StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,051
of 17,803 indexed, latest versions
Container images
4,685
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,051 of 17,803 indexed charts deploy, on 4,685 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,529
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,580
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,051 by stars
ChartLatestAffected imagesRadar Score
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.53.0
1.25.10

Open the chart page →

4,768
nodejsweeklynodejsweekly1.1.01 of 1See more

nodejsweekly nodejsweekly 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

1,489
node-labels-exporternode-labels-exporter0.1.91 of 1See more

node-labels-exporter node-labels-exporter 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/node-labels-exporter:v0.5.1dd6875a0a963
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

292
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/net@v0.19.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

2,983
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

7,758
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
robjuz/postgresql-nominatim:latest805c7bab76df
stdlib@go1.16.5
1.25.10

Open the chart page →

22,812
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

5,940
ingress-helm-chartnotesprojectchart0.1.02 of 2See more

ingress-helm-chart notesprojectchart 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10

Open the chart page →

2,956
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,559
keycloak-helm-chartnotesprojectchart0.1.01 of 2See more

keycloak-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

1,686
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

6,903
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

5,966
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

5,923
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

2,257
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,539
clusterfannousefreakVerified publisher0.1.21 of 1See more

clusterfan nousefreak 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nousefreak/clusterfan:v0.1.04ea05e2a7b57
stdlib@go1.17.5
1.25.10

Open the chart page →

1,791
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.5
0.53.0
1.25.10

Open the chart page →

4,862
nfs-server-provisionernovum-rgi-charts1.1.21 of 1See more

nfs-server-provisioner novum-rgi-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.53.0
1.25.10

Open the chart page →

2,806
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.11
0.53.0
1.25.10

Open the chart page →

27,560
nri-memory-policynri-pluginsVerified publisher0.14.01 of 1See more

nri-memory-policy nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memory-policy:v0.14.0531d21ec4ba2
stdlib@go1.26.0
1.25.10

Open the chart page →

272
nri-memory-qosnri-pluginsOfficialVerified publisher0.14.01 of 1See more

nri-memory-qos nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memory-qos:v0.14.0c7c5c24ed894
stdlib@go1.26.0
1.25.10

Open the chart page →

272
nri-resctrl-monnri-pluginsVerified publisher0.14.01 of 1See more

nri-resctrl-mon nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resctrl-mon:v0.14.0a9c9775fab70
stdlib@go1.26.0
1.25.10

Open the chart page →

272
nri-resource-annotatornri-pluginsVerified publisher0.14.01 of 1See more

nri-resource-annotator nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resource-annotator:v0.14.08100a19e85f7
stdlib@go1.26.0
1.25.10

Open the chart page →

235
nri-resource-policy-templatenri-pluginsVerified publisher0.14.01 of 1See more

nri-resource-policy-template nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resource-policy-template:v0.14.00edfc075277b
stdlib@go1.26.0
1.25.10

Open the chart page →

303
nri-sgx-epcnri-pluginsVerified publisher0.14.01 of 1See more

nri-sgx-epc nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-sgx-epc:v0.14.0b4c4d0d83c14
stdlib@go1.26.0
1.25.10

Open the chart page →

272
cnaos-pvc-populatornutanix-helm-releasesVerified publisher1.1.0-174-prod1 of 2See more

cnaos-pvc-populator nutanix-helm-releases 1.1.0-174-prod

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.53.0
1.25.10

Open the chart page →

1,838
nai-knative-istio-controllernutanix-helm-releasesVerified publisher1.13.12 of 2See more

nai-knative-istio-controller nutanix-helm-releases 1.13.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.13.1a5b041ba3c9e
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.13.1f066376eee17
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

1,566
nai-knative-servingnutanix-helm-releasesVerified publisher1.13.14 of 4See more

nai-knative-serving nutanix-helm-releases 1.13.1

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.13.121f8e11a44bf
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.13.134796e9f760b
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.13.153d9aa4d2c7a
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.13.1700c69915dc7
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

3,766
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.04 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

4 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
stdlib@go1.24.2
1.25.10
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.53.0
1.25.10
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.25.10
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.39751856cacc8
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.53.0
1.25.10

Open the chart page →

4,997
firecrawlobeoneVerified publisher3.0.62 of 5See more

firecrawl obeone 3.0.6

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/firecrawl:2.11.349ddbbb3023fea
golang.org/x/net@v0.41.0
stdlib@go1.24.13
0.53.0
1.25.10
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
stdlib@go1.24.6
1.25.10

Open the chart page →

10,311
observabilitysecobservabilitysec0.0.11 of 2See more

observabilitysec observabilitysec 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jdvalencia422/observabilitysec:latesta80b6e47a7b8
stdlib@go1.18.4
1.25.10

Open the chart page →

1,179
lensoci-ai-incubations0.1.1411 of 16See more

lens oci-ai-incubations 0.1.14

11 of the 16 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
golang.org/x/net@v0.19.0
stdlib@go1.22.7
0.53.0
1.25.10
grafana/grafana:12.1.1a1701c218024
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10
library/postgres:134689940c6838
stdlib@go1.24.6
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.85.0ebb560bcb6bd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.5.063805ebb8d2b
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.11.103738d278e08
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.2050a34002d5b
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

17,257
ocisocis-community0.1.01 of 1See more

ocis ocis-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
owncloud/ocis:8.0.1b38fd8fdd58f
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

2,356
argocd-agent-addonocm-helm-chartsVerified publisher0.29.01 of 2See more

argocd-agent-addon ocm-helm-charts 0.29.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.18.0a09814522a72
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

671
cluster-gateway-addon-managerocm-helm-chartsVerified publisher1.4.01 of 1See more

cluster-gateway-addon-manager ocm-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

1,607
cluster-managerocm-helm-chartsVerified publisher1.3.11 of 1See more

cluster-manager ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

822
cluster-proxyocm-helm-chartsVerified publisher0.12.01 of 1See more

cluster-proxy ocm-helm-charts 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

1,350
dynamic-scoring-frameworkocm-helm-chartsVerified publisher0.1.02 of 2See more

dynamic-scoring-framework ocm-helm-charts 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/dynamic-scoring-addon:latest7e571a08ec1a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
quay.io/open-cluster-management/dynamic-scoring-controller:latest587f5bc8f2ed
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

996
klusterletocm-helm-chartsVerified publisher1.3.11 of 1See more

klusterlet ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

822
kueue-addonocm-helm-chartsVerified publisher0.1.41 of 1See more

kueue-addon ocm-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

1,619
multicluster-controlplaneocm-helm-chartsVerified publisher0.8.01 of 1See more

multicluster-controlplane ocm-helm-charts 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

626
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.13
0.53.0
1.25.10

Open the chart page →

2,131
octantoctant0.1.861 of 1See more

octant octant 0.1.86

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/mydecisive/octant:0.1.86ebbd44abae6c
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

566
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
golang.org/x/net@v0.21.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

5,812
aspromokgoloveVerified publisher2.0.01 of 1See more

asprom okgolove 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
okgolove/asprom:1.10.1974d2e5eb150
stdlib@go1.14.11
1.25.10

Open the chart page →

1,869
cmsmsoleds-helm-chartsVerified publisher0.1.61 of 1See more

cmsms oleds-helm-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
stdlib@go1.23.10
1.25.10

Open the chart page →

2,899
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.4
0.53.0
1.25.10

Open the chart page →

8,549
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10

Open the chart page →

4,679
exposecontrollerolli-aiVerified publisher1.0.51 of 1See more

exposecontroller olli-ai 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
olliai/exposecontroller:1.0.5a470d96525e4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.3
0.53.0
1.25.10

Open the chart page →

2,861
k8s-replicatorolli-aiVerified publisher1.3.01 of 1See more

k8s-replicator olli-ai 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
olliai/k8s-replicator:1.3.05716f2a8bd4c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.17.2
0.53.0
1.25.10

Open the chart page →

2,825

Container images carrying it

4,685 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.53.0
1.25.10
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/net@v0.41.0
stdlib@go1.24.3
0.53.0
1.25.10
1
dashops/dash-ops:latest23537693ff05
golang.org/x/net@v0.46.0
0.53.0
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
stdlib@go1.16.9
1.25.10
1
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.11
0.53.0
1.25.10
1
datadog/agent:6aad9994de6a7
golang.org/x/net@v0.33.0
stdlib@go1.21.11
0.53.0
1.25.10
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.15
0.53.0
1.25.10
1
datadog/operator:0.3.117f08a860090
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.2
0.53.0
1.25.10
1
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.21.4
0.53.0
1.25.10
1
datappeal/hive-metastore:lateste38c085a3567
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.4
0.53.0
1.25.10
1
datappeal/trino-exporter:latest325b91c2b09e
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.15
0.53.0
1.25.10
1
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.17.13
0.53.0
1.25.10
1
datasaker/dsk-container-agent:latest08b52999f67b
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.53.0
1.25.10
1
datasaker/dsk-k8s-agent:latest2542ee73be51
golang.org/x/net@v0.17.0
stdlib@go1.19.1
0.53.0
1.25.10
1
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.53.0
1.25.10
1
datasaker/dsk-node-agent:latest1b95913b6729
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.53.0
1.25.10
1
datasaker/dsk-process-agent:latest2f38720a637d
golang.org/x/net@v0.15.0
stdlib@go1.21.0
0.53.0
1.25.10
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.53.0
1.25.10
1
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.53.0
1.25.10
1
datawire/aes:3.11.195ec30b3c732
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.53.0
1.25.10
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.16.5
0.53.0
1.25.10
1
datawire/emissary:3.12.21f67a1292d2a
golang.org/x/net@v0.28.0
stdlib@go1.22.4
0.53.0
1.25.10
1
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.53.0
1.25.10
1
ddefrancesco/scoperunner-server:0.2.1daaac6657600
stdlib@go1.21.10
1.25.10
1
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.53.0
1.25.10
1
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.53.0
1.25.10
1
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.53.0
1.25.10
1
ddvk/rmfakecloud:latest2f5c45cbf0c5
golang.org/x/net@v0.38.0
0.53.0
1
deconzcommunity/deconz:2.29.2062de2362641
stdlib@go1.19.8
1.25.10
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.25.10
1
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
golang.org/x/net@v0.8.0
stdlib@go1.19.1
0.53.0
1.25.10
1
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
1
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.25.10
1
defactops/defactops-ui:1.0.16825cdf9ba706
golang.org/x/net@v0.25.0
stdlib@go1.21.10
0.53.0
1.25.10
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.5
0.53.0
1.25.10
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.53.0
1.25.10
1
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10
1
deluan/navidrome:0.50.02cf4442b0099
golang.org/x/net@v0.18.0
stdlib@go1.21.0
0.53.0
1.25.10
1
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.53.0
1.25.10
1
deluan/navidrome:0.61.29fa40b3d8dec
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.53.0
1.25.10
1
denniswitt/yas3p:0.2.488a235619af6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
1
devopsfaith/krakend:2.6.34c678c224f67
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.53.0
1.25.10
1
devopsfaith/krakend:2.7.09219cda867e2
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
1
devopstales/trivy-operator:2.575136aa7a26e
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.53.0
1.25.10
1
devsecurely/cview-issuer:0.0.42eecd4314e933
golang.org/x/net@v0.52.0
0.53.0
1
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.53.0
1.25.10
1
dexidp/dex:v2.39.1-distroless43655afd1a8f
golang.org/x/net@v0.24.0
stdlib@go1.21.6
0.53.0
1.25.10
1
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.7
0.53.0
1.25.10
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
golang.org/x/net@v0.35.0
stdlib@go1.22.12
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.