StackRadar

CVE-2026-46600

Unscored

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,559
of 17,787 indexed, latest versions
Container images
4,367
deployed by those charts
Fix available
2 of 2
affected packages

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Carried by container images the latest versions of 3,559 of 17,787 indexed charts deploy, on 4,367 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+221 more0.56.03,943
stdlibgolanggo1.26.0, go1.26.1, go1.26.2, go1.26.2-X:boringcrypto+7 more1.26.6898
OSV records
GO-2026-5942
Also known as
BIT-golang-2026-46600

Charts affected

3,559 by stars
ChartLatestAffected imagesRadar Score
nextcloud-exporterchristianhuthVerified publisher1.5.01 of 1See more

nextcloud-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
xperimental/nextcloud-exporter:0.9.13e90a3897651
stdlib@go1.26.1
1.26.6

Open the chart page →

194
ntp-exporterchristianhuthVerified publisher1.4.01 of 1See more

ntp-exporter christianhuth 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/sapcc/ntp_exporter:v2.9.079c40c65f5d4
golang.org/x/net@v0.43.0
0.56.0

Open the chart page →

378
promlenschristianhuthVerified publisher1.6.01 of 1See more

promlens christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
prom/promlens:v0.4.04a377d1a0eaa
stdlib@go1.26.5
1.26.6

Open the chart page →

128
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.56.0

Open the chart page →

2,290
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

7,006
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/net@v0.30.0
0.56.0

Open the chart page →

4,858
ethereumchronicleVerified publisher0.3.11 of 1See more

ethereum chronicle 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

1,350
ethereum-metrics-exporterchronicleVerified publisher0.1.41 of 1See more

ethereum-metrics-exporter chronicle 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
samcm/ethereum-metrics-exporter:0.29.291a2d9a015c1
golang.org/x/net@v0.43.0
0.56.0

Open the chart page →

684
goferchronicleVerified publisher0.4.41 of 1See more

gofer chronicle 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/gofer:0.613915d2e41e04
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

721
mantlechronicleVerified publisher0.1.31 of 1See more

mantle chronicle 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/net@v0.10.0
0.56.0

Open the chart page →

1,934
spirechronicleVerified publisher0.3.61 of 1See more

spire chronicle 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

1,521
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.56.0

Open the chart page →

3,595
ciliumcilium21.20.13 of 3See more

cilium cilium2 1.20.1

3 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
stdlib@go1.26.5
1.26.6
quay.io/cilium/cilium-envoy:v1.37.5-1786810558-766ccfb37260a43e9d228837aa84ce3faf9f64e775b8094c7127
golang.org/x/net@v0.55.0
0.56.0
quay.io/cilium/operator-generic:v1.20.16c3885fc7b62
stdlib@go1.26.5
1.26.6

Open the chart page →

1,786
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/chekrdigest-pinnedf299baf467b5
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0

Open the chart page →

3,470
vulnerability-operatorckotzbauerVerified publisher0.31.151 of 1See more

vulnerability-operator ckotzbauer 0.31.15

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/vulnerability-operator:0.28.167008df32715c
stdlib@go1.26.4
1.26.6

Open the chart page →

187
clairclair-helmVerified publisher0.12.01 of 3See more

clair clair-helm 0.12.0

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.9.023329c3368e4
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

1,618
calico-cniclastixVerified publisher3.28.13 of 3See more

calico-cni clastix 3.28.1

3 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
calico/cni:v3.28.1e486870cfde8
golang.org/x/net@v0.24.0
0.56.0
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/net@v0.24.0
0.56.0
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/net@v0.24.0
0.56.0

Open the chart page →

3,050
capi-kamaji-vsphere-fullclastixVerified publisher1.0.19 of 9See more

capi-kamaji-vsphere-full clastix 1.0.1

9 of the 9 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
golang.org/x/net@v0.38.0
0.56.0
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/net@v0.32.0
0.56.0
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/net@v0.33.0
0.56.0
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/net@v0.33.0
0.56.0
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
0.56.0
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
0.56.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/net@v0.33.0
0.56.0
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
0.56.0

Open the chart page →

5,933
capsule-rancher-addonclastixVerified publisher0.1.15 of 5See more

capsule-rancher-addon clastix 0.1.1

5 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/net@v0.4.0
0.56.0
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
0.56.0
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
0.56.0
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
0.56.0
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
0.56.0

Open the chart page →

7,104
kamajiclastixVerified publisher0.0.0+latest3 of 4See more

kamaji clastix 0.0.0+latest

3 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
clastix/kamaji:latesta7c5d108810b
stdlib@go1.26.5
1.26.6
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.56.0
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
0.56.0

Open the chart page →

4,630
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
golang.org/x/net@v0.23.0
0.56.0

Open the chart page →

2,761
kamaji-etcdclastixVerified publisher0.17.03 of 4See more

kamaji-etcd clastix 0.17.0

3 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
golang.org/x/net@v0.20.0
0.56.0
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.56.0
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
0.56.0

Open the chart page →

12,021
local-path-provisionerclastixVerified publisher0.0.301 of 1See more

local-path-provisioner clastix 0.0.30

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/net@v0.27.0
0.56.0

Open the chart page →

1,208
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
0.56.0
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.56.0
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0

Open the chart page →

7,386
cloudflare-ddnsclouddrove0.1.51 of 1See more

cloudflare-ddns clouddrove 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
favonia/cloudflare-ddns:161013368c8f9
stdlib@go1.26.4
1.26.6

Open the chart page →

68
cloudflared-tunnelclouddrove0.1.41 of 1See more

cloudflared-tunnel clouddrove 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/net@v0.40.0
0.56.0

Open the chart page →

1,750
cronjobclouddrove1.0.11 of 1See more

cronjob clouddrove 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
stdlib@go1.26.5
1.26.6

Open the chart page →

733
kube-acp-stackcloudentity2.28.02 of 7See more

kube-acp-stack cloudentity 2.28.0

2 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/net@v0.33.0
0.56.0
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.56.0

Open the chart page →

20,936
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.56.0
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.56.0
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.56.0
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.56.0
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.56.0
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.56.0

Open the chart page →

18,040
cloudflare-ddns-updatecloudflare-ddns-update0.1.21 of 1See more

cloudflare-ddns-update cloudflare-ddns-update 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/net@v0.25.0
0.56.0

Open the chart page →

1,338
cloudflare-tunnel-ingress-controllercloudflare-tunnel-ingress-controller0.2.31 of 1See more

cloudflare-tunnel-ingress-controller cloudflare-tunnel-ingress-controller 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/oliverbaehler/cloudflare-tunnel-ingress-controller:0.2.30aec31e36d95
golang.org/x/net@v0.37.0
0.56.0

Open the chart page →

438
cloudfront-tenant-operatorcloudfront-tenant-operatorVerified publisher0.3.01 of 1See more

cloudfront-tenant-operator cloudfront-tenant-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.56.0
1.26.6

Open the chart page →

269
hcloud-csi-mgmtcloudhippieVerified publisher2.10.02 of 5See more

hcloud-csi-mgmt cloudhippie 2.10.0

2 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

583
mercurecloudnativeapp1.0.21 of 1See more

mercure cloudnativeapp 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
dunglas/mercure:v0916834e49961
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

1,098
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/net@v0.14.0
0.56.0

Open the chart page →

25,152
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0

Open the chart page →

6,696
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
0.56.0

Open the chart page →

6,921
ocs-operatorcloud-native-toolkit0.2.41 of 1See more

ocs-operator cloud-native-toolkit 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:latest605eaa5d469c
stdlib@go1.26.5
1.26.6

Open the chart page →

369
refarch-infraconfigcloud-native-toolkit0.2.21 of 1See more

refarch-infraconfig cloud-native-toolkit 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:latest605eaa5d469c
stdlib@go1.26.5
1.26.6

Open the chart page →

369
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad2 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

2 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.56.0
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
golang.org/x/net@v0.41.0
0.56.0

Open the chart page →

18,256
cloud-provider-kubevirtcloud-provider-kubevirtVerified publisher0.2.01 of 1See more

cloud-provider-kubevirt cloud-provider-kubevirt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/net@v0.49.0
0.56.0

Open the chart page →

656
k8s-monitoring-appcloudscriptVerified publisher1.0.01 of 1See more

k8s-monitoring-app cloudscript 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/k8s-monitoring-app:v0.0.25cab66a6b3574
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

1,294
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.56.0

Open the chart page →

3,136
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/net@v0.14.0
0.56.0

Open the chart page →

5,552
galaxy-cvmfs-csicloudve2.5.12 of 3See more

galaxy-cvmfs-csi cloudve 2.5.1

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
golang.org/x/net@v0.18.0
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
0.56.0

Open the chart page →

1,501
galaxy-depscloudve1.1.16 of 7See more

galaxy-deps cloudve 1.1.1

6 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
0.56.0
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.56.0
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/net@v0.0.0-20220614195744-fb05da6f9022
0.56.0
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/net@v0.32.0
0.56.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

10,543
galaxy-k8s-monitorcloudve0.1.11 of 1See more

galaxy-k8s-monitor cloudve 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
afgane/galaxy-k8s-monitor:latest457173db5640
golang.org/x/net@v0.30.0
0.56.0

Open the chart page →

313
galaxykubemancloudve2.10.14 of 7See more

galaxykubeman cloudve 2.10.1

4 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.56.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
0.56.0
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.56.0

Open the chart page →

16,117
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.56.0

Open the chart page →

14,285
openstack-cinder-csicloudve1.2.01 of 5See more

openstack-cinder-csi cloudve 1.2.0

1 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0

Open the chart page →

2,061

Container images carrying it

4,367 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
golang.org/x/net@v0.42.0
0.56.0
2
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/net@v0.38.0
0.56.0
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.56.0
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
0.56.0
2
bitnamisecure/git72ae5bd9715f
golang.org/x/net@v0.38.0
0.56.0
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
0.56.0
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
0.56.0
2
bloomberg/goldpinger:3.11.3a8ea8c61ff4c
golang.org/x/net@v0.49.0
0.56.0
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
golang.org/x/net@v0.55.0
0.56.0
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.56.0
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
0.56.0
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.56.0
2
cloudflare/cloudflared:2026.6.16d91c121b803
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
2
coredns/coredns:1.13.19b9128672209
golang.org/x/net@v0.45.0
0.56.0
2
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
0.56.0
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.56.0
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
0.56.0
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.56.0
2
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
0.56.0
2
danielqsj/kafka-exporter:latesta51b280b55a7
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.56.0
1.26.6
2
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.56.0
2
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/net@v0.36.0
0.56.0
2
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
2
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/net@v0.22.0
0.56.0
2
dunglas/mercure:v0:v0.24.2916834e49961
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
2
epamedp/edp-tekton:0.27.088189f16f94b
golang.org/x/net@v0.55.0
0.56.0
2
epamedp/gitfusion:0.6.10b7eb7d5ca43
golang.org/x/net@v0.55.0
0.56.0
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.56.0
2
filebrowser/filebrowser:latest:v2.63.23a469ea076d4a
stdlib@go1.26.5
1.26.6
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
0.56.0
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
0.56.0
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
0.56.0
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
0.56.0
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
0.56.0
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
0.56.0
2
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/net@v0.23.0
0.56.0
2
free5gc/udm:v3.4.32f68df062a50
golang.org/x/net@v0.23.0
0.56.0
2
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/net@v0.23.0
0.56.0
2
free5gc/upf:v3.4.3b6b362a39fdd
golang.org/x/net@v0.23.0
0.56.0
2
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/net@v0.23.0
0.56.0
2
githubexporter/github-exporter:v2.3.1a36fbedeedf8
stdlib@go1.26.4
1.26.6
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
0.56.0
2
gotenberg/gotenberg:8.36.087c16b9f3642
stdlib@go1.26.5
1.26.6
2
gotify/server:3.1.0be44495e4609
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.56.0
1.26.6
2
gotson/komga:1.26.36c2a967bbe9a
stdlib@go1.26.5
1.26.6
2
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.56.0
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.56.0
2
grafana/alloy:v1.8.17790f6f7fbd8
golang.org/x/net@v0.37.0
0.56.0
2
grafana/alloy:v1.12.2f94b1c82957a
golang.org/x/net@v0.46.0
0.56.0
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.