StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,843
of 17,805 indexed, latest versions
Container images
4,392
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,843 of 17,805 indexed charts deploy, on 4,392 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+271 more0.44.04,392
OSV records
GO-2026-5024

Charts affected

3,843 by stars
ChartLatestAffected imagesRadar Score
minioowan-charts0.1.21 of 2See more

minio owan-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

1,083
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0

Open the chart page →

1,827
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
golang.org/x/sys@v0.19.0
0.44.0

Open the chart page →

1,997
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

3,695
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
golang.org/x/sys@v0.19.0
0.44.0

Open the chart page →

3,358
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
golang.org/x/sys@v0.20.0
0.44.0
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
golang.org/x/sys@v0.20.0
0.44.0

Open the chart page →

2,336
predicatep2p-avs0.1.41 of 1See more

predicate p2p-avs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

893
p4p40.1.03 of 7See more

p4 p4 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/sys@v0.5.0
0.44.0
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/sys@v0.38.0
0.44.0
library/mysql:8b3b90af2a655
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

27,870
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

19,767
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

3,626
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-andromeda1.0.01 of 3See more

pages pages-andromeda 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespagesbadami1.0.01 of 3See more

pages pagesbadami 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-blackburn1.0.01 of 3See more

pages pages-blackburn 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-botes1.0.01 of 3See more

pages pages-botes 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-brian1.0.01 of 3See more

pages pages-brian 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-buckll1.0.01 of 3See more

pages pages-buckll 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-camden1.0.01 of 3See more

pages pages-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-camden7711.0.01 of 3See more

pages pages-camden771 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-diarmuidkeane1.0.01 of 3See more

pages pages-diarmuidkeane 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-draco1.0.01 of 3See more

pages pages-draco 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-ellora1.0.01 of 3See more

pages pages-ellora 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-finchley1.0.01 of 3See more

pages pages-finchley 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-fornax1.0.01 of 3See more

pages pages-fornax 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-harsh1.0.01 of 3See more

pages pages-harsh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespagesk1.0.01 of 3See more

pages pagesk 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-microservice-ashim1.0.01 of 3See more

pages pages-microservice-ashim 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-mihai1.0.01 of 3See more

pages pages-mihai 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-nivesh1.0.01 of 3See more

pages pages-nivesh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespagessandeepgudu1.0.01 of 3See more

pages pagessandeepgudu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-shubhanker1.0.01 of 3See more

pages pages-shubhanker 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-ssharma09091.0.01 of 3See more

pages pages-ssharma0909 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-sucharitha1.0.01 of 3See more

pages pages-sucharitha 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-sudhir1.0.01 of 3See more

pages pages-sudhir 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-sushi1.0.01 of 3See more

pages pages-sushi 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-vasanth58141.0.01 of 3See more

pages pages-vasanth5814 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-vjp1.0.01 of 3See more

pages pages-vjp 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
paperclippaperclip-helmVerified publisher0.1.01 of 3See more

paperclip paperclip-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

494
Parpar0.1.01 of 1See more

Par par 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/jmcgrath207/par:v0.1.09977511cb142
golang.org/x/sys@v0.8.0
0.44.0

Open the chart page →

890
parcaparca4.19.02 of 2See more

parca parca 4.19.0

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/sys@v0.13.0
0.44.0
ghcr.io/parca-dev/parca-agent:v0.28.06d6794f45f3e
golang.org/x/sys@v0.15.0
0.44.0

Open the chart page →

3,384
parcaparca-chart0.1.01 of 1See more

parca parca-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

1,995
parcaparca-rr0.1.02 of 2See more

parca parca-rr 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.24.23776500fde82
golang.org/x/sys@v0.33.0
0.44.0
ghcr.io/parca-dev/parca-agent:v0.42.0adc0eeb4dd05
golang.org/x/sys@v0.35.0
0.44.0

Open the chart page →

2,405
parcial-1parcial-1-chart1.0.02 of 5See more

parcial-1 parcial-1-chart 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
golang.org/x/sys@v0.35.0
0.44.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.1e63459ec5965
golang.org/x/sys@v0.34.0
0.44.0

Open the chart page →

3,887

Container images carrying it

4,392 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/sys@v0.19.0
0.44.0
1
grafana/alloy:v1.14.0f50931848bd8
golang.org/x/sys@v0.41.0
0.44.0
1
grafana/beyla:1.3.336d07f8d276e
golang.org/x/sys@v0.17.0
0.44.0
1
grafana/beyla-k8s-cache:253b2f561cb1b
golang.org/x/sys@v0.39.0
0.44.0
1
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/sys@v0.0.0-20191220142924-d4481acd189f
0.44.0
1
grafana/grafana:10.1.50679e877ba20
golang.org/x/sys@v0.10.0
0.44.0
1
grafana/grafana:7.5.609bb407e26ab
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
1
grafana/grafana:13.0.10f86bada30d6
golang.org/x/sys@v0.42.0
0.44.0
1
grafana/grafana:7.3.315b977f5207d
golang.org/x/sys@v0.0.0-20200812155832-6a926be9bd1d
0.44.0
1
grafana/grafana:9.4.71a359d92f40e
golang.org/x/sys@v0.3.0
0.44.0
1
grafana/grafana:10.1.11b9ca4bbc4a2
golang.org/x/sys@v0.10.0
0.44.0
1
grafana/grafana:13.0.1-security-012d1f9ae67c17
golang.org/x/sys@v0.42.0
0.44.0
1
grafana/grafana:12.2.22ebef928d7e5
golang.org/x/sys@v0.36.0
0.44.0
1
grafana/grafana:12.2.135c41e0fd029
golang.org/x/sys@v0.36.0
0.44.0
1
grafana/grafana:9.5.239c849cebccc
golang.org/x/sys@v0.6.0
0.44.0
1
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/sys@v0.23.0
0.44.0
1
grafana/grafana:11.5.15781759b3d27
golang.org/x/sys@v0.29.0
0.44.0
1
grafana/grafana:11.6.062d2b9d20a19
golang.org/x/sys@v0.30.0
0.44.0
1
grafana/grafana:8.0.3696823fbc561
golang.org/x/sys@v0.0.0-20210521203332-0cec03c779c1
0.44.0
1
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/sys@v0.15.0
0.44.0
1
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/sys@v0.0.0-20200812155832-6a926be9bd1d
0.44.0
1
grafana/grafana:12.3.070d9599b186c
golang.org/x/sys@v0.37.0
0.44.0
1
grafana/grafana:7.2.1733842cca5bd
golang.org/x/sys@v0.0.0-20200812155832-6a926be9bd1d
0.44.0
1
grafana/grafana:12.2.074144189b384
golang.org/x/sys@v0.35.0
0.44.0
1
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/sys@v0.3.0
0.44.0
1
grafana/grafana:10.3.38640e5038e83
golang.org/x/sys@v0.15.0
0.44.0
1
grafana/grafana:11.5.28b37a2f028f1
golang.org/x/sys@v0.29.0
0.44.0
1
grafana/grafana:9.1.19746858c20e6
golang.org/x/sys@v0.0.0-20220615213510-4f61da869c0c
0.44.0
1
grafana/grafana:12.1.1a1701c218024
golang.org/x/sys@v0.33.0
0.44.0
1
grafana/grafana:9.0.1a738d0744784
golang.org/x/sys@v0.0.0-20220422013727-9388b58f7150
0.44.0
1
grafana/grafana:10.4.19a9043254ba16
golang.org/x/sys@v0.33.0
0.44.0
1
grafana/grafana:13.1.3ab5cb380e3ff
golang.org/x/sys@v0.42.0
0.44.0
1
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/sys@v0.21.0
0.44.0
1
grafana/grafana:12.0.2b5b59bfc7561
golang.org/x/sys@v0.33.0
0.44.0
1
grafana/grafana:12.3.2ba93c9d192e5
golang.org/x/sys@v0.38.0
0.44.0
1
grafana/grafana:6.5.1befcd84da2c1
golang.org/x/sys@v0.0.0-20190922100055-0a153f010e69
0.44.0
1
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/sys@v0.0.0-20210908233432-aa78b53d3365
0.44.0
1
grafana/grafana:8.3.4cf81d2c753c8
golang.org/x/sys@v0.0.0-20210908233432-aa78b53d3365
0.44.0
1
grafana/grafana:7.4.5d322192ed2fa
golang.org/x/sys@v0.0.0-20201022201747-fb209a7c41cd
0.44.0
1
grafana/grafana:8.5.3ecc1b80b8ca2
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0
1
grafana/grafana:10.4.0f9811e4e687f
golang.org/x/sys@v0.16.0
0.44.0
1
grafana/grafana:11.3.1fa801ab6e1ae
golang.org/x/sys@v0.25.0
0.44.0
1
grafana/kubernetes-diff-logger:0.0.598f6d1cd1e25
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0
1
grafana/logcli:main-c90366d-amd643d85bb66e39b
golang.org/x/sys@v0.0.0-20210503173754-0981d6026fa6
0.44.0
1
grafana/loki:2.9.1035b02acc6765
golang.org/x/sys@v0.21.0
0.44.0
1
grafana/loki:2.9.26074e01dbe03
golang.org/x/sys@v0.13.0
0.44.0
1
grafana/loki:2.9.66ca6e2cd3b6f
golang.org/x/sys@v0.16.0
0.44.0
1
grafana/loki:3.0.0757b5fadf816
golang.org/x/sys@v0.18.0
0.44.0
1
grafana/loki:2.0.077e138f81a8e
golang.org/x/sys@v0.0.0-20201008064518-c1f3e3309c71
0.44.0
1
grafana/loki:3.6.5847c287ada0e
golang.org/x/sys@v0.38.0
0.44.0
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.