StackRadar

CVE-2026-46600

Unscored

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,533
of 17,792 indexed, latest versions
Container images
4,322
deployed by those charts
Fix available
2 of 2
affected packages

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Carried by container images the latest versions of 3,533 of 17,792 indexed charts deploy, on 4,322 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+221 more0.56.03,910
stdlibgolanggo1.26.0, go1.26.1, go1.26.2, go1.26.2-X:boringcrypto+7 more1.26.6868
OSV records
GO-2026-5942
Also known as
BIT-golang-2026-46600

Charts affected

3,533 by stars
ChartLatestAffected imagesRadar Score
harborgpg-dev1.18.34 of 8See more

harbor gpg-dev 1.18.3

4 of the 8 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.14.3a30e5a8be3d9
golang.org/x/net@v0.47.0
0.56.0
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
golang.org/x/net@v0.47.0
0.56.0
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
golang.org/x/net@v0.47.0
0.56.0
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
golang.org/x/net@v0.28.0
0.56.0

Open the chart page →

3,406
ingress-nginxgpg-dev4.9.02 of 2See more

ingress-nginx gpg-dev 4.9.0

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/net@v0.17.0
0.56.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
0.56.0

Open the chart page →

2,316
jaegergpg-dev3.3.33 of 5See more

jaeger gpg-dev 3.3.3

3 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
0.56.0
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
0.56.0
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
0.56.0

Open the chart page →

19,311
kube-prometheus-stackgpg-dev84.0.05 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

5 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/grafana:13.0.10f86bada30d6
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.56.0
1.26.6
ghcr.io/jkroepke/kube-webhook-certgen:1.8.14f6da0256b1b
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.56.0
1.26.6
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
golang.org/x/net@v0.52.0
0.56.0
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.56.0
1.26.6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
0.56.0

Open the chart page →

4,303
kubernetes-dashboardgpg-dev7.5.04 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

4 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
kubernetesui/dashboard-api:1.7.060595892c2cf
golang.org/x/net@v0.25.0
0.56.0
kubernetesui/dashboard-auth:1.1.307135c09e9ff
golang.org/x/net@v0.22.0
0.56.0
kubernetesui/dashboard-metrics-scraper:1.1.17747d363c9fe
golang.org/x/net@v0.21.0
0.56.0
kubernetesui/dashboard-web:1.4.04445b31a2c25
golang.org/x/net@v0.25.0
0.56.0

Open the chart page →

6,078
metrics-servergpg-dev3.12.11 of 1See more

metrics-server gpg-dev 3.12.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/net@v0.20.0
0.56.0

Open the chart page →

1,078
opentelemetry-demogpg-dev0.33.88 of 27See more

opentelemetry-demo gpg-dev 0.33.8

8 of the 27 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
golang.org/x/net@v0.29.0
0.56.0
jaegertracing/all-in-one:1.53.060e65bfffe1f
golang.org/x/net@v0.19.0
0.56.0
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
golang.org/x/net@v0.31.0
0.56.0
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
golang.org/x/net@v0.27.0
0.56.0
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
golang.org/x/net@v0.25.0
0.56.0
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
golang.org/x/net@v0.25.0
0.56.0
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
golang.org/x/net@v0.19.0
0.56.0
quay.io/prometheus/prometheus:v3.0.03b9b2a15d376
golang.org/x/net@v0.30.0
0.56.0

Open the chart page →

49,362
prometheusgpg-dev29.2.16 of 6See more

prometheus gpg-dev 29.2.1

6 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.90.1693faa0b8724
golang.org/x/net@v0.52.0
0.56.0
quay.io/prometheus/alertmanager:v0.32.058e117eabcce
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.56.0
1.26.6
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.56.0
1.26.6
quay.io/prometheus/prometheus:v3.11.2cd37346c9745
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.56.0
1.26.6
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/net@v0.46.0
0.56.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
0.56.0

Open the chart page →

3,281
prometheus-operator-admission-webhookgpg-dev0.18.12 of 2See more

prometheus-operator-admission-webhook gpg-dev 0.18.1

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/admission-webhook:v0.79.2d4c97a1b2d67
golang.org/x/net@v0.32.0
0.56.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
0.56.0

Open the chart page →

1,685
thanosgpg-dev0.5.31 of 1See more

thanos gpg-dev 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/net@v0.49.0
0.56.0

Open the chart page →

592
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
golang.org/x/net@v0.51.0
0.56.0

Open the chart page →

1,280
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

1,562
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
prom/graphite-exporter:latestc1a266f63a84
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

6,148
cloudcost-exportergrafana1.1.131 of 1See more

cloudcost-exporter grafana 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/cloudcost-exporter:v1.12.0eeb2cfecb23e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

160
grafana-cloud-onboardinggrafana0.4.75 of 5See more

grafana-cloud-onboarding grafana 0.4.7

5 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/beyla-k8s-cache:253b2f561cb1b
golang.org/x/net@v0.48.0
0.56.0
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
golang.org/x/net@v0.49.0
0.56.0
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
0.56.0
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.56.0
1.26.6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
0.56.0

Open the chart page →

4,681
grafana-samplinggrafana1.1.72 of 2See more

grafana-sampling grafana 1.1.7

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
golang.org/x/net@v0.43.0
0.56.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
0.56.0

Open the chart page →

3,370
k8s-injection-controllergrafana0.2.11 of 1See more

k8s-injection-controller grafana 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/grafana/k8s-injection-controller:0.2.0c5bad40655a3
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

130
mimir-openshift-experimentalgrafana2.1.03 of 4See more

mimir-openshift-experimental grafana 2.1.0

3 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
0.56.0
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.56.0
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.56.0

Open the chart page →

17,780
pyroscope-monitoringgrafana0.1.15 of 6See more

pyroscope-monitoring grafana 0.1.1

5 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
golang.org/x/net@v0.38.0
0.56.0
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
golang.org/x/net@v0.41.0
0.56.0
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
0.56.0
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
0.56.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
0.56.0

Open the chart page →

8,269
prometheusgrafana-uxadax26.0.16 of 6See more

prometheus grafana-uxadax 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
0.56.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
0.56.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
0.56.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
0.56.0
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
0.56.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
0.56.0

Open the chart page →

5,312
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.56.0

Open the chart page →

7,519
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/net@v0.26.0
0.56.0

Open the chart page →

7,956
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
library/mongo:85211c51171f5
stdlib@go1.26.5
1.26.6

Open the chart page →

5,347
armada-executorgresearch0.22.81 of 1See more

armada-executor gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gresearch/armada-executor:latest393aff4aa8f2
golang.org/x/net@v0.55.0
0.56.0

Open the chart page →

714
armada-lookout-ingestergresearch0.22.81 of 1See more

armada-lookout-ingester gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gresearch/armada-lookout-ingester:latest3df14cda1855
golang.org/x/net@v0.55.0
0.56.0

Open the chart page →

714
armada-lookout-migrationgresearch0.22.81 of 1See more

armada-lookout-migration gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gresearch/armada-lookout:latestf5e3226f1d33
golang.org/x/net@v0.55.0
0.56.0

Open the chart page →

714
armada-scheduler-migrationgresearch0.22.81 of 1See more

armada-scheduler-migration gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gresearch/armada-scheduler:latest6141a6213fcb
golang.org/x/net@v0.55.0
0.56.0

Open the chart page →

714
fasttrackmlgresearch0.1.01 of 1See more

fasttrackml gresearch 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/net@v0.24.0
0.56.0

Open the chart page →

1,398
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.56.0

Open the chart page →

14,327
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
golang.org/x/net@v0.27.0
0.56.0

Open the chart page →

2,598
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0

Open the chart page →

2,182
routergroundcover1.12.3701See more

router groundcover 1.12.370

1 container image this version deploys carries CVE-2026-46600.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/net@v0.52.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

temporalgroundcover1.12.3702See more

temporal groundcover 1.12.370

2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

tailscale-subnet-routergtaylor1.2.11 of 1See more

tailscale-subnet-router gtaylor 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
golang.org/x/net@v0.1.0
0.56.0

Open the chart page →

1,834
minifluxhajowielandVerified publisher1.0.01 of 1See more

miniflux hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

1,113
hakoniwahakoniwa0.1.01 of 1See more

hakoniwa hakoniwa 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/aplulu/hakoniwa:0.1.0accf0b921388
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

338
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.56.0

Open the chart page →

2,381
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0

Open the chart page →

4,462
thunderdome-planning-pokerhalkeye0.1.11 of 1See more

thunderdome-planning-poker halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
golang.org/x/net@v0.52.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

425
hcp-terraform-operatorhashicorpVerified publisher2.12.12 of 2See more

hcp-terraform-operator hashicorp 2.12.1

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
hashicorp/hcp-terraform-operator:2.12.15a15932f6838
stdlib@go1.26.5
1.26.6
quay.io/brancz/kube-rbac-proxy:v0.20.1f5fbfec6a2b2
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

685
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/consumer:main73f59c032812
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
0.56.0

Open the chart page →

9,178
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.56.0

Open the chart page →

3,029
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/net@v0.0.0-20200520182314-0ba52f642ac2
0.56.0

Open the chart page →

2,637
headcniheadcni1.0.101 of 1See more

headcni headcni 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
binrc/headcni:1.0.10e199c334b957
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

724
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
supabase/gotrue:v2.91.07174d551d720
golang.org/x/net@v0.10.0
0.56.0

Open the chart page →

25,183
hello_worldcharthellohelm0.1.01 of 1See more

hello_worldchart hellohelm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
dockerdaemon0901/rolldice:v14e5bfe179c7e
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

855
helm-airportshelm-airports0.1.01 of 7See more

helm-airports helm-airports 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.56.0

Open the chart page →

12,715
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.56.0

Open the chart page →

4,558
helm-airportshelm-airports-dan0.1.01 of 7See more

helm-airports helm-airports-dan 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.56.0

Open the chart page →

5,584
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.56.0

Open the chart page →

4,558

Container images carrying it

4,322 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
1password/connect-api:1.7.26aa94cf713f9
golang.org/x/net@v0.14.0
0.56.0
1
1password/connect-api:1.8.2e915c0c84397
golang.org/x/net@v0.50.0
0.56.0
1
1password/connect-sync:1.8.26297ca6136c0
golang.org/x/net@v0.50.0
0.56.0
1
1password/connect-sync:1.7.2fe527ed9d81f
golang.org/x/net@v0.14.0
0.56.0
1
1password/kubernetes-secrets-injector:1.0.25884757f7879
golang.org/x/net@v0.8.0
0.56.0
1
42wim/matterircd:latest808b4c3228d9
golang.org/x/net@v0.55.0
0.56.0
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
1
aavishay/right-sizer:0.6.23d7c4d79595c
golang.org/x/net@v0.48.0
0.56.0
1
abiondevelopment/cert-manager-webhook-abion:latestc741988fbd23
golang.org/x/net@v0.44.0
0.56.0
1
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/net@v0.17.0
0.56.0
1
absaoss/terraform-controller:v0.0.20ad538a1285a0
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0
1
adguard/adguardhome:v0.107.513a143e6c071c
golang.org/x/net@v0.25.0
0.56.0
1
adguard/adguardhome:v0.107.3843ec119419a9
golang.org/x/net@v0.15.0
0.56.0
1
adguard/adguardhome:v0.107.595d5e3aef39a8
golang.org/x/net@v0.37.0
0.56.0
1
adguard/adguardhome:v0.107.767157eb1dc3b2
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.56.0
1.26.6
1
adguard/adguardhome:v0.107.737fbf01d73ecb
golang.org/x/net@v0.50.0
0.56.0
1
adguard/adguardhome:v0.107.7b9974aed13d0
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.56.0
1
adguard/adguardhome:v0.107.56c64a0b37f7b9
golang.org/x/net@v0.33.0
0.56.0
1
adguard/adguardhome:v0.107.65d765078d2140
golang.org/x/net@v0.43.0
0.56.0
1
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.56.0
1
adyanth/cloudflare-operator6b168dc237d5
golang.org/x/net@v0.39.0
0.56.0
1
aerokube/moon:1.9.17da76ca51220d
golang.org/x/net@v0.25.0
0.56.0
1
aerokube/moon-api:1.9.176b6323e75785
golang.org/x/net@v0.25.0
0.56.0
1
aerokube/selenoid-ui:1.10.113f3e299509fd
golang.org/x/net@v0.10.0
0.56.0
1
aerospike/aerospike-backup-service:3.5.1be40d709c583
golang.org/x/net@v0.50.0
0.56.0
1
aerospike/aerospike-kubernetes-operator:4.5.070a9eeb991b8
golang.org/x/net@v0.54.0
0.56.0
1
afgane/galaxy-k8s-monitor:latest457173db5640
golang.org/x/net@v0.30.0
0.56.0
1
agentarea/agentarea-mcp-manager:latestefe23cef3727
golang.org/x/net@v0.55.0
0.56.0
1
aibrix/controller-manager:v0.7.076aabbbfda79
golang.org/x/net@v0.34.0
0.56.0
1
aibrix/gateway-plugins:v0.7.05b93ea4c753a
golang.org/x/net@v0.34.0
0.56.0
1
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
golang.org/x/net@v0.17.0
0.56.0
1
airbyte/pod-sweeper:1.5.198d2c39d512e
golang.org/x/net@v0.26.0
0.56.0
1
ajilaag/clamav-rest:latestad689c7b75b1
stdlib@go1.26.0
1.26.6
1
akeyless/akeyless-csi-provider:lateste48bddc5dd72
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
1
akeyless/base:latest759e4289fae8
stdlib@go1.26.3
1.26.6
1
akeyless/k8s-webhook-server:0.39.0996cd9afb3b4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
1
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
stdlib@go1.26.5
1.26.6
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
stdlib@go1.26.5
1.26.6
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.56.0
1.26.6
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
stdlib@go1.26.5
1.26.6
1
aktosecurity/mirror-api-logging:k8s_agentc1313b1ff2ed
golang.org/x/net@v0.55.0
0.56.0
1
aktosecurity/mirror-api-logging:k8s_ebpffcf8be10bead
golang.org/x/net@v0.38.0
0.56.0
1
alazidis/stornx:1.1.1602d4f7f090c
golang.org/x/net@v0.47.0
0.56.0
1
alcounit/browser-controller:v1.0.093b7cdbab14b
golang.org/x/net@v0.47.0
0.56.0
1
alcounit/browser-service:v0.0.94bd10defc324
golang.org/x/net@v0.47.0
0.56.0
1
alcounit/browser-ui:v0.0.96a977c92ef27
golang.org/x/net@v0.47.0
0.56.0
1
alcounit/selenosis:v2.1.1d01a9dbbd943
golang.org/x/net@v0.47.0
0.56.0
1
alex6021710/ai-scale-auth:latest6c7a47e470c3
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
0.56.0
1
alex6021710/ai-scale-doer:latest31e533cf7cd3
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
0.56.0
1
alex6021710/ai-scale-migrator:latest744b8a924f35
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
0.56.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.