StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,162
of 17,821 indexed, latest versions
Container images
4,792
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,162 of 17,821 indexed charts deploy, on 4,792 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,634
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,652
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,162 by stars
ChartLatestAffected imagesRadar Score
metrics-servergpg-dev3.12.11 of 1See more

metrics-server gpg-dev 3.12.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/net@v0.20.0
stdlib@go1.21.8
0.53.0
1.25.10

Open the chart page →

1,086
opentelemetry-demogpg-dev0.33.88 of 27See more

opentelemetry-demo gpg-dev 0.33.8

8 of the 27 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.53.0
1.25.10
jaegertracing/all-in-one:1.53.060e65bfffe1f
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.53.0
1.25.10
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
golang.org/x/net@v0.27.0
stdlib@go1.22.5
0.53.0
1.25.10
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
golang.org/x/net@v0.25.0
stdlib@go1.22.8
0.53.0
1.25.10
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
golang.org/x/net@v0.25.0
stdlib@go1.22.8
0.53.0
1.25.10
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.0.03b9b2a15d376
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

50,088
prometheusgpg-dev29.2.16 of 6See more

prometheus gpg-dev 29.2.1

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.90.1693faa0b8724
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.32.058e117eabcce
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
quay.io/prometheus/prometheus:v3.11.2cd37346c9745
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

3,309
prometheus-operator-admission-webhookgpg-dev0.18.12 of 2See more

prometheus-operator-admission-webhook gpg-dev 0.18.1

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/admission-webhook:v0.79.2d4c97a1b2d67
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.53.0
1.25.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.53.0
1.25.10

Open the chart page →

1,687
thanosgpg-dev0.5.31 of 1See more

thanos gpg-dev 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

602
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

1,309
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

1,582
whoami-demogpg-dev0.1.01 of 1See more

whoami-demo gpg-dev 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.25.10

Open the chart page →

1,280
grafana-cloud-onboardinggrafana0.4.75 of 5See more

grafana-cloud-onboarding grafana 0.4.7

5 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/beyla-k8s-cache:253b2f561cb1b
golang.org/x/net@v0.48.0
stdlib@go1.25.3
0.53.0
1.25.10
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
stdlib@go1.23.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

4,738
grafana-samplinggrafana1.1.72 of 2See more

grafana-sampling grafana 1.1.7

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10

Open the chart page →

3,412
mimir-openshift-experimentalgrafana2.1.03 of 4See more

mimir-openshift-experimental grafana 2.1.0

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.8
0.53.0
1.25.10
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.53.0
1.25.10
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.53.0
1.25.10

Open the chart page →

17,818
pyroscope-monitoringgrafana0.1.15 of 6See more

pyroscope-monitoring grafana 0.1.1

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
stdlib@go1.23.6
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

8,493
snyk-exportergrafana0.1.01 of 1See more

snyk-exporter grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/snyk_exporter:v1.4.1d3c9093401ca
stdlib@go1.21.0
1.25.10

Open the chart page →

670
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.53.0
1.25.10
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.53.0
1.25.10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.53.0
1.25.10
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.53.0
1.25.10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.53.0
1.25.10

Open the chart page →

5,324
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

7,521
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/net@v0.26.0
stdlib@go1.18.10
0.53.0
1.25.10

Open the chart page →

83,520
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:85d7043a4ffe0
stdlib@go1.24.6
1.25.10

Open the chart page →

5,026
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/net@v0.24.0
stdlib@go1.21.10
0.53.0
1.25.10

Open the chart page →

1,399
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

14,304
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.53.0
1.25.10

Open the chart page →

2,608
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

2,183
routergroundcover1.12.3784 of 7See more

router groundcover 1.12.378

4 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
stdlib@go1.25.7
1.25.10
quay.io/groundcover/tools:20260719b705e0cbe171
stdlib@go1.24.4
1.25.10

Open the chart page →

6,192
mysqlgroundhog2k3.1.41 of 1See more

mysql groundhog2k 3.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
stdlib@go1.24.6
1.25.10

Open the chart page →

463
tailscale-subnet-routergtaylor1.2.11 of 1See more

tailscale-subnet-router gtaylor 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
golang.org/x/net@v0.1.0
stdlib@go1.19.2-ts3fd24dee31
0.53.0
1.25.10

Open the chart page →

1,835
minifluxhajowielandVerified publisher1.0.01 of 1See more

miniflux hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.53.0
1.25.10

Open the chart page →

1,259
hakoniwahakoniwa0.1.01 of 1See more

hakoniwa hakoniwa 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/aplulu/hakoniwa:0.1.0accf0b921388
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

338
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.53.0
1.25.10

Open the chart page →

2,382
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.3
0.53.0
1.25.10

Open the chart page →

4,463
mautrix-signalhalkeye0.3.01 of 2See more

mautrix-signal halkeye 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
signald/signald:0.23.2edbff058278c
stdlib@go1.18.10
1.25.10

Open the chart page →

1,500
thunderdome-planning-pokerhalkeye0.1.11 of 1See more

thunderdome-planning-poker halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

432
whoamihalkeye1.0.11 of 1See more

whoami halkeye 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
containous/whoami:v1.5.07d6a3c8f9147
stdlib@go1.14
1.25.10

Open the chart page →

1,280
hcp-terraform-operatorhashicorpVerified publisher2.12.11 of 2See more

hcp-terraform-operator hashicorp 2.12.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.20.1f5fbfec6a2b2
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10

Open the chart page →

692
hatchet-apihatchetOfficialVerified publisher0.19.01 of 4See more

hatchet-api hatchet 0.19.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

1,658
hatchet-hahatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-ha hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

7,427
hatchet-stackhatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-stack hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
stdlib@go1.24.6
1.25.10

Open the chart page →

7,427
hawk-envoy-pluginhawk0.1.02 of 4See more

hawk-envoy-plugin hawk 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/collector-go:main7217f1a4fa28
stdlib@go1.17.13
1.25.10
ghcr.io/privacyengineering/consumer:main73f59c032812
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.13
0.53.0
1.25.10

Open the chart page →

66,025
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.6
0.53.0
1.25.10

Open the chart page →

3,030
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/net@v0.0.0-20200520182314-0ba52f642ac2
stdlib@go1.14.7
0.53.0
1.25.10

Open the chart page →

2,638
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.25.10

Open the chart page →

6,772
headcniheadcni1.0.101 of 1See more

headcni headcni 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
binrc/headcni:1.0.10e199c334b957
stdlib@go1.22.10
1.25.10

Open the chart page →

725
heliconehelicone0.1.422 of 14See more

helicone helicone 0.1.42

2 of the 14 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
stdlib@go1.19.5
1.25.10
supabase/gotrue:v2.91.07174d551d720
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.53.0
1.25.10

Open the chart page →

77,076
hello-gohello-goVerified publisher0.2.21 of 1See more

hello-go hello-go 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.25.10

Open the chart page →

1,315
hello_worldcharthellohelm0.1.01 of 1See more

hello_worldchart hellohelm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
dockerdaemon0901/rolldice:v14e5bfe179c7e
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.53.0
1.25.10

Open the chart page →

863
helm-airportshelm-airports0.1.02 of 7See more

helm-airports helm-airports 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

12,681
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,559
airports-postgreshelm-airports-dan0.1.01 of 1See more

airports-postgres helm-airports-dan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10

Open the chart page →

1,027
helm-airportshelm-airports-dan0.1.02 of 7See more

helm-airports helm-airports-dan 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

5,586
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.53.0
1.25.10

Open the chart page →

4,559
airports-postgreshelm-airports-postgres0.1.01 of 1See more

airports-postgres helm-airports-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.25.10

Open the chart page →

1,027
jenkinshelm-chart-for-jenkinsVerified publisher1.0.01 of 1See more

jenkins helm-chart-for-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

2,451

Container images carrying it

4,792 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/cloudnatix/llmariner/session-manager-server:0.1.0-gfu-devb9537499ff9e
golang.org/x/net@v0.35.0
stdlib@go1.23.7
0.53.0
1.25.10
1
public.ecr.aws/cloudnatix/llmariner/session-manager-server:1.9.0f24ecd37fbaa
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.53.0
1.25.10
1
public.ecr.aws/cloudnatix/llmariner/vector-store-manager-server:1.7.0f1f6b884b325
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.53.0
1.25.10
1
public.ecr.aws/csi-components/csi-node-driver-registrar:v2.16.0-eksbuild.3592d7034d6c7
golang.org/x/net@v0.49.0
stdlib@go1.26.1
0.53.0
1.25.10
1
public.ecr.aws/csi-components/livenessprobe:v2.18.0-eksbuild.38e307f4e5820
golang.org/x/net@v0.49.0
stdlib@go1.26.1
0.53.0
1.25.10
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
golang.org/x/net@v0.47.0
stdlib@go1.24.9
0.53.0
1.25.10
1
public.ecr.aws/decisiveai/mdai-s3-logs-reader:0.0.8d1e35167eec5
golang.org/x/net@v0.40.0
stdlib@go1.24.10
0.53.0
1.25.10
1
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
golang.org/x/net@v0.5.0
stdlib@go1.20
0.53.0
1.25.10
1
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.53.0
1.25.10
1
public.ecr.aws/eks/amazon-eks-pod-identity-webhook:v0.6.173071570e8e8c
golang.org/x/net@v0.49.0
0.53.0
1
public.ecr.aws/eks-distro/kubernetes/kube-scheduler:v1.29.14-eks-1-29-lateste7e1db003e6a
golang.org/x/net@v0.24.0
stdlib@go1.22.12
0.53.0
1.25.10
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
stdlib@go1.23.5
1.25.10
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
stdlib@go1.20.12
1.25.10
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
1
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
1
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.53.0
1.25.10
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
stdlib@go1.25.7
1.25.10
1
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.15.15
0.53.0
1.25.10
1
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.9
0.53.0
1.25.10
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-agent:v3.0.1d75b6da94913
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.53.0
1.25.10
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
stdlib@go1.25.9
1.25.10
1
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.53.0
1.25.10
1
public.ecr.aws/karpenter/controller:1.9.030a506c64fbb
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.53.0
1.25.10
1
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.53.0
1.25.10
1
public.ecr.aws/karpenter/controller:1.1.1fe383abf1dbc
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.53.0
1.25.10
1
public.ecr.aws/kyos/evicted-pod-reaper:1.0.0b9d047442ce2
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10
1
public.ecr.aws/lumigo/lumigo-kubernetes-operator:69491c39346b19
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.53.0
1.25.10
1
public.ecr.aws/lumigo/lumigo-kubernetes-rbac-proxy:696c2f0585cd6c
golang.org/x/net@v0.10.0
stdlib@go1.22.12
0.53.0
1.25.10
1
public.ecr.aws/lumigo/lumigo-kubernetes-telemetry-proxy:691d548e59c2c8
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10
1
public.ecr.aws/lumigo/lumigo-kubernetes-watchdog:696458fcd61e0c
golang.org/x/net@v0.37.0
stdlib@go1.23.12
0.53.0
1.25.10
1
public.ecr.aws/n8h5y2v5/rad-security/rad-bootstrapper:v1.1.115ca2d500d374
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
1
public.ecr.aws/n8h5y2v5/rad-security/rad-guard:v1.1.17a94d2d4aae85
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
1
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
1
public.ecr.aws/n8h5y2v5/rad-security/rad-sync:v1.1.1514f3dfbc0225
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
1
public.ecr.aws/n8h5y2v5/rad-security/rad-watch:v1.1.25b9a7d6bc2a0c
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.53.0
1.25.10
1
public.ecr.aws/neuron/neuron-device-plugin:2.23.30.075a6d5ce3bd3
golang.org/x/net@v0.23.0
stdlib@go1.20.4
0.53.0
1.25.10
1
public.ecr.aws/neuron/neuron-scheduler:2.23.30.04cd274463e6b
golang.org/x/net@v0.23.0
stdlib@go1.20.4
0.53.0
1.25.10
1
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
golang.org/x/net@v0.28.0
stdlib@go1.22.6
0.53.0
1.25.10
1
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
golang.org/x/net@v0.33.0
stdlib@go1.23.0
0.53.0
1.25.10
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
stdlib@go1.20.2
1.25.10
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.53.0
1.25.10
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.53.0
1.25.10
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/net@v0.39.0
stdlib@go1.21.6
0.53.0
1.25.10
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.53.0
1.25.10
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.5
0.53.0
1.25.10
1
public.ecr.aws/sumologic/tailing-sidecar-operator:0.111.0920b8f901aef
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.53.0
1.25.10
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.1
0.53.0
1.25.10
1
public.ecr.aws/t0u0d5o5/ecr_authenticator:latest077e4e57e41c
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.53.0
1.25.10
1
public.ecr.aws/truefoundrycloud/eks/eks-node-monitoring-agent:v1.5.1-eksbuild.1988c8e1a273a
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.53.0
1.25.10
1
public.ecr.aws/v0r6c2e2/minio:latest08c90bd040bf
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.