StackRadar

CVE-2026-25680

Medium

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,011
of 17,792 indexed, latest versions
Container images
3,684
deployed by those charts
Fix available
1 of 1
affected package

Go Net HTML parser is vulnerable to denial of service

Carried by container images the latest versions of 3,011 of 17,792 indexed charts deploy, on 3,684 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,684
OSV records
GHSA-5cv4-jp36-h3mw
Also known as
GO-2026-5028

Charts affected

3,011 by stars
ChartLatestAffected imagesRadar Score
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
golang.org/x/net@v0.49.0
0.55.0

Open the chart page →

394
ygdrassil-monitoringygdrassilVerified publisher0.4.07 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

7 of the 10 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
golang.org/x/net@v0.34.0
0.55.0
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/net@v0.33.0
0.55.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/net@v0.32.0
0.55.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
0.55.0
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/net@v0.32.0
0.55.0
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/net@v0.34.0
0.55.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
0.55.0

Open the chart page →

9,401
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
golang.org/x/net@v0.24.0
0.55.0

Open the chart page →

1,610
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.55.0

Open the chart page →

1,965
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.55.0
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.55.0
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.55.0

Open the chart page →

8,000
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.55.0

Open the chart page →

3,024
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
golang.org/x/net@v0.51.0
0.55.0

Open the chart page →

899
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/net@v0.8.0
0.55.0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/net@v0.7.0
0.55.0

Open the chart page →

5,047
zahori-moonzahoriVerified publisher1.0.13 of 3See more

zahori-moon zahori 1.0.1

3 of the 3 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
quay.io/aerokube/moon:2.5.1a8837b00ba1c
golang.org/x/net@v0.7.0
0.55.0
quay.io/aerokube/moon-conf:2.5.19ca307b30080
golang.org/x/net@v0.7.0
0.55.0
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/net@v0.11.0
0.55.0

Open the chart page →

2,908
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.55.0

Open the chart page →

3,697
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-25680.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
golang.org/x/net@v0.49.0
0.55.0

Open the chart page →

7,936

Container images carrying it

3,684 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
0.55.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
0.55.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.55.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
0.55.0
4
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
0.55.0
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
0.55.0
4
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
0.55.0
4
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
0.55.0
4
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
0.55.0
4
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
0.55.0
4
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
0.55.0
4
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
golang.org/x/net@v0.54.0
0.55.0
4
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
0.55.0
4
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
0.55.0
3
alpine/git:latest:v2.54.06f3b5029566d
golang.org/x/net@v0.54.0
0.55.0
3
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
0.55.0
3
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
0.55.0
3
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.55.0
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
0.55.0
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
0.55.0
3
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
0.55.0
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
0.55.0
3
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
golang.org/x/net@v0.38.0
0.55.0
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.55.0
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.55.0
3
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
0.55.0
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.55.0
3
ethpandaops/tracoor:latestd8514b9f4c59
golang.org/x/net@v0.40.0
0.55.0
3
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
golang.org/x/net@v0.54.0
0.55.0
3
goharbor/registry-photon:v2.15.2c4ebef61ceb5
golang.org/x/net@v0.54.0
0.55.0
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.55.0
3
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
0.55.0
3
grafana/grafana:13.2.1-distroless3600073f45a9
golang.org/x/net@v0.51.0
0.55.0
3
grafana/grafana:13.1.17cb8c64c4d57
golang.org/x/net@v0.49.0
0.55.0
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
0.55.0
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
0.55.0
3
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/net@v0.47.0
0.55.0
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
0.55.0
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.55.0
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/net@v0.47.0
0.55.0
3
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/net@v0.19.0
0.55.0
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
0.55.0
3
migrate/migrate:latestcc4ad8e19d66
golang.org/x/net@v0.47.0
0.55.0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.55.0
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
0.55.0
3
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/net@v0.44.0
0.55.0
3
natsio/nats-box:0.19.7ffce8bd10338
golang.org/x/net@v0.53.0
0.55.0
3
neosmemo/memos:0.30.071a5b4738d1b
golang.org/x/net@v0.53.0
0.55.0
3
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/net@v0.18.0
0.55.0
3

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.