StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,765
of 17,797 indexed, latest versions
Container images
4,328
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,765 of 17,797 indexed charts deploy, on 4,328 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+268 more0.44.04,328
OSV records
GO-2026-5024

Charts affected

3,765 by stars
ChartLatestAffected imagesRadar Score
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
0.44.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
0.44.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
0.44.0

Open the chart page →

10,094
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/sys@v0.0.0-20210809222454-d867a43fc93e
0.44.0

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.021 of 28See more

devtron-enterprise devtron-labs 48.0.0

21 of the 28 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
golang.org/x/sys@v0.39.0
0.44.0
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
golang.org/x/sys@v0.42.0
0.44.0
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
golang.org/x/sys@v0.33.0
0.44.0
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
golang.org/x/sys@v0.42.0
0.44.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
golang.org/x/sys@v0.42.0
0.44.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/sys@v0.13.0
0.44.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
0.44.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/sys@v0.0.0-20210220050731-9a76102bfb43
0.44.0
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/sys@v0.42.0
0.44.0
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/sys@v0.42.0
0.44.0
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/sys@v0.42.0
0.44.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/sys@v0.8.0
0.44.0
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/sys@v0.0.0-20220928140112-f11e5e49a4ec
0.44.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/sys@v0.0.0-20220928140112-f11e5e49a4ec
0.44.0
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
golang.org/x/sys@v0.0.0-20200918174421-af09f7315aff
0.44.0
quay.io/devtron/postgres:14.91b594392f7cb
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.44.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/sys@v0.0.0-20210218155724-8ebf48af031b
0.44.0
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/sys@v0.24.0
0.44.0

Open the chart page →

68,765
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

5,055
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

4,979
devtron-operatordevtron-labs0.23.39 of 11See more

devtron-operator devtron-labs 0.23.3

9 of the 11 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/sys@v0.42.0
0.44.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/sys@v0.42.0
0.44.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/sys@v0.0.0-20210220050731-9a76102bfb43
0.44.0
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/sys@v0.42.0
0.44.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/sys@v0.8.0
0.44.0
quay.io/devtron/postgres:14.91b594392f7cb
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.44.0

Open the chart page →

33,219
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/sys@v0.0.0-20210511113859-b0526f3d8744
0.44.0

Open the chart page →

11,981
jcmhproxy-ingressdevtron-labs0.14.61 of 1See more

jcmhproxy-ingress devtron-labs 0.14.6

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/sys@v0.16.0
0.44.0

Open the chart page →

1,379
kube-prometheus-stackdevtron-labs19.3.03 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

3 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/sys@v0.0.0-20210806184541-e5e7981a1069
0.44.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
0.44.0

Open the chart page →

8,659
migrantdevtron-labs0.0.31 of 1See more

migrant devtron-labs 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
migrate/migrate:latestcc4ad8e19d66
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

740
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

3,927
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0

Open the chart page →

2,442
winter-soldierdevtron-labs0.10.61 of 1See more

winter-soldier devtron-labs 0.10.6

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0

Open the chart page →

1,176
zincdevtron-labs0.1.21 of 1See more

zinc devtron-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/sys@v0.3.0
0.44.0

Open the chart page →

1,514
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
golang.org/x/sys@v0.0.0-20200523222454-059865788121
0.44.0

Open the chart page →

27,676
dicedbdicedb-chart0.1.01 of 1See more

dicedb dicedb-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
prathamkrishna/dicedb:v1a7298180cd24
golang.org/x/sys@v0.25.0
0.44.0

Open the chart page →

672
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
golang.org/x/sys@v0.16.0
0.44.0
langgenius/dify-web:1.0.0d64914ff0d6d
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

19,513
digital-mobiusdigital-mobius0.1.41 of 1See more

digital-mobius digital-mobius 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
qoveryrd/digital-mobius:0.1.4b30a9398a83c
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
0.44.0

Open the chart page →

2,288
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,262
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

4,553
direktivdirektivVerified publisher0.10.04 of 6See more

direktiv direktiv 0.10.0

4 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
golang.org/x/sys@v0.30.0
0.44.0
victoriametrics/victoria-logs:v1.15.0-victorialogsd7435244eb19
golang.org/x/sys@v0.30.0
0.44.0
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/sys@v0.28.0
0.44.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

3,480
adventurelogdjjudas21Verified publisher0.1.12 of 3See more

adventurelog djjudas21 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

7,549
graphite-exporterdjjudas21Verified publisher0.1.91 of 1See more

graphite-exporter djjudas21 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
prom/graphite-exporter:v0.16.0e54bca6645ea
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

782
hammonddjjudas21Verified publisher0.3.91 of 1See more

hammond djjudas21 0.3.9

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/sys@v0.0.0-20210330210617-4fbd30eecc44
0.44.0

Open the chart page →

1,807
nova-exporterdjjudas21Verified publisher0.1.161 of 1See more

nova-exporter djjudas21 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
djjudas21/nova-exporter:0.0.10e9094580885c
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

1,412
ownclouddjjudas21Verified publisher0.3.231 of 3See more

owncloud djjudas21 0.3.23

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

10,199
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
golang.org/x/sys@v0.22.0
0.44.0

Open the chart page →

17,129
smokepingdjjudas21Verified publisher0.1.31 of 1See more

smokeping djjudas21 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.8.2b7f906899cd3
golang.org/x/sys@v0.0.0-20210514084401-e8d321eab015
0.44.0

Open the chart page →

2,054
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

5,304
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/sys@v0.15.0
0.44.0

Open the chart page →

4,226
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

3,845
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

3,845
dnation-kubernetes-monitoring-stackdnationcloud4.0.28 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

8 of the 17 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
golang.org/x/sys@v0.26.0
0.44.0
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
golang.org/x/sys@v0.38.0
0.44.0
grafana/grafana:13.1.0121a7a9ece6d
golang.org/x/sys@v0.40.0
0.44.0
grafana/loki:3.2.0882e30c20683
golang.org/x/sys@v0.24.0
0.44.0
grafana/loki-canary:3.2.049e03f80d361
golang.org/x/sys@v0.24.0
0.44.0
prom/memcached-exporter:v0.15.0bb01ad25e9fc
golang.org/x/sys@v0.26.0
0.44.0
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
golang.org/x/sys@v0.1.0
0.44.0
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

21,767
ssl-exporterdnationcloud1.2.11 of 1See more

ssl-exporter dnationcloud 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/sys@v0.0.0-20220712014510-0a85c31ab51e
0.44.0

Open the chart page →

1,632
snmp-exporterdniel0.0.21 of 1See more

snmp-exporter dniel 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
prom/snmp-exporter:v0.20.09d226d7de223
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
0.44.0

Open the chart page →

2,126
dnsmasq-k8sdnsmasq-k8s1.4.11 of 1See more

dnsmasq-k8s dnsmasq-k8s 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

3,075
docker-authdocker-auth1.14.01 of 1See more

docker-auth docker-auth 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.14.098e0307e0d2d
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

1,514
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
0.44.0

Open the chart page →

8,417
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

2,865
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
golang.org/x/sys@v0.0.0-20201005172224-997123666555
0.44.0

Open the chart page →

3,055
domain-exporterdomain-exporterVerified publisher0.0.81 of 1See more

domain-exporter domain-exporter 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/shift/domain_exporter:v0.1.1347e27690a816
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0

Open the chart page →

1,352
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

10,393
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/sys@v0.30.0
0.44.0

Open the chart page →

3,195
redminebotdossif0.1.71 of 1See more

redminebot dossif 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
dossif/redminebot:0.2.296dcd2c0e9f2
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

817
aliyun-exporterdoubanVerified publisher0.1.21 of 1See more

aliyun-exporter douban 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/douban/aliyun-exporter:mainb7c694331362
golang.org/x/sys@v0.9.0
0.44.0

Open the chart page →

968
channelsdoubanVerified publisher1.1.21 of 1See more

channels douban 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
everpcpc/channels:latestb378d137ae8b
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
0.44.0

Open the chart page →

2,540
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
codecov/self-hosted-gateway:24.4.1de483faad6e5
golang.org/x/sys@v0.17.0
0.44.0
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
golang.org/x/sys@v0.0.0-20191026070338-33540a1f6037
0.44.0

Open the chart page →

24,986
corednsdoubanVerified publisher1.39.21 of 1See more

coredns douban 1.39.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
coredns/coredns:1.12.040384aa1f5ea
golang.org/x/sys@v0.27.0
0.44.0

Open the chart page →

1,139
gatekeeperdoubanVerified publisher3.17.12 of 3See more

gatekeeper douban 3.17.1

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.17.1b7b4d7cfdd52
golang.org/x/sys@v0.22.0
0.44.0
openpolicyagent/gatekeeper-crds:v3.17.177bc9bf3d163
golang.org/x/sys@v0.18.0
0.44.0

Open the chart page →

2,499
goinceptiondoubanVerified publisher0.3.11 of 2See more

goinception douban 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
hanchuanchuan/goinception:latestb3c0dd26fb50
golang.org/x/sys@v0.18.0
0.44.0

Open the chart page →

1,208

Container images carrying it

4,328 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jaegertracing/jaeger-operator:1.61.03f036ec60e61
golang.org/x/sys@v0.25.0
0.44.0
1
jaegertracing/jaeger-query:1.41.0b636f0f464bc
golang.org/x/sys@v0.3.0
0.44.0
1
jakuboskera/todo-operator:v0.1.0a305b8ce5bff
golang.org/x/sys@v0.38.0
0.44.0
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/sys@v0.25.0
0.44.0
1
jeboehm/mailserver-filter:5.0.92e756949e537d
golang.org/x/sys@v0.31.0
0.44.0
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
golang.org/x/sys@v0.31.0
0.44.0
1
jeboehm/mailserver-mta:5.0.925fb2f31c940d
golang.org/x/sys@v0.31.0
0.44.0
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
golang.org/x/sys@v0.31.0
0.44.0
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
golang.org/x/sys@v0.15.0
0.44.0
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
golang.org/x/sys@v0.15.0
0.44.0
1
jfwenisch/alpine-tor:latest9e6c229f953c
golang.org/x/sys@v0.0.0-20190329044733-9eb1bfa1ce65
0.44.0
1
jhaals/yopass:11.17.026873480863b
golang.org/x/sys@v0.26.0
0.44.0
1
jhaals/yopass:11.15.16bca8d5a4914
golang.org/x/sys@v0.13.0
0.44.0
1
jhaals/yopass:12.5.0916a1cf45d36
golang.org/x/sys@v0.38.0
0.44.0
1
jhaals/yopass:11.4.69516e3b3e88c
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
1
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/sys@v0.1.0
0.44.0
1
jhonbrownn/elchi-discovery:latest8f6551ecc98c
golang.org/x/sys@v0.10.0
0.44.0
1
jkremser/log2rbac:v0.0.5e35cf56ef183
golang.org/x/sys@v0.0.0-20220412211240-33da011f77ad
0.44.0
1
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/sys@v0.0.0-20191028164358-195ce5e7f934
0.44.0
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
0.44.0
1
johnblack77/clustereye-api:latest9b8dbc0264ac
golang.org/x/sys@v0.41.0
0.44.0
1
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/sys@v0.13.0
0.44.0
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/sys@v0.7.0
0.44.0
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/sys@v0.13.0
0.44.0
1
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
golang.org/x/sys@v0.42.0
0.44.0
1
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/sys@v0.0.0-20220728004956-3c1f35247d10
0.44.0
1
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
golang.org/x/sys@v0.27.0
0.44.0
1
jwilder/dockerize:v0.10.0839cd6793d19
golang.org/x/sys@v0.40.0
0.44.0
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0
1
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
0.44.0
1
kaiso/kom-operator:v2.2.0e0e22b928bdd
golang.org/x/sys@v0.13.0
0.44.0
1
kayrosuno/kping:latestf3bd44b29b0d
golang.org/x/sys@v0.35.0
0.44.0
1
kazem26/liqo-upgrade-operator:v0.1268b7c6a59dd
golang.org/x/sys@v0.31.0
0.44.0
1
keelhq/keel:0.19.202ac4ea616c4
golang.org/x/sys@v0.8.0
0.44.0
1
keeper/injector-webhook:0.10.0aeb5476b95f0
golang.org/x/sys@v0.38.0
0.44.0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
golang.org/x/sys@v0.35.0
0.44.0
1
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/sys@v0.0.0-20200420163511-1957bb5e6d1f
0.44.0
1
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
1
keptn/distributor:0.8.472e17527a4f9
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
1
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/sys@v0.0.0-20210603125802-9665404d3644
0.44.0
1
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
golang.org/x/sys@v0.0.0-20190312061237-fead79001313
0.44.0
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
golang.org/x/sys@v0.13.0
0.44.0
1
kfirfer/scripts:0.0.2481e5c4e5d70e
golang.org/x/sys@v0.0.0-20210809222454-d867a43fc93e
0.44.0
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/sys@v0.0.0-20200905004654-be1d3432aa8f
0.44.0
1
khaliq/drl-exporter:latestf63cf53166f8
golang.org/x/sys@v0.24.0
0.44.0
1
khaliq/pingme:v0.2.749f96888d2ab
golang.org/x/sys@v0.38.0
0.44.0
1
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
1
komodorio/komoplane:0.2.19678d02c3f2e
golang.org/x/sys@v0.38.0
0.44.0
1
kong/gateway-operator:1.603510967482b
golang.org/x/sys@v0.32.0
0.44.0
1
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/sys@v0.0.0-20220328115105-d36c6a25d886
0.44.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.