StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,127
of 17,805 indexed, latest versions
Container images
4,734
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,127 of 17,805 indexed charts deploy, on 4,734 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,576
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,613
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,127 by stars
ChartLatestAffected imagesRadar Score
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,279
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,279
casdoor-helm-chartscasdoor4.6.01 of 1See more

casdoor-helm-charts casdoor 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
casbin/casdoor:4.6.0cd30c9fc3d5a
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

1,113
cassandra-webcassandra-web0.1.01 of 1See more

cassandra-web cassandra-web 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ipushc/cassandra-web:latestfa3e0c66c289
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.53.0
1.25.10

Open the chart page →

1,302
castai-evictorcastaiVerified publisher0.35.1451 of 3See more

castai-evictor castai 0.35.145

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.35.64d8c68e8c2bf
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

144
castai-tetragoncastaiVerified publisher0.6.12 of 4See more

castai-tetragon castai 0.6.1

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.19.2
0.53.0
1.25.10
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.18.3
0.53.0
1.25.10

Open the chart page →

4,144
castware-componentscastaiVerified publisher0.4.01 of 1See more

castware-components castai 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

3,452
oci-csi-drivercastaiVerified publisher1.13.81 of 7See more

oci-csi-driver castai 1.13.8

1 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

1,775
temporalcastaiVerified publisher0.54.210 of 14See more

temporal castai 0.54.2

10 of the 14 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.53.0
1.25.10
temporalio/admin-tools:1.26.237e2e33dbd7b
golang.org/x/net@v0.31.0
stdlib@go1.22.5
0.53.0
1.25.10
temporalio/server:1.26.21e2626efcbc1
golang.org/x/net@v0.31.0
stdlib@go1.23.2
0.53.0
1.25.10
temporalio/ui:2.33.05c586a3c8ec5
golang.org/x/net@v0.17.0
stdlib@go1.23.0
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

16,268
catalyst-agentscatalyst-agents0.1.339 of 18See more

catalyst-agents catalyst-agents 0.1.33

9 of the 18 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
golang.org/x/net@v0.37.0
stdlib@go1.23.6
0.53.0
1.25.10
grafana/grafana:13.1.3ab5cb380e3ff
golang.org/x/net@v0.49.0
0.53.0
grafana/loki:3.0.0757b5fadf816
golang.org/x/net@v0.22.0
stdlib@go1.21.9
0.53.0
1.25.10
grafana/loki-canary:3.0.028d7c00588aa
golang.org/x/net@v0.22.0
stdlib@go1.21.9
0.53.0
1.25.10
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/net@v0.24.0
stdlib@go1.21.3
0.53.0
1.25.10
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.25.5
0.53.0
1.25.10
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
golang.org/x/net@v0.52.0
0.53.0
ghcr.io/chaos-mesh/chaos-mesh:v2.8.3bdb31f3121a2
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

17,675
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.10
0.53.0
1.25.10

Open the chart page →

6,391
openldapccowleyVerified publisher2.0.41 of 3See more

openldap ccowley 2.0.4

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.53.0
1.25.10

Open the chart page →

6,222
openldap_exporterccowleyVerified publisher0.1.01 of 1See more

openldap_exporter ccowley 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
stdlib@go1.15.7
1.25.10

Open the chart page →

2,144
kube-ceemsceemsOfficialVerified publisher1.40.01 of 5See more

kube-ceems ceems 1.40.0

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:13.2.1-distroless3600073f45a9
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

668
cerberuscerberusVerified publisher0.16.01 of 1See more

cerberus cerberus 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/tsouza/cerberus:1.20.0ef384585f9a3
stdlib@go1.26.2
1.25.10

Open the chart page →

162
cert-manager-acm-synccert-manager-acm-sync0.7.41 of 1See more

cert-manager-acm-sync cert-manager-acm-sync 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/camilorivera/cert-manager-acm-sync:0.7.489a83796a550
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

132
cert-manager-alidns-webhookcert-manager-alidns-webhook0.1.41 of 1See more

cert-manager-alidns-webhook cert-manager-alidns-webhook 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/crazygit/cert-manager-alidns-webhook:0.1.4976be6506eb6
golang.org/x/net@v0.47.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

1,337
cert-manager-desec-webhookcert-manager-desec-webhook1.0.11 of 1See more

cert-manager-desec-webhook cert-manager-desec-webhook 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

1,424
cert-manager-webhook-abioncert-manager-webhook-abion1.3.21 of 1See more

cert-manager-webhook-abion cert-manager-webhook-abion 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
abiondevelopment/cert-manager-webhook-abion:latestc741988fbd23
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.53.0
1.25.10

Open the chart page →

1,247
cert-manager-webhook-bunnycert-manager-webhook-bunnyVerified publisher1.0.21 of 1See more

cert-manager-webhook-bunny cert-manager-webhook-bunny 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/o0th/cert-manager-webhook-bunny:1.0.2fe7ce555a12d
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10

Open the chart page →

847
cert-manager-webhook-civocert-manager-webhook-civoVerified publisher0.0.0-05b683cb6efdc99135f68af18007954e74f184041 of 1See more

cert-manager-webhook-civo cert-manager-webhook-civo 0.0.0-05b683cb6efdc99135f68af18007954e74f18404

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
okteto/civo-webhook:0.5.357cd51176538
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,286
cert-manager-webhook-hcloud-zonescert-manager-webhook-hcloud-zones0.1.51 of 1See more

cert-manager-webhook-hcloud-zones cert-manager-webhook-hcloud-zones 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/cert-manager-webhook-hcloud-zones:0.1.5a7a846bba3e8
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

422
cert-manager-webhook-infoblox-wapicert-manager-webhook-infoblox-wapiVerified publisher1.5.21 of 1See more

cert-manager-webhook-infoblox-wapi cert-manager-webhook-infoblox-wapi 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

2,353
cert-manager-webhook-namecheapcert-manager-webhook-namecheap0.1.21 of 1See more

cert-manager-webhook-namecheap cert-manager-webhook-namecheap 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10

Open the chart page →

1,767
cert-manager-webhook-pdnscert-manager-webhook-pdns3.2.51 of 1See more

cert-manager-webhook-pdns cert-manager-webhook-pdns 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
zachomedia/cert-manager-webhook-pdns:v2.5.54940e227a39b
golang.org/x/net@v0.50.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

1,088
cert-manager-webhook-regerycert-manager-webhook-regery1.0.01 of 1See more

cert-manager-webhook-regery cert-manager-webhook-regery 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
darioackermann/cert-manager-webhook-regery:latest0d450bc4acc4
golang.org/x/net@v0.26.0
stdlib@go1.22.10
0.53.0
1.25.10

Open the chart page →

897
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.13
0.53.0
1.25.10
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.53.0
1.25.10

Open the chart page →

7,785
getoutlinecfi20171.2.01 of 4See more

getoutline cfi2017 1.2.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.25.10

Open the chart page →

4,529
opencvecfi20170.1.23 of 7See more

opencve cfi2017 0.1.2

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.25.10
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
stdlib@go1.22.10
1.25.10

Open the chart page →

15,688
clechaosnative0.2.73 of 6See more

cle chaosnative 0.2.7

3 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.15
0.53.0
1.25.10
chaosnative/cle-license-module:2.7.062cf6adc355e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.15
0.53.0
1.25.10
chaosnative/cle-server:2.7.0e7bcff4a20c0
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

16,435
charon-relaycharonOfficialVerified publisher0.8.02 of 2See more

charon-relay charon 0.8.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

4,488
dv-podcharonOfficialVerified publisher0.19.12 of 5See more

dv-pod charon 0.19.1

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
obolnetwork/charon-dkg-sidecar:maine263be0a7440
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

7,586
chart-appchart-app0.3.01 of 2See more

chart-app chart-app 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

1,775
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

5,898
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
stdlib@go1.24.6
1.25.10

Open the chart page →

4,112
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
stdlib@go1.17.8
1.25.10

Open the chart page →

4,995
memoscharts-derwitt-devVerified publisher1.4.01 of 1See more

memos charts-derwitt-dev 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
neosmemo/memos:0.30.071a5b4738d1b
stdlib@go1.26.2
1.25.10

Open the chart page →

707
paperless-ngxcharts-derwitt-devVerified publisher2.1.41 of 1See more

paperless-ngx charts-derwitt-dev 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10

Open the chart page →

4,757
yas3pcharts-derwitt-devVerified publisher0.3.11 of 1See more

yas3p charts-derwitt-dev 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
denniswitt/yas3p:0.2.488a235619af6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

738
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
stdlib@go1.20.12
1.25.10

Open the chart page →

2,124
checker-edgechecker-edge1.1.111 of 1See more

checker-edge checker-edge 1.1.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/imcitius/checker-edge:1.1.1174426c1fe00f
golang.org/x/net@v0.50.0
stdlib@go1.25.9
0.53.0
1.25.10

Open the chart page →

812
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

8,419
aws-ecr-tokencheveo-charts0.1.01 of 1See more

aws-ecr-token cheveo-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
huzafach/aws-cli-k8:1.0.06e271d43ea48
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

1,110
pathling-serverchglVerified publisher0.10.111 of 3See more

pathling-server chgl 0.10.11

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

1,230
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.53.0
1.25.10

Open the chart page →

2,877
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.53.0
1.25.10

Open the chart page →

2,829
supersetchoerodon1.0.01 of 3See more

superset choerodon 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

1,440
argocd-metrics-serverchristianhuthVerified publisher1.1.11 of 1See more

argocd-metrics-server christianhuth 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
golang.org/x/net@v0.10.0
stdlib@go1.21.11
0.53.0
1.25.10

Open the chart page →

1,031
cluster-api-visualizerchristianhuthVerified publisher0.6.01 of 1See more

cluster-api-visualizer christianhuth 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.53.0
1.25.10

Open the chart page →

558
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
stdlib@go1.19.4
1.25.10
countly/frontend:25.05.42acbc11499b6
stdlib@go1.19.4
1.25.10

Open the chart page →

7,321

Container images carrying it

4,734 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.14.5
0.53.0
1.25.10
1
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.14.5
0.53.0
1.25.10
1
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.14.5
0.53.0
1.25.10
1
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.11
0.53.0
1.25.10
1
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.13.7
0.53.0
1.25.10
1
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.13.8
0.53.0
1.25.10
1
mesosphere/kubefed:proxyurl4fd8889195fe
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.53.0
1.25.10
1
mesosphere/traefik-forward-auth:3.1.05456581d7b76
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.15
0.53.0
1.25.10
1
metacontrollerio/metacontroller:v2.1.10336993b88e4
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.6
0.53.0
1.25.10
1
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.53.0
1.25.10
1
metacubex/mihomo:v1.19.29e1d7dadaa936
golang.org/x/net@v0.35.0
0.53.0
1
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
golang.org/x/net@v0.0.0-20181213202711-891ebc4b82d6
stdlib@go1.13.15
0.53.0
1.25.10
1
metalmatze/transmission-exporter:0.3.090d6acb6d47d
stdlib@go1.13
1.25.10
1
middlewareeng/middleware:0.3.1747d880812f1
stdlib@go1.17.13
1.25.10
1
mikefarah/yq:4.45.12c100efaca06
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
1
mikefarah/yq:2.4.16fc625c402de
stdlib@go1.13.3
1.25.10
1
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
golang.org/x/net@v0.30.0
stdlib@go1.23.4
0.53.0
1.25.10
1
mikejoh/imagine:0.1.078737d7345f9
golang.org/x/net@v0.26.0
stdlib@go1.23.3
0.53.0
1.25.10
1
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.2
0.53.0
1.25.10
1
milvusdb/etcd:3.5.25-r1fededb2f2d63
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.53.0
1.25.10
1
milvusdb/milvus:v2.2.13a3a55e1c1497
golang.org/x/net@v0.10.0
stdlib@go1.18.3
0.53.0
1.25.10
1
milvusdb/milvus-config-tool:v0.1.12212dfb61401
golang.org/x/net@v0.0.0-20220706163947-c90051bbdb60
stdlib@go1.16.15
0.53.0
1.25.10
1
mindsdb/mindsdb:latest163011c09299
stdlib@go1.20.13
1.25.10
1
miniflux/miniflux:2.2.18a3ca6bbc1f74
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
1
miniflux/miniflux:2.0.36e2fb990dae74
golang.org/x/net@v0.0.0-20210916014120-12bc252f5db8
stdlib@go1.17.8
0.53.0
1.25.10
1
minio/kes:v0.22.255f3aef5803e
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
stdlib@go1.19.3
0.53.0
1.25.10
1
minio/kes:2023-04-03T16-41-28Zf93c2d9088df
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.53.0
1.25.10
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.53.0
1.25.10
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.53.0
1.25.10
1
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.8
0.53.0
1.25.10
1
minio/mc:RELEASE.2024-01-16T16-06-34Z591b097ea2d4
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
minio/mc:RELEASE.2025-04-16T18-13-26Zaead63c77f9d
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.53.0
1.25.10
1
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.5
0.53.0
1.25.10
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.5
0.53.0
1.25.10
1
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
1
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
minio/minio:RELEASE.2024-01-18T22-51-28Z551682a57a94
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.53.0
1.25.10
1
minio/minio:RELEASE.2025-07-23T15-54-02Zd249d1fb6966
golang.org/x/net@v0.39.0
stdlib@go1.24.5
0.53.0
1.25.10
1
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.9
0.53.0
1.25.10
1
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.5
0.53.0
1.25.10
1
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.53.0
1.25.10
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.53.0
1.25.10
1
minio/operator:v5.0.9170b154d2c61
golang.org/x/net@v0.13.0
stdlib@go1.21.1
0.53.0
1.25.10
1
minio/operator:v4.1.02adc5be088f5
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.16.3
0.53.0
1.25.10
1
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.13.12
0.53.0
1.25.10
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.13.9
0.53.0
1.25.10
1
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.13.9
0.53.0
1.25.10
1
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.13.9
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.