StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,155
of 17,813 indexed, latest versions
Container images
4,778
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,155 of 17,813 indexed charts deploy, on 4,778 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,618
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,640
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,155 by stars
ChartLatestAffected imagesRadar Score
miniobysamioVerified publisher1.0.31 of 1See more

minio bysamio 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

1,201
caddycaddyVerified publisher0.0.41 of 1See more

caddy caddy 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/caddy:2.11.2-alpine834468128c76
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.53.0
1.25.10

Open the chart page →

1,706
etcdcagriekinVerified publisher0.1.51 of 1See more

etcd cagriekin 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.16d967d98a12dc
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.53.0
1.25.10

Open the chart page →

907
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.53.0
1.25.10

Open the chart page →

2,403
rediscagriekinVerified publisher1.5.21 of 2See more

redis cagriekin 1.5.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.67.0120f7ec77293
stdlib@go1.23.4
1.25.10

Open the chart page →

1,426
ct-singlecalltelemetry0.8.44 of 7See more

ct-single calltelemetry 0.8.4

4 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.25.10
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.1
0.53.0
1.25.10
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.25.10
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.25.10

Open the chart page →

10,701
stablecalltelemetry0.7.14 of 9See more

stable calltelemetry 0.7.1

4 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.25.10
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.1
0.53.0
1.25.10
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.25.10
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.25.10

Open the chart page →

7,705
stable-hacalltelemetry0.11.43 of 7See more

stable-ha calltelemetry 0.11.4

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats:2.10.12-alpinebca70839d953
stdlib@go1.21.8
1.25.10
natsio/nats-box:0.14.2e808e0644ce1
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
natsio/nats-server-config-reloader:0.14.10d50270fa374
stdlib@go1.20.5
1.25.10

Open the chart page →

4,706
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:5.0fc5ecd863862
stdlib@go1.16.7
1.25.10

Open the chart page →

8,117
geoservercamptocamp20.0.31 of 12See more

geoserver camptocamp2 0.0.3

1 of the 12 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.25.10

Open the chart page →

88,806
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.5
0.53.0
1.25.10

Open the chart page →

4,527
getconfigcamptocamp30.1.11 of 1See more

getconfig camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

2,202
prometheus-puppetdb-sdcamptocamp38.0.21 of 2See more

prometheus-puppetdb-sd camptocamp3 8.0.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/prometheus-puppetdb-sd:0.14.0414c0c99fd06
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10

Open the chart page →

6,189
redisoperatorcamptocamp33.0.11 of 1See more

redisoperator camptocamp3 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/spotahome/redis-operator:latest8c772955184e
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

1,194
s3-exportercamptocamp32.2.01 of 1See more

s3-exporter camptocamp3 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ribbybibby/s3-exporter:v0.5.0998184c51a00
stdlib@go1.15.15
1.25.10

Open the chart page →

1,184
snyk-exportercamptocamp30.1.41 of 1See more

snyk-exporter camptocamp3 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/lunarway/snyk_exporter:v1.11.155e5cc5aaa0a
stdlib@go1.17.7
1.25.10

Open the chart page →

1,080
ssl-exportercamptocamp30.1.01 of 1See more

ssl-exporter camptocamp3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/net@v0.0.0-20220708220712-1185a9018129
stdlib@go1.18.3
0.53.0
1.25.10

Open the chart page →

1,633
terraboardcamptocamp32.4.01 of 1See more

terraboard camptocamp3 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,337
caninecanine0.1.105 of 7See more

canine canine 0.1.10

5 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.53.0
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

14,429
cert-managercanine1.15.34 of 4See more

cert-manager canine 1.15.3

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

2,909
capi2argo-cluster-operatorcapi2argo1.5.01 of 1See more

capi2argo-cluster-operator capi2argo 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dntosas/capi2argo-cluster-operator:v1.5.0fb8c6457ef6e
golang.org/x/net@v0.40.0
stdlib@go1.25.6
0.53.0
1.25.10

Open the chart page →

281
capsule-argo-addoncapsule-argo-addonVerified publisher0.7.52 of 2See more

capsule-argo-addon capsule-argo-addon 0.7.5

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
ghcr.io/peak-scale/capsule-argo-addon:0.7.5087a80163971
golang.org/x/net@v0.43.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

2,080
freebox-exportercaptnbpVerified publisher1.0.01 of 1See more

freebox-exporter captnbp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
captnbp/freebox-exporter:1.0.0-r01600c5a253e0
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

718
ranchercarbide-charts2.15.12 of 2See more

rancher carbide-charts 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
rancher/shell:v0.8.1f293af9c635f
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

1,534
stigatroncarbide-charts0.4.13 of 10See more

stigatron carbide-charts 0.4.1

3 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.25.10
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.53.0
1.25.10
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.25.10

Open the chart page →

4,425
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
casdoor-helm-chartscasdoor4.7.01 of 1See more

casdoor-helm-charts casdoor 4.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
casbin/casdoor:4.7.09d015582847d
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

963
cassandra-webcassandra-web0.1.01 of 1See more

cassandra-web cassandra-web 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ipushc/cassandra-web:latestfa3e0c66c289
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.53.0
1.25.10

Open the chart page →

1,302
castai-evictorcastaiVerified publisher0.35.1451 of 3See more

castai-evictor castai 0.35.145

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.35.64d8c68e8c2bf
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

144
castai-tetragoncastaiVerified publisher0.6.12 of 4See more

castai-tetragon castai 0.6.1

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.19.2
0.53.0
1.25.10
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.18.3
0.53.0
1.25.10

Open the chart page →

4,145
castware-componentscastaiVerified publisher0.4.01 of 1See more

castware-components castai 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

3,452
oci-csi-drivercastaiVerified publisher1.13.81 of 7See more

oci-csi-driver castai 1.13.8

1 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

1,775
temporalcastaiVerified publisher0.54.210 of 14See more

temporal castai 0.54.2

10 of the 14 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.53.0
1.25.10
temporalio/admin-tools:1.26.237e2e33dbd7b
golang.org/x/net@v0.31.0
stdlib@go1.22.5
0.53.0
1.25.10
temporalio/server:1.26.21e2626efcbc1
golang.org/x/net@v0.31.0
stdlib@go1.23.2
0.53.0
1.25.10
temporalio/ui:2.33.05c586a3c8ec5
golang.org/x/net@v0.17.0
stdlib@go1.23.0
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

16,271
catalyst-agentscatalyst-agents0.1.339 of 18See more

catalyst-agents catalyst-agents 0.1.33

9 of the 18 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
golang.org/x/net@v0.37.0
stdlib@go1.23.6
0.53.0
1.25.10
grafana/grafana:13.1.3ab5cb380e3ff
golang.org/x/net@v0.49.0
0.53.0
grafana/loki:3.0.0757b5fadf816
golang.org/x/net@v0.22.0
stdlib@go1.21.9
0.53.0
1.25.10
grafana/loki-canary:3.0.028d7c00588aa
golang.org/x/net@v0.22.0
stdlib@go1.21.9
0.53.0
1.25.10
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/net@v0.24.0
stdlib@go1.21.3
0.53.0
1.25.10
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.25.5
0.53.0
1.25.10
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
golang.org/x/net@v0.52.0
0.53.0
ghcr.io/chaos-mesh/chaos-mesh:v2.8.3bdb31f3121a2
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

17,686
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.10
0.53.0
1.25.10

Open the chart page →

6,391
openldapccowleyVerified publisher2.0.41 of 3See more

openldap ccowley 2.0.4

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.53.0
1.25.10

Open the chart page →

6,222
openldap_exporterccowleyVerified publisher0.1.01 of 1See more

openldap_exporter ccowley 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
stdlib@go1.15.7
1.25.10

Open the chart page →

2,144
kube-ceemsceemsOfficialVerified publisher1.40.01 of 5See more

kube-ceems ceems 1.40.0

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:13.2.1-distroless3600073f45a9
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

668
cerberuscerberusVerified publisher0.16.01 of 1See more

cerberus cerberus 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/tsouza/cerberus:1.20.0ef384585f9a3
stdlib@go1.26.2
1.25.10

Open the chart page →

162
cert-manager-acm-synccert-manager-acm-sync0.7.41 of 1See more

cert-manager-acm-sync cert-manager-acm-sync 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/camilorivera/cert-manager-acm-sync:0.7.489a83796a550
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

132
cert-manager-alidns-webhookcert-manager-alidns-webhook0.1.41 of 1See more

cert-manager-alidns-webhook cert-manager-alidns-webhook 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/crazygit/cert-manager-alidns-webhook:0.1.4976be6506eb6
golang.org/x/net@v0.47.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

1,337
cert-manager-desec-webhookcert-manager-desec-webhook1.0.11 of 1See more

cert-manager-desec-webhook cert-manager-desec-webhook 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.53.0
1.25.10

Open the chart page →

1,424
cert-manager-webhook-abioncert-manager-webhook-abion1.3.21 of 1See more

cert-manager-webhook-abion cert-manager-webhook-abion 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
abiondevelopment/cert-manager-webhook-abion:latestc741988fbd23
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.53.0
1.25.10

Open the chart page →

1,247
cert-manager-webhook-bunnycert-manager-webhook-bunnyVerified publisher1.0.21 of 1See more

cert-manager-webhook-bunny cert-manager-webhook-bunny 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/o0th/cert-manager-webhook-bunny:1.0.2fe7ce555a12d
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10

Open the chart page →

847
cert-manager-webhook-civocert-manager-webhook-civoVerified publisher0.0.0-05b683cb6efdc99135f68af18007954e74f184041 of 1See more

cert-manager-webhook-civo cert-manager-webhook-civo 0.0.0-05b683cb6efdc99135f68af18007954e74f18404

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
okteto/civo-webhook:0.5.357cd51176538
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,286
cert-manager-webhook-hcloud-zonescert-manager-webhook-hcloud-zones0.1.51 of 1See more

cert-manager-webhook-hcloud-zones cert-manager-webhook-hcloud-zones 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/cert-manager-webhook-hcloud-zones:0.1.5a7a846bba3e8
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

422
cert-manager-webhook-infoblox-wapicert-manager-webhook-infoblox-wapiVerified publisher1.5.21 of 1See more

cert-manager-webhook-infoblox-wapi cert-manager-webhook-infoblox-wapi 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

2,353
cert-manager-webhook-namecheapcert-manager-webhook-namecheap0.1.21 of 1See more

cert-manager-webhook-namecheap cert-manager-webhook-namecheap 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10

Open the chart page →

1,767

Container images carrying it

4,778 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
golang.org/x/net@v0.25.0
stdlib@go1.20.14
0.53.0
1.25.10
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
stdlib@go1.25.4
1.25.10
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.53.0
1.25.10
1
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.17
0.53.0
1.25.10
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
stdlib@go1.16.6
1.25.10
1
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
golang.org/x/net@v0.37.0
stdlib@go1.24.3
0.53.0
1.25.10
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.2
0.53.0
1.25.10
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.53.0
1.25.10
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/net@v0.11.0
stdlib@go1.19.6
0.53.0
1.25.10
1
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/dirien/minecraft-exporter:0.24.061d89bf99ff7
golang.org/x/net@v0.51.0
0.53.0
1
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
stdlib@go1.17.5
0.53.0
1.25.10
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/net@v0.10.0
stdlib@go1.21.0
0.53.0
1.25.10
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.25.10
1
ghcr.io/dntosas/capi2argo-cluster-operator:v1.5.0fb8c6457ef6e
golang.org/x/net@v0.40.0
stdlib@go1.25.6
0.53.0
1.25.10
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.53.0
1.25.10
1
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
stdlib@go1.18.1
1.25.10
1
ghcr.io/donkie/spoolman:0.24.042135965c42d
stdlib@go1.19.8
1.25.10
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.8
0.53.0
1.25.10
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.16.15
0.53.0
1.25.10
1
ghcr.io/doodlescheduling/saml-exporter:v0.5.03d5a99841bc2
stdlib@go1.22.3
1.25.10
1
ghcr.io/douban/aliyun-exporter:mainb7c694331362
stdlib@go1.24.2
1.25.10
1
ghcr.io/douban/qiniu-exporter:maind1da3bcfad7d
stdlib@go1.19.5
1.25.10
1
ghcr.io/douban/ucloud-exporter:mainb4bb8a9021a2
stdlib@go1.24.2
1.25.10
1
ghcr.io/douban/upyun-exporter:main6810900c9c4a
stdlib@go1.25.5
1.25.10
1
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.53.0
1.25.10
1
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
golang.org/x/net@v0.35.0
0.53.0
1
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.53.0
1.25.10
1
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
stdlib@go1.16.12
1.25.10
1
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
stdlib@go1.22.2
1.25.10
1
ghcr.io/edgelesssys/continuum/continuum-proxy24c76f294a80
golang.org/x/net@v0.32.0
stdlib@go1.23.3
0.53.0
1.25.10
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.53.0
1.25.10
1
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
stdlib@go1.26.1
1.25.10
1
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
ghcr.io/element-hq/ess-helm/matrix-tools:0.3.20eac0521be29
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.53.0
1.25.10
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
stdlib@go1.19.8
1.25.10
1
ghcr.io/eminaktas/oom-tracer:v0.1.0c90ca8389c87
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.53.0
1.25.10
1
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/emqx/emqx-operator:2.3.23333ed546165
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/eosc-lot-1/logrotate:3-alpineb0e20d200f89
stdlib@go1.22.4
1.25.10
1
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.20
0.53.0
1.25.10
1
ghcr.io/erpc/erpc:0.0.49f5654f745d4c
golang.org/x/net@v0.36.0
stdlib@go1.23.9
0.53.0
1.25.10
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
ghcr.io/ethpandaops/benchmarkoor:latest5470b2ec3161
stdlib@go1.24.13
1.25.10
1
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/ethpandaops/syncoor:master233aa9808fc7
stdlib@go1.26.0
1.25.10
1
ghcr.io/eugenmayer/whatsmyip:0.0.14b6700cc0e2d
stdlib@go1.22.1
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.