StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,035
of 17,803 indexed, latest versions
Container images
4,662
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,035 of 17,803 indexed charts deploy, on 4,662 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,511
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,565
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,035 by stars
ChartLatestAffected imagesRadar Score
pyroscope-monitoringgrafana0.1.15 of 6See more

pyroscope-monitoring grafana 0.1.1

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
stdlib@go1.23.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

8,281
snyk-exportergrafana0.1.01 of 1See more

snyk-exporter grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/snyk_exporter:v1.4.1d3c9093401ca
stdlib@go1.21.0
1.25.10

Open the chart page →

669
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

5,312
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,519
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/net@v0.26.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

8,012
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:85211c51171f5
stdlib@go1.24.6
1.25.10

Open the chart page →

5,366
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/net@v0.24.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

1,398
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

14,327
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.53.0
1.25.10

Open the chart page →

2,598
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

2,182
routergroundcover1.12.3754See more

router groundcover 1.12.375

4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
stdlib@go1.25.7
1.25.10
quay.io/groundcover/tools:20260719b705e0cbe171
stdlib@go1.24.4
1.25.10

Open the chart page →

temporalgroundcover1.12.3751See more

temporal groundcover 1.12.375

1 container image this version deploys carries CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

mysqlgroundhog2k3.1.41 of 1See more

mysql groundhog2k 3.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
stdlib@go1.24.6
1.25.10

Open the chart page →

463
tailscale-subnet-routergtaylor1.2.11 of 1See more

tailscale-subnet-router gtaylor 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
golang.org/x/net@v0.1.0
stdlib@go1.19.2-ts3fd24dee31
0.53.0
1.25.10

Open the chart page →

1,834
minifluxhajowielandVerified publisher1.0.01 of 1See more

miniflux hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

1,113
hakoniwahakoniwa0.1.01 of 1See more

hakoniwa hakoniwa 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/aplulu/hakoniwa:0.1.0accf0b921388
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

338
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.53.0
1.25.10

Open the chart page →

2,381
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.3
0.53.0
1.25.10

Open the chart page →

4,462
mautrix-signalhalkeye0.3.01 of 2See more

mautrix-signal halkeye 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
signald/signald:0.23.2edbff058278c
stdlib@go1.18.10
1.25.10

Open the chart page →

1,500
thunderdome-planning-pokerhalkeye0.1.11 of 1See more

thunderdome-planning-poker halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

425
whoamihalkeye1.0.11 of 1See more

whoami halkeye 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
containous/whoami:v1.5.07d6a3c8f9147
stdlib@go1.14
1.25.10

Open the chart page →

1,280
hcp-terraform-operatorhashicorpVerified publisher2.12.11 of 2See more

hcp-terraform-operator hashicorp 2.12.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.20.1f5fbfec6a2b2
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

685
hatchet-apihatchetOfficialVerified publisher0.19.01 of 4See more

hatchet-api hatchet 0.19.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

1,707
hatchet-hahatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-ha hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

7,447
hatchet-stackhatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-stack hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

7,447
hawk-envoy-pluginhawk0.1.02 of 4See more

hawk-envoy-plugin hawk 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/collector-go:main7217f1a4fa28
stdlib@go1.17.13
1.25.10
ghcr.io/privacyengineering/consumer:main73f59c032812
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

9,233
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.6
0.53.0
1.25.10

Open the chart page →

3,029
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/net@v0.0.0-20200520182314-0ba52f642ac2
stdlib@go1.14.7
0.53.0
1.25.10

Open the chart page →

2,637
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.25.10

Open the chart page →

6,758
headcniheadcni1.0.101 of 1See more

headcni headcni 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
binrc/headcni:1.0.10e199c334b957
stdlib@go1.22.10
1.25.10

Open the chart page →

724
heliconehelicone0.1.422 of 14See more

helicone helicone 0.1.42

2 of the 14 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
stdlib@go1.19.5
1.25.10
supabase/gotrue:v2.91.07174d551d720
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

25,250
hello-gohello-goVerified publisher0.2.21 of 1See more

hello-go hello-go 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.25.10

Open the chart page →

1,315
hello_worldcharthellohelm0.1.01 of 1See more

hello_worldchart hellohelm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dockerdaemon0901/rolldice:v14e5bfe179c7e
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

855
helm-airportshelm-airports0.1.02 of 7See more

helm-airports helm-airports 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

12,718
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,558
airports-postgreshelm-airports-dan0.1.01 of 1See more

airports-postgres helm-airports-dan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10

Open the chart page →

1,027
helm-airportshelm-airports-dan0.1.02 of 7See more

helm-airports helm-airports-dan 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

5,585
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,558
airports-postgreshelm-airports-postgres0.1.01 of 1See more

airports-postgres helm-airports-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10

Open the chart page →

1,027
pageshelm-chart-repos-camden1.0.01 of 3See more

pages helm-chart-repos-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,262
adguard-homehelm-chart-roeiVerified publisher0.107.591 of 2See more

adguard-home helm-chart-roei 0.107.59

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.595d5e3aef39a8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

761
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
stdlib@go1.23.3
1.25.10

Open the chart page →

4,653
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
iofog/router:2.0.17260cf861479
stdlib@go1.15
1.25.10

Open the chart page →

24,205
logging-stackhelm-charts-alexis-carbillet0.1.05 of 9See more

logging-stack helm-charts-alexis-carbillet 0.1.0

5 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18
0.53.0
1.25.10
grafana/grafana:11.1.0079600c9517b
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.53.0
1.25.10
grafana/loki:2.8.2b1da1d23037e
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.53.0
1.25.10
grafana/loki-canary:2.6.1ab2a2569307b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.53.0
1.25.10

Open the chart page →

12,685
monitoring-stackhelm-charts-alexis-carbillet0.1.09 of 11See more

monitoring-stack helm-charts-alexis-carbillet 0.1.0

9 of the 11 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.53.0
1.25.10
grafana/grafana:latestf772d434e8fa
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.53.0
1.25.10
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.70.0e20576b76ffd
golang.org/x/net@v0.19.0
stdlib@go1.21.4
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.7.04cb2b9019f17
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/net@v0.10.0
stdlib@go1.21.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

10,649
teslamate-apihelm-charts-darox1.0.11 of 1See more

teslamate-api helm-charts-darox 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
tobiasehlert/teslamateapi:1.20.2cf09259ad0ea
golang.org/x/net@v0.37.0
stdlib@go1.24.0
0.53.0
1.25.10

Open the chart page →

1,043
aws-ebs-csi-driverhelm-charts-nr2.17.46 of 6See more

aws-ebs-csi-driver helm-charts-nr 2.17.4

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/net@v0.4.0
stdlib@go1.19.6
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/net@v0.4.0
stdlib@go1.19.8
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes-csi/livenessprobe:v2.9.0-eks-1-25-latest8a305e162caa
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes-csi/node-driver-registrar:v2.7.0-eks-1-25-latestf4345e67df8f
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.53.0
1.25.10

Open the chart page →

6,525
aws-s3-proxyhelm-charts-nr0.1.71 of 1See more

aws-s3-proxy helm-charts-nr 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
pottava/s3-proxy:2.020a0bcb15f76
stdlib@go1.13.7
1.25.10

Open the chart page →

1,323
aws-service-events-exporterhelm-charts-nr1.0.71 of 1See more

aws-service-events-exporter helm-charts-nr 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
stdlib@go1.15.6
1.25.10

Open the chart page →

1,300
aws-service-quotas-exporterhelm-charts-nr0.1.41 of 1See more

aws-service-quotas-exporter helm-charts-nr 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
thoughtmachine/aws-service-quotas-exporter:v1.3.2c6065ba55c72
stdlib@go1.19.4
1.25.10

Open the chart page →

771

Container images carrying it

4,662 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
golang.org/x/net@v0.34.0
stdlib@go1.22.10
0.53.0
1.25.10
1
aristidetm/basic-notebook:3.6.5469dbc951224
golang.org/x/net@v0.7.0
stdlib@go1.22.5
0.53.0
1.25.10
1
artifacthub/db-migrator:v1.19.02a746b289fcd
stdlib@go1.22.4
1.25.10
1
artifacthub/hub:v1.19.0111918d8c399
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10
1
artifacthub/scanner:v1.23.02d8365601f0e
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.53.0
1.25.10
1
artifacthub/scanner:v1.19.0323d026e78c3
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.53.0
1.25.10
1
artifacthub/tracker:v1.23.05368d21a6e5c
golang.org/x/net@v0.44.0
stdlib@go1.24.4
0.53.0
1.25.10
1
artifacthub/tracker:v1.19.06596c8c4d955
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
stdlib@go1.22.4
1.25.10
1
arunvelsriram/utils:latest655ad18fd8d6
golang.org/x/net@v0.24.0
stdlib@go1.23.8
0.53.0
1.25.10
1
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.25.10
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.53.0
1.25.10
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
stdlib@go1.18.2
1.25.10
1
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.53.0
1.25.10
1
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.53.0
1.25.10
1
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.53.0
1.25.10
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.25.10
1
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.25.10
1
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.13
0.53.0
1.25.10
1
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.53.0
1.25.10
1
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.22.1
1.25.10
1
astarte/astarte-kubernetes-operator:26.5.1e3ff1b3c0c98
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.53.0
1.25.10
1
atlassian/bamboo:12.1.114af4bb6c8d46
stdlib@go1.22.2
1.25.10
1
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
stdlib@go1.22.2
1.25.10
1
automatischio/automatisch:0.15.03bace7a12d5f
stdlib@go1.23.8
1.25.10
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.53.0
1.25.10
1
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.53.0
1.25.10
1
ayushsobti/kube-monkey:v0.5.40a5bb6fc3f3f
golang.org/x/net@v0.49.0
0.53.0
1
b3log/siyuan:v3.1.2595c0d129bc19
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10
1
baserow/backend:1.31.1e0b3c8130b91
stdlib@go1.19.8
1.25.10
1
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.17.8
0.53.0
1.25.10
1
beanbag/reviewboard:latest6b840f546e1c
stdlib@go1.18.1
1.25.10
1
bedag/goblackhole:0.2.0447a88598f4c
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.6
0.53.0
1.25.10
1
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/net@v0.37.0
stdlib@go1.23.12
0.53.0
1.25.10
1
beopenit/door-cd-operator:v3.0.4d3999cb8d026
golang.org/x/net@v0.17.0
stdlib@go1.23.9
0.53.0
1.25.10
1
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/net@v0.15.0
stdlib@go1.19.13
0.53.0
1.25.10
1
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.53.0
1.25.10
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
golang.org/x/net@v0.38.0
stdlib@go1.23.5
0.53.0
1.25.10
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.6
0.53.0
1.25.10
1
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/net@v0.2.0
stdlib@go1.17.6
0.53.0
1.25.10
1
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/net@v0.0.0-20220418201149-a630d4f3e7a2
stdlib@go1.19.3
0.53.0
1.25.10
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.25.10
1
binrc/headcni:1.0.10e199c334b957
stdlib@go1.22.10
1.25.10
1
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
golang.org/x/net@v0.25.0
stdlib@go1.22.2
0.53.0
1.25.10
1
binwiederhier/ntfy:v2.6.283e2e43d9956
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.53.0
1.25.10
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.53.0
1.25.10
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.53.0
1.25.10
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.