StackRadar

CVE-2026-39822

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,446
of 17,879 indexed, latest versions
Container images
5,060
deployed by those charts
Fix available
1 of 1
affected package

Root escape via symlink plus trailing slash in os

Carried by container images the latest versions of 4,446 of 17,879 indexed charts deploy, on 5,060 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+189 more1.25.125,060
OSV records
GO-2026-4970
Also known as
BIT-golang-2026-39822

Charts affected

4,446 by stars
ChartLatestAffected imagesRadar Score
centralbrainsciencemeshVerified publisher0.0.34 of 5See more

centralbrain sciencemesh 0.0.3

4 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:7.3.315b977f5207d
stdlib@go1.15.1
1.25.12
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.25.12
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.25.12
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
stdlib@go1.15.3
1.25.12

Open the chart page →

9,766
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
stdlib@go1.19.4
1.25.12

Open the chart page →

4,868
hermitcrabseal-ioVerified publisher0.1.42 of 2See more

hermitcrab seal-io 0.1.4

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
sealio/hermitcrab:v0.1.4a326a2f03660
stdlib@go1.21.6
1.25.12
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
stdlib@go1.20.7
1.25.12

Open the chart page →

4,891
searchpesearchpe4.1.01 of 2See more

searchpe searchpe 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.25.12

Open the chart page →

2,652
seashellsseashells1.0.01 of 1See more

seashells seashells 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
rokk42/seashells:1.0-k8sdfc850a5db9e
stdlib@go1.22.3
1.25.12

Open the chart page →

822
seaweedfs-operatorseaweedfs-operatorVerified publisher1.5.82 of 3See more

seaweedfs-operator seaweedfs-operator 1.5.8

2 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/nnstd/seaweedfs-operator:1.43ebe2fd253f6
stdlib@go1.24.5
1.25.12
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
stdlib@go1.21.3
1.25.12

Open the chart page →

2,123
wallabagsebtiz13-chartsVerified publisher0.6.01 of 1See more

wallabag sebtiz13-charts 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.25.12

Open the chart page →

1,148
secret-managersecret-managerVerified publisher1.0.03 of 4See more

secret-manager secret-manager 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault:v1.0.0e4acd2fbb7b1
stdlib@go1.23.1
1.25.12
leonardomulticloud/webhook:v1.0.0d119918900e8
stdlib@go1.22.6
1.25.12
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.25.12

Open the chart page →

5,617
secrets-bridgesecrets-bridge0.2.01 of 1See more

secrets-bridge secrets-bridge 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/haydercyber/secrets-bridge:0.2.04709f1bb3039
stdlib@go1.24.13
1.25.12

Open the chart page →

394
aws-secretssecretsprovider0.1.01 of 1See more

aws-secrets secretsprovider 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Open the chart page →

2,219
secretssecrets-proxy1.0.61 of 1See more

secrets secrets-proxy 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
udhos/secrets:1.0.6daa2b4eaac09
stdlib@go1.24.2
1.25.12

Open the chart page →

1,194
secret-syncsecret-syncVerified publisher0.1.111 of 1See more

secret-sync secret-sync 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
csepulvedab/secret-sync:0.5227a6f2b0ff8
stdlib@go1.19.4
1.25.12

Open the chart page →

1,446
cloudflaredsectionmeVerified publisher2022.3.41 of 1See more

cloudflared sectionme 2022.3.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
stdlib@go1.17.1
1.25.12

Open the chart page →

2,442
influxdb_exportersectionmeVerified publisher0.0.21 of 1See more

influxdb_exporter sectionme 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/prometheus/influxdb-exporter:v0.10.03854d8af7bd4
stdlib@go1.18.3
1.25.12

Open the chart page →

924
operatorsecurecodebox-operator5.8.01 of 2See more

operator securecodebox-operator 5.8.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
securecodebox/operator:5.8.0c14bd5c550e3
stdlib@go1.26.4
1.25.12

Open the chart page →

102
security-smellssecurity-smells0.1.01 of 1See more

security-smells security-smells 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
durellirsd/security-smells-api:v17398aca4fc2e
stdlib@go1.22.4
1.25.12

Open the chart page →

1,442
pagessekharpkube1.0.01 of 3See more

pages sekharpkube 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

20,573
seldon-core-analyticsseldon1.17.14 of 8See more

seldon-core-analytics seldon 1.17.1

4 of the 8 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.25.12
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.25.12
prom/prometheus:v2.18.15880ec936055
stdlib@go1.14.2
1.25.12
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.25.12

Open the chart page →

10,756
postgresself-hosters-by-nightVerified publisher0.14.31 of 1See more

postgres self-hosters-by-night 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
stdlib@go1.24.6
1.25.12

Open the chart page →

2,565
semaphoresemaphore-light1.0.01 of 1See more

semaphore semaphore-light 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
semaphoreui/semaphore:latest98ad9bc7a2a0
stdlib@go1.25.5
1.25.12

Open the chart page →

1,441
sentry-kubernetessentry0.4.01 of 1See more

sentry-kubernetes sentry 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/getsentry/sentry-kubernetes:latestc88fec0dde4a
stdlib@go1.26.4
1.25.12

Open the chart page →

82
s3managersergeyshevch0.1.01 of 1See more

s3manager sergeyshevch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/sergeyshevch/s3manager:feature_refactoringff59fcdf44eb
stdlib@go1.18
1.25.12

Open the chart page →

2,158
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
stdlib@go1.21.8
1.25.12

Open the chart page →

3,380
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
stdlib@go1.24.1
1.25.12

Open the chart page →

3,491
miniosergiotocaliniVerified publisher1.0.01 of 1See more

minio sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
stdlib@go1.19.11
1.25.12

Open the chart page →

4,444
rdpgwsergiotocaliniVerified publisher1.0.01 of 1See more

rdpgw sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bolkedebruin/rdpgw:masterc0dc0589373a
stdlib@go1.24.13
1.25.12

Open the chart page →

697
service-binding-operatorservice-binding-operator-helm-chart1.4.11 of 1See more

service-binding-operator service-binding-operator-helm-chart 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/redhat-developer/servicebinding-operatordigest-pinned16286ac84ddd
stdlib@go1.20.6
1.25.12

Open the chart page →

800
serviceexampleserviceexample0.1.03 of 5See more

serviceexample serviceexample 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/nats:2.9.20-alpined6c6ae7df4a0
stdlib@go1.19.11
1.25.12
natsio/nats-box:0.13.559cf2e949181
stdlib@go1.19.5
1.25.12
natsio/nats-server-config-reloader:0.11.0c3a755eab2cc
stdlib@go1.20.5
1.25.12

Open the chart page →

5,471
service-exampleservice-example-10.1.05 of 7See more

service-example service-example-1 0.1.0

5 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.12
library/nats:2.9.11-alpineccbe811b8575
stdlib@go1.19.4
1.25.12
natsio/nats-box:0.13.3c507bd7e3831
stdlib@go1.19.4
1.25.12
natsio/nats-server-config-reloader:0.8.06bdaceb63aa5
stdlib@go1.19.4
1.25.12
natsio/prometheus-nats-exporter:0.10.1bce728062c4f
stdlib@go1.19.3
1.25.12

Open the chart page →

8,427
serviceexampleserviceexample-chart0.3.01 of 4See more

serviceexample serviceexample-chart 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.12

Open the chart page →

3,449
serviceexampleservice-example-helm-chart0.1.01 of 4See more

serviceexample service-example-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.12

Open the chart page →

1,593
service-exampleservice-example-jt0.1.14 of 9See more

service-example service-example-jt 0.1.1

4 of the 9 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/nats:2.12.2-alpine2d5fce3229ae
stdlib@go1.25.4
1.25.12
natsio/nats-box:0.19.28031d190c7ee
stdlib@go1.25.2
1.25.12
natsio/nats-server-config-reloader:0.20.147094fcae2f4
stdlib@go1.24.8
1.25.12
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.25.12

Open the chart page →

7,585
ccx-monitoringseveralnines0.6.215 of 7See more

ccx-monitoring severalnines 0.6.21

5 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:12.3.12175aaa91c96
stdlib@go1.25.5
1.25.12
victoriametrics/victoria-metrics:v1.120.0a1cb2f3dfd45
stdlib@go1.24.4
1.25.12
victoriametrics/vmalert:v1.96.0150cd08fde94
stdlib@go1.21.5
1.25.12
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.25.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
stdlib@go1.20.10
1.25.12

Open the chart page →

7,870
apache-shardingsphere-operator-chartsshardingsphere0.3.01 of 2See more

apache-shardingsphere-operator-charts shardingsphere 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
stdlib@go1.19.10
1.25.12

Open the chart page →

1,700
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.12

Open the chart page →

3,239
shopwareshopware-storeVerified publisher2.2.11 of 5See more

shopware shopware-store 2.2.1

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
stdlib@go1.26.4
1.25.12

Open the chart page →

1,872
bffshortlink0.2.11 of 1See more

bff shortlink 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
stdlib@go1.25.7
1.25.12

Open the chart page →

1,743
linkshortlink0.7.31 of 1See more

link shortlink 0.7.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
stdlib@go1.25.7
1.25.12

Open the chart page →

1,725
pagesshrutiujlan-pages1.0.01 of 3See more

pages shrutiujlan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

20,573
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:18.43a82e1f56c8f
stdlib@go1.24.6
1.25.12

Open the chart page →

2,866
nut-exportersi-gitops0.5.01 of 1See more

nut-exporter si-gitops 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
stdlib@go1.26.3
1.25.12

Open the chart page →

817
backendsignalen4.25.02 of 4See more

backend signalen 4.25.0

2 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.25.12
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
stdlib@go1.16.7
1.25.12

Open the chart page →

11,385
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
stdlib@go1.14
1.25.12

Open the chart page →

2,176
postgresqlsignoz0.0.21 of 1See more

postgresql signoz 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
stdlib@go1.24.6
1.25.12

Open the chart page →

1,321
zookeepersignoz0.0.11 of 1See more

zookeeper signoz 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.25.12

Open the chart page →

2,978
local-static-provisionersig-storage-local-static-provisioner2.9.01 of 1See more

local-static-provisioner sig-storage-local-static-provisioner 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.12

Open the chart page →

1,348
ctlogsigstoreVerified publisher0.2.683 of 4See more

ctlog sigstore 0.2.68

3 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
stdlib@go1.25.0
1.25.12
ghcr.io/sigstore/scaffolding/createtree:v0.7.31e5232e8c9122
stdlib@go1.25.0
1.25.12
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
stdlib@go1.25.0
1.25.12

Open the chart page →

2,790
ctlog-tilessigstoreVerified publisher0.1.81 of 1See more

ctlog-tiles sigstore 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/transparency-dev/tesseract/posix:v0.1.2b044edd23888
stdlib@go1.25.8
1.25.12

Open the chart page →

288
sigstore-probersigstoreVerified publisher0.3.11 of 1See more

sigstore-prober sigstore 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
stdlib@go1.26.0
1.25.12

Open the chart page →

448
trilliansigstoreVerified publisher0.3.204 of 5See more

trillian sigstore 0.3.20

4 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.25.12
ghcr.io/sigstore/scaffolding/createdbdigest-pinned3cee6c78973b
stdlib@go1.25.0
1.25.12
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
stdlib@go1.26.0
1.25.12
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
stdlib@go1.26.0
1.25.12

Open the chart page →

2,785

Container images carrying it

5,060 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
stdlib@go1.26.4
1.25.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.12
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.12
1

syft 1.42.1 · advisories as of 26 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.