StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,779
of 17,787 indexed, latest versions
Container images
4,354
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,779 of 17,787 indexed charts deploy, on 4,354 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+268 more0.44.04,354
OSV records
GO-2026-5024

Charts affected

3,779 by stars
ChartLatestAffected imagesRadar Score
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

4,858
ethereumchronicleVerified publisher0.3.11 of 1See more

ethereum chronicle 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/sys@v0.36.0
0.44.0

Open the chart page →

1,350
ethereum-metrics-exporterchronicleVerified publisher0.1.41 of 1See more

ethereum-metrics-exporter chronicle 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
samcm/ethereum-metrics-exporter:0.29.291a2d9a015c1
golang.org/x/sys@v0.36.0
0.44.0

Open the chart page →

684
goferchronicleVerified publisher0.4.41 of 1See more

gofer chronicle 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/gofer:0.613915d2e41e04
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

721
mantlechronicleVerified publisher0.1.31 of 1See more

mantle chronicle 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/sys@v0.8.0
0.44.0

Open the chart page →

1,934
sith-exporterschronicleVerified publisher0.2.41 of 1See more

sith-exporters chronicle 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/oracles-updates-exporter:0.0.4992d0e793af6
golang.org/x/sys@v0.11.0
0.44.0

Open the chart page →

996
spirechronicleVerified publisher0.3.61 of 1See more

spire chronicle 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

1,521
tor-proxychronicleVerified publisher0.1.01 of 1See more

tor-proxy chronicle 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
btcpayserver/tor:0.4.8.10e9585b68dc6b
golang.org/x/sys@v0.0.0-20210426230700-d19ff857e887
0.44.0

Open the chart page →

3,051
zksyncchronicleVerified publisher0.1.01 of 2See more

zksync chronicle 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

5,550
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/sys@v0.0.0-20191010194322-b09406accb47
0.44.0

Open the chart page →

3,595
ciliumcilium21.20.12 of 3See more

cilium cilium2 1.20.1

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
golang.org/x/sys@v0.35.0
0.44.0
quay.io/cilium/operator-generic:v1.20.16c3885fc7b62
golang.org/x/sys@v0.30.0
0.44.0

Open the chart page →

1,786
tetragoncilium21.7.11 of 3See more

tetragon cilium2 1.7.1

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
golang.org/x/sys@v0.30.0
0.44.0

Open the chart page →

219
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/chekrdigest-pinnedf299baf467b5
golang.org/x/sys@v0.0.0-20210823070655-63515b42dcdf
0.44.0

Open the chart page →

3,470
clairclair-helmVerified publisher0.12.02 of 3See more

clair clair-helm 0.12.0

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
golang.org/x/sys@v0.1.0
0.44.0
quay.io/projectquay/clair:4.9.023329c3368e4
golang.org/x/sys@v0.39.0
0.44.0

Open the chart page →

1,618
calico-cniclastixVerified publisher3.28.13 of 3See more

calico-cni clastix 3.28.1

3 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
calico/cni:v3.28.1e486870cfde8
golang.org/x/sys@v0.0.0-20210809222454-d867a43fc93e
0.44.0
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/sys@v0.19.0
0.44.0
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/sys@v0.19.0
0.44.0

Open the chart page →

3,050
capi-kamaji-vsphere-fullclastixVerified publisher1.0.19 of 9See more

capi-kamaji-vsphere-full clastix 1.0.1

9 of the 9 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
golang.org/x/sys@v0.31.0
0.44.0
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/sys@v0.28.0
0.44.0
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/sys@v0.28.0
0.44.0
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/sys@v0.28.0
0.44.0
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/sys@v0.29.0
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/sys@v0.15.0
0.44.0
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/sys@v0.29.0
0.44.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/sys@v0.28.0
0.44.0
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

5,933
capsule-rancher-addonclastixVerified publisher0.1.15 of 5See more

capsule-rancher-addon clastix 0.1.1

5 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/sys@v0.3.0
0.44.0
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/sys@v0.4.0
0.44.0
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/sys@v0.4.0
0.44.0
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/sys@v0.4.0
0.44.0
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/sys@v0.4.0
0.44.0

Open the chart page →

7,104
kamajiclastixVerified publisher0.0.0+latest2 of 4See more

kamaji clastix 0.0.0+latest

2 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.44.0
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

4,630
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

2,761
kamaji-etcdclastixVerified publisher0.17.03 of 4See more

kamaji-etcd clastix 0.17.0

3 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
golang.org/x/sys@v0.17.0
0.44.0
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.44.0
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

12,021
local-path-provisionerclastixVerified publisher0.0.301 of 1See more

local-path-provisioner clastix 0.0.30

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/sys@v0.22.0
0.44.0

Open the chart page →

1,208
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/sys@v0.0.0-20210330210617-4fbd30eecc44
0.44.0
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e
0.44.0
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0

Open the chart page →

7,386
cloudflared-tunnelclouddrove0.1.41 of 1See more

cloudflared-tunnel clouddrove 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

1,750
kube-acp-stackcloudentity2.28.03 of 7See more

kube-acp-stack cloudentity 2.28.0

3 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
golang.org/x/sys@v0.21.0
0.44.0
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/sys@v0.28.0
0.44.0
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
0.44.0

Open the chart page →

20,936
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0

Open the chart page →

18,040
cloudflare-ddns-updatecloudflare-ddns-update0.1.21 of 1See more

cloudflare-ddns-update cloudflare-ddns-update 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/sys@v0.20.0
0.44.0

Open the chart page →

1,338
cloudflare-tunnel-ingress-controllercloudflare-tunnel-ingress-controller0.2.31 of 1See more

cloudflare-tunnel-ingress-controller cloudflare-tunnel-ingress-controller 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/oliverbaehler/cloudflare-tunnel-ingress-controller:0.2.30aec31e36d95
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

438
cloudfront-tenant-operatorcloudfront-tenant-operatorVerified publisher0.3.01 of 1See more

cloudfront-tenant-operator cloudfront-tenant-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

269
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/sys@v0.10.0
0.44.0

Open the chart page →

25,152
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/sys@v0.0.0-20210403161142-5e06dd20ab57
0.44.0

Open the chart page →

6,696
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0

Open the chart page →

6,921
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
0.44.0

Open the chart page →

2,814
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
robotshop/rs-mongodb:latest119b545823cd
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
0.44.0

Open the chart page →

29,594
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad5 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

5 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/sys@v0.34.0
0.44.0
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

18,256
cloud-provider-kubevirtcloud-provider-kubevirtVerified publisher0.2.01 of 1See more

cloud-provider-kubevirt cloud-provider-kubevirt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

656
k8s-monitoring-appcloudscriptVerified publisher1.0.01 of 1See more

k8s-monitoring-app cloudscript 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/k8s-monitoring-app:v0.0.25cab66a6b3574
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

1,294
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:18.3-alpine54451ecb8ab3
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

2,185
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/sys@v0.0.0-20210816074244-15123e1e1f71
0.44.0

Open the chart page →

3,136
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/sys@v0.11.0
0.44.0

Open the chart page →

5,552
galaxy-cvmfs-csicloudve2.5.12 of 3See more

galaxy-cvmfs-csi cloudve 2.5.1

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
golang.org/x/sys@v0.15.0
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/sys@v0.15.0
0.44.0

Open the chart page →

1,501
galaxy-depscloudve1.1.16 of 7See more

galaxy-deps cloudve 1.1.1

6 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/sys@v0.31.0
0.44.0
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/sys@v0.0.0-20220319134239-a9b59b0215f8
0.44.0
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/sys@v0.0.0-20220614162138-6c1b26c55098
0.44.0
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/sys@v0.28.0
0.44.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/sys@v0.7.0
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

10,543
galaxy-k8s-monitorcloudve0.1.11 of 1See more

galaxy-k8s-monitor cloudve 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
afgane/galaxy-k8s-monitor:latest457173db5640
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

313
galaxykubemancloudve2.10.14 of 7See more

galaxykubeman cloudve 2.10.1

4 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/sys@v0.0.0-20220412211240-33da011f77ad
0.44.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/sys@v0.7.0
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/sys@v0.6.0
0.44.0
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/sys@v0.0.0-20190924154521-2837fb4f24fe
0.44.0

Open the chart page →

16,117
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
0.44.0

Open the chart page →

14,285
openstack-cinder-csicloudve1.2.01 of 5See more

openstack-cinder-csi cloudve 1.2.0

1 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0

Open the chart page →

2,061
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
0.44.0

Open the chart page →

2,853
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
golang.org/x/sys@v0.30.0
0.44.0

Open the chart page →

5,994
argo-cdcluster-deploy0.3.22 of 3See more

argo-cd cluster-deploy 0.3.2

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
golang.org/x/sys@v0.31.0
0.44.0
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

3,733
argo-eventscluster-deploy0.1.01 of 1See more

argo-events cluster-deploy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

1,036
authentikcluster-deploy0.2.01 of 1See more

authentik cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

2,457

Container images carrying it

4,354 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/sys@v0.33.0
0.44.0
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/sys@v0.14.0
0.44.0
3
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/sys@v0.38.0
0.44.0
3
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
golang.org/x/sys@v0.31.0
0.44.0
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e
0.44.0
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/sys@v0.0.0-20201214095126-aec9a390925b
0.44.0
3
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/sys@v0.29.0
0.44.0
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/sys@v0.0.0-20210511113859-b0526f3d8744
0.44.0
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
golang.org/x/sys@v0.38.0
0.44.0
3
ethpandaops/tracoor:latestd8514b9f4c59
golang.org/x/sys@v0.33.0
0.44.0
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/sys@v0.0.0-20210806184541-e5e7981a1069
0.44.0
3
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/sys@v0.18.0
0.44.0
3
grafana/grafana:13.1.17cb8c64c4d57
golang.org/x/sys@v0.42.0
0.44.0
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/sys@v0.25.0
0.44.0
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/sys@v0.29.0
0.44.0
3
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/sys@v0.38.0
0.44.0
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/sys@v0.0.0-20210917161153-d61c044b1678
0.44.0
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/sys@v0.38.0
0.44.0
3
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/sys@v0.15.0
0.44.0
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/sys@v0.3.0
0.44.0
3
library/mysql:latest66aec17cd21a
golang.org/x/sys@v0.1.0
0.44.0
3
library/nats:2.10-alpineb83efabe3e7d
golang.org/x/sys@v0.32.0
0.44.0
3
library/postgres:14.13162a6ead070
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
0.44.0
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
golang.org/x/sys@v0.13.0
0.44.0
3
library/postgres:115d2aa4a7b5f9
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
0.44.0
3
library/postgres:14-alpine727876d27466
golang.org/x/sys@v0.1.0
0.44.0
3
library/redis:7.2.4-alpinec8bb255c3559
golang.org/x/sys@v0.13.0
0.44.0
3
migrate/migrate:latestcc4ad8e19d66
golang.org/x/sys@v0.38.0
0.44.0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/sys@v0.0.0-20210119212857-b64e53b001e4
0.44.0
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/sys@v0.0.0-20190215142949-d0b11bdaac8a
0.44.0
3
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/sys@v0.32.0
0.44.0
3
natsio/nats-box:0.19.7ffce8bd10338
golang.org/x/sys@v0.38.0
0.44.0
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
golang.org/x/sys@v0.12.0
0.44.0
3
neosmemo/memos:0.30.071a5b4738d1b
golang.org/x/sys@v0.43.0
0.44.0
3
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/sys@v0.15.0
0.44.0
3
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/sys@v0.28.0
0.44.0
3
prom/prometheus:v3.0.1565ee8650122
golang.org/x/sys@v0.26.0
0.44.0
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/sys@v0.0.0-20200602225109-6fdc65e7d980
0.44.0
3
prom/pushgateway:v1.3.18305a33fb80a
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
0.44.0
3
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/sys@v0.25.0
0.44.0
3
prom/statsd-exporter:v0.18.0d23aca343b86
golang.org/x/sys@v0.0.0-20200523222454-059865788121
0.44.0
3
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/sys@v0.31.0
0.44.0
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
golang.org/x/sys@v0.15.0
0.44.0
3
signoz/zookeeper:3.7.1fcc4a3288154
golang.org/x/sys@v0.2.0
0.44.0
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
0.44.0
3
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/sys@v0.18.0
0.44.0
3
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/sys@v0.18.0
0.44.0
3

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.