StackRadar

CVE-2026-46600

Unscored

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,542
of 17,781 indexed, latest versions
Container images
4,336
deployed by those charts
Fix available
2 of 2
affected packages

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Carried by container images the latest versions of 3,542 of 17,781 indexed charts deploy, on 4,336 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more0.56.03,910
stdlibgolanggo1.26.0, go1.26.1, go1.26.2, go1.26.2-X:boringcrypto+7 more1.26.6906
OSV records
GO-2026-5942
Also known as
BIT-golang-2026-46600

Charts affected

3,542 by stars
ChartLatestAffected imagesRadar Score
oesopsmxVerified publisher4.0.327 of 25See more

oes opsmx 4.0.32

7 of the 25 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.56.0
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.56.0
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
golang.org/x/net@v0.7.0
0.56.0
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
0.56.0
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
golang.org/x/net@v0.38.0
0.56.0
quay.io/opsmxpublic/opa:1.12.084fb1af7401c
golang.org/x/net@v0.47.0
0.56.0
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.56.0

Open the chart page →

107,811
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
golang.org/x/net@v0.0.0-20220517181318-183a9ca12b87
0.56.0
ipfs/ipfs-cluster:1.0.21511f6d57994
golang.org/x/net@v0.0.0-20220517181318-183a9ca12b87
0.56.0

Open the chart page →

3,757
psmdb-operatorpercona1.23.11 of 1See more

psmdb-operator percona 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
percona/percona-server-mongodb-operator:1.23.0feaff989e253
stdlib@go1.26.5
1.26.6

Open the chart page →

246
permifypermifyVerified publisher0.5.01 of 1See more

permify permify 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/permify/permify:v1.3.5f0c6f7d7daa6
golang.org/x/net@v0.26.0
0.56.0

Open the chart page →

997
persespersesOfficialVerified publisher0.23.21 of 1See more

perses perses 0.23.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
persesdev/perses:v0.54.0a0e34ddaf9d7
stdlib@go1.26.5
1.26.6

Open the chart page →

133
platzioplatz-ioVerified publisher0.6.51 of 2See more

platzio platz-io 0.6.5

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
platzio/backend:v0.6.5d5e5972f344b
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

2,866
plecopleco0.24.01 of 1See more

pleco pleco 0.24.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

1,346
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/net@v0.9.0
0.56.0

Open the chart page →

1,942
prometheus-pgbouncer-exporterprometheus-communityVerified publisher0.10.11 of 1See more

prometheus-pgbouncer-exporter prometheus-community 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/pgbouncer-exporter:v0.12.130f31b6c2efd
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

298
prometheus-systemd-exporterprometheus-communityVerified publisher0.5.21 of 1See more

prometheus-systemd-exporter prometheus-community 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/systemd-exporter:v0.7.078c03f875dfb
golang.org/x/net@v0.33.0
0.56.0

Open the chart page →

725
prometheus-yet-another-cloudwatch-exporterprometheus-communityVerified publisher0.47.01 of 1See more

prometheus-yet-another-cloudwatch-exporter prometheus-community 0.47.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/yet-another-cloudwatch-exporter:v0.67.0404791bf0b2f
stdlib@go1.26.4
1.26.6

Open the chart page →

68
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.56.0
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.56.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.56.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.56.0

Open the chart page →

12,125
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
golang.org/x/net@v0.35.0
0.56.0

Open the chart page →

5,435
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.56.0

Open the chart page →

2,730
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-07-23T15-54-02Zd249d1fb6966
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

13,521
backrestrobertobochetVerified publisher0.7.01 of 1See more

backrest robertobochet 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
garethgeorge/backrest:v1.14.1b85297975428
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.56.0
1.26.6

Open the chart page →

859
rqliterqliteOfficialVerified publisher2.0.01 of 1See more

rqlite rqlite 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
rqlite/rqlite:9.1.37b992a526eee
golang.org/x/net@v0.46.0
0.56.0

Open the chart page →

1,311
qbittorrent-vpnrtomik-helm-chartsVerified publisher0.0.21 of 2See more

qbittorrent-vpn rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.40.02b42bfa04675
golang.org/x/net@v0.31.0
0.56.0

Open the chart page →

1,218
sabliersablier-helm-chartsOfficialVerified publisher1.8.11 of 1See more

sablier sablier-helm-charts 1.8.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
sablierapp/sablier:1.16.1413704376656
stdlib@go1.26.3
1.26.6

Open the chart page →

147
seaweedfs-csi-driverseaweedfs-csi-driver0.2.385 of 7See more

seaweedfs-csi-driver seaweedfs-csi-driver 0.2.38

5 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

5,270
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
golang.org/x/net@v0.44.0
0.56.0

Open the chart page →

841
bentoself-hosters-by-nightVerified publisher0.9.11 of 1See more

bento self-hosters-by-night 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
golang.org/x/net@v0.37.0
0.56.0

Open the chart page →

1,046
appshini4iVerified publisher0.4.01 of 1See more

app shini4i 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
traefik/whoami:v1.10.21474027c3166
golang.org/x/net@v0.25.0
0.56.0

Open the chart page →

537
skypilotskypilotOfficialVerified publisher0.13.03 of 3See more

skypilot skypilot 0.13.0

3 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
golang.org/x/net@v0.38.0
stdlib@go1.26.4
0.56.0
1.26.6
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/net@v0.41.0
0.56.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
0.56.0

Open the chart page →

5,852
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/net@v0.4.0
0.56.0

Open the chart page →

1,663
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.56.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.56.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.56.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.56.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.56.0

Open the chart page →

12,502
miniosolidchartsVerified publisher0.5.01 of 1See more

minio solidcharts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
golang.org/x/net@v0.42.0
0.56.0

Open the chart page →

1,055
forecastlestakaterVerified publisher2.1.11 of 1See more

forecastle stakater 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
stakater/forecastle:v2.0.2382cd9572352
golang.org/x/net@v0.51.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

712
ingressmonitorcontrollerstakaterVerified publisher2.2.131 of 1See more

ingressmonitorcontroller stakater 2.2.13

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/stakater/ingressmonitorcontroller:v2.2.133301afb61c10
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

576
vertical-pod-autoscalerstevehipwell-helm-charts-vertical-pod-autoscalerVerified publisher1.12.13 of 3See more

vertical-pod-autoscaler stevehipwell-helm-charts-vertical-pod-autoscaler 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

228
sn-platformstreamnative1.11.445 of 9See more

sn-platform streamnative 1.11.44

5 of the 9 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
0.56.0
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
0.56.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
0.56.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

15,477
stunnerstunner1.2.12 of 2See more

stunner stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:1.2.10d2094060b72
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
l7mp/stunner-gateway-operator:1.2.10ea40a1d42d5
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

263
pocketbasetechwolf12Verified publisher0.29.31 of 1See more

pocketbase techwolf12 0.29.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/net@v0.43.0
0.56.0

Open the chart page →

1,446
feedbacksystemthm-mni-iiVerified publisher0.47.14 of 10See more

feedbacksystem thm-mni-ii 0.47.1

4 of the 10 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/net@v0.19.0
0.56.0
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
0.56.0
library/docker:20.10.21-dind3153fa63f546
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

28,534
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

1,494
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.56.0

Open the chart page →

4,136
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.56.0
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.56.0

Open the chart page →

9,257
k8s-ttl-controllertwin0.4.01 of 1See more

k8s-ttl-controller twin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/net@v0.26.0
0.56.0

Open the chart page →

471
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/net@v0.11.0
0.56.0
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

10,315
uptraceuptrace2.0.21 of 2See more

uptrace uptrace 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
uptrace/uptrace:2.0.234a02c3b2d12
golang.org/x/net@v0.42.0
0.56.0

Open the chart page →

1,619
valkey-operatorvalkeyVerified publisher0.6.01 of 1See more

valkey-operator valkey 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/valkey-io/valkey-operator:v0.6.052a0f1ed0c03
golang.org/x/net@v0.49.0
0.56.0

Open the chart page →

134
vaultvaultVerified publisher1.22.04 of 4See more

vault vault 1.22.0

4 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alpine/k8s:1.35.5d870622d0040
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.56.0
1.26.6
hashicorp/vault:2.0.1755355002715
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
prom/statsd-exporter:v0.29.0632f70580492
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.56.0
1.26.6
ghcr.io/bank-vaults/bank-vaults:v1.33.198b6ea2ed319
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

4,243
vouchvouchVerified publisher3.2.01 of 1See more

vouch vouch 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/net@v0.5.0
0.56.0

Open the chart page →

1,031
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
0.56.0

Open the chart page →

1,344
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
0.56.0

Open the chart page →

2,245
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
golang.org/x/net@v0.52.0
0.56.0

Open the chart page →

999
wallarm-ingresswallarmVerified publisher5.3.10-12 of 2See more

wallarm-ingress wallarm 5.3.10-1

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
golang.org/x/net@v0.34.0
0.56.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
0.56.0

Open the chart page →

1,301
wallarm-sidecarwallarmOfficialVerified publisher6.13.11 of 3See more

wallarm-sidecar wallarm 6.13.1

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
0.56.0

Open the chart page →

965
argo-cdwenerme10.9.02 of 3See more

argo-cd wenerme 10.9.0

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/net@v0.50.0
stdlib@go1.26.0
0.56.0
1.26.6
quay.io/argoproj/argocd:v3.5.2e2aadfae709d
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.56.0
1.26.6

Open the chart page →

3,218
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0.56.0

Open the chart page →

6,085

Container images carrying it

4,336 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/net@v0.50.0
stdlib@go1.26.0
0.56.0
1.26.6
3
ghcr.io/kuberocketci/krci-cache:0.3.05f6cd61e6da6
golang.org/x/net@v0.55.0
0.56.0
3
ghcr.io/kubevault/vault-operator:v0.25.0c8e042b5cee8
golang.org/x/net@v0.55.0
0.56.0
3
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
golang.org/x/net@v0.46.0
0.56.0
3
ghcr.io/sigstore/scaffolding/createdb3cee6c78973b
golang.org/x/net@v0.46.0
0.56.0
3
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
golang.org/x/net@v0.46.0
0.56.0
3
ghcr.io/sigstore/scaffolding/trillian_log_server5a878e4e4f03
stdlib@go1.26.0
1.26.6
3
ghcr.io/sigstore/scaffolding/trillian_log_signer28c5ff40963f
stdlib@go1.26.0
1.26.6
3
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.12d7747f308042
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.56.0
1.26.6
3
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/net@v0.47.0
0.56.0
3
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.56.0
3
quay.io/argoproj/argocd:v3.5.2e2aadfae709d
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.56.0
1.26.6
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.56.0
3
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
0.56.0
3
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
stdlib@go1.26.5
1.26.6
3
quay.io/cilium/operator-generic:v1.20.16c3885fc7b62
stdlib@go1.26.5
1.26.6
3
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/net@v0.23.0
0.56.0
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.56.0
3
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0
3
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
golang.org/x/net@v0.48.0
0.56.0
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
golang.org/x/net@v0.48.0
0.56.0
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/net@v0.48.0
0.56.0
3
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.56.0
3
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
golang.org/x/net@v0.40.0
0.56.0
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
golang.org/x/net@v0.48.0
0.56.0
3
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
golang.org/x/net@v0.48.0
0.56.0
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/net@v0.48.0
0.56.0
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.56.0
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
0.56.0
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.56.0
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
0.56.0
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
0.56.0
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/net@v0.48.0
0.56.0
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/net@v0.48.0
0.56.0
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/net@v0.48.0
0.56.0
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
0.56.0
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/net@v0.48.0
0.56.0
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.56.0
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
0.56.0
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.56.0
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.56.0
3
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
0.56.0
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
0.56.0
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
0.56.0
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.56.0
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
0.56.0
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0
3

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.