StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,039
of 17,792 indexed, latest versions
Container images
4,657
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,039 of 17,792 indexed charts deploy, on 4,657 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,508
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,567
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,039 by stars
ChartLatestAffected imagesRadar Score
capa-vpc-peering-operatorappscodeVerified publisher2023.12.111 of 1See more

capa-vpc-peering-operator appscode 2023.12.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

1,433
capi-ops-managerappscodeVerified publisher2024.8.142 of 2See more

capi-ops-manager appscode 2024.8.14

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
golang.org/x/net@v0.33.0
stdlib@go1.23.2
0.53.0
1.25.10
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.53.0
1.25.10

Open the chart page →

3,430
cattlesetappscodeVerified publisher2026.7.81 of 1See more

cattleset appscode 2026.7.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/cattleset:v0.0.145554a03e448
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

625
cert-manager-csi-driver-cacertsappscodeVerified publisher2026.1.153 of 3See more

cert-manager-csi-driver-cacerts appscode 2026.1.15

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/csi-driver-cacerts:v0.5.0b6bf1888f9d5
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.53.0
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

3,461
cert-manager-webhook-aceappscodeVerified publisher2026.9.111 of 1See more

cert-manager-webhook-ace appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/cert-manager-webhook-ace:v0.0.2dc6b5fdcec06
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,316
cluster-auth-agentappscodeVerified publisher2026.2.161 of 1See more

cluster-auth-agent appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

985
cluster-auth-managerappscodeVerified publisher2026.2.161 of 1See more

cluster-auth-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

985
cluster-connectorappscodeVerified publisher2025.12.151 of 1See more

cluster-connector appscode 2025.12.15

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/cluster-connector:v0.0.140efd9d9ef6ca
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

619
cluster-gatewayappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

647
cluster-gateway-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

647
cluster-importerappscodeVerified publisher2026.9.111 of 1See more

cluster-importer appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/ace:v0.2.0b8e03da90e70
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.53.0
1.25.10

Open the chart page →

1,039
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

1,063
cluster-proxyappscodeVerified publisher2024.2.251 of 1See more

cluster-proxy appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:latest27a5c64b7ea8
golang.org/x/net@v0.20.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

1,125
cluster-proxy-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-proxy-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:v0.10.1a7fce69e171c
golang.org/x/net@v0.47.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

1,472
crd-managerappscodeVerified publisher2026.7.211 of 1See more

crd-manager appscode 2026.7.21

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

790
dns-proxyappscodeVerified publisher2026.9.111 of 1See more

dns-proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/cloudflare-dns-proxy:v0.0.5dfbef0285e14
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

647
docker-machine-operatorappscodeVerified publisher2024.7.91 of 1See more

docker-machine-operator appscode 2024.7.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/net@v0.14.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

2,227
falco-ui-serverappscodeVerified publisher2026.1.152 of 2See more

falco-ui-server appscode 2026.1.15

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
ghcr.io/appscode/falco-ui-server:v0.0.66ec488d89b56
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

2,887
fluxcd-addon-managerappscodeVerified publisher2024.2.251 of 1See more

fluxcd-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/fluxcd-addon:v0.0.23acba3df8827
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.53.0
1.25.10

Open the chart page →

1,311
fluxcd-managerappscodeVerified publisher2026.2.161 of 1See more

fluxcd-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/fluxcd-addon:v0.0.103475404bef5c
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.53.0
1.25.10

Open the chart page →

1,101
gateway-converterappscodeVerified publisher2024.8.301 of 1See more

gateway-converter appscode 2024.8.30

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway-converter:v0.0.1b92123805584
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.53.0
1.25.10

Open the chart page →

1,275
gcp-credential-managerappscodeVerified publisher2026.3.111 of 1See more

gcp-credential-manager appscode 2026.3.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/gcp-credential-manager:v0.1.0b58345fe8209
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

1,067
gh-ci-webhookappscodeVerified publisher2026.9.111 of 1See more

gh-ci-webhook appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/gh-ci-webhook:v0.0.2036ce246d884e
golang.org/x/net@v0.33.0
stdlib@go1.24.0
0.53.0
1.25.10

Open the chart page →

1,248
grafanaappscodeVerified publisher2026.9.111 of 1See more

grafana appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.1
0.53.0
1.25.10

Open the chart page →

2,340
grafana-operatorappscodeVerified publisher2026.6.121 of 1See more

grafana-operator appscode 2026.6.12

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana-tools:v0.8.077c9d29080eb
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

368
inbox-agentappscodeVerified publisher2026.6.22 of 2See more

inbox-agent appscode 2026.6.2

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-agent:v0.0.66b99ee9feece
golang.org/x/net@v0.47.0
0.53.0
ghcr.io/appscode/kube-rbac-proxy:v0.15.0d8cc6ffb9819
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

2,129
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.25.10

Open the chart page →

15,718
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.25.10

Open the chart page →

17,122
kube-auth-managerappscodeVerified publisher2023.11.141 of 1See more

kube-auth-manager appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.53.0
1.25.10

Open the chart page →

1,946
kube-auth-proxyappscodeVerified publisher2023.11.141 of 1See more

kube-auth-proxy appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.53.0
1.25.10

Open the chart page →

1,946
kubedb-certifiedappscodeVerified publisher2026.7.103 of 8See more

kubedb-certified appscode 2026.7.10

3 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10
ghcr.io/appscode/petset:v0.1.093fa0daf603c
golang.org/x/net@v0.47.0
0.53.0
ghcr.io/appscode/sidekick:v0.0.15d1036b07e348
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

4,145
kubedb-communityappscodeVerified publisher0.24.21 of 2See more

kubedb-community appscode 0.24.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubedb/operator:v0.24.01a06ff0bda52
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.6
0.53.0
1.25.10

Open the chart page →

2,557
kubedb-enterpriseappscodeVerified publisher0.11.21 of 2See more

kubedb-enterprise appscode 0.11.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.3
0.53.0
1.25.10

Open the chart page →

2,581
kubedb-oneappscodeVerified publisher2023.12.289 of 10See more

kubedb-one appscode 2023.12.28

9 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.53.0
1.25.10
ghcr.io/kubedb/kubedb-autoscaler:v0.25.0df6b11907d33
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
ghcr.io/kubedb/kubedb-dashboard:v0.16.07bfe1c07bd9b
golang.org/x/net@v0.17.0
stdlib@go1.20.7
0.53.0
1.25.10
ghcr.io/kubedb/kubedb-ops-manager:v0.27.1ec36422b09af
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.53.0
1.25.10
ghcr.io/kubedb/kubedb-provisioner:v0.40.242574f512837
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.53.0
1.25.10
ghcr.io/kubedb/kubedb-schema-manager:v0.16.09518de37eed5
golang.org/x/net@v0.17.0
stdlib@go1.20.7
0.53.0
1.25.10
ghcr.io/kubedb/kubedb-webhook-server:v0.16.2e24894e32cbc
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.53.0
1.25.10
ghcr.io/stashed/stash-crd-installer:v0.32.0c6f2a844b5dd
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.53.0
1.25.10
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
golang.org/x/net@v0.15.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

15,265
kubedb-provider-awsappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-aws appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

2,534
kubedb-provider-azureappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-azure appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

2,712
kubedb-provider-gcpappscodeVerified publisher2026.7.102 of 2See more

kubedb-provider-gcp appscode 2026.7.10

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
golang.org/x/net@v0.23.0
stdlib@go1.19.1
0.53.0
1.25.10

Open the chart page →

3,040
kubedb-ui-serverappscodeVerified publisher2021.12.211 of 1See more

kubedb-ui-server appscode 2021.12.21

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.8
0.53.0
1.25.10

Open the chart page →

2,054
kubeform-provider-awsappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-aws appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
golang.org/x/net@v0.10.0
stdlib@go1.19.1
0.53.0
1.25.10

Open the chart page →

2,803
kubeform-provider-azureappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-azure appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

2,724
kubeform-provider-gcpappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-gcp appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
golang.org/x/net@v0.9.0
stdlib@go1.19.9
0.53.0
1.25.10

Open the chart page →

2,750
kubestashappscodeVerified publisher2026.7.102 of 2See more

kubestash appscode 2026.7.10

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,098
kubestash-certifiedappscodeVerified publisher2026.7.102 of 2See more

kubestash-certified appscode 2026.7.10

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,098
kubestash-operatorappscodeVerified publisher0.29.02 of 2See more

kubestash-operator appscode 0.29.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10
ghcr.io/kubestash/kubestash:v0.29.043e01ed32486
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,098
kubevaultappscodeVerified publisher2026.8.71 of 2See more

kubevault appscode 2026.8.7

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

806
kubevault-certifiedappscodeVerified publisher2026.2.271 of 1See more

kubevault-certified appscode 2026.2.27

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kubevault/vault-operator:v0.24.00087cb49616f
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.53.0
1.25.10

Open the chart page →

1,129
kubevault-webhook-serverappscodeVerified publisher0.25.01 of 2See more

kubevault-webhook-server appscode 0.25.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

806
kubevirt-infra-csi-driverappscodeVerified publisher0.1.02 of 6See more

kubevirt-infra-csi-driver appscode 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-csi-driver:latest7b31b21b3f1e
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.53.0
1.25.10

Open the chart page →

1,209
kubevirt-tenant-csi-driverappscodeVerified publisher0.1.02 of 4See more

kubevirt-tenant-csi-driver appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-csi-driver:latest7b31b21b3f1e
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.53.0
1.25.10
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/net@v0.17.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

1,297
license-proxyserverappscodeVerified publisher2026.2.161 of 1See more

license-proxyserver appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.1.1e192ad567e0b
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

1,113

Container images carrying it

4,657 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
golang.org/x/net@v0.25.0
stdlib@go1.23.12
0.53.0
1.25.10
1
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/net@v0.10.0
stdlib@go1.21.13
0.53.0
1.25.10
1
eclipseaerios/openldap:2.6.30208743f315e
stdlib@go1.18.2
1.25.10
1
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
1
ekofr/pihole-exporter:0.0.109fdad6f352e0
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.7
0.53.0
1.25.10
1
elastic/apm-server:7.17.6c7a1c63257d0
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.2
0.53.0
1.25.10
1
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.25.10
1
emirozbir/dashdns-admission-webhook:v2.0.56801ba2a3fc3
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10
1
emirozbir/dashdns-controller:v2.0.5d3a5c1063425
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10
1
empathyco/cost-report:0.0.124f1e26eaacbf
stdlib@go1.15.15
1.25.10
1
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
golang.org/x/net@v0.23.0
stdlib@go1.23.3
0.53.0
1.25.10
1
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/net@v0.30.0
stdlib@go1.22.0
0.53.0
1.25.10
1
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.53.0
1.25.10
1
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
stdlib@go1.19.10
0.53.0
1.25.10
1
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.25.10
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.53.0
1.25.10
1
enketo/enketo-express:3.0.4dcad9c2273f6
stdlib@go1.17.1
1.25.10
1
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.53.0
1.25.10
1
envoyproxy/gateway:v0.5.02a9f99d28567
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10
1
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.53.0
1.25.10
1
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14
0.53.0
1.25.10
1
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.13
0.53.0
1.25.10
1
envoyproxy/ratelimit:4d2efd61ede09a75a84c
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.15
0.53.0
1.25.10
1
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.19.6
0.53.0
1.25.10
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.53.0
1.25.10
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.18.3
0.53.0
1.25.10
1
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.4
0.53.0
1.25.10
1
epamedp/edp-headlamp:0.25.093417e18bb1a
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.53.0
1.25.10
1
epamedp/edp-tekton:0.2.4924939850655
golang.org/x/net@v0.1.0
stdlib@go1.18.3
0.53.0
1.25.10
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.53.0
1.25.10
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.53.0
1.25.10
1
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.53.0
1.25.10
1
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.53.0
1.25.10
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.2
0.53.0
1.25.10
1
epamedp/perf-operator:2.13.0bd2079b7bfcb
golang.org/x/net@v0.8.0
stdlib@go1.19.6
0.53.0
1.25.10
1
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.18.4
0.53.0
1.25.10
1
epamedp/tekton-custom-task:0.2.067d896676f45
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.53.0
1.25.10
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.25.10
1
erenozcan17/go_backend:v4.250b4f23422b6
golang.org/x/net@v0.10.0
stdlib@go1.23.12
0.53.0
1.25.10
1
erigontech/erigon:v2.61.288706754b627
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.53.0
1.25.10
1
escaping/core-keeper-dedicated:latest87fa79255962
stdlib@go1.24.4
1.25.10
1
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.53.0
1.25.10
1
ethereum/client-go:v1.15.101f36ca5922a5
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.53.0
1.25.10
1
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.53.0
1.25.10
1
ethereum/client-go:v1.10.186d6d12a40465
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.18.2
0.53.0
1.25.10
1
ethereum/client-go:v1.14.8886ec69b35b0
golang.org/x/net@v0.24.0
stdlib@go1.22.6
0.53.0
1.25.10
1
ethereum/client-go:stableb8ab3451a117
golang.org/x/net@v0.50.0
0.53.0
1
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.5
0.53.0
1.25.10
1
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.53.0
1.25.10
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
stdlib@go1.19.3
1.25.10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.