StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,878
of 17,821 indexed, latest versions
Container images
4,449
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,878 of 17,821 indexed charts deploy, on 4,449 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+273 more0.44.04,449
OSV records
GO-2026-5024

Charts affected

3,878 by stars
ChartLatestAffected imagesRadar Score
icinga2g0dscookie0.2.01 of 1See more

icinga2 g0dscookie 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
golang.org/x/sys@v0.0.0-20211205182925-97ca703d548d
0.44.0

Open the chart page →

4,435
passboltg0dscookie0.5.22 of 2See more

passbolt g0dscookie 0.5.2

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mariadb:10.79a48ac9f196f
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
0.44.0
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
0.44.0

Open the chart page →

8,029
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

2,585
castsponsorskipgabe565Verified publisher0.8.11 of 1See more

castsponsorskip gabe565 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

1,383
generic-device-plugingabe565Verified publisher0.1.31 of 1See more

generic-device-plugin gabe565 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:latestdc192e164c69
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

260
gotifygabe565Verified publisher0.4.01 of 1See more

gotify gabe565 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/gotify/server:2.6.104f4c4bb7cdd
golang.org/x/sys@v0.27.0
0.44.0

Open the chart page →

763
hammondgabe565Verified publisher0.6.41 of 1See more

hammond gabe565 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/sys@v0.0.0-20210330210617-4fbd30eecc44
0.44.0

Open the chart page →

1,807
limogabe565Verified publisher0.8.01 of 1See more

limo gabe565 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/gabe565/limo:latest6dfdbc9853bb
golang.org/x/sys@v0.5.0
0.44.0

Open the chart page →

1,331
matrimonygabe565Verified publisher0.7.01 of 1See more

matrimony gabe565 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/gabe565/matrimony:latestd39a9d7c3e1b
golang.org/x/sys@v0.17.0
0.44.0

Open the chart page →

1,136
podgrabgabe565Verified publisher0.5.21 of 1See more

podgrab gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
0.44.0

Open the chart page →

2,402
smarter-device-managergabe565Verified publisher0.5.21 of 1See more

smarter-device-manager gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
golang.org/x/sys@v0.0.0-20220728004956-3c1f35247d10
0.44.0

Open the chart page →

1,227
transsmutegabe565Verified publisher1.1.01 of 1See more

transsmute gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

801
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

6,408
galoygaloymoney0.34.74 of 24See more

galoy galoymoney 0.34.7

4 of the 24 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/sys@v0.15.0
0.44.0
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/sys@v0.8.0
0.44.0
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

8,732
galoy-depsgaloymoney0.10.208 of 9See more

galoy-deps galoymoney 0.10.20

8 of the 9 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/sys@v0.25.0
0.44.0
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/sys@v0.15.0
0.44.0
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/sys@v0.15.0
0.44.0
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/sys@v0.15.0
0.44.0
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/sys@v0.15.0
0.44.0
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/sys@v0.9.0
0.44.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/sys@v0.5.0
0.44.0

Open the chart page →

12,016
lndgaloymoney0.10.61 of 3See more

lnd galoymoney 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/sys@v0.19.0
0.44.0

Open the chart page →

2,162
monitoringgaloymoney0.12.215 of 6See more

monitoring galoymoney 0.12.21

5 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/sys@v0.25.0
0.44.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/sys@v0.25.0
0.44.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/sys@v0.19.0
0.44.0
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/sys@v0.25.0
0.44.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

5,340
galoygaloymoney20.34.74 of 24See more

galoy galoymoney2 0.34.7

4 of the 24 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/sys@v0.15.0
0.44.0
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/sys@v0.8.0
0.44.0
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

8,732
galoy-depsgaloymoney20.10.208 of 9See more

galoy-deps galoymoney2 0.10.20

8 of the 9 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/sys@v0.25.0
0.44.0
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/sys@v0.15.0
0.44.0
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/sys@v0.15.0
0.44.0
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/sys@v0.15.0
0.44.0
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/sys@v0.15.0
0.44.0
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/sys@v0.9.0
0.44.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/sys@v0.5.0
0.44.0

Open the chart page →

12,016
lndgaloymoney20.10.61 of 3See more

lnd galoymoney2 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/sys@v0.19.0
0.44.0

Open the chart page →

2,162
monitoringgaloymoney20.12.215 of 6See more

monitoring galoymoney2 0.12.21

5 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/sys@v0.25.0
0.44.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/sys@v0.25.0
0.44.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/sys@v0.19.0
0.44.0
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/sys@v0.25.0
0.44.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

5,340
gameserver-operatorgameserver-operator0.3.01 of 1See more

gameserver-operator gameserver-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/idebeijer/gameserver-operator:latest1b099cfe9e5e
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

383
pagesgary-pages1.0.01 of 3See more

pages gary-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,287
anonaddygeek-cookbookVerified publisher6.0.01 of 1See more

anonaddy geek-cookbook 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
anonaddy/anonaddy:0.12.3957a95565166
golang.org/x/sys@v0.0.0-20211116061358-0a5406a5449c
0.44.0

Open the chart page →

4,793
autobrrgeek-cookbookVerified publisher1.1.31 of 1See more

autobrr geek-cookbook 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
golang.org/x/sys@v0.0.0-20220811171246-fbc7d0a398ab
0.44.0

Open the chart page →

2,237
dendritegeek-cookbookVerified publisher6.4.01 of 1See more

dendrite geek-cookbook 6.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/sys@v0.0.0-20220731174439-a90be440212d
0.44.0

Open the chart page →

2,145
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:lateste1fdac6133ad
golang.org/x/sys@v0.20.0
0.44.0

Open the chart page →

1,736
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
golang.org/x/sys@v0.0.0-20191026070338-33540a1f6037
0.44.0

Open the chart page →

8,612
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/sys@v0.0.0-20211003122950-b1ebd4e1001c
0.44.0

Open the chart page →

1,882
gotifygeek-cookbookVerified publisher1.2.21 of 1See more

gotify geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gotify/server:2.1.409c79bc1e403
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.44.0

Open the chart page →

3,133
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
golang.org/x/sys@v0.0.0-20191026070338-33540a1f6037
0.44.0

Open the chart page →

11,080
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
golang.org/x/sys@v0.0.0-20191026070338-33540a1f6037
0.44.0

Open the chart page →

14,492
maddygeek-cookbookVerified publisher3.2.01 of 1See more

maddy geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
foxcpp/maddy:v0.5.28fa2bd8f6830
golang.org/x/sys@v0.0.0-20211007075335-d3039528d8ac
0.44.0

Open the chart page →

2,631
minifluxgeek-cookbookVerified publisher5.2.01 of 2See more

miniflux geek-cookbook 5.2.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
miniflux/miniflux:2.0.36e2fb990dae74
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0

Open the chart page →

2,431
navidromegeek-cookbookVerified publisher6.4.21 of 1See more

navidrome geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
0.44.0

Open the chart page →

3,598
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
golang.org/x/sys@v0.0.0-20191026070338-33540a1f6037
0.44.0

Open the chart page →

17,824
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
0.44.0

Open the chart page →

3,244
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/sys@v0.0.0-20220615213510-4f61da869c0c
0.44.0

Open the chart page →

19,612
pod-gatewaygeek-cookbookVerified publisher5.6.21 of 2See more

pod-gateway geek-cookbook 5.6.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v3.5.0175512bb3f61
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.44.0

Open the chart page →

2,361
pod-gateway-settergeek-cookbookVerified publisher1.0.01 of 1See more

pod-gateway-setter geek-cookbook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
golang.org/x/sys@v0.0.0-20210309074719-68d13333faf2
0.44.0

Open the chart page →

1,642
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
golang.org/x/sys@v0.0.0-20191026070338-33540a1f6037
0.44.0

Open the chart page →

7,832
rtsp-to-webgeek-cookbookVerified publisher2.2.21 of 1See more

rtsp-to-web geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.44.0

Open the chart page →

1,468
searxgeek-cookbookVerified publisher5.6.21 of 4See more

searx geek-cookbook 5.6.2

1 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/sys@v0.0.0-20200615200032-f1bc736245b1
0.44.0

Open the chart page →

7,507
skypilotgeek-cookbookVerified publisher0.0.13 of 3See more

skypilot geek-cookbook 0.0.1

3 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
golang.org/x/sys@v0.31.0
0.44.0
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/sys@v0.33.0
0.44.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

9,116
torrservergeek-cookbookVerified publisher1.2.21 of 1See more

torrserver geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
smailkoz/torrserver:1.0.1117b52d15de8f0
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.44.0

Open the chart page →

3,167
vikunjageek-cookbookVerified publisher6.2.02 of 4See more

vikunja geek-cookbook 6.2.0

2 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.44.0
vikunja/api:0.17.18cba0520bf8c
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
0.44.0

Open the chart page →

6,905
webhook-receivergeek-cookbookVerified publisher0.0.11 of 1See more

webhook-receiver geek-cookbook 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

1,369
asynqmongeneral-helm-chartsVerified publisher0.0.11 of 1See more

asynqmon general-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
hibiken/asynqmon:latestac80bcffd2f9
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

752
cbtgeneral-helm-chartsVerified publisher0.0.51 of 1See more

cbt general-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ethpandaops/cbt:latest5377ffb3091a
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

566
chproxygeneral-helm-chartsVerified publisher0.0.21 of 1See more

chproxy general-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
contentsquareplatform/chproxy:v1.26.524555f22d4be
golang.org/x/sys@v0.18.0
0.44.0

Open the chart page →

3,686

Container images carrying it

4,449 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
golang.org/x/sys@v0.41.0
0.44.0
1
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/sys@v0.35.0
0.44.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/sys@v0.11.0
0.44.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/sys@v0.28.0
0.44.0
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
golang.org/x/sys@v0.39.0
0.44.0
1
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
golang.org/x/sys@v0.31.0
0.44.0
1
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/sys@v0.28.0
0.44.0
1
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/sys@v0.28.0
0.44.0
1
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
golang.org/x/sys@v0.31.0
0.44.0
1
registry.k8s.io/descheduler/descheduler:v0.36.07ca92c0a7b4f
golang.org/x/sys@v0.42.0
0.44.0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/sys@v0.13.0
0.44.0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
golang.org/x/sys@v0.37.0
0.44.0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
golang.org/x/sys@v0.13.0
0.44.0
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/sys@v0.0.0-20220319134239-a9b59b0215f8
0.44.0
1
registry.k8s.io/etcd:3.6.4-0e36c08168342
golang.org/x/sys@v0.31.0
0.44.0
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
1
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
golang.org/x/sys@v0.4.0
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
golang.org/x/sys@v0.35.0
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
golang.org/x/sys@v0.35.0
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
golang.org/x/sys@v0.17.0
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/sys@v0.0.0-20220412211240-33da011f77ad
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
golang.org/x/sys@v0.8.0
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
golang.org/x/sys@v0.6.0
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
golang.org/x/sys@v0.0.0-20220412211240-33da011f77ad
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
golang.org/x/sys@v0.26.0
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
golang.org/x/sys@v0.19.0
0.44.0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/sys@v0.28.0
0.44.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.2050a34002d5b
golang.org/x/sys@v0.35.0
0.44.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.33d671cf20a35
golang.org/x/sys@v0.36.0
0.44.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
golang.org/x/sys@v0.17.0
0.44.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/sys@v0.28.0
0.44.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.1e63459ec5965
golang.org/x/sys@v0.34.0
0.44.0
1
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/sys@v0.5.0
0.44.0
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
1
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/sys@v0.17.0
0.44.0
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
1
registry.k8s.io/kubectl:1.33.4261a9ed843eb
golang.org/x/sys@v0.31.0
0.44.0
1
registry.k8s.io/kubectl:v1.32.73c5268158974
golang.org/x/sys@v0.26.0
0.44.0
1
registry.k8s.io/kubectl:v1.35.64d8c68e8c2bf
golang.org/x/sys@v0.38.0
0.44.0
1
registry.k8s.io/kubectl:v1.34.159bafa07ff3a
golang.org/x/sys@v0.31.0
0.44.0
1
registry.k8s.io/kubectl:v1.32.08ccae74fc039
golang.org/x/sys@v0.26.0
0.44.0
1
registry.k8s.io/kubectl:v1.36.2b0d792e0d8df
golang.org/x/sys@v0.40.0
0.44.0
1
registry.k8s.io/kubectl:v1.36.1d08f476d04d0
golang.org/x/sys@v0.40.0
0.44.0
1
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/sys@v0.21.0
0.44.0
1
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
golang.org/x/sys@v0.13.0
0.44.0
1
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
golang.org/x/sys@v0.15.0
0.44.0
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.