StackRadar

CVE-2026-39822

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,463
of 17,911 indexed, latest versions
Container images
5,073
deployed by those charts
Fix available
1 of 1
affected package

Root escape via symlink plus trailing slash in os

Carried by container images the latest versions of 4,463 of 17,911 indexed charts deploy, on 5,073 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.125,073
OSV records
GO-2026-4970
Also known as
BIT-golang-2026-39822

Charts affected

4,463 by stars
ChartLatestAffected imagesRadar Score
pulsarv2milvus-helm2.7.82 of 4See more

pulsarv2 milvus-helm 2.7.8

2 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
stdlib@go1.13.10
1.25.12
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
stdlib@go1.13.4
1.25.12

Open the chart page →

15,921
mimirmimir0.1.101 of 1See more

mimir mimir 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
stdlib@go1.24.13
1.25.12

Open the chart page →

384
zkapps-dashboardminaVerified publisher0.1.21 of 2See more

zkapps-dashboard mina 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.25.12

Open the chart page →

1,703
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
stdlib@go1.24.6
1.25.12

Open the chart page →

13,432
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
stdlib@go1.17.4
1.25.12

Open the chart page →

6,135
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:13-alpinefb9065b6e3e2
stdlib@go1.24.6
1.25.12

Open the chart page →

117,938
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
stdlib@go1.19.7
1.25.12

Open the chart page →

10,853
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
stdlib@go1.19.7
1.25.12

Open the chart page →

10,853
helmmirasys-chart0.1.01 of 4See more

helm mirasys-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.12

Open the chart page →

3,830
mitosmitosVerified publisher1.6.05 of 7See more

mitos mitos 1.6.0

5 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/mitos-run/mitos-console:v1.6.0209e966322ab
stdlib@go1.26.4
1.25.12
ghcr.io/mitos-run/mitos-controller:v1.6.0b547c38dcc9d
stdlib@go1.26.4
1.25.12
ghcr.io/mitos-run/mitos-forkd:v1.6.0979b462ab7d6
stdlib@go1.26.4
1.25.12
ghcr.io/mitos-run/mitos-gateway:v1.6.0017274a28204
stdlib@go1.26.4
1.25.12
ghcr.io/mitos-run/mitos-kvm-device-plugin:v1.6.063e2b78d03c4
stdlib@go1.26.4
1.25.12

Open the chart page →

3,220
jupyterhubmizzoukube0.0.1-set.by.chartpress1 of 7See more

jupyterhub mizzoukube 0.0.1-set.by.chartpress

1 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
stdlib@go1.21.7
1.25.12

Open the chart page →

1,899
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
stdlib@go1.15.13
1.25.12

Open the chart page →

2,855
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
stdlib@go1.13.14
1.25.12

Open the chart page →

7,927
echoperatormmontesVerified publisher0.0.21 of 1See more

echoperator mmontes 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
stdlib@go1.18.3
1.25.12

Open the chart page →

1,831
mariadbmmontesVerified publisher0.3.01 of 1See more

mariadb mmontes 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mariadb:10.7.307e06f2e7ae9
stdlib@go1.16.7
1.25.12

Open the chart page →

10,344
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.25.12

Open the chart page →

7,283
basic-git-servermoikot0.0.21 of 1See more

basic-git-server moikot 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
moikot/basic-git-server:0.0.20d941bd30ffa
stdlib@go1.14.9
1.25.12

Open the chart page →

2,956
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
stdlib@go1.14.4
1.25.12

Open the chart page →

2,561
smartthings-metricsmoikot0.1.01 of 1See more

smartthings-metrics moikot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:0.1.08625f53aa9b7
stdlib@go1.14.13
1.25.12

Open the chart page →

1,748
smartthings-metrics-feat-log-detailsmoikot0.0.921 of 1See more

smartthings-metrics-feat-log-details moikot 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:feat-log-detailsfb8565140106
stdlib@go1.14.15
1.25.12

Open the chart page →

1,736
docker-registrymoinologics0.1.11 of 1See more

docker-registry moinologics 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/registry:2a3d8aaa63ed8
stdlib@go1.20.8
1.25.12

Open the chart page →

551
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
stdlib@go1.18.7
1.25.12

Open the chart page →

2,485
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.12

Open the chart page →

12,128
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.12

Open the chart page →

12,128
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.12

Open the chart page →

12,549
backendmojaloop0.1.05 of 6See more

backend mojaloop 0.1.0

5 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
stdlib@go1.18.2
1.25.12
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
stdlib@go1.17
1.25.12
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
stdlib@go1.23.8
1.25.12
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
stdlib@go1.16.4
1.25.12
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
stdlib@go1.21.5
1.25.12

Open the chart page →

16,601
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.12

Open the chart page →

19,785
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.25.12

Open the chart page →

6,354
mollysocketmollysocket-wrenixVerified publisher0.1.141 of 2See more

mollysocket mollysocket-wrenix 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.3c4a11ae9a1cb
stdlib@go1.25.7
1.25.12

Open the chart page →

2,663
eks-pod-identity-webhookmondu-aiVerified publisher0.3.11 of 1See more

eks-pod-identity-webhook mondu-ai 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
stdlib@go1.26.2
1.25.12

Open the chart page →

470
gar-credential-providermondu-aiVerified publisher0.2.11 of 1See more

gar-credential-provider mondu-ai 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
stdlib@go1.26.0
1.25.12

Open the chart page →

737
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
stdlib@go1.25.9
1.25.12

Open the chart page →

5,379
enterprise-operatormongodb-helm-charts1.33.01 of 1See more

enterprise-operator mongodb-helm-charts 1.33.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
stdlib@go1.24.2
1.25.12

Open the chart page →

1,633
mongodb-query-exportermongodb-query-exporterVerified publisher5.1.01 of 1See more

mongodb-query-exporter mongodb-query-exporter 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/raffis/mongodb-query-exporter:v5.1.0ca6ac8a5b329
stdlib@go1.20.5
1.25.12

Open the chart page →

981
mongodb-secure-backupmongodb-secure-backup1.0.01 of 2See more

mongodb-secure-backup mongodb-secure-backup 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
stdlib@go1.22.10
1.25.12

Open the chart page →

1,035
mongopingmongoping1.3.11 of 1See more

mongoping mongoping 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
udhos/mongoping:1.3.103b08b63f524
stdlib@go1.24.2
1.25.12

Open the chart page →

1,309
moodlemoodle1.0.31 of 2See more

moodle moodle 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
cloudtooling/moodle:5.2.3f4f04e0fc401
stdlib@go1.26.4
1.25.12

Open the chart page →

4,306
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
stdlib@go1.17.10
1.25.12

Open the chart page →

12,182
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
stdlib@go1.17.10
1.25.12

Open the chart page →

9,296
mqtt-loggermoreillonVerified publisher0.3.12 of 5See more

mqtt-logger moreillon 0.3.1

2 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
stdlib@go1.19.6
1.25.12
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
stdlib@go1.17.10
1.25.12

Open the chart page →

11,316
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
stdlib@go1.19.12
1.25.12

Open the chart page →

26,876
backupmorremeyer4.0.01 of 1See more

backup morremeyer 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
restic/restic:0.15.2579e4e6a4931
stdlib@go1.19.8
1.25.12

Open the chart page →

2,305
hcloud-ccm-networksmorremeyer2.0.01 of 1See more

hcloud-ccm-networks morremeyer 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
stdlib@go1.20.5
1.25.12

Open the chart page →

1,753
hcloud-csi-drivermorremeyer3.0.06 of 6See more

hcloud-csi-driver morremeyer 3.0.0

6 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
stdlib@go1.19.7
1.25.12
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
stdlib@go1.19
1.25.12
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
stdlib@go1.19
1.25.12
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.25.12
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.25.12
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.12

Open the chart page →

7,238
chirpstackmosquitto-helm-chart0.5.03 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

3 of the 8 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3fb7667fe037f
stdlib@go1.19.3
1.25.12
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
stdlib@go1.19.3
1.25.12
oliver006/redis_exporter:v1.14.0d55e056987af
stdlib@go1.15.6
1.25.12

Open the chart page →

104,841
chirpstack-event-forwardmosquitto-helm-chart0.1.21 of 1See more

chirpstack-event-forward mosquitto-helm-chart 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
stdlib@go1.17.10
1.25.12

Open the chart page →

1,849
replacermosquitto-helm-chart0.2.02 of 3See more

replacer mosquitto-helm-chart 0.2.0

2 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
stdlib@go1.17.7
1.25.12
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
stdlib@go1.17.7
1.25.12

Open the chart page →

3,930
configmapsecretsmozilla0.0.11 of 1See more

configmapsecrets mozilla 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
stdlib@go1.16.1
1.25.12

Open the chart page →

2,104
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
stdlib@go1.20.12
1.25.12

Open the chart page →

4,649
ms-hello-webms-hello-test0.1.01 of 1See more

ms-hello-web ms-hello-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
irakli/ms-web-hello:latest966a4bfefe27
stdlib@go1.19.2
1.25.12

Open the chart page →

756

Container images carrying it

5,073 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
stdlib@go1.24.6
1.25.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.25.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.12
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.12
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.12
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
stdlib@go1.26.4
1.25.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.12
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.12
1

syft 1.42.1 · advisories as of 27 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.