StackRadar

CVE-2026-78659

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4wvv-4gxm-pc68CGA-9hv5-59p6-4m49CGA-9mpv-qcf2-fr4cCGA-cmf5-g287-mphmCGA-ggmx-8j82-p2pfCGA-hmpr-chf9-7j4fDEBIAN-CVE-2026-78659GO-2026-6603
Also known as
CGA-2j9j-6w7w-x98q, CGA-32h2-ph4h-6j25, CGA-437c-v9xq-v77f, CGA-5cmh-mcx3-x7xj, CGA-62vw-6x79-rpw5, CGA-7fqm-wjjc-9pfc, CGA-7vrh-rfw7-r9f6, CGA-868g-cgmx-cvph, CGA-8r9c-282h-5mvw, CGA-ch5q-gfj4-q8gh, CGA-fwv6-mhj4-q3jf, CGA-gqw6-fwhv-jpf8, CGA-gw2c-84xv-m8g4, CGA-hcgj-v82p-m28j, CGA-j93h-pjfq-52jm, CGA-jj9f-32xw-j4r7, CGA-mqcg-6v5g-5xp3, CGA-mvr9-28rx-545x, CGA-pjc7-rhj8-2m9q, CGA-q38p-jqw6-276f, CGA-qq83-54q4-2pph, CGA-rhx4-wwr7-qfg4, CGA-v9h6-27pv-3g4r, CGA-w63p-h8hw-xp53, CGA-w7mj-m6pj-r2xq, CGA-wcf2-p3g3-gq3c
Trending
Rank 2 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
vault-unsealbabykart-helm-chartsVerified publisher1.0.51 of 1See more

vault-unseal babykart-helm-charts 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/lrstanley/vault-unseal:1.0.1dd873930b6df
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

479
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

6,070
music-assistantbdclark-helm-chartsVerified publisher0.4.131 of 1See more

music-assistant bdclark-helm-charts 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.3885872224fa5
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

4,873
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.8
0.60.0
1.26.9
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.17.5
0.60.0
1.26.9
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

10,956
livekit-serverbeeinventor1.0.01 of 2See more

livekit-server beeinventor 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.10
0.60.0
1.26.9

Open the chart page →

3,843
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.60.0
1.26.9

Open the chart page →

2,500
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/net@v0.10.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

3,659
yatai-image-builderbentomlVerified publisher3.0.441 of 1See more

yatai-image-builder bentoml 3.0.44

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-image-builder:3.0.4401d8538c4f48
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

896
betterdb-monitorbetterdb-monitorOfficialVerified publisher0.49.01 of 1See more

betterdb-monitor betterdb-monitor 0.49.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
betterdb/monitor:0.49.0-no-ai97dcd2d2192f
stdlib@go1.26.8
1.26.9

Open the chart page →

601
aramid-indexerbiatec-repoVerified publisher3.9.04 of 5See more

aramid-indexer biatec-repo 3.9.0

4 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:14c2427de38f99
stdlib@go1.24.6
1.26.9
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.60.0
1.26.9
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

17,129
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

8,373
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
golang.org/x/net@v0.39.0
stdlib@go1.23.11
0.60.0
1.26.9

Open the chart page →

6,187
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

8,373
self-hostbitwarden2.5.110 of 11See more

self-host bitwarden 2.5.1

10 of the 11 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/bitwarden/admin:2026.9.2e82f37409cce
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/api:2026.9.272abdfb33c83
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/attachments:2026.9.2a3e09f120b64
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/events:2026.9.2818a1d907fc4
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/icons:2026.9.25e23eaab3976
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/identity:2026.9.263037d60f7d8
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/notifications:2026.9.2029f0d8a576f
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/sso:2026.9.23ef058df2039
stdlib@go1.26.5
1.26.9
ghcr.io/bitwarden/web:2026.9.10d9b5f239cb8
stdlib@go1.26.5
1.26.9
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
stdlib@go1.23.1
1.26.9

Open the chart page →

6,133
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
stdlib@go1.21.6
1.26.9

Open the chart page →

3,644
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

2,272
syncthingbrandan-schmitz-helm-chartsVerified publisher2.1.01 of 1See more

syncthing brandan-schmitz-helm-charts 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
syncthing/syncthing:2.1.1775c4aac4862
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,541
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,799
btrfs-nfs-csibtrfs-nfs-csi0.4.07 of 7See more

btrfs-nfs-csi btrfs-nfs-csi 0.4.0

7 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/erikmagkekse/btrfs-nfs-csi:0.12.0cb29d9b801a5
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

6,059
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

2,918
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.60.0
1.26.9

Open the chart page →

3,918
buildkite-agent-metricsbuildkite-agent-metrics0.1.01 of 1See more

buildkite-agent-metrics buildkite-agent-metrics 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

2,072
buildkit-fleetbuildkit-fleetVerified publisher0.1.21 of 1See more

buildkit-fleet buildkit-fleet 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
moby/buildkit:v0.33.0-rootless80b15f0735e8
golang.org/x/net@v0.43.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,338
static-httpserverbyjgVerified publisher0.3.11 of 1See more

static-httpserver byjg 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
byjg/static-httpserver:0.5.1bed29f3f45e8
stdlib@go1.26.8
1.26.9

Open the chart page →

153
nacosbytectl0.1.61 of 1See more

nacos bytectl 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.26.9

Open the chart page →

2,620
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

2,269
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

2,269
pgcagriekinVerified publisher2.4.11 of 2See more

pg cagriekin 2.4.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.1.0-pg18111ccc617ce7
golang.org/x/net@v0.58.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

2,339
pgvectorcagriekinVerified publisher2.4.12 of 3See more

pgvector cagriekin 2.4.1

2 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
cagriekin/pg-ha:2.1.0-pg18111ccc617ce7
golang.org/x/net@v0.58.0
stdlib@go1.25.12
0.60.0
1.26.9
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
stdlib@go1.24.6
1.26.9

Open the chart page →

4,828
camel-dashboard-operatorcamel-dashboardVerified publisher0.1.01 of 1See more

camel-dashboard-operator camel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

928
camel-monitor-operatorcamel-dashboardVerified publisher0.2.11 of 1See more

camel-monitor-operator camel-dashboard 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/camel-tooling/camel-monitor-operator:latest6a2e094f9cc2
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

223
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9

Open the chart page →

1,502
camunda-operatorcamunda-operatorVerified publisher0.2.01 of 1See more

camunda-operator camunda-operator 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/konsole-is/camunda-operator:0.2.0c06f61af7b3c
golang.org/x/net@v0.58.0
0.60.0

Open the chart page →

65
capsulecapsuleOfficialVerified publisher0.14.62 of 2See more

capsule capsule 0.14.6

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

2,072
capsule-proxycapsule-proxyOfficialVerified publisher0.15.02 of 2See more

capsule-proxy capsule-proxy 0.15.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/projectcapsule/capsule-proxy:v0.15.0233c41fe7229
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,880
casdoorcasdoorVerified publisher4.19.01 of 1See more

casdoor casdoor 4.19.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
casbin/casdoor:4.19.01813811ddc1c
golang.org/x/net@v0.58.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

907
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

4,763
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/net@v0.27.0
stdlib@go1.23.0
0.60.0
1.26.9

Open the chart page →

2,381
cert-estuarycert-estuaryVerified publisher0.2.11 of 1See more

cert-estuary cert-estuary 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/hsn723/cert-estuary:0.2.00c4b6132b0ad
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

627
cert-manager-approver-policycert-managerOfficialVerified publisher0.28.01 of 1See more

cert-manager-approver-policy cert-manager 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-approver-policy:v0.28.01a955b0a5c41
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

205
cert-manager-google-cas-issuercert-managerOfficialVerified publisher0.13.01 of 1See more

cert-manager-google-cas-issuer cert-manager 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-google-cas-issuer:v0.13.00d6a852d7c6a
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

205
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.60.0
1.26.9

Open the chart page →

17,205
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/net@v0.9.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,625
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
golang.org/x/net@v0.26.0
stdlib@go1.22.0
0.60.0
1.26.9

Open the chart page →

1,701
cert-manager-webhook-ionos-cloudcert-manager-webhook-ionos-cloudVerified publisher0.3.41 of 1See more

cert-manager-webhook-ionos-cloud cert-manager-webhook-ionos-cloud 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/ionos-cloud/cert-manager-webhook-ionos-cloud:v1.0.46860c5df73f1
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

230
cert-manager-webhook-porkbuncert-manager-webhook-porkbunVerified publisher2.0.71 of 1See more

cert-manager-webhook-porkbun cert-manager-webhook-porkbun 2.0.7

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/octabits-io/cert-manager-webhook-porkbun:2.0.7ab5e9a28a30a
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

213
cert-vaultcert-vaultOfficialVerified publisher2.12.04 of 7See more

cert-vault cert-vault 2.12.0

4 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/net@v0.33.0
stdlib@go1.23.7
0.60.0
1.26.9
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
stdlib@go1.23.7
1.26.9
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.26.9
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

19,173
chatclichatcliVerified publisher1.215.21 of 2See more

chatcli chatcli 1.215.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/net@v0.26.0
stdlib@go1.23.10
0.60.0
1.26.9

Open the chart page →

1,533
chatcli-operatorchatcli-operatorVerified publisher1.215.21 of 2See more

chatcli-operator chatcli-operator 1.215.2

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/net@v0.26.0
stdlib@go1.23.10
0.60.0
1.26.9

Open the chart page →

1,526
etcd-defragchristianhuthVerified publisher1.6.21 of 1See more

etcd-defrag christianhuth 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.7.2e9afa62b1e91
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

238

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
kubernetesui/dashboard:v2.7.02e500d29e9d5
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
1
kubernetesui/dashboard-api:1.7.060595892c2cf
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
1
kubernetesui/dashboard-auth:1.1.307135c09e9ff
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.60.0
1.26.9
1
kubernetesui/dashboard-metrics-scraper:1.1.17747d363c9fe
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.60.0
1.26.9
1
kubernetesui/dashboard-web:1.4.04445b31a2c25
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
1
kubernetesui/metrics-scraper:v1.0.876049887f07a
golang.org/x/net@v0.0.0-20220524220425-1d687d428aca
stdlib@go1.18.2
0.60.0
1.26.9
1
kubesec/kubesec:latest6735b7f3d1c8
stdlib@go1.27.1
1.27.2
1
kubesec/kubesec:v2.13.0c0f3b0673578
stdlib@go1.19.7
1.26.9
1
kubeshark/hub:v53.50532936678f8
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2
1
kubeshark/worker:v53.51f3e121224f8
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
1
kubeshop/bitnami-mongodb:8.3.11e209888ede02
golang.org/x/net@v0.48.0
stdlib@go1.26.8
0.60.0
1.26.9
1
kubeshop/kube-webhook-certgen:0.0.7866827c379ae
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
1
kubeshop/kusk-gateway:v1.5.48b5bfd57a3ce
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.4
0.60.0
1.26.9
1
kubeshop/kusk-gateway-api:v1.5.4126c713cf7d8
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.10
0.60.0
1.26.9
1
kubeshop/kusk-gateway-api-websocket:v1.5.43b4f8345ca5c
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.10
0.60.0
1.26.9
1
kubeshop/testkube-api-server:0.11.160ad97f07a78b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
golang.org/x/net@v0.40.0
stdlib@go1.23.10
0.60.0
1.26.9
1
kubeshop/testkube-kubectl:1.37.15011b74081fa
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
kubeshop/testkube-logs-server:latest094186b19698
golang.org/x/net@v0.34.0
stdlib@go1.24.1
0.60.0
1.26.9
1
kubeshop/testkube-minio:2025.10d8e1af6aca99
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
1
kubeshop/testkube-operator:2.1.154def0d0f0d4ab
golang.org/x/net@v0.34.0
stdlib@go1.23.9
0.60.0
1.26.9
1
kubeshop/tracetest:v1.7.173d7e3a2db43
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.60.0
1.26.9
1
kubeskoop/agent:v1.0.0-rc.19031d9f74832
golang.org/x/net@v0.10.0
stdlib@go1.22.1
0.60.0
1.26.9
1
kubeskoop/controller:v1.0.0-rc.137a3eb73325d
golang.org/x/net@v0.10.0
stdlib@go1.22.1
0.60.0
1.26.9
1
kubesphere/fluentbit-operator:v0.9.0b87db3c57cb3
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
1
kubesphere/fluent-operator:v1.0.2702df77228c6
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.6
0.60.0
1.26.9
1
kubesphere/ks-extensions-museum:latest29681958f220
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.60.0
1.26.9
1
kubesphere/kubectl:v1.27.1649b445b1b732
golang.org/x/net@v0.23.0
stdlib@go1.18.10
0.60.0
1.26.9
1
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.60.0
1.26.9
1
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.10
0.60.0
1.26.9
1
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.10
0.60.0
1.26.9
1
kubestar/event-exporter:latest656606941255
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9
1
kubestar/security-webhook:latest156d495afe77
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9
1
kubesuite/kubereport:latest0262424ee702
golang.org/x/net@v0.29.0
stdlib@go1.22.0
0.60.0
1.26.9
1
kubevious/ui:1.2.16233e84bdd59
golang.org/x/net@v0.0.0-20220812165438-1d4ff48094d1
stdlib@go1.19.1
0.60.0
1.26.9
1
kubevip/kube-vip-cloud-provider:v0.0.12f8f4e3401f76
golang.org/x/net@v0.37.0
stdlib@go1.24.2
0.60.0
1.26.9
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.60.0
1.26.9
1
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9
1
kudobuilder/controller:v0.9.069072d979708
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13
0.60.0
1.26.9
1
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.60.0
1.26.9
1
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9
1
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/net@v0.19.0
stdlib@go1.22.12
0.60.0
1.26.9
1
kusionstack/kuperator:v0.7.4d2f72ae1d2f2
golang.org/x/net@v0.28.0
stdlib@go1.24.13
0.60.0
1.26.9
1
kusionstack/kusion:v0.14.0126c8f0b0976
golang.org/x/net@v0.31.0
stdlib@go1.22.10
0.60.0
1.26.9
1
kusionstack/operating:v0.5.0c28bd96b986b
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
1
kvalitetsit/go-loop:1.1.0d07f449d75ed
stdlib@go1.25.1
1.26.9
1
kvalitetsit/kitargus:2026-03-09-091234-10013c4c5cde2d9371c
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
1
kvalitetsit/kitcaddy:1.5.110e66907ea266
golang.org/x/net@v0.55.0
stdlib@go1.26.6
0.60.0
1.26.9
1
kvalitetsit/metadoc-app:maine89e351733ad
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.19.5
0.60.0
1.26.9
1
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.