StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,056
of 17,787 indexed, latest versions
Container images
4,691
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,056 of 17,787 indexed charts deploy, on 4,691 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,537
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,584
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,056 by stars
ChartLatestAffected imagesRadar Score
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
stdlib@go1.24.4
1.25.10

Open the chart page →

3,816
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.263 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

3 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
stdlib@go1.20.5
1.25.10
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
stdlib@go1.19.12
1.25.10
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.25.10

Open the chart page →

14,568
feedbacksystemthm-mni-iiVerified publisher0.47.16 of 10See more

feedbacksystem thm-mni-ii 0.47.1

6 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.53.0
1.25.10
bitnamilegacy/mysql:8.0.35-debian-11-r2be03e8ea6129
stdlib@go1.21.5
1.25.10
library/docker:20.10.21-dind3153fa63f546
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.7
0.53.0
1.25.10
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
stdlib@go1.20.12
1.25.10
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.53.0
1.25.10

Open the chart page →

28,579
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

1,494
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.14.4
0.53.0
1.25.10

Open the chart page →

4,136
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.53.0
1.25.10
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.53.0
1.25.10
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.19
0.53.0
1.25.10

Open the chart page →

9,257
k8s-ttl-controllertwin0.4.01 of 1See more

k8s-ttl-controller twin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/net@v0.26.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

471
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/net@v0.11.0
stdlib@go1.19.6
0.53.0
1.25.10
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/net@v0.17.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

10,355
crossplaneupbound-stable2.4.0-up.11 of 5See more

crossplane upbound-stable 2.4.0-up.1

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.10

Open the chart page →

1,638
uptraceuptrace2.0.21 of 2See more

uptrace uptrace 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
uptrace/uptrace:2.0.234a02c3b2d12
golang.org/x/net@v0.42.0
stdlib@go1.24.10
0.53.0
1.25.10

Open the chart page →

1,620
valkey-operatorvalkeyVerified publisher0.6.01 of 1See more

valkey-operator valkey 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/valkey-io/valkey-operator:v0.6.052a0f1ed0c03
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

134
vaultvaultVerified publisher1.22.02 of 4See more

vault vault 1.22.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.35.5d870622d0040
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.53.0
1.25.10
prom/statsd-exporter:v0.29.0632f70580492
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.53.0
1.25.10

Open the chart page →

4,243
vouchvouchVerified publisher3.2.01 of 1See more

vouch vouch 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

1,031
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

1,344
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.5
0.53.0
1.25.10

Open the chart page →

2,245
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

1,000
wallarm-ingresswallarmVerified publisher5.3.10-12 of 2See more

wallarm-ingress wallarm 5.3.10-1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.53.0
1.25.10

Open the chart page →

1,301
wallarm-sidecarwallarmOfficialVerified publisher6.13.11 of 3See more

wallarm-sidecar wallarm 6.13.1

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.53.0
1.25.10

Open the chart page →

965
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.25.10

Open the chart page →

3,178
argo-cdwenerme10.9.12 of 3See more

argo-cd wenerme 10.9.1

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/net@v0.50.0
stdlib@go1.25.6
0.53.0
1.25.10
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

2,989
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.17.4
0.53.0
1.25.10

Open the chart page →

6,085
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:15.186eb0add3b77c
stdlib@go1.24.6
1.25.10

Open the chart page →

8,587
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18.1
0.53.0
1.25.10
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.53.0
1.25.10
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.53.0
1.25.10
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.53.0
1.25.10

Open the chart page →

10,033
windmillwindmill4.0.2631 of 3See more

windmill windmill 4.0.263

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

1,638
buildkitdwiremindVerified publisher0.33.01 of 1See more

buildkitd wiremind 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

1,153
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.53.0
1.25.10

Open the chart page →

4,713
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.4
0.53.0
1.25.10

Open the chart page →

4,041
yet-another-cloudwatch-exporteryet-another-cloudwatch-exporter0.38.01 of 1See more

yet-another-cloudwatch-exporter yet-another-cloudwatch-exporter 0.38.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
stdlib@go1.22.4
1.25.10

Open the chart page →

923
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
stdlib@go1.23.12
1.25.10

Open the chart page →

4,016
paperlesszekker6Verified publisher11.8.01 of 1See more

paperless zekker6 11.8.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10

Open the chart page →

4,644
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.53.0
1.25.10

Open the chart page →

828
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
golang.org/x/net@v0.38.0
stdlib@go1.23.7
0.53.0
1.25.10

Open the chart page →

1,836
no-latest-tag-webhookadmission-webhook-no-latest1.0.141 of 1See more

no-latest-tag-webhook admission-webhook-no-latest 1.0.14

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/omkar-shelke25/admission-webhook-no-latest:sha-33165455976a1d3236a
golang.org/x/net@v0.38.0
0.53.0

Open the chart page →

162
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10

Open the chart page →

19,769
agentareaagentareaVerified publisher0.0.187 of 16See more

agentarea agentarea 0.0.18

7 of the 16 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-manager:latestefe23cef3727
stdlib@go1.22.5
1.25.10
agentarea/agentarea-mcp-runner:latestd3c209a5d531
stdlib@go1.19.8
1.25.10
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10
library/postgres:alpined3e1620b530c
stdlib@go1.24.6
1.25.10
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.53.0
1.25.10
temporalio/auto-setup:1.29.15b3502a3b685
golang.org/x/net@v0.35.0
stdlib@go1.25.0
0.53.0
1.25.10
temporalio/ui:2.39.0b768f87f18b5
golang.org/x/net@v0.40.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

14,960
alertmanager-discordalertmanagerdiscordVerified publisher0.3.21 of 1See more

alertmanager-discord alertmanagerdiscord 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
speckle/alertmanager-discord:latestf6221ff308e9
stdlib@go1.22.4
1.25.10

Open the chart page →

419
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
stdlib@go1.24.4
1.25.10

Open the chart page →

11,936
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.25.10

Open the chart page →

12,061
clearml-servingallegroaiVerified publisher1.6.26 of 9See more

clearml-serving allegroai 1.6.2

6 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
stdlib@go1.19.6
1.25.10
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
stdlib@go1.18.2
1.25.10
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.10
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

17,879
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.25.10

Open the chart page →

4,996
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.25.10

Open the chart page →

8,384
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.53.0
1.25.10

Open the chart page →

3,119
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

2,173
cloudflare-operatorankra-chartsVerified publisher0.2.01 of 1See more

cloudflare-operator ankra-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
adyanth/cloudflare-operatordigest-pinned6b168dc237d5
golang.org/x/net@v0.39.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

493
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
stdlib@go1.24.4
1.25.10

Open the chart page →

5,918
upcloud-csiankra-chartsVerified publisher0.4.08 of 8See more

upcloud-csi ankra-charts 0.4.0

8 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
golang.org/x/net@v0.43.0
stdlib@go1.23.12
0.53.0
1.25.10
ghcr.io/upcloudltd/upcloud-csidigest-pinned5af91c663788
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.53.0
1.25.10
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.53.0
1.25.10

Open the chart page →

14,920
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

1,149
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

3,378
anteonanteonVerified publisher2.6.45 of 13See more

anteon anteon 2.6.4

5 of the 13 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.53.0
1.25.10
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.53.0
1.25.10
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.53.0
1.25.10
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.25.10
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
stdlib@go1.19.11
0.53.0
1.25.10

Open the chart page →

22,233
antreaantreaVerified publisher2.7.01 of 2See more

antrea antrea 2.7.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
stdlib@go1.25.7
1.25.10

Open the chart page →

3,514

Container images carrying it

4,691 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
golang.org/x/net@v0.38.0
stdlib@go1.18.3
0.53.0
1.25.10
1
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.53.0
1.25.10
1
andreacioni/kube-workload-restarter:0.0.242938b310090a
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.53.0
1.25.10
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.25.10
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
stdlib@go1.18.2
1.25.10
1
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.25.10
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.53.0
1.25.10
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.25.10
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
stdlib@go1.25.7
1.25.10
1
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.25.10
1
anujdatar/cups:25.07.01685df04a643b
stdlib@go1.19.8
1.25.10
1
apache/airflow:2.8.4-python3.964e58748b6b9
stdlib@go1.21.8
1.25.10
1
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
stdlib@go1.23.7
1.25.10
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
stdlib@go1.22.7
1.25.10
1
apache/airflow:2.8.1e5560ad0b86e
stdlib@go1.19.8
1.25.10
1
apache/apisix-dashboard:2.9.0c010ea7d1694
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.15
0.53.0
1.25.10
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.13.8
0.53.0
1.25.10
1
apache/camel-k:1.10.43bb13d14f64a
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.13
0.53.0
1.25.10
1
apache/doris:operator-latest3a4422656592
golang.org/x/net@v0.33.0
stdlib@go1.23.12
0.53.0
1.25.10
1
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.53.0
1.25.10
1
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.53.0
1.25.10
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.53.0
1.25.10
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.53.0
1.25.10
1
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.53.0
1.25.10
1
apache/solr-operator:v0.9.14db34508137f
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.53.0
1.25.10
1
apache/tika:3.3.1.090b7fa1dc018
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.53.0
1.25.10
1
apecloud/dt-platform:0.1.1d48bcbd38066
golang.org/x/net@v0.8.0
stdlib@go1.19.11
0.53.0
1.25.10
1
apecloud/gemini-scheduler:0.1.15832d1a9097a
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.53.0
1.25.10
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.53.0
1.25.10
1
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.13
0.53.0
1.25.10
1
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.53.0
1.25.10
1
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
stdlib@go1.19.6
0.53.0
1.25.10
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/net@v0.5.0
stdlib@go1.19.13
0.53.0
1.25.10
1
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/net@v0.40.0
stdlib@go1.25.7
0.53.0
1.25.10
1
appwrite/appwrite:1.9.6adc7d0e7ec23
golang.org/x/net@v0.40.0
0.53.0
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.53.0
1.25.10
1
aquasec/kube-bench:v0.6.176672264accce
stdlib@go1.20.4
1.25.10
1
aquasec/kube-bench:v0.15.07a8fa32dce21
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.53.0
1.25.10
1
aquasec/kube-bench:v0.6.9c329d73fea58
stdlib@go1.19
1.25.10
1
aquasec/postee:2.12.0-amd640795cba777e7
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
1
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.53.0
1.25.10
1
aquasec/starboard-operator:0.15.38e0b1c7ddc843
golang.org/x/net@v0.41.0
0.53.0
1
aquasec/tracee:0.24.1cfbbfee972e6
golang.org/x/net@v0.42.0
stdlib@go1.24.9
0.53.0
1.25.10
1
aquasec/trivy:0.43.1944a04445179
golang.org/x/net@v0.11.0
stdlib@go1.19.10
0.53.0
1.25.10
1
aquasec/trivy:0.32.0973d0df16189
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.53.0
1.25.10
1
aquasec/trivy:0.69.3bcc376de8d77
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.53.0
1.25.10
1
archivebox/archivebox:0.7.41a5a37331091
stdlib@go1.24.6
1.25.10
1
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
golang.org/x/net@v0.34.0
stdlib@go1.22.10
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.