StackRadar

CVE-2026-27136

Unscored

Advisory

Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,003
of 17,790 indexed, latest versions
Container images
3,682
deployed by those charts
Fix available
1 of 1
affected package

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Carried by container images the latest versions of 3,003 of 17,790 indexed charts deploy, on 3,682 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.55.03,682
OSV records
GO-2026-5030

Charts affected

3,003 by stars
ChartLatestAffected imagesRadar Score
linkerd-preview-vizlinkerd-buoyantVerified publisher25.4.34 of 5See more

linkerd-preview-viz linkerd-buoyant 25.4.3

4 of the 5 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
golang.org/x/net@v0.39.0
0.55.0
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/net@v0.28.0
0.55.0
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
golang.org/x/net@v0.39.0
0.55.0
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
golang.org/x/net@v0.39.0
0.55.0

Open the chart page →

3,420
linkerd-dashboardlinkerd-dashboardOfficial0.11.11 of 2See more

linkerd-dashboard linkerd-dashboard 0.11.1

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
golang.org/x/net@v0.35.0
0.55.0

Open the chart page →

1,037
linode-blockstorage-csi-driverlinode-blockstorage-csi-driverOfficialVerified publisher1.1.44 of 5See more

linode-blockstorage-csi-driver linode-blockstorage-csi-driver 1.1.4

4 of the 5 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
golang.org/x/net@v0.47.0
0.55.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
0.55.0
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
golang.org/x/net@v0.51.0
0.55.0
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
0.55.0

Open the chart page →

2,933
liqo-upgrade-operatorliqo-upgrade-operatorVerified publisher0.1.01 of 1See more

liqo-upgrade-operator liqo-upgrade-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
kazem26/liqo-upgrade-operator:v0.1268b7c6a59dd
golang.org/x/net@v0.38.0
0.55.0

Open the chart page →

368
listmonklistmonk-chartVerified publisher2.0.11 of 2See more

listmonk listmonk-chart 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
listmonk/listmonk:v6.0.0bf3903d54a46
golang.org/x/net@v0.47.0
0.55.0

Open the chart page →

3,080
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
golang.org/x/net@v0.18.0
0.55.0

Open the chart page →

10,773
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/net@v0.0.0-20211004195052-b30845b58a23
0.55.0

Open the chart page →

2,129
livekit-serverlivekit-server1.9.01 of 1See more

livekit-server livekit-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.9.03602a85840d5
golang.org/x/net@v0.40.0
0.55.0

Open the chart page →

1,553
llmarinerllmariner1.53.113 of 21See more

llmariner llmariner 1.53.1

13 of the 21 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/inference-manager-engine:1.46.0c46f109c3d0b
golang.org/x/net@v0.48.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/inference-manager-server:1.45.090b890f800ab
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/job-manager-server:1.27.0fe9de719f91e
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/model-manager-server:1.27.0c057dcdd9ef3
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/rbac-server:1.19.1df1adeb86679
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/session-manager-server:1.9.0f24ecd37fbaa
golang.org/x/net@v0.38.0
0.55.0
public.ecr.aws/cloudnatix/llmariner/user-manager-server:1.27.1628a14449241
golang.org/x/net@v0.38.0
0.55.0

Open the chart page →

12,034
llm-dllm-dVerified publisher1.0.231 of 2See more

llm-d llm-d 1.0.23

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
golang.org/x/net@v0.40.0
0.55.0

Open the chart page →

2,524
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
golang.org/x/net@v0.49.0
0.55.0

Open the chart page →

2,450
mt-mcp-grafanaloafoe0.10.01 of 2See more

mt-mcp-grafana loafoe 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
grafana/mcp-grafana:0.14.042f541f22063
golang.org/x/net@v0.53.0
0.55.0

Open the chart page →

1,845
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
golang.org/x/net@v0.27.0
0.55.0

Open the chart page →

2,155
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.55.0

Open the chart page →

4,904
picoclawloafoe0.1.11 of 2See more

picoclaw loafoe 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loafoe/picoclaw:v0.0.1942e1b6862913
golang.org/x/net@v0.53.0
0.55.0

Open the chart page →

479
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/net@v0.14.0
0.55.0

Open the chart page →

2,101
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
golang.org/x/net@v0.27.0
0.55.0

Open the chart page →

2,020
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-auth-go:latest6597b26959d2
golang.org/x/net@v0.10.0
0.55.0

Open the chart page →

5,905
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0

Open the chart page →

7,510
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
golang.org/x/net@v0.22.0
0.55.0

Open the chart page →

7,516
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
golang.org/x/net@v0.40.0
0.55.0

Open the chart page →

32,893
central-hostpath-mapperloftVerified publisher0.2.91 of 1See more

central-hostpath-mapper loft 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
golang.org/x/net@v0.26.0
0.55.0

Open the chart page →

917
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/net@v0.21.0
0.55.0

Open the chart page →

3,225
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0

Open the chart page →

9,880
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.55.0

Open the chart page →

3,086
license-serverloftVerified publisher0.6.01 of 1See more

license-server loft 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
golang.org/x/net@v0.53.0
0.55.0

Open the chart page →

804
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/net@v0.6.0
0.55.0

Open the chart page →

2,444
loft-direct-cluster-endpointloftVerified publisher1.14.01 of 1See more

loft-direct-cluster-endpoint loft 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.55.0

Open the chart page →

3,112
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/net@v0.21.0
0.55.0

Open the chart page →

3,225
vcluster-headloftVerified publisher0.0.0-035ec6e1 of 2See more

vcluster-head loft 0.0.0-035ec6e

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/kubernetes:v1.35.090097a08b87c
golang.org/x/net@v0.42.0
0.55.0

Open the chart page →

1,269
vcluster-hpmloftVerified publisher0.2.71 of 1See more

vcluster-hpm loft 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-hpm:0.2.7f65f6810ea23
golang.org/x/net@v0.40.0
0.55.0

Open the chart page →

826
vcluster-proloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
0.55.0
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
0.55.0

Open the chart page →

5,085
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.102 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

2 of the 4 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
0.55.0
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.55.0

Open the chart page →

5,936
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/net@v0.5.0
0.55.0
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
0.55.0

Open the chart page →

5,770
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.104 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

4 of the 4 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
0.55.0
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.55.0
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.55.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.55.0

Open the chart page →

8,206
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.55.0

Open the chart page →

2,986
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
golang.org/x/net@v0.46.0
0.55.0

Open the chart page →

2,507
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0

Open the chart page →

7,492
nightingalelogic3579Verified publisher0.3.12 of 6See more

nightingale logic3579 0.3.1

2 of the 6 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
golang.org/x/net@v0.47.0
0.55.0
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
0.55.0

Open the chart page →

9,021
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.55.0

Open the chart page →

7,498
apica-ascentlogiqai2.0.47 of 19See more

apica-ascent logiqai 2.0.4

7 of the 19 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/net@v0.20.0
0.55.0
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.55.0
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.55.0
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.55.0
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.55.0
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.55.0
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.55.0

Open the chart page →

23,255
loki-proxyloki-proxyVerified publisher0.4.11 of 1See more

loki-proxy loki-proxy 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/peak-scale/observability-tenancy/loki-proxy:0.4.1548e962d0061
golang.org/x/net@v0.43.0
0.55.0

Open the chart page →

782
loxilbloxilbVerified publisher0.1.02 of 2See more

loxilb loxilb 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
golang.org/x/net@v0.38.0
0.55.0
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
golang.org/x/net@v0.23.0
0.55.0

Open the chart page →

4,502
lsdisklsdiskVerified publisher2.0.73 of 4See more

lsdisk lsdisk 2.0.7

3 of the 4 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/net@v0.28.0
0.55.0
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
golang.org/x/net@v0.25.0
0.55.0
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/net@v0.13.0
0.55.0

Open the chart page →

5,032
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.55.0

Open the chart page →

2,342
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
0.55.0
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.55.0

Open the chart page →

9,332
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.55.0

Open the chart page →

6,623
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.55.0

Open the chart page →

3,764
xteveluiscajl0.1.61 of 1See more

xteve luiscajl 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
dnsforge/xteve:latest4d9a685c8c28
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.55.0

Open the chart page →

4,314
ratelimitlumiumcoVerified publisher0.0.41 of 2See more

ratelimit lumiumco 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-27136.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
golang.org/x/net@v0.38.0
0.55.0

Open the chart page →

1,002

Container images carrying it

3,682 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.55.0
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
golang.org/x/net@v0.42.0
0.55.0
2
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/net@v0.38.0
0.55.0
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.55.0
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
0.55.0
2
bitnamisecure/git72ae5bd9715f
golang.org/x/net@v0.38.0
0.55.0
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
0.55.0
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
0.55.0
2
bloomberg/goldpinger:3.11.3a8ea8c61ff4c
golang.org/x/net@v0.49.0
0.55.0
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.55.0
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
0.55.0
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.55.0
2
coredns/coredns:1.13.19b9128672209
golang.org/x/net@v0.45.0
0.55.0
2
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
0.55.0
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.55.0
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
0.55.0
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.55.0
2
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
0.55.0
2
danielqsj/kafka-exporter:latesta51b280b55a7
golang.org/x/net@v0.51.0
0.55.0
2
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.55.0
2
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/net@v0.36.0
0.55.0
2
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.55.0
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.55.0
2
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/net@v0.22.0
0.55.0
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.55.0
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
0.55.0
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
0.55.0
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
0.55.0
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
0.55.0
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
0.55.0
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
0.55.0
2
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/net@v0.23.0
0.55.0
2
free5gc/udm:v3.4.32f68df062a50
golang.org/x/net@v0.23.0
0.55.0
2
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/net@v0.23.0
0.55.0
2
free5gc/upf:v3.4.3b6b362a39fdd
golang.org/x/net@v0.23.0
0.55.0
2
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/net@v0.23.0
0.55.0
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
0.55.0
2
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.55.0
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.55.0
2
grafana/alloy:v1.8.17790f6f7fbd8
golang.org/x/net@v0.37.0
0.55.0
2
grafana/alloy:v1.12.2f94b1c82957a
golang.org/x/net@v0.46.0
0.55.0
2
grafana/grafana:9.2.4057896e23443
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.55.0
2
grafana/grafana:11.1.0079600c9517b
golang.org/x/net@v0.26.0
0.55.0
2
grafana/grafana:12.3.12175aaa91c96
golang.org/x/net@v0.46.0
0.55.0
2
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.55.0
2
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
0.55.0
2
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
0.55.0
2
grafana/grafana:12.3.39e1e77ade304
golang.org/x/net@v0.47.0
0.55.0
2
grafana/grafana:11.4.0d8ea37798ccc
golang.org/x/net@v0.29.0
0.55.0
2
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
0.55.0
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.