StackRadar

CVE-2026-46600

Unscored

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,634
of 17,813 indexed, latest versions
Container images
4,391
deployed by those charts
Fix available
2 of 2
affected packages

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Carried by container images the latest versions of 3,634 of 17,813 indexed charts deploy, on 4,391 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+221 more0.56.03,989
stdlibgolanggo1.26.0, go1.26.1, go1.26.2, go1.26.2-X:boringcrypto+7 more1.26.6867
OSV records
GO-2026-5942
Also known as
BIT-golang-2026-46600

Charts affected

3,634 by stars
ChartLatestAffected imagesRadar Score
argo-cdwenerme10.9.22 of 3See more

argo-cd wenerme 10.9.2

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
golang.org/x/net@v0.50.0
stdlib@go1.26.0
0.56.0
1.26.6
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

3,043
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0.56.0

Open the chart page →

6,088
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.56.0
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.56.0
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.56.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.56.0

Open the chart page →

10,051
buildkitdwiremindVerified publisher0.33.01 of 1See more

buildkitd wiremind 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

1,165
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.56.0

Open the chart page →

4,715
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.56.0

Open the chart page →

4,051
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/net@v0.26.0
0.56.0

Open the chart page →

829
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

1,875
no-latest-tag-webhookadmission-webhook-no-latest1.0.141 of 1See more

no-latest-tag-webhook admission-webhook-no-latest 1.0.14

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/omkar-shelke25/admission-webhook-no-latest:sha-33165455976a1d3236a
golang.org/x/net@v0.38.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

162
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
stdlib@go1.26.5
1.26.6

Open the chart page →

20,721
agentareaagentareaVerified publisher0.0.185 of 16See more

agentarea agentarea 0.0.18

5 of the 16 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-manager:latestefe23cef3727
golang.org/x/net@v0.55.0
0.56.0
openfga/openfga:v1.18.036097b960f66
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
0.56.0
temporalio/auto-setup:1.29.15b3502a3b685
golang.org/x/net@v0.35.0
0.56.0
temporalio/ui:2.39.0b768f87f18b5
golang.org/x/net@v0.40.0
0.56.0

Open the chart page →

14,566
traefikaigisukVerified publisher0.1.11 of 1See more

traefik aigisuk 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
library/traefik:2.7.0-rc2b70710baceeb
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0

Open the chart page →

2,884
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.261 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.26

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
stdlib@go1.26.3
1.26.6

Open the chart page →

2,458
alertmanager-matrixalertmanager-matrixVerified publisher0.1.161 of 1See more

alertmanager-matrix alertmanager-matrix 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
silkeh/alertmanager_matrix:0.6.1900010497f8c
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

471
clearml-servingallegroaiVerified publisher1.6.23 of 9See more

clearml-serving allegroai 1.6.2

3 of the 9 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/net@v0.4.0
0.56.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
0.56.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
0.56.0

Open the chart page →

18,003
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0

Open the chart page →

3,121
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.56.0

Open the chart page →

2,174
cloudflare-operatorankra-chartsVerified publisher0.2.01 of 1See more

cloudflare-operator ankra-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
adyanth/cloudflare-operatordigest-pinned6b168dc237d5
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

507
upcloud-csiankra-chartsVerified publisher0.4.08 of 8See more

upcloud-csi ankra-charts 0.4.0

8 of the 8 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
golang.org/x/net@v0.43.0
0.56.0
ghcr.io/upcloudltd/upcloud-csidigest-pinned5af91c663788
golang.org/x/net@v0.48.0
0.56.0
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.56.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.56.0
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.56.0

Open the chart page →

15,008
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.56.0

Open the chart page →

1,150
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
0.56.0

Open the chart page →

3,437
anteonanteonVerified publisher2.6.44 of 13See more

anteon anteon 2.6.4

4 of the 13 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/net@v0.21.0
0.56.0
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
0.56.0
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.56.0
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
0.56.0

Open the chart page →

22,658
api-usage-serverapi-usage-server1.16.01 of 1See more

api-usage-server api-usage-server 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

740
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

1,096
kubedb-opscenterappscodeVerified publisher2026.7.101 of 1See more

kubedb-opscenter appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-ui-server:v0.42.0e93dfe7454d4
golang.org/x/net@v0.55.0
0.56.0

Open the chart page →

263
kubedb-provisionerappscodeVerified publisher0.66.01 of 1See more

kubedb-provisioner appscode 0.66.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
golang.org/x/net@v0.55.0
0.56.0

Open the chart page →

660
scannerappscodeVerified publisher2026.1.153 of 3See more

scanner appscode 2026.1.15

3 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
0.56.0
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
golang.org/x/net@v0.47.0
0.56.0
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/net@v0.26.0
0.56.0

Open the chart page →

5,343
smtprelayappscodeVerified publisher2026.9.111 of 1See more

smtprelay appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/net@v0.34.0
0.56.0

Open the chart page →

872
stash-enterpriseappscodeVerified publisher0.42.04 of 4See more

stash-enterprise appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
0.56.0
ghcr.io/stashed/stash-crd-installer:v0.42.1d6c9b7a1f7b8
golang.org/x/net@v0.38.0
0.56.0
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

3,637
virtual-secrets-serverappscodeVerified publisher2026.8.141 of 1See more

virtual-secrets-server appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/appscode/virtual-secrets-server:v0.4.0efa03f4c9551
golang.org/x/net@v0.55.0
0.56.0

Open the chart page →

295
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0

Open the chart page →

5,283
argocd-rbac-operatorargocd-rbac-operator0.4.51 of 1See more

argocd-rbac-operator argocd-rbac-operator 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-rbac-operator:v0.2.451dded00137a
golang.org/x/net@v0.40.0
0.56.0

Open the chart page →

985
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
golang.org/x/net@v0.30.0
0.56.0
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
golang.org/x/net@v0.30.0
0.56.0

Open the chart page →

2,529
s3dartur9010Verified publisher1.0.11 of 1See more

s3d artur9010 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.56.0
1.26.6

Open the chart page →

1,768
arvancloud-webhookarvancloud-webhookVerified publisher1.0.01 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

2,368
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.56.0

Open the chart page →

2,820
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.56.0

Open the chart page →

10,798
dltbrokerassist-iot-distributed-broker0.2.05 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.56.0
hyperledger/fabric-ca:latesta70b6ba64a08
stdlib@go1.26.4
1.26.6
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0

Open the chart page →

194,560
dltloggingassist-iot-logging-auditing0.2.05 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0
hyperledger/fabric-ca:latesta70b6ba64a08
stdlib@go1.26.4
1.26.6
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0

Open the chart page →

194,540
astradnsastradnsVerified publisher0.2.92 of 2See more

astradns astradns 0.2.9

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.56.0
1.26.6
ghcr.io/astradns/astradns-operator:v0.2.909e58b62416a
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.56.0
1.26.6

Open the chart page →

2,699
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
0.56.0

Open the chart page →

4,326
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.56.0

Open the chart page →

3,399
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.56.0

Open the chart page →

3,750
kubebrowseravistoOfficialVerified publisher1.4.01 of 1See more

kubebrowser avisto 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/kubebrowser:0.10.0a354b8dc7e6a
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

678
vault-unsealbabykart-helm-chartsVerified publisher1.0.51 of 1See more

vault-unseal babykart-helm-charts 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/lrstanley/vault-unseal:1.0.1dd873930b6df
stdlib@go1.26.5
1.26.6

Open the chart page →

205
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
0.56.0

Open the chart page →

4,822
music-assistantbdclark-helm-chartsVerified publisher0.4.131 of 1See more

music-assistant bdclark-helm-charts 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.3885872224fa5
golang.org/x/net@v0.48.0
0.56.0

Open the chart page →

3,748
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.56.0
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.56.0
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.56.0

Open the chart page →

7,824
livekit-serverbeeinventor1.0.01 of 2See more

livekit-server beeinventor 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.56.0

Open the chart page →

2,610
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.56.0

Open the chart page →

1,596

Container images carrying it

4,391 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.56.0
1
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
golang.org/x/net@v0.29.0
0.56.0
1
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.56.0
1
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0
1
quay.io/ohiosupercomputercenter/job-pod-reaper:v0.14.0775449888968
stdlib@go1.26.4
1.26.6
1
quay.io/ohiosupercomputercenter/k8-ldap-configmap:v0.16.040d0b67afd77
stdlib@go1.26.4
1.26.6
1
quay.io/ohiosupercomputercenter/k8-namespace-reaper:v0.11.0ead1f817e8c2
stdlib@go1.26.4
1.26.6
1
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
0.56.0
1
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
golang.org/x/net@v0.23.0
0.56.0
1
quay.io/open-cluster-management/dynamic-scoring-addon:latest7e571a08ec1a
golang.org/x/net@v0.47.0
0.56.0
1
quay.io/open-cluster-management/dynamic-scoring-controller:latest587f5bc8f2ed
golang.org/x/net@v0.47.0
0.56.0
1
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
golang.org/x/net@v0.38.0
0.56.0
1
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
golang.org/x/net@v0.52.0
stdlib@go1.26.4
0.56.0
1.26.6
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.56.0
1
quay.io/openshift/origin-cli:4.66722d5041b47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.56.0
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.56.0
1
quay.io/openshift/origin-csi-external-attacher:latest4f9b3d0f2c7f
stdlib@go1.26.5
1.26.6
1
quay.io/openshift/origin-csi-external-provisioner:lateste4074ec254f5
stdlib@go1.26.5
1.26.6
1
quay.io/openshift/origin-csi-node-driver-registrar:latestea08b5e5f4ab
stdlib@go1.26.5
1.26.6
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
golang.org/x/net@v0.20.0
0.56.0
1
quay.io/operator-framework/catalogd:v1.8.06ff40fa6257f
golang.org/x/net@v0.50.0
0.56.0
1
quay.io/operator-framework/olm1b6002156f56
golang.org/x/net@v0.20.0
0.56.0
1
quay.io/operator-framework/olm40d0363f4aa6
golang.org/x/net@v0.25.0
0.56.0
1
quay.io/operator-framework/olm:v0.45.0f228c7a6b8c5
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6
1
quay.io/operator-framework/olmf9ea8cef95ac
golang.org/x/net@v0.7.0
0.56.0
1
quay.io/operator-framework/operator-controller:v1.8.0bca5dfcc67ca
golang.org/x/net@v0.50.0
0.56.0
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
golang.org/x/net@v0.7.0
0.56.0
1
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
0.56.0
1
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
golang.org/x/net@v0.38.0
0.56.0
1
quay.io/opsmxpublic/opa:1.12.084fb1af7401c
golang.org/x/net@v0.47.0
0.56.0
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.56.0
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.56.0
1.26.6
1
quay.io/opstree/kube-state-metrics:2.18.0-debian1353525d253793
golang.org/x/net@v0.53.0
0.56.0
1
quay.io/opstree/logging-operator:v0.4.0fd8bb57ef3cf
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.56.0
1
quay.io/opstree/loki:3.6-debian13bdfee214c7ea
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.56.0
1.26.6
1
quay.io/opstree/memcached-exporter:0.15.5-debian13cf8f8410eaad
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.56.0
1.26.6
1
quay.io/opstree/mongodb-operator:v0.3.0879b9bead838
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.56.0
1
quay.io/opstree/node-exporter:1.11.1-alpine3.233b6b3a7eb001
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.56.0
1.26.6
1
quay.io/opstree/opentelemetry-operator:0.149.0-debian13a21405ab9a9a
golang.org/x/net@v0.53.0
0.56.0
1
quay.io/opstree/redis-operator:v0.26.01c6818e5e505
golang.org/x/net@v0.55.0
0.56.0
1
quay.io/opstree/tempo:2.10.4-debian13cb734024b3fd
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.56.0
1.26.6
1
quay.io/opstree/victoriametrics-operator:v0.69.066fe5216c278
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.56.0
1.26.6
1
quay.io/orc/openstack-resource-controller:v2.5.079f22af49612
golang.org/x/net@v0.52.0
0.56.0
1
quay.io/piraeusdatastore/nri-volume-qos:v0.1.3cbe3e1ea2b6a
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.56.0
1.26.6
1
quay.io/piraeusdatastore/piraeus-operator:v2.10.5dd68a66332de
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.56.0
1.26.6
1
quay.io/piraeusdatastore/piraeus-operator:v2.2.0ec4022c8b0e3
golang.org/x/net@v0.8.0
0.56.0
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
stdlib@go1.26.5
1.26.6
1
quay.io/projectquay/clair:4.9.023329c3368e4
golang.org/x/net@v0.47.0
0.56.0
1
quay.io/projectquay/clair:4.7.28d38ffa8fad7
golang.org/x/net@v0.14.0
0.56.0
1
quay.io/prometheus/alertmanager:v0.24.0088464f949de
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.56.0
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.