StackRadar

CVE-2026-33814

Unscored

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4,162
of 17,821 indexed, latest versions
Container images
4,792
deployed by those charts
Fix available
2 of 2
affected packages

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Carried by container images the latest versions of 4,162 of 17,821 indexed charts deploy, on 4,792 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+182 more1.25.104,634
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+218 more0.53.03,652
OSV records
GO-2026-4918
Also known as
BIT-golang-2026-33814

Charts affected

4,162 by stars
ChartLatestAffected imagesRadar Score
cert-manager-webhook-hcloud-zonescert-manager-webhook-hcloud-zones0.1.51 of 1See more

cert-manager-webhook-hcloud-zones cert-manager-webhook-hcloud-zones 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/cert-manager-webhook-hcloud-zones:0.1.5a7a846bba3e8
golang.org/x/net@v0.52.0
0.53.0

Open the chart page →

422
cert-manager-webhook-infoblox-wapicert-manager-webhook-infoblox-wapiVerified publisher1.5.21 of 1See more

cert-manager-webhook-infoblox-wapi cert-manager-webhook-infoblox-wapi 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

2,353
cert-manager-webhook-namecheapcert-manager-webhook-namecheap0.1.21 of 1See more

cert-manager-webhook-namecheap cert-manager-webhook-namecheap 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.53.0
1.25.10

Open the chart page →

1,767
cert-manager-webhook-pdnscert-manager-webhook-pdns3.2.51 of 1See more

cert-manager-webhook-pdns cert-manager-webhook-pdns 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
zachomedia/cert-manager-webhook-pdns:v2.5.54940e227a39b
golang.org/x/net@v0.50.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

1,088
cert-manager-webhook-regerycert-manager-webhook-regery1.0.01 of 1See more

cert-manager-webhook-regery cert-manager-webhook-regery 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
darioackermann/cert-manager-webhook-regery:latest0d450bc4acc4
golang.org/x/net@v0.26.0
stdlib@go1.22.10
0.53.0
1.25.10

Open the chart page →

897
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.13
0.53.0
1.25.10
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.53.0
1.25.10

Open the chart page →

7,788
getoutlinecfi20171.2.01 of 4See more

getoutline cfi2017 1.2.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.25.10

Open the chart page →

4,546
opencvecfi20170.1.23 of 7See more

opencve cfi2017 0.1.2

3 of the 7 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.25.10
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.53.0
1.25.10
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
stdlib@go1.22.10
1.25.10

Open the chart page →

15,656
clechaosnative0.2.73 of 6See more

cle chaosnative 0.2.7

3 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.15
0.53.0
1.25.10
chaosnative/cle-license-module:2.7.062cf6adc355e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.15
0.53.0
1.25.10
chaosnative/cle-server:2.7.0e7bcff4a20c0
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

16,437
charon-relaycharonOfficialVerified publisher0.8.02 of 2See more

charon-relay charon 0.8.0

2 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

4,429
dv-podcharonOfficialVerified publisher0.19.12 of 5See more

dv-pod charon 0.19.1

2 of the 5 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10
obolnetwork/charon-dkg-sidecar:maine263be0a7440
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.53.0
1.25.10

Open the chart page →

7,529
chart-appchart-app0.3.01 of 2See more

chart-app chart-app 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

1,775
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
stdlib@go1.24.6
1.25.10

Open the chart page →

5,931
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
stdlib@go1.24.6
1.25.10

Open the chart page →

4,114
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
stdlib@go1.17.8
1.25.10

Open the chart page →

4,997
memoscharts-derwitt-devVerified publisher1.4.01 of 1See more

memos charts-derwitt-dev 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
neosmemo/memos:0.30.071a5b4738d1b
stdlib@go1.26.2
1.25.10

Open the chart page →

707
paperless-ngxcharts-derwitt-devVerified publisher2.1.41 of 1See more

paperless-ngx charts-derwitt-dev 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.25.10

Open the chart page →

4,703
yas3pcharts-derwitt-devVerified publisher0.3.11 of 1See more

yas3p charts-derwitt-dev 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
denniswitt/yas3p:0.2.488a235619af6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.53.0
1.25.10

Open the chart page →

738
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
stdlib@go1.20.12
1.25.10

Open the chart page →

2,126
checker-edgechecker-edge1.1.111 of 1See more

checker-edge checker-edge 1.1.11

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/imcitius/checker-edge:1.1.1174426c1fe00f
golang.org/x/net@v0.50.0
stdlib@go1.25.9
0.53.0
1.25.10

Open the chart page →

812
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.53.0
1.25.10

Open the chart page →

8,419
aws-ecr-tokencheveo-charts0.1.01 of 1See more

aws-ecr-token cheveo-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
huzafach/aws-cli-k8:1.0.06e271d43ea48
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.53.0
1.25.10

Open the chart page →

1,110
pathling-serverchglVerified publisher0.10.111 of 3See more

pathling-server chgl 0.10.11

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10

Open the chart page →

1,230
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.53.0
1.25.10

Open the chart page →

2,877
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.53.0
1.25.10

Open the chart page →

2,829
supersetchoerodon1.0.01 of 3See more

superset choerodon 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.53.0
1.25.10

Open the chart page →

1,440
argocd-metrics-serverchristianhuthVerified publisher1.1.11 of 1See more

argocd-metrics-server christianhuth 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
golang.org/x/net@v0.10.0
stdlib@go1.21.11
0.53.0
1.25.10

Open the chart page →

1,032
cluster-api-visualizerchristianhuthVerified publisher0.6.01 of 1See more

cluster-api-visualizer christianhuth 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.53.0
1.25.10

Open the chart page →

558
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
stdlib@go1.19.4
1.25.10
countly/frontend:25.05.42acbc11499b6
stdlib@go1.19.4
1.25.10

Open the chart page →

7,325
dnsbl-exporterchristianhuthVerified publisher1.4.01 of 2See more

dnsbl-exporter christianhuth 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/luzilla/dnsbl_exporter:v0.7.0-rc3d9767232a55e
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.53.0
1.25.10

Open the chart page →

1,461
goldpingerchristianhuthVerified publisher1.4.11 of 1See more

goldpinger christianhuth 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.11.3a8ea8c61ff4c
golang.org/x/net@v0.49.0
0.53.0

Open the chart page →

142
kubedoomchristianhuthVerified publisher1.1.21 of 1See more

kubedoom christianhuth 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/storax/kubedoom:0.6.0851ba8c80b93
stdlib@go1.17.6
1.25.10

Open the chart page →

1,021
kubevirt-cloud-controller-managerchristianhuthVerified publisher0.0.21 of 1See more

kubevirt-cloud-controller-manager christianhuth 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.53.0
1.25.10

Open the chart page →

670
kubevirt-managerchristianhuthVerified publisher0.7.01 of 1See more

kubevirt-manager christianhuth 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,990
mailcow-exporterchristianhuthVerified publisher1.5.01 of 1See more

mailcow-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
stdlib@go1.23.12
1.25.10

Open the chart page →

753
nextcloud-exporterchristianhuthVerified publisher1.5.01 of 1See more

nextcloud-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
xperimental/nextcloud-exporter:0.9.13e90a3897651
stdlib@go1.26.1
1.25.10

Open the chart page →

194
ntp-exporterchristianhuthVerified publisher1.4.01 of 1See more

ntp-exporter christianhuth 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/sapcc/ntp_exporter:v2.9.079c40c65f5d4
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

378
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.25.10

Open the chart page →

5,954
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.16.15
0.53.0
1.25.10

Open the chart page →

2,291
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.53.0
1.25.10

Open the chart page →

7,056
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/net@v0.30.0
stdlib@go1.22.10
0.53.0
1.25.10

Open the chart page →

4,902
ethereumchronicleVerified publisher0.3.11 of 1See more

ethereum chronicle 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.53.0
1.25.10

Open the chart page →

1,353
ethereum-metrics-exporterchronicleVerified publisher0.1.41 of 1See more

ethereum-metrics-exporter chronicle 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
samcm/ethereum-metrics-exporter:0.29.291a2d9a015c1
golang.org/x/net@v0.43.0
stdlib@go1.25.8
0.53.0
1.25.10

Open the chart page →

684
goferchronicleVerified publisher0.4.41 of 1See more

gofer chronicle 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/gofer:0.613915d2e41e04
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.53.0
1.25.10

Open the chart page →

721
mantlechronicleVerified publisher0.1.31 of 1See more

mantle chronicle 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.53.0
1.25.10

Open the chart page →

1,942
sith-exporterschronicleVerified publisher0.2.41 of 1See more

sith-exporters chronicle 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/oracles-updates-exporter:0.0.4992d0e793af6
stdlib@go1.19.13
1.25.10

Open the chart page →

997
spirechronicleVerified publisher0.3.61 of 1See more

spire chronicle 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10

Open the chart page →

1,553
tor-proxychronicleVerified publisher0.1.01 of 1See more

tor-proxy chronicle 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
btcpayserver/tor:0.4.8.10e9585b68dc6b
stdlib@go1.16.5
1.25.10

Open the chart page →

3,385
zksyncchronicleVerified publisher0.1.01 of 2See more

zksync chronicle 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
stdlib@go1.24.6
1.25.10

Open the chart page →

6,031
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2026-33814.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.53.0
1.25.10

Open the chart page →

3,602

Container images carrying it

4,792 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.4
0.53.0
1.25.10
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.18.1
0.53.0
1.25.10
1
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.25.10
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16
0.53.0
1.25.10
1
registry.gitlab.com/bitspur/rock8s/easy-olm-operator:0.0.1779454fea06c
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.10
0.53.0
1.25.10
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.53.0
1.25.10
1
registry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.063cf51392ce7
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.13
0.53.0
1.25.10
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/net@v0.0.0-20180811021610-c39426892332
stdlib@go1.14.2
0.53.0
1.25.10
1
registry.gitlab.com/dyff/dyff-operator:0.24.20e9ca51627601
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.53.0
1.25.10
1
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.53.0
1.25.10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.53.0
1.25.10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.25.10
1
registry.gitlab.com/gitlab-org/build/cng/cfssl-self-sign:v19.4.07757679afa1b
golang.org/x/net@v0.20.0
stdlib@go1.22.0
0.53.0
1.25.10
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
golang.org/x/net@v0.48.0
0.53.0
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
golang.org/x/net@v0.49.0
0.53.0
1
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.53.0
1.25.10
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.16.14
0.53.0
1.25.10
1
registry.gitlab.com/lenitech/docker/keycloak-ppolicy:0.6.09895d6915075
golang.org/x/net@v0.46.0
stdlib@go1.25.7
0.53.0
1.25.10
1
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.53.0
1.25.10
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.53.0
1.25.10
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.15
0.53.0
1.25.10
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.53.0
1.25.10
1
registry.gitlab.com/xrow-public/ci-tools/kubectl:main9357cfeef63c
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.53.0
1.25.10
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.53.0
1.25.10
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.53.0
1.25.10
1
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.25.10
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.93.006a950310ecd
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.53.0
1.25.10
1
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
golang.org/x/net@v0.49.0
0.53.0
1
registry.k8s.io/agent-sandbox/sandbox-router-go:v1.0.125b1a0939630
stdlib@go1.26.2
1.25.10
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
golang.org/x/net@v0.38.0
stdlib@go1.24.7
0.53.0
1.25.10
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.4.171d817780aa9
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
1
registry.k8s.io/autoscaling/vpa-recommender:1.4.140b6d76e8526
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
1
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
1
registry.k8s.io/autoscaling/vpa-updater:1.4.18ebf269779c1
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.53.0
1.25.10
1
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.53.0
1.25.10
1
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.53.0
1.25.10
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
stdlib@go1.20.7
0.53.0
1.25.10
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/net@v0.32.0
stdlib@go1.23.0
0.53.0
1.25.10
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.53.0
1.25.10
1
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
1
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.53.0
1.25.10
1
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.53.0
1.25.10
1
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.53.0
1.25.10
1
registry.k8s.io/descheduler/descheduler:v0.36.07ca92c0a7b4f
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.53.0
1.25.10
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/net@v0.17.0
stdlib@go1.21.7
0.53.0
1.25.10
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.