StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
checkoutlabs64io-helm-chartsVerified publisher0.11.82 of 3See more

checkout labs64io-helm-charts 0.11.8

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
labs64/checkoutdigest-pinned4009b8251b57
stdlib@go1.26.7
1.26.9
library/postgres:1874935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

2,388
payment-gatewaylabs64io-helm-chartsVerified publisher0.10.82 of 2See more

payment-gateway labs64io-helm-charts 0.10.8

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
labs64/payment-gatewaydigest-pinned5421f763b53e
stdlib@go1.26.7
1.26.9
library/postgres:1874935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

2,366
lagoon-remotelagoon-chartsVerified publisher0.107.01 of 1See more

lagoon-remote lagoon-charts 0.107.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

2,999
lakilakiOfficialVerified publisher1.11.01 of 2See more

laki laki 1.11.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/laki-n/laki:v1.6.0599a10c453a3
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

663
landelijketabellencataloguslandelijketabellencatalogus1.0.01 of 3See more

landelijketabellencatalogus landelijketabellencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,415
glancelbenicio-communityVerified publisher0.1.31 of 1See more

glance lbenicio-community 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
glanceapp/glance:latest9dfb09470b20
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

299
lgtmlgtmVerified publisher0.28.17 of 9See more

lgtm lgtm 0.28.1

7 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:13.2.2-distroless69a5d2d957ca
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
grafana/loki:3.7.81107dd5274e0
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
grafana/pyroscope:2.3.186a9ee744848
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
grafana/tempo:2.10.8f0561deb1c68
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.159.02ceb3b541295
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,067
lgtm-stacklgtm-stackVerified publisher0.1.35 of 8See more

lgtm-stack lgtm-stack 0.1.3

5 of the 8 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.10f4434c92b3e
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/grafana:13.1.0121a7a9ece6d
golang.org/x/net@v0.55.0
stdlib@go1.25.7
0.60.0
1.26.9
grafana/loki:3.7.6efd47c67f9ba
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/mimir:3.2.0736f7459913d
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/tempo:2.10.8f0561deb1c68
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

3,950
keptn-cert-managerlifecycle-toolkitVerified publisher0.3.01 of 1See more

keptn-cert-manager lifecycle-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

953
keptn-lifecycle-operatorlifecycle-toolkitVerified publisher0.6.01 of 1See more

keptn-lifecycle-operator lifecycle-toolkit 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,069
keptn-metrics-operatorlifecycle-toolkitVerified publisher0.5.01 of 1See more

keptn-metrics-operator lifecycle-toolkit 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
golang.org/x/net@v0.37.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,305
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.13.8
0.60.0
1.26.9

Open the chart page →

5,784
lightrun-k8s-operatorlightrun-k8s-operatorOfficialVerified publisher0.4.71 of 1See more

lightrun-k8s-operator lightrun-k8s-operator 0.4.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
lightruncom/lightrun-k8s-operator:0.4.73e32b97777a9
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
linkerd-jaegerlinkerd2-edgeVerified publisher30.14.11-edge2 of 4See more

linkerd-jaeger linkerd2-edge 30.14.11-edge

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.6
0.60.0
1.26.9
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.60.0
1.26.9

Open the chart page →

6,058
halitesql0.1.51 of 2See more

ha litesql 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/litesql/ha:latest14d266f40e00
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

887
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
golang.org/x/net@v0.40.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

9,701
go-hello-worldloafoe0.17.01 of 1See more

go-hello-world loafoe 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/loafoe/go-hello-world:v2.16.022d94845e317
golang.org/x/net@v0.59.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

516
locust-k8s-operatorlocust-k8s-operatorVerified publisher2.3.11 of 1See more

locust-k8s-operator locust-k8s-operator 2.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
lotest/locust-k8s-operator:2.3.1859b0d36f371
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

173
home-assistantloeken-at-homeVerified publisher2026.5.11 of 1See more

home-assistant loeken-at-home 2026.5.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
loeken/home-assistant:2026.5.14ce6abc553b3
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

4,022
jspolicyloftVerified publisher0.2.21 of 1See more

jspolicy loft 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
loftsh/jspolicy:0.2.225deb9bd2683
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.60.0
1.26.9

Open the chart page →

3,278
vcluster-eksloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-eks loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes/kube-apiserver:v1.24.9-eks-1-24-772e06b605692
stdlib@go1.18.9
1.26.9
public.ecr.aws/eks-distro/kubernetes/kube-controller-manager:v1.24.9-eks-1-24-7eaea8c230432
stdlib@go1.18.9
1.26.9

Open the chart page →

5,526
vcluster-k0sloftVerified publisher0.0.0-ci.31 of 2See more

vcluster-k0s loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

3,970
log2rbac-operatorlog2rbac-operator0.0.51 of 1See more

log2rbac-operator log2rbac-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jkremser/log2rbac:v0.0.5e35cf56ef183
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

2,947
logclilogcliVerified publisher0.1.01 of 1See more

logcli logcli 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/logcli:main-c90366d-amd643d85bb66e39b
golang.org/x/net@v0.0.0-20210505214959-0714010a04ed
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

4,079
lokxylokxyVerified publisher0.2.01 of 1See more

lokxy lokxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
lokxy/lokxy:v0.9.0e4ac800dc55d
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

425
plexluiscajl1.0.11 of 2See more

plex luiscajl 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest3f71bd6eb6a4
stdlib@go1.26.7
1.26.9

Open the chart page →

784
lumenvoxlumenvox8.0.011 of 11See more

lumenvox lumenvox 8.0.0

11 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
lumenvox/admin-portal:8.0258583dde8a7
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
lumenvox/archive:8.04611915d66f6
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
lumenvox/cloud-init-tools:8.0c01faf8d628d
stdlib@go1.27.1
1.27.2
lumenvox/configuration:8.07badfce0df13
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
lumenvox/deployment:8.0dce4f18b4945
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
lumenvox/deployment-portal:8.04cf9bad0381d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
lumenvox/file-store:8.08090031da992
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
lumenvox/license:8.01f985ca4d603
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
lumenvox/management-api:8.098fe71067039
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
lumenvox/resource:8.026edd01fa2ee
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
lumenvox/storage:8.057d15feb3603
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,568
voice-biometricslumenvox2.0.18 of 26See more

voice-biometrics lumenvox 2.0.1

8 of the 26 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.26.9
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
lumenvox/cloud-init-tools:2.0.07ff037a71c50
stdlib@go1.17.3
1.26.9
lumenvox/cloud-license:2.0.09a69862e1248
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.3
0.60.0
1.26.9
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.26.9
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

82,163
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/luzilla/dnsbl_exporter:v0.12.0ecba7360ff12
golang.org/x/net@v0.53.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

2,020
lynqlynqVerified publisher1.1.221 of 1See more

lynq lynq 1.1.22

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-lynq/lynq:1.1.22229b05e3c717
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

962
cert-manager-webhook-infomaniakm0nsterrr-cert-manager-webhook-infomaniakVerified publisher1.1.31 of 1See more

cert-manager-webhook-infomaniak m0nsterrr-cert-manager-webhook-infomaniak 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/cert-manager-webhook-infomaniak:v0.1.65b7373bc3664
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

145
magentomagento3.2.35 of 12See more

magento magento 3.2.3

5 of the 12 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
stdlib@go1.18.2
1.26.9
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.26.9
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.60.0
1.26.9
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
longhornio/longhorn-ui:v1.10.0e60f36161511
stdlib@go1.24.6
1.26.9

Open the chart page →

17,532
mcp-orchestratormagertronVerified publisher4.0.834 of 7See more

mcp-orchestrator magertron 4.0.83

4 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
curtismager20/mcp-chat-daemon:4.0.83dbf757dad657
stdlib@go1.26.8
1.26.9
curtismager20/mcp-inventory:4.0.83bf588de2c078
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
curtismager20/mcp-sync:4.0.83e407298e4756
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9

Open the chart page →

2,244
goblackholemainVerified publisher0.0.41 of 1See more

goblackhole main 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bedag/goblackhole:0.2.0447a88598f4c
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.6
0.60.0
1.26.9

Open the chart page →

3,184
plane-enterprisemakeplaneOfficialVerified publisher3.10.54 of 13See more

plane-enterprise makeplane 3.10.5

4 of the 13 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.26.9
makeplane/monitor-commercial:v3.3.2a3cdc662ba20
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
pgsty/mc:RELEASE.2026-09-16T00-00-00Zcfc83108c3ab
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
pgsty/minio:RELEASE.2026-08-04T00-00-00Zb6bfe7239bfc
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

6,657
mattermost-enterprise-editionmattermostVerified publisher2.6.1051 of 3See more

mattermost-enterprise-edition mattermost 2.6.105

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mattermost/mattermost-enterprise-edition:11.11.1996a008fc0d5
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

1,102
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

22,415
mcpmcp-chartsVerified publisher0.0.233 of 7See more

mcp mcp-charts 0.0.23

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest0bdf876e5703
golang.org/x/net@v0.57.0
0.60.0
ghcr.io/gla-rad/mc-mms-router:latest99e8c2a00a83
golang.org/x/net@v0.57.0
0.60.0
ghcr.io/maritimeconnectivity/identityregistry:latest91de8dfffafe
stdlib@go1.26.7
1.26.9

Open the chart page →

4,141
traefik-forward-authmesosphere0.3.102 of 2See more

traefik-forward-auth mesosphere 0.3.10

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.11
0.60.0
1.26.9
mesosphere/traefik-forward-auth:3.1.05456581d7b76
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.15
0.60.0
1.26.9

Open the chart page →

7,859
metadata-injectormetadata-injector-operator0.0.11 of 1See more

metadata-injector metadata-injector-operator 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ruslanguns/metadata-injector-operator:v0.0.16c77e4675e07
golang.org/x/net@v0.26.0
stdlib@go1.22.11
0.60.0
1.26.9

Open the chart page →

1,019
metrics-server-exportermetrics-server-exporterVerified publisher2.4.01 of 1See more

metrics-server-exporter metrics-server-exporter 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mrnim94/metrics-server-exporter:v2.4.086c4807a4bca
golang.org/x/net@v0.47.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,586
subspacemglants0.1.01 of 1See more

subspace mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
subspacecommunity/subspace:1.5.0e2042b63fb35
golang.org/x/net@v0.0.0-20200519113804-d87ec0cfa476
stdlib@go1.14.6
0.60.0
1.26.9

Open the chart page →

4,431
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

5,020
librenmsmidokura-communityVerified publisher0.3.21 of 6See more

librenms midokura-community 0.3.2

1 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
librenms/librenms:22.4.14f1f3d667cc7
stdlib@go1.16.12
1.26.9

Open the chart page →

9,945
chartmuseummike75151.2.01 of 1See more

chartmuseum mike7515 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

4,152
minecraft-exporterminecraft-exporterVerified publisher0.16.01 of 1See more

minecraft-exporter minecraft-exporter 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dirien/minecraft-exporter:0.24.061d89bf99ff7
golang.org/x/net@v0.51.0
stdlib@go1.25.10
0.60.0
1.26.9

Open the chart page →

604
miniapiminiapi1.3.21 of 1See more

miniapi miniapi 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
udhos/miniapi:1.3.28a7042db82ce
stdlib@go1.23.2
1.26.9

Open the chart page →

1,218
miropsmirops-operatorVerified publisher0.2.02 of 2See more

mirops mirops-operator 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/miropshq/mirops/operator:v0.2.04b0b5fef9a6a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
ghcr.io/miropshq/mirops/remediation:v0.2.0976a7319ff4a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,697
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

7,278
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

36,819

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.60.0
1.26.9
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/udm:v3.4.32f68df062a50
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/upf:v3.4.3b6b362a39fdd
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
freikin/dawarich:1.15.3589e3606b11b
stdlib@go1.24.4
1.26.9
2
friendsofgo/killgrave:0.4.139cfbecca342
stdlib@go1.16.3
1.26.9
2
frinx/krakend:7.0.0bf8edd4f52f3
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.60.0
1.26.9
2
frinx/resource-manager:6.1.09cd0147a09bd
stdlib@go1.21.7
1.26.9
2
frinx/schellar:6.1.04693dc627d32
stdlib@go1.21.11
1.26.9
2
garethgeorge/backrest:latest:v1.14.1b85297975428
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9
2
garugaru/aws-cloudwatch-exporter:latest541852cafda5
stdlib@go1.16.15
1.26.9
2
githubexporter/github-exporter:v2.3.1a36fbedeedf8
stdlib@go1.26.4
1.26.9
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
stdlib@go1.18
0.60.0
1.26.9
2
gomods/athens:v0.11.0efb811df7844
golang.org/x/net@v0.0.0-20200222125558-5a598a2470a0
stdlib@go1.13.10
0.60.0
1.26.9
2
gotenberg/gotenberg:8.36.087c16b9f3642
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
2
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.60.0
1.26.9
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18
0.60.0
1.26.9
2
grafana/alloy:v1.8.17790f6f7fbd8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
2
grafana/alloy:v1.19.2b8ec653c4423
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
2
grafana/grafana:9.2.4057896e23443
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.60.0
1.26.9
2
grafana/grafana:11.1.0079600c9517b
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
2
grafana/grafana:13.0.10f86bada30d6
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.60.0
1.26.9
2
grafana/grafana:12.3.12175aaa91c96
golang.org/x/net@v0.46.0
stdlib@go1.25.5
0.60.0
1.26.9
2
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.17.9
0.60.0
1.26.9
2
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.5
0.60.0
1.26.9
2
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
2
grafana/grafana:12.3.39e1e77ade304
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
2
grafana/grafana:11.4.0d8ea37798ccc
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9
2
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
2
grafana/loki:3.6.5847c287ada0e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
2
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.60.0
1.26.9
2
grafana/loki:3.1.0d947e68a84d9
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
2
grafana/loki:2.5.0f9ef133793af
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.8
0.60.0
1.26.9
2
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.60.0
1.26.9
2
grafana/promtail:2.9.3b338a29de45e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
2
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/net@v0.24.0
stdlib@go1.21.3
0.60.0
1.26.9
2
grafana/tempo:2.10.8f0561deb1c68
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
2
hanchuanchuan/goinception:latestb3c0dd26fb50
golang.org/x/net@v0.23.0
stdlib@go1.22.1
0.60.0
1.26.9
2
hashicorp/boundary-enterprise:1.0.2-ent3a8061968ee4
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
2
hashicorp/consul:1.14.2e38576edcdfd
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.2
0.60.0
1.26.9
2
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.2
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.