StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,127
of 17,805 indexed, latest versions
Container images
4,734
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,127 of 17,805 indexed charts deploy, on 4,734 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,576
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,613
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,127 by stars
ChartLatestAffected imagesRadar Score
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
golang.org/x/net@v0.24.0
stdlib@go1.21.12
0.53.0
1.25.10

Open the chart page →

4,372
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
golang.org/x/net@v0.0.0-20210907225631-ff17edfbf26d
stdlib@go1.17.2
0.53.0
1.25.10

Open the chart page →

1,580
hybrid-csi-pluginhybrid-csi-plugin0.1.111 of 1See more

hybrid-csi-plugin hybrid-csi-plugin 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/hybrid-csi-provisioner:v0.3.1221e07794a8a
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

380
spoolmanideaplexusVerified publisher2.7.11 of 1See more

spoolman ideaplexus 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.25.10

Open the chart page →

1,848
idle-reaperidle-reaperVerified publisher0.1.41 of 1See more

idle-reaper idle-reaper 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/b100to/idle-reaper:0.1.447b4a0e091f0
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

148
backendikusi-bk-chart1.0.31 of 3See more

backend ikusi-bk-chart 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
stdlib@go1.24.6
1.25.10

Open the chart page →

6,140
ilum-coreilumOfficialVerified publisher6.7.32 of 5See more

ilum-core ilum 6.7.3

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
stdlib@go1.20.12
0.53.0
1.25.10

Open the chart page →

3,559
ilum-jupyterilumVerified publisher6.7.31 of 2See more

ilum-jupyter ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamisecure/gitdigest-pinned72ae5bd9715f
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

645
odooimioVerified publisher3.1.01 of 3See more

odoo imio 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:17.10ebba4f4de37f
stdlib@go1.24.6
1.25.10

Open the chart page →

3,127
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.25.10

Open the chart page →

15,975
webhook-broker-chartimytech0.2.41 of 1See more

webhook-broker-chart imytech 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
golang.org/x/net@v0.33.0
stdlib@go1.23.0
0.53.0
1.25.10

Open the chart page →

1,253
inbucketinbucketVerified publisher2.5.01 of 1See more

inbucket inbucket 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
inbucket/inbucket:3.0.01f10a0efea69
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.1
0.53.0
1.25.10

Open the chart page →

2,168
telegraf-operatorinfluxdata1.4.01 of 1See more

telegraf-operator influxdata 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
golang.org/x/net@v0.17.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

925
valkey-clusterinnagoVerified publisher1.1.01 of 2See more

valkey-cluster innago 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.66.0d98e6db8094f
stdlib@go1.23.2
1.25.10

Open the chart page →

2,675
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

7,136
interlinkinterlink0.6.11 of 2See more

interlink interlink 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/interlink-hq/interlink/virtual-kubelet-inttw:latest0e05a7b49c33
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

2,494
irsa-managerirsa-managerVerified publisher0.3.21 of 1See more

irsa-manager irsa-manager 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kkb0318/irsa-manager:0.3.296d600ae97b4
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.53.0
1.25.10

Open the chart page →

821
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

74,740
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

74,815
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

74,761
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

74,761
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

75,013
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.15
0.53.0
1.25.10

Open the chart page →

1,820
kubernetes-event-exporteritakurahVerified publisher0.2.31 of 1See more

kubernetes-event-exporter itakurah 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/itakurah/kubernetes-event-exporter:v1.78abb52b66557
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.53.0
1.25.10

Open the chart page →

1,142
jessejesse-chartVerified publisher0.0.461 of 6See more

jesse jesse-chart 0.0.46

1 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:alpined3e1620b530c
stdlib@go1.24.6
1.25.10

Open the chart page →

3,441
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

9,351
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

7,447
job-manager-dispatcherjob-manager-dispatcher1.27.01 of 1See more

job-manager-dispatcher job-manager-dispatcher 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.53.0
1.25.10

Open the chart page →

479
job-manager-serverjob-manager-server1.27.01 of 1See more

job-manager-server job-manager-server 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-server:1.27.0fe9de719f91e
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.53.0
1.25.10

Open the chart page →

757
hncjouveVerified publisher0.8.31 of 1See more

hnc jouve 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-multitenancy/hnc-manager:v1.1.08ab8229f6a89
golang.org/x/net@v0.3.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

1,078
joylive-injectorjoyliveOfficialVerified publisher1.3.51 of 2See more

joylive-injector joylive 1.3.5

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
otel/opentelemetry-collector:0.100.09e36620d6c2c
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.53.0
1.25.10

Open the chart page →

1,290
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/net@v0.11.0
stdlib@go1.18.7
0.53.0
1.25.10

Open the chart page →

3,381
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.3213 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

13 of the 17 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/alloy:v1.14.0f50931848bd8
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
grafana/grafana:12.3.12175aaa91c96
golang.org/x/net@v0.46.0
stdlib@go1.25.5
0.53.0
1.25.10
grafana/loki:3.6.73c8fd3570dd9
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
grafana/tempo:2.9.065a578975943
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.53.0
1.25.10
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.53.0
1.25.10
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.89.0cb4ac6a56555
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.31.188b605de9aba
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.10.07571a304e67f
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

15,794
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
golang.org/x/net@v0.38.0
stdlib@go1.24.7
0.53.0
1.25.10

Open the chart page →

5,595
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

5,875
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
stdlib@go1.20.7
1.25.10

Open the chart page →

5,287
keycloakkeycloak1.13.71 of 2See more

keycloak keycloak 1.13.7

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.gitlab.com/lenitech/docker/keycloak-ppolicy:0.6.09895d6915075
golang.org/x/net@v0.46.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

349
keycloak-client-operatorkeycloak-client-operator0.9.11 of 1See more

keycloak-client-operator keycloak-client-operator 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

521
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.25.10

Open the chart page →

5,324
giteakeyporttech0.2.102 of 4See more

gitea keyporttech 0.2.10

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gitea/gitea:1.12.485416d6f65fe
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.8
0.53.0
1.25.10
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.25.10

Open the chart page →

5,409
kikplatekikplateVerified publisher0.22.01 of 3See more

kikplate kikplate 0.22.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
stdlib@go1.24.6
1.25.10

Open the chart page →

2,979
glpikitsune-itopsVerified publisher1.0.71 of 3See more

glpi kitsune-itops 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:latestdd9b303aed4f
stdlib@go1.24.6
1.25.10

Open the chart page →

5,005
kokukokuVerified publisher1.0.03 of 7See more

koku koku 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/mc:latesta7fe349ef4bd
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.53.0
1.25.10
public.ecr.aws/v0r6c2e2/minio:latest08c90bd040bf
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
stdlib@go1.23.0
1.25.10

Open the chart page →

12,237
komkomVerified publisher0.3.01 of 1See more

kom kom 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kkb0318/kom:0.3.04e77eff2d906
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

398
kronos-corekronos-coreVerified publisher0.4.11 of 2See more

kronos-core kronos-core 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kronosorg/kronos-core:v0.4.0301da21c59a5
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

544
kubeadaptkubeadaptVerified publisher1.0.71 of 1See more

kubeadapt kubeadapt 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-agent:v3.0.1d75b6da94913
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

214
cert-managerkubeblocksVerified publisher1.17.24 of 4See more

cert-manager kubeblocks 1.17.2

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.17.2ec56edb1161d
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.53.0
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.17.2e18989b4f912
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.53.0
1.25.10

Open the chart page →

2,928
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
golang.org/x/net@v0.20.0
stdlib@go1.20.6
0.53.0
1.25.10

Open the chart page →

20,617
ks-corekubeblocksVerified publisher1.1.32 of 5See more

ks-core kubeblocks 1.1.3

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubesphere/ks-extensions-museum:latest29681958f220
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.53.0
1.25.10
kubesphere/kubectl:v1.27.1649b445b1b732
golang.org/x/net@v0.23.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

4,741
kubebrowsekubebrowse1.7.03 of 5See more

kubebrowse kubebrowse 1.7.0

3 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.53.0
1.25.10
ghcr.io/browsersec/kubebrowse:sha-09dfa1fb853e9e6372a
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.53.0
1.25.10
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.53.0
1.25.10

Open the chart page →

4,302

Container images carrying it

4,734 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/crazy-max/diun:4.19.0c94e32b888e4
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.5
0.53.0
1.25.10
1
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.25.10
1
ghcr.io/cronschedules/cronjob-scale-down-operator:0.4.41c4e803d7169
golang.org/x/net@v0.52.0
stdlib@go1.25.0
0.53.0
1.25.10
1
ghcr.io/csepulveda/trivy-webhook-aws-security-hub:v0.1.206836b779b060
golang.org/x/net@v0.50.0
stdlib@go1.26.2
0.53.0
1.25.10
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10
1
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.4
0.53.0
1.25.10
1
ghcr.io/danieldonoghue/vault-sync-operator:v0.0.1-beta.38d7ec69a193c
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.53.0
1.25.10
1
ghcr.io/daocloud/crproxy/crproxy:v0.8.0ee1eb3c9c9a1
golang.org/x/net@v0.26.0
stdlib@go1.21.11
0.53.0
1.25.10
1
ghcr.io/dapr/injector:1.17.0-rc.37a2fd888ed5f
golang.org/x/net@v0.48.0
stdlib@go1.24.11
0.53.0
1.25.10
1
ghcr.io/dapr/operator:1.17.0-rc.3d5cc61cbe735
golang.org/x/net@v0.48.0
stdlib@go1.24.11
0.53.0
1.25.10
1
ghcr.io/dapr/placement:1.17.0-rc.3a237b43cd5c6
golang.org/x/net@v0.48.0
stdlib@go1.24.11
0.53.0
1.25.10
1
ghcr.io/dapr/scheduler:1.17.0-rc.36c62e01e736b
golang.org/x/net@v0.48.0
stdlib@go1.24.11
0.53.0
1.25.10
1
ghcr.io/dapr/sentry:1.17.0-rc.3bf79b03591e0
golang.org/x/net@v0.48.0
stdlib@go1.24.11
0.53.0
1.25.10
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
1
ghcr.io/davidkarlsen/flyway-operator:0.2.1366f60b461c0d
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
1
ghcr.io/dcristobalhmad/kube-secrets-exporter:latesta9043737cb73
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.53.0
1.25.10
1
ghcr.io/debridmediamanager/zurg-testing:v0.9.3-final5c47ef99443a
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.53.0
1.25.10
1
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.6
0.53.0
1.25.10
1
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.53.0
1
ghcr.io/defensia/agent:1.4.57e9d40ae44711
golang.org/x/net@v0.47.0
0.53.0
1
ghcr.io/deliveryhero/field-exporter:v1.4.06b71ba4f9297
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.53.0
1.25.10
1
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
golang.org/x/net@v0.48.0
0.53.0
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
stdlib@go1.24.4
1.25.10
1
ghcr.io/depthmark/github-sts:0.0.31de580f136a9
stdlib@go1.26.2
1.25.10
1
ghcr.io/desuuuu/cluster-network-policy-operator:v1.1.0d943d13c5281
stdlib@go1.26.0
1.25.10
1
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
golang.org/x/net@v0.25.0
stdlib@go1.20.14
0.53.0
1.25.10
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
stdlib@go1.25.4
1.25.10
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.53.0
1.25.10
1
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.17
0.53.0
1.25.10
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
stdlib@go1.16.6
1.25.10
1
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
golang.org/x/net@v0.37.0
stdlib@go1.24.3
0.53.0
1.25.10
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.2
0.53.0
1.25.10
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.53.0
1.25.10
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/net@v0.11.0
stdlib@go1.19.6
0.53.0
1.25.10
1
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/dirien/minecraft-exporter:0.24.061d89bf99ff7
golang.org/x/net@v0.51.0
0.53.0
1
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
stdlib@go1.17.5
0.53.0
1.25.10
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/net@v0.10.0
stdlib@go1.21.0
0.53.0
1.25.10
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.25.10
1
ghcr.io/dntosas/capi2argo-cluster-operator:v1.5.0fb8c6457ef6e
golang.org/x/net@v0.40.0
stdlib@go1.25.6
0.53.0
1.25.10
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.53.0
1.25.10
1
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
stdlib@go1.18.1
1.25.10
1
ghcr.io/donkie/spoolman:0.24.042135965c42d
stdlib@go1.19.8
1.25.10
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.8
0.53.0
1.25.10
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.16.15
0.53.0
1.25.10
1
ghcr.io/doodlescheduling/saml-exporter:v0.5.03d5a99841bc2
stdlib@go1.22.3
1.25.10
1
ghcr.io/douban/aliyun-exporter:mainb7c694331362
stdlib@go1.24.2
1.25.10
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.