StackRadar

CVE-2026-39822

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,510
of 17,926 indexed, latest versions
Container images
5,123
deployed by those charts
Fix available
1 of 1
affected package

Root escape via symlink plus trailing slash in os

Carried by container images the latest versions of 4,510 of 17,926 indexed charts deploy, on 5,123 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+191 more1.25.125,123
OSV records
GO-2026-4970
Also known as
BIT-golang-2026-39822

Charts affected

4,510 by stars
ChartLatestAffected imagesRadar Score
waardepapieren-registerwaardepapieren-register1.1.01 of 4See more

waardepapieren-register waardepapieren-register 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
stdlib@go1.13.10
1.25.12

Open the chart page →

7,485
wachdwachdVerified publisher0.4.371 of 1See more

wachd wachd 0.4.37

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/wachd/wachd:0.4.1805b05c56da94
stdlib@go1.25.10
1.25.12

Open the chart page →

1,239
waldurwaldur-chartsVerified publisher8.1.21 of 3See more

waldur waldur-charts 8.1.2

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
stdlib@go1.24.6
1.25.12

Open the chart page →

4,946
azure-metrics-exporterwebdevopsVerified publisher1.2.111 of 1See more

azure-metrics-exporter webdevops 1.2.11

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
webdevops/azure-metrics-exporter:25.12.01d3b453fba99
stdlib@go1.25.5
1.25.12

Open the chart page →

503
webhookswebhooks0.1.51 of 1See more

webhooks webhooks 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
stdlib@go1.20.1
1.25.12

Open the chart page →

2,036
webhook-testerwebhook-testerVerified publisher2.3.01 of 1See more

webhook-tester webhook-tester 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/webhook-tester:2.3.085818267b450
stdlib@go1.26.2
1.25.12

Open the chart page →

221
well-knownwell-knownOfficialVerified publisher1.11.01 of 1See more

well-known well-known 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/stenic/well-known:1.11.0ae85f257a10f
stdlib@go1.24.13
1.25.12

Open the chart page →

262
frpcwener1.0.11 of 1See more

frpc wener 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wener/frpc:v0.37.0cc9fd4da44c0
stdlib@go1.17.3
1.25.12

Open the chart page →

3,358
frpswener1.0.11 of 1See more

frps wener 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wener/frps:v0.37.05c92cc9e8597
stdlib@go1.17.3
1.25.12

Open the chart page →

3,358
harborwener1.19.25 of 8See more

harbor wener 1.19.2

5 of the 8 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.2d7b780d23721
stdlib@go1.26.4
1.25.12
goharbor/harbor-jobservice:v2.15.2f71a4452a095
stdlib@go1.26.4
1.25.12
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
stdlib@go1.26.4
1.25.12
goharbor/registry-photon:v2.15.2c4ebef61ceb5
stdlib@go1.26.4
1.25.12
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
stdlib@go1.26.4
1.25.12

Open the chart page →

1,802
prometheus-snmp-exporterwener9.18.11 of 1See more

prometheus-snmp-exporter wener 9.18.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
stdlib@go1.25.5
1.25.12

Open the chart page →

503
seaweedfswener2.92.01 of 1See more

seaweedfs wener 2.92.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:2.92db095fe8a8d6
stdlib@go1.17.7
1.25.12

Open the chart page →

2,755
cockroachdbwenerme22.0.41 of 3See more

cockroachdb wenerme 22.0.4

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.10b0fcc6c8147a
stdlib@go1.26.2
1.25.12

Open the chart page →

304
frpswenerme1.0.11 of 1See more

frps wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wener/frps:v0.37.05c92cc9e8597
stdlib@go1.17.3
1.25.12

Open the chart page →

3,358
ingress-nginxwenerme4.15.12 of 2See more

ingress-nginx wenerme 4.15.1

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
stdlib@go1.26.1
1.25.12
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
stdlib@go1.26.1
1.25.12

Open the chart page →

1,584
kube-prometheus-stackwenerme91.8.01 of 6See more

kube-prometheus-stack wenerme 91.8.0

1 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
grafana/grafana:13.2.2-distroless69a5d2d957ca
stdlib@go1.26.4
1.25.12

Open the chart page →

707
natswenerme2.15.02 of 3See more

nats wenerme 2.15.0

2 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
natsio/nats-box:0.19.7ffce8bd10338
stdlib@go1.26.3
1.25.12
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.25.12

Open the chart page →

2,205
prometheus-blackbox-exporterwenerme11.19.11 of 1See more

prometheus-blackbox-exporter wenerme 11.19.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.28.0e753ff9f3fc4
stdlib@go1.25.5
1.25.12

Open the chart page →

599
wharf-ainowharf-helmVerified publisher0.1.55 of 7See more

wharf-aino wharf-helm 0.1.5

5 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
stdlib@go1.18.1
1.25.12
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
stdlib@go1.18.2
1.25.12
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
stdlib@go1.18.2
1.25.12
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
stdlib@go1.18.2
1.25.12
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
stdlib@go1.18.2
1.25.12

Open the chart page →

13,488
wharf-cmdwharf-helmVerified publisher0.3.31 of 1See more

wharf-cmd wharf-helm 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
stdlib@go1.18.2
1.25.12

Open the chart page →

3,438
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
stdlib@go1.24.1
1.25.12

Open the chart page →

59,645
external-monitoringwiremindVerified publisher0.3.01 of 1See more

external-monitoring wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
stdlib@go1.20.4
1.25.12

Open the chart page →

1,299
kubemodwiremindVerified publisher0.1.51 of 2See more

kubemod wiremind 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.13.0cadca39288ad
stdlib@go1.14.7
1.25.12

Open the chart page →

3,025
db-backup-retentionwjentner-chartsVerified publisher1.1.01 of 1See more

db-backup-retention wjentner-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/wjentner/k8s-db-backup-retention:v1.1.08027bb46d1f4
stdlib@go1.23.5
1.25.12

Open the chart page →

1,077
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

8,306
wordpress-helmwordpress-helm0.2.92 of 4See more

wordpress-helm wordpress-helm 0.2.9

2 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
stdlib@go1.26.3
1.25.12
library/mysql:80744ee5ef89c
stdlib@go1.24.6
1.25.12

Open the chart page →

8,778
workflows-informerworkflows-informerVerified publisher0.4.41 of 1See more

workflows-informer workflows-informer 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
stdlib@go1.20.14
1.25.12

Open the chart page →

1,214
wraftwraft0.1.123 of 9See more

wraft wraft 0.1.12

3 of the 9 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:14-alpine1a916758fce6
stdlib@go1.24.6
1.25.12
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
stdlib@go1.19.11
1.25.12
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
stdlib@go1.23.10
1.25.12

Open the chart page →

9,561
pi-hole-exporterwyrihaximusnetVerified publisher0.1.31 of 1See more

pi-hole-exporter wyrihaximusnet 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ekofr/pihole-exporter:0.0.109fdad6f352e0
stdlib@go1.14.7
1.25.12

Open the chart page →

1,813
redis-db-assignment-operatorwyrihaximusnetVerified publisher1.0.61 of 1See more

redis-db-assignment-operator wyrihaximusnet 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/kubernetes-redis-db-assignment-operator:v1.0.831060be60bec
stdlib@go1.16.15
1.25.12

Open the chart page →

2,232
x402-k8s-operatorx402-k8s-operator0.1.01 of 2See more

x402-k8s-operator x402-k8s-operator 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/razvanmacovei/x402-k8s-operator:0.1.0bf3407fad182
stdlib@go1.25.7
1.25.12

Open the chart page →

275
prometheusalertxxl-job-adminVerified publisher1.4.01 of 1See more

prometheusalert xxl-job-admin 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.28192368b0578
stdlib@go1.20.6
1.25.12

Open the chart page →

1,111
heistyouniqx-ossVerified publisher1.1.2091 of 1See more

heist youniqx-oss 1.1.209

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/youniqx/heist:v1.1.209c43b3a9d98ae
stdlib@go1.22.7
1.25.12

Open the chart page →

801
yugawareyugabyteVerified publisher2026.1.21 of 5See more

yugaware yugabyte 2026.1.2

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:14.232f439458ab6a
stdlib@go1.24.6
1.25.12

Open the chart page →

1,815
tailscale-relayzeet0.1.51 of 1See more

tailscale-relay zeet 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
zeetdev/tailscale-relay:v1.24.21967aa2840b6
stdlib@go1.18.1-ts710a0d8610
1.25.12

Open the chart page →

2,161
crowdsec-web-uizekker6Verified publisher0.52.01 of 1See more

crowdsec-web-ui zekker6 0.52.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.9.162614fd45986
stdlib@go1.24.4
1.25.12

Open the chart page →

1,132
cloudflare-zero-trust-operatorzelic-io0.7.11 of 1See more

cloudflare-zero-trust-operator zelic-io 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/bojanzelic/cloudflare-zero-trust-operator:0.7.1f4b2dbc19a78
stdlib@go1.23.4
1.25.12

Open the chart page →

598
velero-notificationszokeber-velero-notificationsVerified publisher0.1.101 of 2See more

velero-notifications zokeber-velero-notifications 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/zokeber/velero-notifications:0.0.176d84f6c4ce20
stdlib@go1.25.8
1.25.12

Open the chart page →

759
backendzymtraceOfficialVerified publisher26.9.31 of 6See more

backend zymtrace 26.9.3

1 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:17.4304ab8135187
stdlib@go1.18.2
1.25.12

Open the chart page →

9,761
aaqaaqVerified publisher0.3.01 of 1See more

aaq aaq 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/kubevirt/aaq-operator:v1.7.0d28a2daa5b15
stdlib@go1.24.12
1.25.12

Open the chart page →

1,052
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/abstract-foundation/zksync-external-node-sidecar:v1.0.03e705d0eb1ce
stdlib@go1.18.10
1.25.12

Open the chart page →

4,734
accurateaccurateVerified publisher0.8.01 of 1See more

accurate accurate 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/cybozu-go/accurate:2.0.0be4a2680bef4
stdlib@go1.26.3
1.25.12

Open the chart page →

88
rabbitmq-cluster-operatoradeptia-automate-operator5.2.02 of 2See more

rabbitmq-cluster-operator adeptia-automate-operator 5.2.0

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-rabbitmq-cluster-operator:5.2cf610f8c614c
stdlib@go1.25.7
1.25.12
adeptiainc/adeptia-connect-rabbitmq-messaging-topology-operator:5.27cdf6ac2e738
stdlib@go1.25.7
1.25.12

Open the chart page →

555
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
stdlib@go1.25.3
1.25.12

Open the chart page →

2,643
activepiecesadnoctemVerified publisher0.6.01 of 1See more

activepieces adnoctem 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
activepieces/activepieces:0.91.058414dfc94c4
stdlib@go1.23.5
1.25.12

Open the chart page →

1,136
gobackupadnoctemVerified publisher0.4.01 of 1See more

gobackup adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
huacnlee/gobackup:v3.1.1560be93229a5
stdlib@go1.26.3
1.25.12

Open the chart page →

1,854
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
stdlib@go1.23.7
1.25.12

Open the chart page →

4,144
popeyeadnoctemVerified publisher0.3.01 of 1See more

popeye adnoctem 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
stdlib@go1.23.5
1.25.12

Open the chart page →

1,371
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
stdlib@go1.20.5
1.25.12

Open the chart page →

31,884
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
stdlib@go1.13.10
1.25.12

Open the chart page →

7,503

Container images carrying it

5,123 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
stdlib@go1.24.6
1.25.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.25.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.12
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.12
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.12
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
stdlib@go1.26.4
1.25.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.12
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.12
1

syft 1.42.1 · advisories as of 28 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.