CVE-2026-107386
MediumAdvisory
Published 8 Oct 2026In the index since 9 Oct 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.3
- base score, highest
- EPSS
- —
- probability of exploitation
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 101
- of 18,071 indexed, latest versions
- Container images
- 90
- deployed by those charts
- Fix available
- 1 of 1
- affected package
amqp091-go: Pre-negotiation frame limit is not enforced to 4KB
Carried by container images the latest versions of 101 of 18,071 indexed charts deploy, on 90 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v1.1.0, v1.5.0, v1.6.1, v1.8.1+5 more | 1.14.0 | 90 |
- OSV records
- GHSA-w6r9-248c-frg8
Charts affected
101 by stars
Container images carrying it
90 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 6d4c9fe66e4f | github.com/ | 1.14.0 | 4 |
| ghcr.io/ | e7041c3b41e7 | github.com/ | 1.14.0 | 4 |
| cloudpirates/ | 8dc02a7e5093 | github.com/ | 1.14.0 | 3 |
| pgsty/ | b616a0cf8cb2 | github.com/ | 1.14.0 | 3 |
| tykio/ | 1161bd297135 | github.com/ | 1.14.0 | 3 |
| tykio/ | 50b3e4f5398a | github.com/ | 1.14.0 | 3 |
| quay.io/ | fa07b2c9ece6 | github.com/ | 1.14.0 | 3 |
| devopsfaith/ | f8bdaa8a1a43 | github.com/ | 1.14.0 | 2 |
| frinx/ | bf8edd4f52f3 | github.com/ | 1.14.0 | 2 |
| openebs/ | bb04e41fc1b8 | github.com/ | 1.14.0 | 2 |
| otel/ | 799dc6cf12c9 | github.com/ | 1.14.0 | 2 |
| otel/ | a7343f018690 | github.com/ | 1.14.0 | 2 |
| otel/ | fd328de25524 | github.com/ | 1.14.0 | 2 |
| pgsty/ | b6bfe7239bfc | github.com/ | 1.14.0 | 2 |
| shlinkio/ | 844e1f2b6455 | github.com/ | 1.14.0 | 2 |
| ghcr.io/ | 1e4639a7dbea | github.com/ | 1.14.0 | 2 |
| quay.io/ | 1dce27c494a1 | github.com/ | 1.14.0 | 2 |
| airbyte/ | fdae972eaf0e | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | 0b60b6565ab2 | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | 0f7c8ac484ac | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | 5501c419f42e | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | 5bb0aa825d16 | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | 6dabb4a2088c | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | 8935e75fa5d1 | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | 952f86d1116c | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | ba9f3b4b0b00 | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | c0ede65eb88e | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | cce234b4381a | github.com/ | 1.14.0 | 1 |
| bitnamilegacy/ | d7cd0e172c4c | github.com/ | 1.14.0 | 1 |
| cleanstart/ | f1156f7fd14a | github.com/ | 1.14.0 | 1 |
| ddosify/ | 181965edb12e | github.com/ | 1.14.0 | 1 |
| ddosify/ | a97a1b8a66af | github.com/ | 1.14.0 | 1 |
| devopsfaith/ | 4c678c224f67 | github.com/ | 1.14.0 | 1 |
| devopsfaith/ | 9219cda867e2 | github.com/ | 1.14.0 | 1 |
| dragonflyoss/ | c3ef7f10698d | github.com/ | 1.14.0 | 1 |
| dragonflyoss/ | 523785c77787 | github.com/ | 1.14.0 | 1 |
| dragonflyoss/ | d5dea9e662cd | github.com/ | 1.14.0 | 1 |
| falcosecurity/ | 1976da721518 | github.com/ | 1.14.0 | 1 |
| getconvoy/ | f4934cc05e31 | github.com/ | 1.14.0 | 1 |
| grafana/ | 09d8c3ce4f3a | github.com/ | 1.14.0 | 1 |
| hyperledgerk8s/ | ed0b0c56f1ea | github.com/ | 1.14.0 | 1 |
| kubeshop/ | d8e1af6aca99 | github.com/ | 1.14.0 | 1 |
| lavr/ | 23b055e946ab | github.com/ | 1.14.0 | 1 |
| library/ | 507a3eecf809 | github.com/ | 1.14.0 | 1 |
| lishimeng/ | c79a67657baf | github.com/ | 1.14.0 | 1 |
| lishimeng/ | 3d00485e64dc | github.com/ | 1.14.0 | 1 |
| lishimeng/ | e0b8d2d8ca28 | github.com/ | 1.14.0 | 1 |
| lumenvox/ | 4611915d66f6 | github.com/ | 1.14.0 | 1 |
| lumenvox/ | 7badfce0df13 | github.com/ | 1.14.0 | 1 |
| lumenvox/ | dce4f18b4945 | github.com/ | 1.14.0 | 1 |