StackRadar

CVE-2026-39836

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,033
of 17,813 indexed, latest versions
Container images
4,618
deployed by those charts
Fix available
1 of 1
affected package

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Carried by container images the latest versions of 4,033 of 17,813 indexed charts deploy, on 4,618 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,618
OSV records
GO-2026-4971
Also known as
BIT-golang-2026-39836

Charts affected

4,033 by stars
ChartLatestAffected imagesRadar Score
otel-operatorot-container-kit1.0.11 of 1See more

otel-operator ot-container-kit 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
quay.io/opstree/opentelemetry-operator:0.149.0-debian13a21405ab9a9a
stdlib@go1.25.9
1.25.10

Open the chart page →

290
ot-karpenterot-container-kit0.3.01 of 1See more

ot-karpenter ot-container-kit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:1.1.1fe383abf1dbc
stdlib@go1.23.2
1.25.10

Open the chart page →

495
pgaot-container-kit1.0.34 of 6See more

pga ot-container-kit 1.0.3

4 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
grafana/grafana:11.1.0079600c9517b
stdlib@go1.22.4
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.75.1a7cc63108511
stdlib@go1.22.4
1.25.10
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.25.10

Open the chart page →

5,153
tempo-standaloneot-container-kit1.0.11 of 1See more

tempo-standalone ot-container-kit 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
quay.io/opstree/tempo:2.10.4-debian13cb734024b3fd
stdlib@go1.26.2
1.25.10

Open the chart page →

612
vmot-container-kit0.0.34 of 7See more

vm ot-container-kit 0.0.3

4 of the 7 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
stdlib@go1.22.4
1.25.10
victoriametrics/operator:v0.47.271be93cfafb6
stdlib@go1.23.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.10

Open the chart page →

5,428
vm-standaloneot-container-kit0.0.44 of 6See more

vm-standalone ot-container-kit 0.0.4

4 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
quay.io/opstree/grafana:12.4.3b61c1ed2f015
stdlib@go1.26.2
1.25.10
quay.io/opstree/kube-state-metrics:2.18.0-debian1353525d253793
stdlib@go1.25.9
1.25.10
quay.io/opstree/node-exporter:1.11.1-alpine3.233b6b3a7eb001
stdlib@go1.26.2
1.25.10
quay.io/opstree/victoriametrics-operator:v0.69.066fe5216c278
stdlib@go1.26.2
1.25.10

Open the chart page →

3,507
otel-add-onotel-add-onVerified publisher0.1.41 of 1See more

otel-add-on otel-add-on 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/kedify/otel-add-on:v0.1.4a6f2155bd822
stdlib@go1.24.3
1.25.10

Open the chart page →

734
otsotsVerified publisher1.8.41 of 2See more

ots ots 1.8.4

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/luzifer/ots:v1.21.5c94f6c9ed173
stdlib@go1.26.2
1.25.10

Open the chart page →

367
adotowan-charts0.1.01 of 1See more

adot owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
stdlib@go1.24.3
1.25.10

Open the chart page →

1,033
httpbunowan-charts0.1.01 of 1See more

httpbun owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
sharat87/httpbun:latest405332d9050a
stdlib@go1.25.1
1.25.10

Open the chart page →

314
minioowan-charts0.1.21 of 2See more

minio owan-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
stdlib@go1.24.4
1.25.10

Open the chart page →

1,083
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
stdlib@go1.17
1.25.10

Open the chart page →

1,827
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
stdlib@go1.22.5
1.25.10

Open the chart page →

1,997
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
stdlib@go1.22.1
1.25.10

Open the chart page →

3,695
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
stdlib@go1.22.5
1.25.10

Open the chart page →

3,362
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
stdlib@go1.21.1
1.25.10
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
stdlib@go1.21.1
1.25.10

Open the chart page →

2,336
predicatep2p-avs0.1.41 of 1See more

predicate p2p-avs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
stdlib@go1.23.5
1.25.10

Open the chart page →

893
p4p40.1.03 of 7See more

p4 p4 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
stdlib@go1.18.10
1.25.10
library/mongo:5.0-focal5e15a3f014ed
stdlib@go1.25.9
1.25.10
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

27,879
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

19,768
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
stdlib@go1.24.0
1.25.10

Open the chart page →

3,627
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-andromeda1.0.01 of 3See more

pages pages-andromeda 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespagesbadami1.0.01 of 3See more

pages pagesbadami 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-blackburn1.0.01 of 3See more

pages pages-blackburn 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-botes1.0.01 of 3See more

pages pages-botes 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-brian1.0.01 of 3See more

pages pages-brian 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-buckll1.0.01 of 3See more

pages pages-buckll 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-camden1.0.01 of 3See more

pages pages-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-camden7711.0.01 of 3See more

pages pages-camden771 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-diarmuidkeane1.0.01 of 3See more

pages pages-diarmuidkeane 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-draco1.0.01 of 3See more

pages pages-draco 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-ellora1.0.01 of 3See more

pages pages-ellora 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-finchley1.0.01 of 3See more

pages pages-finchley 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-fornax1.0.01 of 3See more

pages pages-fornax 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-harsh1.0.01 of 3See more

pages pages-harsh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespagesk1.0.01 of 3See more

pages pagesk 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-microservice-ashim1.0.01 of 3See more

pages pages-microservice-ashim 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-mihai1.0.01 of 3See more

pages pages-mihai 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-nivesh1.0.01 of 3See more

pages pages-nivesh 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespagessandeepgudu1.0.01 of 3See more

pages pagessandeepgudu 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-shubhanker1.0.01 of 3See more

pages pages-shubhanker 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-ssharma09091.0.01 of 3See more

pages pages-ssharma0909 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagespages-sucharitha1.0.01 of 3See more

pages pages-sucharitha 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285

Container images carrying it

4,618 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
rancher/k3s:v1.25.3-k3s1eaa270df79cc
stdlib@go1.19.2
1.25.10
1
rancher/kubectl:v1.25.085a0d1148784
stdlib@go1.19
1.25.10
1
rancher/kube-webhook-certgen:v1.14.5-hardened26bb869baf40b
stdlib@go1.26.2
1.25.10
1
rancher/local-path-provisioner:v0.0.329289da488b07
stdlib@go1.24.4
1.25.10
1
rancher/local-path-provisioner:v0.0.309b9148811700
stdlib@go1.23.1
1.25.10
1
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
stdlib@go1.16.6
1.25.10
1
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
stdlib@go1.16.15
1.25.10
1
rancher/mirrored-cloud-provider-vsphere:v1.31.1febfd0517838
stdlib@go1.22.8
1.25.10
1
rancher/mirrored-longhornio-csi-attacher:v4.11.0-20260428fe417c28a6b8
stdlib@go1.25.9
1.25.10
1
rancher/mirrored-longhornio-csi-node-driver-registrar:v2.16.0-20260428e82a8c8f800d
stdlib@go1.25.9
1.25.10
1
rancher/mirrored-longhornio-csi-provisioner:v5.3.0-202604289e519a21a77c
stdlib@go1.25.9
1.25.10
1
rancher/mirrored-longhornio-csi-resizer:v2.1.0-2026042841cb674d1154
stdlib@go1.25.9
1.25.10
1
rancher/mirrored-longhornio-csi-snapshotter:v8.5.0-202604281975fac3890f
stdlib@go1.25.9
1.25.10
1
rancher/nginx-ingress-controller:v1.14.5-hardened26cbc1e932b5b
stdlib@go1.24.13
1.25.10
1
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
stdlib@go1.16.4
1.25.10
1
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
stdlib@go1.16.4
1.25.10
1
rancher/system-upgrade-controller:v0.19.234fa058fe453
stdlib@go1.25.8
1.25.10
1
rancher/system-upgrade-controller:v0.18.09813f85653c8
stdlib@go1.25.3
1.25.10
1
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
stdlib@go1.13.15
1.25.10
1
rayselfs/aws-ec2-runtime-checker:v0.1.5562e5b2f81ce
stdlib@go1.24.11
1.25.10
1
rclone/rclone:1.63.008e1af3c8814
stdlib@go1.20.5
1.25.10
1
rclone/rclone:1.57.01e6eeabddc01
stdlib@go1.17.2
1.25.10
1
rclone/rclone:1.56.0f2fc45c8bc57
stdlib@go1.16.6
1.25.10
1
reallibrephotos/librephotos-frontend:1.0.358cdf5e93471
stdlib@go1.24.13
1.25.10
1
reaper99/recipya:v1.2.27f7ec3aeb88c
stdlib@go1.22.0
1.25.10
1
redislabs/operator:8.0.18-119078e713bb6a
stdlib@go1.26.1
1.25.10
1
redislabs/operator:7.4.2-2ecb101af0506
stdlib@go1.21.5
1.25.10
1
redislabs/redisearch:2.4.1433561794c5c8
stdlib@go1.16.7
1.25.10
1
redpandadata/kminion:v2.3.0c05fa976428e
stdlib@go1.25.8
1.25.10
1
regclient/regsync:v0.8.33d8d8e40afb7
stdlib@go1.24.2
1.25.10
1
replicated/replicated-sdk:1.0.0-beta.318751b4963250
stdlib@go1.23.2
1.25.10
1
reportportal/migrations:5.15.4464468240d7b
stdlib@go1.24.6
1.25.10
1
reportportal/migrations:5.7.0da5d8e1395fe
stdlib@go1.13.6
1.25.10
1
reportportal/service-index:5.0.112b27a2d7a87d
stdlib@go1.17.1
1.25.10
1
reportportal/service-index:5.15.1b1860ed33071
stdlib@go1.26.2
1.25.10
1
restic/restic:0.15.2579e4e6a4931
stdlib@go1.19.8
1.25.10
1
restic/rest-server:0.14.0d2aff06f47eb
stdlib@go1.24.3
1.25.10
1
resurfaceio/resurface:3.7.84d5cda2f64109
stdlib@go1.23.0
1.25.10
1
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.19.12
1.25.10
1
ribbybibby/s3-exporter:v0.5.0998184c51a00
stdlib@go1.15.15
1.25.10
1
richardjennings/opa-nginx:0.0.366424aca125d
stdlib@go1.20.5
1.25.10
1
rimusz/security-sample-app:0.2.0b9a178ca76ef
stdlib@go1.14.4
1.25.10
1
robjuz/postgresql-nominatim:latest805c7bab76df
stdlib@go1.16.5
1.25.10
1
robotshop/rs-dispatch:latestde81f1d07b02
stdlib@go1.17
1.25.10
1
robotshop/rs-mongodb:latest119b545823cd
stdlib@go1.16.3
1.25.10
1
robustadev/kubewatch:v2.9.00457a51e36e8
stdlib@go1.23.1
1.25.10
1
rocm/k8s-device-plugin:1.31.0.926212c665aab
stdlib@go1.23.6
1.25.10
1
rogerrum/alertmanager-discord:1.0.3827593369625
stdlib@go1.17.4
1.25.10
1
rokk42/seashells:1.0-k8sdfc850a5db9e
stdlib@go1.22.3
1.25.10
1
rook/ceph:v1.20.72f970c425617
stdlib@go1.22.10
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.