StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,058
of 17,790 indexed, latest versions
Container images
4,694
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,058 of 17,790 indexed charts deploy, on 4,694 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+179 more1.25.104,539
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,589
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,058 by stars
ChartLatestAffected imagesRadar Score
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.25.10

Open the chart page →

30,217
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
golang.org/x/net@v0.33.0
stdlib@go1.24.4
0.53.0
1.25.10
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
golang.org/x/net@v0.33.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

3,956
eg-universal-agent-operatoreg-universal-agent-operatorVerified publisher0.0.51 of 1See more

eg-universal-agent-operator eg-universal-agent-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

573
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,519
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
golang.org/x/net@v0.30.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

902
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.10

Open the chart page →

8,049
postgresqleks-storageclass0.1.01 of 1See more

postgresql eks-storageclass 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
stdlib@go1.24.6
1.25.10

Open the chart page →

1,649
elastic-agentelasticVerified publisher9.5.41 of 2See more

elastic-agent elastic 9.5.4

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

760
kube-state-metricselasticVerified publisher6.1.01 of 1See more

kube-state-metrics elastic 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

760
seafileeleksbai0.1.12 of 3See more

seafile eleksbai 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.692e50059ea0a
stdlib@go1.24.6
1.25.10
seafileltd/seafile-mc:9.0.106693911bcc40
stdlib@go1.19
1.25.10

Open the chart page →

25,263
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
stdlib@go1.23.12
1.25.10

Open the chart page →

2,968
elsaelsa0.1.01 of 4See more

elsa elsa 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/stakater/reloader:v1.4.4a571c5b32c0f
golang.org/x/net@v0.39.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

398
rabbitmqemberstackVerified publisher1.0.211 of 1See more

rabbitmq emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/rabbitmq:managementffd1b50c522a
stdlib@go1.22.2
1.25.10

Open the chart page →

1,045
emissary-ingressemissary-ingress4.1.01 of 1See more

emissary-ingress emissary-ingress 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

955
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10

Open the chart page →

2,837
parrot-mirroremmas-chartsVerified publisher1.0.01 of 1See more

parrot-mirror emmas-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

2,243
cost-reportempathyco0.7.81 of 1See more

cost-report empathyco 0.7.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
empathyco/cost-report:0.0.124f1e26eaacbf
stdlib@go1.15.15
1.25.10

Open the chart page →

1,167
deadman-switchempathyco0.0.21 of 1See more

deadman-switch empathyco 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
stdlib@go1.16.3
1.25.10

Open the chart page →

1,258
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.25.10

Open the chart page →

10,610
yace-exporterempathyco0.1.01 of 1See more

yace-exporter empathyco 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
stdlib@go1.17.3
1.25.10

Open the chart page →

1,642
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
stdlib@go1.19.10
0.53.0
1.25.10

Open the chart page →

1,329
kube-ecp-stackemqx-operator2.5.111 of 16See more

kube-ecp-stack emqx-operator 2.5.1

11 of the 16 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
golang.org/x/net@v0.23.0
stdlib@go1.23.3
0.53.0
1.25.10
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/net@v0.30.0
stdlib@go1.22.0
0.53.0
1.25.10
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.53.0
1.25.10
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.53.0
1.25.10
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.1e2dc5623bcdd
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.53.0
1.25.10

Open the chart page →

23,813
cnpg-monitoringenixVerified publisher0.3.01 of 1See more

cnpg-monitoring enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

824
kube-packetloss-exporterenixVerified publisher0.2.12 of 2See more

kube-packetloss-exporter enix 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.53.0
1.25.10
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.53.0
1.25.10

Open the chart page →

6,165
mariadb-operator-monitoringenixVerified publisher0.1.01 of 1See more

mariadb-operator-monitoring enix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

738
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10

Open the chart page →

3,963
network-exporterenixVerified publisher0.3.01 of 1See more

network-exporter enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
syepes/network_exporter:1.8.000af1691570e
golang.org/x/net@v0.39.0
stdlib@go1.25.1
0.53.0
1.25.10

Open the chart page →

1,372
zfs-exporterenixVerified publisher2.2.01 of 1See more

zfs-exporter enix 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/enix/zfs-exporter:2.3.1223b053f1cbd0
golang.org/x/net@v0.47.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

977
ai-gateway-helmenvoy-ai-gateway0.0.0-003ab39f36923b5d40609a601e2951b73f6318fb1 of 1See more

ai-gateway-helm envoy-ai-gateway 0.0.0-003ab39f36923b5d40609a601e2951b73f6318fb

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

863
eoapi-supporteoapiVerified publisher0.1.76 of 7See more

eoapi-support eoapi 0.1.7

6 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:10.3.38640e5038e83
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

8,667
backendeoc-chartsVerified publisher0.1.01 of 1See more

backend eoc-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/http-echo:latestfcb75f691c8b
stdlib@go1.21.1
1.25.10

Open the chart page →

550
databaseeoc-chartsVerified publisher0.1.01 of 1See more

database eoc-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:14-alpine727876d27466
stdlib@go1.24.6
1.25.10

Open the chart page →

494
mariadbeoc-chartsVerified publisher0.3.141 of 1See more

mariadb eoc-charts 0.3.14

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.25.10

Open the chart page →

5,153
umbrella-appeoc-chartsVerified publisher0.1.02 of 3See more

umbrella-app eoc-charts 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/http-echo:latestfcb75f691c8b
stdlib@go1.21.1
1.25.10
library/postgres:14-alpine727876d27466
stdlib@go1.24.6
1.25.10

Open the chart page →

1,078
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.25.10
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.25.10

Open the chart page →

27,361
eoloPlanteolo-plannerVerified publisher0.1.03 of 7See more

eoloPlant eolo-planner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.53.0
1.25.10
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

27,702
eoloplannereoloplannerVerified publisher0.1.03 of 7See more

eoloplanner eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

32,372
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.03 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.53.0
1.25.10
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

27,702
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.25.10
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.25.10

Open the chart page →

27,327
eoloplannereoloplanner-molynx-gat0.1.03 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

28,549
eolo-plannereolo-planner-repo0.1.03 of 7See more

eolo-planner eolo-planner-repo 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

27,197
eoloplanteoloplant1.0.03 of 7See more

eoloplant eoloplant 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.53.0
1.25.10
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

27,702
eoloplantseoloplants-urjcVerified publisher0.1.03 of 7See more

eoloplants eoloplants-urjc 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

27,822
servereoloserverVerified publisher0.1.03 of 7See more

server eoloserver 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.25.10
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.25.10

Open the chart page →

32,372
download-from-github-repoeosc-lot-1Verified publisher0.1.01 of 2See more

download-from-github-repo eosc-lot-1 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
golang.org/x/net@v0.15.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

992
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/git:v2.49.1c0280cf95723
golang.org/x/net@v0.45.0
stdlib@go1.24.8
0.53.0
1.25.10

Open the chart page →

9,402
mariadbeosc-lot-1Verified publisher0.2.01 of 2See more

mariadb eosc-lot-1 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
stdlib@go1.24.6
1.25.10

Open the chart page →

2,458
mariadb-backupeosc-lot-1Verified publisher0.5.01 of 2See more

mariadb-backup eosc-lot-1 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
stdlib@go1.24.6
1.25.10

Open the chart page →

2,458
mariadb-run-scripteosc-lot-1Verified publisher0.3.01 of 1See more

mariadb-run-script eosc-lot-1 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
stdlib@go1.24.6
1.25.10

Open the chart page →

2,458
postgresql-backupeosc-lot-1Verified publisher0.4.21 of 2See more

postgresql-backup eosc-lot-1 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.25.10

Open the chart page →

1,467

Container images carrying it

4,694 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.53.0
1.25.10
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.53.0
1.25.10
3
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.53.0
1.25.10
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.53.0
1.25.10
3
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.53.0
1.25.10
3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.53.0
1.25.10
3
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.16.8
0.53.0
1.25.10
2
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.25.10
2
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/net@v0.33.0
stdlib@go1.24.13
0.53.0
1.25.10
2
alpine/git:2.47.2062a01ad7a0e
golang.org/x/net@v0.23.0
stdlib@go1.23.9
0.53.0
1.25.10
2
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
2
alpine/kubectl:1.35.49ccd82364762
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.53.0
1.25.10
2
alpine/kubectl:1.35.2ec8f734b0a10
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.53.0
1.25.10
2
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.53.0
1.25.10
2
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10
2
apecloud/apecloud-mcp:0.1.094041b080510
stdlib@go1.23.7
1.25.10
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
2
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.53.0
1.25.10
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.9
0.53.0
1.25.10
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.53.0
1.25.10
2
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.53.0
1.25.10
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.6
0.53.0
1.25.10
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.53.0
1.25.10
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
stdlib@go1.23.7
1.25.10
2
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
stdlib@go1.15.1
1.25.10
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.25.10
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.25.10
2
bitnamilegacy/redis:latest5927ff3702df
stdlib@go1.24.5
1.25.10
2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
stdlib@go1.24.6
1.25.10
2
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.25.10
2
bitnamisecure/git72ae5bd9715f
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.53.0
1.25.10
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.53.0
1.25.10
2
bloomberg/goldpinger:3.11.3a8ea8c61ff4c
golang.org/x/net@v0.49.0
0.53.0
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
stdlib@go1.24.4
1.25.10
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.53.0
1.25.10
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.53.0
1.25.10
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.5
0.53.0
1.25.10
2
clickhouse/clickhouse-server:24.2ed9640bfff07
stdlib@go1.19.10
1.25.10
2
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.25.10
2
coredns/coredns:1.13.19b9128672209
golang.org/x/net@v0.45.0
stdlib@go1.25.2
0.53.0
1.25.10
2
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.53.0
1.25.10
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.17.3
0.53.0
1.25.10
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.53.0
1.25.10
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.19.13
0.53.0
1.25.10
2
danielfm/aws-limits-exporter:0.6.07152b84e57cb
stdlib@go1.17.2
1.25.10
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.