StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,907
of 17,837 indexed, latest versions
Container images
4,451
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,907 of 17,837 indexed charts deploy, on 4,451 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+271 more0.44.04,451
OSV records
GO-2026-5024

Charts affected

3,907 by stars
ChartLatestAffected imagesRadar Score
bootaerokube1.0.12 of 4See more

boot aerokube 1.0.1

2 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/aerokube/boot:1.0.13c269612053f
golang.org/x/sys@v0.19.0
0.44.0
quay.io/aerokube/keygen:1.0.1578934444f04
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

8,034
browser-opsaerokube2.6.71 of 1See more

browser-ops aerokube 2.6.7

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/aerokube/browser-ops:2.6.7807c1bb67086
golang.org/x/sys@v0.18.0
0.44.0

Open the chart page →

553
moonaerokube1.1.372 of 3See more

moon aerokube 1.1.37

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aerokube/moon:1.9.17da76ca51220d
golang.org/x/sys@v0.20.0
0.44.0
aerokube/moon-api:1.9.176b6323e75785
golang.org/x/sys@v0.20.0
0.44.0

Open the chart page →

2,473
aerospike-backup-serviceaerospike-helmVerified publisher2.0.131 of 1See more

aerospike-backup-service aerospike-helm 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aerospike/aerospike-backup-service:3.5.1be40d709c583
golang.org/x/sys@v0.41.0
0.44.0

Open the chart page →

637
msockperfaetrius2.0.81 of 2See more

msockperf aetrius 2.0.8

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
golang.org/x/sys@v0.16.0
0.44.0

Open the chart page →

4,357
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
0.44.0

Open the chart page →

7,220
agentgateway-route-reconcileragentgateway-route-reconciler0.3.11 of 1See more

agentgateway-route-reconciler agentgateway-route-reconciler 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/ricardozd/agentgateway-route-reconciler:0.3.1846f6e407c96
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

259
agentkube-operatoragentkube-operator0.3.01 of 1See more

agentkube-operator agentkube-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

1,734
mt-channel-brokerahhhhVerified publisher0.1.03 of 3See more

mt-channel-broker ahhhh 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/filterdigest-pinnedd675f211a40f
golang.org/x/sys@v0.26.0
0.44.0
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/ingressdigest-pinnedec4b544499ba
golang.org/x/sys@v0.26.0
0.44.0
gcr.io/knative-releases/knative.dev/eventing/cmd/mtchannel_brokerdigest-pinned395f4ff1bd34
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

2,631
net-istioahhhhVerified publisher0.1.12 of 2See more

net-istio ahhhh 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinnede70bc675f977
golang.org/x/sys@v0.26.0
0.44.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned7d76a6d42d13
golang.org/x/sys@v0.26.0
0.44.0

Open the chart page →

1,128
net-kourierahhhhVerified publisher0.18.11 of 1See more

net-kourier ahhhh 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned15a601147ef4
golang.org/x/sys@v0.32.0
0.44.0

Open the chart page →

516
airbyte-keycloakairbyteVerified publisher0.1.21 of 2See more

airbyte-keycloak airbyte 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

1,290
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

5,042
airbyteairbyte-v2Verified publisher2.3.03 of 10See more

airbyte airbyte-v2 2.3.0

3 of the 10 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
airbyte/db:2.3.000cc017f0393
golang.org/x/sys@v0.1.0
0.44.0
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
golang.org/x/sys@v0.13.0
0.44.0
temporalio/auto-setup:1.27.2b44cbfeb43db
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

12,223
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.44.0

Open the chart page →

4,559
airports-postgresairports-postgres0.1.01 of 1See more

airports-postgres airports-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

1,027
akriakri0.12.551 of 3See more

akri akri 0.12.55

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0

Open the chart page →

1,546
aktoakto0.2.01 of 7See more

akto akto 0.2.0

1 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

13,918
akto-ai-guardrailsakto0.1.21 of 2See more

akto-ai-guardrails akto 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-agent-guard-service:latest5c6ff17c5849
golang.org/x/sys@v0.36.0
0.44.0

Open the chart page →

255
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

42,708
akto-hybrid-redactakto1.44.72 of 5See more

akto-hybrid-redact akto 1.44.7

2 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/sys@v0.28.0
0.44.0
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

4,975
akto-k8s-ebpfakto0.1.31 of 1See more

akto-k8s-ebpf akto 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_ebpf3e506f5e5f47
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

539
akto-k8s-ebpf-openshiftakto0.1.11 of 1See more

akto-k8s-ebpf-openshift akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
golang.org/x/sys@v0.43.0
0.44.0

Open the chart page →

1,282
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

3,343
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

6,650
akto-mini-testing-kafkaakto1.42.11 of 5See more

akto-mini-testing-kafka akto 1.42.1

1 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

6,468
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

1,882
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

11,355
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

4,919
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/sys@v0.28.0
0.44.0

Open the chart page →

35,337
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/sys@v0.0.0-20210823070655-63515b42dcdf
0.44.0

Open the chart page →

2,230
rabbitmq-cluster-operatoralekcVerified publisher2.9.01 of 1See more

rabbitmq-cluster-operator alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

257
valkey-operatoralekcVerified publisher0.4.01 of 1See more

valkey-operator alekc 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/hyperspike/valkey-operator:v0.0.617d8c669f11a4
golang.org/x/sys@v0.36.0
0.44.0

Open the chart page →

333
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

889
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

1,620
wireguardalexpressoVerified publisher0.1.71 of 2See more

wireguard alexpresso 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
linuxserver/wireguard:latestdca67384e3e9
golang.org/x/sys@v0.39.0
0.44.0

Open the chart page →

478
alibaba-rsocket-brokeralibaba-rsocket-brokerVerified publisher0.1.31 of 1See more

alibaba-rsocket-broker alibaba-rsocket-broker 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
golang.org/x/sys@v0.0.0-20220207234003-57398862261d
0.44.0

Open the chart page →

89,991
book-serveral-masood-helm-charts0.1.01 of 1See more

book-server al-masood-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
almasood/book-server:latest6ffac9b63cdf
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

494
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/sys@v0.29.0
0.44.0

Open the chart page →

572
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/sys@v0.29.0
0.44.0

Open the chart page →

572
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

1,152
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
golang.org/x/sys@v0.30.0
0.44.0

Open the chart page →

549
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
golang.org/x/sys@v0.25.0
0.44.0
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
golang.org/x/sys@v0.25.0
0.44.0

Open the chart page →

4,595
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
golang.org/x/sys@v0.25.0
0.44.0

Open the chart page →

590
versitygwalpineworks0.1.21 of 1See more

versitygw alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
versity/versitygw:v1.0.145192635d0353
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

1,261
versitygw-webhook-pulsar-proxyalpineworks0.1.11 of 1See more

versitygw-webhook-pulsar-proxy alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

908
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

20,372
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
golang.org/x/sys@v0.18.0
0.44.0
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/sys@v0.5.0
0.44.0
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/sys@v0.10.0
0.44.0
daprio/operator:1.11.2c584428aa12d
golang.org/x/sys@v0.10.0
0.44.0
daprio/placement:1.11.2d8e1446da996
golang.org/x/sys@v0.10.0
0.44.0
daprio/sentry:1.11.21f507c1a181b
golang.org/x/sys@v0.10.0
0.44.0
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/sys@v0.13.0
0.44.0
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

28,549
ampsamps0.1.95 of 10See more

amps amps 0.1.9

5 of the 10 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
hashicorp/vault:1.9.2ff9b17b0cefe
golang.org/x/sys@v0.0.0-20211025201205-69cdffdb9359
0.44.0
library/nats:2.7.2-alpine8b3fb2423a8c
golang.org/x/sys@v0.0.0-20220111092808-5a964db01320
0.44.0
natsio/nats-box:0.8.1b7f9328145f4
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
0.44.0
natsio/nats-server-config-reloader:0.6.2ad0374303b13
golang.org/x/sys@v0.0.0-20200918174421-af09f7315aff
0.44.0
natsio/prometheus-nats-exporter:0.9.14665cdc7e749
golang.org/x/sys@v0.0.0-20220111092808-5a964db01320
0.44.0

Open the chart page →

10,774
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

1,607

Container images carrying it

4,451 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.