StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,202
of 17,828 indexed, latest versions
Container images
4,829
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,202 of 17,828 indexed charts deploy, on 4,829 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,668
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.53.03,685
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,202 by stars
ChartLatestAffected imagesRadar Score
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.53.0
1.25.10

Open the chart page →

6,999
neosyncneosyncVerified publisher0.5.412 of 3See more

neosync neosync 0.5.41

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
golang.org/x/net@v0.37.0
stdlib@go1.24.5
0.53.0
1.25.10
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
golang.org/x/net@v0.37.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

7,329
apineosync-apiVerified publisher0.5.411 of 1See more

api neosync-api 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
golang.org/x/net@v0.37.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

2,888
workerneosync-workerVerified publisher0.5.411 of 1See more

worker neosync-worker 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
golang.org/x/net@v0.37.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

2,866
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
stdlib@go1.25.6
1.25.10

Open the chart page →

2,402
core-keeper-dedicatednerkho-helm-charts0.1.11 of 1See more

core-keeper-dedicated nerkho-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
escaping/core-keeper-dedicated:latest87fa79255962
stdlib@go1.24.4
1.25.10

Open the chart page →

3,970
kubernetes-operatornetbird0.3.11 of 1See more

kubernetes-operator netbird 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
netbirdio/kubernetes-operator:0.3.157740157b4d7
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10

Open the chart page →

210
netbirdnetbird1.9.03 of 4See more

netbird netbird 1.9.0

3 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.53.0
1.25.10
netbirdio/relay:0.46.0d32f82514a24
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.53.0
1.25.10
netbirdio/signal:0.46.0e8f392611152
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.53.0
1.25.10

Open the chart page →

6,500
netris-dpu-agentnetrisai0.1.01 of 1See more

netris-dpu-agent netrisai 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
netrisai/bare-metal-dpu-agent:4.7.0.003c271efe749d0
golang.org/x/net@v0.50.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

1,621
iamdnetsocVerified publisher0.6.11 of 2See more

iamd netsoc 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.6
0.53.0
1.25.10

Open the chart page →

2,892
shhdnetsocVerified publisher0.1.71 of 1See more

shhd netsoc 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.17
0.53.0
1.25.10

Open the chart page →

3,989
webspacednetsocVerified publisher0.2.82 of 2See more

webspaced netsoc 0.2.8

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.53.0
1.25.10
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
stdlib@go1.16.8
0.53.0
1.25.10

Open the chart page →

5,196
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

7,686
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

3,922
agent-control-cdnewrelic1.0.03 of 3See more

agent-control-cd newrelic 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
golang.org/x/net@v0.35.0
stdlib@go1.23.6
0.53.0
1.25.10
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.53.0
1.25.10

Open the chart page →

5,520
nexus-freenexus-freeVerified publisher1.0.31 of 1See more

nexus-free nexus-free 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/fossa/postgres:17.2-15af45ac79f38
stdlib@go1.18.2
1.25.10

Open the chart page →

1,123
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-backend:2.0.0f80349eb018b
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.53.0
1.25.10

Open the chart page →

3,932
nginx-examplengrok-ingress-helm0.3.01 of 2See more

nginx-example ngrok-ingress-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
wernight/ngrok:latestd211f29ebcfe
golang.org/x/net@v0.17.0
stdlib@go1.21.6
0.53.0
1.25.10

Open the chart page →

2,722
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.9
0.53.0
1.25.10

Open the chart page →

24,394
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.9
0.53.0
1.25.10

Open the chart page →

25,571
filezillanicholaswildeVerified publisher1.0.11 of 1See more

filezilla nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/filezilla:version-3.51.0-r15103cdd266ce
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.12
0.53.0
1.25.10

Open the chart page →

3,177
golinksnicholaswildeVerified publisher1.0.01 of 1See more

golinks nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/golinks:version-154c5818e67b26324c5
stdlib@go1.16.5
1.25.10

Open the chart page →

1,118
notesnicholaswildeVerified publisher1.0.01 of 1See more

notes nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/notes:version-ee287b9ab9bc16465bc
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.5
0.53.0
1.25.10

Open the chart page →

1,482
olivetinnicholaswildeVerified publisher1.0.21 of 1See more

olivetin nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/olivetin:version-2021-07-19e1d5c8a01008
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.5
0.53.0
1.25.10

Open the chart page →

1,670
podgrabnicholaswildeVerified publisher0.1.01 of 1See more

podgrab nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.2
0.53.0
1.25.10

Open the chart page →

2,402
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.11
0.53.0
1.25.10

Open the chart page →

22,447
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.12
0.53.0
1.25.10

Open the chart page →

23,673
staticnicholaswildeVerified publisher1.0.01 of 1See more

static nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/static:version-ee8a20cd1d47c730bc4
stdlib@go1.16.5
1.25.10

Open the chart page →

1,155
todonicholaswildeVerified publisher0.1.01 of 1See more

todo nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/todo:941c0d3-ls1d7ba1341a940
stdlib@go1.14.15
1.25.10

Open the chart page →

1,230
twtxtnicholaswildeVerified publisher1.0.01 of 1See more

twtxt nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/twtxt:version-0.1.158736a73ca10
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.5
0.53.0
1.25.10

Open the chart page →

2,334
wikinicholaswildeVerified publisher1.0.01 of 1See more

wiki nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/wiki:version-900b76a6c4f261d8f5e
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.16.5
0.53.0
1.25.10

Open the chart page →

1,789
cert-managernicklasfrahm-cert-managerVerified publisher0.1.24 of 4See more

cert-manager nicklasfrahm-cert-manager 0.1.2

4 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.18.2af59e01ad975
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
quay.io/jetstack/cert-manager-controller:v1.18.281316365dc0b
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
quay.io/jetstack/cert-manager-startupapicheck:v1.18.21075e0974151
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
quay.io/jetstack/cert-manager-webhook:v1.18.29431f0d8b510
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

2,856
ciliumnicklasfrahm-ciliumVerified publisher0.7.45 of 6See more

cilium nicklasfrahm-cilium 0.7.4

5 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
golang.org/x/net@v0.41.0
stdlib@go1.24.2
0.53.0
1.25.10
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
golang.org/x/net@v0.41.0
stdlib@go1.24.7
0.53.0
1.25.10
quay.io/cilium/hubble-relay:v1.18.26079308ee15e
golang.org/x/net@v0.42.0
stdlib@go1.24.7
0.53.0
1.25.10
quay.io/cilium/hubble-ui-backend:v0.13.3db1454e45dc3
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.53.0
1.25.10
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
golang.org/x/net@v0.42.0
stdlib@go1.24.7
0.53.0
1.25.10

Open the chart page →

7,312
metrics-servernicklasfrahm-metrics-serverVerified publisher0.1.11 of 1See more

metrics-server nicklasfrahm-metrics-server 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.53.0
1.25.10

Open the chart page →

799
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
stdlib@go1.21.5
1.25.10

Open the chart page →

2,293
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.6
0.53.0
1.25.10

Open the chart page →

2,064
terraform-backendnimbolus0.3.21 of 2See more

terraform-backend nimbolus 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/terraform-backend:0.2.2bf876252fbe1
golang.org/x/net@v0.46.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

2,516
yopassnimbolus0.6.11 of 2See more

yopass nimbolus 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
jhaals/yopass:11.17.026873480863b
stdlib@go1.20.5
1.25.10

Open the chart page →

1,838
airflownineinfra-charts1.12.12 of 4See more

airflow nineinfra-charts 1.12.1

2 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.25.10
quay.io/prometheus/statsd-exporter:v0.22.8f53cca722a03
stdlib@go1.18.6
1.25.10

Open the chart page →

2,260
cloudnative-pgnineinfra-charts0.19.11 of 1See more

cloudnative-pg nineinfra-charts 0.19.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,188
doris-operatornineinfra-charts1.3.11 of 1See more

doris-operator nineinfra-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
selectdb/doris.k8s-operator:1.3.1919210765cb8
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.53.0
1.25.10

Open the chart page →

870
hdfs-operatornineinfra-charts0.7.01 of 1See more

hdfs-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/hdfs-operator:v0.7.0debb1e3410e2
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

724
kyuubi-operatornineinfra-charts0.7.01 of 1See more

kyuubi-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/kyuubi-operator:v0.7.08d8ed87ef77c
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.53.0
1.25.10

Open the chart page →

815
metastore-operatornineinfra-charts0.7.01 of 1See more

metastore-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/metastore-operator:v0.7.011259032fb04
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.53.0
1.25.10

Open the chart page →

815
minio-directpvnineinfra-charts4.0.85 of 5See more

minio-directpv nineinfra-charts 4.0.8

5 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/minio/csi-node-driver-registrardigest-pinnedc805fdc16676
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
quay.io/minio/csi-provisionerdigest-pinned7b5c070ec70d
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
quay.io/minio/csi-resizerdigest-pinned819f68a4daf7
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10
quay.io/minio/directpv:v4.0.84560083eb77d
golang.org/x/net@v0.8.0
stdlib@go1.21.0
0.53.0
1.25.10
quay.io/minio/livenessprobedigest-pinnedf3bc9a84f149
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.53.0
1.25.10

Open the chart page →

7,073
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
golang.org/x/net@v0.13.0
stdlib@go1.21.1
0.53.0
1.25.10

Open the chart page →

3,427
nineinfranineinfra-charts0.7.01 of 1See more

nineinfra nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/nineinfra:v0.7.0d4aad414eccd
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

1,121
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.25.10

Open the chart page →

3,975
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

1,440
zookeeper-operatornineinfra-charts0.7.01 of 1See more

zookeeper-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
nineinfra/zookeeper-operator:v0.7.0af6eb2f37bfc
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10

Open the chart page →

724

Container images carrying it

4,829 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
golang.org/x/net@v0.38.0
stdlib@go1.24.0
0.53.0
1.25.10
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
stdlib@go1.16.5
0.53.0
1.25.10
1
quay.io/argoproj/argocd:v2.10.783c86003b781
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.53.0
1.25.10
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
golang.org/x/net@v0.33.0
stdlib@go1.22.7
0.53.0
1.25.10
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
golang.org/x/net@v0.40.0
stdlib@go1.22.7
0.53.0
1.25.10
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/net@v0.17.0
stdlib@go1.20.4
0.53.0
1.25.10
1
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10
1
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
1
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
golang.org/x/net@v0.49.0
stdlib@go1.24.11
0.53.0
1.25.10
1
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
golang.org/x/net@v0.10.0
stdlib@go1.21.11
0.53.0
1.25.10
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
golang.org/x/net@v0.52.0
0.53.0
1
quay.io/argoprojlabs/argocd-operator:v0.18.0a09814522a72
golang.org/x/net@v0.49.0
0.53.0
1
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
stdlib@go1.18.4
0.53.0
1.25.10
1
quay.io/argoprojlabs/argocd-rbac-operator:v0.2.451dded00137a
golang.org/x/net@v0.40.0
stdlib@go1.24.9
0.53.0
1.25.10
1
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.53.0
1.25.10
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
1
quay.io/argoproj/workflow-controller:v3.7.11c46aa0ded8ed
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.53.0
1.25.10
1
quay.io/backube/snapscheduler:3.5.035ac95c51780
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.53.0
1.25.10
1
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/net@v0.40.0
0.53.0
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.4
0.53.0
1.25.10
1
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.53.0
1.25.10
1
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.53.0
1.25.10
1
quay.io/bentoml/yatai-image-builder:3.0.4401d8538c4f48
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.53.0
1.25.10
1
quay.io/brancz/kube-rbac-proxy:v0.15.02c7b120590cb
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.53.0
1.25.10
1
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.53.0
1.25.10
1
quay.io/brancz/kube-rbac-proxy:v0.18.0754ab2a723c8
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.53.0
1.25.10
1
quay.io/brancz/kube-rbac-proxy:v0.20.1f5fbfec6a2b2
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.53.0
1.25.10
1
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.53.0
1.25.10
1
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.5
0.53.0
1.25.10
1
quay.io/cephcsi/ceph-csi-operator:v0.5.014fe2f1bffc3
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
1
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
stdlib@go1.15.7
1.25.10
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.53.0
1.25.10
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
golang.org/x/net@v0.41.0
stdlib@go1.24.2
0.53.0
1.25.10
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.53.0
1.25.10
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
golang.org/x/net@v0.41.0
stdlib@go1.24.7
0.53.0
1.25.10
1
quay.io/cilium/hubble-relay:v1.18.26079308ee15e
golang.org/x/net@v0.42.0
stdlib@go1.24.7
0.53.0
1.25.10
1
quay.io/cilium/hubble-ui-backend:v0.13.3db1454e45dc3
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.53.0
1.25.10
1
quay.io/cilium/operator-generic:v1.17.14773886ec9337
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.53.0
1.25.10
1
quay.io/cilium/operator-generic:v1.15.1819c7281f5a4
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.53.0
1.25.10
1
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
golang.org/x/net@v0.42.0
stdlib@go1.24.7
0.53.0
1.25.10
1
quay.io/cilium/tetragon:v1.1.096fac2482898
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.53.0
1.25.10
1
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.19.2
0.53.0
1.25.10
1
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.18.3
0.53.0
1.25.10
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18.1
0.53.0
1.25.10
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/net@v0.14.0
stdlib@go1.19.10
0.53.0
1.25.10
1
quay.io/codefresh/dind:3.0.250885ab519dac
golang.org/x/net@v0.43.0
0.53.0
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
stdlib@go1.23.8
1.25.10
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.