StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,155
of 17,813 indexed, latest versions
Container images
4,778
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,155 of 17,813 indexed charts deploy, on 4,778 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,618
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,640
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,155 by stars
ChartLatestAffected imagesRadar Score
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

4,192
monitoring-operatorappscodeVerified publisher2026.6.121 of 1See more

monitoring-operator appscode 2026.6.12

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana-tools:v0.8.077c9d29080eb
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

376
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

2,584
multicluster-ingress-readerappscodeVerified publisher2024.7.101 of 1See more

multicluster-ingress-reader appscode 2024.7.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

302
offline-license-serverappscodeVerified publisher2026.9.111 of 2See more

offline-license-server appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,695
opentelemetry-kube-stackappscodeVerified publisher0.14.123 of 3See more

opentelemetry-kube-stack appscode 0.14.12

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.144.079b81912f1fb
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.53.0
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.53.0
1.25.10

Open the chart page →

1,911
panopticonappscodeVerified publisher2026.9.181 of 2See more

panopticon appscode 2026.9.18

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

422
persesappscodeVerified publisher2026.6.21 of 1See more

perses appscode 2026.6.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/perses:v2026.4.24b880da90aa1a
golang.org/x/net@v0.42.0
0.53.0

Open the chart page →

533
petsetappscodeVerified publisher2026.9.181 of 1See more

petset appscode 2026.9.18

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/petset:v0.2.0913f0858eb24
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

436
pgoutboxappscodeVerified publisher2026.7.101 of 1See more

pgoutbox appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/pgoutbox:v0.0.4a96e06ec5e9f
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

843
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

38,114
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
golang.org/x/net@v0.26.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

778
prom-label-proxyappscodeVerified publisher2026.7.151 of 1See more

prom-label-proxy appscode 2026.7.15

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/prom-label-proxy:v2026.4.2461344c13f17d
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

179
regcacheappscodeVerified publisher2026.9.111 of 1See more

regcache appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.53.0
1.25.10

Open the chart page →

658
secrets-store-csi-driver-provider-virtual-secretsappscodeVerified publisher2026.8.141 of 1See more

secrets-store-csi-driver-provider-virtual-secrets appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/secrets-store-csi-driver-provider-virtual-secrets:v0.2.07afb394f9f97
stdlib@go1.24.1
1.25.10

Open the chart page →

554
service-backendappscodeVerified publisher2026.9.111 of 1See more

service-backend appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,346
service-gatewayappscodeVerified publisher2026.9.112 of 3See more

service-gateway appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/net@v0.47.0
0.53.0
ghcr.io/voyagermesh/echoserver:v20221109fa56a9251de6
stdlib@go1.19
1.25.10

Open the chart page →

2,203
service-presetsappscodeVerified publisher2024.2.111 of 1See more

service-presets appscode 2024.2.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.25.10

Open the chart page →

824
service-providerappscodeVerified publisher2026.9.112 of 2See more

service-provider appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.53.0
1.25.10
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

2,255
stash-communityappscodeVerified publisher0.42.04 of 4See more

stash-community appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.53.0
1.25.10
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
stdlib@go1.24.9
0.53.0
1.25.10
ghcr.io/stashed/stash:v0.42.03a98245a7667
golang.org/x/net@v0.26.0
stdlib@go1.25.3
0.53.0
1.25.10
ghcr.io/stashed/stash-crd-installer:v0.42.076f0a650e44b
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

3,679
stash-opscenterappscodeVerified publisher2025.10.171 of 1See more

stash-opscenter appscode 2025.10.17

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

686
stash-ui-serverappscodeVerified publisher0.23.01 of 1See more

stash-ui-server appscode 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

686
statefulsetappscodeVerified publisher0.0.12 of 3See more

statefulset appscode 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.53.0
1.25.10
ghcr.io/appscode/kubectl-nonroot:v1.248ee5bdd68977
stdlib@go1.20.7
1.25.10

Open the chart page →

2,740
storage-metrics-serverappscodeVerified publisher2026.7.81 of 1See more

storage-metrics-server appscode 2026.7.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/storage-metrics-server:v0.1.09cb4acb742a9
golang.org/x/net@v0.48.0
0.53.0

Open the chart page →

560
supervisorappscodeVerified publisher2026.2.161 of 1See more

supervisor appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/supervisor:v0.0.1223affde10a92
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

237
taskqueueappscodeVerified publisher2026.2.161 of 1See more

taskqueue appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,092
thanos-operatorappscodeVerified publisher2026.6.21 of 1See more

thanos-operator appscode 2026.6.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/thanos-operator:v2026.4.24e05a3e701291
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

385
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,228
vcd-lb-gcappscodeVerified publisher2026.6.251 of 1See more

vcd-lb-gc appscode 2026.6.25

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/net@v0.23.0
0.53.0

Open the chart page →

178
voyagerappscodeVerified publisher2026.3.231 of 1See more

voyager appscode 2026.3.23

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/voyager:v17.5.04964ceaf9d35
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

728
voyager-gatewayappscodeVerified publisher2026.7.211 of 2See more

voyager-gateway appscode 2026.7.21

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

1,379
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
golang.org/x/net@v0.11.0
stdlib@go1.21.1
0.53.0
1.25.10

Open the chart page →

5,720
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/net@v0.19.0
stdlib@go1.22.2
0.53.0
1.25.10

Open the chart page →

1,205
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
stdlib@go1.24.6
1.25.10

Open the chart page →

8,937
appwriteappwrite-helmVerified publisher1.3.24 of 8See more

appwrite appwrite-helm 1.3.2

4 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/net@v0.40.0
stdlib@go1.25.7
0.53.0
1.25.10
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.25.10
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.25.10
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.25.10

Open the chart page →

9,859
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.53.0
1.25.10

Open the chart page →

5,213
arcadearcadeVerified publisher1.10.11 of 10See more

arcade arcade 1.10.1

1 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
stdlib@go1.24.6
1.25.10

Open the chart page →

991
argocd-bitbucket-proxyargocd-bitbucket-proxy1.1.11 of 1See more

argocd-bitbucket-proxy argocd-bitbucket-proxy 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/salemgolemugoo/argocd-bitbucket-proxy:latesta72df069095b
stdlib@go1.26.1
1.25.10

Open the chart page →

189
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.25.10
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/net@v0.34.0
stdlib@go1.22.2
0.53.0
1.25.10

Open the chart page →

7,710
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

1,845
argonix-apiargonix0.3.62 of 4See more

argonix-api argonix 0.3.6

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0951622ae173b
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.53.0
1.25.10
ghcr.io/argonix-io/argonix-api-frontend:1.0.0593c1b0f73cb
stdlib@go1.23.12
1.25.10

Open the chart page →

4,890
argo-zombiesargo-zombies0.1.521 of 1See more

argo-zombies argo-zombies 0.1.52

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

254
arlas-aiasarlas-stackVerified publisher28.9.06 of 22See more

arlas-aias arlas-stack 28.9.0

6 of the 22 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.53.0
1.25.10
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.25.10
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.53.0
1.25.10
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
golang.org/x/net@v0.33.0
stdlib@go1.23.8
0.53.0
1.25.10
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.25.10

Open the chart page →

39,921
arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.53.0
1.25.10
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
stdlib@go1.19.5
1.25.10
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

23,478
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.53.0
1.25.10

Open the chart page →

1,780
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.11
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.10
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.53.0
1.25.10

Open the chart page →

8,634
assemblylineassemblylineVerified publisher7.4.202 of 12See more

assemblyline assemblyline 7.4.20

2 of the 12 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

12,896
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.25.10

Open the chart page →

5,538
dltkvassist-iot-data-integrity-verification0.2.04 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.53.0
1.25.10
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.53.0
1.25.10
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.53.0
1.25.10
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

194,560
dltflassist-iot-dlt-based-fl0.2.04 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

4 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.53.0
1.25.10
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.53.0
1.25.10
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.53.0
1.25.10
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

194,560

Container images carrying it

4,778 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
golang.org/x/net@v0.47.0
stdlib@go1.24.3
0.53.0
1.25.10
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.53.0
1.25.10
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.53.0
1.25.10
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.53.0
1.25.10
1
ghcr.io/loft-sh/vcluster-hpm:0.2.7f65f6810ea23
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.53.0
1.25.10
1
ghcr.io/loft-sh/vcluster-platform:4.12.19bc88940affc
golang.org/x/net@v0.52.0
0.53.0
1
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
golang.org/x/net@v0.46.0
stdlib@go1.24.2
0.53.0
1.25.10
1
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.53.0
1.25.10
1
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.15
0.53.0
1.25.10
1
ghcr.io/lukaszraczylo/jobs-manager-operator:0.1.15e6239e2838d7
golang.org/x/net@v0.49.0
stdlib@go1.25.0
0.53.0
1.25.10
1
ghcr.io/lukaszraczylo/kubernetes-images-sync-operator:0.5.57a424948c8143
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10
1
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.53.0
1.25.10
1
ghcr.io/luzifer/ots:v1.21.5c94f6c9ed173
stdlib@go1.26.2
1.25.10
1
ghcr.io/luzilla/dnsbl_exporter:v0.7.0-rc3d9767232a55e
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.53.0
1.25.10
1
ghcr.io/luzilla/dnsbl_exporter:v0.12.0ecba7360ff12
stdlib@go1.25.0
1.25.10
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
stdlib@go1.20.12
1.25.10
1
ghcr.io/madeddie/opds-aggregator:latest60c56021c552
stdlib@go1.24.13
1.25.10
1
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
stdlib@go1.23.12
1.25.10
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/net@v0.38.0
stdlib@go1.22.7
0.53.0
1.25.10
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
stdlib@go1.20.12
1.25.10
1
ghcr.io/marthydavid/kafka-keda-golang-consumer:0.0.4e07644865dd1
stdlib@go1.23.0
1.25.10
1
ghcr.io/marthydavid/kafka-keda-golang-producer:0.0.454b242c7bf2b
stdlib@go1.23.0
1.25.10
1
ghcr.io/matanbaruch/cursor-admin-api-exporter:0.1.8ba3a29fc479a
stdlib@go1.24.5
1.25.10
1
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.5
0.53.0
1.25.10
1
ghcr.io/mattn/picoclaw:latest517556c8b144
golang.org/x/net@v0.50.0
stdlib@go1.26.0
0.53.0
1.25.10
1
ghcr.io/mcman2017/qt-vault:v0.1.2852edf54c850
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.53.0
1.25.10
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
stdlib@go1.24.4
1.25.10
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
stdlib@go1.24.4
1.25.10
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
stdlib@go1.24.4
1.25.10
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
stdlib@go1.19.8
1.25.10
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
stdlib@go1.24.4
1.25.10
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
golang.org/x/net@v0.33.0
stdlib@go1.24.0
0.53.0
1.25.10
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
golang.org/x/net@v0.33.0
stdlib@go1.24.0
0.53.0
1.25.10
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.53.0
1.25.10
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.53.0
1.25.10
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
golang.org/x/net@v0.20.0
stdlib@go1.22.3
0.53.0
1.25.10
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.4
0.53.0
1.25.10
1
ghcr.io/mesosphere/dkp-container-images/objectstorage-controller:v0.2.23c708e508197
golang.org/x/net@v0.40.0
stdlib@go1.24.11
0.53.0
1.25.10
1
ghcr.io/metrico/gigapipe:v4.1.6caeb2652ce5e
stdlib@go1.26.2
1.25.10
1
ghcr.io/mgumz/mtr-exporter:0.4.0f4691c8fe8eb
stdlib@go1.22.8
1.25.10
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
golang.org/x/net@v0.4.0
stdlib@go1.18.9
0.53.0
1.25.10
1
ghcr.io/middleware-labs/mw-auto-injector:0.1.18512248e17e8
golang.org/x/net@v0.26.0
stdlib@go1.23.12
0.53.0
1.25.10
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
golang.org/x/net@v0.14.0
stdlib@go1.20.14
0.53.0
1.25.10
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
stdlib@go1.25.6
1.25.10
1
ghcr.io/middleware-labs/mw-kube-agent-config-updater:1.21.0d4edc3f244f4
stdlib@go1.25.6
1.25.10
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
golang.org/x/net@v0.26.0
stdlib@go1.24.0
0.53.0
1.25.10
1
ghcr.io/middleware-labs/mw-lang-detector:0.1.2a4776aa2a56b
golang.org/x/net@v0.26.0
stdlib@go1.23.12
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.