StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,068
of 17,805 indexed, latest versions
Container images
4,673
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,068 of 17,805 indexed charts deploy, on 4,673 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,520
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,573
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,068 by stars
ChartLatestAffected imagesRadar Score
grafana-samplinggrafana1.1.72 of 2See more

grafana-sampling grafana 1.1.7

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10

Open the chart page →

3,403
mimir-openshift-experimentalgrafana2.1.03 of 4See more

mimir-openshift-experimental grafana 2.1.0

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.8
0.53.0
1.25.10
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.53.0
1.25.10
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.53.0
1.25.10

Open the chart page →

17,808
pyroscope-monitoringgrafana0.1.15 of 6See more

pyroscope-monitoring grafana 0.1.1

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
stdlib@go1.23.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

8,488
snyk-exportergrafana0.1.01 of 1See more

snyk-exporter grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/snyk_exporter:v1.4.1d3c9093401ca
stdlib@go1.21.0
1.25.10

Open the chart page →

669
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

5,323
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,520
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/net@v0.26.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

78,760
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:85211c51171f5
stdlib@go1.24.6
1.25.10

Open the chart page →

5,389
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/net@v0.24.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

1,398
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

14,302
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.53.0
1.25.10

Open the chart page →

2,608
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

2,182
routergroundcover1.12.3754 of 7See more

router groundcover 1.12.375

4 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
stdlib@go1.25.7
1.25.10
quay.io/groundcover/tools:20260719b705e0cbe171
stdlib@go1.24.4
1.25.10

Open the chart page →

6,154
temporalgroundcover1.12.3751 of 2See more

temporal groundcover 1.12.375

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

2,164
mysqlgroundhog2k3.1.41 of 1See more

mysql groundhog2k 3.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
stdlib@go1.24.6
1.25.10

Open the chart page →

463
tailscale-subnet-routergtaylor1.2.11 of 1See more

tailscale-subnet-router gtaylor 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
golang.org/x/net@v0.1.0
stdlib@go1.19.2-ts3fd24dee31
0.53.0
1.25.10

Open the chart page →

1,834
minifluxhajowielandVerified publisher1.0.01 of 1See more

miniflux hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

1,257
hakoniwahakoniwa0.1.01 of 1See more

hakoniwa hakoniwa 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/aplulu/hakoniwa:0.1.0accf0b921388
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

338
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.53.0
1.25.10

Open the chart page →

2,381
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.3
0.53.0
1.25.10

Open the chart page →

4,462
mautrix-signalhalkeye0.3.01 of 2See more

mautrix-signal halkeye 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
signald/signald:0.23.2edbff058278c
stdlib@go1.18.10
1.25.10

Open the chart page →

1,500
thunderdome-planning-pokerhalkeye0.1.11 of 1See more

thunderdome-planning-poker halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

432
whoamihalkeye1.0.11 of 1See more

whoami halkeye 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
containous/whoami:v1.5.07d6a3c8f9147
stdlib@go1.14
1.25.10

Open the chart page →

1,280
hcp-terraform-operatorhashicorpVerified publisher2.12.11 of 2See more

hcp-terraform-operator hashicorp 2.12.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.20.1f5fbfec6a2b2
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

692
hatchet-apihatchetOfficialVerified publisher0.19.01 of 4See more

hatchet-api hatchet 0.19.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

1,726
hatchet-hahatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-ha hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

7,649
hatchet-stackhatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-stack hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

7,649
hawk-envoy-pluginhawk0.1.02 of 4See more

hawk-envoy-plugin hawk 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/collector-go:main7217f1a4fa28
stdlib@go1.17.13
1.25.10
ghcr.io/privacyengineering/consumer:main73f59c032812
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

61,394
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.6
0.53.0
1.25.10

Open the chart page →

3,030
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/net@v0.0.0-20200520182314-0ba52f642ac2
stdlib@go1.14.7
0.53.0
1.25.10

Open the chart page →

2,637
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.25.10

Open the chart page →

6,762
headcniheadcni1.0.101 of 1See more

headcni headcni 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
binrc/headcni:1.0.10e199c334b957
stdlib@go1.22.10
1.25.10

Open the chart page →

724
heliconehelicone0.1.422 of 14See more

helicone helicone 0.1.42

2 of the 14 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
stdlib@go1.19.5
1.25.10
supabase/gotrue:v2.91.07174d551d720
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

72,363
hello-gohello-goVerified publisher0.2.21 of 1See more

hello-go hello-go 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.25.10

Open the chart page →

1,315
hello_worldcharthellohelm0.1.01 of 1See more

hello_worldchart hellohelm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dockerdaemon0901/rolldice:v14e5bfe179c7e
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

863
helm-airportshelm-airports0.1.02 of 7See more

helm-airports helm-airports 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

12,680
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,559
airports-postgreshelm-airports-dan0.1.01 of 1See more

airports-postgres helm-airports-dan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10

Open the chart page →

1,027
helm-airportshelm-airports-dan0.1.02 of 7See more

helm-airports helm-airports-dan 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

5,586
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,559
airports-postgreshelm-airports-postgres0.1.01 of 1See more

airports-postgres helm-airports-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10

Open the chart page →

1,027
pageshelm-chart-repos-camden1.0.01 of 3See more

pages helm-chart-repos-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,261
adguard-homehelm-chart-roeiVerified publisher0.107.591 of 2See more

adguard-home helm-chart-roei 0.107.59

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.595d5e3aef39a8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

761
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
stdlib@go1.23.3
1.25.10

Open the chart page →

4,835
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
iofog/router:2.0.17260cf861479
stdlib@go1.15
1.25.10

Open the chart page →

24,223
logging-stackhelm-charts-alexis-carbillet0.1.05 of 9See more

logging-stack helm-charts-alexis-carbillet 0.1.0

5 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18
0.53.0
1.25.10
grafana/grafana:11.1.0079600c9517b
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.53.0
1.25.10
grafana/loki:2.8.2b1da1d23037e
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.53.0
1.25.10
grafana/loki-canary:2.6.1ab2a2569307b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.53.0
1.25.10

Open the chart page →

12,694
monitoring-stackhelm-charts-alexis-carbillet0.1.09 of 11See more

monitoring-stack helm-charts-alexis-carbillet 0.1.0

9 of the 11 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.53.0
1.25.10
grafana/grafana:latestf772d434e8fa
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.53.0
1.25.10
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.70.0e20576b76ffd
golang.org/x/net@v0.19.0
stdlib@go1.21.4
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.7.04cb2b9019f17
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/net@v0.10.0
stdlib@go1.21.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

10,697
teslamate-apihelm-charts-darox1.0.11 of 1See more

teslamate-api helm-charts-darox 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
tobiasehlert/teslamateapi:1.20.2cf09259ad0ea
golang.org/x/net@v0.37.0
stdlib@go1.24.0
0.53.0
1.25.10

Open the chart page →

1,188
aws-ebs-csi-driverhelm-charts-nr2.17.46 of 6See more

aws-ebs-csi-driver helm-charts-nr 2.17.4

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/net@v0.4.0
stdlib@go1.19.6
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/net@v0.4.0
stdlib@go1.19.8
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes-csi/livenessprobe:v2.9.0-eks-1-25-latest8a305e162caa
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes-csi/node-driver-registrar:v2.7.0-eks-1-25-latestf4345e67df8f
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.53.0
1.25.10

Open the chart page →

6,527
aws-s3-proxyhelm-charts-nr0.1.71 of 1See more

aws-s3-proxy helm-charts-nr 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
pottava/s3-proxy:2.020a0bcb15f76
stdlib@go1.13.7
1.25.10

Open the chart page →

1,323

Container images carrying it

4,673 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.10
0.53.0
1.25.10
1
loeken/home-assistant:2026.5.14ce6abc553b3
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.53.0
1.25.10
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.6
0.53.0
1.25.10
1
loftsh/jspolicy:0.2.225deb9bd2683
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.53.0
1.25.10
1
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.53.0
1.25.10
1
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.53.0
1.25.10
1
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.18.9
0.53.0
1.25.10
1
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.7
0.53.0
1.25.10
1
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.53.0
1.25.10
1
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.53.0
1.25.10
1
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.53.0
1.25.10
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.1
0.53.0
1.25.10
1
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
1
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
golang.org/x/net@v0.49.0
0.53.0
1
longhornio/longhorn-ui:v1.10.0e60f36161511
stdlib@go1.24.6
1.25.10
1
longhornio/upgrade-responder:v0.2.05875cef29348
stdlib@go1.17.13
1.25.10
1
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.25.10
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
golang.org/x/net@v0.9.0
stdlib@go1.19.6
0.53.0
1.25.10
1
louislam/uptime-kuma:13d632903e6af
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:2.0.24c364ef96aad
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:2.4.091e963bfda56
stdlib@go1.20.5
1.25.10
1
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.53.0
1.25.10
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.53.0
1.25.10
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.53.0
1.25.10
1
lumenvox/admin-portal:7.112310cf52f79
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/archive:7.15114f08ab8ef
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/cloud-init-tools:2.0.07ff037a71c50
stdlib@go1.17.3
1.25.10
1
lumenvox/cloud-init-tools:7.1de940e2ec601
stdlib@go1.26.2
1.25.10
1
lumenvox/cloud-license:2.0.09a69862e1248
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.3
0.53.0
1.25.10
1
lumenvox/configuration:7.182bf01d9ebec
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/deployment:7.1dadac2a74be6
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/file-store:7.138aa8711c9ef
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/license:7.135d0b1ac053e
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/management-api:7.16420a6e7d6c2
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/resource:7.193fd6ff1d62c
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
lumenvox/storage:7.1c961fe78e2ca
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
macropower/osrs_ge_exporter:v0.3c77ab5ea955c
stdlib@go1.21.0
1.25.10
1
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.53.0
1.25.10
1
macropower/wakatime-exporter:0.1.0dbb05debb785
stdlib@go1.14.6
1.25.10
1
maldridge/alertmanager-irc-relay:v0.4.1391de2b76128
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.4
0.53.0
1.25.10
1
manojchaulagain/go-k8s:0.1.0f237b5f637ae
stdlib@go1.20.1
1.25.10
1
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.53.0
1.25.10
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/net@v0.4.0
stdlib@go1.20.2
0.53.0
1.25.10
1
masipcat/wireguard-go:latest696206e5954d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.20.14
0.53.0
1.25.10
1
masipcat/wireguard-go:0.0.20230223769f7bb64694
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.20.14
0.53.0
1.25.10
1
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.53.0
1.25.10
1
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18.1
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.