StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,778
of 17,790 indexed, latest versions
Container images
4,358
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,778 of 17,790 indexed charts deploy, on 4,358 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+268 more0.44.04,358
OSV records
GO-2026-5024

Charts affected

3,778 by stars
ChartLatestAffected imagesRadar Score
voyager-gatewayappscodeVerified publisher2026.7.211 of 2See more

voyager-gateway appscode 2026.7.21

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

1,331
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
golang.org/x/sys@v0.10.0
0.44.0

Open the chart page →

5,680
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/sys@v0.16.0
0.44.0

Open the chart page →

1,205
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

8,913
appwriteappwrite-helmVerified publisher1.3.23 of 8See more

appwrite appwrite-helm 1.3.2

3 of the 8 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/sys@v0.37.0
0.44.0
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
golang.org/x/sys@v0.2.0
0.44.0

Open the chart page →

9,855
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
0.44.0

Open the chart page →

5,211
arcadearcadeVerified publisher1.10.11 of 10See more

arcade arcade 1.10.1

1 of the 10 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

991
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/sys@v0.30.0
0.44.0
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
golang.org/x/sys@v0.13.0
0.44.0
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/sys@v0.25.0
0.44.0

Open the chart page →

7,359
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
golang.org/x/sys@v0.33.0
0.44.0
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

1,840
argonix-apiargonix0.2.32 of 4See more

argonix-api argonix 0.2.3

2 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
golang.org/x/sys@v0.20.0
0.44.0
ghcr.io/argonix-io/argonix-api-frontend:1.0.0d041bbf2814f
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

4,956
argo-zombiesargo-zombies0.1.521 of 1See more

argo-zombies argo-zombies 0.1.52

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
golang.org/x/sys@v0.39.0
0.44.0

Open the chart page →

254
arlas-aiasarlas-stackVerified publisher28.8.06 of 22See more

arlas-aias arlas-stack 28.8.0

6 of the 22 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
golang.org/x/sys@v0.32.0
0.44.0
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
golang.org/x/sys@v0.33.0
0.44.0
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/sys@v0.25.0
0.44.0
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
golang.org/x/sys@v0.32.0
0.44.0
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
golang.org/x/sys@v0.21.0
0.44.0
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

40,580
arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/sys@v0.0.0-20220728004956-3c1f35247d10
0.44.0
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/sys@v0.5.0
0.44.0
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/sys@v0.5.0
0.44.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
golang.org/x/sys@v0.4.0
0.44.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/sys@v0.3.0
0.44.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/sys@v0.2.0
0.44.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/sys@v0.3.0
0.44.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/sys@v0.3.0
0.44.0

Open the chart page →

23,425
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0

Open the chart page →

1,779
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/sys@v0.0.0-20220422013727-9388b58f7150
0.44.0
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/sys@v0.0.0-20220222172238-00053529121e
0.44.0
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/sys@v0.0.0-20211117180635-dee7805ff2e1
0.44.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0

Open the chart page →

8,621
assemblylineassemblylineVerified publisher7.4.192 of 12See more

assemblyline assemblyline 7.4.19

2 of the 12 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
golang.org/x/sys@v0.15.0
0.44.0
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/sys@v0.16.0
0.44.0

Open the chart page →

12,666
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0

Open the chart page →

5,537
dltkvassist-iot-data-integrity-verification0.2.04 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.44.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.44.0
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.44.0

Open the chart page →

77,883
dltflassist-iot-dlt-based-fl0.2.04 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.44.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.44.0
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.44.0

Open the chart page →

77,883
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0

Open the chart page →

3,786
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0

Open the chart page →

9,411
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0

Open the chart page →

4,367
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0

Open the chart page →

13,369
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0

Open the chart page →

10,127
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/sys@v0.0.0-20220328115105-d36c6a25d886
0.44.0

Open the chart page →

18,357
performanceandusagediagnosisassist-iot-pud1.0.05 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

5 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
golang.org/x/sys@v0.0.0-20220615213510-4f61da869c0c
0.44.0
jimmidyson/configmap-reload:v0.5.0904d08e9f701
golang.org/x/sys@v0.0.0-20200620081246-981b61492c35
0.44.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/sys@v0.8.0
0.44.0
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/sys@v0.0.0-20220615213510-4f61da869c0c
0.44.0

Open the chart page →

8,570
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0

Open the chart page →

8,052
semantic-repositoryassist-iot-semantic-repository1.1.01 of 3See more

semantic-repository assist-iot-semantic-repository 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
golang.org/x/sys@v0.34.0
0.44.0

Open the chart page →

1,084
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/sys@v0.30.0
0.44.0
library/mongo:4.4.66efa05203990
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
0.44.0
library/mysql:5.74bc6bc963e6d
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0

Open the chart page →

45,656
astrotrekastria0.0.24 of 4See more

astrotrek astria 0.0.2

4 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
golang.org/x/sys@v0.0.0-20191026070338-33540a1f6037
0.44.0
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
golang.org/x/sys@v0.21.0
0.44.0
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
golang.org/x/sys@v0.21.0
0.44.0
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

32,638
celestia-localastria9.0.02 of 2See more

celestia-local astria 9.0.0

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
golang.org/x/sys@v0.36.0
0.44.0
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/sys@v0.35.0
0.44.0

Open the chart page →

3,299
celestia-nodeastria0.7.11 of 1See more

celestia-node astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/sys@v0.35.0
0.44.0

Open the chart page →

1,513
evm-faucetastria0.1.51 of 1See more

evm-faucet astria 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0

Open the chart page →

1,764
evm-rollupastria4.1.01 of 2See more

evm-rollup astria 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

4,010
evm-stackastria5.0.31 of 2See more

evm-stack astria 5.0.3

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

4,010
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

3,710
graph-nodeastria0.2.22 of 3See more

graph-node astria 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/sys@v0.2.0
0.44.0
library/postgres:latest4ef4dbc939d6
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

5,547
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
golang.org/x/sys@v0.29.0
0.44.0
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/sys@v0.0.0-20210423185535-09eb48e85fd7
0.44.0

Open the chart page →

6,335
sequencer-faucetastria0.9.21 of 1See more

sequencer-faucet astria 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
golang.org/x/sys@v0.23.0
0.44.0

Open the chart page →

1,320
phonebook-chartasumankamberoglu0.1.51 of 3See more

phonebook-chart asumankamberoglu 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0

Open the chart page →

3,176
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

9,429
hcloud-csi-driveratem181.5.12 of 6See more

hcloud-csi-driver atem18 1.5.1

2 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
golang.org/x/sys@v0.0.0-20201015000850-e3ed0017c211
0.44.0
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/sys@v0.0.0-20180302081741-dd2ff4accc09
0.44.0

Open the chart page →

6,509
attestkeepattestkeepVerified publisher1.1.01 of 2See more

attestkeep attestkeep 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:16.4-alpine5660c2cbfea5
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

1,598
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
0.44.0

Open the chart page →

7,570
okd-webhookav1o-chartsVerified publisher0.1.01 of 1See more

okd-webhook av1o-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
0.44.0

Open the chart page →

1,727
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
golang.org/x/sys@v0.5.0
0.44.0

Open the chart page →

5,082
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
golang.org/x/sys@v0.0.0-20220919091848-fb04ddd9f9c8
0.44.0

Open the chart page →

6,958
kubeslice-workeraveshaVerified publisher1.5.02 of 14See more

kubeslice-worker avesha 1.5.0

2 of the 14 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
golang.org/x/sys@v0.19.0
0.44.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.1f6717ce72a26
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

1,644
amazon-ec2-metadata-mockaws1.11.21 of 1See more

amazon-ec2-metadata-mock aws 1.11.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/amazon-ec2-metadata-mock:v1.11.2dd02d3569da0
golang.org/x/sys@v0.0.0-20210823070655-63515b42dcdf
0.44.0

Open the chart page →

860
appmesh-jaegeraws1.0.31 of 1See more

appmesh-jaeger aws 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/sys@v0.0.0-20210823070655-63515b42dcdf
0.44.0

Open the chart page →

2,487

Container images carrying it

4,358 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/sys@v0.25.0
0.44.0
2
quay.io/prometheus-operator/prometheus-operator:v0.83.0b6a89b8ec08f
golang.org/x/sys@v0.33.0
0.44.0
2
quay.io/prometheus-operator/prometheus-operator:v0.88.1d3d65efa3bee
golang.org/x/sys@v0.39.0
0.44.0
2
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/sys@v0.25.0
0.44.0
2
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/sys@v0.21.0
0.44.0
2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/sys@v0.28.0
0.44.0
2
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/sys@v0.0.0-20201008064518-c1f3e3309c71
0.44.0
2
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/sys@v0.10.0
0.44.0
2
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
2
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/sys@v0.22.0
0.44.0
2
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/sys@v0.37.0
0.44.0
2
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/sys@v0.8.0
0.44.0
2
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/sys@v0.29.0
0.44.0
2
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/sys@v0.39.0
0.44.0
2
quay.io/thanos/thanos:v0.39.21d022ef4b8ef
golang.org/x/sys@v0.33.0
0.44.0
2
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/sys@v0.23.0
0.44.0
2
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/sys@v0.23.0
0.44.0
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/sys@v0.21.0
0.44.0
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
golang.org/x/sys@v0.38.0
0.44.0
2
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.44.0
2
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/sys@v0.13.0
0.44.0
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/sys@v0.33.0
0.44.0
2
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/sys@v0.15.0
0.44.0
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
golang.org/x/sys@v0.31.0
0.44.0
2
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/sys@v0.5.0
0.44.0
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/sys@v0.3.0
0.44.0
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/sys@v0.3.0
0.44.0
2
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/sys@v0.18.0
0.44.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/sys@v0.1.0
0.44.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/sys@v0.13.0
0.44.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/sys@v0.0.0-20220615213510-4f61da869c0c
0.44.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0db384bf43222
golang.org/x/sys@v0.28.0
0.44.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/sys@v0.8.0
0.44.0
2
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
golang.org/x/sys@v0.33.0
0.44.0
2
registry.k8s.io/sig-storage/csi-attacher:v4.9.05aaefc24f315
golang.org/x/sys@v0.33.0
0.44.0
2
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
2
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
2
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/sys@v0.28.0
0.44.0
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
2
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
2
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
golang.org/x/sys@v0.35.0
0.44.0
2
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
golang.org/x/sys@v0.35.0
0.44.0
2
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0
2
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
2
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/sys@v0.10.0
0.44.0
2
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0
2
registry.k8s.io/sig-storage/csi-snapshotter:v8.3.0bc7be893ecc3
golang.org/x/sys@v0.32.0
0.44.0
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.