StackRadar

CVE-2026-39836

High

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,218
of 17,985 indexed, latest versions
Container images
4,748
deployed by those charts
Fix available
1 of 1
affected package

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Carried by container images the latest versions of 4,218 of 17,985 indexed charts deploy, on 4,748 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+183 more1.25.104,748
OSV records
GO-2026-4971
Also known as
BIT-golang-2026-39836

Charts affected

4,218 by stars
ChartLatestAffected imagesRadar Score
galoygaloymoney0.34.74 of 24See more

galoy galoymoney 0.34.7

4 of the 24 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.25.10
oryd/hydra:v2.2.02c93beb5e5f2
stdlib@go1.21.5
1.25.10
oryd/kratos:v1.0.0d06fc5845f63
stdlib@go1.20.5
1.25.10
oryd/oathkeeper:v0.40.6e8cb9b79a89c
stdlib@go1.20.5
1.25.10

Open the chart page →

10,983
galoy-depsgaloymoney0.10.208 of 9See more

galoy-deps galoymoney 0.10.20

8 of the 9 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
stdlib@go1.18.9
1.25.10
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
stdlib@go1.23.2
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
stdlib@go1.21.7
1.25.10
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
stdlib@go1.21.7
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
stdlib@go1.21.7
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
stdlib@go1.21.7
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.25.10

Open the chart page →

16,054
lndgaloymoney0.10.61 of 3See more

lnd galoymoney 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
stdlib@go1.22.5
1.25.10

Open the chart page →

2,549
monitoringgaloymoney0.12.215 of 6See more

monitoring galoymoney 0.12.21

5 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
stdlib@go1.23.1
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
stdlib@go1.23.2
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.10
quay.io/prometheus/prometheus:v2.55.0378f4e037035
stdlib@go1.23.2
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.10

Open the chart page →

7,131
galoygaloymoney20.34.74 of 24See more

galoy galoymoney2 0.34.7

4 of the 24 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.25.10
oryd/hydra:v2.2.02c93beb5e5f2
stdlib@go1.21.5
1.25.10
oryd/kratos:v1.0.0d06fc5845f63
stdlib@go1.20.5
1.25.10
oryd/oathkeeper:v0.40.6e8cb9b79a89c
stdlib@go1.20.5
1.25.10

Open the chart page →

10,983
galoy-depsgaloymoney20.10.208 of 9See more

galoy-deps galoymoney2 0.10.20

8 of the 9 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
stdlib@go1.18.9
1.25.10
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
stdlib@go1.23.2
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
stdlib@go1.21.7
1.25.10
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
stdlib@go1.21.7
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
stdlib@go1.21.7
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
stdlib@go1.21.7
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
stdlib@go1.20.5
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.25.10

Open the chart page →

16,054
lndgaloymoney20.10.61 of 3See more

lnd galoymoney2 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
stdlib@go1.22.5
1.25.10

Open the chart page →

2,549
monitoringgaloymoney20.12.215 of 6See more

monitoring galoymoney2 0.12.21

5 of the 6 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
stdlib@go1.23.1
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
stdlib@go1.23.2
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.25.10
quay.io/prometheus/prometheus:v2.55.0378f4e037035
stdlib@go1.23.2
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.25.10

Open the chart page →

7,131
gameserver-operatorgameserver-operator0.3.01 of 1See more

gameserver-operator gameserver-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/idebeijer/gameserver-operator:latest1b099cfe9e5e
stdlib@go1.25.7
1.25.10

Open the chart page →

567
pagesgary-pages1.0.01 of 3See more

pages gary-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

21,119
alertmanager-discordgeek-cookbookVerified publisher1.3.21 of 1See more

alertmanager-discord geek-cookbook 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
rogerrum/alertmanager-discord:1.0.3827593369625
stdlib@go1.17.4
1.25.10

Open the chart page →

1,825
anonaddygeek-cookbookVerified publisher6.0.01 of 1See more

anonaddy geek-cookbook 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.25.10

Open the chart page →

5,545
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
stdlib@go1.18.4
1.25.10

Open the chart page →

16,026
autobrrgeek-cookbookVerified publisher1.1.31 of 1See more

autobrr geek-cookbook 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
stdlib@go1.19.3
1.25.10

Open the chart page →

2,888
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
stdlib@go1.16.7
1.25.10

Open the chart page →

17,851
dendritegeek-cookbookVerified publisher6.4.01 of 1See more

dendrite geek-cookbook 6.4.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
stdlib@go1.18.5
1.25.10

Open the chart page →

2,886
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:lateste1fdac6133ad
stdlib@go1.24.9
1.25.10

Open the chart page →

2,157
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
stdlib@go1.15
1.25.10

Open the chart page →

9,786
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
stdlib@go1.18.1
1.25.10

Open the chart page →

2,719
gonicgeek-cookbookVerified publisher6.4.21 of 1See more

gonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
sentriz/gonic:v0.13.1a74012a6adf3
stdlib@go1.16.4
1.25.10

Open the chart page →

4,570
gotifygeek-cookbookVerified publisher1.2.21 of 1See more

gotify geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
gotify/server:2.1.409c79bc1e403
stdlib@go1.16
1.25.10

Open the chart page →

4,673
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
stdlib@go1.15
1.25.10

Open the chart page →

12,397
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
stdlib@go1.18.3
1.25.10

Open the chart page →

10,849
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
stdlib@go1.16.7
1.25.10

Open the chart page →

15,712
maddygeek-cookbookVerified publisher3.2.01 of 1See more

maddy geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
foxcpp/maddy:v0.5.28fa2bd8f6830
stdlib@go1.17.2
1.25.10

Open the chart page →

3,549
minifluxgeek-cookbookVerified publisher5.2.01 of 2See more

miniflux geek-cookbook 5.2.0

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
miniflux/miniflux:2.0.36e2fb990dae74
stdlib@go1.17.8
1.25.10

Open the chart page →

3,272
navidromegeek-cookbookVerified publisher6.4.21 of 1See more

navidrome geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
deluan/navidrome:0.43.04e9ae3bff6aa
stdlib@go1.16.4
1.25.10

Open the chart page →

4,695
nullservgeek-cookbookVerified publisher2.4.21 of 1See more

nullserv geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nullserv:v1.3.00792c7e6d814
stdlib@go1.16.5
1.25.10

Open the chart page →

1,952
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
stdlib@go1.18.4
1.25.10

Open the chart page →

13,377
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
stdlib@go1.15
1.25.10

Open the chart page →

19,181
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
stdlib@go1.16.5
1.25.10

Open the chart page →

4,252
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
stdlib@go1.18.3
1.25.10

Open the chart page →

21,247
pod-gatewaygeek-cookbookVerified publisher5.6.21 of 2See more

pod-gateway geek-cookbook 5.6.2

1 of the 2 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v3.5.0175512bb3f61
stdlib@go1.18.3
1.25.10

Open the chart page →

3,119
pod-gateway-settergeek-cookbookVerified publisher1.0.01 of 1See more

pod-gateway-setter geek-cookbook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
stdlib@go1.16.4
1.25.10

Open the chart page →

2,605
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.25.10

Open the chart page →

13,257
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
stdlib@go1.18.4
1.25.10

Open the chart page →

11,463
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.25.10

Open the chart page →

8,955
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
stdlib@go1.18.1
1.25.10

Open the chart page →

4,387
searxgeek-cookbookVerified publisher5.6.23 of 4See more

searx geek-cookbook 5.6.2

3 of the 4 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.25.10
dalf/morty:latest248a4849c350
stdlib@go1.18.2
1.25.10
library/caddy:2.2.0-alpine7367adca165f
stdlib@go1.15.2
1.25.10

Open the chart page →

10,079
skypilotgeek-cookbookVerified publisher0.0.13 of 3See more

skypilot geek-cookbook 0.0.1

3 of the 3 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
stdlib@go1.23.5
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
stdlib@go1.24.4
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
stdlib@go1.24.4
1.25.10

Open the chart page →

10,686
torrservergeek-cookbookVerified publisher1.2.21 of 1See more

torrserver geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
smailkoz/torrserver:1.0.1117b52d15de8f0
stdlib@go1.17.5
1.25.10

Open the chart page →

4,024
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
stdlib@go1.18.4
1.25.10

Open the chart page →

13,106
vikunjageek-cookbookVerified publisher6.2.02 of 4See more

vikunja geek-cookbook 6.2.0

2 of the 4 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
library/caddy:2.4.2-alpinefbc51bcf1ab0
stdlib@go1.16.5
1.25.10
vikunja/api:0.17.18cba0520bf8c
stdlib@go1.16.5
1.25.10

Open the chart page →

9,512
webhook-receivergeek-cookbookVerified publisher0.0.11 of 1See more

webhook-receiver geek-cookbook 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
stdlib@go1.21.3
1.25.10

Open the chart page →

1,879
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.25.10

Open the chart page →

19,645
asynqmongeneral-helm-chartsVerified publisher0.0.11 of 1See more

asynqmon general-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
hibiken/asynqmon:latestac80bcffd2f9
stdlib@go1.18.10
1.25.10

Open the chart page →

1,285
cbtgeneral-helm-chartsVerified publisher0.0.51 of 1See more

cbt general-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ethpandaops/cbt:latest5377ffb3091a
stdlib@go1.26.1
1.25.10

Open the chart page →

781
chproxygeneral-helm-chartsVerified publisher0.0.21 of 1See more

chproxy general-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
contentsquareplatform/chproxy:v1.26.524555f22d4be
stdlib@go1.22.7
1.25.10

Open the chart page →

4,284
dispatchoor-apigeneral-helm-chartsVerified publisher0.1.11 of 1See more

dispatchoor-api general-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
stdlib@go1.24.13
1.25.10

Open the chart page →

1,103
panda-pulsegeneral-helm-chartsVerified publisher1.0.61 of 1See more

panda-pulse general-helm-charts 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-39836.

Container imageDigestPackageFixed in
ethpandaops/panda-pulse:latestad6fc3b3e6b8
stdlib@go1.26.1
1.25.10

Open the chart page →

820

Container images carrying it

4,748 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

No deployed image carries CVE-2026-39836.

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.