StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,058
of 17,790 indexed, latest versions
Container images
4,694
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,058 of 17,790 indexed charts deploy, on 4,694 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,539
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,589
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,058 by stars
ChartLatestAffected imagesRadar Score
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.25.10

Open the chart page →

11,851
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
stdlib@go1.18.4
1.25.10

Open the chart page →

10,422
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.25.10

Open the chart page →

7,810
rtsp-to-webgeek-cookbookVerified publisher2.2.21 of 1See more

rtsp-to-web geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.53.0

Open the chart page →

1,467
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
stdlib@go1.18.1
1.25.10

Open the chart page →

3,469
searxgeek-cookbookVerified publisher5.6.23 of 4See more

searx geek-cookbook 5.6.2

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.25.10
dalf/morty:latest248a4849c350
golang.org/x/net@v0.0.0-20220421235706-1d1ef9303861
stdlib@go1.18.2
0.53.0
1.25.10
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

7,476
skypilotgeek-cookbookVerified publisher0.0.13 of 3See more

skypilot geek-cookbook 0.0.1

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
golang.org/x/net@v0.38.0
stdlib@go1.23.5
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

8,992
torrservergeek-cookbookVerified publisher1.2.21 of 1See more

torrserver geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
smailkoz/torrserver:1.0.1117b52d15de8f0
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.5
0.53.0
1.25.10

Open the chart page →

3,165
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
stdlib@go1.18.4
1.25.10

Open the chart page →

11,906
vikunjageek-cookbookVerified publisher6.2.02 of 4See more

vikunja geek-cookbook 6.2.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.5
0.53.0
1.25.10
vikunja/api:0.17.18cba0520bf8c
golang.org/x/net@v0.0.0-20210505024714-0287a6fb4125
stdlib@go1.16.5
0.53.0
1.25.10

Open the chart page →

6,893
webhook-receivergeek-cookbookVerified publisher0.0.11 of 1See more

webhook-receiver geek-cookbook 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,368
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.25.10

Open the chart page →

17,996
asynqmongeneral-helm-chartsVerified publisher0.0.11 of 1See more

asynqmon general-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hibiken/asynqmon:latestac80bcffd2f9
stdlib@go1.18.10
1.25.10

Open the chart page →

751
cbtgeneral-helm-chartsVerified publisher0.0.51 of 1See more

cbt general-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ethpandaops/cbt:latest5377ffb3091a
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

564
chproxygeneral-helm-chartsVerified publisher0.0.21 of 1See more

chproxy general-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
contentsquareplatform/chproxy:v1.26.524555f22d4be
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.53.0
1.25.10

Open the chart page →

3,735
dispatchoor-apigeneral-helm-chartsVerified publisher0.1.11 of 1See more

dispatchoor-api general-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

635
panda-pulsegeneral-helm-chartsVerified publisher1.0.61 of 1See more

panda-pulse general-helm-charts 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ethpandaops/panda-pulse:latestad6fc3b3e6b8
stdlib@go1.26.1
1.25.10

Open the chart page →

622
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,558
mongogengxiankun-charts0.1.01 of 1See more

mongo gengxiankun-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.53.0
1.25.10

Open the chart page →

4,010
mysqlgengxiankun-charts0.2.01 of 1See more

mysql gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

463
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
stdlib@go1.19.8
1.25.10

Open the chart page →

4,296
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.82 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
golang.org/x/net@v0.11.0
stdlib@go1.19.11
0.53.0
1.25.10
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.25.10

Open the chart page →

34,893
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.53.0
1.25.10
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.53.0
1.25.10

Open the chart page →

16,854
ghostghostVerified publisher0.1.02 of 4See more

ghost ghost 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
stdlib@go1.18.2
1.25.10
litestream/litestream:0.3c5a1e1b01916
golang.org/x/net@v0.14.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

9,071
rabbitmqginger-society0.1.02 of 2See more

rabbitmq ginger-society 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kbudde/rabbitmq-exporter:latest12f27d6d84e6
stdlib@go1.21.8
1.25.10
library/rabbitmq:4-managementffd1b50c522a
stdlib@go1.22.2
1.25.10

Open the chart page →

1,514
gitanagitana1.4.01 of 1See more

gitana gitana 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ntakashi/gitana:1.4.04171ec641120
golang.org/x/net@v0.0.0-20210929161516-d455829e376d
stdlib@go1.17.7
0.53.0
1.25.10

Open the chart page →

3,478
github-rate-limits-prometheus-exportergithub-rate-limit-prometheus-exporterVerified publisher0.2.151 of 1See more

github-rate-limits-prometheus-exporter github-rate-limit-prometheus-exporter 0.2.15

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kalgurn/grl-exporter:v3.2.0bd109b2bda38
stdlib@go1.23.5
1.25.10

Open the chart page →

896
gitlab-goproxygitlab-goproxy0.2.21 of 1See more

gitlab-goproxy gitlab-goproxy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/net@v0.10.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

1,332
gitlab-mr-conformgitlab-mr-conform0.5.21 of 1See more

gitlab-mr-conform gitlab-mr-conform 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/chrxmvtik/gitlab-mr-conform:0.5.2b2eb79fc99cb
golang.org/x/net@v0.51.0
stdlib@go1.25.9
0.53.0
1.25.10

Open the chart page →

428
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
golang.org/x/net@v0.11.0
stdlib@go1.19.12
0.53.0
1.25.10

Open the chart page →

2,616
prometheus-container-resource-exportergkarthiks0.3.11 of 1See more

prometheus-container-resource-exporter gkarthiks 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gkarthics/container-resource-exporter:latest6799af333e8a
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.7
0.53.0
1.25.10

Open the chart page →

2,218
prometheus-couchdb-exportergkarthiks0.1.31 of 1See more

prometheus-couchdb-exporter gkarthiks 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gesellix/couchdb-prometheus-exporter:v27.2.05b891f1fc2b9
stdlib@go1.13.10
1.25.10

Open the chart page →

1,284
glassflow-etlglassflowVerified publisher0.5.2110 of 16See more

glassflow-etl glassflow 0.5.21

10 of the 16 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats:2.12.3-alpine88fe8e0e09d6
stdlib@go1.25.5
1.25.10
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.53.0
1.25.10
natsio/nats-server-config-reloader:0.21.110ff229eaf52
stdlib@go1.25.5
1.25.10
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.25.10
otel/opentelemetry-collector-contrib:0.108.0923eb1cfae32
golang.org/x/net@v0.28.0
stdlib@go1.23.0
0.53.0
1.25.10
ghcr.io/glassflow/glassflow-etl-be:v3.2.020f066d0f631
golang.org/x/net@v0.52.0
stdlib@go1.25.0
0.53.0
1.25.10
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.53.0
1.25.10
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10
ghcr.io/glassflow/kafka-kerberos-gateway:latest2ae01c524a6e
stdlib@go1.21.13
1.25.10

Open the chart page →

12,115
pgbouncerglassflowVerified publisher0.1.01 of 1See more

pgbouncer glassflow 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/pgbouncer:1.23.192356da09704
stdlib@go1.22.10
1.25.10

Open the chart page →

3,279
postgresqlglassflowVerified publisher0.1.91 of 1See more

postgresql glassflow 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10

Open the chart page →

494
glassflow-operatorglassflow-operatorVerified publisher0.8.51 of 3See more

glassflow-operator glassflow-operator 0.8.5

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.53.0
1.25.10

Open the chart page →

770
glauthglauthVerified publisher0.3.171 of 2See more

glauth glauth 0.3.17

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

2,634
glidergliderVerified publisher0.1.51 of 1See more

glider glider 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nadoo/glider:0.1638aadefbd607
golang.org/x/net@v0.28.0
stdlib@go1.20.14
0.53.0
1.25.10

Open the chart page →

894
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:latestdd9b303aed4f
stdlib@go1.24.6
1.25.10

Open the chart page →

12,359
gnp-stackgnp-stack0.0.57 of 14See more

gnp-stack gnp-stack 0.0.5

7 of the 14 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:12.2.135c41e0fd029
golang.org/x/net@v0.45.0
stdlib@go1.25.3
0.53.0
1.25.10
rancher/local-path-provisioner:v0.0.329289da488b07
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
golang.org/x/net@v0.50.0
stdlib@go1.24.12
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.85.0890b3bb05cf4
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.33d671cf20a35
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

7,683
go-app-helmgo-app-helm0.1.01 of 1See more

go-app-helm go-app-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
manojchaulagain/go-k8s:0.1.0f237b5f637ae
stdlib@go1.20.1
1.25.10

Open the chart page →

1,594
go-file-servergo-file-server1.0.01 of 2See more

go-file-server go-file-server 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
goccx/go-file-server:latestf4b3ebea0303
golang.org/x/net@v0.27.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

2,222
gofitgofit0.0.11 of 1See more

gofit gofit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bamaas/gofit:0.0.132b6a174b419
stdlib@go1.22.11
1.25.10

Open the chart page →

650
goldpingergoldpinger1.1.31 of 1See more

goldpinger goldpinger 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.11.3a8ea8c61ff4c
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

142
googly-logingoogly-login0.1.01 of 2See more

googly-login googly-login 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.10

Open the chart page →

1,649
gorsegorse-io0.4.23 of 4See more

gorse gorse-io 0.4.2

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10

Open the chart page →

4,401
gotwaygotwayVerified publisher0.8.01 of 1See more

gotway gotway 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.18.3
0.53.0
1.25.10

Open the chart page →

1,826
Governify-Bluejaygovernify0.1.02 of 12See more

Governify-Bluejay governify 0.1.0

2 of the 12 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.53.0
1.25.10
library/mongo:latest5211c51171f5
stdlib@go1.24.6
1.25.10

Open the chart page →

22,587
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.53.0
1.25.10
library/mongo:latest5211c51171f5
stdlib@go1.24.6
1.25.10

Open the chart page →

24,379
goweeklygoweekly2.0.01 of 1See more

goweekly goweekly 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
zufardhiyaulhaq/goweekly:v2.0.008dcc130fbea
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.12
0.53.0
1.25.10

Open the chart page →

1,229

Container images carrying it

4,694 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
stdlib@go1.18
1.25.10
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.53.0
1.25.10
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.16.10
0.53.0
1.25.10
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
stdlib@go1.25.5
0.53.0
1.25.10
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.15
0.53.0
1.25.10
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.53.0
1.25.10
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.53.0
1.25.10
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.53.0
1.25.10
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.53.0
1.25.10
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.53.0
1.25.10
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.25.10
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.19.2
0.53.0
1.25.10
3
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.25.10
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.25.10
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
stdlib@go1.21.5
0.53.0
1.25.10
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.10
0.53.0
1.25.10
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.9
0.53.0
1.25.10
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.53.0
1.25.10
3
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.53.0
1.25.10
3
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.25.10
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.53.0
1.25.10
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.53.0
1.25.10
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
stdlib@go1.25.9
1.25.10
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
3
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.53.0
1.25.10
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.53.0
1.25.10
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
3
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.53.0
1.25.10
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.53.0
1.25.10
3
quay.io/prometheus/prometheus:v3.10.07571a304e67f
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.53.0
1.25.10
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.53.0
1.25.10
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.53.0
1.25.10
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.53.0
1.25.10
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.53.0
1.25.10
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.53.0
1.25.10
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.53.0
1.25.10
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.53.0
1.25.10
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.53.0
1.25.10
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.53.0
1.25.10
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.53.0
1.25.10
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
3

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.