StackRadar

CVE-2026-27136

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,011
of 17,792 indexed, latest versions
Container images
3,684
deployed by those charts
Fix available
1 of 1
affected package

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Carried by container images the latest versions of 3,011 of 17,792 indexed charts deploy, on 3,684 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,684
OSV records
GO-2026-5030

Charts affected

3,011 by stars
ChartLatestAffected imagesRadar Score
cert-manager-setupmesosphere-stable0.2.104 of 5See more

cert-manager-setup mesosphere-stable 0.2.10

4 of the 5 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
0.55.0
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
0.55.0
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
0.55.0
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
0.55.0

Open the chart page →

7,201
cosimesosphere-stable0.2.21 of 1See more

cosi mesosphere-stable 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/mesosphere/dkp-container-images/objectstorage-controller:v0.2.23c708e508197
golang.org/x/net@v0.40.0
0.55.0

Open the chart page →

305
dexmesosphere-stable2.14.13 of 5See more

dex mesosphere-stable 2.14.1

3 of the 5 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/net@v0.19.0
0.55.0
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
golang.org/x/net@v0.11.0
0.55.0
mesosphere/dex-controller:v0.16.11b2dd9c0b0fc
golang.org/x/net@v0.25.0
0.55.0

Open the chart page →

19,285
gatekeepermesosphere-stable0.6.111 of 2See more

gatekeeper mesosphere-stable 0.6.11

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.55.0

Open the chart page →

3,041
gcpdisk-csi-drivermesosphere-stable0.7.31 of 7See more

gcpdisk-csi-driver mesosphere-stable 0.7.3

1 of the 7 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
0.55.0

Open the chart page →

3,613
istiomesosphere-stable1.25.11 of 2See more

istio mesosphere-stable 1.25.1

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/net@v0.19.0
0.55.0

Open the chart page →

5,461
istio-helm-cnimesosphere-stable1.23.61 of 1See more

istio-helm-cni mesosphere-stable 1.23.6

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
istio/install-cni:1.23.6ab34c4740f44
golang.org/x/net@v0.37.0
0.55.0

Open the chart page →

3,342
istio-helm-istiodmesosphere-stable1.23.62 of 2See more

istio-helm-istiod mesosphere-stable 1.23.6

2 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
istio/pilot:1.23.69c3d6a218181
golang.org/x/net@v0.37.0
0.55.0
mesosphere/kubectl:v1.35.0-alpineea01a9387771
golang.org/x/net@v0.43.0
0.55.0

Open the chart page →

4,665
kafka-operatormesosphere-stable0.25.11 of 2See more

kafka-operator mesosphere-stable 0.25.1

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
golang.org/x/net@v0.8.0
0.55.0

Open the chart page →

1,242
karmamesosphere-stable2.0.31 of 1See more

karma mesosphere-stable 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
lmierzwa/karma:v0.70d417abe7ddb5
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.55.0

Open the chart page →

1,966
knativemesosphere-stable1.10.87 of 7See more

knative mesosphere-stable 1.10.8

7 of the 7 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.10.2c2994c2b6c2c
golang.org/x/net@v0.7.0
0.55.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.10.28319aa662b49
golang.org/x/net@v0.7.0
0.55.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa:v1.10.2eb612b929eaa
golang.org/x/net@v0.7.0
0.55.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
golang.org/x/net@v0.7.0
0.55.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.10.2f66c41ad7a73
golang.org/x/net@v0.7.0
0.55.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.10.27368aaddf2be
golang.org/x/net@v0.7.0
0.55.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.10.24305209ce498
golang.org/x/net@v0.7.0
0.55.0

Open the chart page →

7,528
kommandermesosphere-stable0.39.218 of 29See more

kommander mesosphere-stable 0.39.2

18 of the 29 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.55.0
mesosphere/karma:v0.55-d2iq-proxy4693bb4e0814
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.55.0
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.55.0
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.55.0
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.55.0
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.55.0
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.55.0
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.55.0
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.55.0
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.55.0
prom/prometheus:v2.19.2cd134bd4fca0
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.55.0
thanosio/thanos:v0.19.088276fcd1491
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.55.0
thanosio/thanos:v0.15.0b12d5c31bf5a
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.55.0
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.55.0
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.55.0
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.55.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.55.0
quay.io/thanos/thanos:v0.17.1e362f02ed304
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.55.0

Open the chart page →

68,432
kube-prometheus-stackmesosphere-stable75.9.16 of 7See more

kube-prometheus-stack mesosphere-stable 75.9.1

6 of the 7 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/net@v0.19.0
0.55.0
grafana/grafana:12.0.2b5b59bfc7561
golang.org/x/net@v0.40.0
0.55.0
quay.io/prometheus-operator/prometheus-operator:v0.83.0b6a89b8ec08f
golang.org/x/net@v0.40.0
0.55.0
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
0.55.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
0.55.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
0.55.0

Open the chart page →

10,239
multusmesosphere-stable0.1.11 of 1See more

multus mesosphere-stable 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.4-thick3c20900b5381
golang.org/x/net@v0.43.0
0.55.0

Open the chart page →

1,808
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.55.0

Open the chart page →

7,030
veleromesosphere-stable3.2.51 of 1See more

velero mesosphere-stable 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
0.55.0

Open the chart page →

1,871
cortexmetakube0.6.01 of 2See more

cortex metakube 0.6.0

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
0.55.0

Open the chart page →

4,115
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.55.0

Open the chart page →

8,958
wg-access-servermglants0.4.71 of 1See more

wg-access-server mglants 0.4.7

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.55.0

Open the chart page →

2,752
gogsmhio0.9.21 of 2See more

gogs mhio 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
gogs/gogs:0.12.1420d53bb7277
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
0.55.0

Open the chart page →

3,231
kube-agent-chartmiddleware-labsVerified publisher0.1.21 of 1See more

kube-agent-chart middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
golang.org/x/net@v0.4.0
0.55.0

Open the chart page →

1,806
middleware-odigosmiddleware-labsVerified publisher0.2.414 of 6See more

middleware-odigos middleware-labs 0.2.41

4 of the 6 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.55.0
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0

Open the chart page →

8,382
middleware-visionmiddleware-labsVerified publisher0.2.654 of 6See more

middleware-vision middleware-labs 0.2.65

4 of the 6 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.55.0
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0

Open the chart page →

8,374
mw-autoinstrumentationmiddleware-labsVerified publisher1.2.65 of 6See more

mw-autoinstrumentation middleware-labs 1.2.6

5 of the 6 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-auto-injector:0.1.18512248e17e8
golang.org/x/net@v0.26.0
0.55.0
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
golang.org/x/net@v0.26.0
0.55.0
ghcr.io/middleware-labs/mw-lang-detector:0.1.2a4776aa2a56b
golang.org/x/net@v0.26.0
0.55.0
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.132.05e331c925091
golang.org/x/net@v0.41.0
0.55.0
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
0.55.0

Open the chart page →

3,729
mw-kube-agentmiddleware-labsVerified publisher0.1.21 of 1See more

mw-kube-agent middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
golang.org/x/net@v0.14.0
0.55.0

Open the chart page →

1,601
mw-kube-agent-v3middleware-labsVerified publisher1.8.52 of 2See more

mw-kube-agent-v3 middleware-labs 1.8.5

2 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
golang.org/x/net@v0.53.0
0.55.0
ghcr.io/middleware-labs/mw-kube-agent-config-updater:1.21.0d4edc3f244f4
golang.org/x/net@v0.53.0
0.55.0

Open the chart page →

2,071
argocd-extra-app-info-exportermikejohVerified publisher0.1.121 of 1See more

argocd-extra-app-info-exporter mikejoh 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
golang.org/x/net@v0.30.0
0.55.0

Open the chart page →

1,341
imaginemikejohVerified publisher0.2.01 of 1See more

imagine mikejoh 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
mikejoh/imagine:0.1.078737d7345f9
golang.org/x/net@v0.26.0
0.55.0

Open the chart page →

559
local-path-provisionermikejohVerified publisher0.0.291 of 1See more

local-path-provisioner mikejoh 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.299bebefa0b908
golang.org/x/net@v0.27.0
0.55.0

Open the chart page →

1,300
miniomilvus-helm8.0.201 of 1See more

minio milvus-helm 8.0.20

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
golang.org/x/net@v0.25.0
0.55.0

Open the chart page →

1,544
pulsarv2milvus-helm2.7.82 of 4See more

pulsarv2 milvus-helm 2.7.8

2 of the 4 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.55.0
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.55.0

Open the chart page →

15,874
mimirmimir0.1.101 of 1See more

mimir mimir 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
golang.org/x/net@v0.17.0
0.55.0

Open the chart page →

382
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0.55.0

Open the chart page →

6,086
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
golang.org/x/net@v0.4.0
0.55.0

Open the chart page →

10,713
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
golang.org/x/net@v0.4.0
0.55.0

Open the chart page →

10,623
jupyterhubmizzoukube0.0.1-set.by.chartpress1 of 7See more

jupyterhub mizzoukube 0.0.1-set.by.chartpress

1 of the 7 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
golang.org/x/net@v0.19.0
0.55.0

Open the chart page →

1,890
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
golang.org/x/net@v0.0.0-20200822124328-c89045814202
0.55.0

Open the chart page →

2,854
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.55.0

Open the chart page →

7,782
echoperatormmontesVerified publisher0.0.21 of 1See more

echoperator mmontes 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.55.0

Open the chart page →

1,826
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.55.0

Open the chart page →

2,554
smartthings-metricsmoikot0.1.01 of 1See more

smartthings-metrics moikot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:0.1.08625f53aa9b7
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.55.0

Open the chart page →

1,744
smartthings-metrics-feat-log-detailsmoikot0.0.921 of 1See more

smartthings-metrics-feat-log-details moikot 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:feat-log-detailsfb8565140106
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.55.0

Open the chart page →

1,732
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
golang.org/x/net@v0.7.0
0.55.0

Open the chart page →

2,470
backendmojaloop0.1.02 of 6See more

backend mojaloop 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.55.0
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.55.0

Open the chart page →

16,304
mollysocketmollysocket-wrenixVerified publisher0.1.141 of 2See more

mollysocket mollysocket-wrenix 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.3c4a11ae9a1cb
golang.org/x/net@v0.47.0
0.55.0

Open the chart page →

2,540
eks-pod-identity-webhookmondu-aiVerified publisher0.3.11 of 1See more

eks-pod-identity-webhook mondu-ai 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
golang.org/x/net@v0.47.0
0.55.0

Open the chart page →

474
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
golang.org/x/net@v0.47.0
0.55.0

Open the chart page →

5,229
enterprise-operatormongodb-helm-charts1.33.01 of 1See more

enterprise-operator mongodb-helm-charts 1.33.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
golang.org/x/net@v0.39.0
0.55.0

Open the chart page →

1,562
mongodb-secure-backupmongodb-secure-backup1.0.01 of 2See more

mongodb-secure-backup mongodb-secure-backup 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
golang.org/x/net@v0.34.0
0.55.0

Open the chart page →

1,033
mongopingmongoping1.3.11 of 1See more

mongoping mongoping 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
udhos/mongoping:1.3.103b08b63f524
golang.org/x/net@v0.40.0
0.55.0

Open the chart page →

1,137

Container images carrying it

3,684 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.55.0
1
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.55.0
1
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.55.0
1
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.55.0
1
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.55.0
1
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.55.0
1
cloudflare/cloudflared:2024.8.314d9c6b01b29
golang.org/x/net@v0.25.0
0.55.0
1
cloudflare/cloudflared:2024.5.05d5f70a59d5e
golang.org/x/net@v0.25.0
0.55.0
1
cloudflare/cloudflared:2023.10.0c18744ae1767
golang.org/x/net@v0.12.0
0.55.0
1
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/net@v0.40.0
0.55.0
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
golang.org/x/net@v0.4.0
0.55.0
1
cmacrae/lgtm:0.1.0dec8d490fe40
golang.org/x/net@v0.0.0-20181108082009-03003ca0c849
0.55.0
1
cockroachdb/cockroach-operator:v2.1.0983312754620
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.55.0
1
codecov/self-hosted-gateway:24.4.1de483faad6e5
golang.org/x/net@v0.21.0
0.55.0
1
codenotary/immudb:1.9.77c85d7cc4f22
golang.org/x/net@v0.17.0
0.55.0
1
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/net@v0.24.0
0.55.0
1
codeskyblue/gohttpserver:latestcaa862590e34
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.55.0
1
cometbft/cometbft:v0.38.1722c2ac018f40
golang.org/x/net@v0.34.0
0.55.0
1
concourse/concourse:8.3.040a143ce5873
golang.org/x/net@v0.50.0
0.55.0
1
conduction/agendaservice-php:latest9cfeeb6c7c20
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
conduction/balance-registration-php:devc36094a41369
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
conduction/cgrc-php:dev25415534d245
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
conduction/checkin-component-php:dev3423845692c1
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
conduction/kvk-php:dev8f177f9f8a7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
conduction/pan-php:dev24f03c57568f
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0
1
consensys/web3signer:latestf146a51a1ba3
golang.org/x/net@v0.40.0
0.55.0
1
containous/maesh:v1.3.2587162516502
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.55.0
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
golang.org/x/net@v0.23.0
0.55.0
1
coordimap/coordimap-agent:latest7748fd0fae9f
golang.org/x/net@v0.38.0
0.55.0
1
coredns/coredns:1.12.040384aa1f5ea
golang.org/x/net@v0.31.0
0.55.0
1
coredns/coredns:1.7.073ca82b4ce82
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.55.0
1
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/net@v0.4.0
0.55.0
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
golang.org/x/net@v0.33.0
0.55.0
1
cortezaproject/corteza:2024.9.08eb7a26605c9
golang.org/x/net@v0.21.0
0.55.0
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
golang.org/x/net@v0.33.0
0.55.0
1
couchbase/admission-controller:2.9.3bf2d2e87e45f
golang.org/x/net@v0.43.0
0.55.0
1
couchbase/operator:2.9.369a385b49e1f
golang.org/x/net@v0.43.0
0.55.0
1
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.55.0
1
crossplane/crossplane:v0.12.066666e6963af
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.55.0
1
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.55.0
1
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.55.0
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.55.0
1
csepulvedab/secret-sync:0.5227a6f2b0ff8
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.55.0
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
0.55.0
1
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.55.0
1
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.55.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.