StackRadar

CVE-2026-78659

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4wvv-4gxm-pc68CGA-9hv5-59p6-4m49CGA-9mpv-qcf2-fr4cCGA-cmf5-g287-mphmCGA-ggmx-8j82-p2pfCGA-hmpr-chf9-7j4fDEBIAN-CVE-2026-78659GO-2026-6603
Also known as
CGA-2j9j-6w7w-x98q, CGA-32h2-ph4h-6j25, CGA-437c-v9xq-v77f, CGA-5cmh-mcx3-x7xj, CGA-62vw-6x79-rpw5, CGA-7fqm-wjjc-9pfc, CGA-7vrh-rfw7-r9f6, CGA-868g-cgmx-cvph, CGA-8r9c-282h-5mvw, CGA-ch5q-gfj4-q8gh, CGA-fwv6-mhj4-q3jf, CGA-gqw6-fwhv-jpf8, CGA-gw2c-84xv-m8g4, CGA-hcgj-v82p-m28j, CGA-j93h-pjfq-52jm, CGA-jj9f-32xw-j4r7, CGA-mqcg-6v5g-5xp3, CGA-mvr9-28rx-545x, CGA-pjc7-rhj8-2m9q, CGA-q38p-jqw6-276f, CGA-qq83-54q4-2pph, CGA-rhx4-wwr7-qfg4, CGA-v9h6-27pv-3g4r, CGA-w63p-h8hw-xp53, CGA-w7mj-m6pj-r2xq, CGA-wcf2-p3g3-gq3c
Trending
Rank 2 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
airbyte-keycloakairbyteVerified publisher0.1.21 of 2See more

airbyte-keycloak airbyte 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

1,919
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

5,823
airbyteairbyte-v2Verified publisher2.4.03 of 10See more

airbyte airbyte-v2 2.4.0

3 of the 10 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
airbyte/db:2.4.091f7b485f019
stdlib@go1.24.6
1.26.9
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
temporalio/auto-setup:1.27.2b44cbfeb43db
golang.org/x/net@v0.34.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

15,544
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.60.0
1.26.9

Open the chart page →

6,066
airports-postgresairports-postgres0.1.01 of 1See more

airports-postgres airports-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
postgis/postgis:latest01a6a70e41e6
stdlib@go1.18.2
1.26.9

Open the chart page →

1,893
akeyless-csi-providerakeyless-services-helmVerified publisher1.0.41 of 1See more

akeyless-csi-provider akeyless-services-helm 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
akeyless/akeyless-csi-provider:lateste48bddc5dd72
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

626
akeyless-gatewayakeyless-services-helmVerified publisher3.8.01 of 2See more

akeyless-gateway akeyless-services-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
akeyless/gateway:5.5.053301745cb50
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,420
akeyless-secrets-injectionakeyless-services-helmVerified publisher2.4.01 of 1See more

akeyless-secrets-injection akeyless-services-helm 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
akeyless/k8s-webhook-server:0.39.0996cd9afb3b4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

737
akriakri0.12.551 of 3See more

akri akri 0.12.55

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

2,650
aktoakto0.2.01 of 7See more

akto akto 0.2.0

1 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

14,532
akto-ai-guardrailsakto0.1.21 of 2See more

akto-ai-guardrails akto 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-agent-guard-service:latest5c6ff17c5849
stdlib@go1.25.5
1.26.9

Open the chart page →

568
akto-ai-guardrails-v2akto0.3.02 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

2 of the 6 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.60.0
1.26.9
aktosecurity/guardrails-service:2.14.8a6218d07e84f
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

51,564
akto-aws-api-gateway-connectorakto0.1.11 of 1See more

akto-aws-api-gateway-connector akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-multi-logging1a1bc76d50fe
stdlib@go1.23.3
1.26.9

Open the chart page →

821
akto-central-setupakto1.2.43 of 5See more

akto-central-setup akto 1.2.4

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:1.18.75a0c66e59678
stdlib@go1.26.7
1.26.9
library/eclipse-temurin:213e3c176ffed1
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

4,544
akto-hybrid-redactakto1.44.84 of 5See more

akto-hybrid-redact akto 1.44.8

4 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.7_local6b75164ae737
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.7_local500745200425
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
stdlib@go1.25.4
1.26.9

Open the chart page →

6,143
akto-k8s-agentakto0.1.21 of 1See more

akto-k8s-agent akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_agentc8266e943ff9
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

267
akto-k8s-ebpfakto0.1.31 of 1See more

akto-k8s-ebpf akto 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:k8s_ebpf3e506f5e5f47
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

979
akto-k8s-ebpf-openshiftakto0.1.11 of 1See more

akto-k8s-ebpf-openshift akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,799
akto-mini-runtimeakto0.7.234 of 5See more

akto-mini-runtime akto 0.7.23

4 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latesteeff3738d708
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/akto-threat-detection:latesta1fe1ef75a55
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9
public.ecr.aws/aktosecurity/keelhq-keel:latest1eb61443d68e
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

6,304
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
stdlib@go1.25.4
1.26.9

Open the chart page →

4,178
akto-mini-testingakto1.46.03 of 5See more

akto-mini-testing akto 1.46.0

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.8_localfa276f7090a4
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

6,025
akto-mini-testing-kafkaakto1.42.11 of 5See more

akto-mini-testing-kafka akto 1.42.1

1 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

7,768
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
stdlib@go1.24.6
1.26.9

Open the chart page →

2,580
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

12,611
akto-regional-setupakto1.4.104 of 9See more

akto-regional-setup akto 1.4.10

4 of the 9 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/guardrails-service:2.40.663e9235153a3
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
stdlib@go1.26.5
1.26.9
public.ecr.aws/aktosecurity/akto-threat-detection:1.18.755b1bd20ef02
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

32,802
akto-runtimeakto0.1.82 of 2See more

akto-runtime akto 0.1.8

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest6b75164ae737
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

1,867
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
stdlib@go1.22.5
1.26.9

Open the chart page →

6,212
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

41,916
akto-threat-backendakto0.1.52 of 2See more

akto-threat-backend akto 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:latestd9d0e7c78578
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

1,943
akto-threat-clientakto0.2.02 of 2See more

akto-threat-client akto 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-threat-detection:latestf14d68a2b1cf
stdlib@go1.26.7
1.26.9
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9

Open the chart page →

1,974
api-gateway-loggingakto0.1.21 of 1See more

api-gateway-logging akto 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aktosecurity/mirror-api-logging:api-gateway-logging-openapi12ed2544756f
stdlib@go1.23.3
1.26.9

Open the chart page →

821
browserlessalekcVerified publisher1.3.01 of 1See more

browserless alekc 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.57.0f4fcb054396a
stdlib@go1.26.7
1.26.9

Open the chart page →

1,400
cliproxyapialekcVerified publisher1.0.71 of 1See more

cliproxyapi alekc 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
eceasy/cli-proxy-api:v8.0.23fc250aafe345
golang.org/x/net@v0.57.0
0.60.0

Open the chart page →

1,289
gitlab-runner-operatoralekcVerified publisher2.5.12 of 2See more

gitlab-runner-operator alekc 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alekc/gitlab-runner-operator:v2.1.0be19341e829b
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.37.1b7cab618e281
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

419
gostalekcVerified publisher0.3.01 of 1See more

gost alekc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
gogost/gost:3.3.0f7a958c45192
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

454
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

3,334
plexalekcVerified publisher2.10.11 of 1See more

plex alekc 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
linuxserver/plex:1.43.406e07af2851e
stdlib@go1.26.7
1.26.9

Open the chart page →

670
rabbitmq-cluster-operatoralekcVerified publisher2.9.01 of 1See more

rabbitmq-cluster-operator alekc 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:2.19.2840be4bad78e
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

638
smokeping-exporteralekcVerified publisher0.3.01 of 1See more

smokeping-exporter alekc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/superq/smokeping-prober:v0.12.02524b895bdae
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

577
valkey-operatoralekcVerified publisher0.4.01 of 1See more

valkey-operator alekc 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/hyperspike/valkey-operator:v0.0.617d8c669f11a4
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.60.0
1.26.9

Open the chart page →

771
vault-operatoralekcVerified publisher1.26.21 of 1See more

vault-operator alekc 1.26.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-operator:v1.24.1b5529976f0f6
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

255
alertmanager-graph-bridgealertmanager-graph-bridge1.0.01 of 1See more

alertmanager-graph-bridge alertmanager-graph-bridge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/slauger/alertmanager-graph-bridge:1.0.0ccca112b6557
stdlib@go1.27.1
1.27.2

Open the chart page →

250
mautrix-signalalexanderbadel0.1.11 of 2See more

mautrix-signal alexanderbadel 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.26.9

Open the chart page →

3,401
pushproxalexmorbo-pushproxVerified publisher1.0.01 of 1See more

pushprox alexmorbo-pushprox 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
prometheuscommunity/pushprox:v0.2.02f32058f4fae
stdlib@go1.22.1
1.26.9

Open the chart page →

966
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/net@v0.17.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

1,659
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

2,104
rabbitmq-cluster-operatoralexmorbo-rabbitmq-cluster-operatorVerified publisher1.0.01 of 1See more

rabbitmq-cluster-operator alexmorbo-rabbitmq-cluster-operator 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/rabbitmqoperator/cluster-operator:2.22.52727b84b835a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

243
rabbitmq-messaging-topology-operatoralexmorbo-rabbitmq-messaging-topology-operatorVerified publisher1.0.11 of 1See more

rabbitmq-messaging-topology-operator alexmorbo-rabbitmq-messaging-topology-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/rabbitmqoperator/messaging-topology-operator:1.20.229174b668012
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

243
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.26.9

Open the chart page →

2,374
wireguardalexpressoVerified publisher0.1.71 of 2See more

wireguard alexpresso 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
linuxserver/wireguard:latest216ca1ce9da7
golang.org/x/net@v0.47.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

747

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
ambassador/ambassador-agent:1.0.227a1ea0d934fb
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.26.9
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
stdlib@go1.20.12
1.26.9
1
anchore/anchore-engine:v0.10.0bde9eedf639d
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.16.3
0.60.0
1.26.9
1
anchore/ecs-inventory:v1.5.12b424b3b9a03
stdlib@go1.26.8
1.26.9
1
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.60.0
1.26.9
1
anchore/kubernetes-admission-controller:v0.8.51a1a374658c8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.60.0
1.26.9
1
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.60.0
1.26.9
1
andreacioni/kube-workload-restarter:0.0.242938b310090a
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.60.0
1.26.9
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.26.9
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
stdlib@go1.18.2
1.26.9
1
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.26.9
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.26.9
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
golang.org/x/net@v0.58.0
stdlib@go1.25.7
0.60.0
1.26.9
1
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
antrea/antrea-ui-backend:v0.8.019f3c0113330
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
antrea/flow-aggregator:v2.7.0065193e7572f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.26.9
1
anujdatar/cups:25.07.01685df04a643b
stdlib@go1.19.8
1.26.9
1
apache/airflow:2.8.4-python3.964e58748b6b9
stdlib@go1.21.8
1.26.9
1
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
stdlib@go1.23.7
1.26.9
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
stdlib@go1.22.7
1.26.9
1
apache/airflow:2.8.1e5560ad0b86e
stdlib@go1.19.8
1.26.9
1
apache/answer:2.0.2a0d71b0e30a5
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
1
apache/apisix-dashboard:2.9.0c010ea7d1694
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.15
0.60.0
1.26.9
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.13.8
0.60.0
1.26.9
1
apache/camel-k:1.10.43bb13d14f64a
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.13
0.60.0
1.26.9
1
apache/camel-k:2.11.0d173e7efe258
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
1
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9
1
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.60.0
1.26.9
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.60.0
1.26.9
1
apache/solr-operator:v0.9.14db34508137f
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
1
apache/tika:3.3.1.090b7fa1dc018
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.60.0
1.26.9
1
apache/tika:latest-fullab9cc988828c
stdlib@go1.26.7
1.26.9
1
apache/yunikorn:scheduler-1.10.049fc54894fdf
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
apache/yunikorn:web-1.10.090e6a62a578a
stdlib@go1.26.7
1.26.9
1
apache/yunikorn:admission-1.10.095c6b951f38a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
apecloud/dt-platform:0.1.1d48bcbd38066
golang.org/x/net@v0.8.0
stdlib@go1.19.11
0.60.0
1.26.9
1
apecloud/gemini-scheduler:0.1.15832d1a9097a
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.60.0
1.26.9
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.60.0
1.26.9
1
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.13
0.60.0
1.26.9
1
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
1
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
stdlib@go1.19.6
0.60.0
1.26.9
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/net@v0.5.0
stdlib@go1.19.13
0.60.0
1.26.9
1
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/net@v0.40.0
stdlib@go1.25.7
0.60.0
1.26.9
1
appwrite/appwrite:2.3.034ef77fb6e87
golang.org/x/net@v0.51.0
stdlib@go1.26.8
0.60.0
1.26.9
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.