StackRadar

CVE-2026-39836

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,033
of 17,813 indexed, latest versions
Container images
4,618
deployed by those charts
Fix available
1 of 1
affected package

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Carried by container images the latest versions of 4,033 of 17,813 indexed charts deploy, on 4,618 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,618
OSV records
GO-2026-4971
Also known as
BIT-golang-2026-39836

Charts affected

4,033 by stars
ChartLatestAffected imagesRadar Score
otel-operatorot-container-kit1.0.11 of 1See more

otel-operator ot-container-kit 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
quay.io/opstree/opentelemetry-operator:0.149.0-debian13a21405ab9a9a
stdlib@go1.25.9
1.25.10

Open the chart page →

290
ot-karpenterot-container-kit0.3.01 of 1See more

ot-karpenter ot-container-kit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:1.1.1fe383abf1dbc
stdlib@go1.23.2
1.25.10

Open the chart page →

495
pgaot-container-kit1.0.34 of 6See more

pga ot-container-kit 1.0.3

4 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
grafana/grafana:11.1.0079600c9517b
stdlib@go1.22.4
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.75.1a7cc63108511
stdlib@go1.22.4
1.25.10
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.10

Open the chart page →

5,153
tempo-standaloneot-container-kit1.0.11 of 1See more

tempo-standalone ot-container-kit 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
quay.io/opstree/tempo:2.10.4-debian13cb734024b3fd
stdlib@go1.26.2
1.25.10

Open the chart page →

612
vmot-container-kit0.0.34 of 7See more

vm ot-container-kit 0.0.3

4 of the 7 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
stdlib@go1.22.4
1.25.10
victoriametrics/operator:v0.47.271be93cfafb6
stdlib@go1.23.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.10

Open the chart page →

5,428
vm-standaloneot-container-kit0.0.44 of 6See more

vm-standalone ot-container-kit 0.0.4

4 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
quay.io/opstree/grafana:12.4.3b61c1ed2f015
stdlib@go1.26.2
1.25.10
quay.io/opstree/kube-state-metrics:2.18.0-debian1353525d253793
stdlib@go1.25.9
1.25.10
quay.io/opstree/node-exporter:1.11.1-alpine3.233b6b3a7eb001
stdlib@go1.26.2
1.25.10
quay.io/opstree/victoriametrics-operator:v0.69.066fe5216c278
stdlib@go1.26.2
1.25.10

Open the chart page →

3,507
otel-add-onotel-add-onVerified publisher0.1.41 of 1See more

otel-add-on otel-add-on 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/kedify/otel-add-on:v0.1.4a6f2155bd822
stdlib@go1.24.3
1.25.10

Open the chart page →

734
otsotsVerified publisher1.8.41 of 2See more

ots ots 1.8.4

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/luzifer/ots:v1.21.5c94f6c9ed173
stdlib@go1.26.2
1.25.10

Open the chart page →

367
adotowan-charts0.1.01 of 1See more

adot owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
stdlib@go1.24.3
1.25.10

Open the chart page →

1,033
httpbunowan-charts0.1.01 of 1See more

httpbun owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
sharat87/httpbun:latest405332d9050a
stdlib@go1.25.1
1.25.10

Open the chart page →

314
minioowan-charts0.1.21 of 2See more

minio owan-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
stdlib@go1.24.4
1.25.10

Open the chart page →

1,083
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
stdlib@go1.17
1.25.10

Open the chart page →

1,827
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
stdlib@go1.22.5
1.25.10

Open the chart page →

1,997
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
stdlib@go1.22.1
1.25.10

Open the chart page →

3,695
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
stdlib@go1.22.5
1.25.10

Open the chart page →

3,362
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
stdlib@go1.21.1
1.25.10
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
stdlib@go1.21.1
1.25.10

Open the chart page →

2,336
predicatep2p-avs0.1.41 of 1See more

predicate p2p-avs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
stdlib@go1.23.5
1.25.10

Open the chart page →

893
p4p40.1.03 of 7See more

p4 p4 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
stdlib@go1.18.10
1.25.10
library/mongo:5.0-focal5e15a3f014ed
stdlib@go1.25.9
1.25.10
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

27,879
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

19,768
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
stdlib@go1.24.0
1.25.10

Open the chart page →

3,627
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-andromeda1.0.01 of 3See more

pages pages-andromeda 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespagesbadami1.0.01 of 3See more

pages pagesbadami 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-blackburn1.0.01 of 3See more

pages pages-blackburn 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-botes1.0.01 of 3See more

pages pages-botes 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-brian1.0.01 of 3See more

pages pages-brian 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-buckll1.0.01 of 3See more

pages pages-buckll 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-camden1.0.01 of 3See more

pages pages-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-camden7711.0.01 of 3See more

pages pages-camden771 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-diarmuidkeane1.0.01 of 3See more

pages pages-diarmuidkeane 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-draco1.0.01 of 3See more

pages pages-draco 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-ellora1.0.01 of 3See more

pages pages-ellora 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-finchley1.0.01 of 3See more

pages pages-finchley 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-fornax1.0.01 of 3See more

pages pages-fornax 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-harsh1.0.01 of 3See more

pages pages-harsh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespagesk1.0.01 of 3See more

pages pagesk 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-microservice-ashim1.0.01 of 3See more

pages pages-microservice-ashim 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-mihai1.0.01 of 3See more

pages pages-mihai 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-nivesh1.0.01 of 3See more

pages pages-nivesh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespagessandeepgudu1.0.01 of 3See more

pages pagessandeepgudu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-shubhanker1.0.01 of 3See more

pages pages-shubhanker 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-ssharma09091.0.01 of 3See more

pages pages-ssharma0909 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-sucharitha1.0.01 of 3See more

pages pages-sucharitha 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285

Container images carrying it

4,618 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gomods/athens:v0.17.10f61d1e62359
stdlib@go1.25.9
1.25.10
1
gomods/athens:v0.18.197cc113b34b0
stdlib@go1.24.1
1.25.10
1
gomods/athens:v0.8.1d714c7ff0231
stdlib@go1.13.4
1.25.10
1
goofball222/pritunl:1.32.3602.807bf26032dfce
stdlib@go1.18.7
1.25.10
1
gophish/gophish:0.12.18a57cd171999
stdlib@go1.15.2
1.25.10
1
gotenberg/gotenberg:8.30206a6c708fc6
stdlib@go1.26.0
1.25.10
1
gotenberg/gotenberg:8.3467097317623a
stdlib@go1.26.2
1.25.10
1
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
stdlib@go1.21.5
1.25.10
1
gotify/server:2.1.409c79bc1e403
stdlib@go1.16
1.25.10
1
gotify/server:2.9.1a3af47067ce6
stdlib@go1.26.0
1.25.10
1
gotify/server-arm7:2.0.23d91e302ad1d0
stdlib@go1.16
1.25.10
1
gotson/komga:1.22.0ba892ab3e082
stdlib@go1.17.8
1.25.10
1
gradiant/open5gs-dbctl:0.10.3332031245fce
stdlib@go1.22.11
1.25.10
1
grafana/agent:v0.44.23364714a2f64
stdlib@go1.22.11
1.25.10
1
grafana/agent:v0.20.0825c09373d27
stdlib@go1.16
1.25.10
1
grafana/agent:v0.40.3f6cbec9409be
stdlib@go1.22.1
1.25.10
1
grafana/agent-operator:v0.34.1045c9125634c
stdlib@go1.20.4
1.25.10
1
grafana/alloy:v1.5.101a63f4e032c
stdlib@go1.22.7
1.25.10
1
grafana/alloy:v1.4.306bdcbb51fc2
stdlib@go1.22.7
1.25.10
1
grafana/alloy:v1.11.38c7256f412fe
stdlib@go1.24.6
1.25.10
1
grafana/alloy:v1.1.1c3dac4e26471
stdlib@go1.22.3
1.25.10
1
grafana/alloy:v1.14.0f50931848bd8
stdlib@go1.25.7
1.25.10
1
grafana/beyla:1.3.336d07f8d276e
stdlib@go1.21.7
1.25.10
1
grafana/beyla:2.2.2a9cf4560472e
stdlib@go1.24.1
1.25.10
1
grafana/beyla-k8s-cache:253b2f561cb1b
stdlib@go1.25.3
1.25.10
1
grafana/grafana:6.6.0052147d7e0ec
stdlib@go1.13.4
1.25.10
1
grafana/grafana:10.1.50679e877ba20
stdlib@go1.20.10
1.25.10
1
grafana/grafana:7.5.609bb407e26ab
stdlib@go1.16.1
1.25.10
1
grafana/grafana:7.3.315b977f5207d
stdlib@go1.15.1
1.25.10
1
grafana/grafana:9.4.71a359d92f40e
stdlib@go1.20.1
1.25.10
1
grafana/grafana:10.1.11b9ca4bbc4a2
stdlib@go1.20.8
1.25.10
1
grafana/grafana:13.0.1-security-012d1f9ae67c17
stdlib@go1.26.2
1.25.10
1
grafana/grafana:12.2.22ebef928d7e5
stdlib@go1.25.3
1.25.10
1
grafana/grafana:12.2.135c41e0fd029
stdlib@go1.25.3
1.25.10
1
grafana/grafana:9.5.239c849cebccc
stdlib@go1.20.4
1.25.10
1
grafana/grafana:11.2.2-security-01464eac539793
stdlib@go1.22.7
1.25.10
1
grafana/grafana:11.5.15781759b3d27
stdlib@go1.23.5
1.25.10
1
grafana/grafana:11.6.062d2b9d20a19
stdlib@go1.23.7
1.25.10
1
grafana/grafana:8.0.3696823fbc561
stdlib@go1.16.1
1.25.10
1
grafana/grafana:10.2.36b5b37eb35bb
stdlib@go1.21.3
1.25.10
1
grafana/grafana:7.3.46d42886b3ebe
stdlib@go1.15.5
1.25.10
1
grafana/grafana:12.3.070d9599b186c
stdlib@go1.25.3
1.25.10
1
grafana/grafana:7.2.1733842cca5bd
stdlib@go1.15.1
1.25.10
1
grafana/grafana:12.2.074144189b384
stdlib@go1.24.6
1.25.10
1
grafana/grafana:9.4.376dcf36e7d2a
stdlib@go1.19.4
1.25.10
1
grafana/grafana:10.3.38640e5038e83
stdlib@go1.21.5
1.25.10
1
grafana/grafana:11.5.28b37a2f028f1
stdlib@go1.23.5
1.25.10
1
grafana/grafana:9.1.19746858c20e6
stdlib@go1.17.12
1.25.10
1
grafana/grafana:12.1.1a1701c218024
stdlib@go1.24.6
1.25.10
1
grafana/grafana:9.0.1a738d0744784
stdlib@go1.17.11
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.