StackRadar

CVE-2026-78659

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4wvv-4gxm-pc68CGA-9hv5-59p6-4m49CGA-9mpv-qcf2-fr4cCGA-cmf5-g287-mphmCGA-ggmx-8j82-p2pfCGA-hmpr-chf9-7j4fDEBIAN-CVE-2026-78659GO-2026-6603
Also known as
CGA-2j9j-6w7w-x98q, CGA-32h2-ph4h-6j25, CGA-437c-v9xq-v77f, CGA-5cmh-mcx3-x7xj, CGA-62vw-6x79-rpw5, CGA-7fqm-wjjc-9pfc, CGA-7vrh-rfw7-r9f6, CGA-868g-cgmx-cvph, CGA-8r9c-282h-5mvw, CGA-ch5q-gfj4-q8gh, CGA-fwv6-mhj4-q3jf, CGA-gqw6-fwhv-jpf8, CGA-gw2c-84xv-m8g4, CGA-hcgj-v82p-m28j, CGA-j93h-pjfq-52jm, CGA-jj9f-32xw-j4r7, CGA-mqcg-6v5g-5xp3, CGA-mvr9-28rx-545x, CGA-pjc7-rhj8-2m9q, CGA-q38p-jqw6-276f, CGA-qq83-54q4-2pph, CGA-rhx4-wwr7-qfg4, CGA-v9h6-27pv-3g4r, CGA-w63p-h8hw-xp53, CGA-w7mj-m6pj-r2xq, CGA-wcf2-p3g3-gq3c
Trending
Rank 2 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
krateo-frontendkrateo2.4.21 of 1See more

krateo-frontend krateo 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/krateo-frontend:2.4.26aff913c8bfe
stdlib@go1.23.8
1.26.9

Open the chart page →

3,839
kserve-controllerkrateo1.0.01 of 1See more

kserve-controller krateo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/kserve-controller:1.0.05683c5ae670e
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

667
kube-bridgekrateo1.0.01 of 1See more

kube-bridge krateo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/kube-bridge:1.0.0839e6b3f1a33
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18
0.60.0
1.26.9

Open the chart page →

2,428
logs-presenterkrateo0.1.01 of 1See more

logs-presenter krateo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/logs-presenter:0.1.0c52fa557d1d0
golang.org/x/net@v0.51.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

542
mlflow-providerkrateo0.0.31 of 1See more

mlflow-provider krateo 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/mlflow-rest-dynamic-controller-plugin:0.0.31106a62d1c06
golang.org/x/net@v0.23.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

985
mlflow-provider-kogkrateo0.0.71 of 1See more

mlflow-provider-kog krateo 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/mlflow-rest-dynamic-controller-plugin:0.0.7887968d0ba9c
golang.org/x/net@v0.23.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

985
oasgen-providerkrateo0.11.11 of 1See more

oasgen-provider krateo 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/oasgen-provider:0.10.0656ec60c6407
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

5,554
opa-kube-mgmtkrateo0.2.32 of 2See more

opa-kube-mgmt krateo 0.2.3

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/kube-mgmt:9.0.1482a00656c34
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.60.0
1.26.9
ghcr.io/krateoplatformops/opa:1.4.2-static3c995dc8a59f
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

2,638
opentofu-providerkrateo1.1.01 of 1See more

opentofu-provider krateo 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/opentofu-provider:1.1.09fa6736c91f2
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,111
patch-providerkrateo1.0.11 of 1See more

patch-provider krateo 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/patch-provider:1.0.00924cf45a3e9
golang.org/x/net@v0.27.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,111
resources-ingesterkrateo1.1.01 of 1See more

resources-ingester krateo 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/resources-ingester:1.1.0534777443059
golang.org/x/net@v0.52.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

813
resources-presenterkrateo0.10.41 of 1See more

resources-presenter krateo 0.10.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/resources-presenter:0.10.44900c4644aed
golang.org/x/net@v0.52.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

444
resource-tree-handlerkrateo0.3.01 of 1See more

resource-tree-handler krateo 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/resource-tree-handler:0.3.0e4bc3216769e
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,176
smitherykrateo0.10.11 of 1See more

smithery krateo 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/smithery:0.10.181a28a5959e0
golang.org/x/net@v0.38.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

1,705
snowplowkrateo0.20.71 of 1See more

snowplow krateo 0.20.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/snowplow:0.20.76aa36cff9bb7
golang.org/x/net@v0.38.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

756
status-informerkrateo0.1.11 of 1See more

status-informer krateo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/status-informer:0.1.14a8b40f4a050
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.60.0
1.26.9

Open the chart page →

1,978
sweeperkrateo0.2.12 of 2See more

sweeper krateo 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
alpine/kubectl:1.36.01ee9df6316d4
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9
ghcr.io/krateoplatformops/eventstack/sweeper:0.1.05d5e24119ff1
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

2,336
terraform-servicekrateo0.1.101 of 1See more

terraform-service krateo 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/terraform-service:0.1.105e731a23e703
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.60.0
1.26.9

Open the chart page →

3,849
vcluster-k8skrateo0.19.64 of 4See more

vcluster-k8s krateo 0.19.6

4 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/ghcr.io/loft-sh/vcluster:0.19.68849703f0ff8
golang.org/x/net@v0.17.0
stdlib@go1.22.4
0.60.0
1.26.9
ghcr.io/krateoplatformops/registry.k8s.io/etcd:3.5.10-03486c0f32467
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
ghcr.io/krateoplatformops/registry.k8s.io/kube-apiserver:v1.29.086076b5576c7
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/krateoplatformops/registry.k8s.io/kube-controller-manager:v1.29.067b0ece5573e
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

8,669
vm-azurekrateo0.1.21 of 1See more

vm-azure krateo 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/kubectl:1.32.0d69cd9c163db
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,796
krokro0.9.41 of 1See more

kro kro 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/kro/kro:v0.9.4eaf9fbaddd9d
golang.org/x/net@v0.58.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

363
kubeflowkromanow94-kubeflow0.5.117 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

17 of the 30 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
kubeflow/model-registry:v0.2.95783f6db428f
golang.org/x/net@v0.28.0
stdlib@go1.21.13
0.60.0
1.26.9
kubeflow/training-operator:v1-04f9f13dabb76dbda29
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
kubeflowkatib/katib-controller:v0.17.072f14e03b9e1
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
kubeflowkatib/katib-db-manager:v0.17.0916a7695b0dd
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
kubeflowkatib/katib-ui:v0.17.07a41c508deb1
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
kubeflownotebookswg/kfam:v1.9.22060a2ede788
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/poddefaults-webhook:v1.9.2bde88d98ad74
golang.org/x/net@v0.13.0
stdlib@go1.21.13
0.60.0
1.26.9
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/pvcviewer-controller:v1.9.29815e9b1728f
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9
kubeflownotebookswg/tensorboard-controller:v1.9.26536a9f61193
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.60.0
1.26.9
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9

Open the chart page →

86,921
kron-aapm-sidecarkron-aapm-sidecar1.1.01 of 1See more

kron-aapm-sidecar kron-aapm-sidecar 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.60.0
1.26.9

Open the chart page →

3,096
adventureworkskronkltdVerified publisher0.1.01 of 1See more

adventureworks kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
chriseaton/adventureworks:latest54c3384ce701
stdlib@go1.23.1
1.26.9

Open the chart page →

5,385
lndkronkltdVerified publisher0.3.93 of 4See more

lnd kronkltd 0.3.9

3 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.1
0.60.0
1.26.9
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.60.0
1.26.9
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

12,049
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
stdlib@go1.20.13
1.26.9

Open the chart page →

11,961
world-dbkronkltdVerified publisher0.1.01 of 1See more

world-db kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghusta/postgres-world-db:latest879d0919fdcc
stdlib@go1.24.6
1.26.9

Open the chart page →

2,424
kron-aapm-sidecarkron-pam-aapm-helmcharts1.2.71 of 1See more

kron-aapm-sidecar kron-pam-aapm-helmcharts 1.2.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.2.18b42fad987b3
golang.org/x/net@v0.57.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

536
casdoorkrzwiatrzyk1.0.01 of 1See more

casdoor krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
casbin/casdoor:v1.224.066f836ef778b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.5
0.60.0
1.26.9

Open the chart page →

4,724
nocodbkrzwiatrzyk0.0.11 of 1See more

nocodb krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
nocodb/nocodb:0.100.2b0b91ec2a2dd
golang.org/x/net@v0.0.0-20220805013720-a33c5aa5df48
stdlib@go1.18.2
0.60.0
1.26.9

Open the chart page →

3,314
pipecdkrzwiatrzyk0.39.01 of 3See more

pipecd krzwiatrzyk 0.39.0

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.6
0.60.0
1.26.9

Open the chart page →

5,092
postgresql-backup-to-miniokrzwiatrzyk0.0.11 of 2See more

postgresql-backup-to-minio krzwiatrzyk 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.26.9

Open the chart page →

3,716
traggokrzwiatrzyk1.0.01 of 1See more

traggo krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
traggo/server:0.2.3f1ced637510e
stdlib@go1.13.1
1.26.9

Open the chart page →

3,036
ksoc-pluginsksocOfficialVerified publisher1.9.105 of 5See more

ksoc-plugins ksoc 1.9.10

5 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/n8h5y2v5/rad-security/rad-bootstrapper:v1.1.115ca2d500d374
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/n8h5y2v5/rad-security/rad-guard:v1.1.17a94d2d4aae85
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/n8h5y2v5/rad-security/rad-sync:v1.1.1514f3dfbc0225
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/n8h5y2v5/rad-security/rad-watch:v1.1.25b9a7d6bc2a0c
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

5,896
authorino-operatorkuadrantOfficialVerified publisher0.27.01 of 1See more

authorino-operator kuadrant 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/kuadrant/authorino-operator:v0.27.02f1802c0f8d0
golang.org/x/net@v0.55.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

271
dns-operatorkuadrantOfficialVerified publisher0.18.01 of 1See more

dns-operator kuadrant 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/kuadrant/dns-operator:v0.18.0bda96d422195
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

242
limitador-operatorkuadrantOfficialVerified publisher0.19.01 of 1See more

limitador-operator kuadrant 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/kuadrant/limitador-operator:v0.19.09d55a070ba54
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

201
kubeadapt-k8s-pulsekubeadaptVerified publisher1.0.21 of 1See more

kubeadapt-k8s-pulse kubeadapt 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
stdlib@go1.25.9
1.26.9

Open the chart page →

2,961
kubearmor-operatorkubearmor1.7.51 of 1See more

kubearmor-operator kubearmor 1.7.5

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kubearmor/kubearmor-operator:v1.7.5f5d21795c0d7
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

243
sidekickkubearmor0.1.01 of 1See more

sidekick kubearmor 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kubearmor/sidekick:latestb7b92a447f15
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

2,651
bc-depositorykubebb0.0.31 of 1See more

bc-depository kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

2,738
bc-explorerkubebb0.0.31 of 1See more

bc-explorer kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

2,738
chartmuseumkubebb3.10.21 of 1See more

chartmuseum kubebb 3.10.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

3,018
cluster-componentkubebb0.2.24 of 4See more

cluster-component kubebb 0.2.2

4 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
kubebb/cert-manager-controller:v1.8.020509de4b399
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.60.0
1.26.9

Open the chart page →

12,302
fabric-operatorkubebb0.1.01 of 1See more

fabric-operator kubebb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.4
0.60.0
1.26.9

Open the chart page →

4,955
ingress-nginxkubebb4.7.02 of 2See more

ingress-nginx kubebb 4.7.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
golang.org/x/net@v0.10.0
stdlib@go1.20.1
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9

Open the chart page →

4,642
kubebbkubebb0.0.11 of 1See more

kubebb kubebb 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kubebb/core:lateste366c34a9b8d
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9

Open the chart page →

2,435
kubebb-corekubebb0.1.271 of 1See more

kubebb-core kubebb 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kubebb/core:v0.1.62b9e7f451d6b
golang.org/x/net@v0.14.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

2,629
miniokubebb5.0.102 of 2See more

minio kubebb 5.0.10

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

9,468
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kubebb/mesh-operator:v5.7.0163ebbfc7a82
golang.org/x/net@v0.7.0
stdlib@go1.18.4
0.60.0
1.26.9

Open the chart page →

7,515

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0:v2.8.1f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
6
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
5
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9
5
containous/whoami:latest:v1.5.07d6a3c8f9147
stdlib@go1.14
1.26.9
5
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
5
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.60.0
1.26.9
5
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
5
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.60.0
1.26.9
5
grafana/tempo:2.9.065a578975943
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9
5
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
5
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.26.9
5
library/mysql:26.7.0:latestade067ae2fb1
stdlib@go1.24.6
1.26.9
5
library/postgres:172d2b8998d310
stdlib@go1.24.6
1.26.9
5
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.26.9
5
library/redis:7.4.2-alpine:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.26.9
5
library/redis:5:5.0fc5ecd863862
stdlib@go1.16.7
1.26.9
5
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.60.0
1.26.9
5
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9
5
rancher/rancher:v2.15.20c3d8e570255
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9
5
rancher/shell:v0.8.21eeed72d4eda
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
5
sigma2as/goidc-proxy:next656ac798963a
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.60.0
1.26.9
5
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
5
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.26.9
5
ghcr.io/paperless-ngx/paperless-ngx:3.3.06b94799bc769
stdlib@go1.24.4
1.26.9
5
ghcr.io/quenchworks/images/prometheusa9dc21133c23
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.60.0
1.26.9
5
quay.io/prometheus/mysqld-exporter:latest:v0.20.0abed8dac117b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
5
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
5
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9
5
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
5
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.60.0
1.26.9
5
adguard/adguardhome:v0.107.79aba9e3bf0613
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
4
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.26.9
4
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.26.9
4
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.26.9
4

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.