StackRadar

CVE-2026-78659

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

HTTP/2 server memory exhaustion due to Trailer headers in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4wvv-4gxm-pc68CGA-9hv5-59p6-4m49CGA-9mpv-qcf2-fr4cCGA-cmf5-g287-mphmCGA-ggmx-8j82-p2pfCGA-hmpr-chf9-7j4fDEBIAN-CVE-2026-78659GO-2026-6603
Also known as
CGA-2j9j-6w7w-x98q, CGA-32h2-ph4h-6j25, CGA-437c-v9xq-v77f, CGA-5cmh-mcx3-x7xj, CGA-62vw-6x79-rpw5, CGA-7fqm-wjjc-9pfc, CGA-7vrh-rfw7-r9f6, CGA-868g-cgmx-cvph, CGA-8r9c-282h-5mvw, CGA-ch5q-gfj4-q8gh, CGA-fwv6-mhj4-q3jf, CGA-gqw6-fwhv-jpf8, CGA-gw2c-84xv-m8g4, CGA-hcgj-v82p-m28j, CGA-j93h-pjfq-52jm, CGA-jj9f-32xw-j4r7, CGA-mqcg-6v5g-5xp3, CGA-mvr9-28rx-545x, CGA-pjc7-rhj8-2m9q, CGA-q38p-jqw6-276f, CGA-qq83-54q4-2pph, CGA-rhx4-wwr7-qfg4, CGA-v9h6-27pv-3g4r, CGA-w63p-h8hw-xp53, CGA-w7mj-m6pj-r2xq, CGA-wcf2-p3g3-gq3c
Trending
Rank 2 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
homeboxcoo-ops-spaceVerified publisher0.1.61 of 1See more

homebox coo-ops-space 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/hay-kot/homebox:v0.9.2e6e0fbd7cca9
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

2,524
coordimap-agentcoordimap-agentVerified publisher0.4.31 of 1See more

coordimap-agent coordimap-agent 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
coordimap/coordimap-agent:latest7748fd0fae9f
golang.org/x/net@v0.38.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,090
cortex-proxycortex-proxyVerified publisher0.4.11 of 1See more

cortex-proxy cortex-proxy 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/peak-scale/observability-tenancy/cortex-proxy:0.4.11838720c13b2
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

844
cortezacorteza1.1.02 of 3See more

corteza corteza 1.1.0

2 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.60.0
1.26.9
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
stdlib@go1.23.5
1.26.9

Open the chart page →

10,139
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
golang.org/x/net@v0.21.0
stdlib@go1.19.13
0.60.0
1.26.9

Open the chart page →

5,560
cosanetcosanet1.0.01 of 1See more

cosanet cosanet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/cosanet/cosanet:1.0.098cb5d9fa215
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

2,885
ociscosmicrocks0.7.01 of 2See more

ocis cosmicrocks 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
owncloud/ocis:7.1.388e7c854517d
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

2,492
cosmo-traefikcosmoVerified publisher0.9.11 of 2See more

cosmo-traefik cosmo 0.9.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/traefik:v2.10.11489caffaedb
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.60.0
1.26.9

Open the chart page →

4,412
dev-code-servercosmoVerified publisher0.0.72 of 2See more

dev-code-server cosmo 0.0.7

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/docker:dind7dcdfc4a2024
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

16,938
cospacecospace0.0.343 of 3See more

cospace cospace 0.0.34

3 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/redis:latest33a5a129cadc
stdlib@go1.26.8
1.26.9
library/mariadb:latestd4fdec0510ad
stdlib@go1.26.7
1.26.9
ghcr.io/twigex/cospace:lateste5ecfd607e42
golang.org/x/net@v0.50.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

4,992
couchbase-monitor-stackcouchbaseVerified publisher2.1.22 of 5See more

couchbase-monitor-stack couchbase 2.1.2

2 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
grafana/grafana:8.1.5b7dd9cd0e59d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.1
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.60.0
1.26.9

Open the chart page →

9,266
grafana-mcpcowboysysopVerified publisher2.0.01 of 1See more

grafana-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
mcp/grafana:latest9362bcf6aa0e
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,654
katibcowboysysopVerified publisher2.4.23 of 4See more

katib cowboysysop 2.4.2

3 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.1
0.60.0
1.26.9
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
stdlib@go1.13.3
0.60.0
1.26.9
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

9,878
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.14
0.60.0
1.26.9

Open the chart page →

5,400
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

2,385
mariadbcowboysysopVerified publisher20.4.21 of 1See more

mariadb cowboysysop 20.4.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
stdlib@go1.23.7
1.26.9

Open the chart page →

3,648
metacontrollercowboysysopVerified publisher1.2.21 of 1See more

metacontroller cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
metacontrollerio/metacontroller:v2.1.10336993b88e4
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

3,084
mongodbcowboysysopVerified publisher15.1.51 of 1See more

mongodb cowboysysop 15.1.5

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
golang.org/x/net@v0.22.0
stdlib@go1.20.12
0.60.0
1.26.9

Open the chart page →

8,004
mpi-operatorcowboysysopVerified publisher1.2.21 of 1See more

mpi-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.15.13
0.60.0
1.26.9

Open the chart page →

3,801
notebook-controllercowboysysopVerified publisher1.1.21 of 1See more

notebook-controller cowboysysop 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.15.15
0.60.0
1.26.9

Open the chart page →

3,841
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
stdlib@go1.13.1
1.26.9

Open the chart page →

6,997
rediscowboysysopVerified publisher21.2.61 of 1See more

redis cowboysysop 21.2.6

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.0.2-debian-12-r4cdc2efa9c306
stdlib@go1.24.4
1.26.9

Open the chart page →

3,215
training-operatorcowboysysopVerified publisher1.2.21 of 1See more

training-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.9
0.60.0
1.26.9

Open the chart page →

3,430
crashloop-operatorcrashloop-operator0.0.61 of 1See more

crashloop-operator crashloop-operator 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/yeonghoo2/crashloop-operator:0.0.6565d1115e6bd
golang.org/x/net@v0.13.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

893
chalkularcrashoverride-helm-chartsVerified publisher0.0.81 of 1See more

chalkular crashoverride-helm-charts 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/chalkular-controller:v0.0.8d31986456626
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

195
pod-killercriblio1.0.01 of 1See more

pod-killer criblio 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

141
crossplane-controllerscrossplane0.12.01 of 1See more

crossplane-controllers crossplane 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
crossplane/crossplane:v0.12.066666e6963af
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.60.0
1.26.9

Open the chart page →

3,490
oam-kubernetes-runtimecrossplane0.0.3-71.g0f235901 of 2See more

oam-kubernetes-runtime crossplane 0.0.3-71.g0f23590

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.14
0.60.0
1.26.9

Open the chart page →

3,409
oam-kubernetes-runtime-legacycrossplane0.3.1-5.g11e18941 of 1See more

oam-kubernetes-runtime-legacy crossplane 0.3.1-5.g11e1894

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

3,379
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.2
0.60.0
1.26.9

Open the chart page →

5,834
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

4,253
electric-mailcryptexlabsVerified publisher0.0.12 of 5See more

electric-mail cryptexlabs 0.0.1

2 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.60.0
1.26.9
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.60.0
1.26.9

Open the chart page →

8,196
iam-zencryptexlabsVerified publisher0.12.232 of 4See more

iam-zen cryptexlabs 0.12.23

2 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

4,745
purple-piecryptexlabsVerified publisher0.0.12 of 4See more

purple-pie cryptexlabs 0.0.1

2 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.60.0
1.26.9
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.60.0
1.26.9

Open the chart page →

8,196
pagescrypticcode-helmchart1.0.01 of 3See more

pages crypticcode-helmchart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
agent-sandboxcsghubVerified publisher0.5.61 of 1See more

agent-sandbox csghub 0.5.6

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.6dc23fb0d5624
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

166
csghubcsghubVerified publisher2.5.025 of 34See more

csghub csghub 2.5.0

25 of the 34 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
library/nats:2.12.150764f1952d72
stdlib@go1.25.12
1.26.9
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.26.9
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
stdlib@go1.19.8
1.26.9
opencsghq/csgbot:v0.6.9-ee7d0271e26521
stdlib@go1.24.4
1.26.9
opencsghq/csghub-portal:v2.5.0-ee1cb36b49151e
golang.org/x/net@v0.28.0
stdlib@go1.23.3
0.60.0
1.26.9
opencsghq/csghub-server:v2.5.0-ee587046575c2c
golang.org/x/net@v0.57.0
stdlib@go1.26.0
0.60.0
1.26.9
opencsghq/csghub-xnet:v2.5.0-ee86ea22f495c7
golang.org/x/net@v0.39.0
stdlib@go1.24.10
0.60.0
1.26.9
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.60.0
1.26.9
opencsghq/gitlab-shell:v19.2.580a65ac370da
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
opencsghq/kube-state-metrics:v2.19.15ea147562ec8
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
opencsghq/lws:v0.6.1de15437db41b
golang.org/x/net@v0.37.0
stdlib@go1.24.0
0.60.0
1.26.9
opencsghq/postgres:15.19b98600564e07
stdlib@go1.24.6
1.26.9
opencsghq/prometheus:v3.13.00aac0d04749e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
opencsghq/prometheus-config-reloader:v0.92.144e6ec00729b
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
opencsghq/stakater-reloader:v1.4.190491782f7bac
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
temporalio/admin-tools:1.32.0a9f84fb9a374
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
temporalio/server:1.32.0c3e752127759
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/operator/cmd/operator:v1.22.3733f21dc06f9
golang.org/x/net@v0.53.0
stdlib@go1.26.4
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/operator/cmd/webhook:v1.22.366ae76179a80
golang.org/x/net@v0.53.0
stdlib@go1.26.4
0.60.0
1.26.9
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
quay.io/argoproj/workflow-controller:v3.7.11c46aa0ded8ed
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.4be477ba317d8
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

62,708
csgshipcsghubVerified publisher0.4.64 of 10See more

csgship csghub 0.4.6

4 of the 10 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
opencsghq/postgres:15.19b98600564e07
stdlib@go1.24.6
1.26.9
opencsghq/stakater-reloader:v1.4.190491782f7bac
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

14,073
dataflowcsghubVerified publisher2.5.03 of 7See more

dataflow csghub 2.5.0

3 of the 7 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
opencsghq/postgres:15.19b98600564e07
stdlib@go1.24.6
1.26.9
opencsghq/stakater-reloader:v1.4.190491782f7bac
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

8,674
ocscsic-charts1.0.01 of 4See more

ocs csic-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

2,321
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.60.0
1.26.9

Open the chart page →

7,684
rtcsic-charts0.1.12 of 5See more

rt csic-charts 0.1.1

2 of the 5 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
golang.org/x/net@v0.5.0
stdlib@go1.19.6
0.60.0
1.26.9
library/postgres:13.11-bullseye5c265bf1fd30
stdlib@go1.18.2
1.26.9

Open the chart page →

17,709
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
golang.org/x/net@v0.5.0
stdlib@go1.18.9
0.60.0
1.26.9

Open the chart page →

15,964
csi-driver-ipfscsi-driver-ipfs0.2.06 of 6See more

csi-driver-ipfs csi-driver-ipfs 0.2.0

6 of the 6 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

5,669
ipfs-clustercsi-driver-ipfs0.2.02 of 2See more

ipfs-cluster csi-driver-ipfs 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ipfs/ipfs-cluster:v1.1.6a83266c524f1
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
ipfs/kubo:v0.41.00661819c2e09
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

2,609
cursor-admin-api-exportercursor-admin-api-exporterVerified publisher0.1.91 of 1See more

cursor-admin-api-exporter cursor-admin-api-exporter 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
ghcr.io/matanbaruch/cursor-admin-api-exporter:0.1.8ba3a29fc479a
stdlib@go1.24.5
1.26.9

Open the chart page →

997
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.8
0.60.0
1.26.9

Open the chart page →

1,992
custom-rhcl-consolecustom-rhcl-consoleVerified publisher0.1.21 of 3See more

custom-rhcl-console custom-rhcl-console 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:latest10fef10863a3
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

2,345
cw-container-insightcwci0.7.01 of 1See more

cw-container-insight cwci 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:latest-arm6432bd729ab859
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

401
cloudflaredcyberjakeVerified publisher0.3.201 of 1See more

cloudflared cyberjake 0.3.20

1 of the 1 container images this version deploys carry CVE-2026-78659.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.6.16d91c121b803
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,009

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9
91
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
37
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9
36
library/postgres:18:18.6:18.6-trixie:latest74935e722416
stdlib@go1.24.6
1.26.9
31
library/postgres:16.15-alpine:16-alpine721873c34ceb
stdlib@go1.24.6
1.26.9
21
jenkins/jenkins:2.580.1-jdk21:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2
19
library/postgres:18:18.6-trixie:latestfc973eb97c9f
stdlib@go1.24.6
1.26.9
19
quay.io/prometheus/prometheus:latest:v3.15.0efd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
19
library/postgres:18:18.6:18.6-trixie:latest5a5a84b19854
stdlib@go1.24.6
1.26.9
18
library/postgres:18.6-alpine:18.6-alpine3.24:18-alpine:alpine77f585114c32
stdlib@go1.24.6
1.26.9
18
library/mysql:8:8.4:8.4.116ea90827b110
stdlib@go1.24.6
1.26.9
17
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
15
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9
14
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.26.9
14
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9
14
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9
14
quay.io/prometheus/node-exporter:latest:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
14
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
13
bitnami/mongodb:latestad05bb9a19fa
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
12
grafana/grafana:latestb28bae15e219
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
12
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9
12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
12
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
12
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
12
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.26.9
11
ethpandaops/xatu:latestef8eb43af9bb
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
10
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
10
library/mariadb:13.0.2:latestf1bba652ba57
stdlib@go1.26.7
1.26.9
10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.26.9
10
library/mongo:9.0.2:latestbac22ea7710d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
10
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
9
library/mysql:26.7.0:latest9d48c42f8341
stdlib@go1.24.6
1.26.9
9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
9
ghcr.io/quenchworks/images/grafana4b7e7a134283
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
9
ghcr.io/quenchworks/images/kubectl4033ac5e5f35
golang.org/x/net@v0.57.0
helm-4@4.3.0-r0
kubernetes-1.37@1.37.1-r0
stdlib@go1.27.1
0.60.0
4.3.0-r2
1.37.1-r2
1.27.2
9
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9
8
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9
8
library/rabbitmq:3.13-management:3-managemente582c0bc7766
stdlib@go1.22.2
1.26.9
8
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9
8
quay.io/prometheus/alertmanager:latest:v0.34.1e9733bafb1bd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
8
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
8
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
8
bitnami/kubectl:latestab90e1058e5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9
7
bitnami/nginx:latestb8d42f076789
stdlib@go1.26.8
1.26.9
7
library/ubuntu:latestf144425ff09b
stdlib@go1.26.7
1.26.9
7
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.60.0
1.26.9
7
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.60.0
1.26.9
7

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.