StackRadar

CVE-2026-39827

Medium

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,515
of 17,832 indexed, latest versions
Container images
2,844
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

Carried by container images the latest versions of 2,515 of 17,832 indexed charts deploy, on 2,844 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+154 more0.52.02,844
OSV records
GHSA-qpw4-5x99-6vjp
Also known as
GO-2026-5016

Charts affected

2,515 by stars
ChartLatestAffected imagesRadar Score
pgoutboxappscodeVerified publisher2026.7.101 of 1See more

pgoutbox appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/appscode/pgoutbox:v0.0.4a96e06ec5e9f
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

843
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
golang.org/x/crypto@v0.38.0
0.52.0
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

38,104
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
golang.org/x/crypto@v0.24.0
0.52.0

Open the chart page →

779
prom-proxyappscodeVerified publisher2023.3.231 of 1See more

prom-proxy appscode 2023.3.23

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2023.03.235f5a40fc1702
golang.org/x/crypto@v0.6.0
0.52.0

Open the chart page →

2,508
regcacheappscodeVerified publisher2026.9.111 of 1See more

regcache appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/crypto@v0.49.0
0.52.0

Open the chart page →

658
service-backendappscodeVerified publisher2026.9.111 of 1See more

service-backend appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

1,346
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

2,195
service-providerappscodeVerified publisher2026.9.112 of 2See more

service-provider appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
golang.org/x/crypto@v0.29.0
0.52.0
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

2,255
stash-communityappscodeVerified publisher0.42.02 of 4See more

stash-community appscode 0.42.0

2 of the 4 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.52.0
ghcr.io/stashed/stash:v0.42.03a98245a7667
golang.org/x/crypto@v0.24.0
0.52.0

Open the chart page →

3,679
stash-opscenterappscodeVerified publisher2025.10.171 of 1See more

stash-opscenter appscode 2025.10.17

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
golang.org/x/crypto@v0.36.0
0.52.0

Open the chart page →

686
stash-ui-serverappscodeVerified publisher0.23.01 of 1See more

stash-ui-server appscode 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
golang.org/x/crypto@v0.36.0
0.52.0

Open the chart page →

686
statefulsetappscodeVerified publisher0.0.11 of 3See more

statefulset appscode 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.52.0

Open the chart page →

2,740
storage-metrics-serverappscodeVerified publisher2026.7.81 of 1See more

storage-metrics-server appscode 2026.7.8

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/appscode/storage-metrics-server:v0.1.09cb4acb742a9
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

560
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

1,228
voyagerappscodeVerified publisher2026.3.231 of 1See more

voyager appscode 2026.3.23

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/voyager:v17.5.04964ceaf9d35
golang.org/x/crypto@v0.49.0
0.52.0

Open the chart page →

728
voyager-gatewayappscodeVerified publisher2026.7.211 of 2See more

voyager-gateway appscode 2026.7.21

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/crypto@v0.46.0
0.52.0

Open the chart page →

1,371
appwriteappwrite-helmVerified publisher1.3.21 of 8See more

appwrite appwrite-helm 1.3.2

1 of the 8 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/crypto@v0.38.0
0.52.0

Open the chart page →

9,859
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.52.0

Open the chart page →

5,214
argocdargo-helm-charts1.0.02 of 3See more

argocd argo-helm-charts 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/crypto@v0.31.0
0.52.0
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/crypto@v0.27.0
0.52.0

Open the chart page →

7,743
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
golang.org/x/crypto@v0.38.0
0.52.0
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
golang.org/x/crypto@v0.38.0
0.52.0

Open the chart page →

1,845
clickhouseargonaut-charts0.6.82See more

clickhouse argonaut-charts 0.6.8

2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.52.0
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.52.0

Open the chart page →

arlas-aiasarlas-stackVerified publisher28.9.02 of 22See more

arlas-aias arlas-stack 28.9.0

2 of the 22 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/crypto@v0.27.0
0.52.0
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
golang.org/x/crypto@v0.37.0
0.52.0

Open the chart page →

39,854
arma-reforgerarma-reforger0.5.36 of 8See more

arma-reforger arma-reforger 0.5.3

6 of the 8 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.52.0
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/crypto@v0.3.0
0.52.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/crypto@v0.1.0
0.52.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.52.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/crypto@v0.1.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.52.0

Open the chart page →

23,484
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.52.0

Open the chart page →

1,781
itera-lmaarzu1.34.603 of 6See more

itera-lma arzu 1.34.60

3 of the 6 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.52.0
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.52.0

Open the chart page →

8,637
assemblylineassemblylineVerified publisher7.4.212See more

assemblyline assemblyline 7.4.21

2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
golang.org/x/crypto@v0.17.0
0.52.0
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/crypto@v0.17.0
0.52.0

Open the chart page →

dltkvassist-iot-data-integrity-verification0.2.03 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0

Open the chart page →

188,990
dltflassist-iot-dlt-based-fl0.2.03 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.52.0

Open the chart page →

188,990
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.52.0

Open the chart page →

3,807
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.52.0

Open the chart page →

9,473
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.52.0

Open the chart page →

4,388
performanceandusagediagnosisassist-iot-pud1.0.04 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

4 of the 7 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.52.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/crypto@v0.8.0
0.52.0
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.52.0

Open the chart page →

8,595
semantic-repositoryassist-iot-semantic-repository1.1.01 of 3See more

semantic-repository assist-iot-semantic-repository 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
golang.org/x/crypto@v0.40.0
0.52.0

Open the chart page →

1,201
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/crypto@v0.35.0
0.52.0
library/mongo:4.4.66efa05203990
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.52.0

Open the chart page →

46,212
astrotrekastria0.0.23 of 4See more

astrotrek astria 0.0.2

3 of the 4 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.52.0
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
golang.org/x/crypto@v0.24.0
0.52.0
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
golang.org/x/crypto@v0.24.0
0.52.0

Open the chart page →

33,010
celestia-localastria9.0.02 of 2See more

celestia-local astria 9.0.0

2 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
golang.org/x/crypto@v0.42.0
0.52.0
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/crypto@v0.41.0
0.52.0

Open the chart page →

3,312
celestia-nodeastria0.7.11 of 1See more

celestia-node astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/crypto@v0.41.0
0.52.0

Open the chart page →

1,521
evm-faucetastria0.1.51 of 1See more

evm-faucet astria 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.52.0

Open the chart page →

1,765
evm-rollupastria4.1.01 of 2See more

evm-rollup astria 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/crypto@v0.24.0
0.52.0

Open the chart page →

4,037
evm-stackastria5.0.31 of 2See more

evm-stack astria 5.0.3

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/crypto@v0.24.0
0.52.0

Open the chart page →

4,037
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
golang.org/x/crypto@v0.24.0
0.52.0

Open the chart page →

3,889
graph-nodeastria0.2.21 of 3See more

graph-node astria 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/crypto@v0.1.0
0.52.0

Open the chart page →

5,203
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
golang.org/x/crypto@v0.32.0
0.52.0
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/crypto@v0.0.0-20210421170649-83a5a9bb288b
0.52.0

Open the chart page →

6,515
sequencer-faucetastria0.9.21 of 1See more

sequencer-faucet astria 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
golang.org/x/crypto@v0.26.0
0.52.0

Open the chart page →

1,320
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.52.0

Open the chart page →

7,571
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.52.0

Open the chart page →

5,087
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.52.0

Open the chart page →

6,994
appmesh-jaegeraws1.0.31 of 1See more

appmesh-jaeger aws 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/crypto@v0.0.0-20210920023735-84f357641f63
0.52.0

Open the chart page →

2,488
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.52.0

Open the chart page →

2,948
aws-node-termination-handler-2aws0.2.01 of 2See more

aws-node-termination-handler-2 aws 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.52.0

Open the chart page →

2,968

Container images carrying it

2,844 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

No deployed image carries CVE-2026-39827.

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.