StackRadar

CVE-2026-78659

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4wvv-4gxm-pc68CGA-9hv5-59p6-4m49CGA-9mpv-qcf2-fr4cCGA-cmf5-g287-mphmCGA-ggmx-8j82-p2pfCGA-hmpr-chf9-7j4fDEBIAN-CVE-2026-78659GO-2026-6603
Also known as
CGA-2j9j-6w7w-x98q, CGA-32h2-ph4h-6j25, CGA-437c-v9xq-v77f, CGA-5cmh-mcx3-x7xj, CGA-62vw-6x79-rpw5, CGA-7fqm-wjjc-9pfc, CGA-7vrh-rfw7-r9f6, CGA-868g-cgmx-cvph, CGA-8r9c-282h-5mvw, CGA-ch5q-gfj4-q8gh, CGA-fwv6-mhj4-q3jf, CGA-gqw6-fwhv-jpf8, CGA-gw2c-84xv-m8g4, CGA-hcgj-v82p-m28j, CGA-j93h-pjfq-52jm, CGA-jj9f-32xw-j4r7, CGA-mqcg-6v5g-5xp3, CGA-mvr9-28rx-545x, CGA-pjc7-rhj8-2m9q, CGA-q38p-jqw6-276f, CGA-qq83-54q4-2pph, CGA-rhx4-wwr7-qfg4, CGA-v9h6-27pv-3g4r, CGA-w63p-h8hw-xp53, CGA-w7mj-m6pj-r2xq, CGA-wcf2-p3g3-gq3c
Trending
Rank 2 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
airbyte-keycloakairbyteVerified publisher0.1.21 of 2See more

airbyte-keycloak airbyte 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

1,919
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

5,823
airbyteairbyte-v2Verified publisher2.4.03 of 10See more

airbyte airbyte-v2 2.4.0

3 of the 10 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
airbyte/db:2.4.091f7b485f019
stdlib@go1.24.6
1.26.9
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
temporalio/auto-setup:1.27.2b44cbfeb43db
golang.org/x/net@v0.34.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

15,544
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.60.0
1.26.9

Open the chart page →

6,066
airports-postgresairports-postgres0.1.01 of 1See more

airports-postgres airports-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.26.9

Open the chart page →

1,893
akeyless-csi-providerakeyless-services-helmVerified publisher1.0.41 of 1See more

akeyless-csi-provider akeyless-services-helm 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
akeyless/akeyless-csi-provider:lateste48bddc5dd72
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

626
akeyless-gatewayakeyless-services-helmVerified publisher3.8.01 of 2See more

akeyless-gateway akeyless-services-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
akeyless/gateway:5.5.053301745cb50
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,420
akeyless-secrets-injectionakeyless-services-helmVerified publisher2.4.01 of 1See more

akeyless-secrets-injection akeyless-services-helm 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
akeyless/k8s-webhook-server:0.39.0996cd9afb3b4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

737
akriakri0.12.551 of 3See more

akri akri 0.12.55

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

2,650
aktoakto0.2.01 of 7See more

akto akto 0.2.0

1 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

14,532
akto-ai-guardrailsakto0.1.21 of 2See more

akto-ai-guardrails akto 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-agent-guard-service:latest5c6ff17c5849
stdlib@go1.25.5
1.26.9

Open the chart page →

568
akto-ai-guardrails-v2akto0.3.02 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

2 of the 6 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.60.0
1.26.9
aktosecurity/guardrails-service:2.14.8a6218d07e84f
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

51,564
akto-aws-api-gateway-connectorakto0.1.11 of 1See more

akto-aws-api-gateway-connector akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-multi-logging1a1bc76d50fe
stdlib@go1.23.3
1.26.9

Open the chart page →

821
akto-central-setupakto1.2.43 of 5See more

akto-central-setup akto 1.2.4

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:1.18.75a0c66e59678
stdlib@go1.26.7
1.26.9
library/eclipse-temurin:213e3c176ffed1
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

4,544
akto-hybrid-redactakto1.44.84 of 5See more

akto-hybrid-redact akto 1.44.8

4 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.7_local6b75164ae737
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.7_local500745200425
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
stdlib@go1.25.4
1.26.9

Open the chart page →

6,143
akto-k8s-agentakto0.1.21 of 1See more

akto-k8s-agent akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_agentc8266e943ff9
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

267
akto-k8s-ebpfakto0.1.31 of 1See more

akto-k8s-ebpf akto 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_ebpf3e506f5e5f47
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

979
akto-k8s-ebpf-openshiftakto0.1.11 of 1See more

akto-k8s-ebpf-openshift akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,799
akto-mini-runtimeakto0.7.234 of 5See more

akto-mini-runtime akto 0.7.23

4 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latesteeff3738d708
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/akto-threat-detection:latesta1fe1ef75a55
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9
public.ecr.aws/aktosecurity/keelhq-keel:latest1eb61443d68e
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

6,304
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
stdlib@go1.25.4
1.26.9

Open the chart page →

4,178
akto-mini-testingakto1.46.03 of 5See more

akto-mini-testing akto 1.46.0

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.8_localfa276f7090a4
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

6,025
akto-mini-testing-kafkaakto1.42.11 of 5See more

akto-mini-testing-kafka akto 1.42.1

1 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

7,768
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
stdlib@go1.24.6
1.26.9

Open the chart page →

2,580
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

12,611
akto-regional-setupakto1.4.104 of 9See more

akto-regional-setup akto 1.4.10

4 of the 9 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/guardrails-service:2.40.663e9235153a3
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
stdlib@go1.26.5
1.26.9
public.ecr.aws/aktosecurity/akto-threat-detection:1.18.755b1bd20ef02
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

32,802
akto-runtimeakto0.1.82 of 2See more

akto-runtime akto 0.1.8

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest6b75164ae737
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

1,867
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
stdlib@go1.22.5
1.26.9

Open the chart page →

6,212
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

41,916
akto-threat-backendakto0.1.52 of 2See more

akto-threat-backend akto 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:latestd9d0e7c78578
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

1,943
akto-threat-clientakto0.2.02 of 2See more

akto-threat-client akto 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latestf14d68a2b1cf
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

1,974
api-gateway-loggingakto0.1.21 of 1See more

api-gateway-logging akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-openapi12ed2544756f
stdlib@go1.23.3
1.26.9

Open the chart page →

821
browserlessalekcVerified publisher1.3.01 of 1See more

browserless alekc 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.57.0f4fcb054396a
stdlib@go1.26.7
1.26.9

Open the chart page →

1,400
cliproxyapialekcVerified publisher1.0.71 of 1See more

cliproxyapi alekc 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
eceasy/cli-proxy-api:v8.0.23fc250aafe345
golang.org/x/net@v0.57.0
0.60.0

Open the chart page →

1,289
gitlab-runner-operatoralekcVerified publisher2.5.12 of 2See more

gitlab-runner-operator alekc 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alekc/gitlab-runner-operator:v2.1.0be19341e829b
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.37.1b7cab618e281
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

419
gostalekcVerified publisher0.3.01 of 1See more

gost alekc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
gogost/gost:3.3.0f7a958c45192
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

454
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

3,334
plexalekcVerified publisher2.10.11 of 1See more

plex alekc 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
linuxserver/plex:1.43.406e07af2851e
stdlib@go1.26.7
1.26.9

Open the chart page →

670
rabbitmq-cluster-operatoralekcVerified publisher2.9.01 of 1See more

rabbitmq-cluster-operator alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

638
smokeping-exporteralekcVerified publisher0.3.01 of 1See more

smokeping-exporter alekc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/superq/smokeping-prober:v0.12.02524b895bdae
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

577
valkey-operatoralekcVerified publisher0.4.01 of 1See more

valkey-operator alekc 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/hyperspike/valkey-operator:v0.0.617d8c669f11a4
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.60.0
1.26.9

Open the chart page →

771
vault-operatoralekcVerified publisher1.26.21 of 1See more

vault-operator alekc 1.26.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-operator:v1.24.1b5529976f0f6
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

255
alertmanager-graph-bridgealertmanager-graph-bridge1.0.01 of 1See more

alertmanager-graph-bridge alertmanager-graph-bridge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/slauger/alertmanager-graph-bridge:1.0.0ccca112b6557
stdlib@go1.27.1
1.27.2

Open the chart page →

250
mautrix-signalalexanderbadel0.1.11 of 2See more

mautrix-signal alexanderbadel 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.26.9

Open the chart page →

3,401
pushproxalexmorbo-pushproxVerified publisher1.0.01 of 1See more

pushprox alexmorbo-pushprox 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
prometheuscommunity/pushprox:v0.2.02f32058f4fae
stdlib@go1.22.1
1.26.9

Open the chart page →

966
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/net@v0.17.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

1,659
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

2,104
rabbitmq-cluster-operatoralexmorbo-rabbitmq-cluster-operatorVerified publisher1.0.01 of 1See more

rabbitmq-cluster-operator alexmorbo-rabbitmq-cluster-operator 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/rabbitmqoperator/cluster-operator:2.22.52727b84b835a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

243
rabbitmq-messaging-topology-operatoralexmorbo-rabbitmq-messaging-topology-operatorVerified publisher1.0.11 of 1See more

rabbitmq-messaging-topology-operator alexmorbo-rabbitmq-messaging-topology-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/rabbitmqoperator/messaging-topology-operator:1.20.229174b668012
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

243
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.26.9

Open the chart page →

2,374
wireguardalexpressoVerified publisher0.1.71 of 2See more

wireguard alexpresso 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
linuxserver/wireguard:latest216ca1ce9da7
golang.org/x/net@v0.47.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

747

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/open-cluster-management/argocd-pull-integration:0.30.0683ae238f351
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.14
0.60.0
1.26.9
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.12
0.60.0
1.26.9
2
quay.io/openshift/origin-cli:lateste7965645fac6
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
2
quay.io/openshift/origin-csi-livenessprobe:latesta6341950c413
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
2
quay.io/opstree/redis-operator:v0.22.2464ac61a6eb4
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
2
quay.io/prometheus/alertmanager:latest:v0.34.0690c7b525f43
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
2
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.60.0
1.26.9
2
quay.io/prometheus/blackbox-exporter:latest:v0.28.0e753ff9f3fc4
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
2
quay.io/prometheuscommunity/elasticsearch-exporter:v1.11.0a056739b095d
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
2
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9
2
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.60.0
1.26.9
2
quay.io/prometheus/node-exporter:v1.11.1-distroless6112664fd761
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
2
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.3
0.60.0
1.26.9
2
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.89.0cb4ac6a56555
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.14.12
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-operator:v0.91.09e53e1313921
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-operator:v0.83.0b6a89b8ec08f
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-operator:v0.88.1d3d65efa3bee
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.60.0
1.26.9
2
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9
2
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
2
quay.io/prometheus/prometheus:v3.13.2508729e0e2d1
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.60.0
1.26.9
2
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.60.0
1.26.9
2
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.60.0
1.26.9
2
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.60.0
1.26.9
2
quay.io/prometheus/pushgateway:v1.11.249ed9fdf3780
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.60.0
1.26.9
2
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/net@v0.10.0
stdlib@go1.21.1
0.60.0
1.26.9
2
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9
2
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.60.0
1.26.9
2
quay.io/thanos/thanos:v0.39.21d022ef4b8ef
golang.org/x/net@v0.41.0
stdlib@go1.24.0
0.60.0
1.26.9
2
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.60.0
1.26.9
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.60.0
1.26.9
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.60.0
1.26.9
2
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
2
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.60.0
1.26.9
2
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
2
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.60.0
1.26.9
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.60.0
1.26.9
2
registry.k8s.io/kubectl:v1.37.1b7cab618e281
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.