StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,817
of 17,813 indexed, latest versions
Container images
4,367
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,817 of 17,813 indexed charts deploy, on 4,367 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+271 more0.44.04,367
OSV records
GO-2026-5024

Charts affected

3,817 by stars
ChartLatestAffected imagesRadar Score
kamajiclastixVerified publisher0.0.0+latest2 of 4See more

kamaji clastix 0.0.0+latest

2 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.44.0
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

4,668
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

2,764
kamaji-etcdclastixVerified publisher0.18.03 of 4See more

kamaji-etcd clastix 0.18.0

3 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
golang.org/x/sys@v0.17.0
0.44.0
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.44.0
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

12,110
local-path-provisionerclastixVerified publisher0.0.301 of 1See more

local-path-provisioner clastix 0.0.30

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/sys@v0.22.0
0.44.0

Open the chart page →

1,209
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/sys@v0.0.0-20210330210617-4fbd30eecc44
0.44.0
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e
0.44.0
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0

Open the chart page →

7,416
cloudflared-tunnelclouddrove0.1.41 of 1See more

cloudflared-tunnel clouddrove 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

1,816
kube-acp-stackcloudentity2.28.03 of 7See more

kube-acp-stack cloudentity 2.28.0

3 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
golang.org/x/sys@v0.21.0
0.44.0
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/sys@v0.28.0
0.44.0
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
0.44.0

Open the chart page →

21,148
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
0.44.0

Open the chart page →

18,045
cloudflare-ddns-updatecloudflare-ddns-update0.1.21 of 1See more

cloudflare-ddns-update cloudflare-ddns-update 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/sys@v0.20.0
0.44.0

Open the chart page →

1,339
cloudflare-tunnel-ingress-controllercloudflare-tunnel-ingress-controller0.2.31 of 1See more

cloudflare-tunnel-ingress-controller cloudflare-tunnel-ingress-controller 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/oliverbaehler/cloudflare-tunnel-ingress-controller:0.2.30aec31e36d95
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

438
cloudfront-tenant-operatorcloudfront-tenant-operatorVerified publisher0.3.01 of 1See more

cloudfront-tenant-operator cloudfront-tenant-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

284
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/sys@v0.10.0
0.44.0

Open the chart page →

25,525
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/sys@v0.0.0-20210403161142-5e06dd20ab57
0.44.0

Open the chart page →

6,706
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0

Open the chart page →

6,931
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
0.44.0

Open the chart page →

2,819
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
robotshop/rs-mongodb:latest119b545823cd
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
0.44.0

Open the chart page →

29,653
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad5 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

5 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/sys@v0.34.0
0.44.0
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

18,459
cloud-provider-kubevirtcloud-provider-kubevirtVerified publisher0.2.01 of 1See more

cloud-provider-kubevirt cloud-provider-kubevirt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

670
k8s-monitoring-appcloudscriptVerified publisher1.0.01 of 1See more

k8s-monitoring-app cloudscript 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/k8s-monitoring-app:v0.0.25cab66a6b3574
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

1,296
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:18.3-alpine54451ecb8ab3
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

2,184
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/sys@v0.0.0-20210816074244-15123e1e1f71
0.44.0

Open the chart page →

3,144
galaxycloudve6.8.81See more

galaxy cloudve 6.8.8

1 container image this version deploys carries CVE-2026-39824.

Container imageDigestPackageFixed in
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/sys@v0.11.0
0.44.0

Open the chart page →

galaxy-cvmfs-csicloudve2.5.12 of 3See more

galaxy-cvmfs-csi cloudve 2.5.1

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
golang.org/x/sys@v0.15.0
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/sys@v0.15.0
0.44.0

Open the chart page →

1,515
galaxy-depscloudve1.1.16 of 7See more

galaxy-deps cloudve 1.1.1

6 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/sys@v0.31.0
0.44.0
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/sys@v0.0.0-20220319134239-a9b59b0215f8
0.44.0
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/sys@v0.0.0-20220614162138-6c1b26c55098
0.44.0
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/sys@v0.28.0
0.44.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/sys@v0.7.0
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

10,625
galaxy-k8s-monitorcloudve0.1.11 of 1See more

galaxy-k8s-monitor cloudve 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
afgane/galaxy-k8s-monitor:latest457173db5640
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

313
galaxykubemancloudve2.10.14 of 7See more

galaxykubeman cloudve 2.10.1

4 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/sys@v0.0.0-20220412211240-33da011f77ad
0.44.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/sys@v0.7.0
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/sys@v0.6.0
0.44.0
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/sys@v0.0.0-20190924154521-2837fb4f24fe
0.44.0

Open the chart page →

16,206
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
0.44.0

Open the chart page →

80,967
openstack-cinder-csicloudve1.2.01 of 5See more

openstack-cinder-csi cloudve 1.2.0

1 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0

Open the chart page →

2,069
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
0.44.0

Open the chart page →

2,854
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
golang.org/x/sys@v0.30.0
0.44.0

Open the chart page →

6,216
argo-cdcluster-deploy0.3.22 of 3See more

argo-cd cluster-deploy 0.3.2

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
golang.org/x/sys@v0.31.0
0.44.0
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

3,836
argo-eventscluster-deploy0.1.01 of 1See more

argo-events cluster-deploy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

1,160
authentikcluster-deploy0.2.01 of 1See more

authentik cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

2,553
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
golang.org/x/sys@v0.4.0
0.44.0

Open the chart page →

8,121
mla-external-secretscluster-deploy0.3.01 of 1See more

mla-external-secrets cluster-deploy 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v2.1.0ec40c3d9c48f
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

723
monitoringcluster-deploy0.3.09 of 11See more

monitoring cluster-deploy 0.3.0

9 of the 11 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/sys@v0.40.0
0.44.0
grafana/loki:3.6.73c8fd3570dd9
golang.org/x/sys@v0.38.0
0.44.0
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/sys@v0.38.0
0.44.0
prom/memcached-exporter:v0.15.592a6ad5a3d3e
golang.org/x/sys@v0.38.0
0.44.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.89.0cb4ac6a56555
golang.org/x/sys@v0.40.0
0.44.0
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/sys@v0.37.0
0.44.0
quay.io/prometheus/prometheus:v3.10.07571a304e67f
golang.org/x/sys@v0.41.0
0.44.0
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/sys@v0.37.0
0.44.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/sys@v0.39.0
0.44.0

Open the chart page →

8,296
clusterfactoryclusterfactory0.2.02 of 5See more

clusterfactory clusterfactory 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gitea/act_runner:0.3.1c2a169c5e998
golang.org/x/sys@v0.41.0
0.44.0
jenkins/jenkins:2.541.3-jdk21c4098086090c
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

7,243
gitea-jenkinsclusterfactory0.1.12 of 5See more

gitea-jenkins clusterfactory 0.1.1

2 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gitea/act_runner:latestb5c35d6bdbb9
golang.org/x/sys@v0.41.0
0.44.0
jenkins/jenkins:2.541.3-jdk21c4098086090c
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

7,032
cluster-monitor-agentcluster-monitor-agent0.10.21 of 1See more

cluster-monitor-agent cluster-monitor-agent 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-agent:0.10.26769c2275a43
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

475
cluster-monitor-servercluster-monitor-server0.10.21 of 1See more

cluster-monitor-server cluster-monitor-server 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

753
clusternet-controller-managerclusternet1.0.01 of 1See more

clusternet-controller-manager clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-controller-manager:v1.0.02ce077d3d02d
golang.org/x/sys@v0.34.0
0.44.0

Open the chart page →

1,556
cluster-octopuscluster-octopus1.0.01 of 1See more

cluster-octopus cluster-octopus 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
golang.org/x/sys@v0.10.0
0.44.0

Open the chart page →

1,040
d2-prometheus-exportercmacraeVerified publisher0.1.01 of 1See more

d2-prometheus-exporter cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
golang.org/x/sys@v0.0.0-20200615200032-f1bc736245b1
0.44.0

Open the chart page →

1,299
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
0.44.0

Open the chart page →

2,090
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
0.44.0

Open the chart page →

2,204
storage-local-pathcnapVerified publisher1.0.11 of 1See more

storage-local-path cnap 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.3534ff0847cc47
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

754
storage-piraeuscnapVerified publisher1.0.11 of 1See more

storage-piraeus cnap 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/piraeusdatastore/piraeus-operator:v2.10.5dd68a66332de
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

334
door-agentcnoVerified publisher3.0.1511 of 15See more

door-agent cno 3.0.15

11 of the 15 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/sys@v0.31.0
0.44.0
beopenit/door-cd-operator:v3.0.4d3999cb8d026
golang.org/x/sys@v0.14.0
0.44.0
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/sys@v0.13.0
0.44.0
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/sys@v0.5.0
0.44.0
doorcloud/apim-operator:v3.0.44e6ef8d72c3e
golang.org/x/sys@v0.24.0
0.44.0
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/sys@v0.0.0-20191120155948-bd437916bb0e
0.44.0
library/docker:27-cli851f91d24121
golang.org/x/sys@v0.30.0
0.44.0
library/docker:27-dindaa3df78ecf32
golang.org/x/sys@v0.26.0
0.44.0
ghcr.io/projectcontour/contour:v1.30.0b12824d7eb58
golang.org/x/sys@v0.21.0
0.44.0
ghcr.io/projectcontour/contour:v1.33.0cd6e13fa882d
golang.org/x/sys@v0.35.0
0.44.0
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/sys@v0.0.0-20220728004956-3c1f35247d10
0.44.0

Open the chart page →

19,804
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

13,426
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.12 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:alpined3e1620b530c
golang.org/x/sys@v0.1.0
0.44.0
rcdelacruz/my-strapi-app:js-amd6438007f358355
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

5,157

Container images carrying it

4,367 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/dapr/injector:1.17.0-rc.37a2fd888ed5f
golang.org/x/sys@v0.40.0
0.44.0
1
ghcr.io/dapr/operator:1.17.0-rc.3d5cc61cbe735
golang.org/x/sys@v0.40.0
0.44.0
1
ghcr.io/dapr/placement:1.17.0-rc.3a237b43cd5c6
golang.org/x/sys@v0.40.0
0.44.0
1
ghcr.io/dapr/scheduler:1.17.0-rc.36c62e01e736b
golang.org/x/sys@v0.40.0
0.44.0
1
ghcr.io/dapr/sentry:1.17.0-rc.3bf79b03591e0
golang.org/x/sys@v0.40.0
0.44.0
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
golang.org/x/sys@v0.13.0
0.44.0
1
ghcr.io/davidkarlsen/flyway-operator:0.2.1366f60b461c0d
golang.org/x/sys@v0.32.0
0.44.0
1
ghcr.io/dcristobalhmad/kube-secrets-exporter:latesta9043737cb73
golang.org/x/sys@v0.18.0
0.44.0
1
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
golang.org/x/sys@v0.0.0-20210426230700-d19ff857e887
0.44.0
1
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.44.0
1
ghcr.io/defensia/agent:1.4.57e9d40ae44711
golang.org/x/sys@v0.38.0
0.44.0
1
ghcr.io/deliveryhero/field-exporter:v1.4.06b71ba4f9297
golang.org/x/sys@v0.21.0
0.44.0
1
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
golang.org/x/sys@v0.40.0
0.44.0
1
ghcr.io/depthmark/github-sts:0.0.31de580f136a9
golang.org/x/sys@v0.35.0
0.44.0
1
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
golang.org/x/sys@v0.38.0
0.44.0
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
golang.org/x/sys@v0.20.0
0.44.0
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
golang.org/x/sys@v0.7.0
0.44.0
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
golang.org/x/sys@v0.40.0
0.44.0
1
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e
0.44.0
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
0.44.0
1
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
golang.org/x/sys@v0.32.0
0.44.0
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/sys@v0.0.0-20220728004956-3c1f35247d10
0.44.0
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
golang.org/x/sys@v0.34.0
0.44.0
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/sys@v0.30.0
0.44.0
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/sys@v0.9.0
0.44.0
1
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
golang.org/x/sys@v0.40.0
0.44.0
1
ghcr.io/dirien/minecraft-exporter:0.24.061d89bf99ff7
golang.org/x/sys@v0.42.0
0.44.0
1
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
golang.org/x/sys@v0.31.0
0.44.0
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
0.44.0
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/sys@v0.8.0
0.44.0
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
golang.org/x/sys@v0.24.0
0.44.0
1
ghcr.io/dntosas/capi2argo-cluster-operator:v1.5.0fb8c6457ef6e
golang.org/x/sys@v0.33.0
0.44.0
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/sys@v0.0.0-20220310020820-b874c991c1a5
0.44.0
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/sys@v0.0.0-20211210111614-af8b64212486
0.44.0
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/sys@v0.0.0-20211109184856-51b60fd695b3
0.44.0
1
ghcr.io/doodlescheduling/saml-exporter:v0.5.03d5a99841bc2
golang.org/x/sys@v0.30.0
0.44.0
1
ghcr.io/douban/aliyun-exporter:mainb7c694331362
golang.org/x/sys@v0.9.0
0.44.0
1
ghcr.io/douban/qiniu-exporter:maind1da3bcfad7d
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
1
ghcr.io/douban/ucloud-exporter:mainb4bb8a9021a2
golang.org/x/sys@v0.0.0-20220731174439-a90be440212d
0.44.0
1
ghcr.io/douban/upyun-exporter:main6810900c9c4a
golang.org/x/sys@v0.40.0
0.44.0
1
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/sys@v0.20.0
0.44.0
1
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
golang.org/x/sys@v0.30.0
0.44.0
1
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/sys@v0.42.0
0.44.0
1
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
0.44.0
1
ghcr.io/edgelesssys/continuum/continuum-proxy24c76f294a80
golang.org/x/sys@v0.28.0
0.44.0
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
0.44.0
1
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/sys@v0.15.0
0.44.0
1
ghcr.io/element-hq/ess-helm/matrix-tools:0.3.20eac0521be29
golang.org/x/sys@v0.30.0
0.44.0
1
ghcr.io/eminaktas/oom-tracer:v0.1.0c90ca8389c87
golang.org/x/sys@v0.35.0
0.44.0
1
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
golang.org/x/sys@v0.41.0
0.44.0
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.