StackRadar

CVE-2026-39822

Unscored

Advisory

Published 7 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,503
of 17,939 indexed, latest versions
Container images
5,117
deployed by those charts
Fix available
1 of 1
affected package

Root escape via symlink plus trailing slash in os

Carried by container images the latest versions of 4,503 of 17,939 indexed charts deploy, on 5,117 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+191 more1.25.125,117
OSV records
GO-2026-4970
Also known as
BIT-golang-2026-39822

Charts affected

4,503 by stars
ChartLatestAffected imagesRadar Score
devportalveecode-platform-nextVerified publisher0.1.251 of 1See more

devportal veecode-platform-next 0.1.25

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinned7a3d61de5e5e
stdlib@go1.26.4
1.25.12

Open the chart page →

2,015
velero-clientvelero-clientVerified publisher1.4.21 of 1See more

velero-client velero-client 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
stdlib@go1.26.4
1.25.12

Open the chart page →

607
velocityvelocity1.0.01 of 2See more

velocity velocity 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.12

Open the chart page →

1,010
doris-foundationdbvelodb25.8.01 of 4See more

doris-foundationdb velodb 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
stdlib@go1.23.7
1.25.12

Open the chart page →

3,271
doris-operatorvelodb25.8.01 of 1See more

doris-operator velodb 25.8.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
apache/doris:operator-latest3a4422656592
stdlib@go1.23.12
1.25.12

Open the chart page →

443
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
stdlib@go1.13.10
1.25.12

Open the chart page →

7,565
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
stdlib@go1.13.10
1.25.12

Open the chart page →

7,583
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
stdlib@go1.13.10
1.25.12

Open the chart page →

7,485
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
stdlib@go1.13.10
1.25.12

Open the chart page →

7,485
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
stdlib@go1.22.5
1.25.12

Open the chart page →

2,847
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
stdlib@go1.20.14
1.25.12

Open the chart page →

4,551
bugsinkvictorlane0.3.71 of 2See more

bugsink victorlane 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mariadb:12.0-noble607835cd628b
stdlib@go1.24.6
1.25.12

Open the chart page →

4,286
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
stdlib@go1.24.6
1.25.12

Open the chart page →

6,844
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
stdlib@go1.21.7
1.25.12

Open the chart page →

74,473
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

20,574
kube-monitoring-telegram-botviento-repository1.0.01 of 1See more

kube-monitoring-telegram-bot viento-repository 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
stdlib@go1.16.4
1.25.12

Open the chart page →

8,058
vineyard-operatorvineyardVerified publisher0.24.22 of 2See more

vineyard-operator vineyard 0.24.2

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
stdlib@go1.19.13
1.25.12
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
stdlib@go1.18.3
1.25.12

Open the chart page →

4,638
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
stdlib@go1.17.8
1.25.12

Open the chart page →

8,314
mychartviveksahu261.0.01 of 2See more

mychart viveksahu26 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.12

Open the chart page →

3,370
ciliumvks-helm-chartsVerified publisher1.17.143 of 3See more

cilium vks-helm-charts 1.17.14

3 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
stdlib@go1.25.8
1.25.12
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
stdlib@go1.25.8
1.25.12
quay.io/cilium/operator-generic:v1.17.14773886ec9337
stdlib@go1.25.8
1.25.12

Open the chart page →

4,434
corednsvks-helm-chartsVerified publisher1.45.01 of 1See more

coredns vks-helm-charts 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
stdlib@go1.25.2
1.25.12

Open the chart page →

927
vm-console-proxyvm-console-proxyVerified publisher0.2.01 of 1See more

vm-console-proxy vm-console-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/kubevirt/vm-console-proxy:v0.8.08d6b4b6e99bd
stdlib@go1.22.4
1.25.12

Open the chart page →

654
vmware-rest-proxyvmware-rest-proxy0.1.111 of 1See more

vmware-rest-proxy vmware-rest-proxy 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/dodevops/vmware-rest-proxy:0.1.730f7f73b0a10
stdlib@go1.21.7
1.25.12

Open the chart page →

1,282
go-devvoid-xmh1.0.11 of 1See more

go-dev void-xmh 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
voidxmh/golang:1.19-alpine-dev423c6195fab2
stdlib@go1.19
1.25.12

Open the chart page →

1,156
muthurvojtechpastyrikVerified publisher0.10.01 of 1See more

muthur vojtechpastyrik 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/muthur:0.10.0b5a06a6e13b9
stdlib@go1.26.1
1.25.12

Open the chart page →

329
muthur-collectorvojtechpastyrikVerified publisher0.11.01 of 1See more

muthur-collector vojtechpastyrik 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/muthur-collector:0.11.00a580fe3a032
stdlib@go1.26.1
1.25.12

Open the chart page →

329
volantmqvolantmq0.1.21 of 1See more

volantmq volantmq 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
stdlib@go1.13.6
1.25.12

Open the chart page →

2,543
volcanovolcano-sh1.15.23 of 3See more

volcano volcano-sh 1.15.2

3 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
volcanosh/vc-controller-manager:v1.15.26a6bc2560d51
stdlib@go1.25.0
1.25.12
volcanosh/vc-scheduler:v1.15.2afab36286a17
stdlib@go1.25.0
1.25.12
volcanosh/vc-webhook-manager:v1.15.22fff65aad011
stdlib@go1.25.0
1.25.12

Open the chart page →

1,585
postgresappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

postgresapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.12

Open the chart page →

1,320
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.12

Open the chart page →

7,647
postgresappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

postgresapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.12

Open the chart page →

1,320
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.12

Open the chart page →

7,647
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:18.3-alpine3.2354451ecb8ab3
stdlib@go1.24.6
1.25.12

Open the chart page →

7,337
vpa-managervpa-managerVerified publisher0.4.91 of 1See more

vpa-manager vpa-manager 0.4.9

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
quay.io/jcluppnow/vpa-manager:0.6.4e459d2fba277
stdlib@go1.22.7
1.25.12

Open the chart page →

495
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
mitre/vulcan:latest2bc4dfb8150f
stdlib@go1.25.5
1.25.12

Open the chart page →

1,573
cert-manager-webhook-vultrvultrVerified publisher1.0.01 of 1See more

cert-manager-webhook-vultr vultr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
stdlib@go1.16.3
1.25.12

Open the chart page →

2,508
vultr-csivultrVerified publisher2.0.01 of 4See more

vultr-csi vultr 2.0.0

1 of the 4 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
vultr/vultr-csi:v0.3.041d26735d437
stdlib@go1.16.8
1.25.12

Open the chart page →

2,362
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
stdlib@go1.20.2
1.25.12

Open the chart page →

3,517
gateway-control-planewallarmVerified publisher0.2.02 of 2See more

gateway-control-plane wallarm 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg17c79fa5891443
stdlib@go1.26.2
1.25.12
wallarm/gateway-control-plane:0.2.0a321bc974a19
stdlib@go1.24.13
1.25.12

Open the chart page →

1,229
kongwallarmVerified publisher4.6.33 of 7See more

kong wallarm 4.6.3

3 of the 7 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wallarm/ingress-python:4.6.0-15cb2ae08b40f
stdlib@go1.18.2
1.25.12
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
stdlib@go1.18.3
1.25.12
wallarm/kong-kubernetes-ingress-controller:2.8b55ff6cecbd5
stdlib@go1.19.4
1.25.12

Open the chart page →

78,242
kong-previewwallarmVerified publisher4.2.32 of 5See more

kong-preview wallarm 4.2.3

2 of the 5 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
stdlib@go1.17.5
1.25.12
wallarm/ingress-ruby:4.2.1-195ea2632326c
stdlib@go1.18.3
1.25.12

Open the chart page →

2,914
wallarm-ingress-rcwallarmVerified publisher4.8.42 of 2See more

wallarm-ingress-rc wallarm 4.8.4

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
stdlib@go1.20.5
1.25.12
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.25.12

Open the chart page →

2,642
wallarm-node-nextwallarmVerified publisher0.5.32 of 2See more

wallarm-node-next wallarm 0.5.3

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
stdlib@go1.22.7
1.25.12
wallarm/node-next:0.5.24314f3d2b918
stdlib@go1.22.7
1.25.12

Open the chart page →

2,438
wallarm-oobwallarmVerified publisher0.23.03 of 3See more

wallarm-oob wallarm 0.23.0

3 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
stdlib@go1.22.1
1.25.12
wallarm/node-helpers:6.10.1aecd88b24c51
stdlib@go1.25.7
1.25.12
wallarm/node-native-processing:0.23.07db2da8fce0b
stdlib@go1.26.0
1.25.12

Open the chart page →

2,899
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.12

Open the chart page →

20,574
wardnwardnVerified publisher0.1.01 of 3See more

wardn wardn 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.25.12

Open the chart page →

401
consulwarjiang1.3.02 of 2See more

consul warjiang 1.3.0

2 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
stdlib@go1.20.10
1.25.12
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
stdlib@go1.20.10
1.25.12

Open the chart page →

4,102
eth-validatorwateim1.4.51 of 3See more

eth-validator wateim 1.4.5

1 of the 3 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wateim/lighthouse-launch:latest2520149ee574
stdlib@go1.23.8
1.25.12

Open the chart page →

5,123
prometheus-storage-adapterwavefront0.1.61 of 2See more

prometheus-storage-adapter wavefront 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wavefronthq/prometheus-storage-adapter:latestded77b38c7c6
stdlib@go1.18
1.25.12

Open the chart page →

1,295
wavefront-hpa-adapterwavefront0.2.101 of 1See more

wavefront-hpa-adapter wavefront 0.2.10

1 of the 1 container images this version deploys carry CVE-2026-39822.

Container imageDigestPackageFixed in
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
stdlib@go1.18
1.25.12

Open the chart page →

1,692

Container images carrying it

5,117 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.12
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.12
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.12
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
stdlib@go1.26.4
1.25.12
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.12
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.12
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.