StackRadar

CVE-2026-35469

High

Advisory

Published 16 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
484
of 17,787 indexed, latest versions
Container images
447
deployed by those charts
Fix available
1 of 1
affected package

SpdyStream: DOS on CRI

Carried by container images the latest versions of 484 of 17,787 indexed charts deploy, on 447 images.

Affected packageAffected versionsFixed inImages
github.com/moby/spdystreamgolangv0.2.0, v0.4.0, v0.5.00.5.1447
OSV records
GHSA-pc3f-x583-g7j2
Also known as
GO-2026-4958

Charts affected

484 by stars
ChartLatestAffected imagesRadar Score
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

9,196
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

3,462
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
grafana/grafana:11.5.28b37a2f028f1
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

7,901
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

7,672
kyvernosoftonic3.5.21 of 7See more

kyverno softonic 3.5.2

1 of the 7 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.32.73c5268158974
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

1,019
redis-operatorsoftonic0.18.01 of 1See more

redis-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
ghcr.io/ot-container-kit/redis-operator/redis-operator:v0.18.090bfeb2e0d71
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

551
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

2,505
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

30,687
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
github.com/moby/spdystream@v0.4.0
0.5.1

Open the chart page →

3,232
spire-identity-exchangespiffeVerified publisher0.2.21 of 3See more

spire-identity-exchange spiffe 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.099b37df34bc4
github.com/moby/spdystream@v0.4.0
0.5.1

Open the chart page →

1,427
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

2,416
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

28,165
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

1,360
paperless-ngx-backuptaskmediaVerified publisher1.1.01 of 1See more

paperless-ngx-backup taskmedia 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
ghcr.io/taskmedia/kubectl-gpg-ncftp:main0fb2b5584f7c
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

518
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

4,212
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

1,675
trident-protecttrident-protect100.2606.01 of 2See more

trident-protect trident-protect 100.2606.0

1 of the 2 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

1,331
trident-protect-bxp-previewtrident-protect100.2511.0-bxp-preview2 of 3See more

trident-protect-bxp-preview trident-protect 100.2511.0-bxp-preview

2 of the 3 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
netapp/controller:25.11.0-bxp-preview06f6c9a0653f
github.com/moby/spdystream@v0.5.0
0.5.1
netapp/trident-protect-utils:v1.0.058b9fac358bd
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

2,183
trident-protect-consoletrident-protect100.2608.0-console1 of 3See more

trident-protect-console trident-protect 100.2608.0-console

1 of the 3 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

1,322
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

2,477
aws-eks-asg-rolling-update-handlertwin1.5.01 of 1See more

aws-eks-asg-rolling-update-handler twin 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

1,118
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

8,607
ciliumvks-helm-chartsVerified publisher1.17.142 of 3See more

cilium vks-helm-charts 1.17.14

2 of the 3 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
github.com/moby/spdystream@v0.5.0
0.5.1
quay.io/cilium/operator-generic:v1.17.14773886ec9337
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

4,046
volcanovolcano-sh1.15.21 of 3See more

volcano volcano-sh 1.15.2

1 of the 3 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
volcanosh/vc-webhook-manager:v1.15.22fff65aad011
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

1,533
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

3,911
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

6,232
azure-scheduledevents-managerwebdevopsVerified publisher1.0.171 of 1See more

azure-scheduledevents-manager webdevops 1.0.17

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
webdevops/azure-scheduledevents-manager:24.9.0-kubernetes7acd46a8a972
github.com/moby/spdystream@v0.4.0
0.5.1

Open the chart page →

1,122
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

969
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
datawire/emissary:3.12.21f67a1292d2a
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

10,843
kubernetes-dashboardwenerme7.14.01 of 5See more

kubernetes-dashboard wenerme 7.14.0

1 of the 5 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
kubernetesui/dashboard-api:1.14.096a702cfd339
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

3,478
openebswenerme3.10.01 of 3See more

openebs wenerme 3.10.0

1 of the 3 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
openebs/provisioner-localpv:3.5.0aea39e49bb97
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

10,489
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

1,286
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
github.com/moby/spdystream@v0.2.0
0.5.1

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-35469.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
github.com/moby/spdystream@v0.5.0
0.5.1

Open the chart page →

9,381

Container images carrying it

447 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
github.com/moby/spdystream@v0.2.0
0.5.1
1
lbenicio/kubernetes-dashboard-api:1.14.951d3d30206c8
github.com/moby/spdystream@v0.5.0
0.5.1
1
leonardomulticloud/webhook:v1.0.0d119918900e8
github.com/moby/spdystream@v0.4.0
0.5.1
1
library/docker:24.0.2-dind1d148deae16a
github.com/moby/spdystream@v0.2.0
0.5.1
1
library/docker:28.5.2-dind2a232a42256f
github.com/moby/spdystream@v0.5.0
0.5.1
1
library/docker:20.10.21-dind3153fa63f546
github.com/moby/spdystream@v0.2.0
0.5.1
1
library/docker:27-cli851f91d24121
github.com/moby/spdystream@v0.4.0
0.5.1
1
library/docker:27-dindaa3df78ecf32
github.com/moby/spdystream@v0.4.0
0.5.1
1
library/docker:23.0.6-dindafa5d5134900
github.com/moby/spdystream@v0.2.0
0.5.1
1
library/docker:23.0.1-dindd9a0fd8bdd15
github.com/moby/spdystream@v0.2.0
0.5.1
1
library/docker:26.1-dinddd43b430341a
github.com/moby/spdystream@v0.2.0
0.5.1
1
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
github.com/moby/spdystream@v0.2.0
0.5.1
1
linuxserver/cloud9:latest45c5fe102ff3
github.com/moby/spdystream@v0.2.0
0.5.1
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
github.com/moby/spdystream@v0.2.0
0.5.1
1
logiqai/flash:v3.10.265b996bc7bdc
github.com/moby/spdystream@v0.2.0
0.5.1
1
mavrick1/kubestellar-b:latest45ca0429a1d4
github.com/moby/spdystream@v0.2.0
0.5.1
1
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
github.com/moby/spdystream@v0.5.0
0.5.1
1
murtazashah46/helmfile:latest4d11726cf803
github.com/moby/spdystream@v0.2.0
0.5.1
1
natsio/nats-operator:0.8.31261dae38389
github.com/moby/spdystream@v0.2.0
0.5.1
1
netapp/controller:25.11.0-bxp-preview06f6c9a0653f
github.com/moby/spdystream@v0.5.0
0.5.1
1
netapp/trident-operator:21.10.049cfe552d9c2
github.com/moby/spdystream@v0.2.0
0.5.1
1
netapp/trident-protect-utils:v1.0.058b9fac358bd
github.com/moby/spdystream@v0.5.0
0.5.1
1
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
github.com/moby/spdystream@v0.5.0
0.5.1
1
nineinfra/nineinfra:v0.7.0d4aad414eccd
github.com/moby/spdystream@v0.2.0
0.5.1
1
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
github.com/moby/spdystream@v0.2.0
0.5.1
1
opencsghq/kubectl:latestb6d87e1048c2
github.com/moby/spdystream@v0.5.0
0.5.1
1
openkruise/kruise-manager:v1.8.30482722b4e56
github.com/moby/spdystream@v0.2.0
0.5.1
1
openkruise/kruise-manager:v1.9.1f81ae78a36a4
github.com/moby/spdystream@v0.5.0
0.5.1
1
openpolicyagent/gatekeeper-crds:v3.17.177bc9bf3d163
github.com/moby/spdystream@v0.2.0
0.5.1
1
percona/percona-postgresql-operator:2.8.06cce2698d3f5
github.com/moby/spdystream@v0.5.0
0.5.1
1
percona/percona-server-mongodb-operator:1.20.1d09453ce7886
github.com/moby/spdystream@v0.5.0
0.5.1
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
github.com/moby/spdystream@v0.2.0
0.5.1
1
phntom/external-dns-host-network:0.0.123adadbac8443
github.com/moby/spdystream@v0.2.0
0.5.1
1
platzio/backend:v0.6.5d5e5972f344b
github.com/moby/spdystream@v0.5.0
0.5.1
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
github.com/moby/spdystream@v0.5.0
0.5.1
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
github.com/moby/spdystream@v0.5.0
0.5.1
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
github.com/moby/spdystream@v0.2.0
0.5.1
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
github.com/moby/spdystream@v0.2.0
0.5.1
1
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
github.com/moby/spdystream@v0.5.0
0.5.1
1
rabbitmqoperator/cluster-operator:2.6.08651dd3cec51
github.com/moby/spdystream@v0.2.0
0.5.1
1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
github.com/moby/spdystream@v0.2.0
0.5.1
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
github.com/moby/spdystream@v0.2.0
0.5.1
1
rancher/kubectl:v1.25.085a0d1148784
github.com/moby/spdystream@v0.2.0
0.5.1
1
replicated/replicated-sdk:1.0.0-beta.318751b4963250
github.com/moby/spdystream@v0.2.0
0.5.1
1
rook/ceph:v1.19.2944a1dd70496
github.com/moby/spdystream@v0.5.0
0.5.1
1
ryuunosukeds3/orbital:latest0879f7261b10
github.com/moby/spdystream@v0.4.0
0.5.1
1
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
github.com/moby/spdystream@v0.2.0
0.5.1
1
shlomibendavid/k8s-applier:0311240529a22ffbe0f04e
github.com/moby/spdystream@v0.2.0
0.5.1
1
sikalabs/slu:v0.72.07bd267f30247
github.com/moby/spdystream@v0.2.0
0.5.1
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
github.com/moby/spdystream@v0.2.0
0.5.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.