StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,127
of 17,805 indexed, latest versions
Container images
4,734
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,127 of 17,805 indexed charts deploy, on 4,734 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+180 more1.25.104,576
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,613
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,127 by stars
ChartLatestAffected imagesRadar Score
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.25.10

Open the chart page →

14,036
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.7
0.53.0
1.25.10

Open the chart page →

2,569
owncastgeek-cookbookVerified publisher3.4.21 of 1See more

owncast geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gabekangas/owncast:0.0.797461aedb580
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

3,168
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.15.12
0.53.0
1.25.10

Open the chart page →

8,060
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.25.10

Open the chart page →

11,797
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.25.10

Open the chart page →

10,311
sambageek-cookbookVerified publisher6.2.21 of 1See more

samba geek-cookbook 6.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.25.10

Open the chart page →

2,318
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.25.10

Open the chart page →

13,335
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.13.15
0.53.0
1.25.10

Open the chart page →

15,924
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.5
0.53.0
1.25.10

Open the chart page →

5,132
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latest20fde516ce31
stdlib@go1.24.1
1.25.10

Open the chart page →

4,953
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.25.10

Open the chart page →

7,723
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.33 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

3 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.8512bb8a21483
stdlib@go1.19.10
1.25.10
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.25.10
minio/minio:latest14cea493d9a3
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

15,831
geo-checkergeo-checkerVerified publisher5.0.01 of 1See more

geo-checker geo-checker 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ymuski/geo-checker:5.0.05ba7fd8c7bdc
stdlib@go1.25.3
1.25.10

Open the chart page →

1,460
gigapipegigapipeVerified publisher0.3.01 of 1See more

gigapipe gigapipe 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/metrico/gigapipe:v4.1.6caeb2652ce5e
stdlib@go1.26.2
1.25.10

Open the chart page →

658
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.25.10

Open the chart page →

6,483
gitea-sonarqube-botgitea-sonarqube-botOfficialVerified publisher0.4.01 of 1See more

gitea-sonarqube-bot gitea-sonarqube-bot 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

1,146
github-stsgithub-sts-helm0.0.41 of 1See more

github-sts github-sts-helm 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/depthmark/github-sts:0.0.31de580f136a9
stdlib@go1.26.2
1.25.10

Open the chart page →

150
prometheus-kafka-exportergkarthiks0.1.31 of 1See more

prometheus-kafka-exporter gkarthiks 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:latesta51b280b55a7
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

431
temporalglasskubeVerified publisher0.45.2-gk.110 of 14See more

temporal glasskube 0.45.2-gk.1

10 of the 14 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.53.0
1.25.10
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
golang.org/x/net@v0.27.0
stdlib@go1.22.3
0.53.0
1.25.10
temporalio/server:1.25.08a5798191dea
golang.org/x/net@v0.28.0
stdlib@go1.22.3
0.53.0
1.25.10
temporalio/ui:2.30.25c2a3645d09c
golang.org/x/net@v0.28.0
stdlib@go1.22.1
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

16,414
go-hello-world-chartgo-hello-worldVerified publisher1.8.31 of 1See more

go-hello-world-chart go-hello-world 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/wasilak/go-hello-world:1.8.366d353e7693f
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

767
gomenhashaigomenhashaiOfficialVerified publisher1.3.41 of 1See more

gomenhashai gomenhashai 1.3.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/gomenhashai/gomenhashai:v1.3.36f031172a5ec
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.53.0
1.25.10

Open the chart page →

642
gorse-enterprisegorse-io0.4.23 of 5See more

gorse-enterprise gorse-io 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10

Open the chart page →

4,437
meta-monitoringgrafana1.3.02 of 2See more

meta-monitoring grafana 1.3.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.53.0
1.25.10
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.10

Open the chart page →

3,603
phlaregrafana0.5.41 of 1See more

phlare grafana 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/phlare:0.5.1330f990cdad9
golang.org/x/net@v0.5.0
stdlib@go1.19.6
0.53.0
1.25.10

Open the chart page →

2,091
greenkubegreenkubeVerified publisher0.3.01 of 3See more

greenkube greenkube 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
stdlib@go1.24.6
1.25.10

Open the chart page →

1,856
armada-operatorgresearch0.7.02 of 2See more

armada-operator gresearch 0.7.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gresearch/armada-operator:latest6c43743e2b2d
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.53.0
1.25.10
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10

Open the chart page →

1,583
carettagroundcover0.0.163 of 3See more

caretta groundcover 0.0.16

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18
0.53.0
1.25.10
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.53.0
1.25.10
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

6,818
ghostgroundhog2k0.212.131 of 1See more

ghost groundhog2k 0.212.13

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/ghost:6.64.0a31d03f1f629
stdlib@go1.24.6
1.25.10

Open the chart page →

2,007
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.4b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

4,226
oscargrycapOfficialVerified publisher4.1.31 of 2See more

oscar grycap 4.1.3

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/grycap/oscar:latest0c58ff972451
golang.org/x/net@v0.51.0
0.53.0

Open the chart page →

432
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
stdlib@go1.21.13
1.25.10

Open the chart page →

10,215
terraform-cloud-operatorhashicorpVerified publisher2.5.02 of 2See more

terraform-cloud-operator hashicorp 2.5.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
golang.org/x/net@v0.24.0
stdlib@go1.22.4
0.53.0
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.18.0754ab2a723c8
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

1,478
hawkhawk1.1.53 of 4See more

hawk hawk 1.1.5

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.17.9
0.53.0
1.25.10
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.25.10
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
golang.org/x/net@v0.19.0
stdlib@go1.20.11
0.53.0
1.25.10

Open the chart page →

13,743
clickstackhdx-oss-v21.1.11 of 5See more

clickstack hdx-oss-v2 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:5.0.32-focal3b6c281e1c08
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.53.0
1.25.10

Open the chart page →

4,775
headscale-uiheadscale-uiVerified publisher0.2.91 of 1See more

headscale-ui headscale-ui 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
golang.org/x/net@v0.42.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

1,502
guacamolehelmforgeVerified publisher1.5.22 of 5See more

guacamole helmforge 1.5.2

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
stdlib@go1.24.6
1.25.10
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.25.10

Open the chart page →

9,052
mariadbhelmforgeVerified publisher2.1.11 of 1See more

mariadb helmforge 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:12.3.3dd9b303aed4f
stdlib@go1.24.6
1.25.10

Open the chart page →

1,948
matomohelmforgeVerified publisher2.3.01 of 3See more

matomo helmforge 2.3.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:9.7.2b2cf29815e62
stdlib@go1.24.6
1.25.10

Open the chart page →

2,796
uptime-kumahelmforgeVerified publisher1.5.131 of 1See more

uptime-kuma helmforge 1.5.13

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
stdlib@go1.20.5
1.25.10

Open the chart page →

30,618
velerohelmforgeVerified publisher1.4.101 of 2See more

velero helmforge 1.4.10

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
velero/velero-plugin-for-aws:v1.14.07e82f717f44e
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

1,462
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.53.0
1.25.10

Open the chart page →

4,247
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.12
0.53.0
1.25.10

Open the chart page →

6,987
spirehelm-spireVerified publisher0.30.23 of 10See more

spire helm-spire 0.30.2

3 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.53.0
1.25.10
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
golang.org/x/net@v0.42.0
stdlib@go1.25.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

1,688
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
golang.org/x/net@v0.15.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

16,765
hiverhiverVerified publisher0.1.459 of 10See more

hiver hiver 0.1.45

9 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hiversh/antigravity:0.1.45-microvm0e36d98402bc
stdlib@go1.19.8
1.25.10
hiversh/browser:0.1.45-microvmb5048c6342ce
stdlib@go1.19.8
1.25.10
hiversh/claude:0.1.45-microvm2fbf9f264498
stdlib@go1.19.8
1.25.10
hiversh/codex:0.1.45-microvm4f43130f51e5
stdlib@go1.19.8
1.25.10
hiversh/controller:0.1.45b0b85f8942c7
stdlib@go1.19.8
1.25.10
hiversh/copilot:0.1.45-microvm50c07b84f298
stdlib@go1.19.8
1.25.10
hiversh/node:0.1.45-alpine-microvm836a37641941
stdlib@go1.19.8
1.25.10
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
stdlib@go1.19.8
1.25.10
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
stdlib@go1.19.8
1.25.10

Open the chart page →

22,224
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.53.0
1.25.10

Open the chart page →

2,921
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.25.10

Open the chart page →

6,818
honeycombhoneycomb1.9.31 of 1See more

honeycomb honeycomb 1.9.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
honeycombio/honeycomb-kubernetes-agent:2.7.448c38d0870f2
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.53.0
1.25.10

Open the chart page →

437
hpe-greenlake-file-csi-driverhpe-storageVerified publisher2.6.45 of 7See more

hpe-greenlake-file-csi-driver hpe-storage 2.6.4

5 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

6,261

Container images carrying it

4,734 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/douban/qiniu-exporter:maind1da3bcfad7d
stdlib@go1.19.5
1.25.10
1
ghcr.io/douban/ucloud-exporter:mainb4bb8a9021a2
stdlib@go1.24.2
1.25.10
1
ghcr.io/douban/upyun-exporter:main6810900c9c4a
stdlib@go1.25.5
1.25.10
1
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.53.0
1.25.10
1
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
golang.org/x/net@v0.35.0
0.53.0
1
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.53.0
1.25.10
1
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
stdlib@go1.16.12
1.25.10
1
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
stdlib@go1.22.2
1.25.10
1
ghcr.io/edgelesssys/continuum/continuum-proxy24c76f294a80
golang.org/x/net@v0.32.0
stdlib@go1.23.3
0.53.0
1.25.10
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.53.0
1.25.10
1
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
stdlib@go1.26.1
1.25.10
1
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
ghcr.io/element-hq/ess-helm/matrix-tools:0.3.20eac0521be29
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.53.0
1.25.10
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
stdlib@go1.19.8
1.25.10
1
ghcr.io/eminaktas/oom-tracer:v0.1.0c90ca8389c87
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.53.0
1.25.10
1
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/emqx/emqx-operator:2.3.23333ed546165
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/eosc-lot-1/logrotate:3-alpineb0e20d200f89
stdlib@go1.22.4
1.25.10
1
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.20
0.53.0
1.25.10
1
ghcr.io/erpc/erpc:0.0.49f5654f745d4c
golang.org/x/net@v0.36.0
stdlib@go1.23.9
0.53.0
1.25.10
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
ghcr.io/ethpandaops/benchmarkoor:latest5470b2ec3161
stdlib@go1.24.13
1.25.10
1
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/ethpandaops/syncoor:master233aa9808fc7
stdlib@go1.26.0
1.25.10
1
ghcr.io/eugenmayer/whatsmyip:0.0.14b6700cc0e2d
stdlib@go1.22.1
1.25.10
1
ghcr.io/eugenmayer/whoami-tls:0.1.0477be2d05aba
stdlib@go1.24.1
1.25.10
1
ghcr.io/eumel8/rancher-servicemonitor:0.2.1f34428cac187
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
1
ghcr.io/evilgn0me/ingressmonitorcontroller:v0.0.50bbfa4db14b9
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/exalsius/exalsius-operator:0.12.0d24a579a3c75
golang.org/x/net@v0.50.0
0.53.0
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.53.0
1.25.10
1
ghcr.io/external-secrets/external-secrets:v2.4.19440a40b3947
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
ghcr.io/external-secrets/external-secrets:v2.1.0ec40c3d9c48f
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.53.0
1.25.10
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.53.0
1.25.10
1
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.53.0
1.25.10
1
ghcr.io/ferretdb/ferretdb:2.7.05706414241eb
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.53.0
1.25.10
1
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
stdlib@go1.20.2
1.25.10
1
ghcr.io/firecrawl/firecrawl:2.11.35987ebe1dc85b0
golang.org/x/net@v0.41.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
stdlib@go1.24.6
1.25.10
1
ghcr.io/flanksource/facet:0.1.7237237038be15
stdlib@go1.23.12
1.25.10
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.53.0
1.25.10
1
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.53.0
1.25.10
1
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/flohansen/dasher-server:latest7cde8c3fa2d1
golang.org/x/net@v0.22.0
stdlib@go1.22.5
0.53.0
1.25.10
1
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.28.0
stdlib@go1.24.12
0.53.0
1.25.10
1
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
golang.org/x/net@v0.35.0
stdlib@go1.23.6
0.53.0
1.25.10
1
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
stdlib@go1.20.12
1.25.10
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.