StackRadar

CVE-2026-46600

Unscored

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,542
of 17,803 indexed, latest versions
Container images
4,339
deployed by those charts
Fix available
2 of 2
affected packages

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Carried by container images the latest versions of 3,542 of 17,803 indexed charts deploy, on 4,339 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+221 more0.56.03,931
stdlibgolanggo1.26.0, go1.26.1, go1.26.2, go1.26.2-X:boringcrypto+7 more1.26.6873
OSV records
GO-2026-5942
Also known as
BIT-golang-2026-46600

Charts affected

3,542 by stars
ChartLatestAffected imagesRadar Score
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.4.02 of 3See more

kubeshark kubeshark-helm-charts 53.4.0

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
kubeshark/hub:v53.46d3f22525a0e
stdlib@go1.26.5
1.26.6
kubeshark/worker:v53.4b226490dfa11
stdlib@go1.26.5
1.26.6

Open the chart page →

845
secrets-store-csi-driversecret-store-csi-driver1.6.13 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

3 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver-crds:v1.6.1cdacfdbe8966
stdlib@go1.26.5
1.26.6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
0.56.0
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
0.56.0

Open the chart page →

1,818
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.11 of 2See more

stackgres-operator stackgres-charts 1.19.1

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

2,154
victoria-logs-singlevictoriametricsVerified publisher0.13.91 of 1See more

victoria-logs-single victoriametrics 0.13.9

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.52.047b820890d64
stdlib@go1.26.5
1.26.6

Open the chart page →

60
mongodbcloudpirates-mongodbVerified publisher0.18.131 of 1See more

mongodb cloudpirates-mongodb 0.18.13

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
library/mongo:8.3.981a1c8842a09
stdlib@go1.26.5
1.26.6

Open the chart page →

979
opensearch-operatoropensearch-operatorVerified publisher3.0.21 of 1See more

opensearch-operator opensearch-operator 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
opensearchproject/opensearch-operator:3.0.0-alphaf78bbdd1a386
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

618
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

433
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
stdlib@go1.26.5
1.26.6

Open the chart page →

1,609
pulsarapache4.7.06 of 10See more

pulsar apache 4.7.0

6 of the 10 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.47.0
0.56.0
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
0.56.0
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.56.0
victoriametrics/operator:v0.68.3f52e1bd679cb
golang.org/x/net@v0.49.0
0.56.0
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
0.56.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
0.56.0

Open the chart page →

9,942
miniocloudpirates-minioVerified publisher0.13.41 of 1See more

minio cloudpirates-minio 0.13.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

1,229
vertical-pod-autoscalercowboysysopVerified publisher11.1.14 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

4 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
0.56.0
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
golang.org/x/net@v0.43.0
0.56.0
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
golang.org/x/net@v0.43.0
0.56.0
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/net@v0.43.0
0.56.0

Open the chart page →

6,997
difydify-helmVerified publisher0.38.04 of 11See more

dify dify-helm 0.38.0

4 of the 11 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
langgenius/dify-api:1.16.1dcefa5f7c47c
stdlib@go1.26.4
1.26.6
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

59,806
eclipse-cheeclipse-cheVerified publisher7.122.01 of 1See more

eclipse-che eclipse-che 7.122.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
stdlib@go1.26.5
1.26.6

Open the chart page →

932
pyroscopegrafana2.3.12 of 3See more

pyroscope grafana 2.3.1

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
golang.org/x/net@v0.46.0
0.56.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
0.56.0

Open the chart page →

3,265
botkubeinfracloudioVerified publisher1.14.01 of 1See more

botkube infracloudio 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
golang.org/x/net@v0.23.0
0.56.0

Open the chart page →

1,104
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

874
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.56.0

Open the chart page →

4,127
k6-operatorgrafana4.6.01 of 1See more

k6-operator grafana 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/grafana/k6-operator:controller-v1.6.0ba7f0fc1e22e
stdlib@go1.26.5
1.26.6

Open the chart page →

103
kiali-serverkiali2.32.01 of 1See more

kiali-server kiali 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/kiali/kiali:v2.32.0b171d679be27
stdlib@go1.26.3
1.26.6

Open the chart page →

256
oktetooktetoOfficialVerified publisher0.0.0-2026-08-177 of 10See more

okteto okteto 0.0.0-2026-08-17

7 of the 10 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/okteto/backend:0.0.0-2026-08-17629bdce31b4d
golang.org/x/net@v0.47.0
stdlib@go1.26.5
0.56.0
1.26.6
ghcr.io/okteto/buildkit:0.0.0-2026-08-1714527ca5d2a9
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
ghcr.io/okteto/daemon:0.0.0-2026-08-17c6e716a3fbbe
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-17265eedb3954b
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
ghcr.io/okteto/okteto:3.22.04585017f52f6
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
ghcr.io/okteto/registry:0.0.0-2026-08-1769131511501f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
ghcr.io/okteto/reloader:0.0.0-2026-08-1704a3fce657c4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

5,585
hydraory0.64.02 of 2See more

hydra ory 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.56.0
1.26.6
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

1,317
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
0.56.0

Open the chart page →

941
proxmox-csi-pluginproxmox-csi0.5.127 of 7See more

proxmox-csi-plugin proxmox-csi 0.5.12

7 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-csi-controller:v0.20.095ef74cce03e
stdlib@go1.26.5
1.26.6
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
stdlib@go1.26.5
1.26.6
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

1,862
thanosthanos-communityOfficialVerified publisher0.44.01 of 1See more

thanos thanos-community 0.44.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
stdlib@go1.26.5
1.26.6

Open the chart page →

212
apisix-ingress-controllerapisix1.4.01 of 2See more

apisix-ingress-controller apisix 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
stdlib@go1.26.5
1.26.6

Open the chart page →

1,708
volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/net@v0.55.0
0.56.0

Open the chart page →

1,409
concourseconcourseVerified publisher20.3.01 of 2See more

concourse concourse 20.3.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
concourse/concourse:8.3.040a143ce5873
golang.org/x/net@v0.50.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

2,088
dynatrace-operatordynatraceVerified publisher1.10.21 of 1See more

dynatrace-operator dynatrace 1.10.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.10.252281db48c93
stdlib@go1.26.5
1.26.6

Open the chart page →

190
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
0.56.0

Open the chart page →

4,180
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
golang.org/x/net@v0.34.0
0.56.0

Open the chart page →

2,016
oncallgrafana1.16.57 of 12See more

oncall grafana 1.16.5

7 of the 12 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
0.56.0
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.56.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.56.0

Open the chart page →

16,456
k8sgpt-operatork8sgptOfficialVerified publisher0.2.292 of 2See more

k8sgpt-operator k8sgpt 0.2.29

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.2982d0adcce816
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.56.0
1.26.6
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

987
node-feature-discoverynode-feature-discoveryOfficialVerified publisher0.19.01 of 1See more

node-feature-discovery node-feature-discovery 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
stdlib@go1.26.3
1.26.6

Open the chart page →

245
openbaoopenbaoVerified publisher0.29.51 of 2See more

openbao openbao 0.29.5

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:1.7.2ae3d307658b7
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

1,519
kratosory0.64.01 of 1See more

kratos ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
oryd/kratos:v26.2.02a13bb8d362c
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.56.0
1.26.6

Open the chart page →

883
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.56.0

Open the chart page →

11,446
aws-cloudwatch-metricsaws0.0.111 of 1See more

aws-cloudwatch-metrics aws 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

1,573
zabbixcetic3.1.31 of 5See more

zabbix cetic 3.1.3

1 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0

Open the chart page →

34,041
csi-driver-smbcsi-driver-smbVerified publisher1.20.35 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

5 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
stdlib@go1.26.4
1.26.6

Open the chart page →

3,019
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.56.0

Open the chart page →

4,959
hpe-csi-driverhpe-storageVerified publisher3.3.05 of 14See more

hpe-csi-driver hpe-storage 3.3.0

5 of the 14 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

1,750
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
golang.org/x/net@v0.44.0
0.56.0

Open the chart page →

2,397
cloudflaredkubitodevVerified publisher1.7.91 of 1See more

cloudflared kubitodev 1.7.9

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
0.56.0

Open the chart page →

1,477
ngrok-operatorngrokOfficialVerified publisher0.24.01 of 2See more

ngrok-operator ngrok 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ngrok/ngrok-operator:0.22.0db8e6fecc52c
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

133
prometheus-snmp-exporterprometheus-communityOfficialVerified publisher9.18.01 of 1See more

prometheus-snmp-exporter prometheus-community 9.18.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/net@v0.48.0
0.56.0

Open the chart page →

509
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.56.0

Open the chart page →

2,040
daskdask2024.1.11 of 2See more

dask dask 2024.1.1

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

12,902
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
golang.org/x/net@v0.35.0
0.56.0

Open the chart page →

3,056
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.56.0

Open the chart page →

6,221
netbirdjaconiVerified publisher0.15.13 of 4See more

netbird jaconi 0.15.1

3 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
golang.org/x/net@v0.39.0
0.56.0
netbirdio/relay:0.45.1872e3add0e1e
golang.org/x/net@v0.39.0
0.56.0
netbirdio/signal:0.45.146ce5a45538f
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

8,651

Container images carrying it

4,339 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/diagrid-dev/diagrid-dashboard:latestf1348a65664a
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
1
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
golang.org/x/net@v0.5.0
0.56.0
1
public.ecr.aws/dynatrace/dynatrace-operator:v1.10.252281db48c93
stdlib@go1.26.5
1.26.6
1
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
golang.org/x/net@v0.28.0
0.56.0
1
public.ecr.aws/eks/amazon-eks-pod-identity-webhook:v0.6.173071570e8e8c
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.56.0
1.26.6
1
public.ecr.aws/eks-distro/kubernetes/kube-scheduler:v1.29.14-eks-1-29-lateste7e1db003e6a
golang.org/x/net@v0.24.0
0.56.0
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
golang.org/x/net@v0.52.0
stdlib@go1.26.3
0.56.0
1.26.6
1
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
golang.org/x/net@v0.47.0
0.56.0
1
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6
1
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.56.0
1.26.6
1
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.56.0
1
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.56.0
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-agent:v3.0.1d75b6da94913
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.56.0
1.26.6
1
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
golang.org/x/net@v0.44.0
0.56.0
1
public.ecr.aws/karpenter/controller:1.9.030a506c64fbb
golang.org/x/net@v0.48.0
0.56.0
1
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
golang.org/x/net@v0.1.0
0.56.0
1
public.ecr.aws/karpenter/controller:1.1.1fe383abf1dbc
golang.org/x/net@v0.30.0
0.56.0
1
public.ecr.aws/kyos/evicted-pod-reaper:1.0.0b9d047442ce2
golang.org/x/net@v0.40.0
0.56.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-bootstrapper:v1.1.115ca2d500d374
golang.org/x/net@v0.33.0
0.56.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-guard:v1.1.17a94d2d4aae85
golang.org/x/net@v0.33.0
0.56.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
golang.org/x/net@v0.33.0
0.56.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-sync:v1.1.1514f3dfbc0225
golang.org/x/net@v0.33.0
0.56.0
1
public.ecr.aws/n8h5y2v5/rad-security/rad-watch:v1.1.25b9a7d6bc2a0c
golang.org/x/net@v0.33.0
0.56.0
1
public.ecr.aws/neuron/neuron-device-plugin:2.23.30.075a6d5ce3bd3
golang.org/x/net@v0.23.0
0.56.0
1
public.ecr.aws/neuron/neuron-scheduler:2.23.30.04cd274463e6b
golang.org/x/net@v0.23.0
0.56.0
1
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
golang.org/x/net@v0.28.0
0.56.0
1
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
golang.org/x/net@v0.33.0
0.56.0
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
golang.org/x/net@v0.17.0
0.56.0
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
golang.org/x/net@v0.27.0
0.56.0
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/net@v0.39.0
0.56.0
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
golang.org/x/net@v0.48.0
0.56.0
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0
1
public.ecr.aws/sumologic/tailing-sidecar-operator:0.111.0920b8f901aef
golang.org/x/net@v0.38.0
0.56.0
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0
1
public.ecr.aws/t0u0d5o5/ecr_authenticator:latest077e4e57e41c
golang.org/x/net@v0.17.0
0.56.0
1
public.ecr.aws/truefoundrycloud/eks/eks-node-monitoring-agent:v1.5.1-eksbuild.1988c8e1a273a
golang.org/x/net@v0.49.0
0.56.0
1
public.ecr.aws/v0r6c2e2/minio:latest08c90bd040bf
golang.org/x/net@v0.34.0
0.56.0
1
public.ecr.aws/xray/aws-xray-daemon:3.6.243d051eed000
golang.org/x/net@v0.38.0
0.56.0
1
quay.io/aerokube/boot:1.0.13c269612053f
golang.org/x/net@v0.24.0
0.56.0
1
quay.io/aerokube/browser-ops:2.6.7807c1bb67086
golang.org/x/net@v0.23.0
0.56.0
1
quay.io/aerokube/keygen:1.0.1578934444f04
golang.org/x/net@v0.8.0
0.56.0
1
quay.io/aerokube/moon:2.5.1a8837b00ba1c
golang.org/x/net@v0.7.0
0.56.0
1
quay.io/aerokube/moon:2.8.1e618a3ed6436
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.56.0
1.26.6
1
quay.io/aerokube/moon-conf:2.8.11ef2b53c98fd
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.56.0
1.26.6
1
quay.io/aerokube/moon-conf:2.5.19ca307b30080
golang.org/x/net@v0.7.0
0.56.0
1
quay.io/aerokube/moon-ui:2.8.156425d4f8b9c
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.56.0
1.26.6
1
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/net@v0.11.0
0.56.0
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
golang.org/x/net@v0.20.0
0.56.0
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
golang.org/x/net@v0.38.0
stdlib@go1.26.4
0.56.0
1.26.6
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.