StackRadar

CVE-2026-40898

Medium

Advisory

Published 3 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
129
of 17,781 indexed, latest versions
Container images
120
deployed by those charts
Fix available
1 of 1
affected package

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

Carried by container images the latest versions of 129 of 17,781 indexed charts deploy, on 120 images.

Affected packageAffected versionsFixed inImages
github.com/quic-go/quic-gogolangv0.32.0, v0.33.0, v0.37.5, v0.38.1+27 more0.59.1120
OSV records
GHSA-vvgj-x9jq-8cj9
Also known as
GO-2026-5676

Charts affected

129 by stars
ChartLatestAffected imagesRadar Score
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
github.com/quic-go/quic-go@v0.38.1
0.59.1

Open the chart page →

2,101
novosgamarcusrepo0.1.11 of 2See more

novosga marcusrepo 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
novosga/novosga:latest34b9acbe6e51
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

3,706
eks-pod-identity-webhookmondu-aiVerified publisher0.3.11 of 1See more

eks-pod-identity-webhook mondu-ai 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
github.com/quic-go/quic-go@v0.54.0
0.59.1

Open the chart page →

474
adguard-homemt1905024.0.121 of 2See more

adguard-home mt190502 4.0.12

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.737fbf01d73ecb
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,166
dify-enterpriseopenshift3.9.81 of 13See more

dify-enterprise openshift 3.9.8

1 of the 13 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
github.com/quic-go/quic-go@v0.57.1
0.59.1

Open the chart page →

4,660
harikubeopenshift0.16.31 of 3See more

harikube openshift 0.16.3

1 of the 3 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/quic-go/quic-go@v0.58.0
0.59.1

Open the chart page →

2,525
gitlab-proxyopslevelVerified publisher0.0.81 of 1See more

gitlab-proxy opslevel 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
library/caddy:2.660fb54d36b4b
github.com/quic-go/quic-go@v0.32.0
0.59.1

Open the chart page →

1,872
cloudflare-tunnelportefaix-hub0.4.01 of 1See more

cloudflare-tunnel portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.8.314d9c6b01b29
github.com/quic-go/quic-go@v0.45.0
0.59.1

Open the chart page →

1,306
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
github.com/quic-go/quic-go@v0.46.0
0.59.1

Open the chart page →

7,084
geopingrotationalVerified publisher1.3.21 of 1See more

geoping rotational 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rotationalio/geoping:1.3.034bcb6fc3cb7
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,569
rotational-apirotationalVerified publisher1.3.11 of 1See more

rotational-api rotational 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rotationalio/rotational-api:1.3.0f1a2d05d8fff
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,567
chainrss30.1.281 of 8See more

chain rss3 0.1.28

1 of the 8 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

8,528
vsl-chainrss30.1.01 of 7See more

vsl-chain rss3 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

6,044
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

4,610
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

4,610
gotifyrubxkubeVerified publisher1.3.31 of 1See more

gotify rubxkube 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
gotify/server:3.1.0be44495e4609
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

320
tailscalesinextraVerified publisher0.18.11 of 2See more

tailscale sinextra 0.18.1

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
github.com/quic-go/quic-go@v0.57.0
0.59.1

Open the chart page →

1,047
deeplxsnubisks0.1.01 of 1See more

deeplx snubisks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
missuo/deeplx:v1.2.232e492587678
github.com/quic-go/quic-go@v0.57.1
0.59.1

Open the chart page →

479
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/quic-go@v0.49.0
0.59.1

Open the chart page →

1,239
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/quic-go/quic-go@v0.46.0
0.59.1

Open the chart page →

6,779
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/quic-go@v0.49.0
0.59.1

Open the chart page →

1,239
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

576
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
github.com/quic-go/quic-go@v0.40.1
0.59.1

Open the chart page →

2,336
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:lateste753ff9f3fc4
github.com/quic-go/quic-go@v0.57.1
0.59.1

Open the chart page →

6,973
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/quic-go/quic-go@v0.32.0
0.59.1

Open the chart page →

2,015
proxyv2flyVerified publisher0.0.61 of 1See more

proxy v2fly 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
v2fly/v2fly-core:latestd06727b221fe
github.com/quic-go/quic-go@v0.55.0
0.59.1

Open the chart page →

1,426
corednsvks-helm-chartsVerified publisher1.45.01 of 1See more

coredns vks-helm-charts 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
github.com/quic-go/quic-go@v0.55.0
0.59.1

Open the chart page →

887
wardnwardnVerified publisher0.1.01 of 3See more

wardn wardn 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/happymooguild/wardn-backend:0.1.023ee1b8cfc3c
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

86
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,456

Container images carrying it

120 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/blackbox-exporter:latest:v0.28.0e753ff9f3fc4
github.com/quic-go/quic-go@v0.57.1
0.59.1
5
rancher/rancher:v2.15.15f6c4dc52a05
github.com/quic-go/quic-go@v0.59.0
0.59.1
4
caddy/ingress:v0.2.118d1366fc0e9
github.com/quic-go/quic-go@v0.40.0
0.59.1
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.59.1
3
coredns/coredns:1.13.19b9128672209
github.com/quic-go/quic-go@v0.55.0
0.59.1
2
gotify/server:3.1.0be44495e4609
github.com/quic-go/quic-go@v0.59.0
0.59.1
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
github.com/quic-go/quic-go@v0.40.0
0.59.1
2
ipfs/ipfs-cluster:latest:v1.1.6a83266c524f1
github.com/quic-go/quic-go@v0.59.0
0.59.1
2
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/quic-go@v0.49.0
0.59.1
2
library/traefik:v3.7.16b9cbca6fac4
github.com/quic-go/quic-go@v0.59.0
0.59.1
2
obolnetwork/charon:v1.10.0278c7e2897b6
github.com/quic-go/quic-go@v0.59.0
0.59.1
2
syncthing/syncthing:2.1.1775c4aac4862
github.com/quic-go/quic-go@v0.59.0
0.59.1
2
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
github.com/quic-go/quic-go@v0.54.0
0.59.1
2
adguard/adguardhome:v0.107.513a143e6c071c
github.com/quic-go/quic-go@v0.44.0
0.59.1
1
adguard/adguardhome:v0.107.3843ec119419a9
github.com/quic-go/quic-go@v0.38.1
0.59.1
1
adguard/adguardhome:v0.107.595d5e3aef39a8
github.com/quic-go/quic-go@v0.49.0
0.59.1
1
adguard/adguardhome:v0.107.767157eb1dc3b2
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
adguard/adguardhome:v0.107.737fbf01d73ecb
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
adguard/adguardhome:v0.107.56c64a0b37f7b9
github.com/quic-go/quic-go@v0.48.2
0.59.1
1
adguard/adguardhome:v0.107.65d765078d2140
github.com/quic-go/quic-go@v0.53.0
0.59.1
1
b3log/siyuan:v3.1.2595c0d129bc19
github.com/quic-go/quic-go@v0.50.0
0.59.1
1
baserow/baserow:1.30.1df0c42eb67e8
github.com/quic-go/quic-go@v0.40.0
0.59.1
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/quic-go/quic-go@v0.46.0
0.59.1
1
bluenviron/mediamtx:1.17.19e39256d1ba3
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
castopod/castopod:1.15.54e4f0440520f
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
cloudflare/cloudflared:2024.8.314d9c6b01b29
github.com/quic-go/quic-go@v0.45.0
0.59.1
1
cloudflare/cloudflared:2024.5.05d5f70a59d5e
github.com/quic-go/quic-go@v0.42.0
0.59.1
1
coredns/coredns:1.12.040384aa1f5ea
github.com/quic-go/quic-go@v0.48.1
0.59.1
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
github.com/quic-go/quic-go@v0.54.0
0.59.1
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
github.com/quic-go/quic-go@v0.57.1
0.59.1
1
ethersphere/bee:2.2.0a884fd84b72f
github.com/quic-go/quic-go@v0.42.0
0.59.1
1
ethpandaops/armiarma:master1a9c3264f0a9
github.com/quic-go/quic-go@v0.42.0
0.59.1
1
ethpandaops/forky:debian-latestc937f4ba737c
github.com/quic-go/quic-go@v0.51.0
0.59.1
1
evcc/evcc:0.300.8ddf2a25afce5
github.com/quic-go/quic-go@v0.57.0
0.59.1
1
gotify/server:2.9.1a3af47067ce6
github.com/quic-go/quic-go@v0.55.0
0.59.1
1
hiversh/antigravity:0.1.45-microvm0e36d98402bc
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
hiversh/browser:0.1.45-microvmb5048c6342ce
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
hiversh/claude:0.1.45-microvm2fbf9f264498
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
hiversh/codex:0.1.45-microvm4f43130f51e5
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
hiversh/controller:0.1.45b0b85f8942c7
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
hiversh/copilot:0.1.45-microvm50c07b84f298
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
hiversh/node:0.1.45-alpine-microvm836a37641941
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
github.com/quic-go/quic-go@v0.40.0
0.59.1
1
iotaledger/hornet:2.001206f1ba89c
github.com/quic-go/quic-go@v0.38.1
0.59.1
1
ipfs/kubo:v0.41.00661819c2e09
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
ipfs/kubo:v0.24.0e3de33bd746b
github.com/quic-go/quic-go@v0.39.3
0.59.1
1
kayrosuno/kping:latestf3bd44b29b0d
github.com/quic-go/quic-go@v0.56.0
0.59.1
1
kubeedge/edgemesh-agent:latest460c6061b608
github.com/quic-go/quic-go@v0.33.0
0.59.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.