StackRadar

CVE-2026-46600

Unscored

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,531
of 17,797 indexed, latest versions
Container images
4,324
deployed by those charts
Fix available
2 of 2
affected packages

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Carried by container images the latest versions of 3,531 of 17,797 indexed charts deploy, on 4,324 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+221 more0.56.03,917
stdlibgolanggo1.26.0, go1.26.1, go1.26.2, go1.26.2-X:boringcrypto+7 more1.26.6868
OSV records
GO-2026-5942
Also known as
BIT-golang-2026-46600

Charts affected

3,531 by stars
ChartLatestAffected imagesRadar Score
symfony-appdefault-ghVerified publisher0.6.51 of 3See more

symfony-app default-gh 0.6.5

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alpine/git:2.36.366b210a97bc0
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.56.0

Open the chart page →

5,123
csi-driver-smbdeimosfr-charts1.20.35 of 5See more

csi-driver-smb deimosfr-charts 1.20.3

5 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
stdlib@go1.26.4
1.26.6

Open the chart page →

2,985
ddns-updaterdeimosfr-charts2.10.01 of 1See more

ddns-updater deimosfr-charts 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
qmcgaw/ddns-updater:v2.10.03e2aa558946b
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.56.0
1.26.6

Open the chart page →

211
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
0.56.0

Open the chart page →

2,241
field-exporterdeliveryheroVerified publisher1.4.11 of 1See more

field-exporter deliveryhero 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/deliveryhero/field-exporter:v1.4.06b71ba4f9297
golang.org/x/net@v0.26.0
0.56.0

Open the chart page →

471
k8s-cloudwatch-adapterdeliveryheroVerified publisher0.2.21 of 1See more

k8s-cloudwatch-adapter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.56.0

Open the chart page →

2,475
prometheus-dellhw-exporterdellhw-exporterVerified publisher1.3.01 of 1See more

prometheus-dellhw-exporter dellhw-exporter 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0b3a5806d73b5
golang.org/x/net@v0.48.0
0.56.0

Open the chart page →

1,876
kubeteach-coredergeberl0.2.31 of 1See more

kubeteach-core dergeberl 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
golang.org/x/net@v0.1.0
0.56.0

Open the chart page →

1,505
kubeteach-exerciseset1dergeberl0.2.31 of 2See more

kubeteach-exerciseset1 dergeberl 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
golang.org/x/net@v0.1.0
0.56.0

Open the chart page →

1,505
clamav-apidevhatVerified publisher1.0.11 of 1See more

clamav-api devhat 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
golang.org/x/net@v0.25.0
0.56.0

Open the chart page →

2,099
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.56.0
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.56.0

Open the chart page →

4,736
devopsweeklydevopsweekly2.1.01 of 1See more

devopsweekly devopsweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
zufardhiyaulhaq/devopsweekly:v2.1.046625567fb60
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.56.0

Open the chart page →

1,218
lxd8sdevplayer0Verified publisher0.5.12 of 2See more

lxd8s devplayer0 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.56.0
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.56.0

Open the chart page →

5,431
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/net@v0.23.0
0.56.0

Open the chart page →

9,703
argocddevtron1.8.12 of 3See more

argocd devtron 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
0.56.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.56.0

Open the chart page →

10,484
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.56.0

Open the chart page →

13,033
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

1,587
caddy-reverse-proxydevtron0.10.11 of 1See more

caddy-reverse-proxy devtron 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
library/caddy:latest13ba145cba2f
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

846
devtron-enterprisedevtron48.0.017 of 28See more

devtron-enterprise devtron 48.0.0

17 of the 28 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
golang.org/x/net@v0.40.0
0.56.0
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.56.0
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
0.56.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.56.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.56.0
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.56.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.56.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
0.56.0

Open the chart page →

68,765
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.56.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

5,055
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

4,979
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.56.0

Open the chart page →

11,981
jcmhproxy-ingressdevtron0.14.61 of 1See more

jcmhproxy-ingress devtron 0.14.6

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

1,379
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.56.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
0.56.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0

Open the chart page →

8,659
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.56.0

Open the chart page →

2,442
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.56.0

Open the chart page →

1,514
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/net@v0.23.0
0.56.0

Open the chart page →

9,703
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
0.56.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.56.0

Open the chart page →

10,484
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.56.0

Open the chart page →

13,033
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

1,587
caddy-reverse-proxydevtron-labs0.10.11 of 1See more

caddy-reverse-proxy devtron-labs 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
library/caddy:latestdf7f1c2fb114
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

846
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0

Open the chart page →

10,094
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.56.0

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.017 of 28See more

devtron-enterprise devtron-labs 48.0.0

17 of the 28 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
golang.org/x/net@v0.40.0
0.56.0
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.56.0
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
0.56.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.56.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.56.0
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.56.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.56.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
0.56.0

Open the chart page →

68,765
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.56.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

5,055
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

4,979
devtron-operatordevtron-labs0.23.38 of 11See more

devtron-operator devtron-labs 0.23.3

8 of the 11 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.56.0
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.56.0
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.56.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0

Open the chart page →

33,219
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.56.0

Open the chart page →

11,981
jcmhproxy-ingressdevtron-labs0.14.61 of 1See more

jcmhproxy-ingress devtron-labs 0.14.6

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

1,379
kube-prometheus-stackdevtron-labs19.3.03 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

3 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.56.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
0.56.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0

Open the chart page →

8,659
migrantdevtron-labs0.0.31 of 1See more

migrant devtron-labs 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
migrate/migrate:latestcc4ad8e19d66
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

740
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.56.0

Open the chart page →

2,442
winter-soldierdevtron-labs0.10.61 of 1See more

winter-soldier devtron-labs 0.10.6

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0

Open the chart page →

1,176
zincdevtron-labs0.1.21 of 1See more

zinc devtron-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.56.0

Open the chart page →

1,514
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
golang.org/x/net@v0.20.0
0.56.0

Open the chart page →

19,513
digital-mobiusdigital-mobius0.1.41 of 1See more

digital-mobius digital-mobius 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
qoveryrd/digital-mobius:0.1.4b30a9398a83c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0

Open the chart page →

2,288
direktivdirektivVerified publisher0.10.03 of 6See more

direktiv direktiv 0.10.0

3 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
golang.org/x/net@v0.35.0
0.56.0
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/net@v0.33.0
0.56.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/net@v0.33.0
0.56.0

Open the chart page →

3,480
graphite-exporterdjjudas21Verified publisher0.1.91 of 1See more

graphite-exporter djjudas21 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
prom/graphite-exporter:v0.16.0e54bca6645ea
golang.org/x/net@v0.30.0
0.56.0

Open the chart page →

782
hammonddjjudas21Verified publisher0.3.91 of 1See more

hammond djjudas21 0.3.9

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
0.56.0

Open the chart page →

1,807

Container images carrying it

4,324 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
layer5/meshery-nsm:stable-latestebd6a8faf21f
golang.org/x/net@v0.0.0-20200822124328-c89045814202
0.56.0
1
layer5/meshery-operator:stable-latest6f58a28fe422
golang.org/x/net@v0.33.0
0.56.0
1
layer5/meshery-osm:stable-latestec898e5786c6
golang.org/x/net@v0.5.0
0.56.0
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
golang.org/x/net@v0.9.0
0.56.0
1
lbenicio/kubernetes-dashboard-api:1.14.951d3d30206c8
golang.org/x/net@v0.46.0
0.56.0
1
lbenicio/kubernetes-dashboard-auth:1.4.1378c63efd9dcd
golang.org/x/net@v0.46.0
0.56.0
1
lbenicio/kubernetes-dashboard-scraper:1.2.69202e96ad403
golang.org/x/net@v0.46.0
0.56.0
1
lbenicio/kubernetes-dashboard-web:1.7.142797937bc2a5
golang.org/x/net@v0.46.0
0.56.0
1
leonardomulticloud/webhook:v1.0.0d119918900e8
golang.org/x/net@v0.26.0
0.56.0
1
library/caddy:latest13ba145cba2f
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
1
library/caddy:2.660fb54d36b4b
golang.org/x/net@v0.7.0
0.56.0
1
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.56.0
1
library/caddy:2.11.2-alpine834468128c76
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.56.0
1.26.6
1
library/caddy:2.4.5874405536b3e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.56.0
1
library/caddy:2.9-alpineb4e3952384eb
golang.org/x/net@v0.33.0
0.56.0
1
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0
1
library/chronograf:1.9.496d8a3f65a4f
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.56.0
1
library/docker:24.0.2-dind1d148deae16a
golang.org/x/net@v0.8.0
0.56.0
1
library/docker:28.5.2-dind2a232a42256f
golang.org/x/net@v0.39.0
0.56.0
1
library/docker:20.10.21-dind3153fa63f546
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0
1
library/docker:29.8.1-dind76cd6bbc3ab6
golang.org/x/net@v0.50.0
0.56.0
1
library/docker:27-cli851f91d24121
golang.org/x/net@v0.33.0
0.56.0
1
library/docker:27-dindaa3df78ecf32
golang.org/x/net@v0.33.0
0.56.0
1
library/docker:23.0.6-dindafa5d5134900
golang.org/x/net@v0.8.0
0.56.0
1
library/docker:dind-rootlessc876e00a0d81
golang.org/x/net@v0.55.0
0.56.0
1
library/docker:23.0.1-dindd9a0fd8bdd15
golang.org/x/net@v0.4.0
0.56.0
1
library/docker:26.1-dinddd43b430341a
golang.org/x/net@v0.25.0
0.56.0
1
library/eclipse-temurin:211f79c73404fb
stdlib@go1.26.5
1.26.6
1
library/eclipse-temurin:2185f00967bcc6
stdlib@go1.26.5
1.26.6
1
library/influxdb:2.8571eb4514977
golang.org/x/net@v0.25.0
0.56.0
1
library/influxdb:2.7.4-alpinea10d46445d68
golang.org/x/net@v0.17.0
0.56.0
1
library/influxdb:1.12.3-datab0f9fc41ed79
golang.org/x/net@v0.47.0
0.56.0
1
library/influxdb:2.0.8ba10ac9ba17a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.56.0
1
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
0.56.0
1
library/influxdb:latestf75e48af0598
golang.org/x/net@v0.51.0
0.56.0
1
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
0.56.0
1
library/mongo:8.002a0cc7939f5
stdlib@go1.26.5
1.26.6
1
library/mongo:5.0.32-focal3b6c281e1c08
golang.org/x/net@v0.47.0
0.56.0
1
library/mongo:7.0-jammy:7-jammy406a4fdca9fc
stdlib@go1.26.5
1.26.6
1
library/mongo:8.3.115d7043a4ffe0
stdlib@go1.26.5
1.26.6
1
library/mongo:noble6ede2806c78e
stdlib@go1.26.5
1.26.6
1
library/mongo:7.0-jammy84c4a18b60a0
stdlib@go1.26.5
1.26.6
1
library/mongo:7.0.28-jammy88785f6f665a
golang.org/x/net@v0.47.0
0.56.0
1
library/mongo:8.0.11dca8d11fe467
golang.org/x/net@v0.40.0
0.56.0
1
library/nats:2.14.2-alpine952d157e28d5
stdlib@go1.26.3
1.26.6
1
library/nats:2.14.5-alpined4ac35882ac6
stdlib@go1.26.5
1.26.6
1
library/telegraf:1.20.428e98eece020
golang.org/x/net@v0.0.0-20211005215030-d2e5035098b3
0.56.0
1
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
0.56.0
1
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0
1
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.56.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.