1See more

azuredevops-provider-kog krateo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/azuredevops-rest-dynamic-controller-plugin:0.0.586f36ba6fcc5
stdlib@go1.24.2
1.25.12

Open the chart page →

420
azure-pricing-rest-dynamic-controller-pluginkrateo0.1.11 of 1See more

azure-pricing-rest-dynamic-controller-plugin krateo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/azure-pricing-rest-dynamic-controller-plugin:0.1.068bd2c3fbf57
stdlib@go1.23.6
1.25.12

Open the chart page →

448
backendkrateo0.15.31 of 1See more

backend krateo 0.15.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/backend:0.15.383743fcca3a7
stdlib@go1.23.3
1.25.12

Open the chart page →

902
bffkrateo0.8.81 of 1See more

bff krateo 0.8.8

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/bff:0.8.7799eeacbf9a0
stdlib@go1.23.3
1.25.12

Open the chart page →

486
capi-watcherkrateo0.1.01 of 1See more

capi-watcher krateo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/capi-watcher:0.1.0fa01a157d972
stdlib@go1.19.2
1.25.12

Open the chart page →

1,063
composition-watcherkrateo0.1.51 of 1See more

composition-watcher krateo 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/composition-watcher:0.1.4ef3b17c07cfc
stdlib@go1.23.2
1.25.12

Open the chart page →

499
core-providerkrateo1.0.02 of 2See more

core-provider krateo 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/chart-inspector:1.0.0264ba5302f8e
stdlib@go1.25.6
1.25.12
ghcr.io/krateoplatformops/core-provider:1.0.0363cdedfa59f
stdlib@go1.25.6
1.25.12

Open the chart page →

1,802
deviserkrateo0.7.11 of 1See more

deviser krateo 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/deviser:0.7.18310717431b2
stdlib@go1.26.3
1.25.12

Open the chart page →

232
etcdkrateo11.1.31 of 1See more

etcd krateo 11.1.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/etcd:3.5.19-debian-12-r00d68858b2699
stdlib@go1.23.7
1.25.12

Open the chart page →

2,551
eventrouterkrateo0.6.51 of 1See more

eventrouter krateo 0.6.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/eventstack/eventrouter:0.6.030121418adfa
stdlib@go1.25.5
1.25.12

Open the chart page →

309
eventrouter-kafka-producerkrateo0.1.11 of 1See more

eventrouter-kafka-producer krateo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/eventrouter-kafka-producer:0.1.155b18c0dda37
stdlib@go1.19.2
1.25.12

Open the chart page →

1,617
events-ingesterkrateo0.5.31 of 1See more

events-ingester krateo 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/events-ingester:0.5.3e917b25f6b49
stdlib@go1.26.3
1.25.12

Open the chart page →

232
events-presenterkrateo0.9.31 of 1See more

events-presenter krateo 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/events-presenter:0.9.381b8ad5e4178
stdlib@go1.26.3
1.25.12

Open the chart page →

255
eventssekrateo0.5.91 of 1See more

eventsse krateo 0.5.9

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/eventstack/eventsse:0.5.8b65eb9c88669
stdlib@go1.25.4
1.25.12

Open the chart page →

416

Container images carrying it

5,073 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
stdlib@go1.24.6
1.25.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.25.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.12
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.12
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.12
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
stdlib@go1.26.4
1.25.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.12
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.12
1

syft 1.42.1 · advisories as of 27 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.