StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,127
of 17,805 indexed, latest versions
Container images
4,734
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,127 of 17,805 indexed charts deploy, on 4,734 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,576
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,613
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,127 by stars
ChartLatestAffected imagesRadar Score
wharf-ainowharf-helmVerified publisher0.1.55 of 7See more

wharf-aino wharf-helm 0.1.5

5 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18.1
0.53.0
1.25.10
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.53.0
1.25.10
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.53.0
1.25.10
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.53.0
1.25.10
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.53.0
1.25.10

Open the chart page →

13,487
wharf-cmdwharf-helmVerified publisher0.3.31 of 1See more

wharf-cmd wharf-helm 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.53.0
1.25.10

Open the chart page →

3,436
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.53.0
1.25.10

Open the chart page →

56,254
external-monitoringwiremindVerified publisher0.3.01 of 1See more

external-monitoring wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

1,301
kubemodwiremindVerified publisher0.1.51 of 2See more

kubemod wiremind 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.13.0cadca39288ad
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.14.7
0.53.0
1.25.10

Open the chart page →

3,031
db-backup-retentionwjentner-chartsVerified publisher1.1.01 of 1See more

db-backup-retention wjentner-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/wjentner/k8s-db-backup-retention:v1.1.08027bb46d1f4
golang.org/x/net@v0.26.0
stdlib@go1.23.5
0.53.0
1.25.10

Open the chart page →

1,044
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

7,842
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:885b9bf2e29cf
stdlib@go1.24.6
1.25.10

Open the chart page →

8,409
workflows-informerworkflows-informerVerified publisher0.4.41 of 1See more

workflows-informer workflows-informer 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.53.0
1.25.10

Open the chart page →

1,181
wraftwraft0.1.124 of 9See more

wraft wraft 0.1.12

4 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:14-alpine727876d27466
stdlib@go1.24.6
1.25.10
minio/mc:latesta7fe349ef4bd
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.53.0
1.25.10
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
golang.org/x/net@v0.12.0
stdlib@go1.19.11
0.53.0
1.25.10
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
stdlib@go1.23.10
1.25.10

Open the chart page →

10,324
pi-hole-exporterwyrihaximusnetVerified publisher0.1.31 of 1See more

pi-hole-exporter wyrihaximusnet 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ekofr/pihole-exporter:0.0.109fdad6f352e0
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.7
0.53.0
1.25.10

Open the chart page →

1,810
redis-db-assignment-operatorwyrihaximusnetVerified publisher1.0.61 of 1See more

redis-db-assignment-operator wyrihaximusnet 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/kubernetes-redis-db-assignment-operator:v1.0.831060be60bec
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

2,236
x402-k8s-operatorx402-k8s-operator0.1.01 of 2See more

x402-k8s-operator x402-k8s-operator 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/razvanmacovei/x402-k8s-operator:0.1.0bf3407fad182
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

272
prometheusalertxxl-job-adminVerified publisher1.4.01 of 1See more

prometheusalert xxl-job-admin 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.28192368b0578
golang.org/x/net@v0.24.0
stdlib@go1.20.6
0.53.0
1.25.10

Open the chart page →

1,116
heistyouniqx-ossVerified publisher1.1.2091 of 1See more

heist youniqx-oss 1.1.209

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/youniqx/heist:v1.1.209c43b3a9d98ae
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.53.0
1.25.10

Open the chart page →

806
yugawareyugabyteVerified publisher2026.1.11 of 3See more

yugaware yugabyte 2026.1.1

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:14.22eba8ddbdd837
stdlib@go1.24.6
1.25.10

Open the chart page →

2,690
tailscale-relayzeet0.1.51 of 1See more

tailscale-relay zeet 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
zeetdev/tailscale-relay:v1.24.21967aa2840b6
golang.org/x/net@v0.0.0-20220407224826-aac1ed45d8e3
stdlib@go1.18.1-ts710a0d8610
0.53.0
1.25.10

Open the chart page →

2,166
crowdsec-web-uizekker6Verified publisher0.51.01 of 1See more

crowdsec-web-ui zekker6 0.51.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
stdlib@go1.24.4
1.25.10

Open the chart page →

1,463
memoszekker6Verified publisher0.55.01 of 1See more

memos zekker6 0.55.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
neosmemo/memos:0.30.071a5b4738d1b
stdlib@go1.26.2
1.25.10

Open the chart page →

707
cloudflare-zero-trust-operatorzelic-io0.7.11 of 1See more

cloudflare-zero-trust-operator zelic-io 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bojanzelic/cloudflare-zero-trust-operator:0.7.1f4b2dbc19a78
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

591
mikochizer0tonin1.11.01 of 1See more

mikochi zer0tonin 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
zer0tonin/mikochi:1.11.009872bae1554
golang.org/x/net@v0.40.0
0.53.0

Open the chart page →

1,017
velero-notificationszokeber-velero-notificationsVerified publisher0.1.101 of 2See more

velero-notifications zokeber-velero-notifications 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/zokeber/velero-notifications:0.0.176d84f6c4ce20
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

729
backendzymtraceOfficialVerified publisher26.9.21 of 6See more

backend zymtrace 26.9.2

1 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:17.4304ab8135187
stdlib@go1.18.2
1.25.10

Open the chart page →

9,318
aaqaaqVerified publisher0.3.01 of 1See more

aaq aaq 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kubevirt/aaq-operator:v1.7.0d28a2daa5b15
golang.org/x/net@v0.47.0
stdlib@go1.24.12
0.53.0
1.25.10

Open the chart page →

1,017
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/abstract-foundation/zksync-external-node-sidecar:v1.0.03e705d0eb1ce
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

4,603
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

2,545
activepiecesadnoctemVerified publisher0.6.01 of 1See more

activepieces adnoctem 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
activepieces/activepieces:0.91.058414dfc94c4
stdlib@go1.23.5
1.25.10

Open the chart page →

1,069
gobackupadnoctemVerified publisher0.4.01 of 1See more

gobackup adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
huacnlee/gobackup:v3.1.1560be93229a5
golang.org/x/net@v0.47.0
stdlib@go1.20.12
0.53.0
1.25.10

Open the chart page →

1,843
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
stdlib@go1.23.7
1.25.10

Open the chart page →

3,888
popeyeadnoctemVerified publisher0.3.01 of 1See more

popeye adnoctem 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10

Open the chart page →

1,342
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
stdlib@go1.20.5
1.25.10

Open the chart page →

30,618
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,459
bootaerokube1.0.13 of 4See more

boot aerokube 1.0.1

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/aerokube/boot:1.0.13c269612053f
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.53.0
1.25.10
quay.io/aerokube/keygen:1.0.1578934444f04
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.53.0
1.25.10
quay.io/aerokube/reloader:1.0.1e4a3661416a5
stdlib@go1.22.2
1.25.10

Open the chart page →

7,964
browser-opsaerokube2.6.71 of 1See more

browser-ops aerokube 2.6.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/aerokube/browser-ops:2.6.7807c1bb67086
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.53.0
1.25.10

Open the chart page →

553
moonaerokube1.1.373 of 3See more

moon aerokube 1.1.37

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
aerokube/moon:1.9.17da76ca51220d
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
aerokube/moon-api:1.9.176b6323e75785
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
aerokube/selenoid-ui:1.10.113f3e299509fd
golang.org/x/net@v0.10.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

2,473
aerospike-backup-serviceaerospike-helmVerified publisher2.0.131 of 1See more

aerospike-backup-service aerospike-helm 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
aerospike/aerospike-backup-service:3.5.1be40d709c583
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

637
msockperfaetrius2.0.81 of 2See more

msockperf aetrius 2.0.8

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
stdlib@go1.22.1
1.25.10

Open the chart page →

4,296
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,220
agentgateway-route-reconcileragentgateway-route-reconciler0.3.11 of 1See more

agentgateway-route-reconciler agentgateway-route-reconciler 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/ricardozd/agentgateway-route-reconciler:0.3.1846f6e407c96
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

259
agentkube-operatoragentkube-operator0.3.01 of 1See more

agentkube-operator agentkube-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.53.0
1.25.10

Open the chart page →

1,734
mt-channel-brokerahhhhVerified publisher0.1.03 of 3See more

mt-channel-broker ahhhh 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/filterdigest-pinnedd675f211a40f
golang.org/x/net@v0.30.0
stdlib@go1.22.8
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/ingressdigest-pinnedec4b544499ba
golang.org/x/net@v0.30.0
stdlib@go1.22.8
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/eventing/cmd/mtchannel_brokerdigest-pinned395f4ff1bd34
golang.org/x/net@v0.30.0
stdlib@go1.22.8
0.53.0
1.25.10

Open the chart page →

2,628
net-istioahhhhVerified publisher0.1.12 of 2See more

net-istio ahhhh 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinnede70bc675f977
golang.org/x/net@v0.30.0
stdlib@go1.22.8
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned7d76a6d42d13
golang.org/x/net@v0.30.0
stdlib@go1.22.8
0.53.0
1.25.10

Open the chart page →

1,128
net-kourierahhhhVerified publisher0.18.11 of 1See more

net-kourier ahhhh 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned15a601147ef4
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

515
airbyte-keycloakairbyteVerified publisher0.1.21 of 2See more

airbyte-keycloak airbyte 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.10

Open the chart page →

1,688
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

4,998
airbyteairbyte-v2Verified publisher2.3.03 of 10See more

airbyte airbyte-v2 2.3.0

3 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
airbyte/db:2.3.000cc017f0393
stdlib@go1.24.6
1.25.10
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.53.0
1.25.10
temporalio/auto-setup:1.27.2b44cbfeb43db
golang.org/x/net@v0.34.0
stdlib@go1.23.2
0.53.0
1.25.10

Open the chart page →

12,149
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,559
airports-postgresairports-postgres0.1.01 of 1See more

airports-postgres airports-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10

Open the chart page →

1,027
akriakri0.12.551 of 3See more

akri akri 0.12.55

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.53.0
1.25.10

Open the chart page →

1,546
aktoakto0.2.01 of 7See more

akto akto 0.2.0

1 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

13,799

Container images carrying it

4,734 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.11
0.53.0
1.25.10
1
velero/velero-plugin-for-aws:v1.14.07e82f717f44e
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
1
venturenox/redis:latest83b471c193ba
stdlib@go1.22.9
1.25.10
1
venturenox/sagawise:latestc11d32f18718
stdlib@go1.22.2
1.25.10
1
versity/versitygw:v1.0.145192635d0353
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.53.0
1.25.10
1
versity/versitygw:v1.1.0f730e0dbc1ef
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.53.0
1.25.10
1
vespaengine/vespa:8.526.1569b160f58211
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
1
victoriametrics/operator:v0.65.0716b89a3ed79
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.53.0
1.25.10
1
victoriametrics/operator:v0.47.271be93cfafb6
golang.org/x/net@v0.26.0
stdlib@go1.23.0
0.53.0
1.25.10
1
victoriametrics/operator:v0.68.3f52e1bd679cb
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10
1
victoriametrics/victoria-logs:v1.15.0-victorialogsd7435244eb19
stdlib@go1.24.0
1.25.10
1
victoriametrics/victoria-metrics:v1.93.577a9815d0640
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.53.0
1.25.10
1
victoriametrics/victoria-metrics:v1.120.0a1cb2f3dfd45
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10
1
victoriametrics/victoria-metrics:v1.34.7b50d5c0153f9
stdlib@go1.14.1
1.25.10
1
victoriametrics/victoria-metrics:v1.95.1f52723a08a44
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.53.0
1.25.10
1
victoriametrics/vmalert:v1.96.0150cd08fde94
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
1
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.53.0
1.25.10
1
vikunja/api:0.17.18cba0520bf8c
golang.org/x/net@v0.0.0-20210505024714-0287a6fb4125
stdlib@go1.16.5
0.53.0
1.25.10
1
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
golang.org/x/net@v0.23.0
stdlib@go1.19.13
0.53.0
1.25.10
1
vmware/kube-fluentd-operator:latestf028c138a5f4
golang.org/x/net@v0.17.0
stdlib@go1.21.7
0.53.0
1.25.10
1
voidxmh/golang:1.19-alpine-dev423c6195fab2
stdlib@go1.19
1.25.10
1
voidxmh/xmh-auther:v193e42a569ca8
stdlib@go1.16.5
1.25.10
1
voidxmh/xmh-cacher:v11b7397412320
stdlib@go1.16.5
1.25.10
1
voidxmh/xmh-ui:v12ff3f2146547
stdlib@go1.16.5
1.25.10
1
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
stdlib@go1.13.6
1.25.10
1
volcanosh/vc-controller-manager:v1.12.13815883c32f6
golang.org/x/net@v0.38.0
stdlib@go1.23.7
0.53.0
1.25.10
1
volcanosh/vc-controller-manager:v1.15.26a6bc2560d51
stdlib@go1.25.0
1.25.10
1
volcanosh/vc-scheduler:v1.15.2afab36286a17
stdlib@go1.25.0
1.25.10
1
volcanosh/vc-scheduler:v1.12.1b24ea8af2d16
golang.org/x/net@v0.38.0
stdlib@go1.23.7
0.53.0
1.25.10
1
volcanosh/vc-webhook-manager:v1.15.22fff65aad011
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.53.0
1.25.10
1
volcanosh/vc-webhook-manager:v1.12.1f8b50088a732
golang.org/x/net@v0.30.0
stdlib@go1.23.7
0.53.0
1.25.10
1
voltha/bbsim:1.16.7d90403d58016
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.13.8
0.53.0
1.25.10
1
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.53.0
1.25.10
1
voltha/bbsim-sadis-server:0.4.0762b272d439e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.53.0
1.25.10
1
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.53.0
1.25.10
1
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.7
0.53.0
1.25.10
1
vultr/vultr-csi:v0.3.041d26735d437
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16.8
0.53.0
1.25.10
1
wagnermanganelli164/webserver-hello-world:0.3.0d4ef27a4f180
stdlib@go1.22.5
1.25.10
1
wait4x/wait4x:3.3.14dcd86307de1
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
1
wallarm/aih-scanner:2.7.11f1cb26db1f5b
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.53.0
1.25.10
1
wallarm/aih-webhook:2.7.116363a9cd2ad8
stdlib@go1.26.2
1.25.10
1
wallarm/api-firewall:v0.9.64d45db0ff240
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.53.0
1.25.10
1
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
1
wallarm/gateway-control-plane:0.2.0a321bc974a19
stdlib@go1.24.13
1.25.10
1
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.53.0
1.25.10
1
wallarm/ingress-controller:4.8.0-1a591b9c91570
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.53.0
1.25.10
1
wallarm/ingress-python:4.6.0-15cb2ae08b40f
stdlib@go1.18.2
1.25.10
1
wallarm/ingress-ruby:4.2.1-195ea2632326c
stdlib@go1.18.3
1.25.10
1
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
stdlib@go1.18.3
1.25.10
1
wallarm/kong-kubernetes-ingress-controller:2.8b55ff6cecbd5
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.