StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,853
of 17,821 indexed, latest versions
Container images
4,415
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,853 of 17,821 indexed charts deploy, on 4,415 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+272 more0.44.04,415
OSV records
GO-2026-5024

Charts affected

3,853 by stars
ChartLatestAffected imagesRadar Score
cloudflare-zero-trust-operatorzelic-io0.7.11 of 1See more

cloudflare-zero-trust-operator zelic-io 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/bojanzelic/cloudflare-zero-trust-operator:0.7.1f4b2dbc19a78
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

591
mikochizer0tonin1.11.01 of 1See more

mikochi zer0tonin 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
zer0tonin/mikochi:1.11.009872bae1554
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

1,017
velero-notificationszokeber-velero-notificationsVerified publisher0.1.101 of 2See more

velero-notifications zokeber-velero-notifications 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/zokeber/velero-notifications:0.0.176d84f6c4ce20
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

729
backendzymtraceOfficialVerified publisher26.9.21 of 6See more

backend zymtrace 26.9.2

1 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:17.4304ab8135187
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

9,329
aaqaaqVerified publisher0.3.01 of 1See more

aaq aaq 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/kubevirt/aaq-operator:v1.7.0d28a2daa5b15
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

1,017
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/abstract-foundation/zksync-external-node-sidecar:v1.0.03e705d0eb1ce
golang.org/x/sys@v0.5.0
0.44.0

Open the chart page →

4,607
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

2,549
activepiecesadnoctemVerified publisher0.6.01 of 1See more

activepieces adnoctem 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
activepieces/activepieces:0.91.058414dfc94c4
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

1,071
gobackupadnoctemVerified publisher0.4.01 of 1See more

gobackup adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
huacnlee/gobackup:v3.1.1560be93229a5
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

1,843
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

3,900
popeyeadnoctemVerified publisher0.3.01 of 1See more

popeye adnoctem 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/sys@v0.29.0
0.44.0

Open the chart page →

1,342
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
0.44.0

Open the chart page →

7,459
bootaerokube1.0.12 of 4See more

boot aerokube 1.0.1

2 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/aerokube/boot:1.0.13c269612053f
golang.org/x/sys@v0.19.0
0.44.0
quay.io/aerokube/keygen:1.0.1578934444f04
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

7,964
browser-opsaerokube2.6.71 of 1See more

browser-ops aerokube 2.6.7

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/aerokube/browser-ops:2.6.7807c1bb67086
golang.org/x/sys@v0.18.0
0.44.0

Open the chart page →

553
moonaerokube1.1.372 of 3See more

moon aerokube 1.1.37

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aerokube/moon:1.9.17da76ca51220d
golang.org/x/sys@v0.20.0
0.44.0
aerokube/moon-api:1.9.176b6323e75785
golang.org/x/sys@v0.20.0
0.44.0

Open the chart page →

2,473
aerospike-backup-serviceaerospike-helmVerified publisher2.0.131 of 1See more

aerospike-backup-service aerospike-helm 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aerospike/aerospike-backup-service:3.5.1be40d709c583
golang.org/x/sys@v0.41.0
0.44.0

Open the chart page →

637
msockperfaetrius2.0.81 of 2See more

msockperf aetrius 2.0.8

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
golang.org/x/sys@v0.16.0
0.44.0

Open the chart page →

4,296
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
0.44.0

Open the chart page →

7,220
agentgateway-route-reconcileragentgateway-route-reconciler0.3.11 of 1See more

agentgateway-route-reconciler agentgateway-route-reconciler 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/ricardozd/agentgateway-route-reconciler:0.3.1846f6e407c96
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

259
agentkube-operatoragentkube-operator0.3.01 of 1See more

agentkube-operator agentkube-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

1,734
mt-channel-brokerahhhhVerified publisher0.1.03 of 3See more

mt-channel-broker ahhhh 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/filterdigest-pinnedd675f211a40f
golang.org/x/sys@v0.26.0
0.44.0
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/ingressdigest-pinnedec4b544499ba
golang.org/x/sys@v0.26.0
0.44.0
gcr.io/knative-releases/knative.dev/eventing/cmd/mtchannel_brokerdigest-pinned395f4ff1bd34
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

2,631
net-istioahhhhVerified publisher0.1.12 of 2See more

net-istio ahhhh 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinnede70bc675f977
golang.org/x/sys@v0.26.0
0.44.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned7d76a6d42d13
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

1,128
net-kourierahhhhVerified publisher0.18.11 of 1See more

net-kourier ahhhh 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned15a601147ef4
golang.org/x/sys@v0.32.0
0.44.0

Open the chart page →

515
airbyte-keycloakairbyteVerified publisher0.1.21 of 2See more

airbyte-keycloak airbyte 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

1,270
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

5,009
airbyteairbyte-v2Verified publisher2.3.03 of 10See more

airbyte airbyte-v2 2.3.0

3 of the 10 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
airbyte/db:2.3.000cc017f0393
golang.org/x/sys@v0.1.0
0.44.0
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
golang.org/x/sys@v0.13.0
0.44.0
temporalio/auto-setup:1.27.2b44cbfeb43db
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

12,176
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0

Open the chart page →

4,559
airports-postgresairports-postgres0.1.01 of 1See more

airports-postgres airports-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

1,027
akriakri0.12.551 of 3See more

akri akri 0.12.55

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0

Open the chart page →

1,546
aktoakto0.2.01 of 7See more

akto akto 0.2.0

1 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

13,798
akto-ai-guardrailsakto0.1.21 of 2See more

akto-ai-guardrails akto 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-agent-guard-service:latest5c6ff17c5849
golang.org/x/sys@v0.36.0
0.44.0

Open the chart page →

255
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

42,385
akto-hybrid-redactakto1.44.72 of 5See more

akto-hybrid-redact akto 1.44.7

2 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/sys@v0.28.0
0.44.0
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

4,863
akto-k8s-ebpfakto0.1.31 of 1See more

akto-k8s-ebpf akto 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_ebpffcf8be10bead
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

838
akto-k8s-ebpf-openshiftakto0.1.11 of 1See more

akto-k8s-ebpf-openshift akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
golang.org/x/sys@v0.43.0
0.44.0

Open the chart page →

1,280
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

3,309
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

6,659
akto-mini-testing-kafkaakto1.42.11 of 5See more

akto-mini-testing-kafka akto 1.42.1

1 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

6,432
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

1,868
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

11,316
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

4,896
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

36,090
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/sys@v0.0.0-20210823070655-63515b42dcdf
0.44.0

Open the chart page →

2,229
rabbitmq-cluster-operatoralekcVerified publisher2.9.01 of 1See more

rabbitmq-cluster-operator alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

257
valkey-operatoralekcVerified publisher0.4.01 of 1See more

valkey-operator alekc 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/hyperspike/valkey-operator:v0.0.617d8c669f11a4
golang.org/x/sys@v0.36.0
0.44.0

Open the chart page →

333
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

889
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

1,619
wireguardalexpressoVerified publisher0.1.71 of 2See more

wireguard alexpresso 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
linuxserver/wireguard:latestdca67384e3e9
golang.org/x/sys@v0.39.0
0.44.0

Open the chart page →

478
book-serveral-masood-helm-charts0.1.01 of 1See more

book-server al-masood-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
almasood/book-server:latest6ffac9b63cdf
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

494
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/sys@v0.29.0
0.44.0

Open the chart page →

572

Container images carrying it

4,415 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/sys@v0.28.0
0.44.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/sys@v0.0.0-20201207223542-d4d67f95c62d
0.44.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
golang.org/x/sys@v0.3.0
0.44.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
golang.org/x/sys@v0.10.0
0.44.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/sys@v0.31.0
0.44.0
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
golang.org/x/sys@v0.31.0
0.44.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
0.44.0
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
golang.org/x/sys@v0.33.0
0.44.0
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
golang.org/x/sys@v0.28.0
0.44.0
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/sys@v0.3.0
0.44.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/sys@v0.13.0
0.44.0
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.