StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
preparrpreparr0.19.81 of 6See more

preparr preparr 0.19.8

1 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.26.9

Open the chart page →

1,204
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.26.9

Open the chart page →

6,773
projectionprojectionVerified publisher0.3.21 of 1See more

projection projection 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/projection-operator/projection:0.3.2d06374430a17
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

450
prometheus-druid-exporterprometheus-communityVerified publisher1.2.01 of 1See more

prometheus-druid-exporter prometheus-community 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/opstree/druid-exporter:v0.119f01c9c5c2e3
stdlib@go1.15.15
1.26.9

Open the chart page →

2,091
prometheus-operator-admission-webhookprometheus-communityVerified publisher0.44.22 of 2See more

prometheus-operator-admission-webhook prometheus-community 0.44.2

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/prometheus-operator/admission-webhook:v0.94.1691ecb7e05ce
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

248
prometheus-pingmesh-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-pingmesh-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:v1.2.2c82de0272da0
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.60.0
1.26.9

Open the chart page →

1,322
prometheus-sql-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-sql-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/justwatchcom/sql_exporter:v0.8c4b1d3d0f052
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,867
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.26.9
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.26.9
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.60.0
1.26.9

Open the chart page →

15,536
dockerhub-exporterpromhippieVerified publisher2.16.01 of 1See more

dockerhub-exporter promhippie 2.16.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/promhippie/dockerhub-exporter:2.17.0cbf4ef61e675
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

141
hcloud-exporterpromhippieVerified publisher4.30.01 of 1See more

hcloud-exporter promhippie 4.30.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/promhippie/hcloud-exporter:3.30.0f1dba83dfd23
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

141
prowlerprowler-appVerified publisher0.0.92 of 5See more

prowler prowler-app 0.0.9

2 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9
prowlercloud/prowler-api:5.31.14f252d579be2
golang.org/x/net@v0.54.0
stdlib@go1.26.3-X:jsonv2
0.60.0
1.26.9

Open the chart page →

10,168
pulumi-kubernetes-operatorpulumi-kubernetes-operator2.9.31 of 1See more

pulumi-kubernetes-operator pulumi-kubernetes-operator 2.9.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
pulumi/pulumi-kubernetes-operator:v2.9.30a0f20eeb071
golang.org/x/net@v0.59.0
0.60.0

Open the chart page →

56
operatorpunchplatform8.1.131 of 1See more

operator punchplatform 8.1.13

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
golang.org/x/net@v0.20.0
stdlib@go1.22.0
0.60.0
1.26.9

Open the chart page →

1,295
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

2,481
go-kube-downscalerpy-kube-downscalerVerified publisher1.4.11 of 1See more

go-kube-downscaler py-kube-downscaler 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/caas-team/gokubedownscaler:1.4.1da4507aa387b
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

184
pyramidanalyticspyramidanalyticsVerified publisher2025.11.2761 of 9See more

pyramidanalytics pyramidanalytics 2025.11.276

1 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:latestefd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

203
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

64,101
qt-vaultqt-vaultVerified publisher0.1.21 of 1See more

qt-vault qt-vault 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/mcman2017/qt-vault:v0.1.2852edf54c850
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

651
caddyquench-caddyVerified publisher0.0.171 of 1See more

caddy quench-caddy 0.0.17

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/caddydigest-pinned015a4b181ab2
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

158
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

7,916
rabbitmqrabbitmq-magefleet1.2.01 of 1See more

rabbitmq rabbitmq-magefleet 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.26.9

Open the chart page →

3,544
jobs-managerraczylo-comVerified publisher0.1.301 of 1See more

jobs-manager raczylo-com 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/lukaszraczylo/jobs-manager-operator:0.1.30461414c3b8ca
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

124
kube-images-syncraczylo-comVerified publisher0.5.691 of 1See more

kube-images-sync raczylo-com 0.5.69

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/lukaszraczylo/kubernetes-images-sync-operator:0.5.69f32ace076a2d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

124
velero-s3-deploymentradar-baseVerified publisher0.4.32 of 4See more

velero-s3-deployment radar-base 0.4.3

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
velero/velero:v1.9.0277fbfaf8dcf
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.18
0.60.0
1.26.9
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.11
0.60.0
1.26.9

Open the chart page →

5,752
ravendb-operatorravendb-operatorOfficialVerified publisher2.1.01 of 1See more

ravendb-operator ravendb-operator 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ravendb/ravendb-operator:2.1.0511050205ac5
golang.org/x/net@v0.48.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

528
rbac-serverrbac-server1.19.11 of 1See more

rbac-server rbac-server 1.19.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/rbac-server:1.19.1df1adeb86679
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,125
rclonercloneVerified publisher2.2.01 of 1See more

rclone rclone 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rclone/rclone:1.6874c51b8817e5
golang.org/x/net@v0.27.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

2,153
redis-enterprise-operatorredis-enterprise-operatorVerified publisher7.13.4-121 of 1See more

redis-enterprise-operator redis-enterprise-operator 7.13.4-12

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
redislabs/operator:7.4.2-2ecb101af0506
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

3,292
redis-chartredis-ha-chartVerified publisher0.1.51 of 2See more

redis-chart redis-ha-chart 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
truebyteinnovationllp/redis-exporter:v1.86.01c6a945af653
stdlib@go1.25.11
1.26.9

Open the chart page →

463
redis-sentinel-gatewayredis-sentinel-gatewayVerified publisher1.0.21 of 1See more

redis-sentinel-gateway redis-sentinel-gateway 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
promzeus/redis-sentinel-gateway:v182f6d56e280b
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.60.0
1.26.9

Open the chart page →

3,386
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
stdlib@go1.24.6
1.26.9

Open the chart page →

5,717
kminionredpanda-dataOfficialVerified publisher0.15.31 of 1See more

kminion redpanda-data 0.15.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
redpandadata/kminion:v2.3.612bc33b3e334
golang.org/x/net@v0.55.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

375
docker-registry-mirrorregistry-mirror1.0.11 of 1See more

docker-registry-mirror registry-mirror 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.26.9

Open the chart page →

1,030
reportportalreportportal-ioOfficialVerified publisher26.8.127 of 15See more

reportportal reportportal-io 26.8.12

7 of the 15 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.26.9
library/rabbitmq:4.3.4-managementeb5295d08332
stdlib@go1.22.2
1.26.9
rancher/kubectl:v1.36.206c7a7a97727
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9
reportportal/k8s-wait-for:latest06cdf299b397
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9
reportportal/migrations:5.15.4464468240d7b
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
reportportal/service-index:5.15.1b1860ed33071
golang.org/x/net@v0.54.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

16,252
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.26.9

Open the chart page →

8,622
resurfaceresurfaceioVerified publisher3.9.03 of 3See more

resurface resurfaceio 3.9.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.60.0
1.26.9
jitesoft/kubectl:latest7f25594d4f33
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
resurfaceio/resurface:3.7.84d5cda2f64109
stdlib@go1.23.0
1.26.9

Open the chart page →

8,912
retyc-csiretyc-csi0.3.03 of 3See more

retyc-csi retyc-csi 0.3.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/retyc/retyc-k8s-csi:v0.3.0551757c204d1
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,838
right-sizerright-sizer0.6.21 of 1See more

right-sizer right-sizer 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
aavishay/right-sizer:0.6.23d7c4d79595c
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

595
backup-repository-serverriotkit-org4.0.01 of 1See more

backup-repository-server riotkit-org 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
stdlib@go1.17.13
0.60.0
1.26.9

Open the chart page →

2,965
rke2-canalrke2-charts3.13.32 of 2See more

rke2-canal rke2-charts 3.13.3

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.36d2cd61a338b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.60.0
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.60.0

Open the chart page →

7,352
rke2-ingress-nginxrke2-charts4.15.1112 of 2See more

rke2-ingress-nginx rke2-charts 4.15.111

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/kube-webhook-certgen:v1.14.5-hardened26bb869baf40b
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
rancher/nginx-ingress-controller:v1.14.5-hardened26cbc1e932b5b
golang.org/x/net@v0.52.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,562
cloudflare-tunnelrlex0.8.01 of 1See more

cloudflare-tunnel rlex 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2023.10.0c18744ae1767
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9

Open the chart page →

2,415
hcloud-fip-controllerrlex0.2.51 of 1See more

hcloud-fip-controller rlex 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.15.3
0.60.0
1.26.9

Open the chart page →

4,117
prometheus-webhook-dingtalkrlex0.0.31 of 1See more

prometheus-webhook-dingtalk rlex 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.26.9

Open the chart page →

2,962
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
stdlib@go1.22.6
1.26.9

Open the chart page →

10,769
kimai2robjuz5.0.151 of 2See more

kimai2 robjuz 5.0.15

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:10.6.12-debian-11-r1678847062532a
stdlib@go1.19.7
1.26.9

Open the chart page →

5,595
rocket-chatrocket-chatVerified publisher0.1.51 of 3See more

rocket-chat rocket-chat 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
pgvector/pgvector:pg167b822b0aac60
stdlib@go1.24.6
1.26.9

Open the chart page →

4,149
grafanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

grafana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:8.3.4cf81d2c753c8
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

3,862
jaeger-collectorromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-collector romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

2,614
jaeger-queryromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-query romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jaegertracing/jaeger-query:1.41.0b636f0f464bc
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

2,559

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
library/traefik:2.4.8eda951fd29a8
golang.org/x/net@v0.0.0-20210220033124-5f55cee0dc0d
stdlib@go1.16.2
0.60.0
1.26.9
2
library/traefik:2.2.8f5af5a5ce17f
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.14.6
0.60.0
1.26.9
2
library/zookeeper:3.9.5e6b279d01350
stdlib@go1.18.1
1.26.9
2
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
2
linuxserver/cloud9:latest:version-1.29.245c5fe102ff3
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.11
0.60.0
1.26.9
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
2
listmonk/listmonk:latest:v6.2.0f535d59e1499
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.60.0
1.26.9
2
localstack/localstack-pro:latest801a3dff7f6a
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:nojsonv2
0.60.0
1.27.2
2
longhornio/longhorn-manager:v1.2.3dca34321452c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.1
0.60.0
1.26.9
2
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.60.0
1.26.9
2
louislam/uptime-kuma:2.3.29aeb4e51d038
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
2
louislam/uptime-kuma:2.5.5c74379ac4509
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
2
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
2
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.60.0
1.26.9
2
maxrocketinternet/datadog-controller:0.1a867315facf8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
2
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.26.9
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.60.0
1.26.9
2
mesosphere/kubectl:v1.35.0-alpineea01a9387771
golang.org/x/net@v0.43.0
stdlib@go1.25.5
0.60.0
1.26.9
2
mikefarah/yq:4:latest4b3d9475d655
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.60.0
1.26.9
2
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.26.9
2
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.1
0.60.0
1.26.9
2
natsio/nats-server-config-reloader:0.20.147094fcae2f4
stdlib@go1.24.8
1.26.9
2
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.26.9
2
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.26.9
2
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.26.9
2
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.26.9
2
neosmemo/memos:0.31.024c2707ddd8f
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
stdlib@go1.24.4
1.26.9
2
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
2
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.26.9
2
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
golang.org/x/net@v0.14.0
stdlib@go1.19.8
no fix listed
0.60.0
1.26.9
2
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9
2
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
2
openebs/mc:RELEASE.2024-11-21T17-21-54Z4d1b85539919
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2
openebs/minio:RELEASE.2024-12-18T13-15-44Zbb04e41fc1b8
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2
openebs/provisioner-localpv:4.6.099f5116f5cb8
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
2
openfga/openfga:latest:v1.22.09cf9a20af32a
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
golang.org/x/net@v0.24.0
stdlib@go1.20.14
0.60.0
1.26.9
2
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.2
0.60.0
1.26.9
2
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
2
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
2
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.60.0
1.26.9
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.60.0
1.26.9
2
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.145.0a7343f018690
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.161.0:latestfd328de25524
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.