StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,113
of 17,813 indexed, latest versions
Container images
4,708
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,113 of 17,813 indexed charts deploy, on 4,708 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,552
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,595
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,113 by stars
ChartLatestAffected imagesRadar Score
kubeclaritykubeclarity2.23.33 of 5See more

kubeclarity kubeclarity 2.23.3

3 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/openclarity/grype-server:v0.6.079412399f301
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.53.0
1.25.10
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
ghcr.io/openclarity/kubeclarity-sbom-db:v2.23.3cef2b88bfc76
golang.org/x/net@v0.17.0
stdlib@go1.21.6
0.53.0
1.25.10

Open the chart page →

5,521
airflow-operatorkubedoopVerified publisher0.4.01 of 1See more

airflow-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/airflow-operator:0.4.0b716ef483b75
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

438
commons-operatorkubedoopVerified publisher0.4.01 of 1See more

commons-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/commons-operator:0.4.01a353def9fe1
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

388
dolphinscheduler-operatorkubedoopVerified publisher0.4.01 of 1See more

dolphinscheduler-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/dolphinscheduler-operator:0.4.0d0a4e55eeb7f
stdlib@go1.25.8
1.25.10

Open the chart page →

381
hbase-operatorkubedoopVerified publisher0.4.01 of 1See more

hbase-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/hbase-operator:0.4.069e9a1b0daf8
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

388
hdfs-operatorkubedoopVerified publisher0.4.01 of 1See more

hdfs-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/hdfs-operator:0.4.0eb3c2928250e
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

438
hive-operatorkubedoopVerified publisher0.4.01 of 1See more

hive-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/hive-operator:0.4.0d66ba9149c22
stdlib@go1.25.8
1.25.10

Open the chart page →

381
kafka-operatorkubedoopVerified publisher0.4.01 of 1See more

kafka-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/kafka-operator:0.4.00a0b4c39c1ba
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

464
listener-operatorkubedoopVerified publisher0.4.06 of 6See more

listener-operator kubedoop 0.4.0

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/listener-csi-driver:0.4.0b69bed123b02
stdlib@go1.25.8
1.25.10
quay.io/zncdatadev/listener-operator:0.4.068b92dae8d75
stdlib@go1.25.8
1.25.10
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

4,537
nifi-operatorkubedoopVerified publisher0.4.01 of 1See more

nifi-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/nifi-operator:0.4.0bb4e26ff5e2f
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

388
secret-operatorkubedoopVerified publisher0.4.05 of 5See more

secret-operator kubedoop 0.4.0

5 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/secret-csi-driver:0.4.0604a7d98ab58
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

4,456
spark-k8s-operatorkubedoopVerified publisher0.4.01 of 1See more

spark-k8s-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/spark-k8s-operator:0.4.0d3f2b10c4a6d
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

411
superset-operatorkubedoopVerified publisher0.4.01 of 1See more

superset-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/superset-operator:0.4.0102e66e32218
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

388
trino-operatorkubedoopVerified publisher0.4.01 of 1See more

trino-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/trino-operator:0.4.04f516757aee3
stdlib@go1.25.8
1.25.10

Open the chart page →

376
zookeeper-operatorkubedoopVerified publisher0.4.01 of 1See more

zookeeper-operator kubedoop 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/zncdatadev/zookeeper-operator:0.4.0b4f33d89ac45
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

388
kube-ecr-secrets-operatorkube-ecr-secrets-operatorVerified publisher0.4.01 of 2See more

kube-ecr-secrets-operator kube-ecr-secrets-operator 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/zak905/kube-ecr-secrets-operator/controller-manager:0.2.11d078e45bac70
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

209
cephfs-csikubegems1.0.81 of 6See more

cephfs-csi kubegems 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.5
0.53.0
1.25.10

Open the chart page →

4,453
chartmuseumkubegems3.8.01 of 1See more

chartmuseum kubegems 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/net@v0.0.0-20220121210141-e204ce36a2ba
stdlib@go1.17.6
0.53.0
1.25.10

Open the chart page →

3,527
gatewaykubegems0.3.22 of 2See more

gateway kubegems 0.3.2

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubegems/ingress-nginx-operator:v0.2.0cc67357beeeb
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.22.5
0.53.0
1.25.10
kubegems/kube-rbac-proxy:v0.8.0941f557ed1ee
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.13.15
0.53.0
1.25.10

Open the chart page →

3,507
giteakubegems5.0.81 of 2See more

gitea kubegems 5.0.8

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gitea/gitea:1.16.8b0bdf102b485
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.53.0
1.25.10

Open the chart page →

3,401
juicefs-csi-driverkubegems0.19.22 of 6See more

juicefs-csi-driver kubegems 0.19.2

2 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.53.0
1.25.10
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.53.0
1.25.10

Open the chart page →

4,866
juicefs-tenantkubegems1.0.11 of 3See more

juicefs-tenant kubegems 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubegems/redis:7.2.5-debian-12-r2870ee3a77add
stdlib@go1.21.11
1.25.10

Open the chart page →

4,339
knative-servingkubegems1.0.17 of 8See more

knative-serving kubegems 1.0.1

7 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned197fbb71d1f1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned08315309da4b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned105bdd14ecaa
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedbac158dfb0c7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mappingdigest-pinnede384a295069b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhookdigest-pinned15f1ce7f35b4
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned1282a399cbb9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.53.0
1.25.10

Open the chart page →

10,476
kubegems-edgekubegems1.24.101 of 1See more

kubegems-edge kubegems 1.24.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/net@v0.19.0
stdlib@go1.24.10
0.53.0
1.25.10

Open the chart page →

3,399
kubegems-multus-cnikubegems2.4.11 of 2See more

kubegems-multus-cni kubegems 2.4.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.16bebbda31416
golang.org/x/net@v0.28.0
stdlib@go1.23.9
0.53.0
1.25.10

Open the chart page →

1,408
kubegems-paikubegems1.0.181 of 1See more

kubegems-pai kubegems 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubegems/mysql:8.0.33-debian-11-r019cb195b9a50
stdlib@go1.19.8
1.25.10

Open the chart page →

1,053
logging-operatorkubegems3.17.61 of 1See more

logging-operator kubegems 3.17.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.9
0.53.0
1.25.10

Open the chart page →

1,801
prometheus-adapterkubegems4.14.11 of 1See more

prometheus-adapter kubegems 4.14.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.53.0
1.25.10

Open the chart page →

945
prometheus-blackbox-exporterkubegems7.1.31 of 1See more

prometheus-blackbox-exporter kubegems 7.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.22.0608acee5704a
golang.org/x/net@v0.0.0-20220728211354-c7608f3a8462
stdlib@go1.18.5
0.53.0
1.25.10

Open the chart page →

1,635
volcanokubegems1.12.13 of 3See more

volcano kubegems 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
volcanosh/vc-controller-manager:v1.12.13815883c32f6
golang.org/x/net@v0.38.0
stdlib@go1.23.7
0.53.0
1.25.10
volcanosh/vc-scheduler:v1.12.1b24ea8af2d16
golang.org/x/net@v0.38.0
stdlib@go1.23.7
0.53.0
1.25.10
volcanosh/vc-webhook-manager:v1.12.1f8b50088a732
golang.org/x/net@v0.30.0
stdlib@go1.23.7
0.53.0
1.25.10

Open the chart page →

5,048
xpai-schedulerkubegems1.12.11 of 2See more

xpai-scheduler kubegems 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

2,325
gptchat-api-feishubotkubegemsapp0.1.13 of 3See more

gptchat-api-feishubot kubegemsapp 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubegems/chatgpt-api:latestf3c492a938ad
stdlib@go1.19.3
1.25.10
kubegems/chatgpt-api-feishubot:latest7c93c84b2055
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
kubegems/chatgpt-api-proxy:latest8905c9dbbb5d
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

8,494
kubeintellectkubeintellectVerified publisher2.5.01 of 2See more

kubeintellect kubeintellect 2.5.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
golang.org/x/net@v0.30.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

1,911
kubelet-summary-exporterkubelet-summary-exporter1.0.01 of 1See more

kubelet-summary-exporter kubelet-summary-exporter 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/salesforce/kubelet-summary-exporter:sha-c2bf90d377e09d2dd72
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

1,016
log-generatorkube-loggingVerified publisher0.6.01 of 1See more

log-generator kube-logging 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/log-generator:v0.6.08324bbc0ec08
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

1,269
logging-demokube-loggingVerified publisher4.0.31 of 1See more

logging-demo kube-logging 4.0.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/log-generator:v0.4.105aa441b20aa
stdlib@go1.20.1
1.25.10

Open the chart page →

1,268
log-socketkube-loggingVerified publisher0.1.21 of 1See more

log-socket kube-logging 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/log-socket:latesta514736d2d4d
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.18.6
0.53.0
1.25.10

Open the chart page →

1,220
kubemacpoolkubemacpoolVerified publisher0.3.01 of 1See more

kubemacpool kubemacpool 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubemacpool:v0.45.0eebb65b8a12c
golang.org/x/net@v0.23.0
stdlib@go1.22.0
0.53.0
1.25.10

Open the chart page →

1,641
kube-netlagkube-netlagVerified publisher1.1.01 of 1See more

kube-netlag kube-netlag 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/net@v0.33.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

1,512
kube-node-readykube-node-ready0.5.01 of 1See more

kube-node-ready kube-node-ready 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/imunhatep/kube-node-ready:0.5.07439f6f9f85c
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

545
apm-serverkube-opsVerified publisher0.1.21 of 1See more

apm-server kube-ops 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
elastic/apm-server:7.17.6c7a1c63257d0
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.2
0.53.0
1.25.10

Open the chart page →

7,229
lokikube-opsVerified publisher1.7.31 of 1See more

loki kube-ops 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kube-ops/loki:2.2.14fbd63194674
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.3
0.53.0
1.25.10

Open the chart page →

2,654
promtailkube-opsVerified publisher1.5.11 of 2See more

promtail kube-ops 1.5.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kube-ops/promtail:2.2.134de6387233b
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.3
0.53.0
1.25.10

Open the chart page →

4,159
kube-ovnkube-ovn-test1.14.01 of 1See more

kube-ovn kube-ovn-test 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubeovn/kube-ovn:v1.14.06722b54eb5c0
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

5,287
kuberay-apiserverkuberay-operator1.7.11 of 2See more

kuberay-apiserver kuberay-operator 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kuberay/security-proxy:nightly4525b5acd23c
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

202
kuberecordkuberecordVerified publisher0.4.01 of 1See more

kuberecord kuberecord 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kuberecord/kuberecord:v0.4.02a19792ad2ec
golang.org/x/net@v0.50.0
0.53.0

Open the chart page →

190
kubereportkubereport1.1.01 of 1See more

kubereport kubereport 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubesuite/kubereport:latest0262424ee702
golang.org/x/net@v0.29.0
stdlib@go1.22.0
0.53.0
1.25.10

Open the chart page →

1,121
cloudflaredkubernetes-homelab-helm-chartsVerified publisher0.1.11 of 1See more

cloudflared kubernetes-homelab-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

1,481
firefly-iiikubernetes-homelab-helm-chartsVerified publisher0.1.31 of 3See more

firefly-iii kubernetes-homelab-helm-charts 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10

Open the chart page →

4,590
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.22 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
stdlib@go1.24.6
1.25.10
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

2,770

Container images carrying it

4,708 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/docker:24.0.2-dind1d148deae16a
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.53.0
1.25.10
1
library/docker:28.5.2-dind2a232a42256f
golang.org/x/net@v0.39.0
stdlib@go1.24.9
0.53.0
1.25.10
1
library/docker:20.10.21-dind3153fa63f546
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.7
0.53.0
1.25.10
1
library/docker:29.8.1-dind76cd6bbc3ab6
golang.org/x/net@v0.50.0
0.53.0
1
library/docker:27-cli851f91d24121
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.53.0
1.25.10
1
library/docker:27-dindaa3df78ecf32
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.53.0
1.25.10
1
library/docker:23.0.6-dindafa5d5134900
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.53.0
1.25.10
1
library/docker:dind-rootlessc876e00a0d81
golang.org/x/net@v0.50.0
0.53.0
1
library/docker:23.0.1-dindd9a0fd8bdd15
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.53.0
1.25.10
1
library/docker:26.1-dinddd43b430341a
golang.org/x/net@v0.25.0
stdlib@go1.21.11
0.53.0
1.25.10
1
library/ghost:6.37.01ef2e532ca4d
stdlib@go1.23.12
1.25.10
1
library/ghost:6.25.12654b1e90413
stdlib@go1.24.6
1.25.10
1
library/ghost:6.41.129773d6be407
stdlib@go1.24.6
1.25.10
1
library/ghost:6.39.0-alpine77196da4b0df
stdlib@go1.24.6
1.25.10
1
library/ghost:5.79.083f7bf209844
stdlib@go1.18.2
1.25.10
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
stdlib@go1.24.6
1.25.10
1
library/ghost:6.63.0e05bc1169fb2
stdlib@go1.24.6
1.25.10
1
library/influxdb:2.8571eb4514977
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.53.0
1.25.10
1
library/influxdb:1.12.3-meta8812029260b5
stdlib@go1.24.13
1.25.10
1
library/influxdb:2.7.4-alpinea10d46445d68
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10
1
library/influxdb:1.12.3-datab0f9fc41ed79
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
1
library/influxdb:2.0.8ba10ac9ba17a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.5
0.53.0
1.25.10
1
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
stdlib@go1.18.3
0.53.0
1.25.10
1
library/influxdb:latestf75e48af0598
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.53.0
1.25.10
1
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.17.2
0.53.0
1.25.10
1
library/logstash:7.17.817a4f64e9cf5
stdlib@go1.19.3
1.25.10
1
library/logstash:9.1.233eae14f0867
stdlib@go1.23.12
1.25.10
1
library/mariadb:10.7.307e06f2e7ae9
stdlib@go1.16.7
1.25.10
1
library/mariadb:10.11.21c33370a599c
stdlib@go1.16.7
1.25.10
1
library/mariadb:10.422edfe1c7834
stdlib@go1.18.2
1.25.10
1
library/mariadb:112439dcd7d140
stdlib@go1.24.6
1.25.10
1
library/mariadb:10.8.2-focal490f01279be1
stdlib@go1.16.7
1.25.10
1
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.25.10
1
library/mariadb:12.3.2628f228f0fd5
stdlib@go1.24.6
1.25.10
1
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.25.10
1
library/mariadb:10.79a48ac9f196f
stdlib@go1.16.7
1.25.10
1
library/mariadb:12.3.2a02fe89cb597
stdlib@go1.24.6
1.25.10
1
library/mariadb:12.3.3ab1c3dd38194
stdlib@go1.24.6
1.25.10
1
library/mariadb:12.2.2b1cb255a9939
stdlib@go1.24.6
1.25.10
1
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.25.10
1
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.25.10
1
library/mariadb:10.9.4fbb8456ebdb1
stdlib@go1.16.7
1.25.10
1
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.25.10
1
library/mongo:7.0.140032d2ca20db
stdlib@go1.21.12
1.25.10
1
library/mongo:8.002a0cc7939f5
stdlib@go1.24.6
1.25.10
1
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.25.10
1
library/mongo:5.0.32-focal3b6c281e1c08
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.53.0
1.25.10
1
library/mongo:4.4-bionic3d0e6df9fd5b
stdlib@go1.16.3
1.25.10
1
library/mongo:7.0-jammy:7-jammy406a4fdca9fc
stdlib@go1.24.6
1.25.10
1
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.25.10
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.