StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,770
of 17,803 indexed, latest versions
Container images
4,347
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,770 of 17,803 indexed charts deploy, on 4,347 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+268 more0.44.04,347
OSV records
GO-2026-5024

Charts affected

3,770 by stars
ChartLatestAffected imagesRadar Score
nvidia-gpu-exporterkubeblocksVerified publisher0.3.11 of 1See more

nvidia-gpu-exporter kubeblocks 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.44.0

Open the chart page →

4,516
openebskubeblocksVerified publisher3.10.03 of 3See more

openebs kubeblocks 3.10.0

3 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
openebs/provisioner-localpv:3.5.0aea39e49bb97
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

10,613
postgres-operatorkubeblocksVerified publisher1.12.21 of 1See more

postgres-operator kubeblocks 1.12.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
golang.org/x/sys@v0.20.0
0.44.0

Open the chart page →

1,555
prometheuskubeblocksVerified publisher15.16.16 of 6See more

prometheus kubeblocks 15.16.1

6 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
golang.org/x/sys@v0.0.0-20200620081246-981b61492c35
0.44.0
prom/pushgateway:v1.4.33496e0f85943
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0
quay.io/prometheus/alertmanager:v0.24.0088464f949de
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/sys@v0.0.0-20211117180635-dee7805ff2e1
0.44.0
quay.io/prometheus/prometheus:v2.39.14748e26f9369
golang.org/x/sys@v0.0.0-20220919091848-fb04ddd9f9c8
0.44.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0

Open the chart page →

10,321
smartfs-csi-driverkubeblocksVerified publisher0.1.21 of 6See more

smartfs-csi-driver kubeblocks 0.1.2

1 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

9,257
snapshot-controllerkubeblocksVerified publisher1.7.21 of 1See more

snapshot-controller kubeblocks 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/sys@v0.3.0
0.44.0

Open the chart page →

1,128
spiderpoolkubeblocksVerified publisher1.2.04 of 4See more

spiderpool kubeblocks 1.2.0

4 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
golang.org/x/sys@v0.18.0
0.44.0
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
golang.org/x/sys@v0.0.0-20210902050250-f475640dd07b
0.44.0
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
golang.org/x/sys@v0.0.0-20210902050250-f475640dd07b
0.44.0
ghcr.io/spidernet-io/spiderpool/spiderpool-plugins:19f19457ae7cec86457b0411543a3cf21dd9f95a8edc39be1e22
golang.org/x/sys@v0.35.0
0.44.0

Open the chart page →

8,498
vaultkubeblocksVerified publisher0.30.02 of 2See more

vault kubeblocks 0.30.0

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
hashicorp/vault:1.19.0bbb7f98dc67d
golang.org/x/sys@v0.30.0
0.44.0
hashicorp/vault-k8s:1.6.2103a2d817a74
golang.org/x/sys@v0.30.0
0.44.0

Open the chart page →

3,042
victoria-metrics-alertkubeblocksVerified publisher0.8.3-reload3 of 3See more

victoria-metrics-alert kubeblocks 0.8.3-reload

3 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
golang.org/x/sys@v0.0.0-20200620081246-981b61492c35
0.44.0
victoriametrics/vmalert:v1.95.1a83e5db0897a
golang.org/x/sys@v0.14.0
0.44.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/sys@v0.3.0
0.44.0

Open the chart page →

3,716
kube-botblocker-operatorkube-botblockerVerified publisher0.2.21 of 2See more

kube-botblocker-operator kube-botblocker 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/gustavojst/kube-botblocker:0.2.04de059bb32ac
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

507
kubeclaritykubeclarity2.23.33 of 5See more

kubeclarity kubeclarity 2.23.3

3 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/openclarity/grype-server:v0.6.079412399f301
golang.org/x/sys@v0.11.0
0.44.0
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
golang.org/x/sys@v0.15.0
0.44.0
ghcr.io/openclarity/kubeclarity-sbom-db:v2.23.3cef2b88bfc76
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

5,521
airflow-operatorkubedoopVerified publisher0.4.01 of 1See more

airflow-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/airflow-operator:0.4.0b716ef483b75
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

438
commons-operatorkubedoopVerified publisher0.4.01 of 1See more

commons-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/commons-operator:0.4.01a353def9fe1
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

388
dolphinscheduler-operatorkubedoopVerified publisher0.4.01 of 1See more

dolphinscheduler-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/dolphinscheduler-operator:0.4.0d0a4e55eeb7f
golang.org/x/sys@v0.43.0
0.44.0

Open the chart page →

381
hbase-operatorkubedoopVerified publisher0.4.01 of 1See more

hbase-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/hbase-operator:0.4.069e9a1b0daf8
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

388
hdfs-operatorkubedoopVerified publisher0.4.01 of 1See more

hdfs-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/hdfs-operator:0.4.0eb3c2928250e
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

438
hive-operatorkubedoopVerified publisher0.4.01 of 1See more

hive-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/hive-operator:0.4.0d66ba9149c22
golang.org/x/sys@v0.43.0
0.44.0

Open the chart page →

381
kafka-operatorkubedoopVerified publisher0.4.01 of 1See more

kafka-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/kafka-operator:0.4.00a0b4c39c1ba
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

464
listener-operatorkubedoopVerified publisher0.4.06 of 6See more

listener-operator kubedoop 0.4.0

6 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/listener-csi-driver:0.4.0b69bed123b02
golang.org/x/sys@v0.43.0
0.44.0
quay.io/zncdatadev/listener-operator:0.4.068b92dae8d75
golang.org/x/sys@v0.43.0
0.44.0
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/sys@v0.23.0
0.44.0
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/sys@v0.23.0
0.44.0
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/sys@v0.21.0
0.44.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/sys@v0.24.0
0.44.0

Open the chart page →

4,534
nifi-operatorkubedoopVerified publisher0.4.01 of 1See more

nifi-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/nifi-operator:0.4.0bb4e26ff5e2f
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

388
secret-operatorkubedoopVerified publisher0.4.05 of 5See more

secret-operator kubedoop 0.4.0

5 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/secret-csi-driver:0.4.0604a7d98ab58
golang.org/x/sys@v0.38.0
0.44.0
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/sys@v0.23.0
0.44.0
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/sys@v0.23.0
0.44.0
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/sys@v0.21.0
0.44.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/sys@v0.24.0
0.44.0

Open the chart page →

4,453
spark-k8s-operatorkubedoopVerified publisher0.4.01 of 1See more

spark-k8s-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/spark-k8s-operator:0.4.0d3f2b10c4a6d
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

411
superset-operatorkubedoopVerified publisher0.4.01 of 1See more

superset-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/superset-operator:0.4.0102e66e32218
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

388
zookeeper-operatorkubedoopVerified publisher0.4.01 of 1See more

zookeeper-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/zncdatadev/zookeeper-operator:0.4.0b4f33d89ac45
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

388
kube-ecr-secrets-operatorkube-ecr-secrets-operatorVerified publisher0.4.01 of 2See more

kube-ecr-secrets-operator kube-ecr-secrets-operator 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/zak905/kube-ecr-secrets-operator/controller-manager:0.2.11d078e45bac70
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

208
cephfs-csikubegems1.0.81 of 6See more

cephfs-csi kubegems 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
0.44.0

Open the chart page →

4,452
chartmuseumkubegems3.8.01 of 1See more

chartmuseum kubegems 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0

Open the chart page →

3,527
gatewaykubegems0.3.22 of 2See more

gateway kubegems 0.3.2

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
kubegems/ingress-nginx-operator:v0.2.0cc67357beeeb
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
0.44.0
kubegems/kube-rbac-proxy:v0.8.0941f557ed1ee
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
0.44.0

Open the chart page →

3,506
giteakubegems5.0.81 of 2See more

gitea kubegems 5.0.8

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gitea/gitea:1.16.8b0bdf102b485
golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9
0.44.0

Open the chart page →

3,400
juicefs-csi-driverkubegems0.19.22 of 6See more

juicefs-csi-driver kubegems 0.19.2

2 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/sys@v0.13.0
0.44.0
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

4,865
juicefs-tenantkubegems1.0.11 of 3See more

juicefs-tenant kubegems 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
kubegems/redis:7.2.5-debian-12-r2870ee3a77add
golang.org/x/sys@v0.2.0
0.44.0

Open the chart page →

4,333
knative-servingkubegems1.0.17 of 8See more

knative-serving kubegems 1.0.1

7 of the 8 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned197fbb71d1f1
golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned08315309da4b
golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned105bdd14ecaa
golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedbac158dfb0c7
golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mappingdigest-pinnede384a295069b
golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhookdigest-pinned15f1ce7f35b4
golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned1282a399cbb9
golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9
0.44.0

Open the chart page →

10,469
kubegems-edgekubegems1.24.101 of 1See more

kubegems-edge kubegems 1.24.10

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/sys@v0.15.0
0.44.0

Open the chart page →

3,397
kubegems-multus-cnikubegems2.4.11 of 2See more

kubegems-multus-cni kubegems 2.4.1

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.16bebbda31416
golang.org/x/sys@v0.23.0
0.44.0

Open the chart page →

1,404
kubegems-paikubegems1.0.181 of 1See more

kubegems-pai kubegems 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
kubegems/mysql:8.0.33-debian-11-r019cb195b9a50
golang.org/x/sys@v0.2.0
0.44.0

Open the chart page →

1,053
logging-operatorkubegems3.17.61 of 1See more

logging-operator kubegems 3.17.6

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0

Open the chart page →

1,801
prometheus-adapterkubegems4.14.11 of 1See more

prometheus-adapter kubegems 4.14.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/sys@v0.19.0
0.44.0

Open the chart page →

945
prometheus-blackbox-exporterkubegems7.1.31 of 1See more

prometheus-blackbox-exporter kubegems 7.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.22.0608acee5704a
golang.org/x/sys@v0.0.0-20220728004956-3c1f35247d10
0.44.0

Open the chart page →

1,635
volcanokubegems1.12.13 of 3See more

volcano kubegems 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
volcanosh/vc-controller-manager:v1.12.13815883c32f6
golang.org/x/sys@v0.32.0
0.44.0
volcanosh/vc-scheduler:v1.12.1b24ea8af2d16
golang.org/x/sys@v0.32.0
0.44.0
volcanosh/vc-webhook-manager:v1.12.1f8b50088a732
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

5,045
xpai-schedulerkubegems1.12.11 of 2See more

xpai-scheduler kubegems 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
0.44.0

Open the chart page →

2,324
gptchat-api-feishubotkubegemsapp0.1.13 of 3See more

gptchat-api-feishubot kubegemsapp 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
kubegems/chatgpt-api:latestf3c492a938ad
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
kubegems/chatgpt-api-feishubot:latest7c93c84b2055
golang.org/x/sys@v0.3.0
0.44.0
kubegems/chatgpt-api-proxy:latest8905c9dbbb5d
golang.org/x/sys@v0.3.0
0.44.0

Open the chart page →

8,491
kubeintellectkubeintellectVerified publisher2.5.01 of 2See more

kubeintellect kubeintellect 2.5.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

1,909
kubelet-summary-exporterkubelet-summary-exporter1.0.01 of 1See more

kubelet-summary-exporter kubelet-summary-exporter 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/salesforce/kubelet-summary-exporter:sha-c2bf90d377e09d2dd72
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

1,016
log-generatorkube-loggingVerified publisher0.6.01 of 1See more

log-generator kube-logging 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/log-generator:v0.6.08324bbc0ec08
golang.org/x/sys@v0.5.0
0.44.0

Open the chart page →

1,269
logging-demokube-loggingVerified publisher4.0.31 of 1See more

logging-demo kube-logging 4.0.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/log-generator:v0.4.105aa441b20aa
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.44.0

Open the chart page →

1,268
log-socketkube-loggingVerified publisher0.1.21 of 1See more

log-socket kube-logging 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/log-socket:latesta514736d2d4d
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0

Open the chart page →

1,220
kubemacpoolkubemacpoolVerified publisher0.3.01 of 1See more

kubemacpool kubemacpool 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubemacpool:v0.45.0eebb65b8a12c
golang.org/x/sys@v0.18.0
0.44.0

Open the chart page →

1,641
kube-netlagkube-netlagVerified publisher1.1.01 of 1See more

kube-netlag kube-netlag 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

1,502
kube-node-readykube-node-ready0.5.01 of 1See more

kube-node-ready kube-node-ready 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/imunhatep/kube-node-ready:0.5.07439f6f9f85c
golang.org/x/sys@v0.35.0
0.44.0

Open the chart page →

543
apm-serverkube-opsVerified publisher0.1.21 of 1See more

apm-server kube-ops 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
elastic/apm-server:7.17.6c7a1c63257d0
golang.org/x/sys@v0.0.0-20220818161305-2296e01440c6
0.44.0

Open the chart page →

7,221

Container images carrying it

4,347 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
golang.org/x/sys@v0.3.0
0.44.0
1
jaegertracing/jaeger-operator:1.61.03f036ec60e61
golang.org/x/sys@v0.25.0
0.44.0
1
jaegertracing/jaeger-query:1.41.0b636f0f464bc
golang.org/x/sys@v0.3.0
0.44.0
1
jakuboskera/todo-operator:v0.1.0a305b8ce5bff
golang.org/x/sys@v0.38.0
0.44.0
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/sys@v0.25.0
0.44.0
1
jeboehm/mailserver-filter:5.0.92e756949e537d
golang.org/x/sys@v0.31.0
0.44.0
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
golang.org/x/sys@v0.31.0
0.44.0
1
jeboehm/mailserver-mta:5.0.925fb2f31c940d
golang.org/x/sys@v0.31.0
0.44.0
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
golang.org/x/sys@v0.31.0
0.44.0
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
golang.org/x/sys@v0.15.0
0.44.0
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
golang.org/x/sys@v0.15.0
0.44.0
1
jfwenisch/alpine-tor:latest9e6c229f953c
golang.org/x/sys@v0.0.0-20190329044733-9eb1bfa1ce65
0.44.0
1
jhaals/yopass:11.17.026873480863b
golang.org/x/sys@v0.26.0
0.44.0
1
jhaals/yopass:11.15.16bca8d5a4914
golang.org/x/sys@v0.13.0
0.44.0
1
jhaals/yopass:12.5.0916a1cf45d36
golang.org/x/sys@v0.38.0
0.44.0
1
jhaals/yopass:11.4.69516e3b3e88c
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
1
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/sys@v0.1.0
0.44.0
1
jhonbrownn/elchi-discovery:latest8f6551ecc98c
golang.org/x/sys@v0.10.0
0.44.0
1
jkremser/log2rbac:v0.0.5e35cf56ef183
golang.org/x/sys@v0.0.0-20220412211240-33da011f77ad
0.44.0
1
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/sys@v0.0.0-20191028164358-195ce5e7f934
0.44.0
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
0.44.0
1
johnblack77/clustereye-api:latest9b8dbc0264ac
golang.org/x/sys@v0.41.0
0.44.0
1
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/sys@v0.13.0
0.44.0
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/sys@v0.7.0
0.44.0
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/sys@v0.13.0
0.44.0
1
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
golang.org/x/sys@v0.42.0
0.44.0
1
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/sys@v0.0.0-20220728004956-3c1f35247d10
0.44.0
1
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
golang.org/x/sys@v0.27.0
0.44.0
1
jwilder/dockerize:v0.10.0839cd6793d19
golang.org/x/sys@v0.40.0
0.44.0
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0
1
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
0.44.0
1
kaiso/kom-operator:v2.2.0e0e22b928bdd
golang.org/x/sys@v0.13.0
0.44.0
1
kayrosuno/kping:latestf3bd44b29b0d
golang.org/x/sys@v0.35.0
0.44.0
1
kazem26/liqo-upgrade-operator:v0.1268b7c6a59dd
golang.org/x/sys@v0.31.0
0.44.0
1
keelhq/keel:0.19.202ac4ea616c4
golang.org/x/sys@v0.8.0
0.44.0
1
keeper/injector-webhook:0.10.0aeb5476b95f0
golang.org/x/sys@v0.38.0
0.44.0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
golang.org/x/sys@v0.35.0
0.44.0
1
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/sys@v0.0.0-20200420163511-1957bb5e6d1f
0.44.0
1
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
1
keptn/distributor:0.8.472e17527a4f9
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
1
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/sys@v0.0.0-20210603125802-9665404d3644
0.44.0
1
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
golang.org/x/sys@v0.0.0-20190312061237-fead79001313
0.44.0
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
golang.org/x/sys@v0.13.0
0.44.0
1
kfirfer/scripts:0.0.2481e5c4e5d70e
golang.org/x/sys@v0.0.0-20210809222454-d867a43fc93e
0.44.0
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/sys@v0.0.0-20200905004654-be1d3432aa8f
0.44.0
1
khaliq/drl-exporter:latestf63cf53166f8
golang.org/x/sys@v0.24.0
0.44.0
1
khaliq/pingme:v0.2.749f96888d2ab
golang.org/x/sys@v0.38.0
0.44.0
1
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
1
komodorio/komoplane:0.2.19678d02c3f2e
golang.org/x/sys@v0.38.0
0.44.0
1
kong/gateway-operator:1.603510967482b
golang.org/x/sys@v0.32.0
0.44.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.