StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,058
of 17,790 indexed, latest versions
Container images
4,694
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,058 of 17,790 indexed charts deploy, on 4,694 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,539
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,589
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,058 by stars
ChartLatestAffected imagesRadar Score
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.25.10

Open the chart page →

30,217
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
golang.org/x/net@v0.33.0
stdlib@go1.24.4
0.53.0
1.25.10
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
golang.org/x/net@v0.33.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

3,956
eg-universal-agent-operatoreg-universal-agent-operatorVerified publisher0.0.51 of 1See more

eg-universal-agent-operator eg-universal-agent-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

573
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,519
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
golang.org/x/net@v0.30.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

902
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.10

Open the chart page →

8,049
postgresqleks-storageclass0.1.01 of 1See more

postgresql eks-storageclass 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.10

Open the chart page →

1,649
elastic-agentelasticVerified publisher9.5.41 of 2See more

elastic-agent elastic 9.5.4

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

760
kube-state-metricselasticVerified publisher6.1.01 of 1See more

kube-state-metrics elastic 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

760
seafileeleksbai0.1.12 of 3See more

seafile eleksbai 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.692e50059ea0a
stdlib@go1.24.6
1.25.10
seafileltd/seafile-mc:9.0.106693911bcc40
stdlib@go1.19
1.25.10

Open the chart page →

25,263
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
stdlib@go1.23.12
1.25.10

Open the chart page →

2,968
elsaelsa0.1.01 of 4See more

elsa elsa 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/stakater/reloader:v1.4.4a571c5b32c0f
golang.org/x/net@v0.39.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

398
rabbitmqemberstackVerified publisher1.0.211 of 1See more

rabbitmq emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/rabbitmq:managementffd1b50c522a
stdlib@go1.22.2
1.25.10

Open the chart page →

1,045
emissary-ingressemissary-ingress4.1.01 of 1See more

emissary-ingress emissary-ingress 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

955
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10

Open the chart page →

2,837
parrot-mirroremmas-chartsVerified publisher1.0.01 of 1See more

parrot-mirror emmas-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

2,243
cost-reportempathyco0.7.81 of 1See more

cost-report empathyco 0.7.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
empathyco/cost-report:0.0.124f1e26eaacbf
stdlib@go1.15.15
1.25.10

Open the chart page →

1,167
deadman-switchempathyco0.0.21 of 1See more

deadman-switch empathyco 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
stdlib@go1.16.3
1.25.10

Open the chart page →

1,258
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.25.10

Open the chart page →

10,610
yace-exporterempathyco0.1.01 of 1See more

yace-exporter empathyco 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
stdlib@go1.17.3
1.25.10

Open the chart page →

1,642
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
stdlib@go1.19.10
0.53.0
1.25.10

Open the chart page →

1,329
kube-ecp-stackemqx-operator2.5.111 of 16See more

kube-ecp-stack emqx-operator 2.5.1

11 of the 16 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
golang.org/x/net@v0.23.0
stdlib@go1.23.3
0.53.0
1.25.10
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/net@v0.30.0
stdlib@go1.22.0
0.53.0
1.25.10
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.53.0
1.25.10
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.53.0
1.25.10
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.1e2dc5623bcdd
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.53.0
1.25.10

Open the chart page →

23,813
cnpg-monitoringenixVerified publisher0.3.01 of 1See more

cnpg-monitoring enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

824
kube-packetloss-exporterenixVerified publisher0.2.12 of 2See more

kube-packetloss-exporter enix 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.53.0
1.25.10
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

6,165
mariadb-operator-monitoringenixVerified publisher0.1.01 of 1See more

mariadb-operator-monitoring enix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

738
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10

Open the chart page →

3,963
network-exporterenixVerified publisher0.3.01 of 1See more

network-exporter enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
syepes/network_exporter:1.8.000af1691570e
golang.org/x/net@v0.39.0
stdlib@go1.25.1
0.53.0
1.25.10

Open the chart page →

1,372
zfs-exporterenixVerified publisher2.2.01 of 1See more

zfs-exporter enix 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/enix/zfs-exporter:2.3.1223b053f1cbd0
golang.org/x/net@v0.47.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

977
ai-gateway-helmenvoy-ai-gateway0.0.0-003ab39f36923b5d40609a601e2951b73f6318fb1 of 1See more

ai-gateway-helm envoy-ai-gateway 0.0.0-003ab39f36923b5d40609a601e2951b73f6318fb

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

863
eoapi-supporteoapiVerified publisher0.1.76 of 7See more

eoapi-support eoapi 0.1.7

6 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:10.3.38640e5038e83
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

8,667
backendeoc-chartsVerified publisher0.1.01 of 1See more

backend eoc-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/http-echo:latestfcb75f691c8b
stdlib@go1.21.1
1.25.10

Open the chart page →

550
databaseeoc-chartsVerified publisher0.1.01 of 1See more

database eoc-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:14-alpine727876d27466
stdlib@go1.24.6
1.25.10

Open the chart page →

494
mariadbeoc-chartsVerified publisher0.3.141 of 1See more

mariadb eoc-charts 0.3.14

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.25.10

Open the chart page →

5,153
umbrella-appeoc-chartsVerified publisher0.1.02 of 3See more

umbrella-app eoc-charts 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/http-echo:latestfcb75f691c8b
stdlib@go1.21.1
1.25.10
library/postgres:14-alpine727876d27466
stdlib@go1.24.6
1.25.10

Open the chart page →

1,078
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.25.10
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.25.10

Open the chart page →

27,361
eoloPlanteolo-plannerVerified publisher0.1.03 of 7See more

eoloPlant eolo-planner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.53.0
1.25.10
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

27,702
eoloplannereoloplannerVerified publisher0.1.03 of 7See more

eoloplanner eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

32,372
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.03 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.53.0
1.25.10
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

27,702
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.25.10
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.25.10

Open the chart page →

27,327
eoloplannereoloplanner-molynx-gat0.1.03 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

28,549
eolo-plannereolo-planner-repo0.1.03 of 7See more

eolo-planner eolo-planner-repo 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

27,197
eoloplanteoloplant1.0.03 of 7See more

eoloplant eoloplant 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.53.0
1.25.10
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

27,702
eoloplantseoloplants-urjcVerified publisher0.1.03 of 7See more

eoloplants eoloplants-urjc 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

27,822
servereoloserverVerified publisher0.1.03 of 7See more

server eoloserver 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

32,372
download-from-github-repoeosc-lot-1Verified publisher0.1.01 of 2See more

download-from-github-repo eosc-lot-1 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
golang.org/x/net@v0.15.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

992
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/git:v2.49.1c0280cf95723
golang.org/x/net@v0.45.0
stdlib@go1.24.8
0.53.0
1.25.10

Open the chart page →

9,402
mariadbeosc-lot-1Verified publisher0.2.01 of 2See more

mariadb eosc-lot-1 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
stdlib@go1.24.6
1.25.10

Open the chart page →

2,458
mariadb-backupeosc-lot-1Verified publisher0.5.01 of 2See more

mariadb-backup eosc-lot-1 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
stdlib@go1.24.6
1.25.10

Open the chart page →

2,458
mariadb-run-scripteosc-lot-1Verified publisher0.3.01 of 1See more

mariadb-run-script eosc-lot-1 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
stdlib@go1.24.6
1.25.10

Open the chart page →

2,458
postgresql-backupeosc-lot-1Verified publisher0.4.21 of 2See more

postgresql-backup eosc-lot-1 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.25.10

Open the chart page →

1,467

Container images carrying it

4,694 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
3
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.53.0
1.25.10
3
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.25.10
3
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.25.10
3
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
3
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.25.10
3
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.25.10
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10
3
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.25.10
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.53.0
1.25.10
3
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.25.10
3
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.53.0
1.25.10
3
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.53.0
1.25.10
3
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.25.10
3
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/net@v0.27.0
stdlib@go1.23.4
0.53.0
1.25.10
3
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.25.10
3
gcr.io/trillian-opensource-ci/db_server2a685a38dd01
stdlib@go1.18.2
1.25.10
3
ghcr.io/appscode/sidekick:v0.0.15d1036b07e348
golang.org/x/net@v0.47.0
0.53.0
3
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
3
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.53.0
1.25.10
3
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/net@v0.50.0
stdlib@go1.25.6
0.53.0
1.25.10
3
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.25.10
3
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.53.0
1.25.10
3
ghcr.io/kuberocketci/krci-cache:0.3.05f6cd61e6da6
stdlib@go1.25.8
1.25.10
3
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
golang.org/x/net@v0.46.0
stdlib@go1.25.0
0.53.0
1.25.10
3
ghcr.io/sigstore/scaffolding/createdb3cee6c78973b
golang.org/x/net@v0.46.0
stdlib@go1.25.0
0.53.0
1.25.10
3
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
golang.org/x/net@v0.46.0
stdlib@go1.25.0
0.53.0
1.25.10
3
ghcr.io/sigstore/scaffolding/trillian_log_server5a878e4e4f03
stdlib@go1.26.0
1.25.10
3
ghcr.io/sigstore/scaffolding/trillian_log_signer28c5ff40963f
stdlib@go1.26.0
1.25.10
3
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/net@v0.47.0
0.53.0
3
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.10
3
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.7
0.53.0
1.25.10
3
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.53.0
1.25.10
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.53.0
1.25.10
3
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
stdlib@go1.19.8
0.53.0
1.25.10
3
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.53.0
1.25.10
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.17.13
0.53.0
1.25.10
3
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.53.0
1.25.10
3
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.53.0
1.25.10
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.53.0
1.25.10
3
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.25.10
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
golang.org/x/net@v0.48.0
stdlib@go1.24.0
0.53.0
1.25.10
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.53.0
1.25.10
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.53.0
1.25.10
3
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.6
0.53.0
1.25.10
3
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.53.0
1.25.10
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.53.0
1.25.10
3
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.25.10
3

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.