StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,051
of 17,803 indexed, latest versions
Container images
4,685
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,051 of 17,803 indexed charts deploy, on 4,685 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,529
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,580
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,051 by stars
ChartLatestAffected imagesRadar Score
openstack-kamaji-clusteropenstack-kamaji-clusterVerified publisher0.2.41 of 1See more

openstack-kamaji-cluster openstack-kamaji-cluster 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
golang.org/x/net@v0.38.0
stdlib@go1.24.7
0.53.0
1.25.10

Open the chart page →

770
opentelemetry-demoopentelemetry-helmOfficialVerified publisher0.41.23 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.2

3 of the 34 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:13.1.0121a7a9ece6d
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.10
ghcr.io/open-feature/flagd:v0.16.032234e63c1d0
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

23,436
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
stdlib@go1.23.7
1.25.10

Open the chart page →

6,991
opikopikOfficialVerified publisher2.2.685 of 13See more

opik opik 2.2.68

5 of the 13 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.0862d86046bbc
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.25.10
library/zookeeper:3.9.4dfa9ba46d14b
stdlib@go1.18.1
1.25.10
ghcr.io/comet-ml/opik/opik-python-backend:2.2.68a6ac6318799c
golang.org/x/net@v0.35.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

14,882
opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest26da43bb5b66
golang.org/x/net@v0.39.0
stdlib@go1.24.13
0.53.0
1.25.10
shaowenchen/ops-server:latest315444f703f4
golang.org/x/net@v0.39.0
stdlib@go1.24.9
0.53.0
1.25.10

Open the chart page →

86,022
orbitalregorbitalregVerified publisher0.3.02 of 4See more

orbitalreg orbitalreg 0.3.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10
orbitalreg/orbitalreg-api:0.1.045f2620337af
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.53.0
1.25.10

Open the chart page →

2,585
kubernetes-dashboard-proxyosc0.7.23 of 4See more

kubernetes-dashboard-proxy osc 0.7.2

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.7.02e500d29e9d5
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.53.0
1.25.10
kubernetesui/metrics-scraper:v1.0.876049887f07a
golang.org/x/net@v0.0.0-20220524220425-1d687d428aca
stdlib@go1.18.2
0.53.0
1.25.10
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16
0.53.0
1.25.10

Open the chart page →

6,012
osc-bsu-csi-driverosc-bsu-csi-driverVerified publisher2.2.03 of 6See more

osc-bsu-csi-driver osc-bsu-csi-driver 2.2.0

3 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

2,391
hlf-caowkin2.1.02 of 2See more

hlf-ca owkin 2.1.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.7
0.53.0
1.25.10
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

3,431
hlf-ordowkin3.1.01 of 1See more

hlf-ord owkin 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hyperledger/fabric-orderer:2.2.137294e05209b
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.4
0.53.0
1.25.10

Open the chart page →

3,357
hlf-peerowkin5.1.01 of 1See more

hlf-peer owkin 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hyperledger/fabric-peer:2.2.1bf4995c86af6
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.4
0.53.0
1.25.10

Open the chart page →

3,695
prometheus-cachethqoxyno-zetaVerified publisher1.1.11 of 1See more

prometheus-cachethq oxyno-zeta 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
oxynozeta/prometheus-cachethq:1.1.131f11669d597
stdlib@go1.15.1
1.25.10

Open the chart page →

1,714
ngrok-operatorpaganuzzi0.0.21 of 1See more

ngrok-operator paganuzzi 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/paganuzzi/ngrokoperator:latest5a10cd095699
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.12
0.53.0
1.25.10

Open the chart page →

2,811
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
stdlib@go1.24.4
1.25.10

Open the chart page →

8,644
pardus-nginx-nodeportpardus-charts0.5.01 of 1See more

pardus-nginx-nodeport pardus-charts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
uderelier19/pardus-nginx:25-nodeport8ab640b44e3f
stdlib@go1.24.4
1.25.10

Open the chart page →

320
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

6,961
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.53.0
1.25.10
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.21.9
0.53.0
1.25.10

Open the chart page →

7,858
pbuf-registrypbuf-registry0.4.12 of 2See more

pbuf-registry pbuf-registry 0.4.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.1-alpine3.2144d837eb4c2e
stdlib@go1.24.6
1.25.10
ghcr.io/pbufio/registry:v0.4.177a36c035b4b
golang.org/x/net@v0.45.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

2,092
pdf-editor-helmpdf-editor-web1.0.02 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
stdlib@go1.18.7
1.25.10
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
stdlib@go1.18.7
1.25.10

Open the chart page →

4,212
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
stdlib@go1.24.4
1.25.10

Open the chart page →

7,198
periscopeperiscopeVerified publisher1.1.61 of 1See more

periscope periscope 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
stdlib@go1.26.2
1.25.10

Open the chart page →

862
pgbouncerpgbouncer-helm0.6.01 of 2See more

pgbouncer pgbouncer-helm 0.6.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
stdlib@go1.23.7
1.25.10

Open the chart page →

471
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.53.0
1.25.10

Open the chart page →

7,271
chadbotphntom0.2.31 of 1See more

chadbot phntom 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
phntom/chadbot:0.2.397c28e4178ad
golang.org/x/net@v0.11.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

1,104
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
golang.org/x/net@v0.10.0
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

2,948
phonebook-chartphonebook-chart0.1.01 of 3See more

phonebook-chart phonebook-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10

Open the chart page →

3,032
phpipamphpipam-helmVerified publisher1.0.121 of 3See more

phpipam phpipam-helm 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.25.10

Open the chart page →

3,778
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.15.8
0.53.0
1.25.10

Open the chart page →

2,121
matomopockostVerified publisher1.3.01 of 3See more

matomo pockost 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:12.3.3dd9b303aed4f
stdlib@go1.24.6
1.25.10

Open the chart page →

5,272
podtracepodtraceOfficialVerified publisher0.14.81 of 2See more

podtrace podtrace 0.14.8

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.37.0b421c2e9419e
golang.org/x/net@v0.38.0
stdlib@go1.24.0
0.53.0
1.25.10

Open the chart page →

624
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.53.0
1.25.10

Open the chart page →

2,213
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.25.10

Open the chart page →

32,151
postfix-exporterpostfix-exporterVerified publisher0.2.01 of 1See more

postfix-exporter postfix-exporter 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/hsn723/postfix_exporter:0.20.0b7da7c554018
stdlib@go1.26.2
1.25.10

Open the chart page →

419
postgres-backuppostgres-backup0.3.02 of 2See more

postgres-backup postgres-backup 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.25.10
nerzhul/mc-arm64:2020.10.034215df511f31
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

5,470
postgresqlpostgresqlVerified publisher0.3.172 of 2See more

postgresql postgresql 0.3.17

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.6-alpined3e1620b530c
stdlib@go1.24.6
1.25.10
pgautoupgrade/pgautoupgrade:18-alpine48b448825656
stdlib@go1.24.6
1.25.10

Open the chart page →

1,270
postgresqlpostgresql-helm0.1.21 of 1See more

postgresql postgresql-helm 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.10

Open the chart page →

1,686
rethinkdbpozetron1.1.91 of 1See more

rethinkdb pozetron 1.1.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.9
0.53.0
1.25.10

Open the chart page →

2,913
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

2,517
home-assistantpree-helm-chartsVerified publisher1.80.01 of 1See more

home-assistant pree-helm-charts 1.80.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.53.0
1.25.10

Open the chart page →

2,145
preparrpreparr0.19.71 of 6See more

preparr preparr 0.19.7

1 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
stdlib@go1.24.6
1.25.10

Open the chart page →

1,127
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.25.10

Open the chart page →

5,541
prometheus-druid-exporterprometheus-communityVerified publisher1.2.01 of 1See more

prometheus-druid-exporter prometheus-community 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/opstree/druid-exporter:v0.119f01c9c5c2e3
stdlib@go1.15.15
1.25.10

Open the chart page →

1,179
prometheus-pingmesh-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-pingmesh-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:v1.2.2c82de0272da0
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.53.0
1.25.10

Open the chart page →

855
prometheus-sql-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-sql-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/justwatchcom/sql_exporter:v0.8c4b1d3d0f052
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

1,351
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.25.10
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.25.10
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.53.0
1.25.10

Open the chart page →

9,950
operatorpunchplatform8.1.131 of 1See more

operator punchplatform 8.1.13

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
golang.org/x/net@v0.20.0
stdlib@go1.22.0
0.53.0
1.25.10

Open the chart page →

718
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
stdlib@go1.19
0.53.0
1.25.10

Open the chart page →

1,662
go-kube-downscalerpy-kube-downscalerVerified publisher1.3.41 of 1See more

go-kube-downscaler py-kube-downscaler 1.3.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/caas-team/gokubedownscaler:1.3.4cea3dd2f1312
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

234
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.53.0
1.25.10

Open the chart page →

51,893
qt-vaultqt-vaultVerified publisher0.1.21 of 1See more

qt-vault qt-vault 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/mcman2017/qt-vault:v0.1.2852edf54c850
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.53.0
1.25.10

Open the chart page →

305

Container images carrying it

4,685 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.8
0.53.0
1.25.10
1
minio/mc:RELEASE.2024-01-16T16-06-34Z591b097ea2d4
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
minio/mc:RELEASE.2025-04-16T18-13-26Zaead63c77f9d
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.53.0
1.25.10
1
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.5
0.53.0
1.25.10
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.5
0.53.0
1.25.10
1
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
1
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
minio/minio:RELEASE.2024-01-18T22-51-28Z551682a57a94
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.53.0
1.25.10
1
minio/minio:RELEASE.2025-07-23T15-54-02Zd249d1fb6966
golang.org/x/net@v0.39.0
stdlib@go1.24.5
0.53.0
1.25.10
1
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.9
0.53.0
1.25.10
1
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.5
0.53.0
1.25.10
1
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.53.0
1.25.10
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.53.0
1.25.10
1
minio/operator:v5.0.9170b154d2c61
golang.org/x/net@v0.13.0
stdlib@go1.21.1
0.53.0
1.25.10
1
minio/operator:v4.1.02adc5be088f5
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.16.3
0.53.0
1.25.10
1
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.13.12
0.53.0
1.25.10
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.13.9
0.53.0
1.25.10
1
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.13.9
0.53.0
1.25.10
1
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.13.9
0.53.0
1.25.10
1
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.9
0.53.0
1.25.10
1
mirrorgitlabcontainers/kubectl:1.13.1299931bd06b41
stdlib@go1.13.3
1.25.10
1
mitre/vulcan:latest2bc4dfb8150f
stdlib@go1.25.5
1.25.10
1
moby/buildkit:master-rootless07115a67cd22
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
1
moby/buildkit:v0.33.06c2fa84a6b61
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.53.0
1.25.10
1
moby/buildkit:v0.33.0-rootless80b15f0735e8
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.53.0
1.25.10
1
moby/buildkit:v0.31.0a095b3d11ce1
golang.org/x/net@v0.35.0
stdlib@go1.25.7
0.53.0
1.25.10
1
moby/buildkit:masterbc964521ee58
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
1
moby/buildkit:v0.10.0c2aeafaed434
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.8
0.53.0
1.25.10
1
moikot/basic-git-server:0.0.20d941bd30ffa
stdlib@go1.14.9
1.25.10
1
moikot/smartthings-metrics:0.1.08625f53aa9b7
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.13
0.53.0
1.25.10
1
moikot/smartthings-metrics:feat-log-detailsfb8565140106
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.15
0.53.0
1.25.10
1
mongodb/mongodb-atlas-local:8925c3d34f0c6
stdlib@go1.25.9
1.25.10
1
monitoror/monitoror:44b88edcf51ff
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.6
0.53.0
1.25.10
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
stdlib@go1.20.12
1.25.10
1
moul/sshportal:v1.19.3332b603727c3
stdlib@go1.17.6
1.25.10
1
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.15.13
0.53.0
1.25.10
1
mrnim94/metrics-server-exporter:v2.4.086c4807a4bca
golang.org/x/net@v0.47.0
0.53.0
1
muonsoft/openapi-mock:latestc9afe1295484
stdlib@go1.20.2
1.25.10
1
murtazashah46/helmfile:latest4d11726cf803
golang.org/x/net@v0.5.0
stdlib@go1.22.8
0.53.0
1.25.10
1
mvisonneau/tailscale:v1.68.1fc45ad8abf10
golang.org/x/net@v0.24.0
stdlib@go1.22.4
0.53.0
1.25.10
1
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.1
0.53.0
1.25.10
1
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
golang.org/x/net@v0.7.0
stdlib@go1.19.13
0.53.0
1.25.10
1
n8nio/n8n:1.86.08b39ed5a2de9
stdlib@go1.24.0
1.25.10
1
n8nio/n8n:1.115.1ed16e560c40e
stdlib@go1.24.6
1.25.10
1
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.25.10
1
nadoo/glider:0.1638aadefbd607
golang.org/x/net@v0.28.0
stdlib@go1.20.14
0.53.0
1.25.10
1
nathanfirmo/dbgate:latest6b0487e6e987
stdlib@go1.24.5
1.25.10
1
natsio/nats-box:0.14.31cc420186664
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.