StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,097
of 17,813 indexed, latest versions
Container images
4,705
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,097 of 17,813 indexed charts deploy, on 4,705 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,549
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,594
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,097 by stars
ChartLatestAffected imagesRadar Score
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
golang.org/x/net@v0.33.0
stdlib@go1.22.8
0.53.0
1.25.10

Open the chart page →

3,313
spire-ha-agentspiffeVerified publisher0.3.21 of 2See more

spire-ha-agent spiffe 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-ha-agent:0.5.0307cf2d05afe
stdlib@go1.25.0
1.25.10

Open the chart page →

368
spire-identity-exchangespiffeVerified publisher0.2.22 of 3See more

spire-identity-exchange spiffe 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-identity-exchange-server:v0.5.0239bc70c1988
stdlib@go1.26.0
1.25.10
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

1,442
spillwayspillwayVerified publisher0.4.41 of 1See more

spillway spillway 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kroy-the-rabbit/spillway:0.4.48de556d3bda7
golang.org/x/net@v0.38.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

267
spinnakerspinnakerVerified publisher2.2.132 of 4See more

spinnaker spinnaker 2.2.13

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.15.5
0.53.0
1.25.10
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.5
0.53.0
1.25.10

Open the chart page →

6,877
spoolmanspoolmanVerified publisher0.2.61 of 1See more

spoolman spoolman 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.25.10

Open the chart page →

1,848
ocean-admission-controllerspot1.0.32 of 3See more

ocean-admission-controller spot 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/spotit-today/spot-ocean-admission-controller:0.1.64f634aeb31b8
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.53.0
1.25.10

Open the chart page →

773
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

51,180
ocean-vpaspot1.0.73 of 4See more

ocean-vpa spot 1.0.7

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.53.0
1.25.10

Open the chart page →

1,195
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.5
0.53.0
1.25.10

Open the chart page →

66,163
airflowsqream-chartsVerified publisher1.17.01 of 4See more

airflow sqream-charts 1.17.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus/statsd-exporter:v0.27.29ed70604d941
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.53.0
1.25.10

Open the chart page →

1,883
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

2,425
sqs-prometheus-exportersqs-prometheus-exporterVerified publisher2.0.31 of 1See more

sqs-prometheus-exporter sqs-prometheus-exporter 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/jmriebold/sqs-prometheus-exporter:1.1.07564828ab7cb
stdlib@go1.24.0
1.25.10

Open the chart page →

368
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,279
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/net@v0.4.0
stdlib@go1.18.9
0.53.0
1.25.10

Open the chart page →

69,027
ecr-cleanersstarcher0.1.1+d13a1ab1 of 1See more

ecr-cleaner sstarcher 0.1.1+d13a1ab

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
sstarcher/ecr-cleaner:0.1.12d43c390cb19
stdlib@go1.14.2
1.25.10

Open the chart page →

2,576
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.9
0.53.0
1.25.10

Open the chart page →

3,097
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.53.0
1.25.10

Open the chart page →

3,076
retail-store-sample-catalog-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-catalog-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-catalog:1.3.0b654b266fa32
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

773
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

28,614
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.53.0
1.25.10

Open the chart page →

2,089
jenkinsstakaterVerified publisher0.21.01 of 1See more

jenkins stakater 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

2,545
k8scostoptimizerstakaterVerified publisher0.0.51 of 1See more

k8scostoptimizer stakater 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.53.0
1.25.10

Open the chart page →

1,409
konfiguratorstakaterVerified publisher0.1.391 of 1See more

konfigurator stakater 0.1.39

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/konfigurator:v0.1.393409565b1ef5
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

1,279
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.53.0
1.25.10

Open the chart page →

2,854
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.53.0
1.25.10

Open the chart page →

2,174
vaultstakaterVerified publisher0.8.42 of 2See more

vault stakater 0.8.4

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.53.0
1.25.10
hashicorp/vault-k8s:0.14.0aff47b5ba39c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.2
0.53.0
1.25.10

Open the chart page →

5,873
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.1
0.53.0
1.25.10

Open the chart page →

2,565
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.13
0.53.0
1.25.10

Open the chart page →

6,680
stakefishstakefish0.1.06 of 8See more

stakefish stakefish 0.1.0

6 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

20,381
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.53.0
1.25.10

Open the chart page →

2,998
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

1,262
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.25.10

Open the chart page →

4,116
mev-booststakewise1.7.41 of 1See more

mev-boost stakewise 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
flashbots/mev-boost:1.8.07c486b5789da
stdlib@go1.22.6
1.25.10

Open the chart page →

1,261
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.53.0
1.25.10

Open the chart page →

6,609
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.53.0
1.25.10

Open the chart page →

7,035
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

1,262
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

576
open-appsec-injectorstartechnicaVerified publisher1.1.22 of 3See more

open-appsec-injector startechnica 1.1.2

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/openappsec/smartsync:latest580d68c50cc7
stdlib@go1.18.10
1.25.10
ghcr.io/openappsec/smartsync-shared-files:latest30c1daa0b33e
stdlib@go1.18.10
1.25.10

Open the chart page →

4,358
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.25.10

Open the chart page →

14,627
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
stdlib@go1.18.4
0.53.0
1.25.10

Open the chart page →

1,985
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.1
0.53.0
1.25.10
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.5
0.53.0
1.25.10
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.53.0
1.25.10
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.16.5
0.53.0
1.25.10

Open the chart page →

16,542
fluentd-operatorstatcan0.5.11 of 1See more

fluentd-operator statcan 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
vmware/kube-fluentd-operator:latestf028c138a5f4
golang.org/x/net@v0.17.0
stdlib@go1.21.7
0.53.0
1.25.10

Open the chart page →

1,960
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

1,584
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.16.3
0.53.0
1.25.10

Open the chart page →

6,598
prometheus-operatorstatcan0.2.24 of 7See more

prometheus-operator statcan 0.2.2

4 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.53.0
1.25.10
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
stdlib@go1.13.11
0.53.0
1.25.10
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
stdlib@go1.13.4
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.3
0.53.0
1.25.10

Open the chart page →

12,254
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.10
0.53.0
1.25.10

Open the chart page →

1,316
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.53.0
1.25.10

Open the chart page →

1,828
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.13.5
0.53.0
1.25.10

Open the chart page →

4,224
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.25.10

Open the chart page →

13,678

Container images carrying it

4,705 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dollarshaveclub/thermite:0.0.31663cbf25fcfe
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.1
0.53.0
1.25.10
1
donetick/donetick:v0.1.79a1cc21dd5a37
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.53.0
1.25.10
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
golang.org/x/net@v0.11.0
stdlib@go1.19.12
0.53.0
1.25.10
1
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.53.0
1.25.10
1
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.53.0
1.25.10
1
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
golang.org/x/net@v0.7.0
stdlib@go1.19.9
0.53.0
1.25.10
1
dongjiang1989/lxcfs-webhook:latestc1f19557bdcb
stdlib@go1.26.0
1.25.10
1
dongjiang1989/ns-node-affinity:latest451f7823723c
golang.org/x/net@v0.7.0
stdlib@go1.18.5
0.53.0
1.25.10
1
dongjiang1989/pingmesh-agent:latest355fa4be8e97
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.53.0
1.25.10
1
dongjiang1989/pingmesh-agent:v1.2.2c82de0272da0
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.53.0
1.25.10
1
doorcloud/apim-operator:v3.0.44e6ef8d72c3e
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.53.0
1.25.10
1
dossif/redminebot:0.2.296dcd2c0e9f2
stdlib@go1.17.13
1.25.10
1
douz/overlord:latestf2bc7fc068c1
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.5
0.53.0
1.25.10
1
dragonflyoss/client:v0.1.82edf3e921f4e0
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
golang.org/x/net@v0.19.0
stdlib@go1.21.1
0.53.0
1.25.10
1
dragonflyoss/scheduler:v2.1.49523785c77787
golang.org/x/net@v0.19.0
stdlib@go1.21.1
0.53.0
1.25.10
1
dragonflyoss/scheduler:v2.5.2d5dea9e662cd
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10
1
drone/drone:2.28.255897c8fb22d
golang.org/x/net@v0.42.0
stdlib@go1.24.13
0.53.0
1.25.10
1
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.15
0.53.0
1.25.10
1
drone/kubernetes-secrets:latest206df2280ecf
golang.org/x/net@v0.0.0-20180811021610-c39426892332
stdlib@go1.13.15
0.53.0
1.25.10
1
drorivry4/rego:lateste035d49b15ca
golang.org/x/net@v0.19.0
stdlib@go1.22.0
0.53.0
1.25.10
1
drumsergio/duplicacy-container:0.1.0dd3ee9703969
golang.org/x/net@v0.10.0
stdlib@go1.21.13
0.53.0
1.25.10
1
drumsergio/genieacs:1.2.16.028244054e1bf
stdlib@go1.19.8
1.25.10
1
dserio83/velero-api:0.3.16b3d9115fee2
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
stdlib@go1.23.7
1.25.10
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
golang.org/x/net@v0.5.0
stdlib@go1.19.6
0.53.0
1.25.10
1
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.25.10
1
durellirsd/security-smells-api:v17398aca4fc2e
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.53.0
1.25.10
1
dutchcoders/transfer.sh:v1.6.1-noroot8db9ade72a0d
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.53.0
1.25.10
1
duyetdev/applause-btn:latest25e59d223eaa
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.14.9
0.53.0
1.25.10
1
dvdlevanon/kubernetes-database-scaler:v0.0.361e79c1643fe4
golang.org/x/net@v0.8.0
0.53.0
1
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.7
0.53.0
1.25.10
1
easysoft/quickon-zentao:18.5592ad5df1f8b
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.20.3
0.53.0
1.25.10
1
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.13
0.53.0
1.25.10
1
ecadlabs/tezos_exporter:latest4bcbe5d1cdd2
stdlib@go1.16.5
1.25.10
1
eclipseaerios/federator:1.1.018c7f0d101c0
golang.org/x/net@v0.25.0
stdlib@go1.22.12
0.53.0
1.25.10
1
eclipseaerios/iota-tangle-peerer:latest99d7ff18d416
golang.org/x/net@v0.30.0
stdlib@go1.22.12
0.53.0
1.25.10
1
eclipseaerios/llo-api:1.2.0ab7a04182191
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.53.0
1.25.10
1
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
golang.org/x/net@v0.25.0
stdlib@go1.23.12
0.53.0
1.25.10
1
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/net@v0.10.0
stdlib@go1.21.13
0.53.0
1.25.10
1
eclipseaerios/openldap:2.6.30208743f315e
stdlib@go1.18.2
1.25.10
1
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
1
ekofr/pihole-exporter:0.0.109fdad6f352e0
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.7
0.53.0
1.25.10
1
elastic/apm-server:7.17.6c7a1c63257d0
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.2
0.53.0
1.25.10
1
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.25.10
1
emirozbir/dashdns-admission-webhook:v2.0.56801ba2a3fc3
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10
1
emirozbir/dashdns-controller:v2.0.5d3a5c1063425
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10
1
empathyco/cost-report:0.0.124f1e26eaacbf
stdlib@go1.15.15
1.25.10
1
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
golang.org/x/net@v0.23.0
stdlib@go1.23.3
0.53.0
1.25.10
1
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/net@v0.30.0
stdlib@go1.22.0
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.