StackRadar

CVE-2026-46600

Unscored

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,666
of 17,832 indexed, latest versions
Container images
4,417
deployed by those charts
Fix available
2 of 2
affected packages

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Carried by container images the latest versions of 3,666 of 17,832 indexed charts deploy, on 4,417 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+224 more0.56.04,039
stdlibgolanggo1.26.0, go1.26.1, go1.26.2, go1.26.2-X:boringcrypto+8 more1.26.6840
OSV records
GO-2026-5942
Also known as
BIT-golang-2026-46600

Charts affected

3,666 by stars
ChartLatestAffected imagesRadar Score
kube-prometheuschoerodon9.3.14 of 7See more

kube-prometheus choerodon 9.3.1

4 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.56.0
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
0.56.0
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
0.56.0
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.56.0

Open the chart page →

12,257
timescaledbcloudpirates-timescaledbVerified publisher0.13.111 of 1See more

timescaledb cloudpirates-timescaledb 0.13.11

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
timescale/timescaledb:2.30.1-pg17c79fa5891443
stdlib@go1.26.2
1.26.6

Open the chart page →

623
csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher1.8.24 of 5See more

csi-secrets-store-provider-azure csi-secrets-store-provider-azure 1.8.2

4 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.14.06cb172e3de7e
golang.org/x/net@v0.40.0
stdlib@go1.26.5
0.56.0
1.26.6
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
golang.org/x/net@v0.39.0
0.56.0
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
golang.org/x/net@v0.47.0
stdlib@go1.26.3
0.56.0
1.26.6
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver-crds:v1.5.6cb0112636dc4
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

2,232
paperless-ngxfmjstudios0.2.81 of 5See more

paperless-ngx fmjstudios 0.2.8

1 of the 5 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
golang.org/x/net@v0.19.0
0.56.0

Open the chart page →

31,518
minifluxgabe565Verified publisher0.9.21 of 2See more

miniflux gabe565 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/net@v0.34.0
0.56.0

Open the chart page →

1,394
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.24.061d866e93b56
golang.org/x/net@v0.10.0
0.56.0

Open the chart page →

3,103
waypointhashicorpVerified publisher0.1.211 of 2See more

waypoint hashicorp 0.1.21

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
hashicorp/waypoint:0.11.397d521a27498
golang.org/x/net@v0.1.0
0.56.0

Open the chart page →

4,177
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.56.0

Open the chart page →

8,054
jaeger-all-in-onejaeger-all-in-oneVerified publisher0.1.121 of 1See more

jaeger-all-in-one jaeger-all-in-one 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.55f6b5d09073f1
golang.org/x/net@v0.21.0
0.56.0

Open the chart page →

1,231
cassandrakubelauncherVerified publisher0.1.271 of 1See more

cassandra kubelauncher 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinnedb66aba320083
stdlib@go1.26.5
1.26.6

Open the chart page →

1,620
etcdkubelauncherVerified publisher0.4.31 of 1See more

etcd kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinned8ab954711fb9
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

885
kafkakubelauncherVerified publisher0.1.261 of 1See more

kafka kubelauncher 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned43e1085cd0a8
stdlib@go1.26.5
1.26.6

Open the chart page →

1,504
keycloakkubelauncherVerified publisher0.4.41 of 1See more

keycloak kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinnedafe3bd73d7cf
stdlib@go1.26.5
1.26.6

Open the chart page →

1,426
kubectlkubelauncherVerified publisher0.2.111 of 1See more

kubectl kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned7280594a2f18
golang.org/x/net@v0.49.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

1,334
mariadbkubelauncherVerified publisher0.5.71 of 1See more

mariadb kubelauncher 0.5.7

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mariadbdigest-pinnede25056a6ec52
stdlib@go1.26.5
1.26.6

Open the chart page →

1,180
mongodbkubelauncherVerified publisher0.4.51 of 1See more

mongodb kubelauncher 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinned9bc37ed78a8b
golang.org/x/net@v0.47.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

1,446
rediskubelauncherVerified publisher0.5.11 of 1See more

redis kubelauncher 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedbcd8e9a6224f
stdlib@go1.26.5
1.26.6

Open the chart page →

874
zookeeperkubelauncherVerified publisher0.2.111 of 1See more

zookeeper kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/zookeeperdigest-pinned7826e9caa461
stdlib@go1.26.5
1.26.6

Open the chart page →

1,133
mauticone-acre-fundVerified publisher0.1.71 of 3See more

mautic one-acre-fund 0.1.7

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

3,088
openclawopenclawVerified publisher1.93.01 of 2See more

openclaw openclaw 1.93.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.93.006a950310ecd
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.56.0
1.26.6

Open the chart page →

3,149
opentelemetry-kube-stackopentelemetry-helmOfficialVerified publisher0.23.01 of 2See more

opentelemetry-kube-stack opentelemetry-helm 0.23.0

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

423
prometheus-stackdriver-exporterprometheus-communityVerified publisher5.2.01 of 1See more

prometheus-stackdriver-exporter prometheus-community 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
prometheuscommunity/stackdriver-exporter:v0.19.0c0a0cbf76570
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.56.0
1.26.6

Open the chart page →

355
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.56.0

Open the chart page →

4,426
dex-k8s-authenticatorsagikazarmarkVerified publisher0.0.31 of 1See more

dex-k8s-authenticator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
0.56.0

Open the chart page →

2,793
thanosstevehipwellVerified publisher1.24.11 of 1See more

thanos stevehipwell 1.24.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
stdlib@go1.26.5
1.26.6

Open the chart page →

212
caddyalekcVerified publisher0.9.01 of 1See more

caddy alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
library/caddy:2.11.4-alpinede23def33b17
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

228
openstack-cinder-csicloud-provider-openstack2.36.57 of 7See more

openstack-cinder-csi cloud-provider-openstack 2.36.5

7 of the 7 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/cinder-csi-plugin:v1.36.078adaeb154c7
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.56.0
1.26.6
registry.k8s.io/sig-storage/csi-attacher:v4.10.0be59d0556508
golang.org/x/net@v0.40.0
0.56.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
0.56.0
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
0.56.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/net@v0.39.0
0.56.0
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
golang.org/x/net@v0.40.0
0.56.0

Open the chart page →

3,667
kubeviewcowboysysopVerified publisher6.0.01 of 1See more

kubeview cowboysysop 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.56.0

Open the chart page →

1,514
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

36,045
devtron-operatordevtron0.23.38 of 11See more

devtron-operator devtron 0.23.3

8 of the 11 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.56.0
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.56.0
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/net@v0.48.0
0.56.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.56.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0

Open the chart page →

33,562
drone-runner-kubedroneVerified publisher0.1.101 of 1See more

drone-runner-kube drone 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0

Open the chart page →

2,069
fluent-operatorfluent4.3.01 of 1See more

fluent-operator fluent 4.3.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluent-operator/fluent-operator:3.10.03108194a4ecc
stdlib@go1.26.3
1.26.6

Open the chart page →

150
hcloud-csihcloud2.23.05 of 6See more

hcloud-csi hcloud 2.23.0

5 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
golang.org/x/net@v0.47.0
0.56.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
0.56.0
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
golang.org/x/net@v0.51.0
0.56.0
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
0.56.0
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
0.56.0

Open the chart page →

2,689
envoy-gatewayhelmforgeVerified publisher2.1.01 of 3See more

envoy-gateway helmforge 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
helmforge/kubectl:1.35.3c3f97e954c47
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

2,473
ilumilumOfficialVerified publisher6.7.36 of 19See more

ilum ilum 6.7.3

6 of the 19 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
0.56.0
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
golang.org/x/net@v0.37.0
0.56.0
bitnamisecure/gitdigest-pinned72ae5bd9715f
golang.org/x/net@v0.38.0
0.56.0
gitea/gitea:1.22.376f516a1a8c2
golang.org/x/net@v0.28.0
0.56.0
ilum/api:6.7.3624fd09528c8
golang.org/x/net@v0.37.0
0.56.0
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
0.56.0

Open the chart page →

22,831
syncthingk8s-home-lab-repo5.2.01 of 1See more

syncthing k8s-home-lab-repo 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
syncthing/syncthing:2.1.1775c4aac4862
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.56.0
1.26.6

Open the chart page →

1,226
kube-greenkube-green-officialOfficialVerified publisher0.7.11 of 1See more

kube-green kube-green-official 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
kubegreen/kube-green:0.7.12dc0f0a6034c
golang.org/x/net@v0.38.0
0.56.0

Open the chart page →

507
temporallemontechVerified publisher0.37.05 of 13See more

temporal lemontech 0.37.0

5 of the 13 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.56.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.56.0
temporalio/server:1.22.4c0a44c26397b
golang.org/x/net@v0.7.0
0.56.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.56.0
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.56.0

Open the chart page →

14,933
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
golang.org/x/net@v0.40.0
0.56.0
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
0.56.0

Open the chart page →

7,502
netris-controllernetrisai2.8.23 of 14See more

netris-controller netrisai 2.8.2

3 of the 14 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.56.0
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
golang.org/x/net@v0.11.0
0.56.0
netrisai/controller-grpc:4.6.0.00753178bf173c2
golang.org/x/net@v0.23.0
0.56.0

Open the chart page →

30,724
nfs-server-provisionernfs-ganesha-server-and-external-provisioner1.8.01 of 1See more

nfs-server-provisioner nfs-ganesha-server-and-external-provisioner 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.56.0

Open the chart page →

2,316
nuclionuclio0.23.81 of 2See more

nuclio nuclio 0.23.8

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/nuclio/dashboard:1.17.8-amd64b5f5bd4efbee
golang.org/x/net@v0.53.0
stdlib@go1.26.1
0.56.0
1.26.6

Open the chart page →

982
syftopenmined0.9.52 of 6See more

syft openmined 0.9.5

2 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
library/traefik:v2.11.00a5157f742d2
golang.org/x/net@v0.20.0
0.56.0
openmined/syft-seaweedfs:0.9.53a4144c0bb82
golang.org/x/net@v0.21.0
0.56.0

Open the chart page →

17,543
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0
platform9community/api-gateway:latest40a4970de568
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0
platform9community/customers-service:latest2089811e5cc6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.56.0

Open the chart page →

42,150
pyrrarlex0.15.01 of 1See more

pyrra rlex 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
ghcr.io/pyrra-dev/pyrra:v0.8.10e02ef538ef0
golang.org/x/net@v0.31.0
0.56.0

Open the chart page →

954
k8s-infrasignoz0.17.11 of 1See more

k8s-infra signoz 0.17.1

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.139.0faf125d656fa
golang.org/x/net@v0.46.0
0.56.0

Open the chart page →

1,188
helm-exportersstarcher0.5.01 of 1See more

helm-exporter sstarcher 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
sstarcher/helm-exporter:0.5.011769d01ba35
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
0.56.0

Open the chart page →

4,164
tailing-sidecar-operatortailing-sidecar-operatorOfficialVerified publisher0.111.02 of 2See more

tailing-sidecar-operator tailing-sidecar-operator 0.111.0

2 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
public.ecr.aws/sumologic/tailing-sidecar-operator:0.111.0920b8f901aef
golang.org/x/net@v0.38.0
0.56.0
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
0.56.0

Open the chart page →

1,220
gatustwin1.5.01 of 1See more

gatus twin 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
twinproduction/gatus:v5.34.03fff895e77d3
golang.org/x/net@v0.47.0
0.56.0

Open the chart page →

728
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-46600.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.11.0a056739b095d
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.56.0
1.26.6

Open the chart page →

2,407

Container images carrying it

4,417 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/net@v0.28.0
0.56.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/net@v0.33.0
0.56.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.56.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.56.0
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.56.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
golang.org/x/net@v0.4.0
0.56.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
golang.org/x/net@v0.13.0
0.56.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/net@v0.37.0
0.56.0
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
stdlib@go1.26.4
1.26.6
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
golang.org/x/net@v0.37.0
0.56.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.56.0
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
golang.org/x/net@v0.40.0
0.56.0
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
golang.org/x/net@v0.33.0
0.56.0
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.56.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/net@v0.4.0
0.56.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/net@v0.17.0
0.56.0
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.56.0
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.