CVE-2026-39836
UnscoredAdvisory
Published 7 May 2026In the index since 5 Sept 2026
- Severity
- Unscored
- worst across findings
- CVSS
- —
- base score, highest
- EPSS
- 0.006
- 47th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,975
- of 17,813 indexed, latest versions
- Container images
- 4,549
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Panic in Dial and LookupPort when handling NUL byte on Windows in net
Carried by container images the latest versions of 3,975 of 17,813 indexed charts deploy, on 4,549 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+180 more | 1.25.10 | 4,549 |
- OSV records
- GO-2026-4971
- Also known as
- BIT-golang-2026-39836
Charts affected
3,975 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
4,549 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | f02121de6f74 | stdlib | 1.25.10 | 3 |
| library/ | c8bb255c3559 | stdlib | 1.25.10 | 3 |
| library/ | 1be55279f18a | stdlib | 1.25.10 | 3 |
| louislam/ | 917318f9d7be | stdlib | 1.25.10 | 3 |
| migrate/ | cc4ad8e19d66 | stdlib | 1.25.10 | 3 |
| minio/ | 54393e03f3b2 | stdlib | 1.25.10 | 3 |
| mintel/ | caf71cee7b9a | stdlib | 1.25.10 | 3 |
| natsio/ | a3381560aab6 | stdlib | 1.25.10 | 3 |
| natsio/ | 8031d190c7ee | stdlib | 1.25.10 | 3 |
| natsio/ | b3359eeb10bf | stdlib | 1.25.10 | 3 |
| neosmemo/ | 71a5b4738d1b | stdlib | 1.25.10 | 3 |
| oamdev/ | 231c423c2b17 | stdlib | 1.25.10 | 3 |
| opencsghq/ | b98600564e07 | stdlib | 1.25.10 | 3 |
| openebs/ | f6c18b0f8c8a | stdlib | 1.25.10 | 3 |
| openebs/ | 6afe2123c457 | stdlib | 1.25.10 | 3 |
| openebs/ | aea39e49bb97 | stdlib | 1.25.10 | 3 |
| oryd/ | 2c93beb5e5f2 | stdlib | 1.25.10 | 3 |
| prom/ | d5155cfac40a | stdlib | 1.25.10 | 3 |
| prom/ | d8a61419b841 | stdlib | 1.25.10 | 3 |
| prom/ | 565ee8650122 | stdlib | 1.25.10 | 3 |
| prom/ | bfad037f95e5 | stdlib | 1.25.10 | 3 |
| prom/ | 0a9031142481 | stdlib | 1.25.10 | 3 |
| prom/ | 8305a33fb80a | stdlib | 1.25.10 | 3 |
| prom/ | a5df60347882 | stdlib | 1.25.10 | 3 |
| prom/ | d23aca343b86 | stdlib | 1.25.10 | 3 |
| rancher/ | 090bef429ed1 | stdlib | 1.25.10 | 3 |
| rcdelacruz/ | 38007f358355 | stdlib | 1.25.10 | 3 |
| rss3/ | d1d2ae6efd05 | stdlib | 1.25.10 | 3 |
| signoz/ | fcc4a3288154 | stdlib | 1.25.10 | 3 |
| stakater/ | 83fef483d497 | stdlib | 1.25.10 | 3 |
| traefik/ | 200689790a0a | stdlib | 1.25.10 | 3 |
| tykio/ | 55b4d31c7a01 | stdlib | 1.25.10 | 3 |
| tykio/ | 1489b58f642b | stdlib | 1.25.10 | 3 |
| tykio/ | 205215b815a4 | stdlib | 1.25.10 | 3 |
| vikunja/ | ed1f3ed467fe | stdlib | 1.25.10 | 3 |
| wallabag/ | 4a527e027e0d | stdlib | 1.25.10 | 3 |
| gcr.io/ | 2a685a38dd01 | stdlib | 1.25.10 | 3 |
| ghcr.io/ | a27779ed1085 | stdlib | 1.25.10 | 3 |
| ghcr.io/ | b776dae45d08 | stdlib | 1.25.10 | 3 |
| ghcr.io/ | cf9b41e17b93 | stdlib | 1.25.10 | 3 |
| ghcr.io/ | 5f6cd61e6da6 | stdlib | 1.25.10 | 3 |
| ghcr.io/ | 3a061734c5be | stdlib | 1.25.10 | 3 |
| ghcr.io/ | 3cee6c78973b | stdlib | 1.25.10 | 3 |
| ghcr.io/ | 66664ba563e7 | stdlib | 1.25.10 | 3 |
| ghcr.io/ | 5a878e4e4f03 | stdlib | 1.25.10 | 3 |
| ghcr.io/ | 28c5ff40963f | stdlib | 1.25.10 | 3 |
| public.ecr.aws/ | c88ea2979a49 | stdlib | 1.25.10 | 3 |
| public.ecr.aws/ | fefa9ee7256a | stdlib | 1.25.10 | 3 |
| quay.io/ | fa07b2c9ece6 | stdlib | 1.25.10 | 3 |
| quay.io/ | aa4da00c5b96 | stdlib | 1.25.10 | 3 |