StackRadar

CVE-2026-46600

Unscored

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,568
of 17,805 indexed, latest versions
Container images
4,317
deployed by those charts
Fix available
2 of 2
affected packages

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Carried by container images the latest versions of 3,568 of 17,805 indexed charts deploy, on 4,317 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+221 more0.56.03,917
stdlibgolanggo1.26.0, go1.26.1, go1.26.2, go1.26.2-X:boringcrypto+7 more1.26.6853
OSV records
GO-2026-5942
Also known as
BIT-golang-2026-46600

Charts affected

3,568 by stars
ChartLatestAffected imagesRadar Score
cadvisorckotzbauerVerified publisher2.4.31 of 1See more

cadvisor ckotzbauer 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.52.1f40e65878e25
golang.org/x/net@v0.33.0
0.56.0

Open the chart page →

968
m365-exportercloudeteer-helm-chartsVerified publisher1.7.11 of 1See more

m365-exporter cloudeteer-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/cloudeteer/m365-exporter:3.9.3a13a11fe9558
stdlib@go1.26.5
1.26.6

Open the chart page →

84
codercoderOfficialVerified publisher1.44.61 of 2See more

coder coder 1.44.6

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/net@v0.24.0
0.56.0

Open the chart page →

7,187
dronecommunity-chartsVerified publisher0.1.52 of 2See more

drone community-charts 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
drone/drone:2.28.255897c8fb22d
golang.org/x/net@v0.42.0
0.56.0
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0

Open the chart page →

2,737
cloudflare-operatorcontainerooVerified publisher1.10.71 of 1See more

cloudflare-operator containeroo 1.10.7

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/containeroo/cloudflare-operator:v1.10.60eda6d237a84
stdlib@go1.26.0
1.26.6

Open the chart page →

222
convoyconvoyVerified publisher3.7.131 of 3See more

convoy convoy 3.7.13

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
getconvoy/convoy:v26.7.6f4934cc05e31
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.56.0
1.26.6

Open the chart page →

6,128
cortexcortex3.3.81 of 4See more

cortex cortex 3.3.8

1 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/cortexproject/cortex:v1.21.18577eb292a01
golang.org/x/net@v0.49.0
0.56.0

Open the chart page →

4,014
doris-operatordorisVerified publisher25.8.01 of 1See more

doris-operator doris 25.8.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
apache/doris:operator-latest3a4422656592
golang.org/x/net@v0.33.0
0.56.0

Open the chart page →

438
uptime-kumaduyet0.1.81 of 1See more

uptime-kuma duyet 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.56.0

Open the chart page →

4,565
emqx-operatoremqx-operator2.3.22 of 2See more

emqx-operator emqx-operator 2.3.2

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alpine/k8s:1.31.49c4976d47656
golang.org/x/net@v0.31.0
0.56.0
ghcr.io/emqx/emqx-operator:2.3.23333ed546165
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

4,706
kube-routerenixVerified publisher1.10.01 of 1See more

kube-router enix 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
golang.org/x/net@v0.4.0
0.56.0

Open the chart page →

2,352
gethethereum-helm-chartsVerified publisher1.1.41 of 2See more

geth ethereum-helm-charts 1.1.4

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ethereum/client-go:stableb8ab3451a117
golang.org/x/net@v0.50.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

633
gotifygotifyVerified publisher0.8.11 of 1See more

gotify gotify 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gotify/server:2.9.1a3af47067ce6
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.56.0
1.26.6

Open the chart page →

568
korkorVerified publisher0.2.161 of 1See more

kor kor 0.2.16

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
yonahdissen/kor:latest1a85158c82bb
stdlib@go1.26.0
1.26.6

Open the chart page →

222
kubelet-csr-approverkubelet-csr-approverOfficialVerified publisher1.2.151 of 1See more

kubelet-csr-approver kubelet-csr-approver 1.2.15

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/postfinance/kubelet-csr-approver:v1.2.156469ef517d2b
golang.org/x/net@v0.49.0
0.56.0

Open the chart page →

64
logging-operatorkube-loggingVerified publisher4.2.31 of 1See more

logging-operator kube-logging 4.2.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/logging-operator:4.2.20dd85dcb1f73
golang.org/x/net@v0.10.0
0.56.0

Open the chart page →

880
myipkuossOfficialVerified publisher0.2.21 of 1See more

myip kuoss 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kuoss/myip:v0.1.7760f5ccae493
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

660
keptnlifecycle-toolkitOfficialVerified publisher0.11.03 of 3See more

keptn lifecycle-toolkit 0.11.0

3 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
golang.org/x/net@v0.30.0
0.56.0
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
golang.org/x/net@v0.30.0
0.56.0
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
golang.org/x/net@v0.37.0
0.56.0

Open the chart page →

1,956
mattermost-operatormattermostVerified publisher1.0.51 of 1See more

mattermost-operator mattermost 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
mattermost/mattermost-operator:v1.25.4bac00a2bbd33
golang.org/x/net@v0.41.0
0.56.0

Open the chart page →

273
meshery-operatormesheryOfficialVerified publisher1.0.702 of 2See more

meshery-operator meshery 1.0.70

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alpine/k8s:1.35.6b7a12c5ddf26
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
meshery/meshery-operator:1.0.50d245bc8b5c6
stdlib@go1.26.4
1.26.6

Open the chart page →

2,461
missing-container-metricsmissing-container-metrics0.1.11 of 1See more

missing-container-metrics missing-container-metrics 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0

Open the chart page →

2,418
tailscale-relaymvisonneau0.2.71 of 1See more

tailscale-relay mvisonneau 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
mvisonneau/tailscale:v1.68.1fc45ad8abf10
golang.org/x/net@v0.24.0
0.56.0

Open the chart page →

1,357
system-upgrade-controllernimbolus0.7.01 of 1See more

system-upgrade-controller nimbolus 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
rancher/system-upgrade-controller:v0.18.09813f85653c8
golang.org/x/net@v0.44.0
0.56.0

Open the chart page →

318
olmolmVerified publisher0.45.01 of 1See more

olm olm 0.45.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/operator-framework/olm:v0.45.0f228c7a6b8c5
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

448
ketoory0.64.01 of 1See more

keto ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
oryd/keto:v26.2.0bfdb8b9e283a
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.56.0
1.26.6

Open the chart page →

978
oathkeeperory0.64.01 of 1See more

oathkeeper ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
oryd/oathkeeper:v26.2.0467329abde34
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.56.0
1.26.6

Open the chart page →

930
pmmpercona1.9.11 of 1See more

pmm percona 1.9.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
percona/pmm-server:3.9.1003f9c25f842
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

823
redis-enterprise-operatorredis-enterprise-operator-officialOfficialVerified publisher8.0.18-111 of 1See more

redis-enterprise-operator redis-enterprise-operator-official 8.0.18-11

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
redislabs/operator:8.0.18-119078e713bb6a
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.56.0
1.26.6

Open the chart page →

944
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
golang.org/x/net@v0.48.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

1,389
rekorsigstoreVerified publisher1.8.65 of 9See more

rekor sigstore 1.8.6

5 of the 9 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/sigstore/rekor/rekor-server:v1.5.4100d793d68d0
stdlib@go1.26.4
1.26.6
ghcr.io/sigstore/scaffolding/createdbdigest-pinned3cee6c78973b
golang.org/x/net@v0.46.0
0.56.0
ghcr.io/sigstore/scaffolding/createtreedigest-pinnede5232e8c9122
golang.org/x/net@v0.46.0
0.56.0
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
stdlib@go1.26.0
1.26.6
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
stdlib@go1.26.0
1.26.6

Open the chart page →

5,526
mssqlserver-2022simcube1.2.31 of 1See more

mssqlserver-2022 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
stdlib@go1.26.1
1.26.6

Open the chart page →

2,975
snyk-monitorsnyk2.23.261 of 2See more

snyk-monitor snyk 2.23.26

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
snyk/kubernetes-monitor:2.23.26fb5ad76ce84e
golang.org/x/net@v0.54.0
0.56.0

Open the chart page →

584
swo-k8s-collectorsolarwindsOfficialVerified publisher5.3.03 of 3See more

swo-k8s-collector solarwinds 5.3.0

3 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
golang.org/x/net@v0.55.0
stdlib@go1.26.4-X:boringcrypto
0.56.0
1.26.6
ghcr.io/open-telemetry/opentelemetry-ebpf-instrumentation/ebpf-instrument:v0.9.026f82b148dfe
golang.org/x/net@v0.53.0
0.56.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.56.0
1.26.6

Open the chart page →

2,439
sops-operatorsops-operatorVerified publisher0.10.12 of 2See more

sops-operator sops-operator 0.10.1

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
0.56.0
ghcr.io/peak-scale/sops-operator:0.10.11da9b716b792
stdlib@go1.26.4
1.26.6

Open the chart page →

1,260
thehivestrangebee-helmOfficialVerified publisher1.0.74 of 7See more

thehive strangebee-helm 1.0.7

4 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
golang.org/x/net@v0.42.0
0.56.0
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
0.56.0
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
golang.org/x/net@v0.42.0
0.56.0
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

16,436
truenas-csptruenas-cspVerified publisher1.2.410 of 11See more

truenas-csp truenas-csp 1.2.4

10 of the 11 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/hpestorage/csi-driver:v3.2.0ef7f4e1544fa
golang.org/x/net@v0.48.0
0.56.0
quay.io/hpestorage/csi-extensions:v1.2.1189146672a7ac
golang.org/x/net@v0.48.0
stdlib@go1.26.3
0.56.0
1.26.6
quay.io/hpestorage/volume-group-provisioner:v1.0.107bf9d8f16a5d
golang.org/x/net@v0.48.0
stdlib@go1.26.3
0.56.0
1.26.6
quay.io/hpestorage/volume-group-snapshotter:v1.0.10caeaaffe7e2b
golang.org/x/net@v0.48.0
stdlib@go1.26.3
0.56.0
1.26.6
quay.io/hpestorage/volume-mutator:v1.3.109e98b2e697bd
golang.org/x/net@v0.48.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
golang.org/x/net@v0.51.0
0.56.0
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
0.56.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
golang.org/x/net@v0.49.0
0.56.0

Open the chart page →

6,027
uffizzi-controlleruffizzi-controller2.4.68 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

8 of the 11 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
0.56.0
uffizzi/uffizzi-cluster-operator:v1.6.55ca448a08783
golang.org/x/net@v0.8.0
0.56.0
quay.io/jetstack/cert-manager-cainjector:v1.14.54ffda7facb4d
golang.org/x/net@v0.24.0
0.56.0
quay.io/jetstack/cert-manager-controller:v1.14.59c0527cab629
golang.org/x/net@v0.24.0
0.56.0
quay.io/jetstack/cert-manager-startupapicheck:v1.14.50f5b104bdd1b
golang.org/x/net@v0.24.0
0.56.0
quay.io/jetstack/cert-manager-webhook:v1.14.5ef419261a209
golang.org/x/net@v0.24.0
0.56.0
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
golang.org/x/net@v0.22.0
0.56.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
0.56.0

Open the chart page →

14,356
filebrowserutkuozdemirVerified publisher1.0.01 of 1See more

filebrowser utkuozdemir 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.56.0

Open the chart page →

3,075
vsphere-csivsphere-tmm3.8.17 of 7See more

vsphere-csi vsphere-tmm 3.8.1

7 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
golang.org/x/net@v0.38.0
0.56.0
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
golang.org/x/net@v0.38.0
0.56.0
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
0.56.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
0.56.0
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
0.56.0
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
0.56.0

Open the chart page →

3,960
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.56.0

Open the chart page →

6,181
aad-pod-identityaad-pod-identity4.1.182 of 2See more

aad-pod-identity aad-pod-identity 4.1.18

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/azure/aad-pod-identity/mic:v1.8.173004b93fcb74
golang.org/x/net@v0.7.0
0.56.0
mcr.microsoft.com/oss/azure/aad-pod-identity/nmi:v1.8.1777788bf38938
golang.org/x/net@v0.7.0
0.56.0

Open the chart page →

2,860
abcdesktopabcdesktopOfficialVerified publisher4.4.121 of 9See more

abcdesktop abcdesktop 4.4.12

1 of the 9 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/abcdesktopio/keysgenerator:4.4ca0662bc92a4
golang.org/x/net@v0.49.0
0.56.0

Open the chart page →

827
agonesagones1.60.01 of 5See more

agones agones 1.60.0

1 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.49ccd82364762
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

1,116
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
stdlib@go1.26.5
1.26.6

Open the chart page →

37,025
kubedbappscodeVerified publisher2026.7.108 of 8See more

kubedb appscode 2026.7.10

8 of the 8 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
0.56.0
ghcr.io/appscode/petset:v0.1.093fa0daf603c
golang.org/x/net@v0.47.0
0.56.0
ghcr.io/appscode/sidekick:v0.0.15d1036b07e348
golang.org/x/net@v0.47.0
0.56.0
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
golang.org/x/net@v0.55.0
0.56.0
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
golang.org/x/net@v0.55.0
0.56.0
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
golang.org/x/net@v0.55.0
0.56.0
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
golang.org/x/net@v0.55.0
0.56.0
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
golang.org/x/net@v0.55.0
0.56.0

Open the chart page →

4,489
cloudflaredartur9010Verified publisher1.0.93 of 3See more

cloudflared artur9010 1.0.9

3 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
0.56.0
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.56.0
1.26.6
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.56.0
1.26.6

Open the chart page →

3,018
baserowbaserow-chartVerified publisher1.0.562 of 6See more

baserow baserow-chart 1.0.56

2 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
golang.org/x/net@v0.26.0
0.56.0
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
0.56.0

Open the chart page →

17,713
mysql-operatorbitpokeVerified publisher0.6.32 of 2See more

mysql-operator bitpoke 0.6.3

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
0.56.0
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

3,356
celestia-appcelestia-labsVerified publisher0.5.01 of 3See more

celestia-app celestia-labs 0.5.0

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
golang.org/x/net@v0.34.0
0.56.0

Open the chart page →

1,076
cert-manager-webhook-hetznercert-manager-webhook-hetznerVerified publisher0.2.11 of 1See more

cert-manager-webhook-hetzner cert-manager-webhook-hetzner 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.56.0

Open the chart page →

3,087

Container images carrying it

4,317 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
golang.org/x/net@v0.49.0
0.56.0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
golang.org/x/net@v0.49.0
0.56.0
1
registry.gitlab.com/xrow-public/ci-tools/kubectl:main9357cfeef63c
golang.org/x/net@v0.38.0
0.56.0
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
golang.org/x/net@v0.48.0
stdlib@go1.26.5
0.56.0
1.26.6
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
golang.org/x/net@v0.41.0
0.56.0
1
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.56.0
1.26.6
1
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.4be477ba317d8
stdlib@go1.26.5
1.26.6
1
registry.k8s.io/agent-sandbox/sandbox-router-go:v1.0.125b1a0939630
stdlib@go1.26.2
1.26.6
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
golang.org/x/net@v0.38.0
0.56.0
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
golang.org/x/net@v0.38.0
0.56.0
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.4.171d817780aa9
golang.org/x/net@v0.39.0
0.56.0
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.6.080e487edff02
golang.org/x/net@v0.50.0
0.56.0
1
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
golang.org/x/net@v0.43.0
0.56.0
1
registry.k8s.io/autoscaling/vpa-recommender:1.4.140b6d76e8526
golang.org/x/net@v0.39.0
0.56.0
1
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
golang.org/x/net@v0.43.0
0.56.0
1
registry.k8s.io/autoscaling/vpa-updater:1.4.18ebf269779c1
golang.org/x/net@v0.39.0
0.56.0
1
registry.k8s.io/autoscaling/vpa-updater:1.6.0b39d1dfa19cb
golang.org/x/net@v0.50.0
0.56.0
1
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/net@v0.43.0
0.56.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
0.56.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/net@v0.32.0
0.56.0
1
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
golang.org/x/net@v0.47.0
0.56.0
1
registry.k8s.io/csi-secrets-store/driver-crds:v1.6.1cdacfdbe8966
stdlib@go1.26.5
1.26.6
1
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
golang.org/x/net@v0.38.0
0.56.0
1
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/net@v0.33.0
0.56.0
1
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/net@v0.33.0
0.56.0
1
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
golang.org/x/net@v0.38.0
0.56.0
1
registry.k8s.io/descheduler/descheduler:v0.36.07ca92c0a7b4f
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.56.0
1.26.6
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/net@v0.17.0
0.56.0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
golang.org/x/net@v0.46.0
0.56.0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
golang.org/x/net@v0.17.0
0.56.0
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.56.0
1
registry.k8s.io/etcd:3.6.4-0e36c08168342
golang.org/x/net@v0.38.0
0.56.0
1
registry.k8s.io/gateway-api/admission-server:v0.7.1fe43ee5176a8
golang.org/x/net@v0.7.0
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
golang.org/x/net@v0.5.0
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
golang.org/x/net@v0.43.0
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
golang.org/x/net@v0.43.0
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
golang.org/x/net@v0.21.0
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
golang.org/x/net@v0.10.0
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
golang.org/x/net@v0.8.0
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
golang.org/x/net@v0.29.0
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
golang.org/x/net@v0.22.0
0.56.0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/net@v0.33.0
0.56.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.2050a34002d5b
golang.org/x/net@v0.43.0
0.56.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.33d671cf20a35
golang.org/x/net@v0.44.0
0.56.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
golang.org/x/net@v0.21.0
0.56.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/net@v0.33.0
0.56.0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.