StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,068
of 17,805 indexed, latest versions
Container images
4,673
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,068 of 17,805 indexed charts deploy, on 4,673 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,520
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,573
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,068 by stars
ChartLatestAffected imagesRadar Score
transsmutegabe565Verified publisher1.1.01 of 1See more

transsmute gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

801
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
stdlib@go1.24.6
1.25.10

Open the chart page →

6,475
galoygaloymoney0.34.74 of 24See more

galoy galoymoney 0.34.7

4 of the 24 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.53.0
1.25.10
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.53.0
1.25.10
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.53.0
1.25.10
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

8,730
galoy-depsgaloymoney0.10.208 of 9See more

galoy-deps galoymoney 0.10.20

8 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.9
0.53.0
1.25.10
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10

Open the chart page →

12,010
lndgaloymoney0.10.61 of 3See more

lnd galoymoney 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

2,162
monitoringgaloymoney0.12.215 of 6See more

monitoring galoymoney 0.12.21

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

5,336
galoygaloymoney20.34.74 of 24See more

galoy galoymoney2 0.34.7

4 of the 24 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.53.0
1.25.10
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.53.0
1.25.10
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.53.0
1.25.10
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

8,730
galoy-depsgaloymoney20.10.208 of 9See more

galoy-deps galoymoney2 0.10.20

8 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.9
0.53.0
1.25.10
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10

Open the chart page →

12,010
lndgaloymoney20.10.61 of 3See more

lnd galoymoney2 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

2,162
monitoringgaloymoney20.12.215 of 6See more

monitoring galoymoney2 0.12.21

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

5,336
gameserver-operatorgameserver-operator0.3.01 of 1See more

gameserver-operator gameserver-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/idebeijer/gameserver-operator:latest1b099cfe9e5e
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

383
pagesgary-pages1.0.01 of 3See more

pages gary-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,261
alertmanager-discordgeek-cookbookVerified publisher1.3.21 of 1See more

alertmanager-discord geek-cookbook 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rogerrum/alertmanager-discord:1.0.3827593369625
stdlib@go1.17.4
1.25.10

Open the chart page →

1,045
anonaddygeek-cookbookVerified publisher6.0.01 of 1See more

anonaddy geek-cookbook 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.25.10

Open the chart page →

4,792
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
stdlib@go1.18.4
1.25.10

Open the chart page →

14,842
autobrrgeek-cookbookVerified publisher1.1.31 of 1See more

autobrr geek-cookbook 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

2,236
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
stdlib@go1.16.7
1.25.10

Open the chart page →

16,237
dendritegeek-cookbookVerified publisher6.4.01 of 1See more

dendrite geek-cookbook 6.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.5
0.53.0
1.25.10

Open the chart page →

2,144
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:latesta792931146b4
stdlib@go1.24.9
1.25.10

Open the chart page →

1,798
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
stdlib@go1.15
1.25.10

Open the chart page →

8,602
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.1
0.53.0
1.25.10

Open the chart page →

1,882
gonicgeek-cookbookVerified publisher6.4.21 of 1See more

gonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.16.4
0.53.0
1.25.10

Open the chart page →

3,525
gotifygeek-cookbookVerified publisher1.2.21 of 1See more

gotify geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.53.0
1.25.10

Open the chart page →

3,132
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
stdlib@go1.15
1.25.10

Open the chart page →

11,069
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
stdlib@go1.18.3
1.25.10

Open the chart page →

9,874
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
stdlib@go1.16.7
1.25.10

Open the chart page →

14,444
maddygeek-cookbookVerified publisher3.2.01 of 1See more

maddy geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
foxcpp/maddy:v0.5.28fa2bd8f6830
golang.org/x/net@v0.0.0-20211011170408-caeb26a5c8c0
stdlib@go1.17.2
0.53.0
1.25.10

Open the chart page →

2,630
minifluxgeek-cookbookVerified publisher5.2.01 of 2See more

miniflux geek-cookbook 5.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
miniflux/miniflux:2.0.36e2fb990dae74
golang.org/x/net@v0.0.0-20210916014120-12bc252f5db8
stdlib@go1.17.8
0.53.0
1.25.10

Open the chart page →

2,430
navidromegeek-cookbookVerified publisher6.4.21 of 1See more

navidrome geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.53.0
1.25.10

Open the chart page →

3,597
nullservgeek-cookbookVerified publisher2.4.21 of 1See more

nullserv geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nullserv:v1.3.00792c7e6d814
stdlib@go1.16.5
1.25.10

Open the chart page →

1,118
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
stdlib@go1.18.4
1.25.10

Open the chart page →

12,276
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
stdlib@go1.15
1.25.10

Open the chart page →

17,805
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.5
0.53.0
1.25.10

Open the chart page →

3,243
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.3
0.53.0
1.25.10

Open the chart page →

19,586
pod-gatewaygeek-cookbookVerified publisher5.6.21 of 2See more

pod-gateway geek-cookbook 5.6.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v3.5.0175512bb3f61
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.3
0.53.0
1.25.10

Open the chart page →

2,355
pod-gateway-settergeek-cookbookVerified publisher1.0.01 of 1See more

pod-gateway-setter geek-cookbook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.4
0.53.0
1.25.10

Open the chart page →

1,642
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.25.10

Open the chart page →

12,000
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
stdlib@go1.18.4
1.25.10

Open the chart page →

10,555
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.25.10

Open the chart page →

7,823
rtsp-to-webgeek-cookbookVerified publisher2.2.21 of 1See more

rtsp-to-web geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.53.0

Open the chart page →

1,467
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
stdlib@go1.18.1
1.25.10

Open the chart page →

3,480
searxgeek-cookbookVerified publisher5.6.23 of 4See more

searx geek-cookbook 5.6.2

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.25.10
dalf/morty:latest248a4849c350
golang.org/x/net@v0.0.0-20220421235706-1d1ef9303861
stdlib@go1.18.2
0.53.0
1.25.10
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

7,478
skypilotgeek-cookbookVerified publisher0.0.13 of 3See more

skypilot geek-cookbook 0.0.1

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
golang.org/x/net@v0.38.0
stdlib@go1.23.5
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

9,065
torrservergeek-cookbookVerified publisher1.2.21 of 1See more

torrserver geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
smailkoz/torrserver:1.0.1117b52d15de8f0
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.5
0.53.0
1.25.10

Open the chart page →

3,165
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
stdlib@go1.18.4
1.25.10

Open the chart page →

12,054
vikunjageek-cookbookVerified publisher6.2.02 of 4See more

vikunja geek-cookbook 6.2.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.5
0.53.0
1.25.10
vikunja/api:0.17.18cba0520bf8c
golang.org/x/net@v0.0.0-20210505024714-0287a6fb4125
stdlib@go1.16.5
0.53.0
1.25.10

Open the chart page →

6,893
webhook-receivergeek-cookbookVerified publisher0.0.11 of 1See more

webhook-receiver geek-cookbook 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,369
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.25.10

Open the chart page →

18,101
asynqmongeneral-helm-chartsVerified publisher0.0.11 of 1See more

asynqmon general-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hibiken/asynqmon:latestac80bcffd2f9
stdlib@go1.18.10
1.25.10

Open the chart page →

752
cbtgeneral-helm-chartsVerified publisher0.0.51 of 1See more

cbt general-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ethpandaops/cbt:latest5377ffb3091a
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

564

Container images carrying it

4,673 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.10
0.53.0
1.25.10
1
loeken/home-assistant:2026.5.14ce6abc553b3
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.53.0
1.25.10
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.6
0.53.0
1.25.10
1
loftsh/jspolicy:0.2.225deb9bd2683
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.53.0
1.25.10
1
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.53.0
1.25.10
1
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.53.0
1.25.10
1
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.18.9
0.53.0
1.25.10
1
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.7
0.53.0
1.25.10
1
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.53.0
1.25.10
1
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.53.0
1.25.10
1
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.53.0
1.25.10
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.1
0.53.0
1.25.10
1
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
1
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
golang.org/x/net@v0.49.0
0.53.0
1
longhornio/longhorn-ui:v1.10.0e60f36161511
stdlib@go1.24.6
1.25.10
1
longhornio/upgrade-responder:v0.2.05875cef29348
stdlib@go1.17.13
1.25.10
1
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.25.10
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
golang.org/x/net@v0.9.0
stdlib@go1.19.6
0.53.0
1.25.10
1
louislam/uptime-kuma:13d632903e6af
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:2.0.24c364ef96aad
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:2.4.091e963bfda56
stdlib@go1.20.5
1.25.10
1
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.53.0
1.25.10
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.53.0
1.25.10
1
lumenvox/admin-portal:7.112310cf52f79
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/archive:7.15114f08ab8ef
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/cloud-init-tools:2.0.07ff037a71c50
stdlib@go1.17.3
1.25.10
1
lumenvox/cloud-init-tools:7.1de940e2ec601
stdlib@go1.26.2
1.25.10
1
lumenvox/cloud-license:2.0.09a69862e1248
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.3
0.53.0
1.25.10
1
lumenvox/configuration:7.182bf01d9ebec
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/deployment:7.1dadac2a74be6
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/file-store:7.138aa8711c9ef
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/license:7.135d0b1ac053e
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/management-api:7.16420a6e7d6c2
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/resource:7.193fd6ff1d62c
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/storage:7.1c961fe78e2ca
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
macropower/osrs_ge_exporter:v0.3c77ab5ea955c
stdlib@go1.21.0
1.25.10
1
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.53.0
1.25.10
1
macropower/wakatime-exporter:0.1.0dbb05debb785
stdlib@go1.14.6
1.25.10
1
maldridge/alertmanager-irc-relay:v0.4.1391de2b76128
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.4
0.53.0
1.25.10
1
manojchaulagain/go-k8s:0.1.0f237b5f637ae
stdlib@go1.20.1
1.25.10
1
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.53.0
1.25.10
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/net@v0.4.0
stdlib@go1.20.2
0.53.0
1.25.10
1
masipcat/wireguard-go:latest696206e5954d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.20.14
0.53.0
1.25.10
1
masipcat/wireguard-go:0.0.20230223769f7bb64694
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.20.14
0.53.0
1.25.10
1
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.53.0
1.25.10
1
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18.1
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.