StackRadar

CVE-2026-39824

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,976
of 17,837 indexed, latest versions
Container images
4,531
deployed by those charts
Fix available
1 of 1
affected package

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

Carried by container images the latest versions of 3,976 of 17,837 indexed charts deploy, on 4,531 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+271 more0.44.04,531
OSV records
GO-2026-5024

Charts affected

3,976 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/sys@v0.0.0-20200812155832-6a926be9bd1d
0.44.0
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
0.44.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/sys@v0.0.0-20201015000850-e3ed0017c211
0.44.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/sys@v0.0.0-20200602225109-6fdc65e7d980
0.44.0

Open the chart page →

12,139
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
golang.org/x/sys@v0.30.0
0.44.0

Open the chart page →

5,563
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/sys@v0.0.0-20190801041406-cbf593c0f2f3
0.44.0

Open the chart page →

2,732
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

12,827
wordpress-hardenedriotkit-org2.0.02 of 2See more

wordpress-hardened riotkit-org 2.0.0

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/waf-proxy:snapshot683656fdace2
golang.org/x/sys@v0.0.0-20220422013727-9388b58f7150
0.44.0
ghcr.io/riotkit-org/wordpress-hardened:v2.0edc6b69873be
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
0.44.0

Open the chart page →

6,622
supabaserock8sVerified publisher0.0.61 of 1See more

supabase rock8s 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:15-alpinea46e076249ce
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

311
rqliterqliteOfficialVerified publisher2.0.01 of 1See more

rqlite rqlite 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
rqlite/rqlite:9.1.37b992a526eee
golang.org/x/sys@v0.37.0
0.44.0

Open the chart page →

1,320
qbittorrent-vpnrtomik-helm-chartsVerified publisher0.0.21 of 2See more

qbittorrent-vpn rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.40.02b42bfa04675
golang.org/x/sys@v0.27.0
0.44.0

Open the chart page →

1,219
seaweedfs-csi-driverseaweedfs-csi-driver0.2.385 of 7See more

seaweedfs-csi-driver seaweedfs-csi-driver 0.2.38

5 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/sys@v0.6.0
0.44.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/sys@v0.7.0
0.44.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/sys@v0.6.0
0.44.0
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/sys@v0.6.0
0.44.0
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

5,323
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
golang.org/x/sys@v0.36.0
0.44.0

Open the chart page →

889
bentoself-hosters-by-nightVerified publisher0.9.11 of 1See more

bento self-hosters-by-night 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

1,178
lldapself-hosters-by-nightVerified publisher0.5.22 of 2See more

lldap self-hosters-by-night 0.5.2

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
golang.org/x/sys@v0.1.0
0.44.0
ghcr.io/lldap/lldap:2025-05-193de697c3ba57
golang.org/x/sys@v0.13.0
0.44.0

Open the chart page →

3,489
skypilotskypilotOfficialVerified publisher0.13.03 of 3See more

skypilot skypilot 0.13.0

3 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
golang.org/x/sys@v0.31.0
0.44.0
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/sys@v0.33.0
0.44.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/sys@v0.33.0
0.44.0

Open the chart page →

6,038
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/sys@v0.4.0
0.44.0

Open the chart page →

1,697
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/sys@v0.0.0-20200331124033-c3d80250170d
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
0.44.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
0.44.0

Open the chart page →

12,542
forecastlestakaterVerified publisher2.1.11 of 1See more

forecastle stakater 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
stakater/forecastle:v2.0.2382cd9572352
golang.org/x/sys@v0.41.0
0.44.0

Open the chart page →

726
ingressmonitorcontrollerstakaterVerified publisher2.2.131 of 1See more

ingressmonitorcontroller stakater 2.2.13

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
golang.org/x/sys@v0.38.0
0.44.0

Open the chart page →

591
sn-platformstreamnative1.11.456 of 9See more

sn-platform streamnative 1.11.45

6 of the 9 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
golang.org/x/sys@v0.0.0-20221010170243-090e33056c14
0.44.0
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/sys@v0.6.0
0.44.0
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/sys@v0.0.0-20220207234003-57398862261d
0.44.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/sys@v0.3.0
0.44.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/sys@v0.2.0
0.44.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

69,898
pocketbasetechwolf12Verified publisher0.29.31 of 1See more

pocketbase techwolf12 0.29.3

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/sys@v0.35.0
0.44.0

Open the chart page →

1,465
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

10,324
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.263 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

3 of the 6 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
golang.org/x/sys@v0.2.0
0.44.0
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
golang.org/x/sys@v0.2.0
0.44.0
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
golang.org/x/sys@v0.2.0
0.44.0

Open the chart page →

14,687
feedbacksystemthm-mni-iiVerified publisher0.47.16 of 10See more

feedbacksystem thm-mni-ii 0.47.1

6 of the 10 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/sys@v0.15.0
0.44.0
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/sys@v0.11.0
0.44.0
bitnamilegacy/mysql:8.0.35-debian-11-r2be03e8ea6129
golang.org/x/sys@v0.2.0
0.44.0
library/docker:20.10.21-dind3153fa63f546
golang.org/x/sys@v0.0.0-20220825204002-c680a09ffe64
0.44.0
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/sys@v0.7.0
0.44.0

Open the chart page →

28,912
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
golang.org/x/sys@v0.32.0
0.44.0

Open the chart page →

1,677
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
0.44.0

Open the chart page →

4,146
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/sys@v0.0.0-20200217220822-9197077df867
0.44.0
library/traefik:v2.57d5a6ae66572
golang.org/x/sys@v0.0.0-20210817190340-bfb29a6856f2
0.44.0
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/sys@v0.0.0-20220704084225-05e143d24a9e
0.44.0

Open the chart page →

9,294
k8s-ttl-controllertwin0.4.01 of 1See more

k8s-ttl-controller twin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

471
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/sys@v0.9.0
0.44.0
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/sys@v0.6.0
0.44.0

Open the chart page →

10,489
crossplaneupbound-stable2.4.1-up.11 of 5See more

crossplane upbound-stable 2.4.1-up.1

1 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

1,713
uptraceuptrace2.0.21 of 2See more

uptrace uptrace 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
uptrace/uptrace:2.0.234a02c3b2d12
golang.org/x/sys@v0.34.0
0.44.0

Open the chart page →

1,611
valkey-operatorvalkeyVerified publisher0.6.01 of 1See more

valkey-operator valkey 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/valkey-io/valkey-operator:v0.6.052a0f1ed0c03
golang.org/x/sys@v0.40.0
0.44.0

Open the chart page →

148
vaultvaultVerified publisher1.22.02 of 4See more

vault vault 1.22.0

2 of the 4 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
alpine/k8s:1.35.5d870622d0040
golang.org/x/sys@v0.42.0
0.44.0
prom/statsd-exporter:v0.29.0632f70580492
golang.org/x/sys@v0.39.0
0.44.0

Open the chart page →

4,312
vouchvouchVerified publisher3.2.01 of 1See more

vouch vouch 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/sys@v0.4.0
0.44.0

Open the chart page →

1,036
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/sys@v0.11.0
0.44.0

Open the chart page →

1,359
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/sys@v0.0.0-20220520151302-bc2c85ada10a
0.44.0

Open the chart page →

2,248
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
golang.org/x/sys@v0.42.0
0.44.0

Open the chart page →

1,003
wallarm-ingresswallarmVerified publisher5.3.10-12 of 2See more

wallarm-ingress wallarm 5.3.10-1

2 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
golang.org/x/sys@v0.29.0
0.44.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/sys@v0.24.0
0.44.0

Open the chart page →

1,302
wallarm-sidecarwallarmOfficialVerified publisher6.13.11 of 3See more

wallarm-sidecar wallarm 6.13.1

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/sys@v0.18.0
0.44.0

Open the chart page →

966
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
golang.org/x/sys@v0.15.0
0.44.0

Open the chart page →

3,532
argo-cdwenerme10.9.22 of 3See more

argo-cd wenerme 10.9.2

2 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/sys@v0.41.0
0.44.0
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

3,086
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
0.44.0

Open the chart page →

6,107
wgerwgerOfficialVerified publisher2.0.01 of 7See more

wger wger 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:15.186eb0add3b77c
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

7,169
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/sys@v0.0.0-20220330033206-e17cdc41300f
0.44.0
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/sys@v0.0.0-20220502124256-b6088ccd6cba
0.44.0
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/sys@v0.0.0-20220502124256-b6088ccd6cba
0.44.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/sys@v0.0.0-20220502124256-b6088ccd6cba
0.44.0

Open the chart page →

10,056
windmillwindmill4.0.2671 of 3See more

windmill windmill 4.0.267

1 of the 3 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
library/postgres:1886c951e05bf5
golang.org/x/sys@v0.1.0
0.44.0

Open the chart page →

1,291
buildkitdwiremindVerified publisher0.33.01 of 1See more

buildkitd wiremind 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/sys@v0.35.0
0.44.0

Open the chart page →

1,165
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
0.44.0

Open the chart page →

4,734
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/sys@v0.0.0-20220503163025-988cb79eb6c6
0.44.0

Open the chart page →

4,544
yet-another-cloudwatch-exporteryet-another-cloudwatch-exporter0.38.01 of 1See more

yet-another-cloudwatch-exporter yet-another-cloudwatch-exporter 0.38.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
golang.org/x/sys@v0.19.0
0.44.0

Open the chart page →

924
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
golang.org/x/sys@v0.0.0-20220715151400-c0bba94af5f8
0.44.0

Open the chart page →

4,195
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/sys@v0.21.0
0.44.0

Open the chart page →

829
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-39824.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
golang.org/x/sys@v0.31.0
0.44.0

Open the chart page →

1,889

Container images carrying it

4,531 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/sys@v0.0.0-20220731174439-a90be440212d
0.44.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
golang.org/x/sys@v0.13.0
0.44.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
golang.org/x/sys@v0.3.0
0.44.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
0.44.0
1
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
golang.org/x/sys@v0.20.0
0.44.0
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
golang.org/x/sys@v0.3.0
0.44.0
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/sys@v0.0.0-20220919091848-fb04ddd9f9c8
0.44.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
golang.org/x/sys@v0.3.0
0.44.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f
0.44.0
1
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
golang.org/x/sys@v0.32.0
0.44.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
golang.org/x/sys@v0.14.0
0.44.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
golang.org/x/sys@v0.24.0
0.44.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/sys@v0.0.0-20220919091848-fb04ddd9f9c8
0.44.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/sys@v0.24.0
0.44.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/sys@v0.28.0
0.44.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/sys@v0.0.0-20201207223542-d4d67f95c62d
0.44.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
golang.org/x/sys@v0.3.0
0.44.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
golang.org/x/sys@v0.10.0
0.44.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/sys@v0.31.0
0.44.0
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
golang.org/x/sys@v0.31.0
0.44.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
0.44.0
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
golang.org/x/sys@v0.33.0
0.44.0
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
golang.org/x/sys@v0.28.0
0.44.0
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.44.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/sys@v0.3.0
0.44.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/sys@v0.13.0
0.44.0
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.44.0
1

syft 1.42.1 · advisories as of 24 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.