StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,134
of 17,821 indexed, latest versions
Container images
4,756
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,134 of 17,821 indexed charts deploy, on 4,756 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,602
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,624
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,134 by stars
ChartLatestAffected imagesRadar Score
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.53.0
1.25.10

Open the chart page →

4,912
picoclawloafoe0.1.11 of 2See more

picoclaw loafoe 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loafoe/picoclaw:v0.0.1942e1b6862913
stdlib@go1.26.2
1.25.10

Open the chart page →

479
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

2,126
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.53.0
1.25.10

Open the chart page →

2,038
weather-app-chartlocal-weatherapp0.1.02 of 4See more

weather-app-chart local-weatherapp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:8.0.36-debian-11-r38aad73aa0c6d
stdlib@go1.21.6
1.25.10
youssef11gaber10/deployment-auth-go:latest6597b26959d2
golang.org/x/net@v0.10.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

5,915
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,521
locust-pluginslocust-pluginsVerified publisher0.0.42 of 3See more

locust-plugins locust-plugins 0.0.4

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10
sky5367/locust-plugins-timescale:latestd3150f201471
stdlib@go1.18.7
1.25.10

Open the chart page →

7,581
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

33,925
central-hostpath-mapperloftVerified publisher0.2.91 of 1See more

central-hostpath-mapper loft 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
golang.org/x/net@v0.26.0
stdlib@go1.23.2
0.53.0
1.25.10

Open the chart page →

931
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/net@v0.21.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

3,242
devspace-cloudloftVerified publisher0.3.32 of 8See more

devspace-cloud loft 0.3.3

2 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.53.0
1.25.10
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.10

Open the chart page →

9,893
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.7
0.53.0
1.25.10

Open the chart page →

3,096
license-serverloftVerified publisher0.6.01 of 1See more

license-server loft 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
golang.org/x/net@v0.47.0
stdlib@go1.24.3
0.53.0
1.25.10

Open the chart page →

804
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/net@v0.6.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

2,460
loft-direct-cluster-endpointloftVerified publisher1.14.01 of 1See more

loft-direct-cluster-endpoint loft 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

3,120
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.53.0
1.25.10

Open the chart page →

3,242
vcluster-headloftVerified publisher0.0.0-035ec6e1 of 2See more

vcluster-head loft 0.0.0-035ec6e

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/kubernetes:v1.35.090097a08b87c
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.53.0
1.25.10

Open the chart page →

1,309
vcluster-hpmloftVerified publisher0.2.71 of 1See more

vcluster-hpm loft 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-hpm:0.2.7f65f6810ea23
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

841
vcluster-proloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
stdlib@go1.19.4
0.53.0
1.25.10
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

5,144
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.104 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.53.0
1.25.10
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.53.0
1.25.10
public.ecr.aws/eks-distro/kubernetes/kube-apiserver:v1.24.9-eks-1-24-772e06b605692
stdlib@go1.18.9
1.25.10
public.ecr.aws/eks-distro/kubernetes/kube-controller-manager:v1.24.9-eks-1-24-7eaea8c230432
stdlib@go1.18.9
1.25.10

Open the chart page →

5,986
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.53.0
1.25.10
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

5,828
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.104 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.53.0
1.25.10
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.53.0
1.25.10
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.53.0
1.25.10
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.53.0
1.25.10

Open the chart page →

8,286
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.53.0
1.25.10

Open the chart page →

2,994
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
golang.org/x/net@v0.46.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

2,546
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,504
nightingalelogic3579Verified publisher0.3.13 of 6See more

nightingale logic3579 0.3.1

3 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.53.0
1.25.10
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.53.0
1.25.10

Open the chart page →

9,172
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,511
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
stdlib@go1.22.5
1.25.10

Open the chart page →

6,610
apica-ascentlogiqai2.0.47 of 19See more

apica-ascent logiqai 2.0.4

7 of the 19 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.53.0
1.25.10
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.18.9
0.53.0
1.25.10
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.7
0.53.0
1.25.10
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.53.0
1.25.10
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.53.0
1.25.10
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.8
0.53.0
1.25.10
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.9
0.53.0
1.25.10

Open the chart page →

23,806
logtidelogtideVerified publisher2.1.141 of 4See more

logtide logtide 2.1.14

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg156343bdc87ca1
stdlib@go1.24.6
1.25.10

Open the chart page →

2,968
loki-proxyloki-proxyVerified publisher0.4.11 of 1See more

loki-proxy loki-proxy 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/peak-scale/observability-tenancy/loki-proxy:0.4.1548e962d0061
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

788
corednslovemew67Verified publisher1.36.01 of 1See more

coredns lovemew67 1.36.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
coredns/coredns:1.11.39caabbf6238b
golang.org/x/net@v0.25.0
stdlib@go1.21.11
0.53.0
1.25.10

Open the chart page →

1,183
oncall-hobbylovemew67Verified publisher0.0.51 of 2See more

oncall-hobby lovemew67 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:7.0.15352c1fdadc91
stdlib@go1.18.2
1.25.10

Open the chart page →

5,909
loxilbloxilbVerified publisher0.1.01 of 2See more

loxilb loxilb 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.53.0
1.25.10

Open the chart page →

4,563
lsdisklsdiskVerified publisher2.0.73 of 4See more

lsdisk lsdisk 2.0.7

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
golang.org/x/net@v0.25.0
stdlib@go1.22.5
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

5,084
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.53.0
1.25.10

Open the chart page →

2,350
fireflylsst-sqre0.3.71 of 2See more

firefly lsst-sqre 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:5fc5ecd863862
stdlib@go1.16.7
1.25.10

Open the chart page →

1,732
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.17.2
0.53.0
1.25.10
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.53.0
1.25.10

Open the chart page →

9,351
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.5
0.53.0
1.25.10

Open the chart page →

6,675
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

3,774
xteveluiscajl0.1.61 of 1See more

xteve luiscajl 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dnsforge/xteve:latest4d9a685c8c28
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.16.2
0.53.0
1.25.10

Open the chart page →

4,316
ratelimitlumiumcoVerified publisher0.0.41 of 2See more

ratelimit lumiumco 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

1,165
qbittorrentm0nsterrr-qbittorrentVerified publisher7.1.21 of 2See more

qbittorrent m0nsterrr-qbittorrent 7.1.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:0.2.066c8d5c270eb
golang.org/x/net@v0.49.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

764
kube-benchm9sweeperVerified publisher1.6.01 of 1See more

kube-bench m9sweeper 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.6.176672264accce
stdlib@go1.20.4
1.25.10

Open the chart page →

1,400
m9sweeperm9sweeperVerified publisher1.6.02 of 6See more

m9sweeper m9sweeper 1.6.0

2 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubesec/kubesec:v2.13.0c0f3b0673578
stdlib@go1.19.7
1.25.10
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

9,858
magistralamagistrala-devopsVerified publisher0.16.214 of 42See more

magistrala magistrala-devops 0.16.2

14 of the 42 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.25.10
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
library/nats:2.10.17-alpineb7752304692b
stdlib@go1.22.4
1.25.10
natsio/nats-box:0.14.31cc420186664
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
natsio/nats-server-config-reloader:0.15.05b21830a9e9d
stdlib@go1.22.4
1.25.10
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
timescale/timescaledb:latest-pg12645fd9e92d76
stdlib@go1.18.7
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

24,771
docker-mailservermailserverVerified publisher0.2.654 of 9See more

docker-mailserver mailserver 0.2.65

4 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jeboehm/mailserver-filter:5.0.92e756949e537d
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10
jeboehm/mailserver-mta:5.0.925fb2f31c940d
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10
jeboehm/mailserver-web:5.0.929da13edf5aa8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

11,554
demoshopmakaira2.4.01 of 4See more

demoshop makaira 2.4.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

4,665
mangadev-hello-worldmangadev0.3.01 of 1See more

mangadev-hello-world mangadev 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wagnermanganelli164/webserver-hello-world:0.3.0d4ef27a4f180
stdlib@go1.22.5
1.25.10

Open the chart page →

864
novosgamarcusrepo0.1.12 of 2See more

novosga marcusrepo 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.25.10
novosga/novosga:latest34b9acbe6e51
stdlib@go1.26.2
1.25.10

Open the chart page →

3,739

Container images carrying it

4,756 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17
0.53.0
1.25.10
1
oxynozeta/prometheus-cachethq:1.1.131f11669d597
stdlib@go1.15.1
1.25.10
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.25.10
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.25.10
1
pannoi/kollektor:1.0.59559617788fc
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.53.0
1.25.10
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
stdlib@go1.14.4
1.25.10
1
percona/mongodb_exporter:0.53.00214e482b2cd
stdlib@go1.26.2
1.25.10
1
percona/percona-postgresql-operator:2.8.06cce2698d3f5
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.53.0
1.25.10
1
percona/percona-server-mongodb-operator:1.20.1d09453ce7886
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.53.0
1.25.10
1
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
stdlib@go1.19.9
1.25.10
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
1
peterdavehello/tor-socks-proxy:latest0cc12d36d312
golang.org/x/net@v0.35.0
stdlib@go1.26.2
0.53.0
1.25.10
1
pgsharding/spqr-router:nightly-2.8.3-1839-f66048d84734940216d3
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10
1
pgvector/pgvector:pg17cf134a767f47
stdlib@go1.24.6
1.25.10
1
phntom/chadbot:0.2.397c28e4178ad
golang.org/x/net@v0.11.0
stdlib@go1.21.5
0.53.0
1.25.10
1
phntom/chartmuseum:v0.16.053883b65d9b7
golang.org/x/net@v0.10.0
stdlib@go1.19.3
0.53.0
1.25.10
1
phntom/chartmuseum:v0.15.29242b4df9e65
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.18.5
0.53.0
1.25.10
1
phntom/codimd:2.4.31b9aafbb62e6
stdlib@go1.16
1.25.10
1
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.53.0
1.25.10
1
phntom/goalert:0.0.298ca4df55499b
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/net@v0.17.0
stdlib@go1.20.7
0.53.0
1.25.10
1
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.16.2
0.53.0
1.25.10
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
golang.org/x/net@v0.0.0-20221012135044-0b7e1fb9d458
stdlib@go1.19.2
0.53.0
1.25.10
1
photoprism/photoprism:231128-ce284de9cc4f9c
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.53.0
1.25.10
1
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.3
0.53.0
1.25.10
1
photoprism/photoprism:251130db16ee6b1ba3
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10
1
photoprism/photoprism:240711-cefc6fd632ca74
golang.org/x/net@v0.27.0
stdlib@go1.22.5
0.53.0
1.25.10
1
piblokto/backlokto-operator:v0.0.20963cda71e393
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.53.0
1.25.10
1
pinclr/v2ray-proxy:latestf37f250b7091
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.53.0
1.25.10
1
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.53.0
1.25.10
1
platform9community/api-gateway:latest40a4970de568
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.53.0
1.25.10
1
platform9community/customers-service:latest2089811e5cc6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.53.0
1.25.10
1
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.11
0.53.0
1.25.10
1
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.53.0
1.25.10
1
platzio/backend:v0.6.5d5e5972f344b
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.53.0
1.25.10
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
stdlib@go1.21.2
1.25.10
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.12
0.53.0
1.25.10
1
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
stdlib@go1.13.10
1.25.10
1
pnnlmiscscripts/pixiecore:1.0.1-1c6f17741a0d7
golang.org/x/net@v0.7.0
stdlib@go1.24.1
0.53.0
1.25.10
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
golang.org/x/net@v0.48.0
stdlib@go1.19.13
0.53.0
1.25.10
1
polyaxon/training-operator:2.1.0b5b29deaec9a
golang.org/x/net@v0.17.0
stdlib@go1.20.13
0.53.0
1.25.10
1
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/net@v0.9.0
stdlib@go1.20.3
0.53.0
1.25.10
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.53.0
1.25.10
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
stdlib@go1.18.2
1.25.10
1
postgis/postgis:18-3.67e00e8c3539f
stdlib@go1.24.6
1.25.10
1
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.25.10
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
stdlib@go1.13.12
0.53.0
1.25.10
1
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.9
0.53.0
1.25.10
1
prathamkrishna/dicedb:v1a7298180cd24
stdlib@go1.23.2
1.25.10
1
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.