StackRadar

CVE-2026-78659

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4wvv-4gxm-pc68CGA-9hv5-59p6-4m49CGA-9mpv-qcf2-fr4cCGA-cmf5-g287-mphmCGA-ggmx-8j82-p2pfCGA-hmpr-chf9-7j4fDEBIAN-CVE-2026-78659GO-2026-6603
Also known as
CGA-2j9j-6w7w-x98q, CGA-32h2-ph4h-6j25, CGA-437c-v9xq-v77f, CGA-5cmh-mcx3-x7xj, CGA-62vw-6x79-rpw5, CGA-7fqm-wjjc-9pfc, CGA-7vrh-rfw7-r9f6, CGA-868g-cgmx-cvph, CGA-8r9c-282h-5mvw, CGA-ch5q-gfj4-q8gh, CGA-fwv6-mhj4-q3jf, CGA-gqw6-fwhv-jpf8, CGA-gw2c-84xv-m8g4, CGA-hcgj-v82p-m28j, CGA-j93h-pjfq-52jm, CGA-jj9f-32xw-j4r7, CGA-mqcg-6v5g-5xp3, CGA-mvr9-28rx-545x, CGA-pjc7-rhj8-2m9q, CGA-q38p-jqw6-276f, CGA-qq83-54q4-2pph, CGA-rhx4-wwr7-qfg4, CGA-v9h6-27pv-3g4r, CGA-w63p-h8hw-xp53, CGA-w7mj-m6pj-r2xq, CGA-wcf2-p3g3-gq3c
Trending
Rank 2 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/net@v0.10.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

3,583
yatai-image-builderbentomlVerified publisher3.0.441 of 1See more

yatai-image-builder bentoml 3.0.44

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-image-builder:3.0.4401d8538c4f48
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

819
betterdb-monitorbetterdb-monitorOfficialVerified publisher0.49.01 of 1See more

betterdb-monitor betterdb-monitor 0.49.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
betterdb/monitor:0.49.0-no-ai97dcd2d2192f
stdlib@go1.26.8
1.26.9

Open the chart page →

549
aramid-indexerbiatec-repoVerified publisher3.9.04 of 5See more

aramid-indexer biatec-repo 3.9.0

4 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:14c2427de38f99
stdlib@go1.24.6
1.26.9
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.60.0
1.26.9
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

16,834
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

8,296
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
golang.org/x/net@v0.39.0
stdlib@go1.23.11
0.60.0
1.26.9

Open the chart page →

6,109
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

8,296
self-hostbitwarden2.5.110 of 11See more

self-host bitwarden 2.5.1

10 of the 11 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/bitwarden/admin:2026.9.2e82f37409cce
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/api:2026.9.272abdfb33c83
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/attachments:2026.9.2a3e09f120b64
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/events:2026.9.2818a1d907fc4
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/icons:2026.9.25e23eaab3976
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/identity:2026.9.263037d60f7d8
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/notifications:2026.9.2029f0d8a576f
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/sso:2026.9.23ef058df2039
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/web:2026.9.10d9b5f239cb8
stdlib@go1.26.5
1.26.9
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
stdlib@go1.23.1
1.26.9

Open the chart page →

5,625
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
stdlib@go1.21.6
1.26.9

Open the chart page →

3,580
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

2,195
syncthingbrandan-schmitz-helm-chartsVerified publisher2.1.01 of 1See more

syncthing brandan-schmitz-helm-charts 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
syncthing/syncthing:2.1.1775c4aac4862
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,466
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,722
btrfs-nfs-csibtrfs-nfs-csi0.4.07 of 7See more

btrfs-nfs-csi btrfs-nfs-csi 0.4.0

7 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/erikmagkekse/btrfs-nfs-csi:0.12.0cb29d9b801a5
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

5,524
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

2,842
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.60.0
1.26.9

Open the chart page →

3,842
buildkite-agent-metricsbuildkite-agent-metrics0.1.01 of 1See more

buildkite-agent-metrics buildkite-agent-metrics 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

1,995
buildkit-fleetbuildkit-fleetVerified publisher0.1.21 of 1See more

buildkit-fleet buildkit-fleet 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
moby/buildkit:v0.33.0-rootless80b15f0735e8
golang.org/x/net@v0.43.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,261
static-httpserverbyjgVerified publisher0.3.11 of 1See more

static-httpserver byjg 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
byjg/static-httpserver:0.5.1bed29f3f45e8
stdlib@go1.26.8
1.26.9

Open the chart page →

102
nacosbytectl0.1.61 of 1See more

nacos bytectl 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.26.9

Open the chart page →

2,569
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

2,179
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

2,179
pgcagriekinVerified publisher2.4.11 of 2See more

pg cagriekin 2.4.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.1.0-pg18111ccc617ce7
golang.org/x/net@v0.58.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

2,247
pgvectorcagriekinVerified publisher2.4.12 of 3See more

pgvector cagriekin 2.4.1

2 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.1.0-pg18111ccc617ce7
golang.org/x/net@v0.58.0
stdlib@go1.25.12
0.60.0
1.26.9
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
stdlib@go1.24.6
1.26.9

Open the chart page →

4,670
camel-dashboard-operatorcamel-dashboardVerified publisher0.1.01 of 1See more

camel-dashboard-operator camel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

851
camel-monitor-operatorcamel-dashboardVerified publisher0.2.11 of 1See more

camel-monitor-operator camel-dashboard 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/camel-tooling/camel-monitor-operator:latest6a2e094f9cc2
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9

Open the chart page →

1,426
camunda-operatorcamunda-operatorVerified publisher0.2.01 of 1See more

camunda-operator camunda-operator 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/konsole-is/camunda-operator:0.2.0c06f61af7b3c
golang.org/x/net@v0.58.0
0.60.0

Open the chart page →

39
capsulecapsuleOfficialVerified publisher0.14.62 of 2See more

capsule capsule 0.14.6

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,920
capsule-proxycapsule-proxyOfficialVerified publisher0.15.02 of 2See more

capsule-proxy capsule-proxy 0.15.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/projectcapsule/capsule-proxy:v0.15.0233c41fe7229
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,727
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

4,689
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/net@v0.27.0
stdlib@go1.23.0
0.60.0
1.26.9

Open the chart page →

2,304
cert-estuarycert-estuaryVerified publisher0.2.11 of 1See more

cert-estuary cert-estuary 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/hsn723/cert-estuary:0.2.00c4b6132b0ad
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

551
cert-manager-approver-policycert-managerOfficialVerified publisher0.28.01 of 1See more

cert-manager-approver-policy cert-manager 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-approver-policy:v0.28.01a955b0a5c41
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
cert-manager-google-cas-issuercert-managerOfficialVerified publisher0.13.01 of 1See more

cert-manager-google-cas-issuer cert-manager 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-google-cas-issuer:v0.13.00d6a852d7c6a
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9

Open the chart page →

16,666
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/net@v0.9.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,549
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
golang.org/x/net@v0.26.0
stdlib@go1.22.0
0.60.0
1.26.9

Open the chart page →

1,624
cert-manager-webhook-ionos-cloudcert-manager-webhook-ionos-cloudVerified publisher0.3.41 of 1See more

cert-manager-webhook-ionos-cloud cert-manager-webhook-ionos-cloud 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/ionos-cloud/cert-manager-webhook-ionos-cloud:v1.0.46860c5df73f1
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

153
cert-manager-webhook-porkbuncert-manager-webhook-porkbunVerified publisher2.0.71 of 1See more

cert-manager-webhook-porkbun cert-manager-webhook-porkbun 2.0.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/octabits-io/cert-manager-webhook-porkbun:2.0.7ab5e9a28a30a
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

136
cert-vaultcert-vaultOfficialVerified publisher2.12.04 of 7See more

cert-vault cert-vault 2.12.0

4 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/net@v0.33.0
stdlib@go1.23.7
0.60.0
1.26.9
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
stdlib@go1.23.7
1.26.9
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.26.9
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

18,875
chatclichatcliVerified publisher1.215.21See more

chatcli chatcli 1.215.2

1 container image this version deploys carries CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/net@v0.26.0
stdlib@go1.23.10
0.60.0
1.26.9

Open the chart page →

—
chatcli-operatorchatcli-operatorVerified publisher1.215.21See more

chatcli-operator chatcli-operator 1.215.2

1 container image this version deploys carries CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/net@v0.26.0
stdlib@go1.23.10
0.60.0
1.26.9

Open the chart page →

—
etcd-defragchristianhuthVerified publisher1.6.21 of 1See more

etcd-defrag christianhuth 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.7.2e9afa62b1e91
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

161
passbolt-hachristianhuthVerified publisher6.0.13 of 4See more

passbolt-ha christianhuth 6.0.1

3 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.26.9
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.26.9

Open the chart page →

14,475
shlink-backendchristianhuthVerified publisher11.12.21 of 1See more

shlink-backend christianhuth 11.12.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
shlinkio/shlink:5.1.7844e1f2b6455
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

583
squestchristianhuthVerified publisher6.6.82 of 4See more

squest christianhuth 6.6.8

2 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.26.9
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9

Open the chart page →

12,227
syncstorage-rschristianhuthVerified publisher6.1.11 of 2See more

syncstorage-rs christianhuth 6.1.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9

Open the chart page →

1,124
typo3christianhuthVerified publisher7.8.11 of 2See more

typo3 christianhuth 7.8.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.26.9

Open the chart page →

10,080
challengerchronicleVerified publisher0.1.21 of 1See more

challenger chronicle 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
stdlib@go1.22.12
1.26.9

Open the chart page →

1,337
erpcchronicleVerified publisher0.7.11 of 1See more

erpc chronicle 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/erpc/erpc:0.1.18bfed3d49a08
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

603

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.5
0.60.0
1.26.9
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.60.0
1.26.9
1
dellnoantechnp/cloudeye-exporter:v2.0.316873356c882d
stdlib@go1.19.6
1.26.9
1
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
1
deluan/navidrome:0.50.02cf4442b0099
golang.org/x/net@v0.18.0
stdlib@go1.21.0
0.60.0
1.26.9
1
deluan/navidrome:0.64.238dc2727bfcf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9
1
deluan/navidrome:0.61.29fa40b3d8dec
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
1
deluan/navidrome:0.41.1fc4d8b6ad9f9
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.60.0
1.26.9
1
denniswitt/yas3p:0.2.488a235619af6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
1
derailed/popeye:v0.21.363b2d2a8f674
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.60.0
1.26.9
1
devopsfaith/krakend:2.6.34c678c224f67
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.60.0
1.26.9
1
devopsfaith/krakend:2.7.09219cda867e2
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
1
devopstales/trivy-operator:2.575136aa7a26e
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.60.0
1.26.9
1
devsecurely/cview-issuer:0.0.4335675bd31bfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.60.0
1.26.9
1
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.7
0.60.0
1.26.9
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
golang.org/x/net@v0.35.0
stdlib@go1.22.12
0.60.0
1.26.9
1
dgraph/ratel:v25.0.34cae1ff95027
stdlib@go1.23.10
1.26.9
1
digitalocean/ceph_exporter:latest3ba058e9a48d
stdlib@go1.20
1.26.9
1
digitalocean/do-operator:v0.1.65e5deb4db76e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18.10
0.60.0
1.26.9
1
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
stdlib@go1.18.7
1.26.9
1
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
stdlib@go1.18.7
1.26.9
1
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.15.8
0.60.0
1.26.9
1
directus/directus:12.0.29c8470ea465c
stdlib@go1.23.12
1.26.9
1
directus/directus:11.1.0e3c8bb975350
stdlib@go1.20.7
1.26.9
1
distribution/distribution:3.1.1bca24727f400
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
1
distribution/distribution:2.8.3f84b2078238f
stdlib@go1.20.8
1.26.9
1
djjudas21/nova-exporter:0.0.10e9094580885c
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.60.0
1.26.9
1
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.60.0
1.26.9
1
dnsforge/xteve:latest4d9a685c8c28
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.16.2
0.60.0
1.26.9
1
dobtc/bitcoin:25.1a870f7cb1105
stdlib@go1.19.8
1.26.9
1
dockerdaemon0901/rolldice:v14e5bfe179c7e
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.60.0
1.26.9
1
documenso/documenso:v1.8.17f16a9449f18
stdlib@go1.20.12
1.26.9
1
dollarshaveclub/furan2:master14a257836529
golang.org/x/net@v0.0.0-20201002202402-0a1ea396d57c
stdlib@go1.17.2
0.60.0
1.26.9
1
dollarshaveclub/thermite:0.0.31663cbf25fcfe
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.1
0.60.0
1.26.9
1
don616/k8s-file-explorer-backend:v1.8.13e228fadb3a8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
donetick/donetick:v0.1.79a1cc21dd5a37
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.60.0
1.26.9
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
golang.org/x/net@v0.11.0
stdlib@go1.19.12
0.60.0
1.26.9
1
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9
1
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9
1
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
golang.org/x/net@v0.7.0
stdlib@go1.19.9
0.60.0
1.26.9
1
dongjiang1989/lxcfs-webhook:latestc1f19557bdcb
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9
1
dongjiang1989/node-metrics:latest3f1f266190bb
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
1
dongjiang1989/ns-node-affinity:latest451f7823723c
golang.org/x/net@v0.7.0
stdlib@go1.18.5
0.60.0
1.26.9
1
dongjiang1989/pingmesh-agent:latest355fa4be8e97
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.60.0
1.26.9
1
dongjiang1989/pingmesh-agent:v1.2.2c82de0272da0
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.60.0
1.26.9
1
doorcloud/apim-operator:v3.0.44e6ef8d72c3e
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.60.0
1.26.9
1
dossif/redminebot:0.2.296dcd2c0e9f2
stdlib@go1.17.13
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.