StackRadar

CVE-2026-78659

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4wvv-4gxm-pc68CGA-9hv5-59p6-4m49CGA-9mpv-qcf2-fr4cCGA-cmf5-g287-mphmCGA-ggmx-8j82-p2pfCGA-hmpr-chf9-7j4fDEBIAN-CVE-2026-78659GO-2026-6603
Also known as
CGA-2j9j-6w7w-x98q, CGA-32h2-ph4h-6j25, CGA-437c-v9xq-v77f, CGA-5cmh-mcx3-x7xj, CGA-62vw-6x79-rpw5, CGA-7fqm-wjjc-9pfc, CGA-7vrh-rfw7-r9f6, CGA-868g-cgmx-cvph, CGA-8r9c-282h-5mvw, CGA-ch5q-gfj4-q8gh, CGA-fwv6-mhj4-q3jf, CGA-gqw6-fwhv-jpf8, CGA-gw2c-84xv-m8g4, CGA-hcgj-v82p-m28j, CGA-j93h-pjfq-52jm, CGA-jj9f-32xw-j4r7, CGA-mqcg-6v5g-5xp3, CGA-mvr9-28rx-545x, CGA-pjc7-rhj8-2m9q, CGA-q38p-jqw6-276f, CGA-qq83-54q4-2pph, CGA-rhx4-wwr7-qfg4, CGA-v9h6-27pv-3g4r, CGA-w63p-h8hw-xp53, CGA-w7mj-m6pj-r2xq, CGA-wcf2-p3g3-gq3c
Trending
Rank 2 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
sftpgosftpgoOfficialVerified publisher0.48.01 of 1See more

sftpgo sftpgo 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
golang.org/x/net@v0.57.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

1,664
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

13,777
aws-cloudwatch-metricsaws0.0.111 of 1See more

aws-cloudwatch-metrics aws 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

2,163
zabbixcetic3.1.33 of 5See more

zabbix cetic 3.1.3

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:14c2427de38f99
stdlib@go1.24.6
1.26.9
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.1
0.60.0
1.26.9
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
stdlib@go1.18.1
1.26.9

Open the chart page →

37,373
chatwootchatwootVerified publisher2.0.272 of 3See more

chatwoot chatwoot 2.0.27

2 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.26.9
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
stdlib@go1.16.7
1.26.9

Open the chart page →

8,728
plugin-barman-cloudcloudnative-pgVerified publisher0.8.11 of 1See more

plugin-barman-cloud cloudnative-pg 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/plugin-barman-cloud:v0.15.1c75acad19a36
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

124
csi-driver-smbcsi-driver-smbVerified publisher1.20.35 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

5 of the 6 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

4,483
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

6,231
flux-operatorflux-operator0.61.01 of 1See more

flux-operator flux-operator 0.61.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/controlplaneio-fluxcd/flux-operator:v0.61.071041d9fff7f
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

135
gadgetgadgetOfficialVerified publisher0.56.11 of 1See more

gadget gadget 0.56.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/inspektor-gadget/inspektor-gadget:v0.56.1d1c34335183b
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

220
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.26.9

Open the chart page →

9,008
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
stdlib@go1.19.8
1.26.9

Open the chart page →

7,558
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
google/cloud-sdk:alpineef78619c8239
stdlib@go1.26.6
1.26.9

Open the chart page →

8,956
hpe-csi-driverhpe-storageVerified publisher3.3.013 of 14See more

hpe-csi-driver hpe-storage 3.3.0

13 of the 14 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/hpestorage/alletra-9000-primera-and-3par-csp:v3.3.0046215e41416
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/alletrastoragemp-b10000-nfs-csp:v1.3.0efaca660f9f0
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/alletrastoragemp-x10000-nfs-csp:v1.1.0043bb2ddb642
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/csi-driver:v3.3.0e58e22427b38
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/csi-extensions:v1.3.0df65cea35805
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-group-provisioner:v1.1.09ba017780f80
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-group-snapshotter:v1.1.0b26660528928
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-mutator:v1.4.03890d0b3aa89
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

4,179
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

3,042
cloudflaredkubitodevVerified publisher1.7.91 of 1See more

cloudflared kubitodev 1.7.9

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,968
trident-operatornetapp-tridentVerified publisher100.2606.21 of 1See more

trident-operator netapp-trident 100.2606.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
netapp/trident-operator:26.06.24cef5a737bcf
golang.org/x/net@v0.59.0
0.60.0

Open the chart page →

39
ngrok-operatorngrokOfficialVerified publisher0.24.02 of 2See more

ngrok-operator ngrok 0.24.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
ngrok/ngrok-operator:0.22.0db8e6fecc52c
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

444
openbaoopenbaoVerified publisher0.30.12 of 2See more

openbao openbao 0.30.1

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:1.7.2ae3d307658b7
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
quay.io/openbao/openbao:2.7.071156a1c6623
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,708
prometheus-snmp-exporterprometheus-communityOfficialVerified publisher9.18.11 of 1See more

prometheus-snmp-exporter prometheus-community 9.18.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

857
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9

Open the chart page →

6,887
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.7
0.60.0
1.26.9

Open the chart page →

3,104
trivytrivy-operator0.27.01 of 1See more

trivy trivy-operator 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
aquasec/trivy:0.75.0af6acf9a6b85
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

235
zotzot0.1.1281 of 1See more

zot zot 0.1.128

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/project-zot/zot:v2.1.2296cda11459ce
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

495
aws-ebs-csi-driveraws-ebs-csi-driver2.66.15 of 6See more

aws-ebs-csi-driver aws-ebs-csi-driver 2.66.1

5 of the 6 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/csi-components/csi-attacher:v4.12.0-eksbuild.9f8db68b6e3b3
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-node-driver-registrar:v2.17.0-eksbuild.89be2a65725f7
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-provisioner:v6.3.0-eksbuild.82fdf13756ccb
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-resizer:v2.2.1-eksbuild.7a2895cc5206d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.66.13ae75c8b0fdc
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

632
daskdask2024.1.11 of 2See more

dask dask 2024.1.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

14,274
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
golang.org/x/net@v0.35.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

3,751
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.60.0
1.26.9

Open the chart page →

9,156
netbirdjaconiVerified publisher0.15.14 of 4See more

netbird jaconi 0.15.1

4 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/golang:lateste0174e51e812
stdlib@go1.27.1
1.27.2
netbirdio/management:0.45.10c9994b393ea
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
netbirdio/relay:0.45.1872e3add0e1e
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
netbirdio/signal:0.45.146ce5a45538f
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9

Open the chart page →

10,263
k8upk8upVerified publisher4.10.01 of 1See more

k8up k8up 4.10.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.16.029458113b8b6
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,016
kube-starrockskube-starrocksOfficialVerified publisher1.11.71 of 1See more

kube-starrocks kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/net@v0.17.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

1,015
linkerd-jaegerlinkerd2Verified publisher30.12.112 of 4See more

linkerd-jaeger linkerd2 30.12.11

2 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.6
0.60.0
1.26.9
otel/opentelemetry-collector:0.59.0ee9da0b08d83
golang.org/x/net@v0.0.0-20220809184613-07c6da5e1ced
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

6,215
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest801a3dff7f6a
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:nojsonv2
0.60.0
1.27.2

Open the chart page →

2,177
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

15,239
renovate-operatormogenius6.4.02 of 2See more

renovate-operator mogenius 6.4.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/mogenius/renovate-operator:6.4.0e8f023764de4
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
registry.k8s.io/kubectl:v1.37.1b7cab618e281
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

282
argocdnicklasfrahm-argocdVerified publisher0.3.02 of 2See more

argocd nicklasfrahm-argocd 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.26.9
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
golang.org/x/net@v0.40.0
stdlib@go1.22.7
0.60.0
1.26.9

Open the chart page →

7,168
oneuptimeoneuptimeOfficialVerified publisher14.0.282 of 7See more

oneuptime oneuptime 14.0.28

2 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:latest74935e722416
stdlib@go1.24.6
1.26.9
oneuptime/runner:releasec2e5e54f0b2c
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

9,221
open-feature-operatoropen-feature-operatorOfficialVerified publisher0.9.31 of 1See more

open-feature-operator open-feature-operator 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/open-feature/open-feature-operator:v0.9.3b37a442c0497
golang.org/x/net@v0.52.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

315
postgres-operatorpostgres-operator2.0.31 of 1See more

postgres-operator postgres-operator 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v2.0.32d3a7ca3950f
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

205
telepresence-osstelepresence-ossOfficialVerified publisher2.32.21 of 2See more

telepresence-oss telepresence-oss 2.32.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/telepresenceio/tel2:2.32.296f5a0f413b1
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

924
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
stdlib@go1.17.1
1.26.9

Open the chart page →

7,334
karmawiremindVerified publisher2.13.11 of 1See more

karma wiremind 2.13.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/prymitive/karma:v0.13190a10c5c6793
stdlib@go1.26.3
1.26.9

Open the chart page →

310
yugabyteyugabyteVerified publisher2026.1.21 of 1See more

yugabyte yugabyte 2026.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
yugabytedb/yugabyte:2026.1.2.0-b137b6dba322c734
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

359
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

1,676
autheliaautheliaOfficialVerified publisher0.11.221 of 1See more

authelia authelia 0.11.22

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/authelia/authelia:4.39.248f428b06bb07
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

8,089
camel-kcamel-kVerified publisher2.11.01 of 1See more

camel-k camel-k 2.11.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
apache/camel-k:2.11.0d173e7efe258
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,782
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

6,661
falcosidekickfalcosecurity0.14.01 of 1See more

falcosidekick falcosecurity 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
falcosecurity/falcosidekick:2.32.01976da721518
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

2,275
flagsmithflagsmithOfficialVerified publisher0.83.01 of 4See more

flagsmith flagsmith 0.83.0

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,414

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
ethersphere/beekeeper:lateste3bc0da9ffde
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
1
ethersphere/ethproxy:latest3a8a3926caa2
stdlib@go1.18.7
1.26.9
1
ethersphere/onboarding-faucet:0.3.0513154aab230
stdlib@go1.18.2
1.26.9
1
ethpandaops/armiarma:master1a9c3264f0a9
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9
1
ethpandaops/assertoor:latest1efa2fba6711
golang.org/x/net@v0.56.0
stdlib@go1.25.11
0.60.0
1.26.9
1
ethpandaops/blob-me-baby:latestad26158420dd
stdlib@go1.20.1
1.26.9
1
ethpandaops/buildoor:maina04c231ce0e8
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
ethpandaops/cbt:latest99f52ce7bad8
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
1
ethpandaops/cbt-api:latestd60029a656db
golang.org/x/net@v0.52.0
stdlib@go1.26.3-X:jsonv2
0.60.0
1.26.9
1
ethpandaops/clickhouse-movoor:latestc0e6cc6542c1
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
ethpandaops/contributoor:latest1edd4074fd79
golang.org/x/net@v0.53.0
stdlib@go1.26.1
0.60.0
1.26.9
1
ethpandaops/dora:master13be067c3cf7
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
ethpandaops/dugtrio:1.0.0e261d1734e9f
golang.org/x/net@v0.10.0
stdlib@go1.21.4
0.60.0
1.26.9
1
ethpandaops/ethereum-address-metrics-exporter:latest431cd3790ed2
stdlib@go1.26.1
1.26.9
1
ethpandaops/ethereumjs:masterfb84b718500f
stdlib@go1.23.12
1.26.9
1
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.10
0.60.0
1.26.9
1
ethpandaops/ethereum-validator-metrics-exporter:latest38448e9d4aef
stdlib@go1.19.10
1.26.9
1
ethpandaops/execution-processor:latest5c4832e9588f
stdlib@go1.25.4
1.26.9
1
ethpandaops/forky:debian-latestc937f4ba737c
golang.org/x/net@v0.52.0
stdlib@go1.26.4
0.60.0
1.26.9
1
ethpandaops/panda-pulse:latestad6fc3b3e6b8
stdlib@go1.26.1
1.26.9
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
golang.org/x/net@v0.43.0
stdlib@go1.25.12
0.60.0
1.26.9
1
ethpandaops/service-authenticatoor:main27b8e5ea3125
stdlib@go1.25.12
1.26.9
1
ethpandaops/slashoor:latesta71967db581f
stdlib@go1.23.12
1.26.9
1
ethpandaops/spamoor:latestc8c6ab0816c4
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
ethpandaops/splitoor:latest989da6bea4bd
golang.org/x/net@v0.38.0
stdlib@go1.26.1
0.60.0
1.26.9
1
ethpandaops/stubbies:latest9f1d6aec0d04
stdlib@go1.19.8
1.26.9
1
ethpandaops/xatu-cbt-api:latestf7dec2e07091
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9
1
evcc/evcc:0.317.042bf170708f9
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
evcc/evcc:0.300.8ddf2a25afce5
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9
1
everpcpc/channels:latestb378d137ae8b
stdlib@go1.17
1.26.9
1
evoapicloud/evolution-api:latest966625532d90
stdlib@go1.23.12
1.26.9
1
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.3
0.60.0
1.26.9
1
factly/dega-api:0.15.166fafc7b0a17
stdlib@go1.16.2
1.26.9
1
factly/dega-server:0.15.194d21479382e
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.2
0.60.0
1.26.9
1
factly/kavach-server:0.22.3be85ff1b9bd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.2
0.60.0
1.26.9
1
factly/mande-server:0.34.1384d384310ef
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
1
factly/vidcheck-server:0.12.087064eb0463c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.14.2
0.60.0
1.26.9
1
falcosecurity/event-generator:latest932956d86c99
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
1
falcosecurity/falco:0.45.0788f1129c542
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
falcosecurity/falcoctl:0.14.290ba9627886e
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
falcosecurity/falco-driver-loader:0.45.0d7d287d4dcee
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
falcosecurity/falco-operator:0.4.18a99fcc57a57
golang.org/x/net@v0.53.0
stdlib@go1.26.0
0.60.0
1.26.9
1
falcosecurity/falcosidekick:2.32.01976da721518
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9
1
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.18.1
0.60.0
1.26.9
1
falcosecurity/k8s-metacollector:0.1.42c9b17ec36e8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
farmer1992/sshpiperd:v1.6.19ddc25422cc2
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
1
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9
1
favonia/cloudflare-ddns:15e61736b982b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
featureformcom/quickstart-loader:latest82396f8fb5e8
stdlib@go1.21.11
1.26.9
1
federid/webhook:0.1.0fbfb7c6510a7
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.