StackRadar

CVE-2026-78660

Unscored

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,521
of 18,087 indexed, latest versions
Container images
6,343
deployed by those charts
Fix available
2 of 3
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,521 of 18,087 indexed charts deploy, on 6,343 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,331
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,106
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-78660GO-2026-6610
Trending
Rank 4 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,521 by stars
ChartLatestAffected imagesRadar Score
cluster-api-operatorcluster-api-operator0.29.01 of 1See more

cluster-api-operator cluster-api-operator 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/capi-operator/cluster-api-operator:v0.29.0465e72f8b06a
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

135
immudbcodenotaryVerified publisher1.9.71 of 1See more

immudb codenotary 1.9.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codenotary/immudb:1.9.77c85d7cc4f22
golang.org/x/net@v0.17.0
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

1,957
routercosmo-routerOfficialVerified publisher0.18.01 of 1See more

router cosmo-router 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

2,198
dolibarrcowboysysopVerified publisher9.0.32 of 3See more

dolibarr cowboysysop 9.0.3

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
stdlib@go1.23.7
1.26.9
wait4x/wait4x:3.3.14dcd86307de1
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

11,097
csi-wekafsplugincsi-wekafsOfficialVerified publisher0.6.2-01 of 6See more

csi-wekafsplugin csi-wekafs 0.6.2-0

1 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.60.0
1.26.9

Open the chart page →

3,998
daskhubdask2024.1.13 of 9See more

daskhub dask 2024.1.1

3 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/traefik:2.10.61957e3314f43
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
quay.io/jupyterhub/k8s-image-awaiter:3.2.1f65b644ed6db
stdlib@go1.18.10
1.26.9
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.60.0
1.26.9

Open the chart page →

17,237
seafiledatamateVerified publisher0.6.05 of 6See more

seafile datamate 0.6.0

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
stdlib@go1.22.6
1.26.9
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
bitnamilegacy/os-shell:11-debian-11-r968643af4facff
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

85,124
k8s-event-loggerdeliveryheroVerified publisher1.4.01 of 1See more

k8s-event-logger deliveryhero 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
maxrocketinternet/k8s-event-logger:2.70234bdec4626
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

538
drone-runner-dockerdroneVerified publisher0.7.02 of 3See more

drone-runner-docker drone 0.7.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.15
0.60.0
1.26.9
library/docker:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9

Open the chart page →

7,345
gateway-helmenvoy-gateway0.0.0-latest1 of 1See more

gateway-helm envoy-gateway 0.0.0-latest

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
envoyproxy/gateway-dev:latest97b2a036f523
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

332
k8s-image-swapperestahnVerified publisher1.11.01 of 2See more

k8s-image-swapper estahn 1.11.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9

Open the chart page →

2,537
loadtesterflagger0.39.01 of 1See more

loadtester flagger 0.39.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.56.0
stdlib@go1.24.12
0.60.0
1.26.9

Open the chart page →

2,286
flannelflannel0.28.102 of 2See more

flannel flannel 0.28.10

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/flannel-io/flannel:v0.28.10f26b2403273c
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/flannel-io/flannel-cni-plugin:v1.9.1-flannel39fccdf677e6e
stdlib@go1.26.5
1.26.9

Open the chart page →

431
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.1
0.60.0
1.26.9

Open the chart page →

4,464
lndfold0.3.153 of 4See more

lnd fold 0.3.15

3 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.16.4-beta-c287129953689
golang.org/x/net@v0.8.0
stdlib@go1.21.0
0.60.0
1.26.9
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.60.0
1.26.9
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

11,647
geonode-k8sgeonode-k8sVerified publisher2.0.02 of 10See more

geonode-k8s geonode-k8s 2.0.0

2 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jwilder/dockerize:v0.10.0839cd6793d19
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.32.08ccae74fc039
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

62,128
gitops-promotergitops-promoterOfficialVerified publisher0.24.02 of 2See more

gitops-promoter gitops-promoter 0.24.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/gitops-promoter:v0.45.05ac7b6178ddc
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/brancz/kube-rbac-proxy:v0.23.0a6075902738e
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

3,301
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:latestf1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

12,962
grafana-mcpgrafana-communityVerified publisher0.27.11 of 1See more

grafana-mcp grafana-community 0.27.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/mcp-grafana:2.0.187b48c8fa1a0
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,015
mariadbgroundhog2k4.44.01 of 1See more

mariadb groundhog2k 4.44.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:11.8.46b848cb24fbb
stdlib@go1.24.6
1.26.9

Open the chart page →

3,488
mongodbgroundhog2k0.8.31 of 1See more

mongodb groundhog2k 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:8.3.115d7043a4ffe0
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,370
haproxy-ingresshaproxy-ingressVerified publisher0.16.21 of 1See more

haproxy-ingress haproxy-ingress 0.16.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/jcmoraisjr/haproxy-ingress:v0.16.242bcf39842db
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

106
heimdallheimdallOfficialVerified publisher3.3.31 of 2See more

heimdall heimdall 3.3.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

2,759
autheliahelmforgeVerified publisher1.5.141 of 1See more

authelia helmforge 1.5.14

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
authelia/authelia:4.39.28bd97cff4fcbf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

76
dolibarrhelmforgeVerified publisher1.2.191 of 3See more

dolibarr helmforge 1.2.19

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:26.7.0ade067ae2fb1
stdlib@go1.24.6
1.26.9

Open the chart page →

4,955
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
stdlib@go1.20.7
1.26.9

Open the chart page →

11,972
postgresqlhelmforgeVerified publisher2.0.51 of 1See more

postgresql helmforge 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

1,753
umamihelmforgeVerified publisher2.3.41 of 3See more

umami helmforge 2.3.4

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

2,058
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:15724292da1f2e
stdlib@go1.24.6
1.26.9
victoriametrics/victoria-metrics:v1.95.1f52723a08a44
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

16,634
infrahubinfrahubVerified publisher4.33.61 of 5See more

infrahub infrahub 4.33.6

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9

Open the chart page →

12,286
secret-manageritscontainedVerified publisher0.2.11 of 1See more

secret-manager itscontained 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
itscontained/secret-manager:0.3.07ec3e93c6469
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.3
0.60.0
1.26.9

Open the chart page →

4,171
jenkinsjenkins-helm-chartVerified publisher0.1.01 of 1See more

jenkins jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

1,925
kamu-api-serverkamuVerified publisher0.92.01 of 1See more

kamu-api-server kamu 0.92.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.92.016a23a285ffc
golang.org/x/net@v0.59.0
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

7,668
kerberneteskerbernetesVerified publisher1.1.111 of 1See more

kerbernetes kerbernetes 1.1.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/froz42/kerbernetes:v1.1.6d5c074be8366
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

271
percona-xtradb-clusterkfirfer1.5.101 of 3See more

percona-xtradb-cluster kfirfer 1.5.10

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
stdlib@go1.19.9
1.26.9

Open the chart page →

5,547
permission-managerkfirfer1.0.71 of 1See more

permission-manager kfirfer 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.60.0
1.26.9

Open the chart page →

3,264
klusterviewklusterviewVerified publisher0.1.02 of 4See more

klusterview klusterview 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:latestb28bae15e219
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/prometheus/prometheus:latestefd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

3,534
gateway-operatorkongOfficialVerified publisher0.6.11 of 1See more

gateway-operator kong 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kong/gateway-operator:1.603510967482b
golang.org/x/net@v0.39.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

1,238
kong-meshkong-meshVerified publisher2.14.53 of 3See more

kong-mesh kong-mesh 2.14.5

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kong/kuma-cp:2.14.5a154795691d1
golang.org/x/net@v0.58.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
kong/kumactl:2.14.58191df5c7019
golang.org/x/net@v0.58.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
registry.k8s.io/kubectl:v1.36.1d08f476d04d0
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

919
kubeflowkubeflow1.6.226 of 45See more

kubeflow kubeflow 1.6.2

26 of the 45 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.13
0.60.0
1.26.9
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.60.0
1.26.9
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/net@v0.0.0-20211205041911-012df41ee64c
stdlib@go1.17.7
0.60.0
1.26.9
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.11
0.60.0
1.26.9
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.60.0
1.26.9
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/mysql:5.7-debiandf28187b5455
stdlib@go1.16.7
1.26.9
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.11
0.60.0
1.26.9
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

188,880
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
stdlib@go1.20.6
1.26.9

Open the chart page →

12,137
testkubekubeshop2.14.16 of 6See more

testkube kubeshop 2.14.1

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubeshop/bitnami-mongodb:8.3.11e209888ede02
golang.org/x/net@v0.48.0
stdlib@go1.26.8
0.60.0
1.26.9
kubeshop/testkube-api-server:2.14.1ce04897e5ea2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
kubeshop/testkube-kubectl:1.37.15011b74081fa
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
kubeshop/testkube-minio:2025.10d8e1af6aca99
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
library/nats:2.15.0-alpineac8f88a6494b
stdlib@go1.27.1
1.27.2
natsio/nats-server-config-reloader:0.24.0d758a82a9c20
stdlib@go1.26.5
1.26.9

Open the chart page →

5,308
openelbkubesphere-stable0.5.02 of 2See more

openelb kubesphere-stable 0.5.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.60.0
1.26.9
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

6,372
operatorkube-starrocksVerified publisher1.11.71 of 1See more

operator kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/net@v0.17.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

963
sbomscannerkubewardenVerified publisher0.13.05 of 5See more

sbomscanner kubewarden 0.13.0

5 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/nats:2.14.6-alpinead7a43eb7e33
stdlib@go1.26.7
1.26.9
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.26.9
ghcr.io/kubewarden/sbomscanner/controller:v0.13.0611e21c44268
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/kubewarden/sbomscanner/storage:v0.13.064929d3a8ecf
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/kubewarden/sbomscanner/worker:v0.13.00a8e4e31c890
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,660
venti-stackkuossOfficialVerified publisher0.5.08 of 9See more

venti-stack kuoss 0.5.0

8 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kuoss/eventrouter:v0.4.156226040e1346
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.60.0
1.26.9
ghcr.io/kuoss/lethe:v0.3.3ebdf55fd5705
golang.org/x/net@v0.41.0
stdlib@go1.24.10
0.60.0
1.26.9
ghcr.io/kuoss/venti:v0.3.38ee3e70d77f1
golang.org/x/net@v0.42.0
stdlib@go1.24.10
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.93.1428f088fe6fe
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.13.2508729e0e2d1
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

5,630
librechatlibrechat-openshiftVerified publisher1.9.01 of 3See more

librechat librechat-openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

6,669
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestf1bc435659b9
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

3,934
vclustermainVerified publisher0.17.07 of 10See more

vcluster main 0.17.0

7 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.60.0
1.26.9
registry.k8s.io/etcd:3.6.4-0e36c08168342
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.60.0
1.26.9
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

16,201
stannatsVerified publisher0.13.01 of 2See more

stan nats 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
natsio/prometheus-nats-exporter:latestc623b608e148
stdlib@go1.26.6
1.26.9

Open the chart page →

251

Container images carrying it

6,343 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.60.0
1.26.9
2
louislam/uptime-kuma:2.3.29aeb4e51d038
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
2
louislam/uptime-kuma:2.5.5c74379ac4509
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
2
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
2
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.60.0
1.26.9
2
maxrocketinternet/datadog-controller:0.1a867315facf8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
2
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.26.9
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.60.0
1.26.9
2
mesosphere/kubectl:v1.35.0-alpineea01a9387771
golang.org/x/net@v0.43.0
stdlib@go1.25.5
0.60.0
1.26.9
2
mikefarah/yq:4:latest4b3d9475d655
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.60.0
1.26.9
2
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.26.9
2
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.1
0.60.0
1.26.9
2
natsio/nats-server-config-reloader:0.20.147094fcae2f4
stdlib@go1.24.8
1.26.9
2
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.26.9
2
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.26.9
2
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.26.9
2
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.26.9
2
neosmemo/memos:0.31.024c2707ddd8f
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
stdlib@go1.24.4
1.26.9
2
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
2
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.26.9
2
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
golang.org/x/net@v0.14.0
stdlib@go1.19.8
no fix listed
0.60.0
1.26.9
2
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9
2
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
2
openebs/mc:RELEASE.2024-11-21T17-21-54Z4d1b85539919
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2
openebs/minio:RELEASE.2024-12-18T13-15-44Zbb04e41fc1b8
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2
openebs/provisioner-localpv:4.6.099f5116f5cb8
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
2
openfga/openfga:latest:v1.22.09cf9a20af32a
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
golang.org/x/net@v0.24.0
stdlib@go1.20.14
0.60.0
1.26.9
2
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.2
0.60.0
1.26.9
2
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
2
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
2
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.60.0
1.26.9
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.60.0
1.26.9
2
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.60.0
1.26.9
2
otel/opentelemetry-collector:latest310a800ad69e
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.145.0a7343f018690
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.161.0:latestfd328de25524
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
2
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.26.9
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.26.9
2
percona/everest-helmtools:0.0.1904458d04a18
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
2
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
2
pgautoupgrade/pgautoupgrade:18-alpine2245aabc5b80
stdlib@go1.24.6
1.26.9
2
pgsty/mc:RELEASE.2026-09-16T00-00-00Zcfc83108c3ab
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
pgsty/minio:RELEASE.2026-08-04T00-00-00Zb6bfe7239bfc
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.