StackRadar

CVE-2026-39836

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,154
of 17,844 indexed, latest versions
Container images
4,718
deployed by those charts
Fix available
1 of 1
affected package

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Carried by container images the latest versions of 4,154 of 17,844 indexed charts deploy, on 4,718 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,718
OSV records
GO-2026-4971
Also known as
BIT-golang-2026-39836

Charts affected

4,154 by stars
ChartLatestAffected imagesRadar Score
cortexmetakube0.6.01 of 2See more

cortex metakube 0.6.0

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
stdlib@go1.16.3
1.25.10

Open the chart page →

4,121
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
stdlib@go1.17.3
1.25.10

Open the chart page →

9,084
wg-access-servermglants0.4.71 of 1See more

wg-access-server mglants 0.4.7

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
stdlib@go1.13.8
1.25.10

Open the chart page →

2,741
gogsmhio0.9.21 of 2See more

gogs mhio 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
gogs/gogs:0.12.1420d53bb7277
stdlib@go1.14.7
1.25.10

Open the chart page →

3,227
postgresmicroboxlabs0.3.01 of 1See more

postgres microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/postgres:16.6557fea37a744
stdlib@go1.18.2
1.25.10

Open the chart page →

4,072
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.10

Open the chart page →

4,897
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.10

Open the chart page →

4,350
apimicroslacVerified publisher0.1.01 of 2See more

api microslac 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.1999213b98257
stdlib@go1.21.9
1.25.10

Open the chart page →

3,540
argomicroslacVerified publisher0.1.03 of 4See more

argo microslac 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.10
ghcr.io/dexidp/dex:v2.38.0b1d793440a98
stdlib@go1.21.6
1.25.10
quay.io/argoproj/argocd:v2.10.783c86003b781
stdlib@go1.20.10
1.25.10

Open the chart page →

10,158
streamsmicroslacVerified publisher0.1.01 of 6See more

streams microslac 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
microslac/kafka-connect:latesta90091a1f524
stdlib@go1.20.4
1.25.10

Open the chart page →

20,480
kube-agent-chartmiddleware-labsVerified publisher0.1.21 of 1See more

kube-agent-chart middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
stdlib@go1.18.9
1.25.10

Open the chart page →

1,798
middleware-odigosmiddleware-labsVerified publisher0.2.414 of 6See more

middleware-odigos middleware-labs 0.2.41

4 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
stdlib@go1.18.10
1.25.10
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
stdlib@go1.18.10
1.25.10
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
stdlib@go1.19.6
1.25.10
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
stdlib@go1.18.10
1.25.10

Open the chart page →

8,412
middleware-visionmiddleware-labsVerified publisher0.2.654 of 6See more

middleware-vision middleware-labs 0.2.65

4 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
stdlib@go1.18.10
1.25.10
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
stdlib@go1.18.10
1.25.10
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
stdlib@go1.19.7
1.25.10
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
stdlib@go1.18.10
1.25.10

Open the chart page →

8,404
mw-autoinstrumentationmiddleware-labsVerified publisher1.2.65 of 6See more

mw-autoinstrumentation middleware-labs 1.2.6

5 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-auto-injector:0.1.18512248e17e8
stdlib@go1.23.12
1.25.10
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
stdlib@go1.24.0
1.25.10
ghcr.io/middleware-labs/mw-lang-detector:0.1.2a4776aa2a56b
stdlib@go1.23.12
1.25.10
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.132.05e331c925091
stdlib@go1.24.6
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
stdlib@go1.24.2
1.25.10

Open the chart page →

3,777
mw-kube-agentmiddleware-labsVerified publisher0.1.21 of 1See more

mw-kube-agent middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
stdlib@go1.20.14
1.25.10

Open the chart page →

1,605
mw-kube-agent-v3middleware-labsVerified publisher1.8.62 of 2See more

mw-kube-agent-v3 middleware-labs 1.8.6

2 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.21.507011b628e6b
stdlib@go1.25.6
1.25.10
ghcr.io/middleware-labs/mw-kube-agent-config-updater:1.21.50a054cedfe30
stdlib@go1.25.6
1.25.10

Open the chart page →

1,380
sshportalmidokura-communityVerified publisher0.1.41 of 2See more

sshportal midokura-community 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
moul/sshportal:v1.19.3332b603727c3
stdlib@go1.17.6
1.25.10

Open the chart page →

2,322
argocd-extra-app-info-exportermikejohVerified publisher0.1.121 of 1See more

argocd-extra-app-info-exporter mikejoh 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
stdlib@go1.23.4
1.25.10

Open the chart page →

1,375
imaginemikejohVerified publisher0.2.01 of 1See more

imagine mikejoh 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
mikejoh/imagine:0.1.078737d7345f9
stdlib@go1.23.3
1.25.10

Open the chart page →

562
local-path-provisionermikejohVerified publisher0.0.291 of 1See more

local-path-provisioner mikejoh 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.299bebefa0b908
stdlib@go1.22.5
1.25.10

Open the chart page →

1,318
miniomilvus-helm8.0.201 of 1See more

minio milvus-helm 8.0.20

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
stdlib@go1.22.3
1.25.10

Open the chart page →

1,711
pulsarv2milvus-helm2.7.82 of 4See more

pulsarv2 milvus-helm 2.7.8

2 of the 4 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
stdlib@go1.13.10
1.25.10
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
stdlib@go1.13.4
1.25.10

Open the chart page →

15,919
mimirmimir0.1.101 of 1See more

mimir mimir 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
stdlib@go1.24.13
1.25.10

Open the chart page →

384
zkapps-dashboardminaVerified publisher0.1.21 of 2See more

zkapps-dashboard mina 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.25.10

Open the chart page →

1,689
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
stdlib@go1.24.6
1.25.10

Open the chart page →

13,414
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
stdlib@go1.17.4
1.25.10

Open the chart page →

6,126
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/postgres:13-alpinefb9065b6e3e2
stdlib@go1.24.6
1.25.10

Open the chart page →

115,176
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
stdlib@go1.19.7
1.25.10

Open the chart page →

10,854
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
stdlib@go1.19.7
1.25.10

Open the chart page →

10,854
helmmirasys-chart0.1.01 of 4See more

helm mirasys-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
stdlib@go1.24.6
1.25.10

Open the chart page →

3,842
jupyterhubmizzoukube0.0.1-set.by.chartpress1 of 7See more

jupyterhub mizzoukube 0.0.1-set.by.chartpress

1 of the 7 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
stdlib@go1.21.7
1.25.10

Open the chart page →

1,901
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
stdlib@go1.15.13
1.25.10

Open the chart page →

2,857
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
stdlib@go1.13.14
1.25.10

Open the chart page →

7,897
echoperatormmontesVerified publisher0.0.21 of 1See more

echoperator mmontes 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
stdlib@go1.18.3
1.25.10

Open the chart page →

1,830
mariadbmmontesVerified publisher0.3.01 of 1See more

mariadb mmontes 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mariadb:10.7.307e06f2e7ae9
stdlib@go1.16.7
1.25.10

Open the chart page →

10,340
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.25.10

Open the chart page →

7,305
basic-git-servermoikot0.0.21 of 1See more

basic-git-server moikot 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
moikot/basic-git-server:0.0.20d941bd30ffa
stdlib@go1.14.9
1.25.10

Open the chart page →

2,955
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
stdlib@go1.14.4
1.25.10

Open the chart page →

2,563
smartthings-metricsmoikot0.1.01 of 1See more

smartthings-metrics moikot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:0.1.08625f53aa9b7
stdlib@go1.14.13
1.25.10

Open the chart page →

1,748
smartthings-metrics-feat-log-detailsmoikot0.0.921 of 1See more

smartthings-metrics-feat-log-details moikot 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:feat-log-detailsfb8565140106
stdlib@go1.14.15
1.25.10

Open the chart page →

1,736
docker-registrymoinologics0.1.11 of 1See more

docker-registry moinologics 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/registry:2a3d8aaa63ed8
stdlib@go1.20.8
1.25.10

Open the chart page →

551
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
stdlib@go1.18.7
1.25.10

Open the chart page →

2,486
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.10

Open the chart page →

12,123
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.10

Open the chart page →

12,123
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.10

Open the chart page →

12,544
backendmojaloop0.1.05 of 6See more

backend mojaloop 0.1.0

5 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
stdlib@go1.18.2
1.25.10
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
stdlib@go1.17
1.25.10
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
stdlib@go1.23.8
1.25.10
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
stdlib@go1.16.4
1.25.10
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
stdlib@go1.21.5
1.25.10

Open the chart page →

16,583
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
stdlib@go1.24.6
1.25.10

Open the chart page →

19,779
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.25.10

Open the chart page →

6,376
mollysocketmollysocket-wrenixVerified publisher0.1.141 of 2See more

mollysocket mollysocket-wrenix 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.3c4a11ae9a1cb
stdlib@go1.25.7
1.25.10

Open the chart page →

2,653
eks-pod-identity-webhookmondu-aiVerified publisher0.3.11 of 1See more

eks-pod-identity-webhook mondu-ai 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
stdlib@go1.26.2
1.25.10

Open the chart page →

471

Container images carrying it

4,718 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.25.10
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.25.10
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.25.10
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.25.10
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.25.10
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.25.10
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
stdlib@go1.25.5
1.25.10
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.25.10
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.25.10
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
stdlib@go1.24.11
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.25.10
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.25.10
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.25.10
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.