StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,043
of 17,797 indexed, latest versions
Container images
4,670
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,043 of 17,797 indexed charts deploy, on 4,670 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,519
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,570
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,043 by stars
ChartLatestAffected imagesRadar Score
mortalgpumortalgpuOfficialVerified publisher1.3.71 of 1See more

mortalgpu mortalgpu 1.3.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/maxiv/mortalgpu:1.3.7e1c5c194bbf0
stdlib@go1.26.0
1.25.10

Open the chart page →

379
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.19
0.53.0
1.25.10

Open the chart page →

3,803
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

4,096
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.53.0
1.25.10

Open the chart page →

5,067
gateway-apinicklasfrahm-gateway-apiVerified publisher0.2.01 of 1See more

gateway-api nicklasfrahm-gateway-api 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/kubectl:1.33.32c59a3f0726c
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

1,258
observalobservalVerified publisher1.13.11 of 8See more

observal observal 1.13.1

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.10

Open the chart page →

5,952
aws-xrayokgoloveVerified publisher5.0.01 of 1See more

aws-xray okgolove 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/xray/aws-xray-daemon:3.6.243d051eed000
golang.org/x/net@v0.38.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

273
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

6,881
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
stdlib@go1.17.1
1.25.10
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

18,543
secrets-injectoronepassword-connect1.2.01 of 1See more

secrets-injector onepassword-connect 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
1password/kubernetes-secrets-injector:1.0.25884757f7879
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

891
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/git:2.47.2062a01ad7a0e
golang.org/x/net@v0.23.0
stdlib@go1.23.9
0.53.0
1.25.10

Open the chart page →

5,224
opentelemetry-ebpfopentelemetry-helmOfficialVerified publisher0.1.71 of 4See more

opentelemetry-ebpf opentelemetry-helm 0.1.7

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
golang.org/x/net@v0.7.0
stdlib@go1.20
0.53.0
1.25.10

Open the chart page →

2,582
oesopsmxVerified publisher4.0.3210 of 25See more

oes opsmx 4.0.32

10 of the 25 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.15.5
0.53.0
1.25.10
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.5
0.53.0
1.25.10
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
stdlib@go1.17.2
1.25.10
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
stdlib@go1.16.15
1.25.10
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.53.0
1.25.10
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.19.1
0.53.0
1.25.10
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.53.0
1.25.10
quay.io/opsmxpublic/opa:1.12.084fb1af7401c
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
stdlib@go1.22.2
1.25.10
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.1
0.53.0
1.25.10

Open the chart page →

108,354
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
golang.org/x/net@v0.0.0-20220517181318-183a9ca12b87
stdlib@go1.18.3
0.53.0
1.25.10
ipfs/ipfs-cluster:1.0.21511f6d57994
golang.org/x/net@v0.0.0-20220517181318-183a9ca12b87
stdlib@go1.18.3
0.53.0
1.25.10

Open the chart page →

3,771
permifypermifyVerified publisher0.5.01 of 1See more

permify permify 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/permify/permify:v1.3.5f0c6f7d7daa6
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

1,004
platzioplatz-ioVerified publisher0.6.51 of 2See more

platzio platz-io 0.6.5

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
platzio/backend:v0.6.5d5e5972f344b
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.53.0
1.25.10

Open the chart page →

2,879
plecopleco0.24.01 of 1See more

pleco pleco 0.24.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/net@v0.39.0
stdlib@go1.21.6
0.53.0
1.25.10

Open the chart page →

1,353
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
stdlib@go1.13.10
1.25.10

Open the chart page →

2,994
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/net@v0.9.0
stdlib@go1.20.3
0.53.0
1.25.10

Open the chart page →

1,949
prometheus-systemd-exporterprometheus-communityVerified publisher0.5.21 of 1See more

prometheus-systemd-exporter prometheus-community 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/systemd-exporter:v0.7.078c03f875dfb
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

725
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.53.0
1.25.10
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.14.12
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.53.0
1.25.10

Open the chart page →

12,134
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.53.0
1.25.10

Open the chart page →

5,483
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.53.0
1.25.10

Open the chart page →

2,731
repoflowrepoflow-helm-public0.9.12 of 8See more

repoflow repoflow-helm-public 0.9.1

2 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.25.10
minio/minio:RELEASE.2025-07-23T15-54-02Zd249d1fb6966
golang.org/x/net@v0.39.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

13,692
backrestrobertobochetVerified publisher0.7.01 of 1See more

backrest robertobochet 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
garethgeorge/backrest:v1.14.1b85297975428
stdlib@go1.26.0
1.25.10

Open the chart page →

866
supabaserock8sVerified publisher0.0.61 of 1See more

supabase rock8s 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
stdlib@go1.24.6
1.25.10

Open the chart page →

494
rqliterqliteOfficialVerified publisher2.0.01 of 1See more

rqlite rqlite 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rqlite/rqlite:9.1.37b992a526eee
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

1,319
qbittorrent-vpnrtomik-helm-chartsVerified publisher0.0.21 of 2See more

qbittorrent-vpn rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.40.02b42bfa04675
golang.org/x/net@v0.31.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

1,219
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
stdlib@go1.18.1
1.25.10

Open the chart page →

3,476
seaweedfs-csi-driverseaweedfs-csi-driver0.2.385 of 7See more

seaweedfs-csi-driver seaweedfs-csi-driver 0.2.38

5 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10

Open the chart page →

5,321
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
golang.org/x/net@v0.44.0
stdlib@go1.24.11
0.53.0
1.25.10

Open the chart page →

860
bentoself-hosters-by-nightVerified publisher0.9.11 of 1See more

bento self-hosters-by-night 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
golang.org/x/net@v0.37.0
stdlib@go1.23.10
0.53.0
1.25.10

Open the chart page →

1,053
lldapself-hosters-by-nightVerified publisher0.5.22 of 2See more

lldap self-hosters-by-night 0.5.2

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
stdlib@go1.24.6
1.25.10
ghcr.io/lldap/lldap:2025-05-193de697c3ba57
stdlib@go1.18.2
1.25.10

Open the chart page →

3,441
appshini4iVerified publisher0.4.01 of 1See more

app shini4i 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
traefik/whoami:v1.10.21474027c3166
golang.org/x/net@v0.25.0
stdlib@go1.22.2
0.53.0
1.25.10

Open the chart page →

537
skypilotskypilotOfficialVerified publisher0.13.03 of 3See more

skypilot skypilot 0.13.0

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

5,943
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/net@v0.4.0
stdlib@go1.20
0.53.0
1.25.10

Open the chart page →

1,670
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.53.0
1.25.10

Open the chart page →

12,537
miniosolidchartsVerified publisher0.5.01 of 1See more

minio solidcharts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

1,070
forecastlestakaterVerified publisher2.1.11 of 1See more

forecastle stakater 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/forecastle:v2.0.2382cd9572352
golang.org/x/net@v0.51.0
0.53.0

Open the chart page →

711
ingressmonitorcontrollerstakaterVerified publisher2.2.131 of 1See more

ingressmonitorcontroller stakater 2.2.13

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

583
sn-platformstreamnative1.11.446 of 9See more

sn-platform streamnative 1.11.44

6 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.10
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.53.0
1.25.10
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.11
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.53.0
1.25.10

Open the chart page →

15,620
pocketbasetechwolf12Verified publisher0.29.31 of 1See more

pocketbase techwolf12 0.29.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

1,448
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.25.10

Open the chart page →

10,046
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
stdlib@go1.24.4
1.25.10

Open the chart page →

3,834
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.263 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

3 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
stdlib@go1.20.5
1.25.10
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
stdlib@go1.19.12
1.25.10
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.25.10

Open the chart page →

14,578
feedbacksystemthm-mni-iiVerified publisher0.47.16 of 10See more

feedbacksystem thm-mni-ii 0.47.1

6 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.53.0
1.25.10
bitnamilegacy/mysql:8.0.35-debian-11-r2be03e8ea6129
stdlib@go1.21.5
1.25.10
library/docker:20.10.21-dind3153fa63f546
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.7
0.53.0
1.25.10
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
stdlib@go1.20.12
1.25.10
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.53.0
1.25.10

Open the chart page →

28,692
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

1,503
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.14.4
0.53.0
1.25.10

Open the chart page →

4,145
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.53.0
1.25.10
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.53.0
1.25.10
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.19
0.53.0
1.25.10

Open the chart page →

9,271
k8s-ttl-controllertwin0.4.01 of 1See more

k8s-ttl-controller twin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/net@v0.26.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

471

Container images carrying it

4,670 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.53.0
1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.53.0
1
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.53.0
1
rancher/harvester-csi-driver:v0.2.9f9099b5ef8cb
golang.org/x/net@v0.49.0
0.53.0
1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.53.0
1.25.10
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.2
0.53.0
1.25.10
1
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.53.0
1.25.10
1
rancher/kube-webhook-certgen:v1.14.5-hardened26bb869baf40b
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
rancher/local-path-provisioner:v0.0.361eba82e9c386
golang.org/x/net@v0.38.0
0.53.0
1
rancher/local-path-provisioner:v0.0.329289da488b07
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
1
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.53.0
1.25.10
1
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.16.6
0.53.0
1.25.10
1
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.16.15
0.53.0
1.25.10
1
rancher/mirrored-cloud-provider-vsphere:v1.31.1febfd0517838
golang.org/x/net@v0.26.0
stdlib@go1.22.8
0.53.0
1.25.10
1
rancher/mirrored-longhornio-csi-attacher:v4.11.0-20260428fe417c28a6b8
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.53.0
1.25.10
1
rancher/mirrored-longhornio-csi-node-driver-registrar:v2.16.0-20260428e82a8c8f800d
golang.org/x/net@v0.49.0
stdlib@go1.25.9
0.53.0
1.25.10
1
rancher/mirrored-longhornio-csi-provisioner:v5.3.0-202604289e519a21a77c
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.53.0
1.25.10
1
rancher/mirrored-longhornio-csi-resizer:v2.1.0-2026042841cb674d1154
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.53.0
1.25.10
1
rancher/mirrored-longhornio-csi-snapshotter:v8.5.0-202604281975fac3890f
golang.org/x/net@v0.49.0
stdlib@go1.25.9
0.53.0
1.25.10
1
rancher/nginx-ingress-controller:v1.14.5-hardened26cbc1e932b5b
golang.org/x/net@v0.52.0
stdlib@go1.24.13
0.53.0
1.25.10
1
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
stdlib@go1.16.4
1.25.10
1
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
stdlib@go1.16.4
1.25.10
1
rancher/system-upgrade-controller:v0.19.234fa058fe453
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.53.0
1.25.10
1
rancher/system-upgrade-controller:v0.18.09813f85653c8
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.53.0
1.25.10
1
ravendb/ravendb-operator:2.1.0511050205ac5
golang.org/x/net@v0.48.0
0.53.0
1
rayselfs/aws-ec2-runtime-checker:v0.1.5562e5b2f81ce
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.53.0
1.25.10
1
rclone/rclone:1.63.008e1af3c8814
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.53.0
1.25.10
1
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.2
0.53.0
1.25.10
1
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.6
0.53.0
1.25.10
1
reallibrephotos/librephotos-frontend:1.0.358cdf5e93471
stdlib@go1.24.13
1.25.10
1
reaper99/recipya:v1.2.27f7ec3aeb88c
golang.org/x/net@v0.27.0
stdlib@go1.22.0
0.53.0
1.25.10
1
redislabs/operator:8.0.18-119078e713bb6a
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.53.0
1.25.10
1
redislabs/redisearch:2.4.1433561794c5c8
stdlib@go1.16.7
1.25.10
1
redpandadata/kminion:v2.3.0c05fa976428e
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10
1
regclient/regsync:v0.8.33d8d8e40afb7
stdlib@go1.24.2
1.25.10
1
replicated/replicated-sdk:1.0.0-beta.318751b4963250
golang.org/x/net@v0.23.0
stdlib@go1.23.2
0.53.0
1.25.10
1
reportportal/k8s-wait-for:latest06cdf299b397
golang.org/x/net@v0.49.0
0.53.0
1
reportportal/migrations:5.15.4464468240d7b
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
1
reportportal/migrations:5.7.0da5d8e1395fe
golang.org/x/net@v0.0.0-20190424112056-4829fb13d2c6
stdlib@go1.13.6
0.53.0
1.25.10
1
reportportal/service-index:5.0.112b27a2d7a87d
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.17.1
0.53.0
1.25.10
1
reportportal/service-index:5.15.1b1860ed33071
stdlib@go1.26.2
1.25.10
1
restic/restic:0.15.2579e4e6a4931
golang.org/x/net@v0.8.0
stdlib@go1.19.8
0.53.0
1.25.10
1
restic/rest-server:0.14.0d2aff06f47eb
stdlib@go1.24.3
1.25.10
1
resurfaceio/resurface:3.7.84d5cda2f64109
stdlib@go1.23.0
1.25.10
1
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.19.12
1.25.10
1
ribbybibby/s3-exporter:v0.5.0998184c51a00
stdlib@go1.15.15
1.25.10
1
richardjennings/opa-nginx:0.0.366424aca125d
stdlib@go1.20.5
1.25.10
1
rimusz/security-sample-app:0.2.0b9a178ca76ef
stdlib@go1.14.4
1.25.10
1
robjuz/postgresql-nominatim:latest805c7bab76df
stdlib@go1.16.5
1.25.10
1
robotshop/rs-dispatch:latestde81f1d07b02
stdlib@go1.17
1.25.10
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.