StackRadar

CVE-2026-39825

Medium

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,154
of 17,844 indexed, latest versions
Container images
4,718
deployed by those charts
Fix available
1 of 2
affected packages

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

Carried by container images the latest versions of 4,154 of 17,844 indexed charts deploy, on 4,718 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,718
OSV records
DEBIAN-CVE-2026-39825GO-2026-4976
Also known as
BIT-golang-2026-39825

Charts affected

4,154 by stars
ChartLatestAffected imagesRadar Score
gobackupadnoctemVerified publisher0.4.01 of 1See more

gobackup adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
huacnlee/gobackup:v3.1.1560be93229a5
stdlib@go1.20.12
1.25.10

Open the chart page →

1,863
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
stdlib@go1.23.7
1.25.10

Open the chart page →

4,090
popeyeadnoctemVerified publisher0.3.01 of 1See more

popeye adnoctem 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
stdlib@go1.23.5
1.25.10

Open the chart page →

1,363
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
stdlib@go1.20.5
1.25.10

Open the chart page →

31,812
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
stdlib@go1.13.10
1.25.10

Open the chart page →

7,492
bootaerokube1.0.13 of 4See more

boot aerokube 1.0.1

3 of the 4 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/aerokube/boot:1.0.13c269612053f
stdlib@go1.22.2
1.25.10
quay.io/aerokube/keygen:1.0.1578934444f04
stdlib@go1.20.5
1.25.10
quay.io/aerokube/reloader:1.0.1e4a3661416a5
stdlib@go1.22.2
1.25.10

Open the chart page →

8,254
browser-opsaerokube2.6.71 of 1See more

browser-ops aerokube 2.6.7

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/aerokube/browser-ops:2.6.7807c1bb67086
stdlib@go1.22.2
1.25.10

Open the chart page →

556
moonaerokube1.1.373 of 3See more

moon aerokube 1.1.37

3 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
aerokube/moon:1.9.17da76ca51220d
stdlib@go1.22.3
1.25.10
aerokube/moon-api:1.9.176b6323e75785
stdlib@go1.22.3
1.25.10
aerokube/selenoid-ui:1.10.113f3e299509fd
stdlib@go1.21.5
1.25.10

Open the chart page →

2,466
aerospike-backup-serviceaerospike-helmVerified publisher2.0.131 of 1See more

aerospike-backup-service aerospike-helm 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
aerospike/aerospike-backup-service:3.5.1be40d709c583
stdlib@go1.24.13
1.25.10

Open the chart page →

642
msockperfaetrius2.0.81 of 2See more

msockperf aetrius 2.0.8

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
stdlib@go1.22.1
1.25.10

Open the chart page →

4,493
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
stdlib@go1.13.10
1.25.10

Open the chart page →

7,256
agentgateway-route-reconcileragentgateway-route-reconciler0.3.11 of 1See more

agentgateway-route-reconciler agentgateway-route-reconciler 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/ricardozd/agentgateway-route-reconciler:0.3.1846f6e407c96
stdlib@go1.24.13
1.25.10

Open the chart page →

262
agentkube-operatoragentkube-operator0.3.01 of 1See more

agentkube-operator agentkube-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
stdlib@go1.19.7
1.25.10

Open the chart page →

1,724
mt-channel-brokerahhhhVerified publisher0.1.03 of 3See more

mt-channel-broker ahhhh 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/filterdigest-pinnedd675f211a40f
stdlib@go1.22.8
1.25.10
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/ingressdigest-pinnedec4b544499ba
stdlib@go1.22.8
1.25.10
gcr.io/knative-releases/knative.dev/eventing/cmd/mtchannel_brokerdigest-pinned395f4ff1bd34
stdlib@go1.22.8
1.25.10

Open the chart page →

2,634
net-istioahhhhVerified publisher0.1.12 of 2See more

net-istio ahhhh 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinnede70bc675f977
stdlib@go1.22.8
1.25.10
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned7d76a6d42d13
stdlib@go1.22.8
1.25.10

Open the chart page →

1,144
net-kourierahhhhVerified publisher0.18.11 of 1See more

net-kourier ahhhh 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned15a601147ef4
stdlib@go1.24.2
1.25.10

Open the chart page →

524
airbyte-keycloakairbyteVerified publisher0.1.21 of 2See more

airbyte-keycloak airbyte 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
stdlib@go1.24.6
1.25.10

Open the chart page →

1,319
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
stdlib@go1.23.4
1.25.10

Open the chart page →

5,140
airbyteairbyte-v2Verified publisher2.3.03 of 10See more

airbyte airbyte-v2 2.3.0

3 of the 10 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
airbyte/db:2.3.000cc017f0393
stdlib@go1.24.6
1.25.10
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
stdlib@go1.21.4
1.25.10
temporalio/auto-setup:1.27.2b44cbfeb43db
stdlib@go1.23.2
1.25.10

Open the chart page →

12,756
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
stdlib@go1.17.10
1.25.10

Open the chart page →

4,609
airports-postgresairports-postgres0.1.01 of 1See more

airports-postgres airports-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10

Open the chart page →

1,027
akriakri0.12.551 of 3See more

akri akri 0.12.55

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
stdlib@go1.16.9
1.25.10

Open the chart page →

1,549
aktoakto0.2.01 of 7See more

akto akto 0.2.0

1 of the 7 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
stdlib@go1.23.4
1.25.10

Open the chart page →

14,331
akto-ai-guardrailsakto0.1.21 of 2See more

akto-ai-guardrails akto 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-agent-guard-service:latest5c6ff17c5849
stdlib@go1.25.5
1.25.10

Open the chart page →

255
akto-aws-api-gateway-connectorakto0.1.11 of 1See more

akto-aws-api-gateway-connector akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-multi-logging1a1bc76d50fe
stdlib@go1.23.3
1.25.10

Open the chart page →

416
akto-hybrid-redactakto1.44.72 of 5See more

akto-hybrid-redact akto 1.44.7

2 of the 5 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
stdlib@go1.23.4
1.25.10
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
stdlib@go1.25.4
1.25.10

Open the chart page →

5,133
akto-k8s-ebpf-openshiftakto0.1.11 of 1See more

akto-k8s-ebpf-openshift akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
stdlib@go1.25.9
1.25.10

Open the chart page →

1,325
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
stdlib@go1.25.4
1.25.10

Open the chart page →

3,484
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
stdlib@go1.23.4
1.25.10

Open the chart page →

6,838
akto-mini-testing-kafkaakto1.42.11 of 5See more

akto-mini-testing-kafka akto 1.42.1

1 of the 5 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
stdlib@go1.23.4
1.25.10

Open the chart page →

6,756
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
stdlib@go1.24.6
1.25.10

Open the chart page →

1,952
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
stdlib@go1.23.4
1.25.10

Open the chart page →

11,627
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
stdlib@go1.22.5
1.25.10

Open the chart page →

5,016
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
stdlib@go1.23.4
1.25.10

Open the chart page →

38,212
api-gateway-loggingakto0.1.21 of 1See more

api-gateway-logging akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-openapi12ed2544756f
stdlib@go1.23.3
1.25.10

Open the chart page →

416
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
stdlib@go1.16.9
1.25.10

Open the chart page →

2,233
rabbitmq-cluster-operatoralekcVerified publisher2.9.01 of 1See more

rabbitmq-cluster-operator alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
stdlib@go1.25.8
1.25.10

Open the chart page →

261
valkey-operatoralekcVerified publisher0.4.01 of 1See more

valkey-operator alekc 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/hyperspike/valkey-operator:v0.0.617d8c669f11a4
stdlib@go1.25.2
1.25.10

Open the chart page →

336
mautrix-signalalexanderbadel0.1.11 of 2See more

mautrix-signal alexanderbadel 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.25.10

Open the chart page →

2,107
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
stdlib@go1.20.2
1.25.10

Open the chart page →

898
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
stdlib@go1.25.7
1.25.10

Open the chart page →

1,650
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.25.10

Open the chart page →

1,838
gotifyalexvanderberkelVerified publisher0.7.11 of 1See more

gotify alexvanderberkel 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/gotify/server:3.1.144fc5bbd1c06
stdlib@go1.26.0
1.25.10

Open the chart page →

330
alibaba-rsocket-brokeralibaba-rsocket-brokerVerified publisher0.1.31 of 1See more

alibaba-rsocket-broker alibaba-rsocket-broker 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
stdlib@go1.17.7
1.25.10

Open the chart page →

93,258
book-serveral-masood-helm-charts0.1.01 of 1See more

book-server al-masood-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
almasood/book-server:latest6ffac9b63cdf
stdlib@go1.24.6
1.25.10

Open the chart page →

502
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
stdlib@go1.14.15
1.25.10

Open the chart page →

2,111
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
stdlib@go1.24.0
1.25.10

Open the chart page →

580
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
stdlib@go1.24.0
1.25.10

Open the chart page →

580
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
stdlib@go1.24.3
1.25.10

Open the chart page →

1,160
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39825.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
stdlib@go1.24.2
1.25.10

Open the chart page →

557

Container images carrying it

4,718 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.10
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.10
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.10
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.10
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.10
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.10
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.10
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.10
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.10
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.10
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.