StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,202
of 17,828 indexed, latest versions
Container images
4,829
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,202 of 17,828 indexed charts deploy, on 4,829 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,668
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.53.03,685
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,202 by stars
ChartLatestAffected imagesRadar Score
capi-watcherkrateo0.1.01 of 1See more

capi-watcher krateo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/capi-watcher:0.1.0fa01a157d972
golang.org/x/net@v0.4.0
stdlib@go1.19.2
0.53.0
1.25.10

Open the chart page →

1,060
deviserkrateo0.7.11 of 1See more

deviser krateo 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/deviser:0.7.18310717431b2
golang.org/x/net@v0.51.0
0.53.0

Open the chart page →

225
eventrouterkrateo0.6.51 of 1See more

eventrouter krateo 0.6.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/eventstack/eventrouter:0.6.030121418adfa
golang.org/x/net@v0.43.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

305
eventrouter-kafka-producerkrateo0.1.11 of 1See more

eventrouter-kafka-producer krateo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/eventrouter-kafka-producer:0.1.155b18c0dda37
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.19.2
0.53.0
1.25.10

Open the chart page →

1,623
events-ingesterkrateo0.5.31 of 1See more

events-ingester krateo 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/events-ingester:0.5.3e917b25f6b49
golang.org/x/net@v0.51.0
0.53.0

Open the chart page →

225
events-presenterkrateo0.9.31 of 1See more

events-presenter krateo 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/events-presenter:0.9.381b8ad5e4178
golang.org/x/net@v0.51.0
0.53.0

Open the chart page →

248
eventssekrateo0.5.91 of 1See more

eventsse krateo 0.5.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/eventstack/eventsse:0.5.8b65eb9c88669
golang.org/x/net@v0.38.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

407
finops-composition-definition-parserkrateo0.1.41 of 1See more

finops-composition-definition-parser krateo 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/finops-composition-definition-parser:0.1.2d9d82c32f418
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

941
finops-database-handler-uploaderkrateo0.2.11 of 1See more

finops-database-handler-uploader krateo 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/finops-database-handler-uploader:0.2.131ee1096bc9c
golang.org/x/net@v0.38.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

322
finops-example-pricing-vm-azurekrateo0.2.141 of 1See more

finops-example-pricing-vm-azure krateo 0.2.14

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/kubectl:1.32.0d69cd9c163db
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

1,216
finops-http-rest-queuekrateo0.1.01 of 1See more

finops-http-rest-queue krateo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/finops-http-rest-queue:0.1.0eaa0801e29a7
stdlib@go1.22.1
1.25.10

Open the chart page →

770
finops-operator-scraperkrateo0.5.11 of 1See more

finops-operator-scraper krateo 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/finops-operator-scraper:0.5.15523ff02e511
golang.org/x/net@v0.34.0
stdlib@go1.23.0
0.53.0
1.25.10

Open the chart page →

513
finops-operator-vm-managerkrateo0.1.21 of 2See more

finops-operator-vm-manager krateo 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/finops-operator-vm-manager:0.1.215f804bdd1e8
golang.org/x/net@v0.19.0
stdlib@go1.21.12
0.53.0
1.25.10

Open the chart page →

586
frontend-providerkrateo0.3.01 of 1See more

frontend-provider krateo 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/frontend-provider:0.3.084c3219b00a2
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.53.0
1.25.10

Open the chart page →

948
git-providerkrateo0.13.01 of 1See more

git-provider krateo 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/git-provider:0.10.061deb827aa9f
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.53.0
1.25.10

Open the chart page →

747
installerkrateo2.7.12 of 2See more

installer krateo 2.7.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10
ghcr.io/krateoplatformops/installer/installer:0.6.3a7e922ddac55
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

3,277
installer-post-upgrade-2-5-1krateo1.0.11 of 1See more

installer-post-upgrade-2-5-1 krateo 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

2,543
installer-pre-upgradekrateo2.7.11 of 1See more

installer-pre-upgrade krateo 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

2,543
installer-pre-upgrade-2-5-0krateo1.0.11 of 1See more

installer-pre-upgrade-2-5-0 krateo 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

2,543
installer-pre-upgrade-2-5-1krateo1.0.11 of 1See more

installer-pre-upgrade-2-5-1 krateo 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

2,543
kserve-controllerkrateo1.0.01 of 1See more

kserve-controller krateo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/kserve-controller:1.0.05683c5ae670e
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.53.0
1.25.10

Open the chart page →

267
logs-presenterkrateo0.1.01 of 1See more

logs-presenter krateo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/logs-presenter:0.1.0c52fa557d1d0
golang.org/x/net@v0.51.0
0.53.0

Open the chart page →

225
oasgen-providerkrateo0.11.11 of 1See more

oasgen-provider krateo 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/oasgen-provider:0.10.0656ec60c6407
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

4,723
sweeperkrateo0.2.12 of 2See more

sweeper krateo 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/kubectl:1.36.01ee9df6316d4
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.53.0
1.25.10
ghcr.io/krateoplatformops/eventstack/sweeper:0.1.05d5e24119ff1
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

1,506
kubeflowkromanow94-kubeflow0.5.116 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

16 of the 30 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubeflow/model-registry:v0.2.95783f6db428f
golang.org/x/net@v0.28.0
stdlib@go1.21.13
0.53.0
1.25.10
kubeflow/training-operator:v1-04f9f13dabb76dbda29
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.53.0
1.25.10
kubeflowkatib/katib-controller:v0.17.072f14e03b9e1
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
kubeflowkatib/katib-db-manager:v0.17.0916a7695b0dd
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
kubeflowkatib/katib-ui:v0.17.07a41c508deb1
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
kubeflownotebookswg/kfam:v1.9.22060a2ede788
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.53.0
1.25.10
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.53.0
1.25.10
kubeflownotebookswg/poddefaults-webhook:v1.9.2bde88d98ad74
golang.org/x/net@v0.13.0
stdlib@go1.21.13
0.53.0
1.25.10
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.53.0
1.25.10
kubeflownotebookswg/pvcviewer-controller:v1.9.29815e9b1728f
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.53.0
1.25.10
kubeflownotebookswg/tensorboard-controller:v1.9.26536a9f61193
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.53.0
1.25.10
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10

Open the chart page →

71,041
kron-aapm-sidecarkron-aapm-sidecar1.1.01 of 1See more

kron-aapm-sidecar kron-aapm-sidecar 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

2,112
adventureworkskronkltdVerified publisher0.1.01 of 1See more

adventureworks kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
chriseaton/adventureworks:latest54c3384ce701
stdlib@go1.23.1
1.25.10

Open the chart page →

4,564
lndkronkltdVerified publisher0.3.93 of 4See more

lnd kronkltd 0.3.9

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.1
0.53.0
1.25.10
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.53.0
1.25.10
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.53.0
1.25.10

Open the chart page →

8,476
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
stdlib@go1.20.13
1.25.10

Open the chart page →

9,742
world-dbkronkltdVerified publisher0.1.01 of 1See more

world-db kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghusta/postgres-world-db:latest879d0919fdcc
stdlib@go1.24.6
1.25.10

Open the chart page →

1,731
casdoorkrzwiatrzyk1.0.01 of 1See more

casdoor krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
casbin/casdoor:v1.224.066f836ef778b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.5
0.53.0
1.25.10

Open the chart page →

3,651
nocodbkrzwiatrzyk0.0.11 of 1See more

nocodb krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nocodb/nocodb:0.100.2b0b91ec2a2dd
golang.org/x/net@v0.0.0-20220805013720-a33c5aa5df48
stdlib@go1.18.2
0.53.0
1.25.10

Open the chart page →

2,321
pipecdkrzwiatrzyk0.39.01 of 3See more

pipecd krzwiatrzyk 0.39.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.6
0.53.0
1.25.10

Open the chart page →

3,820
postgresql-backup-to-miniokrzwiatrzyk0.0.11 of 2See more

postgresql-backup-to-minio krzwiatrzyk 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.25.10

Open the chart page →

2,200
traggokrzwiatrzyk1.0.01 of 1See more

traggo krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
traggo/server:0.2.3f1ced637510e
stdlib@go1.13.1
1.25.10

Open the chart page →

1,886
ksoc-pluginsksocOfficialVerified publisher1.9.105 of 5See more

ksoc-plugins ksoc 1.9.10

5 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/n8h5y2v5/rad-security/rad-bootstrapper:v1.1.115ca2d500d374
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
public.ecr.aws/n8h5y2v5/rad-security/rad-guard:v1.1.17a94d2d4aae85
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
public.ecr.aws/n8h5y2v5/rad-security/rad-sync:v1.1.1514f3dfbc0225
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
public.ecr.aws/n8h5y2v5/rad-security/rad-watch:v1.1.25b9a7d6bc2a0c
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

3,214
kubeadapt-k8s-pulsekubeadaptVerified publisher1.0.21 of 1See more

kubeadapt-k8s-pulse kubeadapt 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
stdlib@go1.25.9
1.25.10

Open the chart page →

2,452
bc-depositorykubebb0.0.31 of 1See more

bc-depository kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.53.0
1.25.10

Open the chart page →

1,948
bc-explorerkubebb0.0.31 of 1See more

bc-explorer kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.53.0
1.25.10

Open the chart page →

1,948
chartmuseumkubebb3.10.21 of 1See more

chartmuseum kubebb 3.10.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

2,277
cluster-componentkubebb0.2.24 of 4See more

cluster-component kubebb 0.2.2

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.53.0
1.25.10
kubebb/cert-manager-controller:v1.8.020509de4b399
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.53.0
1.25.10
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.53.0
1.25.10
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.53.0
1.25.10

Open the chart page →

8,181
fabric-operatorkubebb0.1.01 of 1See more

fabric-operator kubebb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.4
0.53.0
1.25.10

Open the chart page →

3,997
ingress-nginxkubebb4.7.02 of 2See more

ingress-nginx kubebb 4.7.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
golang.org/x/net@v0.10.0
stdlib@go1.20.1
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10

Open the chart page →

3,100
kubebbkubebb0.0.11 of 1See more

kubebb kubebb 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubebb/core:lateste366c34a9b8d
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10

Open the chart page →

1,758
kubebb-corekubebb0.1.271 of 1See more

kubebb-core kubebb 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubebb/core:v0.1.62b9e7f451d6b
golang.org/x/net@v0.14.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

1,947
miniokubebb5.0.102 of 2See more

minio kubebb 5.0.10

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

7,616
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubebb/mesh-operator:v5.7.0163ebbfc7a82
golang.org/x/net@v0.7.0
stdlib@go1.18.4
0.53.0
1.25.10

Open the chart page →

6,497
tekton-operatorkubebb0.64.02 of 2See more

tekton-operator kubebb 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18.7
0.53.0
1.25.10
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18.7
0.53.0
1.25.10

Open the chart page →

2,434
u4a-componentkubebb0.2.106 of 8See more

u4a-component kubebb 0.2.10

6 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubebb/capsule-ce:v0.1.2-20221122a3dba2a95cef
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.18.8
0.53.0
1.25.10
kubebb/iam-controller:v0.2.0-202401288ffbfa2d67e9
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.20.7
0.53.0
1.25.10
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.13
0.53.0
1.25.10
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18
0.53.0
1.25.10
kubebb/oidc-server:v0.2.02b5894ef1e2f
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.17.8
0.53.0
1.25.10
kubebb/resource-viewer:v0.2.065bb40b353db
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.7
0.53.0
1.25.10

Open the chart page →

13,858
weaviatekubebb16.3.01 of 1See more

weaviate kubebb 16.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
semitechnologies/weaviate:1.19.17a00d226f063
golang.org/x/net@v0.7.0
stdlib@go1.19.9
0.53.0
1.25.10

Open the chart page →

1,877

Container images carrying it

4,829 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
temporalio/server:1.26.21e2626efcbc1
golang.org/x/net@v0.31.0
stdlib@go1.23.2
0.53.0
1.25.10
1
temporalio/server:1.25.08a5798191dea
golang.org/x/net@v0.28.0
stdlib@go1.22.3
0.53.0
1.25.10
1
temporalio/server:1.29.1c1e3326b2ce1
golang.org/x/net@v0.40.0
stdlib@go1.25.0
0.53.0
1.25.10
1
temporalio/server:1.22.0ddeebf8bad8f
golang.org/x/net@v0.14.0
stdlib@go1.19.11
0.53.0
1.25.10
1
temporalio/ui:2.44.00b36e00aad30
golang.org/x/net@v0.34.0
stdlib@go1.24.11
0.53.0
1.25.10
1
temporalio/ui:2.30.25c2a3645d09c
golang.org/x/net@v0.28.0
stdlib@go1.22.1
0.53.0
1.25.10
1
temporalio/ui:2.33.05c586a3c8ec5
golang.org/x/net@v0.17.0
stdlib@go1.23.0
0.53.0
1.25.10
1
temporalio/ui:2.39.0b768f87f18b5
golang.org/x/net@v0.40.0
stdlib@go1.23.4
0.53.0
1.25.10
1
temporalio/ui:2.52.0fc47cd8202c9
golang.org/x/net@v0.49.0
0.53.0
1
tensorzero/ui:2026.6.0f2563d54724e
stdlib@go1.23.12
1.25.10
1
tenureai/tenure:v1.0.285f5b222df9a5
stdlib@go1.26.2
1.25.10
1
thanosio/thanos:v0.19.088276fcd1491
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15.10
0.53.0
1.25.10
1
thanosio/thanos:v0.15.0b12d5c31bf5a
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.2
0.53.0
1.25.10
1
thecampagnards/trafficlight-api:main7dca9d973837
stdlib@go1.16.4
1.25.10
1
thecodingmachine/workadventure-back:v1.17.764001369dad5
stdlib@go1.20.7
1.25.10
1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
stdlib@go1.17.13
1.25.10
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
stdlib@go1.19.3
1.25.10
1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
stdlib@go1.20.7
1.25.10
1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
stdlib@go1.20.7
1.25.10
1
thelande/openmeteo_exporter:v1.0.77e9072ace15f
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.53.0
1.25.10
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
golang.org/x/net@v0.8.0
stdlib@go1.21.0
0.53.0
1.25.10
1
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.1
0.53.0
1.25.10
1
thetorproject/snowflake-proxy:v2.11.01ddc5069d354
golang.org/x/net@v0.35.0
stdlib@go1.23.7
0.53.0
1.25.10
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
stdlib@go1.20.12
1.25.10
1
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.53.0
1.25.10
1
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.53.0
1.25.10
1
thomseddon/traefik-forward-auth:latestb364aa6a4117
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.15
0.53.0
1.25.10
1
tile38/tile38:1.38.05b61c6f3b32e
golang.org/x/net@v0.48.0
0.53.0
1
tile38/tile38:1.33.4afb7e82f9485
golang.org/x/net@v0.23.0
stdlib@go1.23.2
0.53.0
1.25.10
1
timescale/timescaledb:latest-pg12645fd9e92d76
stdlib@go1.18.7
1.25.10
1
timescale/timescaledb:latest-pg16f495f2bc25ca
stdlib@go1.26.2
1.25.10
1
timescale/timescaledb-ha:pg164f288c0a5213
golang.org/x/net@v0.26.0
stdlib@go1.18.1
0.53.0
1.25.10
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.25.10
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
stdlib@go1.19.1
1.25.10
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/net@v0.33.0
stdlib@go1.21.13
0.53.0
1.25.10
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
stdlib@go1.15.6
1.25.10
1
timescale/timescaledb-postgis:latest-pg127758704d4a14
stdlib@go1.14
1.25.10
1
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.25.10
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
stdlib@go1.24.4
1.25.10
1
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20.3
0.53.0
1.25.10
1
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
stdlib@go1.13.10
0.53.0
1.25.10
1
tobiasehlert/teslamateapi:1.20.2cf09259ad0ea
golang.org/x/net@v0.37.0
stdlib@go1.24.0
0.53.0
1.25.10
1
tobirachel/node-project3:v17d9f37154994
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.5
0.53.0
1.25.10
1
tolgee/tolgee:v3.224.52e9c2e57829d
stdlib@go1.24.6
1.25.10
1
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.53.0
1.25.10
1
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.19
0.53.0
1.25.10
1
traefik/whoami:v1.10.21474027c3166
golang.org/x/net@v0.25.0
stdlib@go1.22.2
0.53.0
1.25.10
1
traefik/whoami:v1.101699d99cb4b9
stdlib@go1.23.5
1.25.10
1
traefik/whoami:v1.6.12c52bb2c8480
stdlib@go1.15.6
1.25.10
1
traefik/whoami:v1.8.08d0f943abdbf
stdlib@go1.17.7
1.25.10
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.