StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,155
of 17,813 indexed, latest versions
Container images
4,778
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,155 of 17,813 indexed charts deploy, on 4,778 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,618
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,640
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,155 by stars
ChartLatestAffected imagesRadar Score
capi-kamaji-vsphere-fullclastixVerified publisher1.0.19 of 9See more

capi-kamaji-vsphere-full clastix 1.0.1

9 of the 9 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/net@v0.32.0
stdlib@go1.23.0
0.53.0
1.25.10
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.53.0
1.25.10
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.53.0
1.25.10
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.53.0
1.25.10

Open the chart page →

6,012
capsule-rancher-addonclastixVerified publisher0.1.15 of 5See more

capsule-rancher-addon clastix 0.1.1

5 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/net@v0.4.0
stdlib@go1.19.2
0.53.0
1.25.10
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.53.0
1.25.10

Open the chart page →

7,142
kamajiclastixVerified publisher0.0.0+latest2 of 4See more

kamaji clastix 0.0.0+latest

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.53.0
1.25.10
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

4,669
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
golang.org/x/net@v0.23.0
stdlib@go1.23.7
0.53.0
1.25.10

Open the chart page →

2,765
kamaji-etcdclastixVerified publisher0.18.03 of 4See more

kamaji-etcd clastix 0.18.0

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.53.0
1.25.10
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.53.0
1.25.10
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

12,123
local-path-provisionerclastixVerified publisher0.0.301 of 1See more

local-path-provisioner clastix 0.0.30

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.53.0
1.25.10

Open the chart page →

1,209
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.53.0
1.25.10
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.53.0
1.25.10

Open the chart page →

7,417
cloudflared-tunnelclouddrove0.1.41 of 1See more

cloudflared-tunnel clouddrove 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

1,816
kube-acp-stackcloudentity2.28.03 of 7See more

kube-acp-stack cloudentity 2.28.0

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
stdlib@go1.23.8
1.25.10
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/net@v0.33.0
stdlib@go1.21.13
0.53.0
1.25.10
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.53.0
1.25.10

Open the chart page →

21,162
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.53.0
1.25.10
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.53.0
1.25.10
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.53.0
1.25.10
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.16.6
0.53.0
1.25.10
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.53.0
1.25.10
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

18,046
cloudflare-ddns-updatecloudflare-ddns-update0.1.21 of 1See more

cloudflare-ddns-update cloudflare-ddns-update 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

1,339
cloudflare-dyndnscloudflare-dyndnsVerified publisher1.1.01 of 1See more

cloudflare-dyndns cloudflare-dyndns 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/msueberkrueb/cloudflare-dyndns:1.0.0e5c945a3b000
stdlib@go1.25.1
1.25.10

Open the chart page →

307
cloudflare-tunnel-ingress-controllercloudflare-tunnel-ingress-controller0.2.31 of 1See more

cloudflare-tunnel-ingress-controller cloudflare-tunnel-ingress-controller 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/oliverbaehler/cloudflare-tunnel-ingress-controller:0.2.30aec31e36d95
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10

Open the chart page →

438
cloudfront-tenant-operatorcloudfront-tenant-operatorVerified publisher0.3.01 of 1See more

cloudfront-tenant-operator cloudfront-tenant-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

284
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/net@v0.14.0
stdlib@go1.19.10
0.53.0
1.25.10

Open the chart page →

25,525
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.5
0.53.0
1.25.10

Open the chart page →

6,706
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18.1
0.53.0
1.25.10

Open the chart page →

6,932
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.25.10

Open the chart page →

2,819
robot-shopcloud-native-toolkit1.1.12 of 12See more

robot-shop cloud-native-toolkit 1.1.1

2 of the 12 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
robotshop/rs-dispatch:latestde81f1d07b02
stdlib@go1.17
1.25.10
robotshop/rs-mongodb:latest119b545823cd
stdlib@go1.16.3
1.25.10

Open the chart page →

29,653
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad5 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
stdlib@go1.20.12
1.25.10
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
stdlib@go1.23.8
1.25.10
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.1
0.53.0
1.25.10
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
stdlib@go1.23.8
1.25.10

Open the chart page →

18,471
cloud-provider-kubevirtcloud-provider-kubevirtVerified publisher0.2.01 of 1See more

cloud-provider-kubevirt cloud-provider-kubevirt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

670
cloudrevecloudreve0.2.01 of 2See more

cloudreve cloudreve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudreve/cloudreve:4.18.0f7a464100bf6
stdlib@go1.25.5
1.25.10

Open the chart page →

2,989
k8s-monitoring-appcloudscriptVerified publisher1.0.01 of 1See more

k8s-monitoring-app cloudscript 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/k8s-monitoring-app:v0.0.25cab66a6b3574
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.53.0
1.25.10

Open the chart page →

1,296
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.3-alpine54451ecb8ab3
stdlib@go1.24.6
1.25.10

Open the chart page →

2,185
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.16.13
0.53.0
1.25.10

Open the chart page →

3,144
galaxycloudve6.8.81 of 3See more

galaxy cloudve 6.8.8

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

5,650
galaxy-cvmfs-csicloudve2.5.12 of 3See more

galaxy-cvmfs-csi cloudve 2.5.1

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10

Open the chart page →

1,515
galaxy-depscloudve1.1.16 of 7See more

galaxy-deps cloudve 1.1.1

6 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17
0.53.0
1.25.10
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/net@v0.0.0-20220614195744-fb05da6f9022
stdlib@go1.17
0.53.0
1.25.10
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10

Open the chart page →

10,636
galaxy-k8s-monitorcloudve0.1.11 of 1See more

galaxy-k8s-monitor cloudve 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
afgane/galaxy-k8s-monitor:latest457173db5640
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

313
galaxykubemancloudve2.10.14 of 7See more

galaxykubeman cloudve 2.10.1

4 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.13
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.53.0
1.25.10

Open the chart page →

16,207
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.53.0
1.25.10

Open the chart page →

81,044
openstack-cinder-csicloudve1.2.01 of 5See more

openstack-cinder-csi cloudve 1.2.0

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

2,069
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.53.0
1.25.10

Open the chart page →

2,854
pulsarcloudve0.2.02 of 2See more

pulsar cloudve 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
golang.org/x/net@v0.33.0
stdlib@go1.22.7
0.53.0
1.25.10
library/docker:dind5efed980cba3
golang.org/x/net@v0.50.0
0.53.0

Open the chart page →

6,220
argo-cdcluster-deploy0.3.22 of 3See more

argo-cd cluster-deploy 0.3.2

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
golang.org/x/net@v0.38.0
stdlib@go1.24.0
0.53.0
1.25.10
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

3,836
argo-eventscluster-deploy0.1.01 of 1See more

argo-events cluster-deploy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
golang.org/x/net@v0.49.0
stdlib@go1.24.11
0.53.0
1.25.10

Open the chart page →

1,160
authentikcluster-deploy0.2.01 of 1See more

authentik cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

2,568
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
stdlib@go1.20.2
1.25.10

Open the chart page →

8,201
mla-external-secretscluster-deploy0.3.01 of 1See more

mla-external-secrets cluster-deploy 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v2.1.0ec40c3d9c48f
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

723
monitoringcluster-deploy0.3.09 of 11See more

monitoring cluster-deploy 0.3.0

9 of the 11 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10
grafana/loki:3.6.73c8fd3570dd9
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
prom/memcached-exporter:v0.15.592a6ad5a3d3e
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.89.0cb4ac6a56555
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.10.07571a304e67f
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

8,299
clusterfactoryclusterfactory0.2.02 of 5See more

clusterfactory clusterfactory 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gitea/act_runner:0.3.1c2a169c5e998
golang.org/x/net@v0.50.0
stdlib@go1.26.1
0.53.0
1.25.10
jenkins/jenkins:2.541.3-jdk21c4098086090c
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

7,249
gitea-jenkinsclusterfactory0.1.12 of 5See more

gitea-jenkins clusterfactory 0.1.1

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gitea/act_runner:latestb5c35d6bdbb9
golang.org/x/net@v0.50.0
stdlib@go1.26.2
0.53.0
1.25.10
jenkins/jenkins:2.541.3-jdk21c4098086090c
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

7,038
cluster-monitor-agentcluster-monitor-agent0.10.21 of 1See more

cluster-monitor-agent cluster-monitor-agent 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-agent:0.10.26769c2275a43
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.53.0
1.25.10

Open the chart page →

475
cluster-monitor-servercluster-monitor-server0.10.21 of 1See more

cluster-monitor-server cluster-monitor-server 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.53.0
1.25.10

Open the chart page →

753
clusternet-controller-managerclusternet1.0.01 of 1See more

clusternet-controller-manager clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-controller-manager:v1.0.02ce077d3d02d
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.53.0
1.25.10

Open the chart page →

1,556
cluster-network-policy-operatorcluster-network-policy-operatorVerified publisher1.1.01 of 1See more

cluster-network-policy-operator cluster-network-policy-operator 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/desuuuu/cluster-network-policy-operator:v1.1.0d943d13c5281
stdlib@go1.26.0
1.25.10

Open the chart page →

228
cluster-octopuscluster-octopus1.0.01 of 1See more

cluster-octopus cluster-octopus 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.53.0
1.25.10

Open the chart page →

1,040
clusterpedia-coreclusterpedia0.1.13 of 3See more

clusterpedia-core clusterpedia 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/clusterpedia-io/clusterpedia/apiserver:v0.6.03d089d9078f8
stdlib@go1.19.4
1.25.10
ghcr.io/clusterpedia-io/clusterpedia/clustersynchro-manager:v0.6.082cc9a77f6d6
stdlib@go1.19.4
1.25.10
ghcr.io/clusterpedia-io/clusterpedia/controller-manager:v0.6.081669df338e0
stdlib@go1.19.4
1.25.10

Open the chart page →

3,135
d2-prometheus-exportercmacraeVerified publisher0.1.01 of 1See more

d2-prometheus-exporter cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
stdlib@go1.15
1.25.10

Open the chart page →

1,299
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.17
0.53.0
1.25.10

Open the chart page →

2,090

Container images carrying it

4,778 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.6
0.53.0
1.25.10
1
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.7
0.53.0
1.25.10
1
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.10
0.53.0
1.25.10
1
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10
1
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.18.3
0.53.0
1.25.10
1
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/net@v0.9.0
stdlib@go1.24.4
0.53.0
1.25.10
1
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.53.0
1.25.10
1
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
stdlib@go1.26.0
1.25.10
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
golang.org/x/net@v0.24.0
stdlib@go1.21.12
0.53.0
1.25.10
1
ghcr.io/movetokube/postgres-operator:2.4.0def57d85a2da
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10
1
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.8
0.53.0
1.25.10
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
golang.org/x/net@v0.30.0
stdlib@go1.23.6
0.53.0
1.25.10
1
ghcr.io/msueberkrueb/cloudflare-dyndns:1.0.0e5c945a3b000
stdlib@go1.25.1
1.25.10
1
ghcr.io/muhmmadayan/fake-network-operator:0.1.03806b1fd4a4b
golang.org/x/net@v0.28.0
stdlib@go1.23.12
0.53.0
1.25.10
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
golang.org/x/net@v0.17.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.15.6
0.53.0
1.25.10
1
ghcr.io/mydecisive/octant:0.1.86ebbd44abae6c
golang.org/x/net@v0.52.0
0.53.0
1
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.5
0.53.0
1.25.10
1
ghcr.io/naval-group/butane-operator:v0.1.1-rc285818b510780
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.53.0
1.25.10
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.53.0
1.25.10
1
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
golang.org/x/net@v0.13.0
stdlib@go1.21.1
0.53.0
1.25.10
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
golang.org/x/net@v0.23.0
stdlib@go1.21.11
0.53.0
1.25.10
1
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
stdlib@go1.17.3
1.25.10
1
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
stdlib@go1.22.4
1.25.10
1
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.6
0.53.0
1.25.10
1
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.17
0.53.0
1.25.10
1
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
stdlib@go1.16.8
0.53.0
1.25.10
1
ghcr.io/nginx/nginx-gateway-fabric:2.4.180f3a0a51af5
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/nicholaswilde/golinks:version-154c5818e67b26324c5
stdlib@go1.16.5
1.25.10
1
ghcr.io/nicholaswilde/installer:version-0.2.947d8ecd310a9
stdlib@go1.15.3
1.25.10
1
ghcr.io/nicholaswilde/notes:version-ee287b9ab9bc16465bc
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.5
0.53.0
1.25.10
1
ghcr.io/nicholaswilde/olivetin:version-2021-07-19e1d5c8a01008
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.5
0.53.0
1.25.10
1
ghcr.io/nicholaswilde/shiori:version-v1.5.0e0645abe6777
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.16.5
0.53.0
1.25.10
1
ghcr.io/nicholaswilde/static:version-ee8a20cd1d47c730bc4
stdlib@go1.16.5
1.25.10
1
ghcr.io/nicholaswilde/todo:941c0d3-ls1d7ba1341a940
stdlib@go1.14.15
1.25.10
1
ghcr.io/nicholaswilde/twtxt:version-0.1.158736a73ca10
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.5
0.53.0
1.25.10
1
ghcr.io/nicholaswilde/wiki:version-900b76a6c4f261d8f5e
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.16.5
0.53.0
1.25.10
1
ghcr.io/nicholaswilde/writefreely:version-0.13.1c3c8481b7e56
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.12
0.53.0
1.25.10
1
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.6
0.53.0
1.25.10
1
ghcr.io/nimbolus/terraform-backend:0.2.2bf876252fbe1
golang.org/x/net@v0.46.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/nlamirault/bbox_exporter:1.0.0f5dd1f7794c6
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.18.3
0.53.0
1.25.10
1
ghcr.io/nlamirault/freebox-exporter:1.0.02d522b664e12
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.2
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.