StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,155
of 17,813 indexed, latest versions
Container images
4,778
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,155 of 17,813 indexed charts deploy, on 4,778 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,618
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,640
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,155 by stars
ChartLatestAffected imagesRadar Score
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
stdlib@go1.24.4
1.25.10

Open the chart page →

4,105
qbittorrent-vpnbdclark-helm-chartsVerified publisher0.7.61 of 2See more

qbittorrent-vpn bdclark-helm-charts 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.41.11a5bf4b4820a
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

1,011
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
stdlib@go1.25.7
1.25.10

Open the chart page →

2,154
helm-samplebehnambm-helm-chart1.0.11 of 3See more

helm-sample behnambm-helm-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

2,782
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,354
pagesberrutig-pages1.0.01 of 3See more

pages berrutig-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
trident-operatorberyju-org21.10.01 of 1See more

trident-operator beryju-org 21.10.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
netapp/trident-operator:21.10.049cfe552d9c2
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.53.0
1.25.10

Open the chart page →

2,079
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
golang.org/x/net@v0.35.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

7,437
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

5,307
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.6
0.53.0
1.25.10

Open the chart page →

74,990
mx-notifierbicarus-labs1.1.91 of 1See more

mx-notifier bicarus-labs 1.1.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/net@v0.2.0
stdlib@go1.17.6
0.53.0
1.25.10

Open the chart page →

3,784
wg-access-serverbicarus-labs0.9.91 of 1See more

wg-access-server bicarus-labs 0.9.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/net@v0.0.0-20220418201149-a630d4f3e7a2
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

2,756
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/net@v0.10.0
stdlib@go1.21.1
0.53.0
1.25.10

Open the chart page →

2,353
stackbitpokeVerified publisher0.12.46 of 6See more

stack bitpoke 0.12.4

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.53.0
1.25.10
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.53.0
1.25.10
bitpoke/stack-default-backend:latestc5eed1ddf692
stdlib@go1.16.6
1.25.10
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.2
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.53.0
1.25.10

Open the chart page →

9,904
wordpress-operatorbitpokeVerified publisher0.12.41 of 1See more

wordpress-operator bitpoke 0.12.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

1,124
baserowblackbird-cloudVerified publisher1.0.172 of 6See more

baserow blackbird-cloud 1.0.17

2 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
stdlib@go1.19.8
1.25.10
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.53.0
1.25.10

Open the chart page →

10,308
prometheus-domain-exporterblackbox-domain-exporter1.0.01 of 1See more

prometheus-domain-exporter blackbox-domain-exporter 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

1,409
bdbablackduck2026.6.33 of 9See more

bdba blackduck 2026.6.3

3 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
blackducksoftware/bdba-pgupgrader:2026.6.35c97f3a3f8b7
stdlib@go1.18.2
1.25.10
library/postgres:15.18-bookworme8db9bd3e9e1
stdlib@go1.24.6
1.25.10
library/rabbitmq:4.2.87561d672fae4
stdlib@go1.22.2
1.25.10

Open the chart page →

9,959
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert-db:8.4.06310fac39d53
stdlib@go1.24.6
1.25.10

Open the chart page →

4,329
firehoseblip-firehoseVerified publisher0.0.183 of 11See more

firehose blip-firehose 0.0.18

3 of the 11 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
blipai/deckard:0.0.28737d5d19a312
golang.org/x/net@v0.10.0
stdlib@go1.18.10
0.53.0
1.25.10
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

13,550
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.25.10

Open the chart page →

15,337
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-nti:logc947c3629371
stdlib@go1.23.12
1.25.10

Open the chart page →

27,584
csi-driver-nfsbook-k8sinfra-v24.12.16 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v8.3.0bc7be893ecc3
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
golang.org/x/net@v0.37.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

6,299
grafanabook-k8sinfra-v28.8.21 of 1See more

grafana book-k8sinfra-v2 8.8.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.53.0
1.25.10

Open the chart page →

1,825
jaegerbook-k8sinfra-v23.4.04 of 5See more

jaeger book-k8sinfra-v2 3.4.0

4 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.25.10
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

19,388
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

8,387
kube-prometheus-stackbook-k8sinfra-v265.5.15 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10

Open the chart page →

6,064
metallbbook-k8sinfra-v20.13.102 of 3See more

metallb book-k8sinfra-v2 0.13.10

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.53.0
1.25.10
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.53.0
1.25.10

Open the chart page →

3,857
nfs-subdir-external-provisionerbook-k8sinfra-v24.0.181 of 1See more

nfs-subdir-external-provisioner book-k8sinfra-v2 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.53.0
1.25.10

Open the chart page →

2,746
prometheusbook-k8sinfra-v226.0.16 of 6See more

prometheus book-k8sinfra-v2 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

5,323
pyroscopebook-k8sinfra-v21.10.03 of 3See more

pyroscope book-k8sinfra-v2 1.10.0

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.53.0
1.25.10
grafana/pyroscope:1.10.0319bf32ae06b
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.53.0
1.25.10
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.10

Open the chart page →

3,268
redisbook-k8sinfra-v21.0.01 of 1See more

redis book-k8sinfra-v2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.25.10

Open the chart page →

1,732
tempobook-k8sinfra-v21.10.31 of 1See more

tempo book-k8sinfra-v2 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/net@v0.24.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,877
boundary-softsciboundary-softsci0.2.41 of 1See more

boundary-softsci boundary-softsci 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/boundary:latest76a201954ca0
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

879
bitmagnetbrandan-schmitz-helm-chartsVerified publisher1.0.62 of 2See more

bitmagnet brandan-schmitz-helm-charts 1.0.6

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
stdlib@go1.24.6
1.25.10
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

1,867
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.25.10

Open the chart page →

20,285
tautullibryanalves0.1.01 of 1See more

tautulli bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
tautulli/tautulli:latest670e68dd9efc
stdlib@go1.24.4
1.25.10

Open the chart page →

1,955
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.53.0
1.25.10

Open the chart page →

73,325
buildkitbuildkit0.1.01 of 1See more

buildkit buildkit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
moby/buildkit:master-rootless07115a67cd22
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

620
buildkit-privilegedbuildkit-privileged0.1.01 of 1See more

buildkit-privileged buildkit-privileged 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
moby/buildkit:masterbc964521ee58
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

403
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.24.6
1.25.10

Open the chart page →

11,989
butane-operatorbutane-operatorVerified publisher0.3.02 of 2See more

butane-operator butane-operator 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/naval-group/butane-operator:v0.1.1-rc285818b510780
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.53.0
1.25.10
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10

Open the chart page →

1,411
butlercibutlerciVerified publisher0.1.01 of 1See more

butlerci butlerci 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.53.0
1.25.10

Open the chart page →

2,375
accelerationbuttahtoastVerified publisher0.1.01 of 1See more

acceleration buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
goharbor/harbor-acceld:0.2.13451103a6c8d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

1,409
fluobuttahtoastVerified publisher0.1.01 of 1See more

fluo buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.53.0
1.25.10

Open the chart page →

1,299
kubermatic-operatorbuttahtoastVerified publisher2.24.51 of 1See more

kubermatic-operator buttahtoast 2.24.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
golang.org/x/net@v0.19.0
stdlib@go1.20.6
0.53.0
1.25.10

Open the chart page →

2,781
kubevirt-managerbuttahtoastVerified publisher0.1.31 of 1See more

kubevirt-manager buttahtoast 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10

Open the chart page →

1,497
mariadbbysamioVerified publisher1.0.21 of 1See more

mariadb bysamio 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mariadb:12.0.2607835cd628b
stdlib@go1.24.6
1.25.10

Open the chart page →

2,973

Container images carrying it

4,778 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/eugenmayer/whoami-tls:0.1.0477be2d05aba
stdlib@go1.24.1
1.25.10
1
ghcr.io/eumel8/rancher-servicemonitor:0.2.1f34428cac187
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.53.0
1.25.10
1
ghcr.io/evilgn0me/ingressmonitorcontroller:v0.0.50bbfa4db14b9
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/exalsius/exalsius-operator:0.12.0d24a579a3c75
golang.org/x/net@v0.50.0
0.53.0
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.53.0
1.25.10
1
ghcr.io/external-secrets/external-secrets:v2.4.19440a40b3947
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
ghcr.io/external-secrets/external-secrets:v2.1.0ec40c3d9c48f
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.53.0
1.25.10
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.53.0
1.25.10
1
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.53.0
1.25.10
1
ghcr.io/ferretdb/ferretdb:2.7.05706414241eb
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.53.0
1.25.10
1
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
stdlib@go1.20.2
1.25.10
1
ghcr.io/firecrawl/firecrawl:2.11.35987ebe1dc85b0
golang.org/x/net@v0.41.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
stdlib@go1.24.6
1.25.10
1
ghcr.io/flanksource/facet:0.1.7237237038be15
stdlib@go1.23.12
1.25.10
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.53.0
1.25.10
1
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
golang.org/x/net@v0.8.0
stdlib@go1.20.6
0.53.0
1.25.10
1
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/flohansen/dasher-server:latest7cde8c3fa2d1
golang.org/x/net@v0.22.0
stdlib@go1.22.5
0.53.0
1.25.10
1
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.28.0
stdlib@go1.24.12
0.53.0
1.25.10
1
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.53.0
1.25.10
1
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
golang.org/x/net@v0.35.0
stdlib@go1.23.6
0.53.0
1.25.10
1
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
stdlib@go1.20.12
1.25.10
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
stdlib@go1.23.8
1.25.10
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.1
0.53.0
1.25.10
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
stdlib@go1.23.8
1.25.10
1
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
golang.org/x/net@v0.34.0
stdlib@go1.23.12
0.53.0
1.25.10
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
golang.org/x/net@v0.17.0
stdlib@go1.22.0
0.53.0
1.25.10
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
golang.org/x/net@v0.17.0
stdlib@go1.22.0
0.53.0
1.25.10
1
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
stdlib@go1.18.3
1.25.10
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.18.1
0.53.0
1.25.10
1
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
stdlib@go1.24.0
1.25.10
1
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
1
ghcr.io/gabe565/domain-watch:latest34c5a1e351d6
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.53.0
1.25.10
1
ghcr.io/gabe565/limo:latest6dfdbc9853bb
stdlib@go1.20.12
1.25.10
1
ghcr.io/gabe565/matrimony:latestd39a9d7c3e1b
stdlib@go1.22.0
1.25.10
1
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.53.0
1.25.10
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.53.0
1.25.10
1
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
stdlib@go1.19.8
1.25.10
1
ghcr.io/gijsvandulmen/k8qu:1.4e897b18db13d
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.53.0
1.25.10
1
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
golang.org/x/net@v0.43.0
stdlib@go1.25.4
0.53.0
1.25.10
1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
golang.org/x/net@v0.44.0
stdlib@go1.25.4
0.53.0
1.25.10
1
ghcr.io/glassflow/glassflow-etl-be:v3.2.020f066d0f631
golang.org/x/net@v0.52.0
stdlib@go1.25.0
0.53.0
1.25.10
1
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.