StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,051
of 17,803 indexed, latest versions
Container images
4,685
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,051 of 17,803 indexed charts deploy, on 4,685 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,529
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,580
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,051 by stars
ChartLatestAffected imagesRadar Score
gke-preemptible-notifierslamdev0.0.61 of 1See more

gke-preemptible-notifier slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
golang.org/x/net@v0.0.0-20200501053045-e0ff5e5a1de5
stdlib@go1.13.11
0.53.0
1.25.10

Open the chart page →

2,861
octavia-ingress-controllerslamdev0.0.71 of 1See more

octavia-ingress-controller slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15
0.53.0
1.25.10

Open the chart page →

2,761
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.53.0
1.25.10

Open the chart page →

8,732
slothsloth0.16.02 of 2See more

sloth sloth 0.16.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/slok/sloth:v0.16.0f0f0075b0d45
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
stdlib@go1.25.1
1.25.10

Open the chart page →

4,007
oi-slurm-cluster-chartslurm-cluster-chart0.25.11 of 4See more

oi-slurm-cluster-chart slurm-cluster-chart 0.25.1

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.25.10

Open the chart page →

4,390
slurm-cluster-chartslurm-cluster-chart0.25.01 of 4See more

slurm-cluster-chart slurm-cluster-chart 0.25.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.25.10

Open the chart page →

4,390
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.2
0.53.0
1.25.10

Open the chart page →

3,471
smarter-device-managersmarter-device-manager0.0.101 of 1See more

smarter-device-manager smarter-device-manager 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

1,151
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
stdlib@go1.19.8
1.25.10

Open the chart page →

5,621
smart-proxysmart-proxyVerified publisher0.1.11 of 1See more

smart-proxy smart-proxy 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
isebben/smart-proxy:latestab59a71ee9f4
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

282
smtp-gotifysmtp-gotifyVerified publisher0.1.41 of 1See more

smtp-gotify smtp-gotify 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/reiml/smtp-gotify:latest80ffa9d2044a
golang.org/x/net@v0.28.0
stdlib@go1.23.9
0.53.0
1.25.10

Open the chart page →

562
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
helga09/my_sql_shoes:v1.1.1a03657d97897
stdlib@go1.18.2
1.25.10

Open the chart page →

7,628
avalanchesnowplow-devopsVerified publisher0.12.11 of 6See more

avalanche snowplow-devops 0.12.1

1 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
stdlib@go1.24.2
1.25.10

Open the chart page →

1,330
vertical-pod-autoscalersnowplow-devopsVerified publisher0.1.13 of 3See more

vertical-pod-autoscaler snowplow-devops 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.4.171d817780aa9
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
registry.k8s.io/autoscaling/vpa-recommender:1.4.140b6d76e8526
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
registry.k8s.io/autoscaling/vpa-updater:1.4.18ebf269779c1
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10

Open the chart page →

1,254
snspingsnsping1.2.91 of 1See more

snsping snsping 1.2.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
udhos/snsping:1.2.96ae70677b6a3
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

1,343
axonhubsnubisks0.1.01 of 3See more

axonhub snubisks 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10

Open the chart page →

684
cost-analyzersoftonic2.5.53 of 6See more

cost-analyzer softonic 2.5.5

3 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.5.28b37a2f028f1
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
golang.org/x/net@v0.33.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.2.16927e0919a14
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

8,166
csi-gcs-softonic-factorysoftonic0.9.31 of 4See more

csi-gcs-softonic-factory softonic 0.9.3

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ofekmeister/csi-gcs:v0.9.030d70fa9211b
golang.org/x/net@v0.0.0-20220513224357-95641704303c
stdlib@go1.18.2
0.53.0
1.25.10

Open the chart page →

1,849
harborsoftonic1.13.05 of 8See more

harbor softonic 1.13.0

5 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
goharbor/harbor-jobservice:v2.9.039435daedd0c
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
goharbor/registry-photon:v2.9.08a26e8cb7862
stdlib@go1.20.7
1.25.10
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

7,708
hello-world-appsoftonic1.2.21 of 1See more

hello-world-app softonic 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/giantswarm/helloworld:0.2.07a07ee730305
stdlib@go1.16.7
1.25.10

Open the chart page →

1,957
homing-pigeonsoftonic0.12.01 of 1See more

homing-pigeon softonic 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
softonic/homing-pigeon:0.9.6f26d467b7b82
golang.org/x/net@v0.41.0
stdlib@go1.23.10
0.53.0
1.25.10

Open the chart page →

471
ingress-nginxsoftonic4.15.12 of 2See more

ingress-nginx softonic 4.15.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

1,541
kedasoftonic2.17.03 of 3See more

keda softonic 2.17.0

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.17.0112fc427d933
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.53.0
1.25.10
ghcr.io/kedacore/keda-admission-webhooks:2.17.0a87c42275757
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.53.0
1.25.10
ghcr.io/kedacore/keda-metrics-apiserver:2.17.0167fd532bd43
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.53.0
1.25.10

Open the chart page →

2,836
kube-prometheus-stacksoftonic81.5.15 of 6See more

kube-prometheus-stack softonic 81.5.1

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:12.3.2ba93c9d192e5
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.53.0
1.25.10
ghcr.io/jkroepke/kube-webhook-certgen:1.7.47a62bba56a7c
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.88.1d3d65efa3bee
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

5,017
kyvernosoftonic3.5.21 of 7See more

kyverno softonic 3.5.2

1 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.32.73c5268158974
golang.org/x/net@v0.30.0
stdlib@go1.23.10
0.53.0
1.25.10

Open the chart page →

1,021
pod-defaultersoftonic0.1.31 of 1See more

pod-defaulter softonic 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
softonic/pod-defaulter:0.1.072017aed5902
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.9
0.53.0
1.25.10

Open the chart page →

2,562
policy-reportersoftonic2.18.21 of 1See more

policy-reporter softonic 2.18.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kyverno/policy-reporter:2.14.1e74c6bf33d1b
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.53.0
1.25.10

Open the chart page →

1,045
preemptible-killersoftonic1.2.61 of 1See more

preemptible-killer softonic 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
softonic/preemptible-killer:1.2.6-294b87f1fb362
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.10
0.53.0
1.25.10

Open the chart page →

2,339
rate-limit-operatorsoftonic1.1.01 of 2See more

rate-limit-operator softonic 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
softonic/rate-limit-operator:0.1.1910f6de37763
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.53.0
1.25.10

Open the chart page →

2,220
rclonesoftonic2.1.01 of 1See more

rclone softonic 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rclone/rclone:1.6874c51b8817e5
golang.org/x/net@v0.27.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

1,680
redissoftonic0.3.01 of 2See more

redis softonic 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:5.0fc5ecd863862
stdlib@go1.16.7
1.25.10

Open the chart page →

1,731
redis-operatorsoftonic0.18.01 of 1See more

redis-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/ot-container-kit/redis-operator/redis-operator:v0.18.090bfeb2e0d71
golang.org/x/net@v0.24.0
stdlib@go1.21.12
0.53.0
1.25.10

Open the chart page →

551
sealed-secretssoftonic2.6.91 of 1See more

sealed-secrets softonic 2.6.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.6
0.53.0
1.25.10

Open the chart page →

1,516
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

2,514
webhook-receiversoftonic2.1.11 of 1See more

webhook-receiver softonic 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
almir/webhook:2.8.01698346f6077
stdlib@go1.14.7
1.25.10

Open the chart page →

1,927
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

3,117
gloo-meshsolo-gloo-mesh1.1.21 of 1See more

gloo-mesh solo-gloo-mesh 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.53.0
1.25.10

Open the chart page →

3,267
buildkitsomaz94Verified publisher0.1.41 of 1See more

buildkit somaz94 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
moby/buildkit:v0.33.06c2fa84a6b61
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

717
redis-high-availabilitysomeblackmagic1.3.102 of 3See more

redis-high-availability someblackmagic 1.3.10

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.8-debian-11-r0bf01d031ba8c
stdlib@go1.18.2
1.25.10
haproxytech/haproxy-alpine:2.9.57f3dc8c7e031
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.53.0
1.25.10

Open the chart page →

3,148
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18.2
0.53.0
1.25.10

Open the chart page →

97,304
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

11,998
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
golang.org/x/net@v0.33.0
stdlib@go1.22.8
0.53.0
1.25.10

Open the chart page →

3,304
spire-ha-agentspiffeVerified publisher0.3.21 of 2See more

spire-ha-agent spiffe 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-ha-agent:0.5.0307cf2d05afe
stdlib@go1.25.0
1.25.10

Open the chart page →

368
spire-identity-exchangespiffeVerified publisher0.2.22 of 3See more

spire-identity-exchange spiffe 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-identity-exchange-server:v0.5.0239bc70c1988
stdlib@go1.26.0
1.25.10
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

1,442
spillwayspillwayVerified publisher0.4.41 of 1See more

spillway spillway 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kroy-the-rabbit/spillway:0.4.48de556d3bda7
golang.org/x/net@v0.38.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

267
spinnakerspinnakerVerified publisher2.2.132 of 4See more

spinnaker spinnaker 2.2.13

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.15.5
0.53.0
1.25.10
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.5
0.53.0
1.25.10

Open the chart page →

6,877
spoolmanspoolmanVerified publisher0.2.61 of 1See more

spoolman spoolman 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.25.10

Open the chart page →

1,823
ocean-admission-controllerspot1.0.32 of 3See more

ocean-admission-controller spot 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/spotit-today/spot-ocean-admission-controller:0.1.64f634aeb31b8
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.53.0
1.25.10

Open the chart page →

773
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

46,567
ocean-vpaspot1.0.73 of 4See more

ocean-vpa spot 1.0.7

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.53.0
1.25.10

Open the chart page →

1,195

Container images carrying it

4,685 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
golang.org/x/net@v0.40.0
stdlib@go1.24.12
0.53.0
1.25.10
2
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
2
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.25.10
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.53.0
1.25.10
2
opendatacube/ows:latest668cbb41473c
stdlib@go1.22.2
1.25.10
2
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.53.0
1.25.10
2
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.53.0
1.25.10
2
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.53.0
1.25.10
2
openebs/provisioner-localpv:4.6.099f5116f5cb8
stdlib@go1.25.0
1.25.10
2
openebs/provisioner-localpv:3.5.0aea39e49bb97
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.53.0
1.25.10
2
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
golang.org/x/net@v0.24.0
stdlib@go1.20.14
0.53.0
1.25.10
2
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.2
0.53.0
1.25.10
2
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.53.0
1.25.10
2
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.53.0
1.25.10
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.53.0
1.25.10
2
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.53.0
1.25.10
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10
2
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
2
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.25.10
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.25.10
2
percona/everest-helmtools:0.0.1904458d04a18
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
2
pgautoupgrade/pgautoupgrade:18-alpine48b448825656
stdlib@go1.24.6
1.25.10
2
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
stdlib@go1.24.6
1.25.10
2
pgvector/pgvector:0.8.6-pg16-bookworm:pg16ccc6e83d6e35
stdlib@go1.24.6
1.25.10
2
phntom/kochi:1.1.33b82358bd56e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.5
0.53.0
1.25.10
2
place1/wg-access-server:v0.4.62b2f3ea80ed6
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.13.8
0.53.0
1.25.10
2
polyaxon/polyaxon-operator:2.17.07664c1cebb9d
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10
2
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.25.10
2
pottava/s3-proxy:2.020a0bcb15f76
stdlib@go1.13.7
1.25.10
2
prom/blackbox-exporter:v0.18.01ffc3f109eb3
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.15.2
0.53.0
1.25.10
2
prom/prometheus:v2.17.242d2395cd719
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.13.10
0.53.0
1.25.10
2
prom/prometheus:v2.52.05c435642ca4d
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.53.0
1.25.10
2
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
stdlib@go1.19.11
0.53.0
1.25.10
2
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
2
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.2
0.53.0
1.25.10
2
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.25.10
2
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.25.10
2
qingcloud/cloud-controller-manager:v1.4.1210f66b5df886
stdlib@go1.18.2
1.25.10
2
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.53.0
1.25.10
2
qmcgaw/ddns-updater:2.10.0:v2.10.03e2aa558946b
stdlib@go1.26.2
1.25.10
2
rajnandan1/kener:3.2.1930407afca731
stdlib@go1.20.7
1.25.10
2
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
stdlib@go1.19.4
0.53.0
1.25.10
2
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
2
rancher/kubectl:v1.36.206c7a7a97727
golang.org/x/net@v0.49.0
0.53.0
2
rancher/local-path-provisioner:v0.0.3534ff0847cc47
golang.org/x/net@v0.38.0
stdlib@go1.26.1
0.53.0
1.25.10
2
rancher/local-path-provisioner:v0.0.299bebefa0b908
golang.org/x/net@v0.27.0
stdlib@go1.22.5
0.53.0
1.25.10
2
rclone/rclone:1.6874c51b8817e5
golang.org/x/net@v0.27.0
stdlib@go1.23.3
0.53.0
1.25.10
2
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/net@v0.0.0-20220708220712-1185a9018129
stdlib@go1.18.3
0.53.0
1.25.10
2
rookout/controller:latest4451a6f6b8ec
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.53.0
1.25.10
2
rookout/data-on-prem:latest51c0fce64467
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.53.0
1.25.10
2

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.