StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,155
of 17,813 indexed, latest versions
Container images
4,778
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,155 of 17,813 indexed charts deploy, on 4,778 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+181 more1.25.104,618
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,640
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,155 by stars
ChartLatestAffected imagesRadar Score
pod-gatewayangelnu7.1.11 of 2See more

pod-gateway angelnu 7.1.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/angelnu/gateway-admision-controller:v3.12.06f6ab596afd5
golang.org/x/net@v0.30.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

1,282
ansible-semaphoreansible-semaphore0.1.01 of 1See more

ansible-semaphore ansible-semaphore 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.25.10

Open the chart page →

4,022
aperture-controlleraperture2.34.03 of 5See more

aperture-controller aperture 2.34.0

3 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
fluxninja/aperture-operator:2.34.0356d7aa86632
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.25.10
quay.io/prometheus/prometheus:v2.33.591100b06e86d
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.8
0.53.0
1.25.10

Open the chart page →

4,681
k8upappuio2.0.51 of 1See more

k8up appuio 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.53.0
1.25.10

Open the chart page →

3,308
limesurveyarea-42Verified publisher0.3.961 of 2See more

limesurvey area-42 0.3.96

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.25.10

Open the chart page →

4,539
athens-proxyathens-chartsOfficialVerified publisher0.17.11 of 1See more

athens-proxy athens-charts 0.17.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gomods/athens:v0.18.197cc113b34b0
stdlib@go1.24.1
1.25.10

Open the chart page →

1,307
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.53.0
1.25.10

Open the chart page →

9,064
prometheusaveshaVerified publisher19.3.04 of 4See more

prometheus avesha 19.3.0

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.25.10
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
stdlib@go1.19.3
0.53.0
1.25.10

Open the chart page →

5,505
aws-calicoaws0.3.111 of 1See more

aws-calico aws 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

2,251
aws-node-termination-handleraws-node-termination-handler0.27.61 of 1See more

aws-node-termination-handler aws-node-termination-handler 0.27.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.25.69ad31fb4e5be
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

528
snapschedulerbackube-helm-chartsVerified publisher3.5.02 of 2See more

snapscheduler backube-helm-charts 3.5.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/backube/snapscheduler:3.5.035ac95c51780
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.53.0
1.25.10
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

1,240
yataibentomlVerified publisher1.1.131 of 1See more

yatai bentoml 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

1,917
yatai-deploymentbentomlVerified publisher1.1.211 of 2See more

yatai-deployment bentoml 1.1.21

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.53.0
1.25.10

Open the chart page →

1,160
boundaryboundaryVerified publisher0.1.01 of 1See more

boundary boundary 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hashicorp/boundary:0.21.037bf86488b74
golang.org/x/net@v0.47.0
stdlib@go1.25.1
0.53.0
1.25.10

Open the chart page →

1,591
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.19.12
1.25.10

Open the chart page →

69,135
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.53.0
1.25.10

Open the chart page →

1,901
cadvisorcadvisorVerified publisher0.1.151 of 1See more

cadvisor cadvisor 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.53.0
1.25.10

Open the chart page →

1,705
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.53.0
1.25.10
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.53.0
1.25.10

Open the chart page →

7,801
popeyechristianhuthVerified publisher2.4.31 of 1See more

popeye christianhuth 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10

Open the chart page →

1,342
hellocloudechoVerified publisher0.1.21 of 1See more

hello cloudecho 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.25.10

Open the chart page →

1,818
cloudflare-exportercloudflare-exporter0.2.31 of 1See more

cloudflare-exporter cloudflare-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/lablabs/cloudflare_exporter:0.0.1670d74ec46602
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10

Open the chart page →

791
ghostcloudpirates-ghostVerified publisher0.20.253 of 3See more

ghost cloudpirates-ghost 0.20.25

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/ghost:6.64.0a31d03f1f629
stdlib@go1.24.6
1.25.10
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.25.10
library/mariadb:13.0.2d4fdec0510ad
stdlib@go1.24.6
1.25.10

Open the chart page →

7,009
dumpscriptcloudscriptVerified publisher1.8.31 of 1See more

dumpscript cloudscript 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

2,130
clowardenclowarden0.2.32 of 4See more

clowarden clowarden 0.2.3

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.25.10
ghcr.io/cncf/clowarden/dbmigrator:v0.2.3c022fd42de45
stdlib@go1.25.3
1.25.10

Open the chart page →

5,688
cluster-manager-servercluster-manager-server1.8.01 of 1See more

cluster-manager-server cluster-manager-server 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

753
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
golang.org/x/net@v0.7.0
stdlib@go1.18
0.53.0
1.25.10

Open the chart page →

1,708
coder-observabilitycoder-observabilityVerified publisher0.7.313 of 21See more

coder-observability coder-observability 0.7.3

13 of the 21 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.53.0
1.25.10
grafana/grafana:10.4.19a9043254ba16
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.53.0
1.25.10
grafana/loki:3.1.0d947e68a84d9
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.53.0
1.25.10
grafana/loki-canary:3.1.039baf6d67f85
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.53.0
1.25.10
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.25.10
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.53.0
1.25.10
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.6
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.53.0
1.25.10
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

24,968
convertigoconvertigoOfficialVerified publisher8.4.32 of 5See more

convertigo convertigo 8.4.3

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
timescale/timescaledb:latest-pg16f495f2bc25ca
stdlib@go1.26.2
1.25.10

Open the chart page →

17,183
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

3,089
cosmocosmo-platformOfficialVerified publisher0.20.06 of 10See more

cosmo cosmo-platform 0.20.0

6 of the 10 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.53.0
1.25.10
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.25.10
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.53.0
1.25.10
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.53.0
1.25.10
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
golang.org/x/net@v0.26.0
stdlib@go1.23.6
0.53.0
1.25.10
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
stdlib@go1.20.7
1.25.10

Open the chart page →

29,737
crossviewcrossviewOfficialVerified publisher4.6.01 of 2See more

crossview crossview 4.6.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
stdlib@go1.24.6
1.25.10

Open the chart page →

1,435
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
golang.org/x/net@v0.25.0
stdlib@go1.21.13
0.53.0
1.25.10

Open the chart page →

1,322
deepflowdeepflow6.2.2015 of 8See more

deepflow deepflow 6.2.201

5 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.25.10
deepflowce/deepflow-init-grafana:v6.2.27cd16719eb57
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.3
0.53.0
1.25.10
deepflowce/deepflow-server:v6.2.21477e7334d13
golang.org/x/net@v0.2.0
stdlib@go1.18.10
0.53.0
1.25.10
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.25.10
grafana/grafana:9.3.6e5a9655dabef
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

16,008
defensia-agentdefensia-agentOfficialVerified publisher0.6.01 of 1See more

defensia-agent defensia-agent 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/defensia/agent:1.4.57e9d40ae44711
golang.org/x/net@v0.47.0
0.53.0

Open the chart page →

64
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
golang.org/x/net@v0.17.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

3,482
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10

Open the chart page →

1,624
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.53.0
1.25.10

Open the chart page →

2,538
prometheus-locust-exporterdeliveryheroVerified publisher1.2.31 of 1See more

prometheus-locust-exporter deliveryhero 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.25.10

Open the chart page →

1,277
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.25.10

Open the chart page →

4,237
bscdysnixVerified publisher0.6.591 of 4See more

bsc dysnix 0.6.59

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.53.0
1.25.10

Open the chart page →

1,905
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.53.0
1.25.10

Open the chart page →

2,272
postgres-pgdump-backupeugen0.7.61 of 1See more

postgres-pgdump-backup eugen 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.25.10

Open the chart page →

353
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

12,059
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

14,562
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10

Open the chart page →

13,891
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.25.10

Open the chart page →

5,324
flyte-binaryflyte2.0.491 of 4See more

flyte-binary flyte 2.0.49

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:15-alpinea46e076249ce
stdlib@go1.24.6
1.25.10

Open the chart page →

4,020
flyte-coreflyte2.0.491 of 3See more

flyte-core flyte 2.0.49

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:15-alpinea46e076249ce
stdlib@go1.24.6
1.25.10

Open the chart page →

416
frp-operatorfrpVerified publisher1.0.41 of 1See more

frp-operator frp 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/aureum-cloud/frp-operator:v1.0.196b01d7e7025
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

382
frp-operatorfrp-operator1.9.01 of 1See more

frp-operator frp-operator 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
golang.org/x/net@v0.23.0
stdlib@go1.23.12
0.53.0
1.25.10

Open the chart page →

542

Container images carrying it

4,778 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
stdlib@go1.26.2
1.25.10
1
ghcr.io/siderolabs/talos-backup:v0.1.0-beta.203a71e140f1d
golang.org/x/net@v0.26.0
stdlib@go1.23.0
0.53.0
1.25.10
1
ghcr.io/sigstore/policy-controller/policy-controller0bcd60beb93f
golang.org/x/net@v0.39.0
stdlib@go1.24.7
0.53.0
1.25.10
1
ghcr.io/sigstore/scaffolding/serverae8eb69c7b70
golang.org/x/net@v0.46.0
stdlib@go1.25.0
0.53.0
1.25.10
1
ghcr.io/sigstore/sigstore-probers/prober:v1.0.1d1e914e6d6b9
stdlib@go1.26.0
1.25.10
1
ghcr.io/sigstore/timestamp-server:v2.1.08637f0482ed1
stdlib@go1.25.1
1.25.10
1
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
stdlib@go1.26.2
1.25.10
1
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
golang.org/x/net@v0.26.0
stdlib@go1.22.0
0.53.0
1.25.10
1
ghcr.io/skyhook-io/skyhook-connector:v2.3.23deb8e4b1aaa
golang.org/x/net@v0.44.0
stdlib@go1.26.0
0.53.0
1.25.10
1
ghcr.io/skyhook-io/skyhook-connector:v2.5.56c4e3336600d
golang.org/x/net@v0.52.0
0.53.0
1
ghcr.io/slok/sloth:v0.16.0f0f0075b0d45
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
1
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.25.10
1
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.2
0.53.0
1.25.10
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
golang.org/x/net@v0.33.0
stdlib@go1.24.4
0.53.0
1.25.10
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
golang.org/x/net@v0.33.0
stdlib@go1.24.4
0.53.0
1.25.10
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
golang.org/x/net@v0.42.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
golang.org/x/net@v0.42.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/spidernet-io/spiderpool/spiderpool-plugins:19f19457ae7cec86457b0411543a3cf21dd9f95a8edc39be1e22
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
1
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
1
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
1
ghcr.io/spiffe/spire-ha-agent:0.5.0307cf2d05afe
stdlib@go1.25.0
1.25.10
1
ghcr.io/spiffe/spire-identity-exchange-server:v0.5.0239bc70c1988
stdlib@go1.26.0
1.25.10
1
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.53.0
1.25.10
1
ghcr.io/squat/generic-device-plugin:0.2.066c8d5c270eb
golang.org/x/net@v0.49.0
stdlib@go1.26.1
0.53.0
1.25.10
1
ghcr.io/squat/generic-device-plugin:latestdc192e164c69
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.53.0
1.25.10
1
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/stakater/reloader:v1.4.4a571c5b32c0f
golang.org/x/net@v0.39.0
stdlib@go1.24.4
0.53.0
1.25.10
1
ghcr.io/stashed/stash:v0.42.03a98245a7667
golang.org/x/net@v0.26.0
stdlib@go1.25.3
0.53.0
1.25.10
1
ghcr.io/stashed/stash-crd-installer:v0.42.076f0a650e44b
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10
1
ghcr.io/stashed/stash-crd-installer:v0.32.0c6f2a844b5dd
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.53.0
1.25.10
1
ghcr.io/stashed/stash-crd-installer:v0.42.1d6c9b7a1f7b8
golang.org/x/net@v0.38.0
stdlib@go1.25.5
0.53.0
1.25.10
1
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
golang.org/x/net@v0.38.0
stdlib@go1.25.5
0.53.0
1.25.10
1
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
golang.org/x/net@v0.15.0
stdlib@go1.20.7
0.53.0
1.25.10
1
ghcr.io/steadybit/extension-container:v1.8.1ae79f958b479
golang.org/x/net@v0.50.0
0.53.0
1
ghcr.io/steadybit/extension-host:v1.8.103a5ef26aac5
golang.org/x/net@v0.50.0
0.53.0
1
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.9
0.53.0
1.25.10
1
ghcr.io/stenic/k8status:0.17.093298e03089e
golang.org/x/net@v0.26.0
stdlib@go1.23.12
0.53.0
1.25.10
1
ghcr.io/stenic/sql-operator:1.13.2f4324baa2aad
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.53.0
1.25.10
1
ghcr.io/stenic/well-known:1.11.0ae85f257a10f
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.53.0
1.25.10
1
ghcr.io/storax/kubedoom:0.6.0851ba8c80b93
stdlib@go1.17.6
1.25.10
1
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
golang.org/x/net@v0.19.0
stdlib@go1.22.1
0.53.0
1.25.10
1
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.53.0
1.25.10
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/net@v0.41.0
stdlib@go1.24.10
0.53.0
1.25.10
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.24.5
0.53.0
1.25.10
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.53.0
1.25.10
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.53.0
1.25.10
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.