StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,127
of 17,805 indexed, latest versions
Container images
4,734
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,127 of 17,805 indexed charts deploy, on 4,734 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,576
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,613
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,127 by stars
ChartLatestAffected imagesRadar Score
ucloud-exporterdoubanVerified publisher0.1.31 of 1See more

ucloud-exporter douban 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/douban/ucloud-exporter:mainb4bb8a9021a2
stdlib@go1.24.2
1.25.10

Open the chart page →

984
upyun-exporterdoubanVerified publisher0.1.21 of 1See more

upyun-exporter douban 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/douban/upyun-exporter:main6810900c9c4a
stdlib@go1.25.5
1.25.10

Open the chart page →

833
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.02 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.25.10
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.25.10

Open the chart page →

24,821
drogue-cloud-examplesdrogue-iotVerified publisher0.7.113 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

3 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.53.0
1.25.10
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
stdlib@go1.15.6
1.25.10
ghcr.io/ctron/kubectl:1.25e37d61b5277c
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

30,821
drogue-cloud-metricsdrogue-iotVerified publisher0.7.116 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

6 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.53.0
1.25.10
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.10
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.10
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.53.0
1.25.10

Open the chart page →

13,588
drone-kubernetes-secretsdroneVerified publisher0.1.41 of 1See more

drone-kubernetes-secrets drone 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
drone/kubernetes-secrets:latest206df2280ecf
golang.org/x/net@v0.0.0-20180811021610-c39426892332
stdlib@go1.13.15
0.53.0
1.25.10

Open the chart page →

2,761
mtr-exporterdrpsychickVerified publisher0.0.51 of 1See more

mtr-exporter drpsychick 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/mgumz/mtr-exporter:0.4.0f4691c8fe8eb
stdlib@go1.22.8
1.25.10

Open the chart page →

407
piraeusdtrdnk-helm-chartsVerified publisher2.2.01 of 1See more

piraeus dtrdnk-helm-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/piraeusdatastore/piraeus-operator:v2.2.0ec4022c8b0e3
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

1,042
rook-cephdtrdnk-helm-chartsVerified publisher0.0.12 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.53.0
1.25.10
quay.io/cephcsi/ceph-csi-operator:v0.5.014fe2f1bffc3
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

2,015
tempo-operatordtrdnk-helm-chartsVerified publisher0.0.31 of 2See more

tempo-operator dtrdnk-helm-charts 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/grafana/tempo-operator/tempo-operator:v0.4.02627be646391
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

893
temporaldtrdnk-helm-chartsVerified publisher0.35.08 of 13See more

temporal dtrdnk-helm-charts 0.35.0

8 of the 13 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.53.0
1.25.10
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.10
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.53.0
1.25.10
temporalio/admin-tools:1.22.4258958fe2ff2
golang.org/x/net@v0.8.0
stdlib@go1.20.10
0.53.0
1.25.10
temporalio/server:1.22.4c0a44c26397b
golang.org/x/net@v0.7.0
stdlib@go1.20.11
0.53.0
1.25.10
temporalio/ui:2.16.2af9c9349708f
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.53.0
1.25.10

Open the chart page →

20,261
cloudflaredduck-helm1.1.31 of 1See more

cloudflared duck-helm 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

1,481
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
stdlib@go1.22.6
1.25.10

Open the chart page →

3,513
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
stdlib@go1.20.12
1.25.10

Open the chart page →

4,263
duplicacyduplicacy0.1.21 of 2See more

duplicacy duplicacy 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
drumsergio/duplicacy-container:0.1.0dd3ee9703969
golang.org/x/net@v0.10.0
stdlib@go1.21.13
0.53.0
1.25.10

Open the chart page →

2,424
applause-btnduyet0.1.31 of 1See more

applause-btn duyet 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
duyetdev/applause-btn:latest25e59d223eaa
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.14.9
0.53.0
1.25.10

Open the chart page →

2,637
commentoduyet0.2.01 of 2See more

commento duyet 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/net@v0.0.0-20180811021610-c39426892332
stdlib@go1.14.2
0.53.0
1.25.10

Open the chart page →

2,680
kubernetes-database-scalerdvdlevanonVerified publisher0.1.21 of 1See more

kubernetes-database-scaler dvdlevanon 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dvdlevanon/kubernetes-database-scaler:v0.0.361e79c1643fe4
golang.org/x/net@v0.8.0
0.53.0

Open the chart page →

1,024
ai-scale-authdysnixVerified publisher0.1.12 of 3See more

ai-scale-auth dysnix 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alex6021710/ai-scale-auth:latest6c7a47e470c3
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.16.12
0.53.0
1.25.10
alex6021710/ai-scale-migrator:latest744b8a924f35
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.2
0.53.0
1.25.10

Open the chart page →

6,157
ai-scale-doerdysnixVerified publisher0.1.01 of 1See more

ai-scale-doer dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alex6021710/ai-scale-doer:latest31e533cf7cd3
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.16.10
0.53.0
1.25.10

Open the chart page →

2,808
ai-scale-providerdysnixVerified publisher0.1.01 of 1See more

ai-scale-provider dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alex6021710/ai-scale-provider:latest5837d9b30cc7
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.15.8
0.53.0
1.25.10

Open the chart page →

2,186
ai-scale-saverdysnixVerified publisher0.1.01 of 1See more

ai-scale-saver dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alex6021710/ai-scale-saver:latestf73e8d60fd03
golang.org/x/net@v0.0.0-20211105192438-b53810dc28af
stdlib@go1.17
0.53.0
1.25.10

Open the chart page →

2,143
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
golang.org/x/net@v0.21.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

9,445
bitcoinddysnixVerified publisher0.4.31 of 2See more

bitcoind dysnix 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
stdlib@go1.22.2
1.25.10

Open the chart page →

2,000
bordysnixVerified publisher0.0.81 of 1See more

bor dysnix 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
0xpolygon/bor:1.3.7396d3de26d8b
golang.org/x/net@v0.26.0
stdlib@go1.22.1
0.53.0
1.25.10

Open the chart page →

1,381
gcp-local-ssd-raiddysnixVerified publisher0.1.71 of 2See more

gcp-local-ssd-raid dysnix 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/net@v0.37.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

2,439
gke-upgrade-notification-handlerdysnixVerified publisher0.1.11 of 1See more

gke-upgrade-notification-handler dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.7
0.53.0
1.25.10

Open the chart page →

2,097
grafana-dashboardsdysnixVerified publisher0.2.21 of 2See more

grafana-dashboards dysnix 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:7.4.5d322192ed2fa
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.6
0.53.0
1.25.10

Open the chart page →

5,168
heimdalldysnixVerified publisher0.0.11 of 1See more

heimdall dysnix 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
0xpolygon/heimdall:1.0.134ddf259993c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

1,374
local-path-provisionerdysnixVerified publisher0.0.201 of 1See more

local-path-provisioner dysnix 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

2,926
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
stdlib@go1.16.12
1.25.10

Open the chart page →

5,056
servicemonitor-appsdysnixVerified publisher0.1.01 of 1See more

servicemonitor-apps dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

1,579
smokeping-proberdysnixVerified publisher0.3.11 of 1See more

smokeping-prober dysnix 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
superque/smokeping-prober:v0.11.028ca636d1dee
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

471
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,266
echoappechoapp0.1.01 of 1See more

echoapp echoapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/http-echo:1.0.0fcb75f691c8b
stdlib@go1.21.1
1.25.10

Open the chart page →

550
aeros-orchestrator-overlayeclipse-aeriosVerified publisher2.0.01 of 2See more

aeros-orchestrator-overlay eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
masipcat/wireguard-go:latest696206e5954d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.20.14
0.53.0
1.25.10

Open the chart page →

1,195
api-gatewayeclipse-aeriosVerified publisher1.7.01 of 1See more

api-gateway eclipse-aerios 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
devopsfaith/krakend:2.6.34c678c224f67
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.53.0
1.25.10

Open the chart page →

1,427
federatoreclipse-aeriosVerified publisher1.1.01 of 1See more

federator eclipse-aerios 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eclipseaerios/federator:1.1.018c7f0d101c0
golang.org/x/net@v0.25.0
stdlib@go1.22.12
0.53.0
1.25.10

Open the chart page →

743
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.25.10

Open the chart page →

4,677
iotaeclipse-aeriosVerified publisher1.0.23 of 4See more

iota eclipse-aerios 1.0.2

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eclipseaerios/iota-tangle-peerer:latest99d7ff18d416
golang.org/x/net@v0.30.0
stdlib@go1.22.12
0.53.0
1.25.10
iotaledger/hornet:2.001206f1ba89c
golang.org/x/net@v0.14.0
stdlib@go1.21.10
0.53.0
1.25.10
iotaledger/inx-dashboard:1.012c669cb8748
golang.org/x/net@v0.14.0
stdlib@go1.21.1
0.53.0
1.25.10

Open the chart page →

13,669
llo-apieclipse-aeriosVerified publisher1.0.01 of 1See more

llo-api eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eclipseaerios/llo-api:1.2.0ab7a04182191
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.53.0
1.25.10

Open the chart page →

931
llo-docker-operatoreclipse-aeriosVerified publisher1.0.02 of 2See more

llo-docker-operator eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
golang.org/x/net@v0.25.0
stdlib@go1.23.12
0.53.0
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

2,194
llo-k8seclipse-aeriosVerified publisher1.1.02 of 2See more

llo-k8s eclipse-aerios 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/net@v0.10.0
stdlib@go1.21.13
0.53.0
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

2,166
llo-natseclipse-aeriosVerified publisher1.0.01 of 1See more

llo-nats eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats:2.11.4c8cd23806eef
stdlib@go1.24.3
1.25.10

Open the chart page →

837
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
timescale/timescaledb-postgis:latest-pg127758704d4a14
stdlib@go1.14
1.25.10

Open the chart page →

11,485
openfaas2eclipse-aeriosVerified publisher12.0.56 of 6See more

openfaas2 eclipse-aerios 12.0.5

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats-streaming:0.25.5ced93c701875
stdlib@go1.19.10
1.25.10
prom/prometheus:v2.51.24f6c47e39a90
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.53.0
1.25.10
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
ghcr.io/openfaas/gateway:0.27.1382b15393116e
stdlib@go1.24.6
1.25.10
ghcr.io/openfaasltd/jetstream-queue-worker:0.3.37d96366e208b1
stdlib@go1.22.1
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10

Open the chart page →

6,844
openldap-stack-haeclipse-aeriosVerified publisher4.1.21 of 4See more

openldap-stack-ha eclipse-aerios 4.1.2

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eclipseaerios/openldap:2.6.30208743f315e
stdlib@go1.18.2
1.25.10

Open the chart page →

7,539
orion-ldeclipse-aeriosVerified publisher1.0.01 of 2See more

orion-ld eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.21.12
1.25.10

Open the chart page →

9,829
chartecr-toke-renew0.1.51 of 1See more

chart ecr-toke-renew 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

2,819
edge-accessedge-accessVerified publisher0.1.01 of 1See more

edge-access edge-access 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.13.056e3daedf765
golang.org/x/net@v0.42.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

677

Container images carrying it

4,734 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
linuxserver/calibre-web:0.6.24241009026e6f
stdlib@go1.17.8
1.25.10
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
stdlib@go1.16.7
1.25.10
1
linuxserver/smokeping:2.9.02f4488c9afcd
golang.org/x/net@v0.6.0
stdlib@go1.24.12
0.53.0
1.25.10
1
linuxserver/smokeping:2.8.2b7f906899cd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.22.5
0.53.0
1.25.10
1
linuxserver/wireguard:latestbf03578ef731
golang.org/x/net@v0.47.0
0.53.0
1
linuxserver/wireguard:1.0.20260223-r0-ls122dca67384e3e9
golang.org/x/net@v0.47.0
0.53.0
1
lishimeng/hufu:v1.2.13d5752dac834
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.53.0
1.25.10
1
lishimeng/owl-console:v0.11.2c79a67657baf
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10
1
lishimeng/owl-messager:v0.11.23d00485e64dc
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10
1
lishimeng/passport:v0.2.163e7d05ded625
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.53.0
1.25.10
1
lishimeng/passport-profile:v0.2.160970dfe5dc8f
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.53.0
1.25.10
1
lishimeng/tabby:v1.0.48145c3dc83c8
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.53.0
1.25.10
1
lishimeng/tree:v0.2.89b2f8be6c7d3
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.53.0
1.25.10
1
lishimeng/zoo:v0.4.0e0b8d2d8ca28
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.53.0
1.25.10
1
listmonk/listmonk:v6.0.0bf3903d54a46
golang.org/x/net@v0.47.0
stdlib@go1.24.1
0.53.0
1.25.10
1
litestream/litestream:0.3c5a1e1b01916
golang.org/x/net@v0.14.0
stdlib@go1.21.3
0.53.0
1.25.10
1
livekit/ingress:v1.2.21ab01641b366
golang.org/x/net@v0.18.0
stdlib@go1.20.7
0.53.0
1.25.10
1
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/net@v0.0.0-20211004195052-b30845b58a23
stdlib@go1.16.2
0.53.0
1.25.10
1
livekit/livekit-server:v1.9.03602a85840d5
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.53.0
1.25.10
1
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.10
0.53.0
1.25.10
1
lmierzwa/karma:v0.503751e5eed656
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.53.0
1.25.10
1
lmierzwa/karma:v0.70d417abe7ddb5
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.53.0
1.25.10
1
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.10
0.53.0
1.25.10
1
loeken/home-assistant:2026.5.14ce6abc553b3
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.53.0
1.25.10
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.6
0.53.0
1.25.10
1
loftsh/jspolicy:0.2.225deb9bd2683
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.53.0
1.25.10
1
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.53.0
1.25.10
1
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.53.0
1.25.10
1
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.18.9
0.53.0
1.25.10
1
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.7
0.53.0
1.25.10
1
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.53.0
1.25.10
1
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.53.0
1.25.10
1
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.53.0
1.25.10
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.1
0.53.0
1.25.10
1
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
1
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
golang.org/x/net@v0.49.0
0.53.0
1
longhornio/longhorn-ui:v1.10.0e60f36161511
stdlib@go1.24.6
1.25.10
1
longhornio/upgrade-responder:v0.2.05875cef29348
stdlib@go1.17.13
1.25.10
1
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.25.10
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
golang.org/x/net@v0.9.0
stdlib@go1.19.6
0.53.0
1.25.10
1
louislam/uptime-kuma:13d632903e6af
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:2.0.24c364ef96aad
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:2.4.091e963bfda56
stdlib@go1.20.5
1.25.10
1
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.53.0
1.25.10
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.53.0
1.25.10
1
lumenvox/admin-portal:7.112310cf52f79
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.