StackRadar

CVE-2026-39827

Medium

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,522
of 17,828 indexed, latest versions
Container images
2,853
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

Carried by container images the latest versions of 2,522 of 17,828 indexed charts deploy, on 2,853 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+154 more0.52.02,853
OSV records
GHSA-qpw4-5x99-6vjp
Also known as
GO-2026-5016

Charts affected

2,522 by stars
ChartLatestAffected imagesRadar Score
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.06 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

6 of the 40 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
golang.org/x/crypto@v0.36.0
0.52.0
library/arangodb:3.11.81e75d74954a4
golang.org/x/crypto@v0.17.0
0.52.0
prom/prometheus:v3.0.1565ee8650122
golang.org/x/crypto@v0.28.0
0.52.0
gcr.io/kaniko-project/executor:latest4e7a52dd1f14
golang.org/x/crypto@v0.38.0
0.52.0
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
golang.org/x/crypto@v0.22.0
0.52.0
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.52.0

Open the chart page →

200,900
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
golang.org/x/crypto@v0.17.0
0.52.0

Open the chart page →

6,893
osm-edgeosm-edgeVerified publisher1.3.93 of 7See more

osm-edge osm-edge 1.3.9

3 of the 7 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
golang.org/x/crypto@v0.5.0
0.52.0
flomesh/osm-edge-controller:1.3.9add7a4da4622
golang.org/x/crypto@v0.5.0
0.52.0
flomesh/osm-edge-injector:1.3.947287e3ad324
golang.org/x/crypto@v0.5.0
0.52.0

Open the chart page →

5,614
logging-operatorot-container-kit0.4.01 of 1See more

logging-operator ot-container-kit 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/opstree/logging-operator:v0.4.0fd8bb57ef3cf
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.52.0

Open the chart page →

1,803
lokiot-container-kit1.0.13 of 5See more

loki ot-container-kit 1.0.1

3 of the 5 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
grafana/loki:3.1.0d947e68a84d9
golang.org/x/crypto@v0.21.0
0.52.0
grafana/promtail:3.0.0d3de3da9431c
golang.org/x/crypto@v0.21.0
0.52.0
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/crypto@v0.17.0
0.52.0

Open the chart page →

4,846
loki-standaloneot-container-kit1.0.22 of 5See more

loki-standalone ot-container-kit 1.0.2

2 of the 5 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/opstree/loki:3.6-debian13bdfee214c7ea
golang.org/x/crypto@v0.50.0
0.52.0
quay.io/opstree/memcached-exporter:0.15.5-debian13cf8f8410eaad
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

3,661
mongodb-operatorot-container-kit0.3.11 of 1See more

mongodb-operator ot-container-kit 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/opstree/mongodb-operator:v0.3.0879b9bead838
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.52.0

Open the chart page →

1,874
pgaot-container-kit1.0.33 of 6See more

pga ot-container-kit 1.0.3

3 of the 6 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
grafana/grafana:11.1.0079600c9517b
golang.org/x/crypto@v0.24.0
0.52.0
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/crypto@v0.21.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/crypto@v0.21.0
0.52.0

Open the chart page →

5,155
tempo-standaloneot-container-kit1.0.11 of 1See more

tempo-standalone ot-container-kit 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/opstree/tempo:2.10.4-debian13cb734024b3fd
golang.org/x/crypto@v0.49.0
0.52.0

Open the chart page →

612
vmot-container-kit0.0.33 of 7See more

vm ot-container-kit 0.0.3

3 of the 7 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
golang.org/x/crypto@v0.24.0
0.52.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/crypto@v0.21.0
0.52.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/crypto@v0.24.0
0.52.0

Open the chart page →

5,431
vm-standaloneot-container-kit0.0.43 of 6See more

vm-standalone ot-container-kit 0.0.4

3 of the 6 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/opstree/grafana:12.4.3b61c1ed2f015
golang.org/x/crypto@v0.50.0
0.52.0
quay.io/opstree/kube-state-metrics:2.18.0-debian1353525d253793
golang.org/x/crypto@v0.50.0
0.52.0
quay.io/opstree/node-exporter:1.11.1-alpine3.233b6b3a7eb001
golang.org/x/crypto@v0.49.0
0.52.0

Open the chart page →

3,501
otel-add-onotel-add-onVerified publisher0.1.41 of 1See more

otel-add-on otel-add-on 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/kedify/otel-add-on:v0.1.4a6f2155bd822
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

734
otsotsVerified publisher1.8.41 of 2See more

ots ots 1.8.4

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/luzifer/ots:v1.21.5c94f6c9ed173
golang.org/x/crypto@v0.49.0
0.52.0

Open the chart page →

367
akash-hostname-operatorovrclk-211.5.11 of 1See more

akash-hostname-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
golang.org/x/crypto@v0.28.0
0.52.0

Open the chart page →

3,561
akash-inventory-operatorovrclk-211.5.11 of 1See more

akash-inventory-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
golang.org/x/crypto@v0.28.0
0.52.0

Open the chart page →

3,561
akash-ip-operatorovrclk-211.5.11 of 1See more

akash-ip-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
golang.org/x/crypto@v0.28.0
0.52.0

Open the chart page →

3,561
akash-nodeovrclk-211.1.31 of 1See more

akash-node ovrclk-2 11.1.3

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/akash-network/node:0.36.08763983b31f1
golang.org/x/crypto@v0.22.0
0.52.0

Open the chart page →

1,338
adotowan-charts0.1.01 of 1See more

adot owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
golang.org/x/crypto@v0.36.0
0.52.0

Open the chart page →

1,033
minioowan-charts0.1.21 of 2See more

minio owan-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
golang.org/x/crypto@v0.36.0
0.52.0

Open the chart page →

1,083
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
golang.org/x/crypto@v0.22.0
0.52.0

Open the chart page →

1,998
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
golang.org/x/crypto@v0.24.0
0.52.0

Open the chart page →

3,726
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
golang.org/x/crypto@v0.22.0
0.52.0

Open the chart page →

3,353
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
golang.org/x/crypto@v0.23.0
0.52.0
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
golang.org/x/crypto@v0.23.0
0.52.0

Open the chart page →

2,338
predicatep2p-avs0.1.41 of 1See more

predicate p2p-avs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
golang.org/x/crypto@v0.31.0
0.52.0

Open the chart page →

893
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

28,008
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
golang.org/x/crypto@v0.45.0
0.52.0

Open the chart page →

3,649
alistpanghuli0.1.51 of 2See more

alist panghuli 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
xhofe/alist:v3.24.033f15a31be6c
golang.org/x/crypto@v0.11.0
0.52.0

Open the chart page →

1,990
parcaparca4.19.02 of 2See more

parca parca 4.19.0

2 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/crypto@v0.9.0
0.52.0
ghcr.io/parca-dev/parca-agent:v0.28.06d6794f45f3e
golang.org/x/crypto@v0.16.0
0.52.0

Open the chart page →

3,385
parcaparca-chart0.1.01 of 1See more

parca parca-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/crypto@v0.9.0
0.52.0

Open the chart page →

1,995
parcaparca-rr0.1.01 of 2See more

parca parca-rr 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.24.23776500fde82
golang.org/x/crypto@v0.38.0
0.52.0

Open the chart page →

2,405
istio-operatorparticuleio1.7.01 of 1See more

istio-operator particuleio 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
gcr.io/istio-testing/operator:latest8d4576f7b98f
golang.org/x/crypto@v0.25.0
0.52.0

Open the chart page →

4,219
scaleway-webhookparticuleio0.0.11 of 1See more

scaleway-webhook particuleio 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.52.0

Open the chart page →

2,355
cloudflaredpascaliskeVerified publisher3.0.01 of 1See more

cloudflared pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
golang.org/x/crypto@v0.38.0
0.52.0

Open the chart page →

2,071
hammondpascaliskeVerified publisher2.0.01 of 2See more

hammond pascaliske 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.52.0

Open the chart page →

1,807
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
golang.org/x/crypto@v0.26.0
0.52.0

Open the chart page →

4,877
vikunjapascaliskeVerified publisher5.1.01 of 1See more

vikunja pascaliske 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/crypto@v0.27.0
0.52.0

Open the chart page →

1,343
pax-prometheuspaxtecnologia0.7.11 of 8See more

pax-prometheus paxtecnologia 0.7.1

1 of the 8 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/crypto@v0.22.0
0.52.0

Open the chart page →

1,805
stk-fluent-bit-loki-s3paxtecnologia0.2.12 of 6See more

stk-fluent-bit-loki-s3 paxtecnologia 0.2.1

2 of the 6 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
grafana/loki:3.6.1144148ad243c0
golang.org/x/crypto@v0.49.0
0.52.0
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/crypto@v0.42.0
0.52.0

Open the chart page →

3,768
archive-analysispcp-helm-chartsVerified publisher1.0.11 of 1See more

archive-analysis pcp-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
ghcr.io/performancecopilot/archive-analysis:latestba9f5a44ad68
golang.org/x/crypto@v0.17.0
0.52.0

Open the chart page →

1,386
pmm-ha-dependenciespercona1.0.01 of 4See more

pmm-ha-dependencies percona 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
percona/percona-postgresql-operator:2.8.06cce2698d3f5
golang.org/x/crypto@v0.43.0
0.52.0

Open the chart page →

2,485
permission-managerpermission-manager1.0.0-seal1 of 1See more

permission-manager permission-manager 1.0.0-seal

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.52.0

Open the chart page →

2,268
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.52.0

Open the chart page →

15,476
pet-battle-nsffpetbattle0.0.22 of 4See more

pet-battle-nsff petbattle 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
minio/mc:latesta7fe349ef4bd
golang.org/x/crypto@v0.40.0
0.52.0
minio/minio:latest14cea493d9a3
golang.org/x/crypto@v0.40.0
0.52.0

Open the chart page →

3,909
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.52.0

Open the chart page →

15,476
mongodbpetersandor14.1.81 of 1See more

mongodb petersandor 14.1.8

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
bitnami/mongodb:8.0.8b3bd5b6be9a0
golang.org/x/crypto@v0.35.0
0.52.0

Open the chart page →

4,517
container-agentphntom100.0.11 of 1See more

container-agent phntom 100.0.1

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
circleci/container-agent:34d8d0ae5efc3
golang.org/x/crypto@v0.7.0
0.52.0

Open the chart page →

1,975
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.52.0

Open the chart page →

4,651
goalertphntom0.0.291 of 1See more

goalert phntom 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
phntom/goalert:0.0.298ca4df55499b
golang.org/x/crypto@v0.16.0
0.52.0

Open the chart page →

1,050
kochiphntom1.1.41 of 1See more

kochi phntom 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
phntom/kochi:1.1.33b82358bd56e
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.52.0

Open the chart page →

2,965
loki-stackphntom2.10.22 of 2See more

loki-stack phntom 2.10.2

2 of the 2 container images this version deploys carry CVE-2026-39827.

Container imageDigestPackageFixed in
grafana/loki:2.4.2b3af8ead67d7
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.52.0
grafana/promtail:2.4.2626900031c4e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.52.0

Open the chart page →

5,728

Container images carrying it

2,853 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
golang.org/x/crypto@v0.37.0
0.52.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/crypto@v0.36.0
0.52.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.52.0
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.