StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,521
of 18,087 indexed, latest versions
Container images
6,339
deployed by those charts
Fix available
2 of 3
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,521 of 18,087 indexed charts deploy, on 6,339 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,327
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,102
golang-1.19deb1.19.8-2no fix listed1
OSV records
GO-2026-6610DEBIAN-CVE-2026-78660
Trending
Rank 4 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,521 by stars
ChartLatestAffected imagesRadar Score
alertmanager-matrixalertmanager-matrixVerified publisher0.1.161 of 1See more

alertmanager-matrix alertmanager-matrix 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
silkeh/alertmanager_matrix:0.6.1900010497f8c
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

664
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
stdlib@go1.24.4
1.26.9

Open the chart page →

14,048
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.26.9

Open the chart page →

73,257
clearml-servingallegroaiVerified publisher1.6.26 of 9See more

clearml-serving allegroai 1.6.2

6 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
stdlib@go1.19.6
1.26.9
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
stdlib@go1.18.2
1.26.9
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.26.9
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

25,073
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.26.9

Open the chart page →

6,095
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.26.9

Open the chart page →

9,588
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

3,884
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

2,884
cloudflare-operatorankra-chartsVerified publisher0.2.01 of 1See more

cloudflare-operator ankra-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
adyanth/cloudflare-operatordigest-pinned6b168dc237d5
golang.org/x/net@v0.39.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

858
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
stdlib@go1.24.4
1.26.9

Open the chart page →

7,457
upcloud-csiankra-chartsVerified publisher0.4.18 of 8See more

upcloud-csi ankra-charts 0.4.1

8 of the 8 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
golang.org/x/net@v0.43.0
stdlib@go1.23.12
0.60.0
1.26.9
ghcr.io/upcloudltd/upcloud-csidigest-pinned5af91c663788
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

22,013
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

1,852
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

4,094
anteonanteonVerified publisher2.6.45 of 13See more

anteon anteon 2.6.4

5 of the 13 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.60.0
1.26.9
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.60.0
1.26.9
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.26.9
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
stdlib@go1.19.11
0.60.0
1.26.9

Open the chart page →

27,363
antreaantreaVerified publisher2.7.02 of 2See more

antrea antrea 2.7.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
golang.org/x/net@v0.58.0
stdlib@go1.25.7
0.60.0
1.26.9
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

4,673
api-usage-serverapi-usage-server1.16.01 of 1See more

api-usage-server api-usage-server 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,105
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

1,657
kubedb-opscenterappscodeVerified publisher2026.7.101 of 1See more

kubedb-opscenter appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-ui-server:v0.42.0e93dfe7454d4
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

431
kubedb-provisionerappscodeVerified publisher0.66.01 of 1See more

kubedb-provisioner appscode 0.66.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-provisioner:v0.66.0e7041c3b41e7
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

874
scannerappscodeVerified publisher2026.1.153 of 3See more

scanner appscode 2026.1.15

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/net@v0.26.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

6,966
smtprelayappscodeVerified publisher2026.9.111 of 1See more

smtprelay appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/net@v0.34.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,280
stash-enterpriseappscodeVerified publisher0.42.04 of 4See more

stash-enterprise appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
stdlib@go1.24.9
0.60.0
1.26.9
ghcr.io/stashed/stash-crd-installer:v0.42.1d6c9b7a1f7b8
golang.org/x/net@v0.38.0
stdlib@go1.25.5
0.60.0
1.26.9
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
golang.org/x/net@v0.38.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

5,664
virtual-secrets-serverappscodeVerified publisher2026.8.141 of 1See more

virtual-secrets-server appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/virtual-secrets-server:v0.4.0efa03f4c9551
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

484
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

6,446
argocd-rbac-operatorargocd-rbac-operator0.4.51 of 1See more

argocd-rbac-operator argocd-rbac-operator 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-rbac-operator:v0.2.451dded00137a
golang.org/x/net@v0.40.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

1,311
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

3,459
s3dartur9010Verified publisher1.0.11 of 1See more

s3d artur9010 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

2,108
arvancloud-webhookarvancloud-webhookVerified publisher1.0.11 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.1e58c98b4d28a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

736
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.15
0.60.0
1.26.9

Open the chart page →

3,896
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
stdlib@go1.18.2
1.26.9

Open the chart page →

20,312
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

12,347
dltbrokerassist-iot-distributed-broker0.2.05 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.60.0
1.26.9
hyperledger/fabric-ca:latesta70b6ba64a08
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

196,388
dltloggingassist-iot-logging-auditing0.2.05 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.13
0.60.0
1.26.9
hyperledger/fabric-ca:latesta70b6ba64a08
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

196,368
astradnsastradnsVerified publisher0.2.92 of 2See more

astradns astradns 0.2.9

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.60.0
1.26.9
ghcr.io/astradns/astradns-operator:v0.2.909e58b62416a
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

3,442
deployautoml0.1.02 of 3See more

deploy automl 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.26.9
muonsoft/openapi-mock:latestc9afe1295484
stdlib@go1.20.2
1.26.9

Open the chart page →

4,267
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
stdlib@go1.17.5
0.60.0
1.26.9

Open the chart page →

5,375
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

4,490
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.18.1
0.60.0
1.26.9

Open the chart page →

4,751
prismav1o-chartsVerified publisher0.3.11 of 1See more

prism av1o-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.26.9

Open the chart page →

2,211
avahi-controlleravahi-controllerVerified publisher0.1.191 of 1See more

avahi-controller avahi-controller 0.1.19

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/mm503/avahi-controller:0.6.42207e2ae2179
golang.org/x/net@v0.57.0
0.60.0

Open the chart page →

20
kubebrowseravistoOfficialVerified publisher1.4.01 of 1See more

kubebrowser avisto 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/kubebrowser:0.10.0a354b8dc7e6a
golang.org/x/net@v0.47.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

1,058
azuredisk-csi-driverazuredisk-csi-driverVerified publisher1.36.07 of 8See more

azuredisk-csi-driver azuredisk-csi-driver 1.36.0

7 of the 8 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.36.00b4df214c178
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-attacher:v4.12.03aadb9baa021
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.17.0264963e21f6d
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v6.3.05c9423e1046a
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v2.2.1f755aeee7277
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-snapshotter:v8.6.01ca5b663e3dd
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.19.03eb866c2c773
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

633
generic-appb3oVerified publisher0.1.61 of 1See more

generic-app b3o 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.26.9

Open the chart page →

2,269
gozonebabykart-helm-chartsVerified publisher0.18.11 of 1See more

gozone babykart-helm-charts 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/babykart/gozone:0.19.19c3331309120
stdlib@go1.27.1
1.27.2

Open the chart page →

123
vault-unsealbabykart-helm-chartsVerified publisher1.0.51 of 1See more

vault-unseal babykart-helm-charts 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/lrstanley/vault-unseal:1.0.1dd873930b6df
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

350
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

5,941
music-assistantbdclark-helm-chartsVerified publisher0.4.131 of 1See more

music-assistant bdclark-helm-charts 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.3885872224fa5
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

4,635
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.8
0.60.0
1.26.9
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.17.5
0.60.0
1.26.9
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

10,569
livekit-serverbeeinventor1.0.01 of 2See more

livekit-server beeinventor 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.10
0.60.0
1.26.9

Open the chart page →

3,714
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.60.0
1.26.9

Open the chart page →

2,371

Container images carrying it

6,339 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bloomberg/goldpinger:3.11.5f7c60d319150
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
burningalchemist/sql_exporter:0.24.9:latest6c554722facc
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
cagriekin/pg-ha:2.1.0-pg18111ccc617ce7
golang.org/x/net@v0.58.0
stdlib@go1.25.12
0.60.0
1.26.9
2
casbin/casdoor:3.62.17729da148c61
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.60.0
1.26.9
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.60.0
1.26.9
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.5
0.60.0
1.26.9
2
chrislusf/seaweedfs:2.92db095fe8a8d6
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.7
0.60.0
1.26.9
2
clickhouse/clickhouse-server:24.2ed9640bfff07
stdlib@go1.19.10
1.26.9
2
cloudflare/cloudflared:2022.1.361f608cd1123
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.1
0.60.0
1.26.9
2
cloudflare/cloudflared:2026.6.16d91c121b803
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
2
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.26.9
2
coredns/coredns:1.13.19b9128672209
golang.org/x/net@v0.45.0
stdlib@go1.25.2
0.60.0
1.26.9
2
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.60.0
1.26.9
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.17.3
0.60.0
1.26.9
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.60.0
1.26.9
2
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.4
0.60.0
1.26.9
2
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.60.0
1.26.9
2
danielfm/aws-limits-exporter:0.6.07152b84e57cb
stdlib@go1.17.2
1.26.9
2
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
2
danielqsj/kafka-exporter:latestd1014f41712d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
datawire/emissary:3.12.21f67a1292d2a
golang.org/x/net@v0.28.0
stdlib@go1.22.4
0.60.0
1.26.9
2
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.26.9
2
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.26.9
2
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.60.0
1.26.9
2
dexidp/dex:v2.39.1-distroless43655afd1a8f
golang.org/x/net@v0.24.0
stdlib@go1.21.6
0.60.0
1.26.9
2
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.60.0
1.26.9
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.60.0
1.26.9
2
dunglas/mercure:v0:v0.24.2916834e49961
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
2
envoyproxy/gateway:v1.9.10049bcb384c5
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
2
epamedp/cd-pipeline-operator:2.32.0fc858071b7a1
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
2
epamedp/codebase-operator:2.35.0295a008abcef
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
2
epamedp/edp-tekton:0.27.088189f16f94b
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
2
epamedp/gitfusion:0.6.10b7eb7d5ca43
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
2
eqalpha/keydb:latest6537505c4235
stdlib@go1.16.7
1.26.9
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.26.9
2
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.26.9
2
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.26.9
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.60.0
1.26.9
2
filebrowser/filebrowser:latest:v2.63.23a469ea076d4a
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
2
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.16.2
0.60.0
1.26.9
2
flanksource/incident-manager-ui:v1.4.3228d17f0c08b20
stdlib@go1.23.5
1.26.9
2
flashcatcloud/categraf:latest42e6ab16472e
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
2
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.60.0
1.26.9
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.