StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,843
of 17,805 indexed, latest versions
Container images
4,392
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,843 of 17,805 indexed charts deploy, on 4,392 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+271 more0.44.04,392
OSV records
GO-2026-5024

Charts affected

3,843 by stars
ChartLatestAffected imagesRadar Score
minioowan-charts0.1.21 of 2See more

minio owan-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

1,083
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0

Open the chart page →

1,827
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
golang.org/x/sys@v0.19.0
0.44.0

Open the chart page →

1,997
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

3,695
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
golang.org/x/sys@v0.19.0
0.44.0

Open the chart page →

3,358
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
golang.org/x/sys@v0.20.0
0.44.0
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
golang.org/x/sys@v0.20.0
0.44.0

Open the chart page →

2,336
predicatep2p-avs0.1.41 of 1See more

predicate p2p-avs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

893
p4p40.1.03 of 7See more

p4 p4 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/sys@v0.5.0
0.44.0
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/sys@v0.38.0
0.44.0
library/mysql:8b3b90af2a655
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

27,870
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

19,767
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

3,626
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-andromeda1.0.01 of 3See more

pages pages-andromeda 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespagesbadami1.0.01 of 3See more

pages pagesbadami 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-blackburn1.0.01 of 3See more

pages pages-blackburn 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-botes1.0.01 of 3See more

pages pages-botes 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-brian1.0.01 of 3See more

pages pages-brian 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-buckll1.0.01 of 3See more

pages pages-buckll 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-camden1.0.01 of 3See more

pages pages-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-camden7711.0.01 of 3See more

pages pages-camden771 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-diarmuidkeane1.0.01 of 3See more

pages pages-diarmuidkeane 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-draco1.0.01 of 3See more

pages pages-draco 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-ellora1.0.01 of 3See more

pages pages-ellora 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-finchley1.0.01 of 3See more

pages pages-finchley 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-fornax1.0.01 of 3See more

pages pages-fornax 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-harsh1.0.01 of 3See more

pages pages-harsh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespagesk1.0.01 of 3See more

pages pagesk 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-microservice-ashim1.0.01 of 3See more

pages pages-microservice-ashim 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-mihai1.0.01 of 3See more

pages pages-mihai 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-nivesh1.0.01 of 3See more

pages pages-nivesh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespagessandeepgudu1.0.01 of 3See more

pages pagessandeepgudu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-shubhanker1.0.01 of 3See more

pages pages-shubhanker 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-ssharma09091.0.01 of 3See more

pages pages-ssharma0909 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-sucharitha1.0.01 of 3See more

pages pages-sucharitha 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-sudhir1.0.01 of 3See more

pages pages-sudhir 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-sushi1.0.01 of 3See more

pages pages-sushi 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-vasanth58141.0.01 of 3See more

pages pages-vasanth5814 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
pagespages-vjp1.0.01 of 3See more

pages pages-vjp 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,279
paperclippaperclip-helmVerified publisher0.1.01 of 3See more

paperclip paperclip-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

494
Parpar0.1.01 of 1See more

Par par 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/jmcgrath207/par:v0.1.09977511cb142
golang.org/x/sys@v0.8.0
0.44.0

Open the chart page →

890
parcaparca4.19.02 of 2See more

parca parca 4.19.0

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/sys@v0.13.0
0.44.0
ghcr.io/parca-dev/parca-agent:v0.28.06d6794f45f3e
golang.org/x/sys@v0.15.0
0.44.0

Open the chart page →

3,384
parcaparca-chart0.1.01 of 1See more

parca parca-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

1,995
parcaparca-rr0.1.02 of 2See more

parca parca-rr 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.24.23776500fde82
golang.org/x/sys@v0.33.0
0.44.0
ghcr.io/parca-dev/parca-agent:v0.42.0adc0eeb4dd05
golang.org/x/sys@v0.35.0
0.44.0

Open the chart page →

2,405
parcial-1parcial-1-chart1.0.02 of 5See more

parcial-1 parcial-1-chart 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
golang.org/x/sys@v0.35.0
0.44.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.1e63459ec5965
golang.org/x/sys@v0.34.0
0.44.0

Open the chart page →

3,887

Container images carrying it

4,392 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
layer5/meshery-istio:stable-latestfde47c141ec6
golang.org/x/sys@v0.30.0
0.44.0
1
layer5/meshery-kuma:stable-latest9d25f029a8a2
golang.org/x/sys@v0.13.0
0.44.0
1
layer5/meshery-linkerd:stable-latestb99c73bac1f5
golang.org/x/sys@v0.15.0
0.44.0
1
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
golang.org/x/sys@v0.7.0
0.44.0
1
layer5/meshery-nsm:stable-latestebd6a8faf21f
golang.org/x/sys@v0.0.0-20201009025420-dfb3f7c4e634
0.44.0
1
layer5/meshery-operator:stable-latest6f58a28fe422
golang.org/x/sys@v0.28.0
0.44.0
1
layer5/meshery-osm:stable-latestec898e5786c6
golang.org/x/sys@v0.4.0
0.44.0
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
golang.org/x/sys@v0.7.0
0.44.0
1
lbenicio/kubernetes-dashboard-api:1.14.951d3d30206c8
golang.org/x/sys@v0.37.0
0.44.0
1
lbenicio/kubernetes-dashboard-auth:1.4.1378c63efd9dcd
golang.org/x/sys@v0.37.0
0.44.0
1
lbenicio/kubernetes-dashboard-scraper:1.2.69202e96ad403
golang.org/x/sys@v0.37.0
0.44.0
1
lbenicio/kubernetes-dashboard-web:1.7.142797937bc2a5
golang.org/x/sys@v0.37.0
0.44.0
1
leonardomulticloud/webhook:v1.0.0d119918900e8
golang.org/x/sys@v0.21.0
0.44.0
1
library/caddy:2.660fb54d36b4b
golang.org/x/sys@v0.5.0
0.44.0
1
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/sys@v0.0.0-20200615200032-f1bc736245b1
0.44.0
1
library/caddy:2.11.2-alpine834468128c76
golang.org/x/sys@v0.41.0
0.44.0
1
library/caddy:2.4.5874405536b3e
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
0.44.0
1
library/caddy:2.9-alpineb4e3952384eb
golang.org/x/sys@v0.28.0
0.44.0
1
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.44.0
1
library/cassandra:4.0093ee8ee5eb2
golang.org/x/sys@v0.1.0
0.44.0
1
library/chronograf:1.9.496d8a3f65a4f
golang.org/x/sys@v0.0.0-20210503080704-8803ae5d1324
0.44.0
1
library/docker:24.0.2-dind1d148deae16a
golang.org/x/sys@v0.7.0
0.44.0
1
library/docker:28.5.2-dind2a232a42256f
golang.org/x/sys@v0.37.0
0.44.0
1
library/docker:20.10.21-dind3153fa63f546
golang.org/x/sys@v0.0.0-20220825204002-c680a09ffe64
0.44.0
1
library/docker:27-cli851f91d24121
golang.org/x/sys@v0.30.0
0.44.0
1
library/docker:27-dindaa3df78ecf32
golang.org/x/sys@v0.26.0
0.44.0
1
library/docker:23.0.6-dindafa5d5134900
golang.org/x/sys@v0.10.0
0.44.0
1
library/docker:23.0.1-dindd9a0fd8bdd15
golang.org/x/sys@v0.3.0
0.44.0
1
library/docker:26.1-dinddd43b430341a
golang.org/x/sys@v0.21.0
0.44.0
1
library/ghost:6.37.01ef2e532ca4d
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
1
library/ghost:6.25.12654b1e90413
golang.org/x/sys@v0.1.0
0.44.0
1
library/ghost:6.41.129773d6be407
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
1
library/ghost:6.39.0-alpine77196da4b0df
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
1
library/ghost:5.79.083f7bf209844
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
golang.org/x/sys@v0.1.0
0.44.0
1
library/ghost:6.63.0e05bc1169fb2
golang.org/x/sys@v0.1.0
0.44.0
1
library/influxdb:2.8571eb4514977
golang.org/x/sys@v0.33.0
0.44.0
1
library/influxdb:1.12.3-meta8812029260b5
golang.org/x/sys@v0.38.0
0.44.0
1
library/influxdb:2.7.4-alpinea10d46445d68
golang.org/x/sys@v0.7.0
0.44.0
1
library/influxdb:1.12.3-datab0f9fc41ed79
golang.org/x/sys@v0.38.0
0.44.0
1
library/influxdb:2.0.8ba10ac9ba17a
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
1
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/sys@v0.0.0-20220319134239-a9b59b0215f8
0.44.0
1
library/influxdb:latestf75e48af0598
golang.org/x/sys@v0.41.0
0.44.0
1
library/kapacitor:1.6.37232f6388a4d
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
1
library/mariadb:10.7.307e06f2e7ae9
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
0.44.0
1
library/mariadb:10.11.21c33370a599c
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
0.44.0
1
library/mariadb:10.422edfe1c7834
golang.org/x/sys@v0.13.0
0.44.0
1
library/mariadb:112439dcd7d140
golang.org/x/sys@v0.1.0
0.44.0
1
library/mariadb:10.8.2-focal490f01279be1
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
0.44.0
1
library/mariadb:12.0.25b6a1eac15b8
golang.org/x/sys@v0.13.0
0.44.0
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.