StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,853
of 17,821 indexed, latest versions
Container images
4,415
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,853 of 17,821 indexed charts deploy, on 4,415 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+272 more0.44.04,415
OSV records
GO-2026-5024

Charts affected

3,853 by stars
ChartLatestAffected imagesRadar Score
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
golang.org/x/sys@v0.9.0
0.44.0

Open the chart page →

2,485
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0

Open the chart page →

3,700
zoo-project-druzoo-projectOfficialVerified publisher0.10.42 of 6See more

zoo-project-dru zoo-project 0.10.4

2 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:18.4-alpine3.249a8afca54e78
golang.org/x/sys@v0.1.0
0.44.0
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

7,966

Container images carrying it

4,415 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mattermost/mattermost-push-proxy:6.3.045c53061c74e
golang.org/x/sys@v0.19.0
0.44.0
1
mattermost/rtcd:latesta27058aaa53a
golang.org/x/sys@v0.41.0
0.44.0
1
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/sys@v0.5.0
0.44.0
1
mavrick1/kubestellar-b:latest45ca0429a1d4
golang.org/x/sys@v0.21.0
0.44.0
1
maxrocketinternet/k8s-event-logger:2.70234bdec4626
golang.org/x/sys@v0.31.0
0.44.0
1
maxrocketinternet/k8s-event-logger:2.111224534789d
golang.org/x/sys@v0.6.0
0.44.0
1
mcp/kubernetes:latest5ffbf7f0a8aa
golang.org/x/sys@v0.31.0
0.44.0
1
megaease/easegress:latestfad1c7452958
golang.org/x/sys@v0.39.0
0.44.0
1
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
golang.org/x/sys@v0.5.0
0.44.0
1
mesosphere/dex-controller:v0.16.11b2dd9c0b0fc
golang.org/x/sys@v0.20.0
0.44.0
1
mesosphere/dex-k8s-authenticator:v1.4.1-d2iqf3d9982cc2fd
golang.org/x/sys@v0.10.0
0.44.0
1
mesosphere/karma:v0.55-d2iq-proxy4693bb4e0814
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
0.44.0
1
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
1
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
1
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
1
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.44.0
1
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
golang.org/x/sys@v0.0.0-20210113181707-4bcb84eeeb78
0.44.0
1
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
golang.org/x/sys@v0.0.0-20210113181707-4bcb84eeeb78
0.44.0
1
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
golang.org/x/sys@v0.0.0-20210112080510-489259a85091
0.44.0
1
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
golang.org/x/sys@v0.0.0-20191120155948-bd437916bb0e
0.44.0
1
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
golang.org/x/sys@v0.0.0-20200113162924-86b910548bc1
0.44.0
1
mesosphere/kubefed:proxyurl4fd8889195fe
golang.org/x/sys@v0.0.0-20201015000850-e3ed0017c211
0.44.0
1
mesosphere/traefik-forward-auth:3.1.05456581d7b76
golang.org/x/sys@v0.0.0-20190826190057-c7b8b68b1456
0.44.0
1
metacontrollerio/metacontroller:v2.1.10336993b88e4
golang.org/x/sys@v0.0.0-20210817190340-bfb29a6856f2
0.44.0
1
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
0.44.0
1
metacubex/mihomo:v1.19.29e1d7dadaa936
golang.org/x/sys@v0.30.0
0.44.0
1
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
golang.org/x/sys@v0.0.0-20190813064441-fde4db37ae7a
0.44.0
1
mikefarah/yq:4.45.12c100efaca06
golang.org/x/sys@v0.28.0
0.44.0
1
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
golang.org/x/sys@v0.26.0
0.44.0
1
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.44.0
1
milvusdb/etcd:3.5.25-r1fededb2f2d63
golang.org/x/sys@v0.31.0
0.44.0
1
milvusdb/milvus:v2.2.13a3a55e1c1497
golang.org/x/sys@v0.8.0
0.44.0
1
milvusdb/milvus-config-tool:v0.1.12212dfb61401
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
1
mindsdb/mindsdb:latest163011c09299
golang.org/x/sys@v0.30.0
0.44.0
1
miniflux/miniflux:2.2.18a3ca6bbc1f74
golang.org/x/sys@v0.42.0
0.44.0
1
miniflux/miniflux:2.0.36e2fb990dae74
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
golang.org/x/sys@v0.0.0-20210119212857-b64e53b001e4
0.44.0
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
golang.org/x/sys@v0.0.0-20220412211240-33da011f77ad
0.44.0
1
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/sys@v0.0.0-20200212091648-12a6c2dcc1e4
0.44.0
1
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/sys@v0.0.0-20201013132646-2da7054afaeb
0.44.0
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
golang.org/x/sys@v0.0.0-20211020174200-9d6173849985
0.44.0
1
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
golang.org/x/sys@v0.20.0
0.44.0
1
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
golang.org/x/sys@v0.16.0
0.44.0
1
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/sys@v0.0.0-20200915084602-288bc346aa39
0.44.0
1
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/sys@v0.0.0-20190922100055-0a153f010e69
0.44.0
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
golang.org/x/sys@v0.4.0
0.44.0
1
minio/operator:v5.0.9170b154d2c61
golang.org/x/sys@v0.10.0
0.44.0
1
minio/operator:v4.1.02adc5be088f5
golang.org/x/sys@v0.0.0-20210420072515-93ed5bcd2bfe
0.44.0
1
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
golang.org/x/sys@v0.0.0-20190215142949-d0b11bdaac8a
0.44.0
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
golang.org/x/sys@v0.0.0-20200113162924-86b910548bc1
0.44.0
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.