StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,147
of 17,828 indexed, latest versions
Container images
4,757
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,147 of 17,828 indexed charts deploy, on 4,757 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,604
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,632
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,147 by stars
ChartLatestAffected imagesRadar Score
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
golang.org/x/net@v0.13.0
stdlib@go1.21.1
0.53.0
1.25.10

Open the chart page →

3,427
nineinfranineinfra-charts0.7.01 of 1See more

nineinfra nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/nineinfra:v0.7.0d4aad414eccd
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,120
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.25.10

Open the chart page →

3,979
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

1,440
zookeeper-operatornineinfra-charts0.7.01 of 1See more

zookeeper-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/zookeeper-operator:v0.7.0af6eb2f37bfc
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

724
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

6,993
cosmoshub-rpcnodeifyVerified publisher1.0.71 of 2See more

cosmoshub-rpc nodeify 1.0.7

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

1,870
cosmos-nodenodeifyVerified publisher2.6.01 of 2See more

cosmos-node nodeify 2.6.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

1,870
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/net@v0.41.0
stdlib@go1.24.10
0.53.0
1.25.10

Open the chart page →

6,628
firehose-ethereumnodeifyVerified publisher1.7.11 of 2See more

firehose-ethereum nodeify 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

5,742
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
stdlib@go1.19.3
1.25.10

Open the chart page →

2,922
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.53.0
1.25.10

Open the chart page →

4,785
nodejsweeklynodejsweekly1.1.01 of 1See more

nodejsweekly nodejsweekly 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

1,490
node-labels-exporternode-labels-exporter0.1.91 of 1See more

node-labels-exporter node-labels-exporter 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/node-labels-exporter:v0.5.1dd6875a0a963
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

292
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/net@v0.19.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

2,986
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

7,760
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
robjuz/postgresql-nominatim:latest805c7bab76df
stdlib@go1.16.5
1.25.10

Open the chart page →

22,831
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

5,872
ingress-helm-chartnotesprojectchart0.1.02 of 2See more

ingress-helm-chart notesprojectchart 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10

Open the chart page →

2,958
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,559
keycloak-helm-chartnotesprojectchart0.1.01 of 2See more

keycloak-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

1,618
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

6,839
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

5,899
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

5,855
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

2,257
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,540
clusterfannousefreakVerified publisher0.1.21 of 1See more

clusterfan nousefreak 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nousefreak/clusterfan:v0.1.04ea05e2a7b57
stdlib@go1.17.5
1.25.10

Open the chart page →

1,791
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.5
0.53.0
1.25.10

Open the chart page →

4,862
nfs-server-provisionernovum-rgi-charts1.1.21 of 1See more

nfs-server-provisioner novum-rgi-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.53.0
1.25.10

Open the chart page →

2,807
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.11
0.53.0
1.25.10

Open the chart page →

27,585
nri-memory-policynri-pluginsVerified publisher0.14.01 of 1See more

nri-memory-policy nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memory-policy:v0.14.0531d21ec4ba2
stdlib@go1.26.0
1.25.10

Open the chart page →

272
nri-memory-qosnri-pluginsOfficialVerified publisher0.14.01 of 1See more

nri-memory-qos nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memory-qos:v0.14.0c7c5c24ed894
stdlib@go1.26.0
1.25.10

Open the chart page →

272
nri-resctrl-monnri-pluginsVerified publisher0.14.01 of 1See more

nri-resctrl-mon nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resctrl-mon:v0.14.0a9c9775fab70
stdlib@go1.26.0
1.25.10

Open the chart page →

272
nri-resource-annotatornri-pluginsVerified publisher0.14.01 of 1See more

nri-resource-annotator nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resource-annotator:v0.14.08100a19e85f7
stdlib@go1.26.0
1.25.10

Open the chart page →

235
nri-resource-policy-templatenri-pluginsVerified publisher0.14.01 of 1See more

nri-resource-policy-template nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-resource-policy-template:v0.14.00edfc075277b
stdlib@go1.26.0
1.25.10

Open the chart page →

303
nri-sgx-epcnri-pluginsVerified publisher0.14.01 of 1See more

nri-sgx-epc nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-sgx-epc:v0.14.0b4c4d0d83c14
stdlib@go1.26.0
1.25.10

Open the chart page →

272
cnaos-pvc-populatornutanix-helm-releasesVerified publisher1.1.0-174-prod1 of 2See more

cnaos-pvc-populator nutanix-helm-releases 1.1.0-174-prod

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.53.0
1.25.10

Open the chart page →

1,839
nai-knative-istio-controllernutanix-helm-releasesVerified publisher1.13.12 of 2See more

nai-knative-istio-controller nutanix-helm-releases 1.13.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.13.1a5b041ba3c9e
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.13.1f066376eee17
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

1,566
nai-knative-servingnutanix-helm-releasesVerified publisher1.13.14 of 4See more

nai-knative-serving nutanix-helm-releases 1.13.1

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.13.121f8e11a44bf
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.13.134796e9f760b
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.13.153d9aa4d2c7a
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.13.1700c69915dc7
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

3,766
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.04 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

4 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
stdlib@go1.24.2
1.25.10
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.53.0
1.25.10
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.25.10
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.39751856cacc8
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.53.0
1.25.10

Open the chart page →

4,999
firecrawlobeoneVerified publisher3.0.91See more

firecrawl obeone 3.0.9

1 container image this version deploys carries CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
stdlib@go1.24.6
1.25.10

Open the chart page →

observabilitysecobservabilitysec0.0.11 of 2See more

observabilitysec observabilitysec 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jdvalencia422/observabilitysec:latesta80b6e47a7b8
stdlib@go1.18.4
1.25.10

Open the chart page →

1,180
lensoci-ai-incubations0.1.1411 of 16See more

lens oci-ai-incubations 0.1.14

11 of the 16 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
golang.org/x/net@v0.19.0
stdlib@go1.22.7
0.53.0
1.25.10
grafana/grafana:12.1.1a1701c218024
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10
library/postgres:134689940c6838
stdlib@go1.24.6
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.85.0ebb560bcb6bd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.5.063805ebb8d2b
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.11.103738d278e08
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.2050a34002d5b
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

17,198
ocisocis-community0.1.01 of 1See more

ocis ocis-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
owncloud/ocis:8.0.1b38fd8fdd58f
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

2,358
argocd-agent-addonocm-helm-chartsVerified publisher0.29.01 of 2See more

argocd-agent-addon ocm-helm-charts 0.29.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.18.0a09814522a72
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

671
cluster-gateway-addon-managerocm-helm-chartsVerified publisher1.4.01 of 1See more

cluster-gateway-addon-manager ocm-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

1,608
cluster-managerocm-helm-chartsVerified publisher1.3.11 of 1See more

cluster-manager ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

822
cluster-proxyocm-helm-chartsVerified publisher0.12.01 of 1See more

cluster-proxy ocm-helm-charts 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

1,352
dynamic-scoring-frameworkocm-helm-chartsVerified publisher0.1.02 of 2See more

dynamic-scoring-framework ocm-helm-charts 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/dynamic-scoring-addon:latest7e571a08ec1a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
quay.io/open-cluster-management/dynamic-scoring-controller:latest587f5bc8f2ed
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

996
klusterletocm-helm-chartsVerified publisher1.3.11 of 1See more

klusterlet ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

822

Container images carrying it

4,757 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
stdlib@go1.23.12
1.25.10
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/net@v0.38.0
stdlib@go1.22.7
0.53.0
1.25.10
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
stdlib@go1.20.12
1.25.10
1
ghcr.io/marthydavid/kafka-keda-golang-consumer:0.0.4e07644865dd1
stdlib@go1.23.0
1.25.10
1
ghcr.io/marthydavid/kafka-keda-golang-producer:0.0.454b242c7bf2b
stdlib@go1.23.0
1.25.10
1
ghcr.io/matanbaruch/cursor-admin-api-exporter:0.1.8ba3a29fc479a
stdlib@go1.24.5
1.25.10
1
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.5
0.53.0
1.25.10
1
ghcr.io/mattn/picoclaw:latest517556c8b144
golang.org/x/net@v0.50.0
stdlib@go1.26.0
0.53.0
1.25.10
1
ghcr.io/mcman2017/qt-vault:v0.1.2852edf54c850
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.53.0
1.25.10
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
stdlib@go1.24.4
1.25.10
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
stdlib@go1.24.4
1.25.10
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
stdlib@go1.24.4
1.25.10
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
stdlib@go1.19.8
1.25.10
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
stdlib@go1.24.4
1.25.10
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
golang.org/x/net@v0.33.0
stdlib@go1.24.0
0.53.0
1.25.10
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
golang.org/x/net@v0.33.0
stdlib@go1.24.0
0.53.0
1.25.10
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.53.0
1.25.10
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.53.0
1.25.10
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
golang.org/x/net@v0.20.0
stdlib@go1.22.3
0.53.0
1.25.10
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.4
0.53.0
1.25.10
1
ghcr.io/mesosphere/dkp-container-images/objectstorage-controller:v0.2.23c708e508197
golang.org/x/net@v0.40.0
stdlib@go1.24.11
0.53.0
1.25.10
1
ghcr.io/metrico/gigapipe:v4.1.6caeb2652ce5e
stdlib@go1.26.2
1.25.10
1
ghcr.io/mgumz/mtr-exporter:0.4.0f4691c8fe8eb
stdlib@go1.22.8
1.25.10
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
golang.org/x/net@v0.4.0
stdlib@go1.18.9
0.53.0
1.25.10
1
ghcr.io/middleware-labs/mw-auto-injector:0.1.18512248e17e8
golang.org/x/net@v0.26.0
stdlib@go1.23.12
0.53.0
1.25.10
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
golang.org/x/net@v0.14.0
stdlib@go1.20.14
0.53.0
1.25.10
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
stdlib@go1.25.6
1.25.10
1
ghcr.io/middleware-labs/mw-kube-agent-config-updater:1.21.0d4edc3f244f4
stdlib@go1.25.6
1.25.10
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
golang.org/x/net@v0.26.0
stdlib@go1.24.0
0.53.0
1.25.10
1
ghcr.io/middleware-labs/mw-lang-detector:0.1.2a4776aa2a56b
golang.org/x/net@v0.26.0
stdlib@go1.23.12
0.53.0
1.25.10
1
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.6
0.53.0
1.25.10
1
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.7
0.53.0
1.25.10
1
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10
1
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.18.3
0.53.0
1.25.10
1
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/net@v0.9.0
stdlib@go1.24.4
0.53.0
1.25.10
1
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.53.0
1.25.10
1
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
stdlib@go1.26.0
1.25.10
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
golang.org/x/net@v0.24.0
stdlib@go1.21.12
0.53.0
1.25.10
1
ghcr.io/movetokube/postgres-operator:2.4.0def57d85a2da
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10
1
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.8
0.53.0
1.25.10
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
golang.org/x/net@v0.30.0
stdlib@go1.23.6
0.53.0
1.25.10
1
ghcr.io/msueberkrueb/cloudflare-dyndns:1.0.0e5c945a3b000
stdlib@go1.25.1
1.25.10
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.