StackRadar

CVE-2026-27136

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,015
of 17,787 indexed, latest versions
Container images
3,690
deployed by those charts
Fix available
1 of 1
affected package

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Carried by container images the latest versions of 3,015 of 17,787 indexed charts deploy, on 3,690 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,690
OSV records
GO-2026-5030

Charts affected

3,015 by stars
ChartLatestAffected imagesRadar Score
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/net@v0.11.0
0.55.0
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/net@v0.17.0
0.55.0

Open the chart page →

10,355
uptraceuptrace2.0.21 of 2See more

uptrace uptrace 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
uptrace/uptrace:2.0.234a02c3b2d12
golang.org/x/net@v0.42.0
0.55.0

Open the chart page →

1,620
valkey-operatorvalkeyVerified publisher0.6.01 of 1See more

valkey-operator valkey 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/valkey-io/valkey-operator:v0.6.052a0f1ed0c03
golang.org/x/net@v0.49.0
0.55.0

Open the chart page →

134
vaultvaultVerified publisher1.22.03 of 4See more

vault vault 1.22.0

3 of the 4 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
alpine/k8s:1.35.5d870622d0040
golang.org/x/net@v0.48.0
0.55.0
hashicorp/vault:2.0.1755355002715
golang.org/x/net@v0.54.0
0.55.0
prom/statsd-exporter:v0.29.0632f70580492
golang.org/x/net@v0.48.0
0.55.0

Open the chart page →

4,243
vouchvouchVerified publisher3.2.01 of 1See more

vouch vouch 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/net@v0.5.0
0.55.0

Open the chart page →

1,031
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
0.55.0

Open the chart page →

1,344
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
0.55.0

Open the chart page →

2,245
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
golang.org/x/net@v0.52.0
0.55.0

Open the chart page →

1,000
wallarm-ingresswallarmVerified publisher5.3.10-12 of 2See more

wallarm-ingress wallarm 5.3.10-1

2 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
golang.org/x/net@v0.34.0
0.55.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
0.55.0

Open the chart page →

1,301
wallarm-sidecarwallarmOfficialVerified publisher6.13.11 of 3See more

wallarm-sidecar wallarm 6.13.1

1 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
0.55.0

Open the chart page →

965
argo-cdwenerme10.9.12 of 3See more

argo-cd wenerme 10.9.1

2 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/net@v0.50.0
0.55.0
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
golang.org/x/net@v0.40.0
0.55.0

Open the chart page →

2,989
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0.55.0

Open the chart page →

6,085
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.55.0
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.55.0
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.55.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.55.0

Open the chart page →

10,033
buildkitdwiremindVerified publisher0.33.01 of 1See more

buildkitd wiremind 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/net@v0.43.0
0.55.0

Open the chart page →

1,153
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.55.0

Open the chart page →

4,713
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.55.0

Open the chart page →

4,041
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/net@v0.26.0
0.55.0

Open the chart page →

828
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
golang.org/x/net@v0.38.0
0.55.0

Open the chart page →

1,836
no-latest-tag-webhookadmission-webhook-no-latest1.0.141 of 1See more

no-latest-tag-webhook admission-webhook-no-latest 1.0.14

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/omkar-shelke25/admission-webhook-no-latest:sha-33165455976a1d3236a
golang.org/x/net@v0.38.0
0.55.0

Open the chart page →

162
agentareaagentareaVerified publisher0.0.183 of 16See more

agentarea agentarea 0.0.18

3 of the 16 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
0.55.0
temporalio/auto-setup:1.29.15b3502a3b685
golang.org/x/net@v0.35.0
0.55.0
temporalio/ui:2.39.0b768f87f18b5
golang.org/x/net@v0.40.0
0.55.0

Open the chart page →

14,960
alertmanager-matrixalertmanager-matrixVerified publisher0.1.161 of 1See more

alertmanager-matrix alertmanager-matrix 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
silkeh/alertmanager_matrix:0.6.1900010497f8c
golang.org/x/net@v0.54.0
0.55.0

Open the chart page →

454
clearml-servingallegroaiVerified publisher1.6.23 of 9See more

clearml-serving allegroai 1.6.2

3 of the 9 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/net@v0.4.0
0.55.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
0.55.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
0.55.0

Open the chart page →

17,879
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.55.0

Open the chart page →

3,119
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.55.0

Open the chart page →

2,173
cloudflare-operatorankra-chartsVerified publisher0.2.01 of 1See more

cloudflare-operator ankra-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
adyanth/cloudflare-operatordigest-pinned6b168dc237d5
golang.org/x/net@v0.39.0
0.55.0

Open the chart page →

493
upcloud-csiankra-chartsVerified publisher0.4.08 of 8See more

upcloud-csi ankra-charts 0.4.0

8 of the 8 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
golang.org/x/net@v0.43.0
0.55.0
ghcr.io/upcloudltd/upcloud-csidigest-pinned5af91c663788
golang.org/x/net@v0.48.0
0.55.0
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.55.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.55.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.55.0
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.55.0

Open the chart page →

14,920
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.55.0

Open the chart page →

1,149
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
0.55.0

Open the chart page →

3,378
anteonanteonVerified publisher2.6.44 of 13See more

anteon anteon 2.6.4

4 of the 13 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/net@v0.21.0
0.55.0
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
0.55.0
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.55.0
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
0.55.0

Open the chart page →

22,233
api-usage-serverapi-usage-server1.16.01 of 1See more

api-usage-server api-usage-server 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
golang.org/x/net@v0.38.0
0.55.0

Open the chart page →

733
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/net@v0.8.0
0.55.0

Open the chart page →

1,057
scannerappscodeVerified publisher2026.1.153 of 3See more

scanner appscode 2026.1.15

3 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
0.55.0
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
golang.org/x/net@v0.47.0
0.55.0
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/net@v0.26.0
0.55.0

Open the chart page →

5,301
smtprelayappscodeVerified publisher2026.9.111 of 1See more

smtprelay appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/net@v0.34.0
0.55.0

Open the chart page →

840
stash-enterpriseappscodeVerified publisher0.42.04 of 4See more

stash-enterprise appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.55.0
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
0.55.0
ghcr.io/stashed/stash-crd-installer:v0.42.1d6c9b7a1f7b8
golang.org/x/net@v0.38.0
0.55.0
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
golang.org/x/net@v0.38.0
0.55.0

Open the chart page →

3,620
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0

Open the chart page →

5,231
argocd-rbac-operatorargocd-rbac-operator0.4.51 of 1See more

argocd-rbac-operator argocd-rbac-operator 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-rbac-operator:v0.2.451dded00137a
golang.org/x/net@v0.40.0
0.55.0

Open the chart page →

954
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
golang.org/x/net@v0.30.0
0.55.0
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
golang.org/x/net@v0.30.0
0.55.0

Open the chart page →

2,276
s3dartur9010Verified publisher1.0.11 of 1See more

s3d artur9010 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
golang.org/x/net@v0.53.0
0.55.0

Open the chart page →

1,722
arvancloud-webhookarvancloud-webhookVerified publisher1.0.01 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
golang.org/x/net@v0.47.0
0.55.0

Open the chart page →

2,309
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.55.0

Open the chart page →

2,819
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.55.0

Open the chart page →

10,731
dltbrokerassist-iot-distributed-broker0.2.04 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.55.0
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.55.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.55.0
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.55.0

Open the chart page →

77,821
dltloggingassist-iot-logging-auditing0.2.04 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.55.0
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.55.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.55.0
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.55.0

Open the chart page →

77,802
astradnsastradnsVerified publisher0.2.92 of 2See more

astradns astradns 0.2.9

2 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
golang.org/x/net@v0.51.0
0.55.0
ghcr.io/astradns/astradns-operator:v0.2.909e58b62416a
golang.org/x/net@v0.47.0
0.55.0

Open the chart page →

2,541
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
0.55.0

Open the chart page →

4,298
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.55.0

Open the chart page →

3,391
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.55.0

Open the chart page →

3,729
kubebrowseravistoOfficialVerified publisher1.4.01 of 1See more

kubebrowser avisto 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/kubebrowser:0.10.0a354b8dc7e6a
golang.org/x/net@v0.47.0
0.55.0

Open the chart page →

677
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
0.55.0

Open the chart page →

4,814
music-assistantbdclark-helm-chartsVerified publisher0.4.131 of 1See more

music-assistant bdclark-helm-charts 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.3885872224fa5
golang.org/x/net@v0.48.0
0.55.0

Open the chart page →

3,617

Container images carrying it

3,690 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/net@v0.24.0
0.55.0
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.55.0
1
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/net@v0.26.0
0.55.0
1
gutmensch/podnat-controller:0.5.2566979793fc4
golang.org/x/net@v0.4.0
0.55.0
1
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
golang.org/x/net@v0.38.0
0.55.0
1
haproxytech/haproxy-alpine:2.6.614e4afa90dfd
golang.org/x/net@v0.2.0
0.55.0
1
haproxytech/haproxy-alpine:2.9.57f3dc8c7e031
golang.org/x/net@v0.21.0
0.55.0
1
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
golang.org/x/net@v0.11.0
0.55.0
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
golang.org/x/net@v0.21.0
0.55.0
1
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/net@v0.21.0
0.55.0
1
hashicorp/boundary:0.21.037bf86488b74
golang.org/x/net@v0.47.0
0.55.0
1
hashicorp/boundary:latest76a201954ca0
golang.org/x/net@v0.48.0
0.55.0
1
hashicorp/boundary:0.8.1fb70bd9210ff
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.55.0
1
hashicorp/consul:1.17.0712fe02d2f84
golang.org/x/net@v0.17.0
0.55.0
1
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/net@v0.8.0
0.55.0
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
golang.org/x/net@v0.17.0
0.55.0
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/net@v0.7.0
0.55.0
1
hashicorp/terraform:1.44dcb45513699
golang.org/x/net@v0.6.0
0.55.0
1
hashicorp/terraform:1.9.7b77efab1a448
golang.org/x/net@v0.23.0
0.55.0
1
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
golang.org/x/net@v0.24.0
0.55.0
1
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.55.0
1
hashicorp/vault:1.15.40b01ed3924e6
golang.org/x/net@v0.17.0
0.55.0
1
hashicorp/vault:2.0.1755355002715
golang.org/x/net@v0.54.0
0.55.0
1
hashicorp/vault:1.14.0b2177a8bfe85
golang.org/x/net@v0.10.0
0.55.0
1
hashicorp/vault:1.19.0bbb7f98dc67d
golang.org/x/net@v0.35.0
0.55.0
1
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.55.0
1
hashicorp/vault-k8s:1.6.2103a2d817a74
golang.org/x/net@v0.35.0
0.55.0
1
hashicorp/vault-k8s:1.2.14500e988b7ce
golang.org/x/net@v0.7.0
0.55.0
1
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.55.0
1
hashicorp/vault-k8s:1.7.2ae3d307658b7
golang.org/x/net@v0.47.0
0.55.0
1
hashicorp/vault-k8s:0.14.0aff47b5ba39c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.55.0
1
hashicorp/waypoint:0.11.397d521a27498
golang.org/x/net@v0.1.0
0.55.0
1
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.55.0
1
headscale/headscale:0.25.1a7a8ae9616bb
golang.org/x/net@v0.34.0
0.55.0
1
headscale/headscale:0.27.1cd37b3001857
golang.org/x/net@v0.46.0
0.55.0
1
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
golang.org/x/net@v0.11.0
0.55.0
1
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.55.0
1
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.55.0
1
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
0.55.0
1
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
golang.org/x/net@v0.7.0
0.55.0
1
hhyo/archery:v1.9.11aa41843419e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.55.0
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
0.55.0
1
holiman/nodemonitor:latest5cd609761065
golang.org/x/net@v0.9.0
0.55.0
1
homeassistant/home-assistant:2026.75a531753cea9
golang.org/x/net@v0.49.0
0.55.0
1
honeycombio/honeycomb-kubernetes-agent:2.7.448c38d0870f2
golang.org/x/net@v0.38.0
0.55.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
golang.org/x/net@v0.17.0
0.55.0
1
huacnlee/gobackup:v3.1.1560be93229a5
golang.org/x/net@v0.47.0
0.55.0
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
golang.org/x/net@v0.10.0
0.55.0
1
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
golang.org/x/net@v0.0.0-20210907225631-ff17edfbf26d
0.55.0
1
huzafach/aws-cli-k8:1.0.06e271d43ea48
golang.org/x/net@v0.23.0
0.55.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.