StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,058
of 17,790 indexed, latest versions
Container images
4,694
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,058 of 17,790 indexed charts deploy, on 4,694 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,539
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,589
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,058 by stars
ChartLatestAffected imagesRadar Score
snapschedulerbackube-helm-chartsVerified publisher3.5.02 of 2See more

snapscheduler backube-helm-charts 3.5.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/backube/snapscheduler:3.5.035ac95c51780
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.53.0
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

1,231
yataibentomlVerified publisher1.1.131 of 1See more

yatai bentoml 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

1,917
yatai-deploymentbentomlVerified publisher1.1.211 of 2See more

yatai-deployment bentoml 1.1.21

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.53.0
1.25.10

Open the chart page →

1,160
boundaryboundaryVerified publisher0.1.01 of 1See more

boundary boundary 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/boundary:0.21.037bf86488b74
golang.org/x/net@v0.47.0
stdlib@go1.25.1
0.53.0
1.25.10

Open the chart page →

1,445
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.19.12
1.25.10

Open the chart page →

8,026
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.53.0
1.25.10

Open the chart page →

1,891
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.53.0
1.25.10
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.53.0
1.25.10

Open the chart page →

7,797
popeyechristianhuthVerified publisher2.4.31 of 1See more

popeye christianhuth 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10

Open the chart page →

1,196
hellocloudechoVerified publisher0.1.21 of 1See more

hello cloudecho 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.25.10

Open the chart page →

1,817
cloudflare-exportercloudflare-exporter0.2.31 of 1See more

cloudflare-exporter cloudflare-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/lablabs/cloudflare_exporter:0.0.1670d74ec46602
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10

Open the chart page →

791
ghostcloudpirates-ghostVerified publisher0.20.223 of 3See more

ghost cloudpirates-ghost 0.20.22

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
stdlib@go1.24.6
1.25.10
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.25.10
library/mariadb:12.3.3ab1c3dd38194
stdlib@go1.24.6
1.25.10

Open the chart page →

7,267
dumpscriptcloudscriptVerified publisher1.8.31 of 1See more

dumpscript cloudscript 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

2,132
clowardenclowarden0.2.32 of 4See more

clowarden clowarden 0.2.3

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.25.10
ghcr.io/cncf/clowarden/dbmigrator:v0.2.3c022fd42de45
stdlib@go1.25.3
1.25.10

Open the chart page →

5,632
cluster-manager-servercluster-manager-server1.8.01 of 1See more

cluster-manager-server cluster-manager-server 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

753
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
golang.org/x/net@v0.7.0
stdlib@go1.18
0.53.0
1.25.10

Open the chart page →

1,707
coder-observabilitycoder-observabilityVerified publisher0.7.313 of 21See more

coder-observability coder-observability 0.7.3

13 of the 21 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.53.0
1.25.10
grafana/grafana:10.4.19a9043254ba16
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.53.0
1.25.10
grafana/loki:3.1.0d947e68a84d9
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.53.0
1.25.10
grafana/loki-canary:3.1.039baf6d67f85
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.53.0
1.25.10
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.10
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.53.0
1.25.10
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.6
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

24,753
convertigoconvertigoOfficialVerified publisher8.4.32 of 5See more

convertigo convertigo 8.4.3

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
timescale/timescaledb:latest-pg16289d55704b1b
stdlib@go1.24.6
1.25.10

Open the chart page →

17,569
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

3,088
cosmocosmo-platformOfficialVerified publisher0.20.06 of 10See more

cosmo cosmo-platform 0.20.0

6 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.53.0
1.25.10
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.25.10
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.53.0
1.25.10
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
golang.org/x/net@v0.26.0
stdlib@go1.23.6
0.53.0
1.25.10
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
stdlib@go1.20.7
1.25.10

Open the chart page →

29,070
crossviewcrossviewOfficialVerified publisher4.6.01 of 2See more

crossview crossview 4.6.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

1,814
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
golang.org/x/net@v0.25.0
stdlib@go1.21.13
0.53.0
1.25.10

Open the chart page →

1,309
defensia-agentdefensia-agentOfficialVerified publisher0.6.01 of 1See more

defensia-agent defensia-agent 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/defensia/agent:1.4.57e9d40ae44711
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

64
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
golang.org/x/net@v0.17.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

3,458
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10

Open the chart page →

1,623
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.53.0
1.25.10

Open the chart page →

2,537
prometheus-locust-exporterdeliveryheroVerified publisher1.2.31 of 1See more

prometheus-locust-exporter deliveryhero 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.25.10

Open the chart page →

1,276
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.25.10

Open the chart page →

4,200
bscdysnixVerified publisher0.6.591 of 4See more

bsc dysnix 0.6.59

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.53.0
1.25.10

Open the chart page →

2,023
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.53.0
1.25.10

Open the chart page →

2,271
postgres-pgdump-backupeugen0.7.61 of 1See more

postgres-pgdump-backup eugen 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.25.10

Open the chart page →

353
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

12,049
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

14,552
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

13,881
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.25.10

Open the chart page →

5,305
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.10

Open the chart page →

4,723
flyte-coreflyte2.0.481 of 3See more

flyte-core flyte 2.0.48

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.10

Open the chart page →

1,179
frp-operatorfrpVerified publisher1.0.41 of 1See more

frp-operator frp 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/aureum-cloud/frp-operator:v1.0.196b01d7e7025
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

375
frp-operatorfrp-operator1.9.01 of 1See more

frp-operator frp-operator 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
golang.org/x/net@v0.23.0
stdlib@go1.23.12
0.53.0
1.25.10

Open the chart page →

535
ascii-moviegabe565Verified publisher0.16.41 of 1See more

ascii-movie gabe565 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
stdlib@go1.24.0
1.25.10

Open the chart page →

987
domain-watchgabe565Verified publisher1.1.01 of 1See more

domain-watch gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/gabe565/domain-watch:latest34c5a1e351d6
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

790
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.7
0.53.0
1.25.10

Open the chart page →

3,030
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.25.10

Open the chart page →

1,110
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

7,587
multusgeek-cookbookVerified publisher3.5.22 of 3See more

multus geek-cookbook 3.5.2

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.25.10
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

4,915
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.25.10

Open the chart page →

14,004
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
stdlib@go1.18.4
1.25.10

Open the chart page →

9,669
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.17.8
0.53.0
1.25.10

Open the chart page →

10,221
smarter-device-managergeek-cookbookVerified publisher6.5.21 of 1See more

smarter-device-manager geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.4
0.53.0
1.25.10

Open the chart page →

2,336
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.13
0.53.0
1.25.10

Open the chart page →

3,378
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
stdlib@go1.17
0.53.0
1.25.10

Open the chart page →

2,610

Container images carrying it

4,694 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gotenberg/gotenberg:8.3467097317623a
stdlib@go1.26.2
1.25.10
1
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.53.0
1.25.10
1
gotify/server:2.9.1a3af47067ce6
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.53.0
1.25.10
1
gotson/komga:1.22.0ba892ab3e082
stdlib@go1.17.8
1.25.10
1
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.53.0
1.25.10
1
grafana/agent:v0.44.23364714a2f64
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.53.0
1.25.10
1
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16
0.53.0
1.25.10
1
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.53.0
1.25.10
1
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10
1
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/net@v0.31.0
stdlib@go1.22.7
0.53.0
1.25.10
1
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.53.0
1.25.10
1
grafana/alloy:v1.11.38c7256f412fe
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
1
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.53.0
1.25.10
1
grafana/alloy:v1.14.0f50931848bd8
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
1
grafana/beyla:1.3.336d07f8d276e
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10
1
grafana/beyla-k8s-cache:253b2f561cb1b
golang.org/x/net@v0.48.0
stdlib@go1.25.3
0.53.0
1.25.10
1
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.53.0
1.25.10
1
grafana/grafana:10.1.50679e877ba20
golang.org/x/net@v0.12.0
stdlib@go1.20.10
0.53.0
1.25.10
1
grafana/grafana:7.5.609bb407e26ab
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.1
0.53.0
1.25.10
1
grafana/grafana:13.0.10f86bada30d6
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.53.0
1.25.10
1
grafana/grafana:7.3.315b977f5207d
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.53.0
1.25.10
1
grafana/grafana:9.4.71a359d92f40e
golang.org/x/net@v0.4.0
stdlib@go1.20.1
0.53.0
1.25.10
1
grafana/grafana:10.1.11b9ca4bbc4a2
golang.org/x/net@v0.12.0
stdlib@go1.20.8
0.53.0
1.25.10
1
grafana/grafana:13.0.1-security-012d1f9ae67c17
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
grafana/grafana:12.2.22ebef928d7e5
golang.org/x/net@v0.45.0
stdlib@go1.25.3
0.53.0
1.25.10
1
grafana/grafana:12.2.135c41e0fd029
golang.org/x/net@v0.45.0
stdlib@go1.25.3
0.53.0
1.25.10
1
grafana/grafana:9.5.239c849cebccc
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.53.0
1.25.10
1
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.53.0
1.25.10
1
grafana/grafana:11.5.15781759b3d27
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10
1
grafana/grafana:11.6.062d2b9d20a19
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.53.0
1.25.10
1
grafana/grafana:8.0.3696823fbc561
golang.org/x/net@v0.0.0-20210521195947-fe42d452be8f
stdlib@go1.16.1
0.53.0
1.25.10
1
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/net@v0.19.0
stdlib@go1.21.3
0.53.0
1.25.10
1
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.5
0.53.0
1.25.10
1
grafana/grafana:12.3.070d9599b186c
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.53.0
1.25.10
1
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.53.0
1.25.10
1
grafana/grafana:12.2.074144189b384
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
1
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
1
grafana/grafana:10.3.38640e5038e83
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
1
grafana/grafana:11.5.28b37a2f028f1
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10
1
grafana/grafana:9.1.19746858c20e6
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.17.12
0.53.0
1.25.10
1
grafana/grafana:12.1.1a1701c218024
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10
1
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.11
0.53.0
1.25.10
1
grafana/grafana:10.4.19a9043254ba16
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.53.0
1.25.10
1
grafana/grafana:13.1.3ab5cb380e3ff
golang.org/x/net@v0.49.0
0.53.0
1
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10
1
grafana/grafana:12.0.2b5b59bfc7561
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10
1
grafana/grafana:12.3.2ba93c9d192e5
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.53.0
1.25.10
1
grafana/grafana:6.5.1befcd84da2c1
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.53.0
1.25.10
1
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.6
0.53.0
1.25.10
1
grafana/grafana:8.3.4cf81d2c753c8
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.6
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.