StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,043
of 17,797 indexed, latest versions
Container images
4,670
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,043 of 17,797 indexed charts deploy, on 4,670 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,519
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,570
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,043 by stars
ChartLatestAffected imagesRadar Score
redisneomanexlabsVerified publisher1.1.01 of 1See more

redis neomanexlabs 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.25.10

Open the chart page →

1,288
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.53.0
1.25.10

Open the chart page →

6,991
neosyncneosyncVerified publisher0.5.412 of 3See more

neosync neosync 0.5.41

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
golang.org/x/net@v0.37.0
stdlib@go1.24.5
0.53.0
1.25.10
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
golang.org/x/net@v0.37.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

7,260
apineosync-apiVerified publisher0.5.411 of 1See more

api neosync-api 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
golang.org/x/net@v0.37.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

2,856
workerneosync-workerVerified publisher0.5.411 of 1See more

worker neosync-worker 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
golang.org/x/net@v0.37.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

2,833
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
stdlib@go1.25.6
1.25.10

Open the chart page →

2,386
core-keeper-dedicatednerkho-helm-charts0.1.11 of 1See more

core-keeper-dedicated nerkho-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
escaping/core-keeper-dedicated:latest87fa79255962
stdlib@go1.24.4
1.25.10

Open the chart page →

3,927
kubernetes-operatornetbird0.3.11 of 1See more

kubernetes-operator netbird 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
netbirdio/kubernetes-operator:0.3.157740157b4d7
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

210
netbirdnetbird1.9.03 of 4See more

netbird netbird 1.9.0

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.53.0
1.25.10
netbirdio/relay:0.46.0d32f82514a24
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.53.0
1.25.10
netbirdio/signal:0.46.0e8f392611152
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.53.0
1.25.10

Open the chart page →

6,441
netris-dpu-agentnetrisai0.1.01 of 1See more

netris-dpu-agent netrisai 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
netrisai/bare-metal-dpu-agent:4.7.0.003c271efe749d0
golang.org/x/net@v0.50.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

1,584
iamdnetsocVerified publisher0.6.11 of 2See more

iamd netsoc 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

2,891
shhdnetsocVerified publisher0.1.71 of 1See more

shhd netsoc 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.17
0.53.0
1.25.10

Open the chart page →

3,987
webspacednetsocVerified publisher0.2.82 of 2See more

webspaced netsoc 0.2.8

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.53.0
1.25.10
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
stdlib@go1.16.8
0.53.0
1.25.10

Open the chart page →

5,193
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

7,500
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

3,874
agent-control-cdnewrelic1.0.03 of 3See more

agent-control-cd newrelic 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
golang.org/x/net@v0.35.0
stdlib@go1.23.6
0.53.0
1.25.10
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

5,054
nexus-freenexus-freeVerified publisher1.0.31 of 1See more

nexus-free nexus-free 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/fossa/postgres:17.2-15af45ac79f38
stdlib@go1.18.2
1.25.10

Open the chart page →

1,122
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-backend:2.0.0f80349eb018b
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.53.0
1.25.10

Open the chart page →

3,802
nginx-examplengrok-ingress-helm0.3.01 of 2See more

nginx-example ngrok-ingress-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wernight/ngrok:latestd211f29ebcfe
golang.org/x/net@v0.17.0
stdlib@go1.21.6
0.53.0
1.25.10

Open the chart page →

2,989
cert-managernicklasfrahm-cert-managerVerified publisher0.1.24 of 4See more

cert-manager nicklasfrahm-cert-manager 0.1.2

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.18.2af59e01ad975
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.18.281316365dc0b
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.18.21075e0974151
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.18.29431f0d8b510
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

2,840
ciliumnicklasfrahm-ciliumVerified publisher0.7.45 of 6See more

cilium nicklasfrahm-cilium 0.7.4

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
golang.org/x/net@v0.41.0
stdlib@go1.24.2
0.53.0
1.25.10
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
golang.org/x/net@v0.41.0
stdlib@go1.24.7
0.53.0
1.25.10
quay.io/cilium/hubble-relay:v1.18.26079308ee15e
golang.org/x/net@v0.42.0
stdlib@go1.24.7
0.53.0
1.25.10
quay.io/cilium/hubble-ui-backend:v0.13.3db1454e45dc3
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.53.0
1.25.10
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
golang.org/x/net@v0.42.0
stdlib@go1.24.7
0.53.0
1.25.10

Open the chart page →

7,237
metrics-servernicklasfrahm-metrics-serverVerified publisher0.1.11 of 1See more

metrics-server nicklasfrahm-metrics-server 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

792
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
stdlib@go1.21.5
1.25.10

Open the chart page →

2,292
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.6
0.53.0
1.25.10

Open the chart page →

2,063
terraform-backendnimbolus0.3.21 of 2See more

terraform-backend nimbolus 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/terraform-backend:0.2.2bf876252fbe1
golang.org/x/net@v0.46.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

2,492
yopassnimbolus0.6.11 of 2See more

yopass nimbolus 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jhaals/yopass:11.17.026873480863b
stdlib@go1.20.5
1.25.10

Open the chart page →

1,832
airflownineinfra-charts1.12.12 of 4See more

airflow nineinfra-charts 1.12.1

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.25.10
quay.io/prometheus/statsd-exporter:v0.22.8f53cca722a03
stdlib@go1.18.6
1.25.10

Open the chart page →

2,259
cloudnative-pgnineinfra-charts0.19.11 of 1See more

cloudnative-pg nineinfra-charts 0.19.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,188
doris-operatornineinfra-charts1.3.11 of 1See more

doris-operator nineinfra-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
selectdb/doris.k8s-operator:1.3.1919210765cb8
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.53.0
1.25.10

Open the chart page →

870
hdfs-operatornineinfra-charts0.7.01 of 1See more

hdfs-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/hdfs-operator:v0.7.0debb1e3410e2
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

723
kyuubi-operatornineinfra-charts0.7.01 of 1See more

kyuubi-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/kyuubi-operator:v0.7.08d8ed87ef77c
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.53.0
1.25.10

Open the chart page →

815
metastore-operatornineinfra-charts0.7.01 of 1See more

metastore-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/metastore-operator:v0.7.011259032fb04
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.53.0
1.25.10

Open the chart page →

815
minio-directpvnineinfra-charts4.0.85 of 5See more

minio-directpv nineinfra-charts 4.0.8

5 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/minio/csi-node-driver-registrardigest-pinnedc805fdc16676
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
quay.io/minio/csi-provisionerdigest-pinned7b5c070ec70d
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
quay.io/minio/csi-resizerdigest-pinned819f68a4daf7
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
quay.io/minio/directpv:v4.0.84560083eb77d
golang.org/x/net@v0.8.0
stdlib@go1.21.0
0.53.0
1.25.10
quay.io/minio/livenessprobedigest-pinnedf3bc9a84f149
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10

Open the chart page →

7,070
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
golang.org/x/net@v0.13.0
stdlib@go1.21.1
0.53.0
1.25.10

Open the chart page →

3,425
nineinfranineinfra-charts0.7.01 of 1See more

nineinfra nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/nineinfra:v0.7.0d4aad414eccd
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,120
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.25.10

Open the chart page →

3,950
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

1,439
zookeeper-operatornineinfra-charts0.7.01 of 1See more

zookeeper-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/zookeeper-operator:v0.7.0af6eb2f37bfc
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

723
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

6,977
cosmoshub-rpcnodeifyVerified publisher1.0.71 of 2See more

cosmoshub-rpc nodeify 1.0.7

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

2,015
cosmos-nodenodeifyVerified publisher2.6.01 of 2See more

cosmos-node nodeify 2.6.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

2,015
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/net@v0.41.0
stdlib@go1.24.10
0.53.0
1.25.10

Open the chart page →

6,586
firehose-ethereumnodeifyVerified publisher1.7.11 of 2See more

firehose-ethereum nodeify 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

5,695
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
stdlib@go1.19.3
1.25.10

Open the chart page →

2,919
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.53.0
1.25.10

Open the chart page →

4,756
nodejsweeklynodejsweekly1.1.01 of 1See more

nodejsweekly nodejsweekly 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

1,489
node-labels-exporternode-labels-exporter0.1.91 of 1See more

node-labels-exporter node-labels-exporter 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/node-labels-exporter:v0.5.1dd6875a0a963
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

292
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/net@v0.19.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

2,973
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

7,748
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
robjuz/postgresql-nominatim:latest805c7bab76df
stdlib@go1.16.5
1.25.10

Open the chart page →

22,795

Container images carrying it

4,670 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
rss3/op-batcher:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8adae8a5bdd7a6
stdlib@go1.21.3
1.25.10
2
rss3/op-proposer:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8aa4059dd32c48
stdlib@go1.21.3
1.25.10
2
samcm/ethereum-metrics-exporter:0.29.2:latest91a2d9a015c1
golang.org/x/net@v0.43.0
stdlib@go1.25.8
0.53.0
1.25.10
2
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.53.0
1.25.10
2
sikalabs/hello-world-server:latest5f49bf889a64
stdlib@go1.26.2
1.25.10
2
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
stdlib@go1.13.4
0.53.0
1.25.10
2
starrocks/operator:v1.11.78c20435a7579
golang.org/x/net@v0.17.0
stdlib@go1.22.12
0.53.0
1.25.10
2
statping/statping:v0.90.74e874da513a5c
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.13
0.53.0
1.25.10
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.53.0
1.25.10
2
taigaio/taiga-back:latest4beed8f62c9f
stdlib@go1.24.4
1.25.10
2
taigaio/taiga-protected:latestfd4568a97a59
stdlib@go1.24.4
1.25.10
2
temporalio/server:1.22.4c0a44c26397b
golang.org/x/net@v0.7.0
stdlib@go1.20.11
0.53.0
1.25.10
2
temporalio/ui:2.16.2af9c9349708f
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.53.0
1.25.10
2
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
2
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.53.0
1.25.10
2
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.53.0
1.25.10
2
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
stdlib@go1.15.6
1.25.10
2
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.53.0
1.25.10
2
thoughtmachine/aws-service-quotas-exporter:v1.3.2c6065ba55c72
stdlib@go1.19.4
1.25.10
2
timescale/timescaledb:latest-pg156343bdc87ca1
stdlib@go1.24.6
1.25.10
2
tkpd/gripmock:1.10.174441dadcfbd
stdlib@go1.14.6
1.25.10
2
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
stdlib@go1.20.14
0.53.0
1.25.10
2
uselagoon/docker-host:v3.6.12c89ed939b8b
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
2
victoriametrics/vmalert:v1.95.1a83e5db0897a
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.53.0
1.25.10
2
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.53.0
1.25.10
2
voltha/voltha-openolt-adapter:4.5.16d6d79c08350a
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.53.0
1.25.10
2
voltha/voltha-openonu-adapter-go:2.12.25d8f2eb5f2a7e
golang.org/x/net@v0.33.0
stdlib@go1.23.1
0.53.0
1.25.10
2
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.53.0
1.25.10
2
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.53.0
1.25.10
2
wolveix/satisfactory-server:latest:v1.9.10e103700ae6ae
stdlib@go1.18.1
1.25.10
2
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.53.0
1.25.10
2
yzhou442/equiz:latesta3f7ca69e28d
stdlib@go1.16.7
1.25.10
2
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
2
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
2
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
2
gcr.io/k8s-staging-sig-storage/csi-provisioner:v3.2.14ad5fcdbe7e9
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
stdlib@go1.18
0.53.0
1.25.10
2
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.53.0
1.25.10
2
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller0d5f740b4224
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.53.0
1.25.10
2
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook697668be7893
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.53.0
1.25.10
2
gcr.io/knative-releases/knative.dev/serving/cmd/activator031408ec516f
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
2
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler3502bb5aa60f
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
2
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa7405faeb7636
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
2
gcr.io/knative-releases/knative.dev/serving/cmd/controller5b93308a392c
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
2
gcr.io/knative-releases/knative.dev/serving/cmd/webhook50831d9aaa69
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
2
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.53.0
1.25.10
2
ghcr.io/appscode/grafana-tools:v0.8.077c9d29080eb
golang.org/x/net@v0.52.0
0.53.0
2
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.53.0
1.25.10
2
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
stdlib@go1.24.9
0.53.0
1.25.10
2
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.53.0
1.25.10
2
ghcr.io/appscode/license-proxyserver:v0.1.1e192ad567e0b
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
2

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.