StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,051
of 17,803 indexed, latest versions
Container images
4,685
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,051 of 17,803 indexed charts deploy, on 4,685 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,529
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,580
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,051 by stars
ChartLatestAffected imagesRadar Score
haven-complinacy-dashboardjolle-devVerified publisher1.0.01 of 2See more

haven-complinacy-dashboard jolle-dev 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.17.2
0.53.0
1.25.10

Open the chart page →

3,842
cloudnative-pgjouveVerified publisher0.27.01 of 1See more

cloudnative-pg jouve 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.28.034198e85b6e6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

654
corednsjouveVerified publisher1.45.01 of 1See more

coredns jouve 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
golang.org/x/net@v0.45.0
stdlib@go1.25.2
0.53.0
1.25.10

Open the chart page →

923
distributionjouveVerified publisher0.2.31 of 1See more

distribution jouve 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
distribution/distribution:3.1.1bca24727f400
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.53.0
1.25.10

Open the chart page →

860
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.53.0
1.25.10

Open the chart page →

22,748
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.6
0.53.0
1.25.10

Open the chart page →

16,710
firstchartjuanjmerono0.2.01 of 1See more

firstchart juanjmerono 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17
0.53.0
1.25.10

Open the chart page →

1,444
daily-restartjuniorjpdj0.1.691 of 1See more

daily-restart juniorjpdj 0.1.69

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/juniorjpdj/containers/openssl-kubectl:1.36.1-r358afba209ea0
golang.org/x/net@v0.48.0
0.53.0

Open the chart page →

467
mumbledjjuniorjpdj0.1.1991 of 2See more

mumbledj juniorjpdj 0.1.199

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/juniorjpdj/containers/openssl-kubectl:1.36.1-r358afba209ea0
golang.org/x/net@v0.48.0
0.53.0

Open the chart page →

968
alertmanager-irc-relayjuppi880.0.11 of 1See more

alertmanager-irc-relay juppi88 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
maldridge/alertmanager-irc-relay:v0.4.1391de2b76128
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.4
0.53.0
1.25.10

Open the chart page →

1,615
nginx-gateway-fabricjupyter-jscVerified publisher2.4.11 of 1See more

nginx-gateway-fabric jupyter-jsc 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nginx/nginx-gateway-fabric:2.4.180f3a0a51af5
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

373
k10appk10app0.2.11 of 11See more

k10app k10app 0.2.1

1 of the 11 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k10app/businit:latest94c9a3e799c2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

10,607
k8quk8qu1.4.01 of 1See more

k8qu k8qu 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/gijsvandulmen/k8qu:1.4e897b18db13d
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.53.0
1.25.10

Open the chart page →

569
deltabadgerk8s-chartsVerified publisher2.0.01 of 1See more

deltabadger k8s-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
stdlib@go1.24.4
1.25.10

Open the chart page →

5,725
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
stdlib@go1.18.1
1.25.10

Open the chart page →

57,344
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/net@v0.38.0
stdlib@go1.22.7
0.53.0
1.25.10

Open the chart page →

1,904
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.53.0
1.25.10

Open the chart page →

62,809
bitmagnetk8s-home-lab-repo1.0.21 of 1See more

bitmagnet k8s-home-lab-repo 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bitmagnet-io/bitmagnet:v0.10b6373349a301
golang.org/x/net@v0.43.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

1,169
blockyk8s-home-lab-repo11.2.11 of 1See more

blocky k8s-home-lab-repo 11.2.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.29.0a6d99f323d30
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.53.0
1.25.10

Open the chart page →

580
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
stdlib@go1.24.6
1.25.10

Open the chart page →

3,151
influxdb-exporterk8s-home-lab-repo1.1.31 of 1See more

influxdb-exporter k8s-home-lab-repo 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/influxdb-exporter:v0.11.427e33e18634a
stdlib@go1.19.9
1.25.10

Open the chart page →

624
maddyk8s-home-lab-repo4.2.11 of 1See more

maddy k8s-home-lab-repo 4.2.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
foxcpp/maddy:0.8.2eeb5813fc4d1
golang.org/x/net@v0.34.0
stdlib@go1.23.12
0.53.0
1.25.10

Open the chart page →

1,203
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
stdlib@go1.24.4
1.25.10

Open the chart page →

9,176
photoprismk8s-home-lab-repo10.0.11 of 1See more

photoprism k8s-home-lab-repo 10.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
photoprism/photoprism:231128-ce284de9cc4f9c
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.53.0
1.25.10

Open the chart page →

1,140
zurgk8s-home-lab-repo1.2.11 of 1See more

zurg k8s-home-lab-repo 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/debridmediamanager/zurg-testing:v0.9.3-final5c47ef99443a
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

1,733
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

2,443
k8s-mutating-webhookk8s-mutating-webhook0.3.01 of 2See more

k8s-mutating-webhook k8s-mutating-webhook 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

2,012
k8s-ondemand-proxyk8s-ondemand-proxy0.0.61 of 1See more

k8s-ondemand-proxy k8s-ondemand-proxy 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
golang.org/x/net@v0.13.0
stdlib@go1.21.1
0.53.0
1.25.10

Open the chart page →

815
librephotosk8sonlabVerified publisher1.1.63 of 7See more

librephotos k8sonlab 1.1.6

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.22.600ac10bcb759
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.17.6
0.53.0
1.25.10
bitnamilegacy/redis:latest5927ff3702df
stdlib@go1.24.5
1.25.10
reallibrephotos/librephotos-frontend:1.0.358cdf5e93471
stdlib@go1.24.13
1.25.10

Open the chart page →

14,969
thanosk8sonlabVerified publisher1.1.71 of 1See more

thanos k8sonlab 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

602
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.25.10

Open the chart page →

7,445
k8s-pausek8s-pause0.1.41 of 1See more

k8s-pause k8s-pause 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.8
0.53.0
1.25.10

Open the chart page →

1,847
k8s-s3-bucket-operatork8s-s3-bucket-operator0.2.21 of 1See more

k8s-s3-bucket-operator k8s-s3-bucket-operator 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

535
k8s-ssh-bastionk8s-ssh-bastion0.5.41 of 1See more

k8s-ssh-bastion k8s-ssh-bastion 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
golang.org/x/net@v0.23.0
stdlib@go1.21.11
0.53.0
1.25.10

Open the chart page →

3,342
k8s-validating-webhookk8s-validating-webhook0.4.01 of 2See more

k8s-validating-webhook k8s-validating-webhook 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

2,012
kube-admission-controller-starterk8s-validating-webhook0.2.01 of 2See more

kube-admission-controller-starter k8s-validating-webhook 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

2,169
k8svault-controllerk8svault-controller0.1.21 of 1See more

k8svault-controller k8svault-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

1,885
kagentkagent0.10.12 of 6See more

kagent kagent 0.10.1

2 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kagent-dev/kagent/tools:0.2.150b431281d3e
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.53.0
1.25.10
ghcr.io/kagent-dev/kmcp/controller:0.3.086ab878da25a
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

3,064
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

4,622
postgresqlkagiso-me0.4.01 of 1See more

postgresql kagiso-me 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.25.10

Open the chart page →

1,634
rediskagiso-me0.1.61 of 1See more

redis kagiso-me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.25.10

Open the chart page →

1,433
kom-operatorkaisoVerified publisher1.3.01 of 2See more

kom-operator kaiso 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kaiso/kom-operator:v2.2.0e0e22b928bdd
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

710
gpu-provisionerkaitoVerified publisher0.2.01 of 1See more

gpu-provisioner kaito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
mcr.microsoft.com/aks/kaito/gpu-provisioner:0.2.01204a7e948e9
golang.org/x/net@v0.20.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

1,045
workspacekaitoVerified publisher0.12.02 of 7See more

workspace kaito 0.12.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v5.2.0afdfa3da79df
golang.org/x/net@v0.34.0
stdlib@go1.25.5
0.53.0
1.25.10
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v1.13.2fa8eba9843ff
golang.org/x/net@v0.34.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

2,503
jenkinskallakruparaju-jenkins1.0.01 of 1See more

jenkins kallakruparaju-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

2,517
crashlooping-pod-deleterkarljorgensen0.1.31 of 1See more

crashlooping-pod-deleter karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

1,153
dockerdkarljorgensen0.1.01 of 1See more

dockerd karljorgensen 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/docker:28.5.2-dind2a232a42256f
golang.org/x/net@v0.39.0
stdlib@go1.24.9
0.53.0
1.25.10

Open the chart page →

2,054
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
golang.org/x/net@v0.17.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

7,163
k10restorekastenVerified publisher8.0.141 of 1See more

k10restore kasten 8.0.14

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

1,508
kbot-self-hostedkbot-self-hostedVerified publisher0.1.81 of 7See more

kbot-self-hosted kbot-self-hosted 0.1.8

1 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.30206a6c708fc6
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.53.0
1.25.10

Open the chart page →

33,021

Container images carrying it

4,685 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.53.0
1.25.10
2
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.53.0
1.25.10
2
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/net@v0.10.0
stdlib@go1.21.1
0.53.0
1.25.10
2
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.53.0
1.25.10
2
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10
2
quay.io/thanos/thanos:v0.39.21d022ef4b8ef
golang.org/x/net@v0.41.0
stdlib@go1.24.0
0.53.0
1.25.10
2
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10
2
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.53.0
1.25.10
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.53.0
1.25.10
2
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.53.0
1.25.10
2
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.53.0
1.25.10
2
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10
2
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.53.0
1.25.10
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.53.0
1.25.10
2
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/net@v0.23.0
stdlib@go1.23.10
0.53.0
1.25.10
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.53.0
1.25.10
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
stdlib@go1.19.3
0.53.0
1.25.10
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.53.0
1.25.10
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0db384bf43222
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.53.0
1.25.10
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
2
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-attacher:v4.9.05aaefc24f315
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-snapshotter:v8.3.0bc7be893ecc3
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
stdlib@go1.18
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.53.0
1.25.10
2
registry.k8s.io/sig-storage/snapshot-controller:v8.3.012c2da094b02
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
2
0xpolygon/bor:1.3.7396d3de26d8b
golang.org/x/net@v0.26.0
stdlib@go1.22.1
0.53.0
1.25.10
1
0xpolygon/heimdall:1.0.134ddf259993c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.53.0
1.25.10
1
1dev/server:11.9.0cd5b12fe5471
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.