StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,039
of 17,792 indexed, latest versions
Container images
4,657
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,039 of 17,792 indexed charts deploy, on 4,657 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,508
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,567
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,039 by stars
ChartLatestAffected imagesRadar Score
unifi-pollerhalkeye0.1.21 of 1See more

unifi-poller halkeye 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.7
0.53.0
1.25.10

Open the chart page →

1,654
whoamiharrytangVerified publisher0.2.01 of 1See more

whoami harrytang 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.25.10

Open the chart page →

353
monitoring-stackhaukitechVerified publisher0.1.113 of 3See more

monitoring-stack haukitech 0.1.11

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

2,164
prometheus-operatorhaukitechVerified publisher0.1.41 of 1See more

prometheus-operator haukitech 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.53.0
1.25.10

Open the chart page →

561
headscaleheadscaleVerified publisher1.0.191 of 3See more

headscale headscale 1.0.19

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.36.244ef4942e171
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.53.0
1.25.10

Open the chart page →

3,439
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.2
0.53.0
1.25.10

Open the chart page →

1,558
netbirdhelmforgeVerified publisher1.0.101 of 4See more

netbird helmforge 1.0.10

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

3,035
simple-krr-dashboardhelm-simple-krr-dashboardVerified publisher1.6.21 of 3See more

simple-krr-dashboard helm-simple-krr-dashboard 1.6.2

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

2,255
helm-watchdog-pod-deletehelm-watchdog-pod-delete0.3.01 of 1See more

helm-watchdog-pod-delete helm-watchdog-pod-delete 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

1,153
home-assistanthome-assistantVerified publisher0.5.101 of 3See more

home-assistant home-assistant 0.5.10

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.53.0
1.25.10

Open the chart page →

2,338
hpe-cosi-driverhpe-storageVerified publisher2.0.02 of 2See more

hpe-cosi-driver hpe-storage 2.0.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.53.0
1.25.10
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
golang.org/x/net@v0.40.0
stdlib@go1.24.11
0.53.0
1.25.10

Open the chart page →

1,679
inference-manager-engineinference-manager-engine1.46.01 of 1See more

inference-manager-engine inference-manager-engine 1.46.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/inference-manager-engine:1.46.0c46f109c3d0b
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.53.0
1.25.10

Open the chart page →

266
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.5
0.53.0
1.25.10

Open the chart page →

2,623
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.21 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.25.10

Open the chart page →

10,625
inlets-operatorinlets0.17.201 of 1See more

inlets-operator inlets 0.17.20

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/inlets/inlets-operator:0.17.2208265c006973
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

504
coreinstill-aiOfficialVerified publisher0.1.7511 of 15See more

core instill-ai 0.1.75

11 of the 15 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.53.0
1.25.10
instill/api-gateway:9bfdc88b53eaa51c523
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.53.0
1.25.10
instill/artifact-backend:b28766ac4a393e601ed
golang.org/x/net@v0.33.0
stdlib@go1.25.6
0.53.0
1.25.10
instill/console:0.68.54cd70e2df5c6
stdlib@go1.23.10
1.25.10
instill/mgmt-backend:d0933d4ebe12f77a3f9
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.53.0
1.25.10
instill/model-backend:611f0f2e980125e5ba5
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.53.0
1.25.10
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
stdlib@go1.18.3
0.53.0
1.25.10
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.10
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.25.10
openfga/openfga:v1.9.25e94966c11df
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.53.0
1.25.10
temporalio/admin-tools:1.28cfde8170c92f
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

31,122
intel-gpu-resource-driverintelVerified publisher0.7.01 of 1See more

intel-gpu-resource-driver intel 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

565
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.6
0.53.0
1.25.10

Open the chart page →

2,211
amazon-eks-pod-identity-webhookjkroepkeVerified publisher2.6.51 of 1See more

amazon-eks-pod-identity-webhook jkroepke 2.6.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/eks/amazon-eks-pod-identity-webhook:v0.6.173071570e8e8c
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

152
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.25.10

Open the chart page →

4,526
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.53.0
1.25.10

Open the chart page →

4,639
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.25.10

Open the chart page →

7,378
k8s-sftp-gcsk8s-sftp-gcsVerified publisher0.1.41 of 1See more

k8s-sftp-gcs k8s-sftp-gcs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.25.10

Open the chart page →

1,606
k8statusk8statusOfficialVerified publisher0.17.01 of 1See more

k8status k8status 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/stenic/k8status:0.17.093298e03089e
golang.org/x/net@v0.26.0
stdlib@go1.23.12
0.53.0
1.25.10

Open the chart page →

712
kanister-operatorkanister0.118.01 of 1See more

kanister-operator kanister 0.118.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
golang.org/x/net@v0.41.0
stdlib@go1.25.6
0.53.0
1.25.10

Open the chart page →

1,170
kiali-operatorkiali2.32.01 of 1See more

kiali-operator kiali 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

1,085
mysqldumpkokuwa7.0.31 of 1See more

mysqldump kokuwa 7.0.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
stdlib@go1.26.1
1.25.10

Open the chart page →

847
kraken-cikraken-ciVerified publisher1.7.362 of 10See more

kraken-ci kraken-ci 1.7.36

2 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.10
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.53.0
1.25.10

Open the chart page →

7,303
kubearmorkubearmor1.7.41 of 4See more

kubearmor kubearmor 1.7.4

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubearmor/kubearmor-relay-server:latest2dd4809d7c11
stdlib@go1.25.9
1.25.10

Open the chart page →

1,377
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
neosu/kubebadges:v0.0.5256530d8e5c6
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,799
pyroscopekubeblocksVerified publisher0.2.921 of 1See more

pyroscope kubeblocks 0.2.92

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
stdlib@go1.19.6
0.53.0
1.25.10

Open the chart page →

1,620
kubepatternkubepattern0.0.51 of 1See more

kubepattern kubepattern 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kubepattern/kubepattern:0.0.50762baa6d9b0
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

241
skywalkingkubesphere-testVerified publisher3.1.02 of 4See more

skywalking kubesphere-test 3.1.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.53.0
1.25.10
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.53.0
1.25.10

Open the chart page →

18,061
kubeviouskubevious1.2.23 of 7See more

kubevious kubevious 1.2.2

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubevious/ui:1.2.16233e84bdd59
golang.org/x/net@v0.0.0-20220812165438-1d4ff48094d1
stdlib@go1.19.1
0.53.0
1.25.10
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.25.10
redislabs/redisearch:2.4.1433561794c5c8
stdlib@go1.16.7
1.25.10

Open the chart page →

14,212
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.05 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs-webhook:latestc1f19557bdcb
stdlib@go1.26.0
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.53.0
1.25.10
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.53.0
1.25.10

Open the chart page →

11,675
prometheus-pingmesh-exporterkubservice-chartsVerified publisher1.1.11 of 1See more

prometheus-pingmesh-exporter kubservice-charts 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:latest355fa4be8e97
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.53.0
1.25.10

Open the chart page →

855
karporkusionstackVerified publisher0.7.62 of 3See more

karpor kusionstack 0.7.6

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/net@v0.19.0
stdlib@go1.22.12
0.53.0
1.25.10
quay.io/coreos/etcd:v3.5.11842975891182
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.53.0
1.25.10

Open the chart page →

3,310
kwokkwokOfficialVerified publisher0.3.01 of 1See more

kwok kwok 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.53.0
1.25.10

Open the chart page →

708
litellm-operatorlitellm-operatorVerified publisher1.1.21 of 1See more

litellm-operator litellm-operator 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bbdsoftware/litellm-operator:1.1.2167a51113d90
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

276
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

3,686
vcluster-k8sloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-k8s loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.53.0
1.25.10
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.53.0
1.25.10
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.53.0
1.25.10

Open the chart page →

5,595
vcluster-platformloftVerified publisher4.12.01 of 1See more

vcluster-platform loft 4.12.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-platform:4.12.0ef92da4621e6
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

752
lxcfs-on-kuberneteslxcfs-on-kubernetes0.2.71 of 2See more

lxcfs-on-kubernetes lxcfs-on-kubernetes 0.2.7

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cndoit18/lxcfs-agent:latest9853bb613cd0
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

2,095
mariadbmariadbVerified publisher0.4.01 of 1See more

mariadb mariadb 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
stdlib@go1.24.6
1.25.10

Open the chart page →

2,458
mattermost-rtcdmattermostVerified publisher1.4.11 of 1See more

mattermost-rtcd mattermost 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
mattermost/rtcd:latesta27058aaa53a
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

595
veleromesosphere3.2.51 of 1See more

velero mesosphere 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.53.0
1.25.10

Open the chart page →

1,871
kubecostmesosphere-stable0.37.57 of 9See more

kubecost mesosphere-stable 0.37.5

7 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.53.0
1.25.10
grafana/grafana:9.4.71a359d92f40e
golang.org/x/net@v0.4.0
stdlib@go1.20.1
0.53.0
1.25.10
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/thanos/thanos:v0.36.1e542959e1b36
golang.org/x/net@v0.26.0
stdlib@go1.21.13
0.53.0
1.25.10

Open the chart page →

17,799
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.2
0.53.0
1.25.10

Open the chart page →

2,750
helm-ai-kernelmindburn-labsOfficialVerified publisher0.8.51 of 2See more

helm-ai-kernel mindburn-labs 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

2,175
mortalgpumortalgpuOfficialVerified publisher1.3.71 of 1See more

mortalgpu mortalgpu 1.3.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/maxiv/mortalgpu:1.3.7e1c5c194bbf0
stdlib@go1.26.0
1.25.10

Open the chart page →

379

Container images carrying it

4,657 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/postgres:18.1-alpine3.2144d837eb4c2e
stdlib@go1.24.6
1.25.10
1
library/postgres:16.11468e1f126ca5
stdlib@go1.24.6
1.25.10
1
library/postgres:18.3-alpine54451ecb8ab3
stdlib@go1.24.6
1.25.10
1
library/postgres:16.6557fea37a744
stdlib@go1.18.2
1.25.10
1
library/postgres:13.11-bullseye5c265bf1fd30
stdlib@go1.18.2
1.25.10
1
library/postgres:17.5-alpine6567bca8d7bc
stdlib@go1.18.2
1.25.10
1
library/postgres:18.369e8582b781c
stdlib@go1.24.6
1.25.10
1
library/postgres:15.186eb0add3b77c
stdlib@go1.24.6
1.25.10
1
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.25.10
1
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.25.10
1
library/postgres:17.2-alpine7e5df973a748
stdlib@go1.18.2
1.25.10
1
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.25.10
1
library/postgres:18.48ff36f3c6637
stdlib@go1.24.6
1.25.10
1
library/postgres:18.4-alpine3.249a8afca54e78
stdlib@go1.24.6
1.25.10
1
library/postgres:18.3a9abf4275f9e
stdlib@go1.24.6
1.25.10
1
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.25.10
1
library/postgres:13.12ced3ba927f4c
stdlib@go1.18.2
1.25.10
1
library/postgres:15.18-bookworme8db9bd3e9e1
stdlib@go1.24.6
1.25.10
1
library/postgres:14.22eba8ddbdd837
stdlib@go1.24.6
1.25.10
1
library/postgres:17.10ebba4f4de37f
stdlib@go1.24.6
1.25.10
1
library/postgres:17.6-alpineef257d85f76e
stdlib@go1.24.6
1.25.10
1
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.25.10
1
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.25.10
1
library/rabbitmq:4.3.51773ab33af6a
stdlib@go1.22.2
1.25.10
1
library/rabbitmq:4.3.5-management57bddb6fbc34
stdlib@go1.22.2
1.25.10
1
library/rabbitmq:4.2.87561d672fae4
stdlib@go1.22.2
1.25.10
1
library/rabbitmq:4.3.4-managementeb5295d08332
stdlib@go1.22.2
1.25.10
1
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.25.10
1
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.25.10
1
library/redis:7.2.5-alpine6aaf3f5e6bc8
stdlib@go1.18.2
1.25.10
1
library/redis:6.2.20-alpine77697a75da9f
stdlib@go1.18.2
1.25.10
1
library/redis83edc2b8e9ff
stdlib@go1.18.2
1.25.10
1
library/redis:7.0.1092b8b307ee28
stdlib@go1.18.2
1.25.10
1
library/redis:7.4.1bb142a9c18ac
stdlib@go1.18.2
1.25.10
1
library/redis:7.4.1-alpinec1e88455c852
stdlib@go1.18.2
1.25.10
1
library/redis:7.0-alpinec9d92d840fd0
stdlib@go1.18.2
1.25.10
1
library/redmine:6.1.204ac44a2595b
stdlib@go1.24.6
1.25.10
1
library/telegraf:1.20.428e98eece020
golang.org/x/net@v0.0.0-20211005215030-d2e5035098b3
stdlib@go1.17.3
0.53.0
1.25.10
1
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.53.0
1.25.10
1
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.5
0.53.0
1.25.10
1
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.6
0.53.0
1.25.10
1
library/traefik:v2.11.00a5157f742d2
golang.org/x/net@v0.20.0
stdlib@go1.22.0
0.53.0
1.25.10
1
library/traefik:3.3.5104204dadedf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10
1
library/traefik:v2.10.11489caffaedb
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.53.0
1.25.10
1
library/traefik:2.10.61957e3314f43
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.53.0
1.25.10
1
library/traefik:2.5.62f603f8d3abe
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.5
0.53.0
1.25.10
1
library/traefik:v3.6.1334d5089d0b41
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.53.0
1.25.10
1
library/traefik:v1.7.345d47b7bb2546
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16.12
0.53.0
1.25.10
1
library/traefik:2.5.47d0228d19042
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.3
0.53.0
1.25.10
1
library/traefik:2.4.8eda951fd29a8
golang.org/x/net@v0.0.0-20210220033124-5f55cee0dc0d
stdlib@go1.16.2
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.