StackRadar

CVE-2026-39836

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,193
of 18,026 indexed, latest versions
Container images
4,734
deployed by those charts
Fix available
1 of 1
affected package

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Carried by container images the latest versions of 4,193 of 18,026 indexed charts deploy, on 4,734 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+183 more1.25.104,734
OSV records
GO-2026-4971
Also known as
BIT-golang-2026-39836

Charts affected

4,193 by stars
ChartLatestAffected imagesRadar Score
matomohelmforgeVerified publisher2.3.21 of 3See more

matomo helmforge 2.3.2

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:26.7.0ade067ae2fb1
stdlib@go1.24.6
1.25.10

Open the chart page →

3,108
uptime-kumahelmforgeVerified publisher1.5.151 of 1See more

uptime-kuma helmforge 1.5.15

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.5c74379ac4509
stdlib@go1.20.5
1.25.10

Open the chart page →

34,014
velerohelmforgeVerified publisher1.4.121 of 2See more

velero helmforge 1.4.12

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
velero/velero-plugin-for-aws:v1.14.07e82f717f44e
stdlib@go1.25.7
1.25.10

Open the chart page →

1,507
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
stdlib@go1.19.6
1.25.10

Open the chart page →

5,249
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
stdlib@go1.15.12
1.25.10

Open the chart page →

8,137
spirehelm-spireVerified publisher0.30.23 of 10See more

spire helm-spire 0.30.2

3 of the 10 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
stdlib@go1.24.0
1.25.10
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
stdlib@go1.25.3
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
stdlib@go1.24.6
1.25.10

Open the chart page →

2,639
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
stdlib@go1.20.4
1.25.10

Open the chart page →

18,438
hiverhiverVerified publisher0.1.459 of 10See more

hiver hiver 0.1.45

9 of the 10 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
hiversh/antigravity:0.1.45-microvm0e36d98402bc
stdlib@go1.19.8
1.25.10
hiversh/browser:0.1.45-microvmb5048c6342ce
stdlib@go1.19.8
1.25.10
hiversh/claude:0.1.45-microvm2fbf9f264498
stdlib@go1.19.8
1.25.10
hiversh/codex:0.1.45-microvm4f43130f51e5
stdlib@go1.19.8
1.25.10
hiversh/controller:0.1.45b0b85f8942c7
stdlib@go1.19.8
1.25.10
hiversh/copilot:0.1.45-microvm50c07b84f298
stdlib@go1.19.8
1.25.10
hiversh/node:0.1.45-alpine-microvm836a37641941
stdlib@go1.19.8
1.25.10
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
stdlib@go1.19.8
1.25.10
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
stdlib@go1.19.8
1.25.10

Open the chart page →

28,300
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
stdlib@go1.16.3
1.25.10

Open the chart page →

3,915
holoinsightholoinsight0.2.52 of 6See more

holoinsight holoinsight 0.2.5

2 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
holoinsight/otelcontribcol:latest42ba8dc3113c
stdlib@go1.19
1.25.10
library/mysql:86ea90827b110
stdlib@go1.24.6
1.25.10

Open the chart page →

29,661
holoinsight-agentholoinsight0.2.51 of 2See more

holoinsight-agent holoinsight 0.2.5

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
holoinsight/agent:latest5c3994e742f8
stdlib@go1.22.1
1.25.10

Open the chart page →

2,279
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.25.10

Open the chart page →

8,740
honeycombhoneycomb1.9.41 of 1See more

honeycomb honeycomb 1.9.4

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
honeycombio/honeycomb-kubernetes-agent:2.8.044bfbb103ebb
stdlib@go1.24.13
1.25.10

Open the chart page →

493
hpe-greenlake-file-csi-driverhpe-storageVerified publisher2.6.45 of 7See more

hpe-greenlake-file-csi-driver hpe-storage 2.6.4

5 of the 7 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
stdlib@go1.23.1
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
stdlib@go1.24.6
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
stdlib@go1.24.6
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
stdlib@go1.24.6
1.25.10

Open the chart page →

8,120
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
stdlib@go1.21.12
1.25.10

Open the chart page →

4,946
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
stdlib@go1.17.2
1.25.10

Open the chart page →

2,478
hybrid-csi-pluginhybrid-csi-plugin0.1.121 of 1See more

hybrid-csi-plugin hybrid-csi-plugin 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/hybrid-csi-provisioner:v0.3.1221e07794a8a
stdlib@go1.25.5
1.25.10

Open the chart page →

597
spoolmanideaplexusVerified publisher2.10.21 of 1See more

spoolman ideaplexus 2.10.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.27.07aba565eff77
stdlib@go1.19.8
1.25.10

Open the chart page →

2,433
backendikusi-bk-chart1.0.31 of 3See more

backend ikusi-bk-chart 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/postgres:15724292da1f2e
stdlib@go1.24.6
1.25.10

Open the chart page →

6,729
ilum-coreilumOfficialVerified publisher6.7.32 of 5See more

ilum-core ilum 6.7.3

2 of the 5 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
stdlib@go1.24.6
1.25.10
ilum/mongodb:6.0.542b6d774c37d
stdlib@go1.20.12
1.25.10

Open the chart page →

4,610
ilum-jupyterilumVerified publisher6.7.31 of 2See more

ilum-jupyter ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
bitnamisecure/gitdigest-pinned72ae5bd9715f
stdlib@go1.24.6
1.25.10

Open the chart page →

934
odooimioVerified publisher3.2.11 of 3See more

odoo imio 3.2.1

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/postgres:17.10ebba4f4de37f
stdlib@go1.24.6
1.25.10

Open the chart page →

3,679
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.25.10

Open the chart page →

18,204
webhook-broker-chartimytech0.2.41 of 1See more

webhook-broker-chart imytech 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
stdlib@go1.23.0
1.25.10

Open the chart page →

1,632
inbucketinbucketVerified publisher2.5.01 of 1See more

inbucket inbucket 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
inbucket/inbucket:3.0.01f10a0efea69
stdlib@go1.17.1
1.25.10

Open the chart page →

3,067
inference-manager-serverinference-manager-server1.46.01 of 1See more

inference-manager-server inference-manager-server 1.46.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/inference-manager-server:1.46.00bbb5f5ddf71
stdlib@go1.25.9
1.25.10

Open the chart page →

418
telegraf-operatorinfluxdata1.4.01 of 1See more

telegraf-operator influxdata 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
stdlib@go1.18.10
1.25.10

Open the chart page →

1,542
valkey-clusterinnagoVerified publisher1.1.01 of 2See more

valkey-cluster innago 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.66.0d98e6db8094f
stdlib@go1.23.2
1.25.10

Open the chart page →

3,138
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
stdlib@go1.25.5
1.25.10

Open the chart page →

9,113
interlinkinterlink0.6.11 of 2See more

interlink interlink 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/interlink-hq/interlink/virtual-kubelet-inttw:latest0e05a7b49c33
stdlib@go1.24.5
1.25.10

Open the chart page →

3,001
irsa-managerirsa-managerVerified publisher0.3.21 of 1See more

irsa-manager irsa-manager 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/kkb0318/irsa-manager:0.3.296d600ae97b4
stdlib@go1.22.7
1.25.10

Open the chart page →

1,165
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
stdlib@go1.16.6
1.25.10

Open the chart page →

75,543
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
stdlib@go1.16.6
1.25.10

Open the chart page →

75,614
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.25.10

Open the chart page →

75,559
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.25.10

Open the chart page →

75,559
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
stdlib@go1.16.6
1.25.10

Open the chart page →

75,849
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
stdlib@go1.14.15
1.25.10

Open the chart page →

2,802
kubernetes-event-exporteritakurahVerified publisher0.2.31 of 1See more

kubernetes-event-exporter itakurah 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/itakurah/kubernetes-event-exporter:v1.78abb52b66557
stdlib@go1.20.14
1.25.10

Open the chart page →

1,588
statpingitscontainedVerified publisher0.1.91 of 1See more

statping itscontained 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
statping/statping:v0.90.6532f26fffca46
stdlib@go1.14.8
1.25.10

Open the chart page →

4,562
traefik-forward-authitscontainedVerified publisher1.0.21 of 1See more

traefik-forward-auth itscontained 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
stdlib@go1.13.12
1.25.10

Open the chart page →

3,287
jessejesse-chartVerified publisher0.0.461 of 6See more

jesse jesse-chart 0.0.46

1 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.25.10

Open the chart page →

3,197
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
stdlib@go1.17.13
1.25.10

Open the chart page →

10,577
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
stdlib@go1.21.8
1.25.10

Open the chart page →

8,295
forecastlejmmaloney41.1.1201 of 1See more

forecastle jmmaloney4 1.1.120

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
stakater/forecastle:v1.0.13886b24cdef409
stdlib@go1.22.1
1.25.10

Open the chart page →

2,293
rclonejmmaloney42.3.211 of 1See more

rclone jmmaloney4 2.3.21

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
rclone/rclone:1.66.0a693c46a6b8b
stdlib@go1.22.1
1.25.10

Open the chart page →

2,208
job-manager-dispatcherjob-manager-dispatcher1.27.01 of 1See more

job-manager-dispatcher job-manager-dispatcher 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
stdlib@go1.23.12
1.25.10

Open the chart page →

767
hncjouveVerified publisher0.8.31 of 1See more

hnc jouve 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-multitenancy/hnc-manager:v1.1.08ab8229f6a89
stdlib@go1.20.5
1.25.10

Open the chart page →

1,565
joylive-injectorjoyliveOfficialVerified publisher1.3.51 of 2See more

joylive-injector joylive 1.3.5

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
otel/opentelemetry-collector:0.100.09e36620d6c2c
stdlib@go1.22.2
1.25.10

Open the chart page →

1,679
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
stdlib@go1.18.7
1.25.10

Open the chart page →

4,181
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.3211 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

11 of the 17 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
grafana/alloy:v1.14.0f50931848bd8
stdlib@go1.25.7
1.25.10
grafana/grafana:12.3.12175aaa91c96
stdlib@go1.25.5
1.25.10
grafana/loki:3.6.73c8fd3570dd9
stdlib@go1.24.13
1.25.10
grafana/loki-canary:3.6.70dac7d5cb383
stdlib@go1.24.13
1.25.10
grafana/tempo:2.9.065a578975943
stdlib@go1.25.1
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
stdlib@go1.23.7
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.89.0cb4ac6a56555
stdlib@go1.25.6
1.25.10
quay.io/prometheus/alertmanager:v0.31.188b605de9aba
stdlib@go1.25.7
1.25.10
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
stdlib@go1.25.3
1.25.10
quay.io/prometheus/prometheus:v3.10.07571a304e67f
stdlib@go1.26.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
stdlib@go1.25.5
1.25.10

Open the chart page →

16,298

Container images carrying it

4,734 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

No deployed image carries CVE-2026-39836.

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.