StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,765
of 17,797 indexed, latest versions
Container images
4,328
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,765 of 17,797 indexed charts deploy, on 4,328 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+268 more0.44.04,328
OSV records
GO-2026-5024

Charts affected

3,765 by stars
ChartLatestAffected imagesRadar Score
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/sys@v0.4.0
0.44.0

Open the chart page →

1,670
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/sys@v0.0.0-20200331124033-c3d80250170d
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
0.44.0

Open the chart page →

12,537
miniosolidchartsVerified publisher0.5.01 of 1See more

minio solidcharts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
golang.org/x/sys@v0.32.0
0.44.0

Open the chart page →

1,070
forecastlestakaterVerified publisher2.1.11 of 1See more

forecastle stakater 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
stakater/forecastle:v2.0.2382cd9572352
golang.org/x/sys@v0.41.0
0.44.0

Open the chart page →

711
ingressmonitorcontrollerstakaterVerified publisher2.2.131 of 1See more

ingressmonitorcontroller stakater 2.2.13

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

583
sn-platformstreamnative1.11.446 of 9See more

sn-platform streamnative 1.11.44

6 of the 9 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
golang.org/x/sys@v0.0.0-20221010170243-090e33056c14
0.44.0
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/sys@v0.6.0
0.44.0
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/sys@v0.0.0-20220207234003-57398862261d
0.44.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/sys@v0.3.0
0.44.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/sys@v0.2.0
0.44.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

15,620
pocketbasetechwolf12Verified publisher0.29.31 of 1See more

pocketbase techwolf12 0.29.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/sys@v0.35.0
0.44.0

Open the chart page →

1,448
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

10,046
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.263 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

3 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
golang.org/x/sys@v0.2.0
0.44.0
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
golang.org/x/sys@v0.2.0
0.44.0
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
golang.org/x/sys@v0.2.0
0.44.0

Open the chart page →

14,578
feedbacksystemthm-mni-iiVerified publisher0.47.16 of 10See more

feedbacksystem thm-mni-ii 0.47.1

6 of the 10 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/sys@v0.15.0
0.44.0
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/sys@v0.11.0
0.44.0
bitnamilegacy/mysql:8.0.35-debian-11-r2be03e8ea6129
golang.org/x/sys@v0.2.0
0.44.0
library/docker:20.10.21-dind3153fa63f546
golang.org/x/sys@v0.0.0-20220825204002-c680a09ffe64
0.44.0
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

28,692
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
golang.org/x/sys@v0.32.0
0.44.0

Open the chart page →

1,503
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
0.44.0

Open the chart page →

4,145
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/sys@v0.0.0-20200217220822-9197077df867
0.44.0
library/traefik:v2.57d5a6ae66572
golang.org/x/sys@v0.0.0-20210817190340-bfb29a6856f2
0.44.0
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/sys@v0.0.0-20220704084225-05e143d24a9e
0.44.0

Open the chart page →

9,271
k8s-ttl-controllertwin0.4.01 of 1See more

k8s-ttl-controller twin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

471
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/sys@v0.9.0
0.44.0
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

10,382
crossplaneupbound-stable2.4.1-up.11 of 5See more

crossplane upbound-stable 2.4.1-up.1

1 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

1,667
uptraceuptrace2.0.21 of 2See more

uptrace uptrace 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
uptrace/uptrace:2.0.234a02c3b2d12
golang.org/x/sys@v0.34.0
0.44.0

Open the chart page →

1,627
valkey-operatorvalkeyVerified publisher0.6.01 of 1See more

valkey-operator valkey 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/valkey-io/valkey-operator:v0.6.052a0f1ed0c03
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

141
vaultvaultVerified publisher1.22.02 of 4See more

vault vault 1.22.0

2 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
alpine/k8s:1.35.5d870622d0040
golang.org/x/sys@v0.42.0
0.44.0
prom/statsd-exporter:v0.29.0632f70580492
golang.org/x/sys@v0.39.0
0.44.0

Open the chart page →

4,261
vouchvouchVerified publisher3.2.01 of 1See more

vouch vouch 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/sys@v0.4.0
0.44.0

Open the chart page →

1,035
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/sys@v0.11.0
0.44.0

Open the chart page →

1,350
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0

Open the chart page →

2,245
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

1,000
wallarm-ingresswallarmVerified publisher5.3.10-12 of 2See more

wallarm-ingress wallarm 5.3.10-1

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
golang.org/x/sys@v0.29.0
0.44.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/sys@v0.24.0
0.44.0

Open the chart page →

1,301
wallarm-sidecarwallarmOfficialVerified publisher6.13.11 of 3See more

wallarm-sidecar wallarm 6.13.1

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/sys@v0.18.0
0.44.0

Open the chart page →

965
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
golang.org/x/sys@v0.15.0
0.44.0

Open the chart page →

3,485
argo-cdwenerme10.9.22See more

argo-cd wenerme 10.9.2

2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/sys@v0.41.0
0.44.0
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
0.44.0

Open the chart page →

6,086
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:15.186eb0add3b77c
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

8,708
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/sys@v0.0.0-20220330033206-e17cdc41300f
0.44.0
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/sys@v0.0.0-20220502124256-b6088ccd6cba
0.44.0
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/sys@v0.0.0-20220502124256-b6088ccd6cba
0.44.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/sys@v0.0.0-20220502124256-b6088ccd6cba
0.44.0

Open the chart page →

10,047
windmillwindmill4.0.2641 of 3See more

windmill windmill 4.0.264

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

1,667
buildkitdwiremindVerified publisher0.33.01 of 1See more

buildkitd wiremind 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/sys@v0.35.0
0.44.0

Open the chart page →

1,155
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
0.44.0

Open the chart page →

4,714
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/sys@v0.0.0-20220503163025-988cb79eb6c6
0.44.0

Open the chart page →

4,050
yet-another-cloudwatch-exporteryet-another-cloudwatch-exporter0.38.01 of 1See more

yet-another-cloudwatch-exporter yet-another-cloudwatch-exporter 0.38.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
golang.org/x/sys@v0.19.0
0.44.0

Open the chart page →

923
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

4,019
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

829
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

1,852
agentareaagentareaVerified publisher0.0.185 of 16See more

agentarea agentarea 0.0.18

5 of the 16 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
golang.org/x/sys@v0.1.0
0.44.0
library/postgres:alpined3e1620b530c
golang.org/x/sys@v0.1.0
0.44.0
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/sys@v0.23.0
0.44.0
temporalio/auto-setup:1.29.15b3502a3b685
golang.org/x/sys@v0.32.0
0.44.0
temporalio/ui:2.39.0b768f87f18b5
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

15,048
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.261See more

akeyless-api-gateway akeyless-services-helm 1.62.26

1 container image this version deploys carries CVE-2026-39824.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
golang.org/x/sys@v0.41.0
0.44.0

Open the chart page →

alertmanager-discordalertmanagerdiscordVerified publisher0.3.21 of 1See more

alertmanager-discord alertmanagerdiscord 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
speckle/alertmanager-discord:latestf6221ff308e9
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

420
clearml-servingallegroaiVerified publisher1.6.26 of 9See more

clearml-serving allegroai 1.6.2

6 of the 9 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
golang.org/x/sys@v0.2.0
0.44.0
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/sys@v0.3.0
0.44.0
jimmidyson/configmap-reload:v0.8.05af9d3041d12
golang.org/x/sys@v0.0.0-20221010170243-090e33056c14
0.44.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/sys@v0.3.0
0.44.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/sys@v0.3.0
0.44.0

Open the chart page →

17,898
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
0.44.0

Open the chart page →

4,998
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
0.44.0

Open the chart page →

8,395
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0

Open the chart page →

3,120
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/sys@v0.0.0-20220307203707-22a9840ba4d7
0.44.0

Open the chart page →

2,173
cloudflare-operatorankra-chartsVerified publisher0.2.01 of 1See more

cloudflare-operator ankra-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
adyanth/cloudflare-operatordigest-pinned6b168dc237d5
golang.org/x/sys@v0.32.0
0.44.0

Open the chart page →

500
upcloud-csiankra-chartsVerified publisher0.4.08 of 8See more

upcloud-csi ankra-charts 0.4.0

8 of the 8 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
golang.org/x/sys@v0.35.0
0.44.0
ghcr.io/upcloudltd/upcloud-csidigest-pinned5af91c663788
golang.org/x/sys@v0.39.0
0.44.0
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0

Open the chart page →

14,973
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

1,150
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/sys@v0.18.0
0.44.0

Open the chart page →

3,403

Container images carrying it

4,328 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pubeldev/prusa_exporter:2.0.01091665a020a
golang.org/x/sys@v0.37.0
0.44.0
1
pulumi/pulumi-kubernetes-operator:v2.5.17dace4491358
golang.org/x/sys@v0.40.0
0.44.0
1
pysga1996/redis:latest3af6d0c7db19
golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd
0.44.0
1
qichenxu4pd/mysqlweb:1.2d758d41d9c6b
golang.org/x/sys@v0.13.0
0.44.0
1
qmcgaw/gluetun:v3.41.11a5bf4b4820a
golang.org/x/sys@v0.38.0
0.44.0
1
qmcgaw/gluetun:v3.40.02b42bfa04675
golang.org/x/sys@v0.27.0
0.44.0
1
qonstrukt/php:8.4-v8-apache089af7925aa1
golang.org/x/sys@v0.0.0-20200724161237-0e2f3a69832c
0.44.0
1
qoveryrd/digital-mobius:0.1.4b30a9398a83c
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
0.44.0
1
questdb/questdb:10.0.167eaed863ebb
golang.org/x/sys@v0.1.0
0.44.0
1
quiq/docker-registry-ui:0.9.491281da47036
golang.org/x/sys@v0.0.0-20211103235746-7861aae1554b
0.44.0
1
qumine/ingress-controller:v0.8.5f2c8a2148381
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
1
qumine/minecraft-server:v0.1.15c0b650d51132
golang.org/x/sys@v0.0.0-20220909162455-aba9fc2a8ff2
0.44.0
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
0.44.0
1
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
golang.org/x/sys@v0.42.0
0.44.0
1
rabbitmqoperator/cluster-operator:2.6.08651dd3cec51
golang.org/x/sys@v0.14.0
0.44.0
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
1
rancher/hardened-calico:v3.13.36d2cd61a338b
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
0.44.0
1
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
0.44.0
1
rancher/hardened-cni-plugins:v0.9.1-build20210414be3c1d469bf7
golang.org/x/sys@v0.0.0-20201117170446-d9b008d0a637
0.44.0
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
0.44.0
1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
0.44.0
1
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
0.44.0
1
rancher/harvester-csi-driver:v0.2.9f9099b5ef8cb
golang.org/x/sys@v0.40.0
0.44.0
1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/sys@v0.6.0
0.44.0
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/sys@v0.0.0-20220412211240-33da011f77ad
0.44.0
1
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
1
rancher/kube-webhook-certgen:v1.14.5-hardened26bb869baf40b
golang.org/x/sys@v0.42.0
0.44.0
1
rancher/local-path-provisioner:v0.0.361eba82e9c386
golang.org/x/sys@v0.31.0
0.44.0
1
rancher/local-path-provisioner:v0.0.329289da488b07
golang.org/x/sys@v0.31.0
0.44.0
1
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/sys@v0.22.0
0.44.0
1
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
0.44.0
1
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
0.44.0
1
rancher/mirrored-cloud-provider-vsphere:v1.31.1febfd0517838
golang.org/x/sys@v0.21.0
0.44.0
1
rancher/mirrored-longhornio-csi-attacher:v4.11.0-20260428fe417c28a6b8
golang.org/x/sys@v0.42.0
0.44.0
1
rancher/mirrored-longhornio-csi-node-driver-registrar:v2.16.0-20260428e82a8c8f800d
golang.org/x/sys@v0.41.0
0.44.0
1
rancher/mirrored-longhornio-csi-provisioner:v5.3.0-202604289e519a21a77c
golang.org/x/sys@v0.39.0
0.44.0
1
rancher/mirrored-longhornio-csi-resizer:v2.1.0-2026042841cb674d1154
golang.org/x/sys@v0.42.0
0.44.0
1
rancher/mirrored-longhornio-csi-snapshotter:v8.5.0-202604281975fac3890f
golang.org/x/sys@v0.42.0
0.44.0
1
rancher/nginx-ingress-controller:v1.14.5-hardened26cbc1e932b5b
golang.org/x/sys@v0.42.0
0.44.0
1
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
golang.org/x/sys@v0.0.0-20210309074719-68d13333faf2
0.44.0
1
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
golang.org/x/sys@v0.0.0-20210309074719-68d13333faf2
0.44.0
1
rancher/system-upgrade-controller:v0.19.234fa058fe453
golang.org/x/sys@v0.42.0
0.44.0
1
rancher/system-upgrade-controller:v0.18.09813f85653c8
golang.org/x/sys@v0.36.0
0.44.0
1
ravendb/ravendb-operator:2.1.0511050205ac5
golang.org/x/sys@v0.42.0
0.44.0
1
rayselfs/aws-ec2-runtime-checker:v0.1.5562e5b2f81ce
golang.org/x/sys@v0.38.0
0.44.0
1
rclone/rclone:1.63.008e1af3c8814
golang.org/x/sys@v0.7.0
0.44.0
1
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/sys@v0.0.0-20210820121016-41cdb8703e55
0.44.0
1
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/sys@v0.0.0-20210423185535-09eb48e85fd7
0.44.0
1
reaper99/recipya:v1.2.27f7ec3aeb88c
golang.org/x/sys@v0.22.0
0.44.0
1
redislabs/operator:8.0.18-119078e713bb6a
golang.org/x/sys@v0.42.0
0.44.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.