StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
clusterpedia-coreclusterpedia0.1.13 of 3See more

clusterpedia-core clusterpedia 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/clusterpedia-io/clusterpedia/apiserver:v0.6.03d089d9078f8
stdlib@go1.19.4
1.26.9
ghcr.io/clusterpedia-io/clusterpedia/clustersynchro-manager:v0.6.082cc9a77f6d6
stdlib@go1.19.4
1.26.9
ghcr.io/clusterpedia-io/clusterpedia/controller-manager:v0.6.081669df338e0
stdlib@go1.19.4
1.26.9

Open the chart page →

5,160
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
linuxserver/plex:latest06e07af2851e
stdlib@go1.26.7
1.26.9

Open the chart page →

4,149
d2-prometheus-exportercmacraeVerified publisher0.1.01 of 1See more

d2-prometheus-exporter cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
stdlib@go1.15
1.26.9

Open the chart page →

2,359
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.17
0.60.0
1.26.9

Open the chart page →

3,228
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16
0.60.0
1.26.9

Open the chart page →

3,416
lgtmcmacraeVerified publisher0.1.01 of 1See more

lgtm cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cmacrae/lgtm:0.1.0dec8d490fe40
golang.org/x/net@v0.0.0-20181108082009-03003ca0c849
stdlib@go1.14.1
0.60.0
1.26.9

Open the chart page →

3,140
storage-local-pathcnapVerified publisher1.0.11 of 1See more

storage-local-path cnap 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.3534ff0847cc47
golang.org/x/net@v0.38.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

1,179
storage-piraeuscnapVerified publisher1.0.11 of 1See more

storage-piraeus cnap 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/piraeusdatastore/piraeus-operator:v2.10.5dd68a66332de
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

732
door-agentcnoVerified publisher3.0.1512 of 15See more

door-agent cno 3.0.15

12 of the 15 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/net@v0.37.0
stdlib@go1.23.12
0.60.0
1.26.9
beopenit/door-cd-operator:v3.0.4d3999cb8d026
golang.org/x/net@v0.17.0
stdlib@go1.23.9
0.60.0
1.26.9
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/net@v0.15.0
stdlib@go1.19.13
0.60.0
1.26.9
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
doorcloud/apim-operator:v3.0.44e6ef8d72c3e
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.60.0
1.26.9
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.13
0.60.0
1.26.9
library/docker:27-cli851f91d24121
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.60.0
1.26.9
library/docker:27-dindaa3df78ecf32
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.60.0
1.26.9
ghcr.io/projectcontour/contour:v1.30.0b12824d7eb58
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/projectcontour/contour:v1.33.0cd6e13fa882d
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.1
0.60.0
1.26.9
quay.io/prometheus/prometheus:latestefd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

27,616
cobbler-tftpcobbler0.1.11 of 1See more

cobbler-tftp cobbler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cobbler/cobbler-tftp:v0.1.0a7fef3ca80baa4
stdlib@go1.25.10
1.26.9

Open the chart page →

685
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

15,280
coder-logstream-kubecoder-logstream-kube0.0.161 of 1See more

coder-logstream-kube coder-logstream-kube 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/coder/coder-logstream-kube:v0.0.1614af1b1903d2
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

258
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.12 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9

Open the chart page →

6,118
docker-composecoderstudio-strapi-devVerified publisher0.0.12 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9

Open the chart page →

6,118
strapi-devcoderstudio-strapi-devVerified publisher0.0.12 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9

Open the chart page →

6,118
coder-ai-gatewaycoder-v2Verified publisher2.38.01 of 1See more

coder-ai-gateway coder-v2 2.38.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/coder/coder:v2.38.038a4cfc548b0
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

372
coder-provisionercoder-v2OfficialVerified publisher2.38.01 of 1See more

coder-provisioner coder-v2 2.38.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/coder/coder:v2.38.038a4cfc548b0
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

372
codiac-deployment-bundle-chartcodiac-deployment-bundle-chart0.0.151 of 1See more

codiac-deployment-bundle-chart codiac-deployment-bundle-chart 0.0.15

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codiacimages/codiac-deployment-bundle:0.0.15d7d1e91eccde
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

832
cohdicohdi0.2.23 of 3See more

cohdi cohdi 0.2.2

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/cohdi/composable-resource-operator:v0.2.23f45bf0a1bc0
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/cohdi/dynamic-device-scaler:v0.2.2b487e1d74632
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

5,158
colecole1.4.21 of 1See more

cole cole 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ntakashi/cole:1.2.3f7b68bee2a68
golang.org/x/net@v0.10.0
stdlib@go1.20.11
0.60.0
1.26.9

Open the chart page →

1,497
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.60.0
1.26.9

Open the chart page →

3,489
collectordcollectordOfficialVerified publisher2604.5.01 of 1See more

collectord collectord 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

141
collectord-elasticsearchcollectord-elasticsearchOfficialVerified publisher2604.5.01 of 1See more

collectord-elasticsearch collectord-elasticsearch 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

141
collectord-opensearchcollectord-opensearchOfficialVerified publisher2604.5.01 of 1See more

collectord-opensearch collectord-opensearch 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

141
collectord-splunk-kubernetescollectord-splunk-kubernetesOfficialVerified publisher2604.5.01 of 1See more

collectord-splunk-kubernetes collectord-splunk-kubernetes 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

141
collectord-splunk-openshiftcollectord-splunk-openshiftOfficialVerified publisher2604.5.01 of 1See more

collectord-splunk-openshift collectord-splunk-openshift 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforopenshift:26.04.55959c31596a0
stdlib@go1.26.8
1.26.9

Open the chart page →

141
collectord-syslogcollectord-syslogOfficialVerified publisher2604.5.01 of 1See more

collectord-syslog collectord-syslog 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

141
mysqlcomet-mysql-helmVerified publisher1.0.81 of 1See more

mysql comet-mysql-helm 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.26.9

Open the chart page →

1,921
loki-stackcommon-chartsVerified publisher1.0.39 of 12See more

loki-stack common-charts 1.0.3

9 of the 12 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.0491b0578c049
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/grafana:13.1.17cb8c64c4d57
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
grafana/loki:3.6.1144148ad243c0
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.5d0e80b2f62fe
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

8,873
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

10,170
opencloudcommunity-opencloud3.2.02 of 13See more

opencloud community-opencloud 3.2.0

2 of the 13 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
apache/tika:latest-fullab9cc988828c
stdlib@go1.26.7
1.26.9
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

10,456
community-operator-v2community-operator-v21.0.01 of 2See more

community-operator-v2 community-operator-v2 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.60.0
1.26.9

Open the chart page →

2,448
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

15,710
conjur-k8s-csi-providerconjure0.2.91 of 1See more

conjur-k8s-csi-provider conjure 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cyberark/conjur-k8s-csi-provider:latest737a967088d9
golang.org/x/net@v0.54.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

608
consentbbconsentbbVerified publisher2023.12.41 of 5See more

consentbb consentbb 2023.12.4

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
golang.org/x/net@v0.17.0
stdlib@go1.18.8
0.60.0
1.26.9

Open the chart page →

4,026
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,094
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

11,003
agent-forge-operatorcontainerooVerified publisher1.2.31 of 1See more

agent-forge-operator containeroo 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/containeroo/agent-forge-operator:v1.2.32cec21162d6d
golang.org/x/net@v0.57.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

643
autovpacontainerooVerified publisher0.4.21 of 1See more

autovpa containeroo 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/containeroo/autovpa:v0.0.3425b801d8d1f7
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

682
cert-manager-webhook-bluecatcontainerooVerified publisher1.0.21 of 1See more

cert-manager-webhook-bluecat containeroo 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/containeroo/cert-manager-webhook-bluecat:latest96f82d5840d4
golang.org/x/net@v0.57.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

872
filesystem-exportercontainerooVerified publisher1.5.21 of 1See more

filesystem-exporter containeroo 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/containeroo/filesystem-exporter:v1.5.2a66121e16d4e
stdlib@go1.26.1
1.26.9

Open the chart page →

1,782
kube-ephemeral-container-exportercontainerooVerified publisher0.2.31 of 1See more

kube-ephemeral-container-exporter containeroo 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/containeroo/kube-ephemeral-container-exporter:v0.0.14b238f3c58d83
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

682
terrascalercontainerooVerified publisher0.1.01 of 1See more

terrascaler containeroo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/containeroo/terrascaler:v0.1.0b152a8514bd3
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

469
containers-security-chartscontainers-security0.1.03 of 7See more

containers-security-charts containers-security 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.26.9
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.26.9
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.18.1
0.60.0
1.26.9

Open the chart page →

12,396
falcocontainers-security2.4.62 of 2See more

falco containers-security 2.4.6

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.26.9
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.26.9

Open the chart page →

4,459
homeboxcoo-ops-spaceVerified publisher0.1.61 of 1See more

homebox coo-ops-space 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/hay-kot/homebox:v0.9.2e6e0fbd7cca9
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

2,600
coordimap-agentcoordimap-agentVerified publisher0.4.31 of 1See more

coordimap-agent coordimap-agent 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
coordimap/coordimap-agent:latest7748fd0fae9f
golang.org/x/net@v0.38.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,165
cortex-proxycortex-proxyVerified publisher0.4.11 of 1See more

cortex-proxy cortex-proxy 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/peak-scale/observability-tenancy/cortex-proxy:0.4.11838720c13b2
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

920
cortezacorteza1.1.02 of 3See more

corteza corteza 1.1.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.60.0
1.26.9
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
stdlib@go1.23.5
1.26.9

Open the chart page →

10,280
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
golang.org/x/net@v0.21.0
stdlib@go1.19.13
0.60.0
1.26.9

Open the chart page →

5,637

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
library/zookeeper:3.9.5e6b279d01350
stdlib@go1.18.1
1.26.9
2
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
2
linuxserver/cloud9:latest:version-1.29.245c5fe102ff3
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.11
0.60.0
1.26.9
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
2
listmonk/listmonk:latest:v6.2.0f535d59e1499
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.60.0
1.26.9
2
localstack/localstack-pro:latest801a3dff7f6a
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:nojsonv2
0.60.0
1.27.2
2
longhornio/longhorn-manager:v1.2.3dca34321452c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.1
0.60.0
1.26.9
2
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.60.0
1.26.9
2
louislam/uptime-kuma:2.3.29aeb4e51d038
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
2
louislam/uptime-kuma:2.5.5c74379ac4509
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
2
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
2
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.60.0
1.26.9
2
maxrocketinternet/datadog-controller:0.1a867315facf8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
2
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.26.9
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.60.0
1.26.9
2
mesosphere/kubectl:v1.35.0-alpineea01a9387771
golang.org/x/net@v0.43.0
stdlib@go1.25.5
0.60.0
1.26.9
2
mikefarah/yq:4:latest4b3d9475d655
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.60.0
1.26.9
2
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.26.9
2
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.1
0.60.0
1.26.9
2
natsio/nats-server-config-reloader:0.20.147094fcae2f4
stdlib@go1.24.8
1.26.9
2
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.26.9
2
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.26.9
2
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.26.9
2
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.26.9
2
neosmemo/memos:0.31.024c2707ddd8f
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
stdlib@go1.24.4
1.26.9
2
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
2
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.26.9
2
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
golang.org/x/net@v0.14.0
stdlib@go1.19.8
no fix listed
0.60.0
1.26.9
2
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9
2
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
2
openebs/mc:RELEASE.2024-11-21T17-21-54Z4d1b85539919
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2
openebs/minio:RELEASE.2024-12-18T13-15-44Zbb04e41fc1b8
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2
openebs/provisioner-localpv:4.6.099f5116f5cb8
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
2
openfga/openfga:latest:v1.22.09cf9a20af32a
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
golang.org/x/net@v0.24.0
stdlib@go1.20.14
0.60.0
1.26.9
2
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.2
0.60.0
1.26.9
2
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
2
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
2
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.60.0
1.26.9
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.60.0
1.26.9
2
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.145.0a7343f018690
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.161.0:latestfd328de25524
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
2
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.26.9
2

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.