Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
0.005
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,616
of 17,805 indexed, latest versions
Container images
4,367
deployed by those charts
Fix available
2 of 2
affected packages
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
Carried by container images the latest versions of 3,616 of 17,805 indexed charts deploy, on 4,367 images.
Affected package
Affected versions
Fixed in
Images
golang.org/x/netgolang
v0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+221 more
0.56.0
3,960
stdlibgolang
go1.26.0, go1.26.1, go1.26.2, go1.26.2-X:boringcrypto+7 more
matrixdb-operatorymatrixOfficialOfficial: Artifact Hub marks the chart as published by the project itselfVerified publisherVerified publisher: Artifact Hub verified the publisher owns the repository
zoo-project-druzoo-projectOfficialOfficial: Artifact Hub marks the chart as published by the project itselfVerified publisherVerified publisher: Artifact Hub verified the publisher owns the repository