StackRadar

CVE-2026-78659

Unscored

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,566
of 18,071 indexed, latest versions
Container images
6,425
deployed by those charts
Fix available
2 of 3
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,566 of 18,071 indexed charts deploy, on 6,425 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,411
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,172
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-78659GO-2026-6603
Trending
Rank 3 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,566 by stars
ChartLatestAffected imagesRadar Score
natsnatsVerified publisher2.15.03 of 3See more

nats nats 2.15.0

3 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/nats:2.15.0-alpineac8f88a6494b
stdlib@go1.27.1
1.27.2
natsio/nats-box:0.19.7ffce8bd10338
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.26.9

Open the chart page →

2,694
dexdexVerified publisher0.26.01 of 1See more

dex dex 0.26.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

412
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

36,379
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
stdlib@go1.21.8
1.26.9

Open the chart page →

12,588
falcofalcosecurity9.2.03 of 3See more

falco falcosecurity 9.2.0

3 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
falcosecurity/falco:0.45.0788f1129c542
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
falcosecurity/falco-driver-loader:0.45.0d7d287d4dcee
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
falcosecurity/falcoctl:0.14.290ba9627886e
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

3,437
kubeviewkubeviewVerified publisher2.2.11 of 1See more

kubeview kubeview 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/benc-uk/kubeview:latest45b64d7c7016
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

242
alertmanagerprometheus-communityOfficialVerified publisher2.1.02 of 2See more

alertmanager prometheus-community 2.1.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.106b52bd4dbe3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.34.1e9733bafb1bd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

228
kongkongOfficialVerified publisher3.4.11 of 2See more

kong kong 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

793
nfs-server-provisionerkvaps1.8.01 of 1See more

nfs-server-provisioner kvaps 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

3,382
chartmuseumchartmuseumVerified publisher3.10.41 of 1See more

chartmuseum chartmuseum 3.10.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.16.3c81f105c3682
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

2,025
prometheus-node-exporterprometheus-communityOfficialVerified publisher4.59.01 of 1See more

prometheus-node-exporter prometheus-community 4.59.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

221
rook-cephrookOfficialVerified publisher1.21.02 of 2See more

rook-ceph rook 1.21.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
rook/ceph:v1.21.02c3a65786d3c
golang.org/x/net@v0.58.0
stdlib@go1.22.10
0.60.0
1.26.9
quay.io/cephcsi/ceph-csi-operator:v1.1.0c42c95c36fa2
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,793
grafanagrafana-communityVerified publisher13.4.01 of 1See more

grafana grafana-community 13.4.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

184
argo-eventsargoOfficialVerified publisher2.4.271 of 1See more

argo-events argo 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
golang.org/x/net@v0.57.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

1,472
victoria-metrics-k8s-stackvictoriametricsVerified publisher0.95.25 of 7See more

victoria-metrics-k8s-stack victoriametrics 0.95.2

5 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
victoriametrics/operator:v0.75.078da26b41a81
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/victoriametrics/sync-job:v0.0.17b6f233532a85
golang.org/x/net@v0.56.0
stdlib@go1.26.4-X:jsonv2
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

987
aws-node-termination-handleraws0.21.01 of 1See more

aws-node-termination-handler aws 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.19.0844478ebd5b8
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

2,150
kuredkuredOfficialVerified publisher6.1.01 of 1See more

kured kured 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/kubereboot/kured:1.23.08dfd3c2e8893
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

395
home-assistanthelm-hassVerified publisher0.3.841 of 1See more

home-assistant helm-hass 0.3.84

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.10.01b64d38f38d9
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

2,683
prometheus-adapterprometheus-communityOfficialVerified publisher5.3.01 of 1See more

prometheus-adapter prometheus-community 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9

Open the chart page →

1,421
openebsopenebsOfficialVerified publisher4.6.220 of 35See more

openebs openebs 4.6.2

20 of the 35 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.26.9
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.26.9
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.26.9
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
openebs/lvm-driver:1.10.141f73aba7f31
golang.org/x/net@v0.48.0
stdlib@go1.24.7
0.60.0
1.26.9
openebs/mc:RELEASE.2024-11-21T17-21-54Z4d1b85539919
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
openebs/minio:RELEASE.2024-12-18T13-15-44Zbb04e41fc1b8
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
openebs/provisioner-localpv:4.6.099f5116f5cb8
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
openebs/zfs-driver:2.11.20234692bb4a4
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

33,271
tigera-operatorprojectcalico3.33.01 of 1See more

tigera-operator projectcalico 3.33.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.44.0066c2e8d6745
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2

Open the chart page →

76
open-webuiopen-webui16.6.01 of 4See more

open-webui open-webui 16.6.0

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.26.9

Open the chart page →

2,277
actions-runner-controlleractions-runner-controller0.23.72 of 2See more

actions-runner-controller actions-runner-controller 0.23.7

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
summerwind/actions-runner-controller:v0.27.62128f81dbede
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

4,207
aws-for-fluent-bitaws0.2.01 of 1See more

aws-for-fluent-bit aws 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-for-fluent-bit:3.2.1a480a1241720
stdlib@go1.25.6
1.26.9

Open the chart page →

460
corednscorednsVerified publisher1.48.21 of 1See more

coredns coredns 1.48.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
coredns/coredns:1.14.77efd3c635b03
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

410
apisixapisix2.18.01 of 3See more

apisix apisix 2.18.0

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.60.0
1.26.9

Open the chart page →

3,464
vpafairwinds-stableVerified publisher5.1.04 of 4See more

vpa fairwinds-stable 5.1.0

4 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9

Open the chart page →

2,290
x509-certificate-exporterenixOfficialVerified publisher4.2.01 of 1See more

x509-certificate-exporter enix 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/enix/x509-certificate-exporter:4.2.0afef14dc3862
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

221
terraformhashicorpVerified publisher1.1.21 of 1See more

terraform hashicorp 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.18.8
0.60.0
1.26.9

Open the chart page →

2,806
opentelemetry-operatoropentelemetry-helmOfficialVerified publisher0.124.11 of 1See more

opentelemetry-operator opentelemetry-helm 0.124.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.160.05323a0df9508
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

72
trinotrino1.42.21 of 1See more

trino trino 1.42.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
trinodb/trino:4801565e8cac299
stdlib@go1.26.1
1.26.9

Open the chart page →

1,745
prometheus-pushgatewayprometheus-communityOfficialVerified publisher3.9.11 of 1See more

prometheus-pushgateway prometheus-community 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/prometheus/pushgateway:v1.11.491a56b89b97d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

76
dagsterdagsterVerified publisher1.13.251 of 5See more

dagster dagster 1.13.25

1 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.26.9

Open the chart page →

4,256
prometheus-redis-exporterprometheus-communityVerified publisher6.33.01 of 1See more

prometheus-redis-exporter prometheus-community 6.33.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.93.06ca518a72f30
stdlib@go1.27.1
1.27.2

Open the chart page →

56
zabbixzabbix-communityVerified publisher7.1.03 of 5See more

zabbix zabbix-community 7.1.0

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
golang.org/x/net@v0.41.0
stdlib@go1.24.10
0.60.0
1.26.9
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
stdlib@go1.24.10
1.26.9

Open the chart page →

15,941
keycloakcloudpirates-keycloakVerified publisher0.21.462 of 3See more

keycloak cloudpirates-keycloak 0.21.46

2 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
stdlib@go1.24.6
1.26.9
library/postgres:18.674935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

4,977
graylogkong-zVerified publisher3.0.361 of 5See more

graylog kong-z 3.0.36

1 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

3,165
netdatanetdataVerified publisher3.7.1751 of 1See more

netdata netdata 3.7.175

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
netdata/netdata:v2.12.01e50cc0b11f0
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,727
connectonepassword-connect2.4.22 of 2See more

connect onepassword-connect 2.4.2

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
1password/connect-api:1.8.3656e4b10df83
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1password/connect-sync:1.8.3a760350c941a
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

222
node-problem-detectordeliveryheroVerified publisher2.4.11 of 1See more

node-problem-detector deliveryhero 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,421
opencostopencostOfficialVerified publisher2.5.321 of 2See more

opencost opencost 2.5.32

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost:1.121.34cdd173253e5
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

350
openfaasopenfaas15.0.136 of 6See more

openfaas openfaas 15.0.13

6 of the 6 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/nats-streaming:0.25.60ad6861379c9
stdlib@go1.20.11
1.26.9
ghcr.io/openfaas/faas-netes:0.18.176cfe35401d25
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
ghcr.io/openfaas/gateway:0.27.14ee0eaecc490c
stdlib@go1.24.13
1.26.9
ghcr.io/openfaas/queue-worker:0.14.2c18da04d70f6
stdlib@go1.23.4
1.26.9
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.14.05ce7540c3c00
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

5,050
prometheus-elasticsearch-exporterprometheus-communityVerified publisher7.4.01 of 1See more

prometheus-elasticsearch-exporter prometheus-community 7.4.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.11.0a056739b095d
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

248
flux2fluxcd-community2.19.17 of 7See more

flux2 fluxcd-community 2.19.1

7 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
fluxcd/flux-cli:v2.9.5704d55295355
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9
ghcr.io/fluxcd/helm-controller:v1.6.48ff15409e46d
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/image-automation-controller:v1.2.5e1a2720d3951
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/image-reflector-controller:v1.2.5c83ce5c06fed
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/kustomize-controller:v1.9.5a3a955eb2bc4
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/notification-controller:v1.9.4840f318265ee
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/source-controller:v1.9.56f20d232d596
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

3,517
gitlab-agentgitlabVerified publisher2.32.01 of 1See more

gitlab-agent gitlab 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cluster-integration/gitlab-agent/agentk:v19.4.04d3498887bee
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

101
jaeger-operatorjaegertracingOfficialVerified publisher2.57.01 of 1See more

jaeger-operator jaegertracing 2.57.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
jaegertracing/jaeger-operator:1.61.03f036ec60e61
golang.org/x/net@v0.29.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,020
policy-reporterpolicy-reporterOfficialVerified publisher3.11.01 of 1See more

policy-reporter policy-reporter 3.11.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/kyverno/policy-reporter:3.11.00f6eabff483b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

101
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.26.9

Open the chart page →

6,571
netboxnetboxOfficialVerified publisher8.3.913 of 5See more

netbox netbox 8.3.91

3 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9
rancher/kubectl:v1.36.206c7a7a97727
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/netbox-community/netbox:v4.7.26f7177d3ff4d
stdlib@go1.26.7
1.26.9

Open the chart page →

1,630
valkeybitnamiVerified publisher6.3.41 of 1See more

valkey bitnami 6.3.4

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9

Open the chart page →

52

Container images carrying it

6,425 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
3
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.26.9
3
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
stdlib@go1.18
1.26.9
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.60.0
1.26.9
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.16.10
0.60.0
1.26.9
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.15
0.60.0
1.26.9
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.60.0
1.26.9
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.60.0
1.26.9
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.26.9
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.19.2
0.60.0
1.26.9
3
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.26.9
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.26.9
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
stdlib@go1.21.5
0.60.0
1.26.9
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.10
0.60.0
1.26.9
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.9
0.60.0
1.26.9
3
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.60.0
1.26.9
3
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.26.9
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.0142a1f11df8d
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v3.10.07571a304e67f
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.60.0
1.26.9
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.60.0
1.26.9
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.60.0
1.26.9
3
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.60.0
1.26.9
3
quay.io/tigera/operator:v1.44.0066c2e8d6745
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
3
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.