StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,051
of 17,803 indexed, latest versions
Container images
4,685
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,051 of 17,803 indexed charts deploy, on 4,685 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,529
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,580
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,051 by stars
ChartLatestAffected imagesRadar Score
kubernetes-dashboardgpg-dev7.5.04 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

4 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubernetesui/dashboard-api:1.7.060595892c2cf
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
kubernetesui/dashboard-auth:1.1.307135c09e9ff
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.53.0
1.25.10
kubernetesui/dashboard-metrics-scraper:1.1.17747d363c9fe
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.53.0
1.25.10
kubernetesui/dashboard-web:1.4.04445b31a2c25
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10

Open the chart page →

6,092
metrics-servergpg-dev3.12.11 of 1See more

metrics-server gpg-dev 3.12.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/net@v0.20.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

1,085
opentelemetry-demogpg-dev0.33.88 of 27See more

opentelemetry-demo gpg-dev 0.33.8

8 of the 27 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.53.0
1.25.10
jaegertracing/all-in-one:1.53.060e65bfffe1f
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.53.0
1.25.10
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
golang.org/x/net@v0.27.0
stdlib@go1.22.5
0.53.0
1.25.10
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
golang.org/x/net@v0.25.0
stdlib@go1.22.8
0.53.0
1.25.10
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
golang.org/x/net@v0.25.0
stdlib@go1.22.8
0.53.0
1.25.10
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.0.03b9b2a15d376
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

49,771
prometheusgpg-dev29.2.16 of 6See more

prometheus gpg-dev 29.2.1

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.90.1693faa0b8724
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.32.058e117eabcce
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.11.2cd37346c9745
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

3,309
prometheus-operator-admission-webhookgpg-dev0.18.12 of 2See more

prometheus-operator-admission-webhook gpg-dev 0.18.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/admission-webhook:v0.79.2d4c97a1b2d67
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

1,685
thanosgpg-dev0.5.31 of 1See more

thanos gpg-dev 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

602
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

1,308
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

1,573
whoami-demogpg-dev0.1.01 of 1See more

whoami-demo gpg-dev 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.25.10

Open the chart page →

1,280
grafana-cloud-onboardinggrafana0.4.75 of 5See more

grafana-cloud-onboarding grafana 0.4.7

5 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/beyla-k8s-cache:253b2f561cb1b
golang.org/x/net@v0.48.0
stdlib@go1.25.3
0.53.0
1.25.10
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
stdlib@go1.23.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

4,736
grafana-samplinggrafana1.1.72 of 2See more

grafana-sampling grafana 1.1.7

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10

Open the chart page →

3,403
mimir-openshift-experimentalgrafana2.1.03 of 4See more

mimir-openshift-experimental grafana 2.1.0

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.8
0.53.0
1.25.10
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.53.0
1.25.10
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.53.0
1.25.10

Open the chart page →

17,808
pyroscope-monitoringgrafana0.1.15 of 6See more

pyroscope-monitoring grafana 0.1.1

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
stdlib@go1.23.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

8,488
snyk-exportergrafana0.1.01 of 1See more

snyk-exporter grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/snyk_exporter:v1.4.1d3c9093401ca
stdlib@go1.21.0
1.25.10

Open the chart page →

669
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

5,323
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,520
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/net@v0.26.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

78,760
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:85211c51171f5
stdlib@go1.24.6
1.25.10

Open the chart page →

5,389
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/net@v0.24.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

1,398
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

14,302
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.53.0
1.25.10

Open the chart page →

2,608
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

2,182
routergroundcover1.12.3754 of 7See more

router groundcover 1.12.375

4 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
stdlib@go1.25.7
1.25.10
quay.io/groundcover/tools:20260719b705e0cbe171
stdlib@go1.24.4
1.25.10

Open the chart page →

6,154
temporalgroundcover1.12.3751 of 2See more

temporal groundcover 1.12.375

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

2,164
mysqlgroundhog2k3.1.41 of 1See more

mysql groundhog2k 3.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
stdlib@go1.24.6
1.25.10

Open the chart page →

463
tailscale-subnet-routergtaylor1.2.11 of 1See more

tailscale-subnet-router gtaylor 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
golang.org/x/net@v0.1.0
stdlib@go1.19.2-ts3fd24dee31
0.53.0
1.25.10

Open the chart page →

1,834
minifluxhajowielandVerified publisher1.0.01 of 1See more

miniflux hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

1,257
hakoniwahakoniwa0.1.01 of 1See more

hakoniwa hakoniwa 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/aplulu/hakoniwa:0.1.0accf0b921388
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

338
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.53.0
1.25.10

Open the chart page →

2,381
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.3
0.53.0
1.25.10

Open the chart page →

4,462
mautrix-signalhalkeye0.3.01 of 2See more

mautrix-signal halkeye 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
signald/signald:0.23.2edbff058278c
stdlib@go1.18.10
1.25.10

Open the chart page →

1,500
thunderdome-planning-pokerhalkeye0.1.11 of 1See more

thunderdome-planning-poker halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

432
whoamihalkeye1.0.11 of 1See more

whoami halkeye 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
containous/whoami:v1.5.07d6a3c8f9147
stdlib@go1.14
1.25.10

Open the chart page →

1,280
hcp-terraform-operatorhashicorpVerified publisher2.12.11 of 2See more

hcp-terraform-operator hashicorp 2.12.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.20.1f5fbfec6a2b2
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

692
hatchet-apihatchetOfficialVerified publisher0.19.01 of 4See more

hatchet-api hatchet 0.19.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

1,726
hatchet-hahatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-ha hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

7,649
hatchet-stackhatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-stack hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

7,649
hawk-envoy-pluginhawk0.1.02 of 4See more

hawk-envoy-plugin hawk 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/collector-go:main7217f1a4fa28
stdlib@go1.17.13
1.25.10
ghcr.io/privacyengineering/consumer:main73f59c032812
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

61,394
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.6
0.53.0
1.25.10

Open the chart page →

3,030
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/net@v0.0.0-20200520182314-0ba52f642ac2
stdlib@go1.14.7
0.53.0
1.25.10

Open the chart page →

2,637
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.25.10

Open the chart page →

6,762
headcniheadcni1.0.101 of 1See more

headcni headcni 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
binrc/headcni:1.0.10e199c334b957
stdlib@go1.22.10
1.25.10

Open the chart page →

724
heliconehelicone0.1.422 of 14See more

helicone helicone 0.1.42

2 of the 14 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
stdlib@go1.19.5
1.25.10
supabase/gotrue:v2.91.07174d551d720
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

72,363
hello-gohello-goVerified publisher0.2.21 of 1See more

hello-go hello-go 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.25.10

Open the chart page →

1,315
hello_worldcharthellohelm0.1.01 of 1See more

hello_worldchart hellohelm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dockerdaemon0901/rolldice:v14e5bfe179c7e
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

863
helm-airportshelm-airports0.1.02 of 7See more

helm-airports helm-airports 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

12,680
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,559
airports-postgreshelm-airports-dan0.1.01 of 1See more

airports-postgres helm-airports-dan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10

Open the chart page →

1,027
helm-airportshelm-airports-dan0.1.02 of 7See more

helm-airports helm-airports-dan 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

5,586
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,559

Container images carrying it

4,685 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
itzg/minecraft-server:latest8672e335dbef
stdlib@go1.24.6
1.25.10
1
itzg/minecraft-server:2026.9.1e8640538dac5
stdlib@go1.22.2
1.25.10
1
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.6
0.53.0
1.25.10
1
ixsystems/truecommand:3.2.019c218455cd2
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.53.0
1.25.10
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.17.2
0.53.0
1.25.10
1
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.25.10
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.25.10
1
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.17.3
0.53.0
1.25.10
1
jaegertracing/all-in-one:1.53.060e65bfffe1f
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
1
jaegertracing/all-in-one:1.42.07d32a4eddec7
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10
1
jaegertracing/all-in-one:1.22.0ca6b73330616
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15.8
0.53.0
1.25.10
1
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.53.0
1.25.10
1
jaegertracing/all-in-one:1.55f6b5d09073f1
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.53.0
1.25.10
1
jaegertracing/jaeger:2.9.0e128b9adbb29
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.53.0
1.25.10
1
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
1
jaegertracing/jaeger-operator:1.61.03f036ec60e61
golang.org/x/net@v0.29.0
stdlib@go1.22.3
0.53.0
1.25.10
1
jaegertracing/jaeger-query:1.41.0b636f0f464bc
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
1
jakuboskera/todo-operator:v0.1.0a305b8ce5bff
golang.org/x/net@v0.47.0
stdlib@go1.25.3
0.53.0
1.25.10
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/net@v0.29.0
stdlib@go1.22.8
0.53.0
1.25.10
1
jamesread/olivetin:3000.20.0f3066e207efd
stdlib@go1.26.0
1.25.10
1
jdvalencia422/observabilitysec:latesta80b6e47a7b8
stdlib@go1.18.4
1.25.10
1
jeboehm/mailserver-filter:5.0.92e756949e537d
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10
1
jeboehm/mailserver-mta:5.0.925fb2f31c940d
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.53.0
1.25.10
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.53.0
1.25.10
1
jfwenisch/alpine-tor:latest9e6c229f953c
golang.org/x/net@v0.0.0-20190328230028-74de082e2cca
stdlib@go1.14.6
0.53.0
1.25.10
1
jhaals/yopass:11.17.026873480863b
stdlib@go1.20.5
1.25.10
1
jhaals/yopass:11.15.16bca8d5a4914
stdlib@go1.20.5
1.25.10
1
jhaals/yopass:12.5.0916a1cf45d36
stdlib@go1.25.5
1.25.10
1
jhaals/yopass:11.4.69516e3b3e88c
stdlib@go1.19.1
1.25.10
1
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/net@v0.1.0
stdlib@go1.17.13
0.53.0
1.25.10
1
jhonbrownn/elchi-discovery:latest8f6551ecc98c
golang.org/x/net@v0.13.0
stdlib@go1.23.1
0.53.0
1.25.10
1
jkremser/log2rbac:v0.0.5e35cf56ef183
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.53.0
1.25.10
1
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.5
0.53.0
1.25.10
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.15
0.53.0
1.25.10
1
johnblack77/clustereye-api:latest9b8dbc0264ac
golang.org/x/net@v0.50.0
0.53.0
1
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.53.0
1.25.10
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/net@v0.9.0
stdlib@go1.18.10
0.53.0
1.25.10
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.53.0
1.25.10
1
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
golang.org/x/net@v0.52.0
0.53.0
1
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/net@v0.11.0
stdlib@go1.18.7
0.53.0
1.25.10
1
jupyterhub/k8s-image-awaiter:3.0.1-0.dev.git.6287.hbfb05cd6a395326989c3
stdlib@go1.18.10
1.25.10
1
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.53.0
1.25.10
1
jwilder/dockerize:v0.10.0839cd6793d19
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.53.0
1.25.10
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.10
0.53.0
1.25.10
1
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15
0.53.0
1.25.10
1
kaiso/kom-operator:v2.2.0e0e22b928bdd
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
1
kayrosuno/kping:latestf3bd44b29b0d
golang.org/x/net@v0.43.0
stdlib@go1.26.1
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.