StackRadar

CVE-2026-39827

Medium

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,522
of 17,828 indexed, latest versions
Container images
2,853
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

Carried by container images the latest versions of 2,522 of 17,828 indexed charts deploy, on 2,853 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+154 more0.52.02,853
OSV records
GHSA-qpw4-5x99-6vjp
Also known as
GO-2026-5016

Charts affected

2,522 by stars
ChartLatestAffected imagesRadar Score
traefikk3s20.3.1+up20.3.01 of 1See more

traefik k3s 20.3.1+up20.3.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
rancher/mirrored-library-traefik:2.9.40842af6afcdf
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.52.0

Open the chart page →

3,325
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/crypto@v0.26.0
0.52.0

Open the chart page →

1,906
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
golang.org/x/crypto@v0.37.0
0.52.0

Open the chart page →

66,895
bitmagnetk8s-home-lab-repo1.0.21 of 1See more

bitmagnet k8s-home-lab-repo 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/bitmagnet-io/bitmagnet:v0.10b6373349a301
golang.org/x/crypto@v0.41.0
0.52.0

Open the chart page →

1,169
blockyk8s-home-lab-repo11.2.11 of 1See more

blocky k8s-home-lab-repo 11.2.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.29.0a6d99f323d30
golang.org/x/crypto@v0.48.0
0.52.0

Open the chart page →

580
giteak8s-home-lab-repo2.6.01 of 1See more

gitea k8s-home-lab-repo 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
gitea/gitea:1.26.27d13848af126
golang.org/x/crypto@v0.50.0
0.52.0

Open the chart page →

2,143
maddyk8s-home-lab-repo4.2.11 of 1See more

maddy k8s-home-lab-repo 4.2.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
foxcpp/maddy:0.8.2eeb5813fc4d1
golang.org/x/crypto@v0.32.0
0.52.0

Open the chart page →

1,205
photoprismk8s-home-lab-repo10.0.11 of 1See more

photoprism k8s-home-lab-repo 10.0.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
photoprism/photoprism:231128-ce284de9cc4f9c
golang.org/x/crypto@v0.16.0
0.52.0

Open the chart page →

1,141
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
alpine/k8s:1.22.600ac10bcb759
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.52.0

Open the chart page →

15,063
thanosk8sonlabVerified publisher1.1.71 of 1See more

thanos k8sonlab 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/crypto@v0.47.0
0.52.0

Open the chart page →

602
k8s-pausek8s-pause0.1.41 of 1See more

k8s-pause k8s-pause 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.52.0

Open the chart page →

1,848
k8s-s3-bucket-operatork8s-s3-bucket-operator0.2.21 of 1See more

k8s-s3-bucket-operator k8s-s3-bucket-operator 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

535
k8svault-controllerk8svault-controller0.1.21 of 1See more

k8svault-controller k8svault-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.52.0

Open the chart page →

1,886
kagentkagent0.10.11 of 6See more

kagent kagent 0.10.1

1 of the 6 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/kagent-dev/kagent/tools:0.2.150b431281d3e
golang.org/x/crypto@v0.47.0
0.52.0

Open the chart page →

3,064
gpu-provisionerkaitoVerified publisher0.2.01 of 1See more

gpu-provisioner kaito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
mcr.microsoft.com/aks/kaito/gpu-provisioner:0.2.01204a7e948e9
golang.org/x/crypto@v0.18.0
0.52.0

Open the chart page →

1,046
jenkinskallakruparaju-jenkins1.0.01 of 1See more

jenkins kallakruparaju-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/crypto@v0.36.0
0.52.0

Open the chart page →

2,545
dockerdkarljorgensen0.1.01 of 1See more

dockerd karljorgensen 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
library/docker:28.5.2-dind2a232a42256f
golang.org/x/crypto@v0.37.0
0.52.0

Open the chart page →

2,056
k10restorekastenVerified publisher8.0.141 of 1See more

k10restore kasten 8.0.14

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

1,508
kbot-self-hostedkbot-self-hostedVerified publisher0.1.81 of 7See more

kbot-self-hosted kbot-self-hosted 0.1.8

1 of the 7 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.30206a6c708fc6
golang.org/x/crypto@v0.49.0
0.52.0

Open the chart page →

33,121
kestra-starterkestraOfficialVerified publisher2.0.21 of 5See more

kestra-starter kestra 2.0.2

1 of the 5 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
versity/versitygw:v1.1.0f730e0dbc1ef
golang.org/x/crypto@v0.47.0
0.52.0

Open the chart page →

5,630
keycloak-operator-legacykeycloak-operator-legacy1.0.01 of 1See more

keycloak-operator-legacy keycloak-operator-legacy 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.52.0

Open the chart page →

5,071
gogskeyporttech0.1.31 of 3See more

gogs keyporttech 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
gogs/gogs:0.12.30195b095d0b2
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.52.0

Open the chart page →

3,525
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.52.0

Open the chart page →

8,868
connectkfirfer1.15.02 of 2See more

connect kfirfer 1.15.0

2 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
1password/connect-api:1.7.26aa94cf713f9
golang.org/x/crypto@v0.12.0
0.52.0
1password/connect-sync:1.7.2fe527ed9d81f
golang.org/x/crypto@v0.12.0
0.52.0

Open the chart page →

2,788
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.52.0

Open the chart page →

2,793
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.52.0

Open the chart page →

6,517
keelkfirfer1.0.51 of 1See more

keel kfirfer 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
keelhq/keel:0.19.202ac4ea616c4
golang.org/x/crypto@v0.5.0
0.52.0

Open the chart page →

2,084
mysqldumpkfirfer2.8.01 of 1See more

mysqldump kfirfer 2.8.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
golang.org/x/crypto@v0.14.0
0.52.0

Open the chart page →

3,524
prometheus-elasticsearch-exporterkfirfer6.5.11 of 1See more

prometheus-elasticsearch-exporter kfirfer 6.5.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.8.0073dd360de2c
golang.org/x/crypto@v0.21.0
0.52.0

Open the chart page →

779
kiaekiae0.1.66 of 9See more

kiae kiae 0.1.6

6 of the 9 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.52.0
grafana/promtail:2.6.1072527b12cdf
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.52.0
istio/pilot:1.15.2db08d6963975
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.52.0
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
golang.org/x/crypto@v0.1.0
0.52.0
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.52.0
ghcr.io/kiaedev/kiae:latestebd03028ff6a
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.52.0

Open the chart page →

19,303
process-exporterkir4hVerified publisher1.0.11 of 1See more

process-exporter kir4h 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ncabatoff/process-exporterdigest-pinned6f0549dc24e9
golang.org/x/crypto@v0.31.0
0.52.0

Open the chart page →

742
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
golang.org/x/crypto@v0.27.0
0.52.0

Open the chart page →

12,464
kloudlite-platformkloudlite1.1.51 of 3See more

kloudlite-platform kloudlite 1.1.5

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/crypto@v0.13.0
0.52.0

Open the chart page →

1,971
klumklumVerified publisher1.17.11 of 1See more

klum klum 1.17.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/jadolg/klum:v0.8.17c66cc93f9d03
golang.org/x/crypto@v0.51.0
0.52.0

Open the chart page →

357
knative-servingknative-servingVerified publisher1.18.31 of 7See more

knative-serving knative-serving 1.18.3

1 of the 7 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
golang.org/x/crypto@v0.37.0
0.52.0

Open the chart page →

3,778
komiserkomiser-eks3.1.101 of 1See more

komiser komiser-eks 3.1.10

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
tailwarden/komiser:3.1.103f68c8ae7993
golang.org/x/crypto@v0.17.0
0.52.0

Open the chart page →

1,272
komoplanekomodorVerified publisher0.1.81 of 1See more

komoplane komodor 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
komodorio/komoplane:0.2.19678d02c3f2e
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

955
simple-oauth2-proxykostiantyn-matsebora-helm-chartsVerified publisher0.3.71 of 1See more

simple-oauth2-proxy kostiantyn-matsebora-helm-charts 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
golang.org/x/crypto@v0.27.0
0.52.0

Open the chart page →

928
kovi-tile38kovi-charts0.1.11 of 1See more

kovi-tile38 kovi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
tile38/tile38:1.33.4afb7e82f9485
golang.org/x/crypto@v0.21.0
0.52.0

Open the chart page →

1,209
kpingkpingOfficialVerified publisher0.3.51 of 1See more

kping kping 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
kayrosuno/kping:latestf3bd44b29b0d
golang.org/x/crypto@v0.41.0
0.52.0

Open the chart page →

2,278
aggregation-layer-examplekrateo0.1.11 of 1See more

aggregation-layer-example krateo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/aggregation-layer-example:0.1.06a0ed8196346
golang.org/x/crypto@v0.1.0
0.52.0

Open the chart page →

1,504
authnkrateo0.23.01 of 1See more

authn krateo 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/authn:0.23.0791c8f9d885a
golang.org/x/crypto@v0.36.0
0.52.0

Open the chart page →

678
backendkrateo0.15.31 of 1See more

backend krateo 0.15.3

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/backend:0.15.383743fcca3a7
golang.org/x/crypto@v0.28.0
0.52.0

Open the chart page →

903
eventrouter-kafka-producerkrateo0.1.11 of 1See more

eventrouter-kafka-producer krateo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/eventrouter-kafka-producer:0.1.155b18c0dda37
golang.org/x/crypto@v0.0.0-20200204104054-c9f3fb736b72
0.52.0

Open the chart page →

1,623
finops-composition-definition-parserkrateo0.1.41 of 1See more

finops-composition-definition-parser krateo 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/finops-composition-definition-parser:0.1.2d9d82c32f418
golang.org/x/crypto@v0.36.0
0.52.0

Open the chart page →

941
finops-http-rest-queuekrateo0.1.01 of 1See more

finops-http-rest-queue krateo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/finops-http-rest-queue:0.1.0eaa0801e29a7
golang.org/x/crypto@v0.23.0
0.52.0

Open the chart page →

770
git-providerkrateo0.13.01 of 1See more

git-provider krateo 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/git-provider:0.10.061deb827aa9f
golang.org/x/crypto@v0.41.0
0.52.0

Open the chart page →

747
installerkrateo2.7.12 of 2See more

installer krateo 2.7.1

2 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/crypto@v0.17.0
0.52.0
ghcr.io/krateoplatformops/installer/installer:0.6.3a7e922ddac55
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

3,277
installer-post-upgrade-2-5-1krateo1.0.11 of 1See more

installer-post-upgrade-2-5-1 krateo 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/crypto@v0.17.0
0.52.0

Open the chart page →

2,543
installer-pre-upgradekrateo2.7.11 of 1See more

installer-pre-upgrade krateo 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/crypto@v0.17.0
0.52.0

Open the chart page →

2,543

Container images carrying it

2,853 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
golang.org/x/crypto@v0.37.0
0.52.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/crypto@v0.36.0
0.52.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.52.0
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.