StackRadar

CVE-2026-78659

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4wvv-4gxm-pc68CGA-9hv5-59p6-4m49CGA-9mpv-qcf2-fr4cCGA-cmf5-g287-mphmCGA-ggmx-8j82-p2pfCGA-hmpr-chf9-7j4fDEBIAN-CVE-2026-78659GO-2026-6603
Also known as
CGA-2j9j-6w7w-x98q, CGA-32h2-ph4h-6j25, CGA-437c-v9xq-v77f, CGA-5cmh-mcx3-x7xj, CGA-62vw-6x79-rpw5, CGA-7fqm-wjjc-9pfc, CGA-7vrh-rfw7-r9f6, CGA-868g-cgmx-cvph, CGA-8r9c-282h-5mvw, CGA-ch5q-gfj4-q8gh, CGA-fwv6-mhj4-q3jf, CGA-gqw6-fwhv-jpf8, CGA-gw2c-84xv-m8g4, CGA-hcgj-v82p-m28j, CGA-j93h-pjfq-52jm, CGA-jj9f-32xw-j4r7, CGA-mqcg-6v5g-5xp3, CGA-mvr9-28rx-545x, CGA-pjc7-rhj8-2m9q, CGA-q38p-jqw6-276f, CGA-qq83-54q4-2pph, CGA-rhx4-wwr7-qfg4, CGA-v9h6-27pv-3g4r, CGA-w63p-h8hw-xp53, CGA-w7mj-m6pj-r2xq, CGA-wcf2-p3g3-gq3c
Trending
Rank 2 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
akto-ai-guardrails-v2akto0.3.02 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

2 of the 6 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.60.0
1.26.9
aktosecurity/guardrails-service:2.14.8a6218d07e84f
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

51,416
akto-aws-api-gateway-connectorakto0.1.11 of 1See more

akto-aws-api-gateway-connector akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-multi-logging1a1bc76d50fe
stdlib@go1.23.3
1.26.9

Open the chart page →

769
akto-central-setupakto1.2.43 of 5See more

akto-central-setup akto 1.2.4

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:1.18.75a0c66e59678
stdlib@go1.26.7
1.26.9
library/eclipse-temurin:213e3c176ffed1
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

4,368
akto-hybrid-redactakto1.44.84 of 5See more

akto-hybrid-redact akto 1.44.8

4 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.7_local6b75164ae737
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.7_local500745200425
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
stdlib@go1.25.4
1.26.9

Open the chart page →

5,889
akto-k8s-agentakto0.1.21 of 1See more

akto-k8s-agent akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_agentc8266e943ff9
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

190
akto-k8s-ebpfakto0.1.31 of 1See more

akto-k8s-ebpf akto 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_ebpf3e506f5e5f47
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

904
akto-k8s-ebpf-openshiftakto0.1.11 of 1See more

akto-k8s-ebpf-openshift akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,724
akto-mini-runtimeakto0.7.234 of 5See more

akto-mini-runtime akto 0.7.23

4 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latesteeff3738d708
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/akto-threat-detection:latesta1fe1ef75a55
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9
public.ecr.aws/aktosecurity/keelhq-keel:latest1eb61443d68e
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

6,051
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
stdlib@go1.25.4
1.26.9

Open the chart page →

4,092
akto-mini-testingakto1.46.03 of 5See more

akto-mini-testing akto 1.46.0

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.8_localfa276f7090a4
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

5,810
akto-mini-testing-kafkaakto1.42.11 of 5See more

akto-mini-testing-kafka akto 1.42.1

1 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

7,691
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
stdlib@go1.24.6
1.26.9

Open the chart page →

2,507
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

12,534
akto-regional-setupakto1.4.104 of 9See more

akto-regional-setup akto 1.4.10

4 of the 9 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/guardrails-service:2.40.663e9235153a3
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
stdlib@go1.26.5
1.26.9
public.ecr.aws/aktosecurity/akto-threat-detection:1.18.755b1bd20ef02
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

32,553
akto-runtimeakto0.1.82 of 2See more

akto-runtime akto 0.1.8

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest6b75164ae737
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

1,743
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
stdlib@go1.22.5
1.26.9

Open the chart page →

6,163
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

41,842
akto-threat-backendakto0.1.52 of 2See more

akto-threat-backend akto 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:latestd9d0e7c78578
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

1,819
akto-threat-clientakto0.2.02 of 2See more

akto-threat-client akto 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latestf14d68a2b1cf
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

1,850
api-gateway-loggingakto0.1.21 of 1See more

api-gateway-logging akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-openapi12ed2544756f
stdlib@go1.23.3
1.26.9

Open the chart page →

769
browserlessalekcVerified publisher1.3.01 of 1See more

browserless alekc 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.57.0f4fcb054396a
stdlib@go1.26.7
1.26.9

Open the chart page →

1,348
gitlab-runner-operatoralekcVerified publisher2.5.12 of 2See more

gitlab-runner-operator alekc 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alekc/gitlab-runner-operator:v2.1.0be19341e829b
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.37.1b7cab618e281
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

265
gostalekcVerified publisher0.3.01 of 1See more

gost alekc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
gogost/gost:3.3.0f7a958c45192
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

377
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

3,258
plexalekcVerified publisher2.10.11 of 1See more

plex alekc 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
linuxserver/plex:1.43.406e07af2851e
stdlib@go1.26.7
1.26.9

Open the chart page →

789
rabbitmq-cluster-operatoralekcVerified publisher2.9.01 of 1See more

rabbitmq-cluster-operator alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

562
smokeping-exporteralekcVerified publisher0.3.01 of 1See more

smokeping-exporter alekc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/superq/smokeping-prober:v0.12.02524b895bdae
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

502
valkey-operatoralekcVerified publisher0.4.01 of 1See more

valkey-operator alekc 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/hyperspike/valkey-operator:v0.0.617d8c669f11a4
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.60.0
1.26.9

Open the chart page →

695
vault-operatoralekcVerified publisher1.26.21 of 1See more

vault-operator alekc 1.26.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-operator:v1.24.1b5529976f0f6
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

178
alertmanager-graph-bridgealertmanager-graph-bridge1.0.01 of 1See more

alertmanager-graph-bridge alertmanager-graph-bridge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/slauger/alertmanager-graph-bridge:1.0.0ccca112b6557
stdlib@go1.27.1
1.27.2

Open the chart page →

177
mautrix-signalalexanderbadel0.1.11 of 2See more

mautrix-signal alexanderbadel 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.26.9

Open the chart page →

3,350
pushproxalexmorbo-pushproxVerified publisher1.0.01 of 1See more

pushprox alexmorbo-pushprox 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
prometheuscommunity/pushprox:v0.2.02f32058f4fae
stdlib@go1.22.1
1.26.9

Open the chart page →

915
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/net@v0.17.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

1,582
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

2,028
rabbitmq-cluster-operatoralexmorbo-rabbitmq-cluster-operatorVerified publisher1.0.01 of 1See more

rabbitmq-cluster-operator alexmorbo-rabbitmq-cluster-operator 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/rabbitmqoperator/cluster-operator:2.22.52727b84b835a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

166
rabbitmq-messaging-topology-operatoralexmorbo-rabbitmq-messaging-topology-operatorVerified publisher1.0.11 of 1See more

rabbitmq-messaging-topology-operator alexmorbo-rabbitmq-messaging-topology-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/rabbitmqoperator/messaging-topology-operator:1.20.229174b668012
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

166
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.26.9

Open the chart page →

2,322
wireguardalexpressoVerified publisher0.1.71 of 2See more

wireguard alexpresso 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
linuxserver/wireguard:latest216ca1ce9da7
golang.org/x/net@v0.47.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

670
gotifyalexvanderberkelVerified publisher0.7.21See more

gotify alexvanderberkel 0.7.2

1 container image this version deploys carries CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/gotify/server:3.1.144fc5bbd1c06
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

—
alibaba-rsocket-brokeralibaba-rsocket-brokerVerified publisher0.1.31 of 1See more

alibaba-rsocket-broker alibaba-rsocket-broker 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17.7
0.60.0
1.26.9

Open the chart page →

94,430
alluredeckalluredeckVerified publisher0.24.01 of 2See more

alluredeck alluredeck 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,907
book-serveral-masood-helm-charts0.1.01 of 1See more

book-server al-masood-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
almasood/book-server:latest6ffac9b63cdf
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

888
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.15
0.60.0
1.26.9

Open the chart page →

3,266
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

1,013
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

1,013
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

1,653
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
golang.org/x/net@v0.34.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

978
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

5,753
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,041
versitygwalpineworks0.1.21 of 1See more

versitygw alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
versity/versitygw:v1.0.145192635d0353
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

1,777

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
temporalio/admin-tools:1.32.0a9f84fb9a374
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
temporalio/server:1.22.4c0a44c26397b
golang.org/x/net@v0.7.0
stdlib@go1.20.11
0.60.0
1.26.9
2
temporalio/server:1.32.0c3e752127759
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
temporalio/server:1.15.1e26758f5a1bf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
2
temporalio/ui:2.16.2af9c9349708f
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
2
testinprod/op-erigon:latest0a125bd77a2d
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
2
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
2
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.60.0
1.26.9
2
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.60.0
1.26.9
2
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
stdlib@go1.15.6
1.26.9
2
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
2
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.60.0
1.26.9
2
thoughtmachine/aws-service-quotas-exporter:v1.3.2c6065ba55c72
stdlib@go1.19.4
1.26.9
2
timescale/timescaledb:latest-pg156343bdc87ca1
stdlib@go1.24.6
1.26.9
2
timescale/timescaledb:2.30.2-pg17:latest-pg17b346edcdb51a
stdlib@go1.24.6
1.26.9
2
tkpd/gripmock:1.10.174441dadcfbd
stdlib@go1.14.6
1.26.9
2
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.26.9
2
tykio/tyk-mdcb-docker:v2.13.047c25173146e
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
2
tykio/tyk-pump-docker-pub:v1.17.09cc53e58abc4
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
2
ubercadence/server:0.23.22ac5491d13bb
golang.org/x/net@v0.0.0-20201031054903-ff519b6c9102
stdlib@go1.13.6
0.60.0
1.26.9
2
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
stdlib@go1.20.14
0.60.0
1.26.9
2
uselagoon/docker-host:v3.6.12c89ed939b8b
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
2
velero/velero:v1.18.237396519f399
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9
2
victoriametrics/operator:v0.74.0c4fde419a4f0
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
2
victoriametrics/victoria-logs:v1.53.0251121fa882a
stdlib@go1.27.1
1.27.2
2
victoriametrics/victoria-traces:v0.11.09947b14b6b9b
stdlib@go1.26.5
1.26.9
2
victoriametrics/vmalert:v1.95.1a83e5db0897a
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.60.0
1.26.9
2
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.60.0
1.26.9
2
voltha/voltha-openolt-adapter:4.5.16d6d79c08350a
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.60.0
1.26.9
2
voltha/voltha-openonu-adapter-go:2.12.25d8f2eb5f2a7e
golang.org/x/net@v0.33.0
stdlib@go1.23.1
0.60.0
1.26.9
2
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.60.0
1.26.9
2
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.60.0
1.26.9
2
wener/frpc:v0.37.0cc9fd4da44c0
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.60.0
1.26.9
2
wener/frps:v0.37.05c92cc9e8597
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.60.0
1.26.9
2
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.60.0
1.26.9
2
yzhou442/equiz:latesta3f7ca69e28d
stdlib@go1.16.7
1.26.9
2
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
2
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
2
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.10
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.60.0
1.26.9
2
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.60.0
1.26.9
2
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller0d5f740b4224
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
2
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook697668be7893
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.