StackRadar

CVE-2026-78659

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4wvv-4gxm-pc68CGA-9hv5-59p6-4m49CGA-9mpv-qcf2-fr4cCGA-cmf5-g287-mphmCGA-ggmx-8j82-p2pfCGA-hmpr-chf9-7j4fDEBIAN-CVE-2026-78659GO-2026-6603
Also known as
CGA-2j9j-6w7w-x98q, CGA-32h2-ph4h-6j25, CGA-437c-v9xq-v77f, CGA-5cmh-mcx3-x7xj, CGA-62vw-6x79-rpw5, CGA-7fqm-wjjc-9pfc, CGA-7vrh-rfw7-r9f6, CGA-868g-cgmx-cvph, CGA-8r9c-282h-5mvw, CGA-ch5q-gfj4-q8gh, CGA-fwv6-mhj4-q3jf, CGA-gqw6-fwhv-jpf8, CGA-gw2c-84xv-m8g4, CGA-hcgj-v82p-m28j, CGA-j93h-pjfq-52jm, CGA-jj9f-32xw-j4r7, CGA-mqcg-6v5g-5xp3, CGA-mvr9-28rx-545x, CGA-pjc7-rhj8-2m9q, CGA-q38p-jqw6-276f, CGA-qq83-54q4-2pph, CGA-rhx4-wwr7-qfg4, CGA-v9h6-27pv-3g4r, CGA-w63p-h8hw-xp53, CGA-w7mj-m6pj-r2xq, CGA-wcf2-p3g3-gq3c
Trending
Rank 2 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
stdlib@go1.20.7
1.26.9

Open the chart page →

5,633
facetflanksourceVerified publisher0.1.731 of 1See more

facet flanksource 0.1.73

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
stdlib@go1.23.12
1.26.9

Open the chart page →

26,868
flanksource-uiflanksourceVerified publisher1.4.3221 of 1See more

flanksource-ui flanksource 1.4.322

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.3228d17f0c08b20
stdlib@go1.23.5
1.26.9

Open the chart page →

3,514
mission-controlflanksourceVerified publisher0.1.3393 of 8See more

mission-control flanksource 0.1.339

3 of the 8 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.3228d17f0c08b20
stdlib@go1.23.5
1.26.9
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.60.0
1.26.9
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.60.0
1.26.9

Open the chart page →

11,744
mission-control-tenantflanksourceVerified publisher1.0.923 of 3See more

mission-control-tenant flanksource 1.0.92

3 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
golang.org/x/net@v0.7.0
stdlib@go1.17.13
0.60.0
1.26.9
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.60.0
1.26.9
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

8,100
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

6,617
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

5,225
floating-serverfloating-server1.6.31 of 2See more

floating-server floating-server 1.6.3

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
censedata/floating-server:v1.6.3ebfffb9dd4c0
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

2,198
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.26.9

Open the chart page →

9,318
fluent-operatorfluent-operatorVerified publisher0.1.01 of 2See more

fluent-operator fluent-operator 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kubesphere/fluent-operator:v1.0.2702df77228c6
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.6
0.60.0
1.26.9

Open the chart page →

3,765
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
louislam/uptime-kuma:170233f4acb51
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

4,553
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
golang.org/x/net@v0.41.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

3,252
fluxer-helmfluxer-helm0.3.05 of 18See more

fluxer-helm fluxer-helm 0.3.0

5 of the 18 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:4.346620371e8af8
golang.org/x/net@v0.54.0
stdlib@go1.25.11
0.60.0
1.26.9
library/nats:2.14-alpine4063edae0717
stdlib@go1.26.8
1.26.9
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.26.9
livekit/livekit-server:v1.12.0b1281e66e35e
golang.org/x/net@v0.53.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/fluxerapp/fluxer-static:2026.812.125337cfe98ae544df
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

33,518
flyte-depsflyte1.16.81 of 3See more

flyte-deps flyte 1.16.8

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.1
0.60.0
1.26.9

Open the chart page →

3,466
flyte-devboxflyte0.1.07 of 13See more

flyte-devbox flyte 0.1.0

7 of the 13 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

8,200
gobackupfmjstudios0.2.21 of 1See more

gobackup fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
huacnlee/gobackup:v2.11.2d9c693e99576
golang.org/x/net@v0.17.0
stdlib@go1.20.3
0.60.0
1.26.9

Open the chart page →

3,672
gotenbergfmjstudios0.2.21 of 1See more

gotenberg fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.7.0437b9cd3c351
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

10,973
ntfyfmjstudios0.2.21 of 1See more

ntfy fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
golang.org/x/net@v0.25.0
stdlib@go1.22.2
0.60.0
1.26.9

Open the chart page →

1,870
popeyefmjstudios0.1.21 of 1See more

popeye fmjstudios 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
derailed/popeye:v0.21.363b2d2a8f674
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,823
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

5,443
csp-reporterfoomoVerified publisher2.2.01 of 1See more

csp-reporter foomo 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
foomo/csp-reporter:1.3.0e436da524785
stdlib@go1.18
1.26.9

Open the chart page →

2,293
forkliftforklift0.1.42 of 2See more

forklift forklift 0.1.4

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
wuhan005/forklift:daemon4e6da210e449
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
wuhan005/forklift:controllerbfbe82d59850
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

3,284
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

5,715
forwardforward1.3.11 of 1See more

forward forward 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
udhos/forward:1.1.312e120d39fdb
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

2,935
cloudflaredfossa0.1.11 of 1See more

cloudflared fossa 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2022.1.361f608cd1123
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

3,746
uptime-kumafossa1.0.11 of 1See more

uptime-kuma fossa 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
golang.org/x/net@v0.2.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

6,754
maxscalefour-allportalVerified publisher4.1.162 of 3See more

maxscale four-allportal 4.1.16

2 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:10.6.12-debian-11-r1643a70df0e7c6
stdlib@go1.19.7
1.26.9
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

9,121
readium-lcpserverfpetr0.0.51 of 3See more

readium-lcpserver fpetr 0.0.5

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
golang.org/x/net@v0.17.0
stdlib@go1.22.0
0.60.0
1.26.9

Open the chart page →

2,031
readium-lsdserverfpetr0.0.11 of 2See more

readium-lsdserver fpetr 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
golang.org/x/net@v0.17.0
stdlib@go1.22.0
0.60.0
1.26.9

Open the chart page →

2,031
ff-testfrankframework0.7.61 of 2See more

ff-test frankframework 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:17-bookworm3645570cccdf
stdlib@go1.24.6
1.26.9

Open the chart page →

2,089
frank2examplefrankframework0.7.41 of 2See more

frank2example frankframework 0.7.4

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:17-bookworm3645570cccdf
stdlib@go1.24.6
1.26.9

Open the chart page →

2,089
free5gc-amffree5gc-amfVerified publisher0.1.31 of 1See more

free5gc-amf free5gc-amf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,521
free5gc-ausffree5gc-ausfVerified publisher0.1.31 of 1See more

free5gc-ausf free5gc-ausf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,526
free5gc-chffree5gc-chfVerified publisher0.1.31 of 1See more

free5gc-chf free5gc-chf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,620
free5gc-nrffree5gc-nrfVerified publisher0.1.31 of 1See more

free5gc-nrf free5gc-nrf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,535
free5gc-nssffree5gc-nssfVerified publisher0.1.31 of 1See more

free5gc-nssf free5gc-nssf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,526
free5gc-pcffree5gc-pcfVerified publisher0.1.31 of 1See more

free5gc-pcf free5gc-pcf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,519
free5gc-smffree5gc-smfVerified publisher0.1.31 of 1See more

free5gc-smf free5gc-smf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,537
free5gc-udmfree5gc-udmVerified publisher0.1.31 of 1See more

free5gc-udm free5gc-udm 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/udm:v3.4.32f68df062a50
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,526
free5gc-udrfree5gc-udrVerified publisher0.1.31 of 1See more

free5gc-udr free5gc-udr 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,535
free5gc-upffree5gc-upfVerified publisher0.1.31 of 1See more

free5gc-upf free5gc-upf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/upf:v3.4.3b6b362a39fdd
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,740
free5gc-webuifree5gc-webuiVerified publisher0.1.31 of 1See more

free5gc-webui free5gc-webui 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,931
dbmatefrinx-helm-charts1.0.01 of 1See more

dbmate frinx-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
amacneil/dbmate:2.6.03fdce58cc189
stdlib@go1.21.0
1.26.9

Open the chart page →

2,004
frinx-machinefrinx-helm-charts11.0.011 of 26See more

frinx-machine frinx-helm-charts 11.0.0

11 of the 26 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
frinx/krakend:7.0.0bf8edd4f52f3
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.60.0
1.26.9
frinx/resource-manager:6.1.09cd0147a09bd
stdlib@go1.21.7
1.26.9
frinx/schellar:6.1.04693dc627d32
stdlib@go1.21.11
1.26.9
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9
grafana/promtail:2.9.3b338a29de45e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
library/traefik:v2.11b91812c7ee1b
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

52,207
frinx-machine-monitoringfrinx-helm-charts0.1.27 of 8See more

frinx-machine-monitoring frinx-helm-charts 0.1.2

7 of the 8 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9
grafana/promtail:2.9.3b338a29de45e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

15,818
frinx-machine-operatorsfrinx-helm-charts0.3.02 of 2See more

frinx-machine-operators frinx-helm-charts 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
arangodb/kube-arangodb:1.2.4108d1720cec3b
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9
ghcr.io/cloudnative-pg/cloudnative-pg:1.23.2f1f3c20f3637
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

3,063
krakendfrinx-helm-charts5.0.21 of 1See more

krakend frinx-helm-charts 5.0.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
frinx/krakend:7.0.0bf8edd4f52f3
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.60.0
1.26.9

Open the chart page →

1,974
resource-managerfrinx-helm-charts2.3.11 of 4See more

resource-manager frinx-helm-charts 2.3.1

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
frinx/resource-manager:6.1.09cd0147a09bd
stdlib@go1.21.7
1.26.9

Open the chart page →

10,488
uniresourcefrinx-helm-charts1.1.12 of 3See more

uniresource frinx-helm-charts 1.1.1

2 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
frinx/resource-manager:1.0.455575caebd01
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.17.9
0.60.0
1.26.9
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9

Open the chart page →

5,300
workflow-managerfrinx-helm-charts3.2.11 of 5See more

workflow-manager frinx-helm-charts 3.2.1

1 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
frinx/schellar:6.1.04693dc627d32
stdlib@go1.21.11
1.26.9

Open the chart page →

9,952

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
library/zookeeper:3.9.5e6b279d01350
stdlib@go1.18.1
1.26.9
2
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
2
linuxserver/cloud9:latest:version-1.29.245c5fe102ff3
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.11
0.60.0
1.26.9
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
2
listmonk/listmonk:latest:v6.2.0f535d59e1499
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.60.0
1.26.9
2
localstack/localstack-pro:latest801a3dff7f6a
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:nojsonv2
0.60.0
1.27.2
2
longhornio/longhorn-manager:v1.2.3dca34321452c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.1
0.60.0
1.26.9
2
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.60.0
1.26.9
2
louislam/uptime-kuma:2.3.29aeb4e51d038
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
2
louislam/uptime-kuma:2.5.5c74379ac4509
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
2
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
2
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.60.0
1.26.9
2
maxrocketinternet/datadog-controller:0.1a867315facf8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
2
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.26.9
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.60.0
1.26.9
2
mesosphere/kubectl:v1.35.0-alpineea01a9387771
golang.org/x/net@v0.43.0
stdlib@go1.25.5
0.60.0
1.26.9
2
mikefarah/yq:4:latest4b3d9475d655
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.60.0
1.26.9
2
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.26.9
2
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.1
0.60.0
1.26.9
2
natsio/nats-server-config-reloader:0.20.147094fcae2f4
stdlib@go1.24.8
1.26.9
2
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.26.9
2
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.26.9
2
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.26.9
2
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.26.9
2
neosmemo/memos:0.31.024c2707ddd8f
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
stdlib@go1.24.4
1.26.9
2
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
2
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.26.9
2
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
golang.org/x/net@v0.14.0
stdlib@go1.19.8
no fix listed
0.60.0
1.26.9
2
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9
2
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
2
openebs/mc:RELEASE.2024-11-21T17-21-54Z4d1b85539919
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2
openebs/minio:RELEASE.2024-12-18T13-15-44Zbb04e41fc1b8
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2
openebs/provisioner-localpv:4.6.099f5116f5cb8
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
2
openfga/openfga:latest:v1.22.09cf9a20af32a
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
golang.org/x/net@v0.24.0
stdlib@go1.20.14
0.60.0
1.26.9
2
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.2
0.60.0
1.26.9
2
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
2
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
2
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.60.0
1.26.9
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.60.0
1.26.9
2
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.145.0a7343f018690
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.161.0:latestfd328de25524
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
2
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.26.9
2

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.