StackRadar

CVE-2026-78659

Unscored

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,521
of 18,087 indexed, latest versions
Container images
6,339
deployed by those charts
Fix available
2 of 3
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,521 of 18,087 indexed charts deploy, on 6,339 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,327
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,102
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-78659GO-2026-6603
Trending
Rank 3 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,521 by stars
ChartLatestAffected imagesRadar Score
vertical-pod-autoscalerstevehipwell-helm-charts-vertical-pod-autoscalerVerified publisher1.12.13 of 3See more

vertical-pod-autoscaler stevehipwell-helm-charts-vertical-pod-autoscaler 1.12.1

3 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

642
sn-platformstreamnative1.11.466 of 9See more

sn-platform streamnative 1.11.46

6 of the 9 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.26.9
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.60.0
1.26.9
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.11
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.60.0
1.26.9

Open the chart page →

77,633
stunnerstunner1.2.12 of 2See more

stunner stunner 1.2.1

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
l7mp/stunner-auth-server:1.2.10d2094060b72
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
l7mp/stunner-gateway-operator:1.2.10ea40a1d42d5
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

588
pocketbasetechwolf12Verified publisher0.29.31 of 1See more

pocketbase techwolf12 0.29.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,907
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.26.9

Open the chart page →

12,101
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
stdlib@go1.24.4
1.26.9

Open the chart page →

4,667
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.263 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

3 of the 6 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
stdlib@go1.20.5
1.26.9
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
stdlib@go1.19.12
1.26.9
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.26.9

Open the chart page →

17,778
feedbacksystemthm-mni-iiVerified publisher0.48.34See more

feedbacksystem thm-mni-ii 0.48.3

4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.60.0
1.26.9
bitnamilegacy/mysql:8.0.35-debian-11-r2be03e8ea6129
stdlib@go1.21.5
1.26.9
library/docker:20.10.21-dind3153fa63f546
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.7
0.60.0
1.26.9

Open the chart page →

—
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

2,184
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.14.4
0.60.0
1.26.9

Open the chart page →

5,893
traefik-meshtraefikOfficialVerified publisher4.1.13 of 7See more

traefik-mesh traefik 4.1.1

3 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.60.0
1.26.9
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

12,803
ttl-controllerttl-controllerVerified publisher1.9.11 of 1See more

ttl-controller ttl-controller 1.9.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ttl-controller/ttl-controller:1.9.18092dd72f073
golang.org/x/net@v0.57.0
stdlib@go1.27.0-X:nodwarf5
0.60.0
1.27.2

Open the chart page →

72
k8s-ttl-controllertwin0.4.01 of 1See more

k8s-ttl-controller twin 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/twin/k8s-ttl-controller:v1.4.00525a7def93d
golang.org/x/net@v0.26.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

861
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/net@v0.11.0
stdlib@go1.19.6
0.60.0
1.26.9
quay.io/argoproj/argocd:v2.8.6acaf37352569
golang.org/x/net@v0.17.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

12,349
uptraceuptrace2.0.22 of 2See more

uptrace uptrace 2.0.2

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:latestfd328de25524
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
uptrace/uptrace:2.0.234a02c3b2d12
golang.org/x/net@v0.42.0
stdlib@go1.24.10
0.60.0
1.26.9

Open the chart page →

2,073
valkey-operatorvalkeyVerified publisher0.7.01 of 1See more

valkey-operator valkey 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/valkey-io/valkey-operator:v0.7.1bfa3be0b1173
golang.org/x/net@v0.49.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

260
vaultvaultVerified publisher1.22.04 of 4See more

vault vault 1.22.0

4 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
alpine/k8s:1.35.5d870622d0040
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
hashicorp/vault:2.0.1755355002715
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
prom/statsd-exporter:v0.29.0632f70580492
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
ghcr.io/bank-vaults/bank-vaults:v1.33.198b6ea2ed319
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

5,768
victoria-logs-clustervictoriametricsVerified publisher0.2.91 of 1See more

victoria-logs-cluster victoriametrics 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.53.0251121fa882a
stdlib@go1.27.1
1.27.2

Open the chart page →

52
victoria-metrics-authvictoriametricsVerified publisher0.43.01 of 1See more

victoria-metrics-auth victoriametrics 0.43.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
victoriametrics/vmauth:v1.153.04ebf2f21490d
stdlib@go1.27.1
1.27.2

Open the chart page →

65
vouchvouchVerified publisher3.2.01 of 1See more

vouch vouch 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

1,727
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
stdlib@go1.20.7
0.60.0
1.26.9

Open the chart page →

1,939
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

3,020
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,376
wallarm-ingresswallarmVerified publisher5.3.10-12 of 2See more

wallarm-ingress wallarm 5.3.10-1

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.60.0
1.26.9

Open the chart page →

2,108
wallarm-sidecarwallarmOfficialVerified publisher6.13.22 of 3See more

wallarm-sidecar wallarm 6.13.2

2 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.13.2290a87f01799
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.60.0
1.26.9

Open the chart page →

1,569
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.26.9

Open the chart page →

4,066
prometheuswener29.36.16 of 6See more

prometheus wener 29.36.1

6 of the 6 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.106b52bd4dbe3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.34.1e9733bafb1bd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.15.0efd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/prometheus/pushgateway:v1.11.491a56b89b97d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

830
argo-cdwenerme10.10.22See more

argo-cd wenerme 10.10.2

2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/argoproj/argocd:v3.5.449dff79439bb
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

—
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.17.4
0.60.0
1.26.9

Open the chart page →

7,182
wgerwgerOfficialVerified publisher2.0.01 of 7See more

wger wger 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:15.186eb0add3b77c
stdlib@go1.24.6
1.26.9

Open the chart page →

9,028
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18.1
0.60.0
1.26.9
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.60.0
1.26.9
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.60.0
1.26.9
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.60.0
1.26.9

Open the chart page →

13,563
windmillwindmill4.0.2801 of 3See more

windmill windmill 4.0.280

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:1874935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

1,636
buildkitdwiremindVerified publisher0.33.11 of 1See more

buildkitd wiremind 0.33.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,536
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.60.0
1.26.9

Open the chart page →

5,906
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.4
0.60.0
1.26.9

Open the chart page →

5,721
yet-another-cloudwatch-exporteryet-another-cloudwatch-exporter0.38.01 of 1See more

yet-another-cloudwatch-exporter yet-another-cloudwatch-exporter 0.38.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
stdlib@go1.22.4
1.26.9

Open the chart page →

1,284
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
stdlib@go1.23.12
1.26.9

Open the chart page →

5,306
paperlesszekker6Verified publisher11.11.01 of 1See more

paperless zekker6 11.11.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.3.06b94799bc769
stdlib@go1.24.4
1.26.9

Open the chart page →

4,678
adcs-issueradcs-issuer3.0.21 of 1See more

adcs-issuer adcs-issuer 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.60.0
1.26.9

Open the chart page →

1,256
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
golang.org/x/net@v0.38.0
stdlib@go1.23.7
0.60.0
1.26.9

Open the chart page →

2,364
no-latest-tag-webhookadmission-webhook-no-latest1.0.141 of 1See more

no-latest-tag-webhook admission-webhook-no-latest 1.0.14

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/omkar-shelke25/admission-webhook-no-latest:sha-33165455976a1d3236a
golang.org/x/net@v0.38.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

356
paperless-ngxadnoctemVerified publisher0.5.03 of 5See more

paperless-ngx adnoctem 0.5.0

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9
gotenberg/gotenberg:8.36.087c16b9f3642
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/paperless-ngx/paperless-ngx:3.3.06b94799bc769
stdlib@go1.24.4
1.26.9

Open the chart page →

25,719
agentareaagentareaVerified publisher0.0.268 of 17See more

agentarea agentarea 0.0.26

8 of the 17 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
agentarea/agentarea-events:latest71a89daaa2c6
stdlib@go1.25.14
1.26.9
agentarea/agentarea-mcp-manager:latest0e7e53fef298
golang.org/x/net@v0.58.0
stdlib@go1.25.14
0.60.0
1.26.9
agentarea/agentarea-mcp-runner:latest9030cc19a0fc
stdlib@go1.19.8
1.26.9
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.26.9
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9
openfga/openfga:v1.18.036097b960f66
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.60.0
1.26.9
temporalio/auto-setup:1.29.15b3502a3b685
golang.org/x/net@v0.35.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

17,180
traefikaigisukVerified publisher0.1.11 of 1See more

traefik aigisuk 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/traefik:2.7.0-rc2b70710baceeb
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

3,817
ais-operatoraistoreVerified publisher4.1.01 of 1See more

ais-operator aistore 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aistorage/ais-operator:v4.1.0151fc5b9f917
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

72
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.281 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.28

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
stdlib@go1.26.3
1.26.9

Open the chart page →

3,052
visa-k8s-controlleralba-visa-helm-charts1.0.01 of 1See more

visa-k8s-controller alba-visa-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
misalbasynchrotron/visa-k8s:latest48e4dcba8f6e
golang.org/x/net@v0.49.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

260
adguard-homealekcVerified publisher3.2.01 of 2See more

adguard-home alekc 3.2.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.79aba9e3bf0613
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

288
cloudflaredalekcVerified publisher1.9.01 of 1See more

cloudflared alekc 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.10.09b49eed8f628
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

495
alertmanager-discordalertmanagerdiscordVerified publisher0.3.21 of 1See more

alertmanager-discord alertmanagerdiscord 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
speckle/alertmanager-discord:latestf6221ff308e9
stdlib@go1.22.4
1.26.9

Open the chart page →

766

Container images carrying it

6,339 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bloomberg/goldpinger:3.11.5f7c60d319150
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
burningalchemist/sql_exporter:0.24.9:latest6c554722facc
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
cagriekin/pg-ha:2.1.0-pg18111ccc617ce7
golang.org/x/net@v0.58.0
stdlib@go1.25.12
0.60.0
1.26.9
2
casbin/casdoor:3.62.17729da148c61
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.60.0
1.26.9
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.60.0
1.26.9
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.5
0.60.0
1.26.9
2
chrislusf/seaweedfs:2.92db095fe8a8d6
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.7
0.60.0
1.26.9
2
clickhouse/clickhouse-server:24.2ed9640bfff07
stdlib@go1.19.10
1.26.9
2
cloudflare/cloudflared:2022.1.361f608cd1123
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.1
0.60.0
1.26.9
2
cloudflare/cloudflared:2026.6.16d91c121b803
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
2
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.26.9
2
coredns/coredns:1.13.19b9128672209
golang.org/x/net@v0.45.0
stdlib@go1.25.2
0.60.0
1.26.9
2
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.60.0
1.26.9
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.17.3
0.60.0
1.26.9
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.60.0
1.26.9
2
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.4
0.60.0
1.26.9
2
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.60.0
1.26.9
2
danielfm/aws-limits-exporter:0.6.07152b84e57cb
stdlib@go1.17.2
1.26.9
2
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
2
danielqsj/kafka-exporter:latestd1014f41712d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
datawire/emissary:3.12.21f67a1292d2a
golang.org/x/net@v0.28.0
stdlib@go1.22.4
0.60.0
1.26.9
2
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.26.9
2
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.26.9
2
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.60.0
1.26.9
2
dexidp/dex:v2.39.1-distroless43655afd1a8f
golang.org/x/net@v0.24.0
stdlib@go1.21.6
0.60.0
1.26.9
2
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.60.0
1.26.9
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.60.0
1.26.9
2
dunglas/mercure:v0:v0.24.2916834e49961
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
2
envoyproxy/gateway:v1.9.10049bcb384c5
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
2
epamedp/cd-pipeline-operator:2.32.0fc858071b7a1
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
2
epamedp/codebase-operator:2.35.0295a008abcef
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
2
epamedp/edp-tekton:0.27.088189f16f94b
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
2
epamedp/gitfusion:0.6.10b7eb7d5ca43
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
2
eqalpha/keydb:latest6537505c4235
stdlib@go1.16.7
1.26.9
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.26.9
2
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.26.9
2
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.26.9
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.60.0
1.26.9
2
filebrowser/filebrowser:latest:v2.63.23a469ea076d4a
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
2
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.16.2
0.60.0
1.26.9
2
flanksource/incident-manager-ui:v1.4.3228d17f0c08b20
stdlib@go1.23.5
1.26.9
2
flashcatcloud/categraf:latest42e6ab16472e
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
2
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.60.0
1.26.9
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.