StackRadar

CVE-2026-40898

Medium

Advisory

Published 3 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
129
of 17,781 indexed, latest versions
Container images
120
deployed by those charts
Fix available
1 of 1
affected package

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

Carried by container images the latest versions of 129 of 17,781 indexed charts deploy, on 120 images.

Affected packageAffected versionsFixed inImages
github.com/quic-go/quic-gogolangv0.32.0, v0.33.0, v0.37.5, v0.38.1+27 more0.59.1120
OSV records
GHSA-vvgj-x9jq-8cj9
Also known as
GO-2026-5676

Charts affected

129 by stars
ChartLatestAffected imagesRadar Score
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
github.com/quic-go/quic-go@v0.38.1
0.59.1

Open the chart page →

2,101
novosgamarcusrepo0.1.11 of 2See more

novosga marcusrepo 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
novosga/novosga:latest34b9acbe6e51
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

3,706
eks-pod-identity-webhookmondu-aiVerified publisher0.3.11 of 1See more

eks-pod-identity-webhook mondu-ai 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
github.com/quic-go/quic-go@v0.54.0
0.59.1

Open the chart page →

474
adguard-homemt1905024.0.121 of 2See more

adguard-home mt190502 4.0.12

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.737fbf01d73ecb
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,166
dify-enterpriseopenshift3.9.81 of 13See more

dify-enterprise openshift 3.9.8

1 of the 13 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
github.com/quic-go/quic-go@v0.57.1
0.59.1

Open the chart page →

4,660
harikubeopenshift0.16.31 of 3See more

harikube openshift 0.16.3

1 of the 3 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/quic-go/quic-go@v0.58.0
0.59.1

Open the chart page →

2,525
gitlab-proxyopslevelVerified publisher0.0.81 of 1See more

gitlab-proxy opslevel 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
library/caddy:2.660fb54d36b4b
github.com/quic-go/quic-go@v0.32.0
0.59.1

Open the chart page →

1,872
cloudflare-tunnelportefaix-hub0.4.01 of 1See more

cloudflare-tunnel portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.8.314d9c6b01b29
github.com/quic-go/quic-go@v0.45.0
0.59.1

Open the chart page →

1,306
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
github.com/quic-go/quic-go@v0.46.0
0.59.1

Open the chart page →

7,084
geopingrotationalVerified publisher1.3.21 of 1See more

geoping rotational 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rotationalio/geoping:1.3.034bcb6fc3cb7
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,569
rotational-apirotationalVerified publisher1.3.11 of 1See more

rotational-api rotational 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rotationalio/rotational-api:1.3.0f1a2d05d8fff
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,567
chainrss30.1.281 of 8See more

chain rss3 0.1.28

1 of the 8 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

8,528
vsl-chainrss30.1.01 of 7See more

vsl-chain rss3 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

6,044
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

4,610
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

4,610
gotifyrubxkubeVerified publisher1.3.31 of 1See more

gotify rubxkube 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
gotify/server:3.1.0be44495e4609
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

320
tailscalesinextraVerified publisher0.18.11 of 2See more

tailscale sinextra 0.18.1

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
github.com/quic-go/quic-go@v0.57.0
0.59.1

Open the chart page →

1,047
deeplxsnubisks0.1.01 of 1See more

deeplx snubisks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
missuo/deeplx:v1.2.232e492587678
github.com/quic-go/quic-go@v0.57.1
0.59.1

Open the chart page →

479
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/quic-go@v0.49.0
0.59.1

Open the chart page →

1,239
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/quic-go/quic-go@v0.46.0
0.59.1

Open the chart page →

6,779
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/quic-go@v0.49.0
0.59.1

Open the chart page →

1,239
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

576
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
github.com/quic-go/quic-go@v0.40.1
0.59.1

Open the chart page →

2,336
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:lateste753ff9f3fc4
github.com/quic-go/quic-go@v0.57.1
0.59.1

Open the chart page →

6,973
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/quic-go/quic-go@v0.32.0
0.59.1

Open the chart page →

2,015
proxyv2flyVerified publisher0.0.61 of 1See more

proxy v2fly 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
v2fly/v2fly-core:latestd06727b221fe
github.com/quic-go/quic-go@v0.55.0
0.59.1

Open the chart page →

1,426
corednsvks-helm-chartsVerified publisher1.45.01 of 1See more

coredns vks-helm-charts 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
github.com/quic-go/quic-go@v0.55.0
0.59.1

Open the chart page →

887
wardnwardnVerified publisher0.1.01 of 3See more

wardn wardn 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/happymooguild/wardn-backend:0.1.023ee1b8cfc3c
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

86
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,456

Container images carrying it

120 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
github.com/quic-go/quic-go@v0.48.2
0.59.1
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
github.com/quic-go/quic-go@v0.46.0
0.59.1
1
ghcr.io/kite-org/kite:v0.15.14e4d09552f91
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
ghcr.io/kubenetworks/kubevpn:v2.11.7cce8ff866f60
github.com/quic-go/quic-go@v0.50.1
0.59.1
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
github.com/quic-go/quic-go@v0.44.0
0.59.1
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
github.com/quic-go/quic-go@v0.38.1
0.59.1
1
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
github.com/quic-go/quic-go@v0.54.0
0.59.1
1
ghcr.io/okteto/okteto:3.22.0-beta.1e787b6bce27d
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
github.com/quic-go/quic-go@v0.39.0
0.59.1
1
ghcr.io/wasilak/go-hello-world:1.8.366d353e7693f
github.com/quic-go/quic-go@v0.57.1
0.59.1
1
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/quic-go/quic-go@v0.32.0
0.59.1
1
quay.io/backube/volsync:0.16.00d03a6aad575
github.com/quic-go/quic-go@v0.52.0
0.59.1
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/quic-go/quic-go@v0.58.0
0.59.1
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
github.com/quic-go/quic-go@v0.37.5
0.59.1
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
github.com/quic-go/quic-go@v0.57.0
0.59.1
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
github.com/quic-go/quic-go@v0.55.0
0.59.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.