StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,054
of 17,792 indexed, latest versions
Container images
4,683
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,054 of 17,792 indexed charts deploy, on 4,683 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,529
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,580
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,054 by stars
ChartLatestAffected imagesRadar Score
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/net@v0.30.0
stdlib@go1.22.10
0.53.0
1.25.10

Open the chart page →

4,884
ethereumchronicleVerified publisher0.3.11 of 1See more

ethereum chronicle 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.53.0
1.25.10

Open the chart page →

1,351
ethereum-metrics-exporterchronicleVerified publisher0.1.41 of 1See more

ethereum-metrics-exporter chronicle 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
samcm/ethereum-metrics-exporter:0.29.291a2d9a015c1
golang.org/x/net@v0.43.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

684
goferchronicleVerified publisher0.4.41 of 1See more

gofer chronicle 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/gofer:0.613915d2e41e04
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

721
mantlechronicleVerified publisher0.1.31 of 1See more

mantle chronicle 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.53.0
1.25.10

Open the chart page →

1,941
sith-exporterschronicleVerified publisher0.2.41 of 1See more

sith-exporters chronicle 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/oracles-updates-exporter:0.0.4992d0e793af6
stdlib@go1.19.13
1.25.10

Open the chart page →

997
spirechronicleVerified publisher0.3.61 of 1See more

spire chronicle 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,543
tor-proxychronicleVerified publisher0.1.01 of 1See more

tor-proxy chronicle 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
btcpayserver/tor:0.4.8.10e9585b68dc6b
stdlib@go1.16.5
1.25.10

Open the chart page →

3,358
zksyncchronicleVerified publisher0.1.01 of 2See more

zksync chronicle 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.10

Open the chart page →

6,052
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.53.0
1.25.10

Open the chart page →

3,602
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/chekrdigest-pinnedf299baf467b5
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.53.0
1.25.10

Open the chart page →

3,465
clairclair-helmVerified publisher0.12.02 of 3See more

clair clair-helm 0.12.0

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10
quay.io/projectquay/clair:4.9.023329c3368e4
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.53.0
1.25.10

Open the chart page →

1,625
calico-cniclastixVerified publisher3.28.13 of 3See more

calico-cni clastix 3.28.1

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
calico/cni:v3.28.1e486870cfde8
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.53.0
1.25.10
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.53.0
1.25.10
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

3,071
capi-kamaji-vsphere-fullclastixVerified publisher1.0.19 of 9See more

capi-kamaji-vsphere-full clastix 1.0.1

9 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/net@v0.32.0
stdlib@go1.23.0
0.53.0
1.25.10
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.53.0
1.25.10
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.53.0
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.53.0
1.25.10

Open the chart page →

5,996
capsule-rancher-addonclastixVerified publisher0.1.15 of 5See more

capsule-rancher-addon clastix 0.1.1

5 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/net@v0.4.0
stdlib@go1.19.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10

Open the chart page →

7,126
kamajiclastixVerified publisher0.0.0+latest2 of 4See more

kamaji clastix 0.0.0+latest

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.53.0
1.25.10
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

4,653
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
golang.org/x/net@v0.23.0
stdlib@go1.23.7
0.53.0
1.25.10

Open the chart page →

2,763
kamaji-etcdclastixVerified publisher0.17.03 of 4See more

kamaji-etcd clastix 0.17.0

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.53.0
1.25.10
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.53.0
1.25.10
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

12,075
local-path-provisionerclastixVerified publisher0.0.301 of 1See more

local-path-provisioner clastix 0.0.30

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.53.0
1.25.10

Open the chart page →

1,209
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.53.0
1.25.10
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.53.0
1.25.10

Open the chart page →

7,414
cloudflared-tunnelclouddrove0.1.41 of 1See more

cloudflared-tunnel clouddrove 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

1,775
kube-acp-stackcloudentity2.28.03 of 7See more

kube-acp-stack cloudentity 2.28.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
stdlib@go1.23.8
1.25.10
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/net@v0.33.0
stdlib@go1.21.13
0.53.0
1.25.10
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.53.0
1.25.10

Open the chart page →

21,064
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.53.0
1.25.10
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.53.0
1.25.10
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.53.0
1.25.10
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.16.6
0.53.0
1.25.10
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.53.0
1.25.10
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

18,040
cloudflare-ddns-updatecloudflare-ddns-update0.1.21 of 1See more

cloudflare-ddns-update cloudflare-ddns-update 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

1,338
cloudflare-dyndnscloudflare-dyndnsVerified publisher1.1.01 of 1See more

cloudflare-dyndns cloudflare-dyndns 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/msueberkrueb/cloudflare-dyndns:1.0.0e5c945a3b000
stdlib@go1.25.1
1.25.10

Open the chart page →

307
cloudflare-tunnel-ingress-controllercloudflare-tunnel-ingress-controller0.2.31 of 1See more

cloudflare-tunnel-ingress-controller cloudflare-tunnel-ingress-controller 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/oliverbaehler/cloudflare-tunnel-ingress-controller:0.2.30aec31e36d95
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10

Open the chart page →

438
cloudfront-tenant-operatorcloudfront-tenant-operatorVerified publisher0.3.01 of 1See more

cloudfront-tenant-operator cloudfront-tenant-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

276
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/net@v0.14.0
stdlib@go1.19.10
0.53.0
1.25.10

Open the chart page →

25,515
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.5
0.53.0
1.25.10

Open the chart page →

6,704
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18.1
0.53.0
1.25.10

Open the chart page →

6,930
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.25.10

Open the chart page →

2,815
robot-shopcloud-native-toolkit1.1.12 of 12See more

robot-shop cloud-native-toolkit 1.1.1

2 of the 12 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
robotshop/rs-dispatch:latestde81f1d07b02
stdlib@go1.17
1.25.10
robotshop/rs-mongodb:latest119b545823cd
stdlib@go1.16.3
1.25.10

Open the chart page →

29,646
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad5 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
stdlib@go1.20.12
1.25.10
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
stdlib@go1.23.8
1.25.10
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.1
0.53.0
1.25.10
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
stdlib@go1.23.8
1.25.10

Open the chart page →

18,400
cloud-provider-kubevirtcloud-provider-kubevirtVerified publisher0.2.01 of 1See more

cloud-provider-kubevirt cloud-provider-kubevirt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

663
cloudrevecloudreve0.2.01 of 2See more

cloudreve cloudreve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudreve/cloudreve:4.18.0f7a464100bf6
stdlib@go1.25.5
1.25.10

Open the chart page →

2,842
k8s-monitoring-appcloudscriptVerified publisher1.0.01 of 1See more

k8s-monitoring-app cloudscript 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/k8s-monitoring-app:v0.0.25cab66a6b3574
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.53.0
1.25.10

Open the chart page →

1,294
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.3-alpine54451ecb8ab3
stdlib@go1.24.6
1.25.10

Open the chart page →

2,180
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.16.13
0.53.0
1.25.10

Open the chart page →

3,143
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

5,610
galaxy-cvmfs-csicloudve2.5.12 of 3See more

galaxy-cvmfs-csi cloudve 2.5.1

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

1,515
galaxy-depscloudve1.1.16 of 7See more

galaxy-deps cloudve 1.1.1

6 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17
0.53.0
1.25.10
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/net@v0.0.0-20220614195744-fb05da6f9022
stdlib@go1.17
0.53.0
1.25.10
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10

Open the chart page →

10,599
galaxy-k8s-monitorcloudve0.1.11 of 1See more

galaxy-k8s-monitor cloudve 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
afgane/galaxy-k8s-monitor:latest457173db5640
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

313
galaxykubemancloudve2.10.14 of 7See more

galaxykubeman cloudve 2.10.1

4 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.13
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.53.0
1.25.10

Open the chart page →

16,155
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.53.0
1.25.10

Open the chart page →

14,372
openstack-cinder-csicloudve1.2.01 of 5See more

openstack-cinder-csi cloudve 1.2.0

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

2,068
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.53.0
1.25.10

Open the chart page →

2,854
pulsarcloudve0.2.02 of 2See more

pulsar cloudve 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
golang.org/x/net@v0.33.0
stdlib@go1.22.7
0.53.0
1.25.10
library/docker:dind5efed980cba3
golang.org/x/net@v0.50.0
0.53.0

Open the chart page →

6,181
argo-cdcluster-deploy0.3.22 of 3See more

argo-cd cluster-deploy 0.3.2

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
golang.org/x/net@v0.38.0
stdlib@go1.24.0
0.53.0
1.25.10
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

3,759
argo-eventscluster-deploy0.1.01 of 1See more

argo-events cluster-deploy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
golang.org/x/net@v0.49.0
stdlib@go1.24.11
0.53.0
1.25.10

Open the chart page →

1,043
authentikcluster-deploy0.2.01 of 1See more

authentik cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

2,527

Container images carrying it

4,683 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10
1
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10
1
conduction/kvk-php:dev8f177f9f8a7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10
1
conduction/pan-php:dev24f03c57568f
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10
1
consensys/web3signer:latestf146a51a1ba3
golang.org/x/net@v0.40.0
0.53.0
1
containous/maesh:v1.3.2587162516502
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.14.4
0.53.0
1.25.10
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.53.0
1.25.10
1
coordimap/coordimap-agent:latest7748fd0fae9f
golang.org/x/net@v0.38.0
0.53.0
1
coredns/coredns:1.12.040384aa1f5ea
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.53.0
1.25.10
1
coredns/coredns:1.7.073ca82b4ce82
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.4
0.53.0
1.25.10
1
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/net@v0.4.0
stdlib@go1.20
0.53.0
1.25.10
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.53.0
1.25.10
1
cortezaproject/corteza:2024.9.08eb7a26605c9
golang.org/x/net@v0.21.0
stdlib@go1.19.13
0.53.0
1.25.10
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.53.0
1.25.10
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
stdlib@go1.23.5
1.25.10
1
couchbase/admission-controller:2.9.3bf2d2e87e45f
golang.org/x/net@v0.43.0
0.53.0
1
couchbase/operator:2.9.369a385b49e1f
golang.org/x/net@v0.43.0
0.53.0
1
countly/api:25.05.4f4cc7447c4f5
stdlib@go1.19.4
1.25.10
1
countly/countly-server:25.05.4e3c238248f99
stdlib@go1.21.11
1.25.10
1
countly/frontend:25.05.42acbc11499b6
stdlib@go1.19.4
1.25.10
1
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.53.0
1.25.10
1
crossplane/crossplane:v0.12.066666e6963af
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.53.0
1.25.10
1
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.14
0.53.0
1.25.10
1
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.53.0
1.25.10
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.2
0.53.0
1.25.10
1
csepulvedab/secret-sync:0.5227a6f2b0ff8
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.4
0.53.0
1.25.10
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.4
0.53.0
1.25.10
1
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.53.0
1.25.10
1
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.16.13
0.53.0
1.25.10
1
cube8021/push-to-k8s:v1.1.21be9baf096ff
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
golang.org/x/net@v0.43.0
stdlib@go1.25.4
0.53.0
1.25.10
1
czerwonk/ping_exporter:v1.1.394f51e1ef1e2
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
1
dabealu/zookeeper-exporter:latest86106fec315f
stdlib@go1.14.15
1.25.10
1
dagster/dagster-cloud-agent:1.13.2322036fc83927
stdlib@go1.25.7
1.25.10
1
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.25.10
1
dalf/morty:latest248a4849c350
golang.org/x/net@v0.0.0-20220421235706-1d1ef9303861
stdlib@go1.18.2
0.53.0
1.25.10
1
danielfm/kube-ecr-cleanup-controller:0.1.1012485563b1d0
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.53.0
1.25.10
1
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10
1
dannielkil/book-db:latest433290c5c1db
stdlib@go1.18.2
1.25.10
1
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.25.10
1
daprio/dashboard:0.15.04be696707bd1
golang.org/x/net@v0.25.0
stdlib@go1.21.13
0.53.0
1.25.10
1
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
stdlib@go1.19.13
0.53.0
1.25.10
1
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.53.0
1.25.10
1
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.53.0
1.25.10
1
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.53.0
1.25.10
1
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.53.0
1.25.10
1
darioackermann/cert-manager-webhook-regery:latest0d450bc4acc4
golang.org/x/net@v0.26.0
stdlib@go1.22.10
0.53.0
1.25.10
1
darkobas/ethexporter:latest62e6464491ba
stdlib@go1.19.1
1.25.10
1
darkobas/tokenexporter:latesta0349a0eedf0
stdlib@go1.19.1
1.25.10
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.