StackRadar

CVE-2026-46600

Unscored

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,533
of 17,792 indexed, latest versions
Container images
4,322
deployed by those charts
Fix available
2 of 2
affected packages

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Carried by container images the latest versions of 3,533 of 17,792 indexed charts deploy, on 4,322 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+221 more0.56.03,910
stdlibgolanggo1.26.0, go1.26.1, go1.26.2, go1.26.2-X:boringcrypto+7 more1.26.6868
OSV records
GO-2026-5942
Also known as
BIT-golang-2026-46600

Charts affected

3,533 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.56.0
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.56.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.56.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.56.0

Open the chart page →

12,132
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
golang.org/x/net@v0.35.0
0.56.0

Open the chart page →

5,465
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.56.0

Open the chart page →

2,731
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-07-23T15-54-02Zd249d1fb6966
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

13,647
backrestrobertobochetVerified publisher0.7.01 of 1See more

backrest robertobochet 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
garethgeorge/backrest:v1.14.1b85297975428
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.56.0
1.26.6

Open the chart page →

866
rqliterqliteOfficialVerified publisher2.0.01 of 1See more

rqlite rqlite 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
rqlite/rqlite:9.1.37b992a526eee
golang.org/x/net@v0.46.0
0.56.0

Open the chart page →

1,318
qbittorrent-vpnrtomik-helm-chartsVerified publisher0.0.21 of 2See more

qbittorrent-vpn rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.40.02b42bfa04675
golang.org/x/net@v0.31.0
0.56.0

Open the chart page →

1,218
sabliersablier-helm-chartsOfficialVerified publisher1.8.11 of 1See more

sablier sablier-helm-charts 1.8.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
sablierapp/sablier:1.16.1413704376656
stdlib@go1.26.3
1.26.6

Open the chart page →

154
seaweedfs-csi-driverseaweedfs-csi-driver0.2.385 of 7See more

seaweedfs-csi-driver seaweedfs-csi-driver 0.2.38

5 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

5,318
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
golang.org/x/net@v0.44.0
0.56.0

Open the chart page →

860
bentoself-hosters-by-nightVerified publisher0.9.11 of 1See more

bento self-hosters-by-night 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
golang.org/x/net@v0.37.0
0.56.0

Open the chart page →

1,053
appshini4iVerified publisher0.4.01 of 1See more

app shini4i 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
traefik/whoami:v1.10.21474027c3166
golang.org/x/net@v0.25.0
0.56.0

Open the chart page →

537
skypilotskypilotOfficialVerified publisher0.13.03 of 3See more

skypilot skypilot 0.13.0

3 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
golang.org/x/net@v0.38.0
stdlib@go1.26.4
0.56.0
1.26.6
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/net@v0.41.0
0.56.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
0.56.0

Open the chart page →

5,926
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/net@v0.4.0
0.56.0

Open the chart page →

1,670
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.56.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.56.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.56.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.56.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.56.0

Open the chart page →

12,537
miniosolidchartsVerified publisher0.5.01 of 1See more

minio solidcharts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
golang.org/x/net@v0.42.0
0.56.0

Open the chart page →

1,070
forecastlestakaterVerified publisher2.1.11 of 1See more

forecastle stakater 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
stakater/forecastle:v2.0.2382cd9572352
golang.org/x/net@v0.51.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

711
ingressmonitorcontrollerstakaterVerified publisher2.2.131 of 1See more

ingressmonitorcontroller stakater 2.2.13

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

583
vertical-pod-autoscalerstevehipwell-helm-charts-vertical-pod-autoscalerVerified publisher1.12.13 of 3See more

vertical-pod-autoscaler stevehipwell-helm-charts-vertical-pod-autoscaler 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

228
sn-platformstreamnative1.11.445 of 9See more

sn-platform streamnative 1.11.44

5 of the 9 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
0.56.0
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
0.56.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
0.56.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

15,564
stunnerstunner1.2.12 of 2See more

stunner stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:1.2.10d2094060b72
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
l7mp/stunner-gateway-operator:1.2.10ea40a1d42d5
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

263
pocketbasetechwolf12Verified publisher0.29.31 of 1See more

pocketbase techwolf12 0.29.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/net@v0.43.0
0.56.0

Open the chart page →

1,448
feedbacksystemthm-mni-iiVerified publisher0.47.14 of 10See more

feedbacksystem thm-mni-ii 0.47.1

4 of the 10 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/net@v0.19.0
0.56.0
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
0.56.0
library/docker:20.10.21-dind3153fa63f546
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

28,634
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

1,503
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.56.0

Open the chart page →

4,145
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.56.0
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.56.0

Open the chart page →

9,271
k8s-ttl-controllertwin0.4.01 of 1See more

k8s-ttl-controller twin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/net@v0.26.0
0.56.0

Open the chart page →

471
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/net@v0.11.0
0.56.0
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

10,373
uptraceuptrace2.0.21 of 2See more

uptrace uptrace 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
uptrace/uptrace:2.0.234a02c3b2d12
golang.org/x/net@v0.42.0
0.56.0

Open the chart page →

1,627
valkey-operatorvalkeyVerified publisher0.6.01 of 1See more

valkey-operator valkey 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/valkey-io/valkey-operator:v0.6.052a0f1ed0c03
golang.org/x/net@v0.49.0
0.56.0

Open the chart page →

141
vaultvaultVerified publisher1.22.04 of 4See more

vault vault 1.22.0

4 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alpine/k8s:1.35.5d870622d0040
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.56.0
1.26.6
hashicorp/vault:2.0.1755355002715
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
prom/statsd-exporter:v0.29.0632f70580492
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.56.0
1.26.6
ghcr.io/bank-vaults/bank-vaults:v1.33.198b6ea2ed319
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

4,266
vouchvouchVerified publisher3.2.01 of 1See more

vouch vouch 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/net@v0.5.0
0.56.0

Open the chart page →

1,031
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
0.56.0

Open the chart page →

1,350
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
0.56.0

Open the chart page →

2,245
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
golang.org/x/net@v0.52.0
0.56.0

Open the chart page →

1,000
wallarm-ingresswallarmVerified publisher5.3.10-12 of 2See more

wallarm-ingress wallarm 5.3.10-1

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
golang.org/x/net@v0.34.0
0.56.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
0.56.0

Open the chart page →

1,301
wallarm-sidecarwallarmOfficialVerified publisher6.13.11 of 3See more

wallarm-sidecar wallarm 6.13.1

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
0.56.0

Open the chart page →

965
argo-cdwenerme10.9.12 of 3See more

argo-cd wenerme 10.9.1

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/net@v0.50.0
stdlib@go1.26.0
0.56.0
1.26.6
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

3,003
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0.56.0

Open the chart page →

6,085
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.56.0
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.56.0
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.56.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.56.0

Open the chart page →

10,047
buildkitdwiremindVerified publisher0.33.01 of 1See more

buildkitd wiremind 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

1,161
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.56.0

Open the chart page →

4,713
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.56.0

Open the chart page →

4,049
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/net@v0.26.0
0.56.0

Open the chart page →

829
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

1,851
no-latest-tag-webhookadmission-webhook-no-latest1.0.141 of 1See more

no-latest-tag-webhook admission-webhook-no-latest 1.0.14

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/omkar-shelke25/admission-webhook-no-latest:sha-33165455976a1d3236a
golang.org/x/net@v0.38.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

162
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
stdlib@go1.26.5
1.26.6

Open the chart page →

19,828
agentareaagentareaVerified publisher0.0.185 of 16See more

agentarea agentarea 0.0.18

5 of the 16 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-manager:latestefe23cef3727
golang.org/x/net@v0.55.0
0.56.0
openfga/openfga:v1.18.036097b960f66
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
0.56.0
temporalio/auto-setup:1.29.15b3502a3b685
golang.org/x/net@v0.35.0
0.56.0
temporalio/ui:2.39.0b768f87f18b5
golang.org/x/net@v0.40.0
0.56.0

Open the chart page →

15,049
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.241See more

akeyless-api-gateway akeyless-services-helm 1.62.24

1 container image this version deploys carries CVE-2026-46600.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
stdlib@go1.26.3
1.26.6

Open the chart page →

alertmanager-matrixalertmanager-matrixVerified publisher0.1.161 of 1See more

alertmanager-matrix alertmanager-matrix 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
silkeh/alertmanager_matrix:0.6.1900010497f8c
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

461

Container images carrying it

4,322 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
owncloud/server:10.15.051d9b74fc2a8
golang.org/x/net@v0.26.0
0.56.0
1
owncloud/server:10.16.274c53d341076
golang.org/x/net@v0.52.0
stdlib@go1.26.3
0.56.0
1.26.6
1
owncloud/server:10.16.3b3f9efdcd7f7
stdlib@go1.26.5
1.26.6
1
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
1
pannoi/kollektor:1.0.59559617788fc
golang.org/x/net@v0.17.0
0.56.0
1
penpotapp/backend:2.17.2770b55f6e51b
stdlib@go1.26.5
1.26.6
1
penpotapp/exporter:2.17.272a8061e8806
stdlib@go1.26.5
1.26.6
1
penpotapp/mcp:2.17.284f3f07ead11
stdlib@go1.26.5
1.26.6
1
percona/mongodb_exporter:0.53.00214e482b2cd
stdlib@go1.26.2
1.26.6
1
percona/percona-postgresql-operator:2.8.06cce2698d3f5
golang.org/x/net@v0.46.0
0.56.0
1
percona/percona-server-mongodb-operator:1.20.1d09453ce7886
golang.org/x/net@v0.38.0
0.56.0
1
percona/percona-server-mongodb-operator:1.23.0feaff989e253
stdlib@go1.26.5
1.26.6
1
percona/percona-server-mysql-operator:1.2.028bfc38c1d4b
stdlib@go1.26.4
1.26.6
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
golang.org/x/net@v0.19.0
0.56.0
1
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
1
percona/pmm-server:3.9.1003f9c25f842
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
1
persesdev/perses:v0.54.0a0e34ddaf9d7
stdlib@go1.26.5
1.26.6
1
persesdev/perses-operator:v0.5.08f8d7b09caef
stdlib@go1.26.5
1.26.6
1
peterdavehello/tor-socks-proxy:latest0cc12d36d312
golang.org/x/net@v0.35.0
stdlib@go1.26.2
0.56.0
1.26.6
1
pgsharding/spqr-router:nightly-2.8.3-1839-f66048d84734940216d3
golang.org/x/net@v0.47.0
0.56.0
1
philmtd/full-house:1.9.0d68a6bb8a2bf
stdlib@go1.26.3
1.26.6
1
phntom/chadbot:0.2.397c28e4178ad
golang.org/x/net@v0.11.0
0.56.0
1
phntom/chartmuseum:v0.16.053883b65d9b7
golang.org/x/net@v0.10.0
0.56.0
1
phntom/chartmuseum:v0.15.29242b4df9e65
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.56.0
1
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.56.0
1
phntom/goalert:0.0.298ca4df55499b
golang.org/x/net@v0.19.0
0.56.0
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/net@v0.17.0
0.56.0
1
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.56.0
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
golang.org/x/net@v0.0.0-20221012135044-0b7e1fb9d458
0.56.0
1
photoprism/photoprism:231128-ce284de9cc4f9c
golang.org/x/net@v0.18.0
0.56.0
1
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.56.0
1
photoprism/photoprism:260601650c6ad5a651
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
1
photoprism/photoprism:260728958642220223
stdlib@go1.26.5
1.26.6
1
photoprism/photoprism:251130db16ee6b1ba3
golang.org/x/net@v0.47.0
0.56.0
1
photoprism/photoprism:240711-cefc6fd632ca74
golang.org/x/net@v0.27.0
0.56.0
1
piblokto/backlokto-operator:v0.0.20963cda71e393
golang.org/x/net@v0.17.0
0.56.0
1
pinclr/v2ray-proxy:latestf37f250b7091
golang.org/x/net@v0.7.0
0.56.0
1
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0
1
platform9community/api-gateway:latest40a4970de568
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0
1
platform9community/customers-service:latest2089811e5cc6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0
1
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0
1
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0
1
platzio/backend:v0.6.5d5e5972f344b
golang.org/x/net@v0.38.0
0.56.0
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.56.0
1
pnnlmiscscripts/pixiecore:1.0.1-1c6f17741a0d7
golang.org/x/net@v0.7.0
0.56.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
golang.org/x/net@v0.48.0
0.56.0
1
polyaxon/training-operator:2.1.0b5b29deaec9a
golang.org/x/net@v0.17.0
0.56.0
1
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/net@v0.9.0
0.56.0
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
golang.org/x/net@v0.7.0
0.56.0
1
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
stdlib@go1.26.5
1.26.6
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.