StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,155
of 17,813 indexed, latest versions
Container images
4,778
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,155 of 17,813 indexed charts deploy, on 4,778 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,618
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,640
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,155 by stars
ChartLatestAffected imagesRadar Score
ceph-csi-cephfswikimedia0.1.85 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

5 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/csi-provisioner:v3.2.14ad5fcdbe7e9
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
stdlib@go1.18
0.53.0
1.25.10
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.53.0
1.25.10

Open the chart page →

10,335
ceph-csi-rbdwikimedia0.1.136 of 6See more

ceph-csi-rbd wikimedia 0.1.13

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/csi-provisioner:v3.2.14ad5fcdbe7e9
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
stdlib@go1.18
0.53.0
1.25.10
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.53.0
1.25.10

Open the chart page →

11,842
jaegerwikimedia3.1.24 of 4See more

jaeger wikimedia 3.1.2

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.25.10
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

9,364
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

2,035
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.13.8
0.53.0
1.25.10

Open the chart page →

2,753
csi-driver-host-pathwiremindVerified publisher0.1.18 of 8See more

csi-driver-host-path wiremind 0.1.1

8 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
stdlib@go1.18
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.53.0
1.25.10
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.18
0.53.0
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
stdlib@go1.18
0.53.0
1.25.10

Open the chart page →

12,666
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.53.0
1.25.10

Open the chart page →

2,792
druid-tasks-exporterwiremindVerified publisher0.3.01 of 1See more

druid-tasks-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/wiremind/druid-tasks-exporter:v0.4.04755c3fcd5f0
stdlib@go1.21.4
1.25.10

Open the chart page →

533
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
stdlib@go1.25.5
1.25.10

Open the chart page →

7,794
koherencewiremindVerified publisher0.4.11 of 1See more

koherence wiremind 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/wiremind/koherence:v0.2.39c2afc45c55d
stdlib@go1.22.3
1.25.10

Open the chart page →

426
orcwiremindVerified publisher0.3.01 of 1See more

orc wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/orc/openstack-resource-controller:v2.5.079f22af49612
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.53.0
1.25.10

Open the chart page →

277
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
golang.org/x/net@v0.25.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

1,433
prometheus-openstack-exporterwiremindVerified publisher0.5.01 of 1See more

prometheus-openstack-exporter wiremind 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/openstack-exporter/openstack-exporter:1.7.0e5146a7dd515
golang.org/x/net@v0.10.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

1,480
prometheus-safety-exporterwiremindVerified publisher0.6.01 of 2See more

prometheus-safety-exporter wiremind 0.6.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

726
rediswiremindVerified publisher23.0.61 of 1See more

redis wiremind 23.0.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
stdlib@go1.25.5
1.25.10

Open the chart page →

2,169
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10

Open the chart page →

1,358
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

935
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

2,513
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.5
0.53.0
1.25.10

Open the chart page →

2,624
wordpress-alpinewordpress-alpine1.5.182 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

2 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
stdlib@go1.24.6
1.25.10
registry.k8s.io/kubectl:v1.36.2b0d792e0d8df
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

4,118
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:latest66aec17cd21a
stdlib@go1.24.6
1.25.10

Open the chart page →

2,022
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:ltsdd9b303aed4f
stdlib@go1.24.6
1.25.10

Open the chart page →

5,859
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
stdlib@go1.20.12
1.25.10

Open the chart page →

14,255
workadventureworkadventure1.1.06 of 9See more

workadventure workadventure 1.1.0

6 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.53.0
1.25.10
thecodingmachine/workadventure-back:v1.17.764001369dad5
stdlib@go1.20.7
1.25.10
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
stdlib@go1.17.13
1.25.10
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
stdlib@go1.19.3
1.25.10
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
stdlib@go1.20.7
1.25.10
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
stdlib@go1.20.7
1.25.10

Open the chart page →

16,105
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.15
0.53.0
1.25.10

Open the chart page →

1,961
oauth2xdVerified publisher1.0.01 of 1See more

oauth2 xd 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
lishimeng/hufu:v1.2.13d5752dac834
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

2,008
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10
lishimeng/owl-messager:v0.11.23d00485e64dc
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

4,110
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.53.0
1.25.10
lishimeng/passport-profile:v0.2.160970dfe5dc8f
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

3,976
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.53.0
1.25.10

Open the chart page →

7,756
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.53.0
1.25.10

Open the chart page →

1,998
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.53.0
1.25.10

Open the chart page →

2,070
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.24.6
1.25.10
murtazashah46/helmfile:latest4d11726cf803
golang.org/x/net@v0.5.0
stdlib@go1.22.8
0.53.0
1.25.10

Open the chart page →

13,907
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

402
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

1,197
cloudeye-exporterxxl-job-adminVerified publisher0.1.21 of 1See more

cloudeye-exporter xxl-job-admin 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dellnoantechnp/cloudeye-exporter:v2.0.316873356c882d
stdlib@go1.19.6
1.25.10

Open the chart page →

2,697
dingtalk-botxxl-job-adminVerified publisher0.1.21 of 2See more

dingtalk-bot xxl-job-admin 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/bitnami/redis:8.4.029064423c369
stdlib@go1.25.6
1.25.10

Open the chart page →

3,185
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
golang.org/x/net@v0.48.0
0.53.0

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.42 of 4See more

kadalu-operator xxl-job-admin 1.2.4

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kadalu/kadalu-operator:1.2.03726d7a805f2
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.53.0
1.25.10
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.13.15
0.53.0
1.25.10

Open the chart page →

4,926
nfs-subdir-external-provisionerxxl-job-adminVerified publisher4.0.181 of 1See more

nfs-subdir-external-provisioner xxl-job-admin 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.53.0
1.25.10

Open the chart page →

2,746
nightingalexxl-job-adminVerified publisher0.2.113 of 6See more

nightingale xxl-job-admin 0.2.11

3 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
golang.org/x/net@v0.34.0
stdlib@go1.23.9
0.53.0
1.25.10
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.53.0
1.25.10

Open the chart page →

9,738
redisxxl-job-adminVerified publisher24.1.31 of 1See more

redis xxl-job-admin 24.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/bitnami/redis:8.4.029064423c369
stdlib@go1.25.6
1.25.10

Open the chart page →

314
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
stdlib@go1.18.6
1.25.10

Open the chart page →

1,153
ygdrassil-monitoringygdrassilVerified publisher0.4.07 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

7 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

9,526
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
golang.org/x/net@v0.24.0
stdlib@go1.20.6
0.53.0
1.25.10

Open the chart page →

1,610
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18.1
0.53.0
1.25.10

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.53.0
1.25.10
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.53.0
1.25.10
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.53.0
1.25.10
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.53.0
1.25.10

Open the chart page →

8,002
nginx-vts-exporterymrs0.1.21 of 1See more

nginx-vts-exporter ymrs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
sophos/nginx-vts-exporter:latestf1073556b29b
stdlib@go1.13.6
1.25.10

Open the chart page →

1,337
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

3,025
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.53.0
1.25.10
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

5,077

Container images carrying it

4,778 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
stdlib@go1.19.3
1.25.10
1
ethereumoptimism/l2geth:0.5.315577036dc36d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18
0.53.0
1.25.10
1
ethersphere/bee:2.2.0a884fd84b72f
golang.org/x/net@v0.25.0
stdlib@go1.22.7
0.53.0
1.25.10
1
ethersphere/ethproxy:latest3a8a3926caa2
stdlib@go1.18.7
1.25.10
1
ethersphere/onboarding-faucet:0.3.0513154aab230
stdlib@go1.18.2
1.25.10
1
ethpandaops/armiarma:master1a9c3264f0a9
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10
1
ethpandaops/blob-me-baby:latestad26158420dd
stdlib@go1.20.1
1.25.10
1
ethpandaops/cbt:latest5377ffb3091a
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
1
ethpandaops/cbt-api:latest9dc0b50e6c27
golang.org/x/net@v0.52.0
0.53.0
1
ethpandaops/contributoor:latest1edd4074fd79
stdlib@go1.26.1
1.25.10
1
ethpandaops/dugtrio:1.0.0e261d1734e9f
golang.org/x/net@v0.10.0
stdlib@go1.21.4
0.53.0
1.25.10
1
ethpandaops/ethereum-address-metrics-exporter:latest431cd3790ed2
stdlib@go1.26.1
1.25.10
1
ethpandaops/ethereumjs:masterfb84b718500f
stdlib@go1.23.12
1.25.10
1
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.10
0.53.0
1.25.10
1
ethpandaops/ethereum-validator-metrics-exporter:latest38448e9d4aef
stdlib@go1.19.10
1.25.10
1
ethpandaops/execution-processor:latest5c4832e9588f
stdlib@go1.25.4
1.25.10
1
ethpandaops/forky:debian-latestc937f4ba737c
golang.org/x/net@v0.52.0
0.53.0
1
ethpandaops/panda-pulse:latestad6fc3b3e6b8
stdlib@go1.26.1
1.25.10
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
golang.org/x/net@v0.43.0
0.53.0
1
ethpandaops/slashoor:latesta71967db581f
stdlib@go1.23.12
1.25.10
1
ethpandaops/splitoor:latest989da6bea4bd
golang.org/x/net@v0.38.0
stdlib@go1.26.1
0.53.0
1.25.10
1
ethpandaops/stubbies:latest9f1d6aec0d04
stdlib@go1.19.8
1.25.10
1
ethpandaops/xatu-cbt-api:latestf7dec2e07091
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.53.0
1.25.10
1
evcc/evcc:0.300.8ddf2a25afce5
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.53.0
1.25.10
1
everpcpc/channels:latestb378d137ae8b
stdlib@go1.17
1.25.10
1
evoapicloud/evolution-api:latest966625532d90
stdlib@go1.23.12
1.25.10
1
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.3
0.53.0
1.25.10
1
factly/dega-api:0.15.166fafc7b0a17
stdlib@go1.16.2
1.25.10
1
factly/dega-server:0.15.194d21479382e
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.2
0.53.0
1.25.10
1
factly/kavach-server:0.22.3be85ff1b9bd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.2
0.53.0
1.25.10
1
factly/mande-server:0.34.1384d384310ef
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
1
factly/vidcheck-server:0.12.087064eb0463c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.14.2
0.53.0
1.25.10
1
falcosecurity/falco:0.44.1d0cfe422d6ac
golang.org/x/net@v0.49.0
0.53.0
1
falcosecurity/falcoctl:0.13.00eeb79adc580
stdlib@go1.26.2
1.25.10
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
1
falcosecurity/falco-operator:0.4.18a99fcc57a57
stdlib@go1.26.0
1.25.10
1
falcosecurity/falcosidekick:2.32.01976da721518
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.53.0
1.25.10
1
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.18.1
0.53.0
1.25.10
1
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
1
featureformcom/quickstart-loader:latest82396f8fb5e8
stdlib@go1.21.11
1.25.10
1
federid/webhook:0.1.0fbfb7c6510a7
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
1
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
golang.org/x/net@v0.24.0
stdlib@go1.20.6
0.53.0
1.25.10
1
feiyu563/prometheus-alert:v4.9.28192368b0578
golang.org/x/net@v0.24.0
stdlib@go1.20.6
0.53.0
1.25.10
1
felipecs8/conversor-temperatura:v1f945423be36d
stdlib@go1.20.12
1.25.10
1
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.16.9
0.53.0
1.25.10
1
fission/fission-bundle:1.14.13fcfd8a0fa5d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.14
0.53.0
1.25.10
1
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.14
0.53.0
1.25.10
1
fission/reporter:1.14.104c6e06af175
stdlib@go1.15.14
1.25.10
1
flanksource/apm-hub:v0.0.471dacc3195bf9
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
1
flanksource/batch-runner:v1.0.44689687a7cf95
golang.org/x/net@v0.41.0
stdlib@go1.25.5
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.