StackRadar

CVE-2026-78660

Unscored

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,566
of 18,071 indexed, latest versions
Container images
6,425
deployed by those charts
Fix available
2 of 3
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,566 of 18,071 indexed charts deploy, on 6,425 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,411
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,172
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-78660GO-2026-6610
Trending
Rank 4 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,566 by stars
ChartLatestAffected imagesRadar Score
free5gcfree5gcVerified publisher0.1.312 of 12See more

free5gc free5gc 0.1.3

12 of the 12 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/mongodb:latestc8babafb7d15
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/udm:v3.4.32f68df062a50
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/upf:v3.4.3b6b362a39fdd
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

16,184
fsmfsmOfficialVerified publisher0.2.112 of 5See more

fsm fsm 0.2.11

2 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.60.0
1.26.9
flomesh/fsm-manager:0.2.1122f849c70b25
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.60.0
1.26.9

Open the chart page →

5,573
function-mesh-operatorfunction-mesh0.2.451 of 1See more

function-mesh-operator function-mesh 0.2.45

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
streamnative/function-mesh:v0.29.04176923db03c
golang.org/x/net@v0.56.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

350
adguard-homegabe565Verified publisher0.3.251 of 2See more

adguard-home gabe565 0.3.25

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.56c64a0b37f7b9
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,226
home-assistantgabe565Verified publisher0.17.01 of 1See more

home-assistant gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:latest3e6710a7ab2a
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

3,025
memosgabe565Verified publisher0.17.01 of 1See more

memos gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/usememos/memos:0.24.04723d86e6797
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

2,006
dexgabibbo974.0.41 of 1See more

dex gabibbo97 4.0.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

4,490
garage-uigarage-uiVerified publisher0.13.01 of 1See more

garage-ui garage-ui 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
noooste/garage-ui:v0.13.0a1444fa10585
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

89
garmgarmVerified publisher4.2.01 of 3See more

garm garm 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/igrikus/garm-operator:4.2.09e24d8a6a3b2
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

1,072
gateboardgateboard1.12.51 of 1See more

gateboard gateboard 1.12.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
udhos/gateboard:1.12.53acc0e7599bf
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

1,854
gateboard-discoverygateboard1.9.51 of 1See more

gateboard-discovery gateboard 1.9.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
udhos/gateboard-discovery:1.9.55567c9363c4c
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

1,561
gboxgboxVerified publisher1.0.51 of 2See more

gbox gbox 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gboxproxy/gbox:v1.0.63a9f4a711d5c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.9
0.60.0
1.26.9

Open the chart page →

3,434
adguard-homegeek-cookbookVerified publisher5.5.21 of 2See more

adguard-home geek-cookbook 5.5.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.7b9974aed13d0
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.9
0.60.0
1.26.9

Open the chart page →

2,623
alertmanager-botgeek-cookbookVerified publisher6.4.21 of 1See more

alertmanager-bot geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
golang.org/x/net@v0.0.0-20181213202711-891ebc4b82d6
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

4,682
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
stdlib@go1.16.8
1.26.9

Open the chart page →

19,125
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

4,520
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.5
0.60.0
1.26.9

Open the chart page →

5,160
gollumgeek-cookbookVerified publisher3.4.21 of 3See more

gollum geek-cookbook 3.4.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/git:latesta4bb51f1a355
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

5,315
influxdb-exportergeek-cookbookVerified publisher1.2.21 of 1See more

influxdb-exporter geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.26.9

Open the chart page →

1,836
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.26.9

Open the chart page →

15,286
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.7
0.60.0
1.26.9

Open the chart page →

3,495
owncastgeek-cookbookVerified publisher3.4.21 of 1See more

owncast geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gabekangas/owncast:0.0.797461aedb580
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

4,252
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

9,407
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.26.9

Open the chart page →

13,059
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.26.9

Open the chart page →

11,685
sambageek-cookbookVerified publisher6.2.21 of 1See more

samba geek-cookbook 6.2.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.26.9

Open the chart page →

3,182
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.26.9

Open the chart page →

14,392
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

17,750
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.5
0.60.0
1.26.9

Open the chart page →

6,642
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latest19f55bcf7bb6
stdlib@go1.24.1
1.26.9

Open the chart page →

2,797
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.26.9

Open the chart page →

8,920
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.32 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

2 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.8512bb8a21483
stdlib@go1.19.10
1.26.9
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.26.9

Open the chart page →

16,735
geo-checkergeo-checkerVerified publisher5.0.01 of 1See more

geo-checker geo-checker 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ymuski/geo-checker:5.0.05ba7fd8c7bdc
stdlib@go1.25.3
1.26.9

Open the chart page →

1,887
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9

Open the chart page →

3,665
gigapipegigapipeVerified publisher0.3.01 of 1See more

gigapipe gigapipe 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/metrico/gigapipe:v4.1.6caeb2652ce5e
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

961
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.26.9

Open the chart page →

7,577
gitea-sonarqube-botgitea-sonarqube-botOfficialVerified publisher0.4.01 of 1See more

gitea-sonarqube-bot gitea-sonarqube-bot 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,572
git-hubbygit-hubbyOfficialVerified publisher1.20.111 of 1See more

git-hubby git-hubby 1.20.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/interhyp/git-hubby:0.8.1724b8257c0bda
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

125
github-platform-operatorgithub-platform-operatorVerified publisher0.7.81 of 1See more

github-platform-operator github-platform-operator 0.7.8

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/pierinho13/github-platform-operator:v0.7.88b5cb8098f76
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

131
github-stsgithub-sts-helmVerified publisher0.1.11 of 1See more

github-sts github-sts-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/depthmark/github-sts:0.1.129fda68298da
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

127
gitops-reversergitops-reverserVerified publisher0.52.01 of 1See more

gitops-reverser gitops-reverser 0.52.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/configbutler/gitops-reverser:0.52.0a44138514b30
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

76
prometheus-kafka-exportergkarthiks0.1.31 of 1See more

prometheus-kafka-exporter gkarthiks 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:latestd1014f41712d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

76
temporalglasskubeVerified publisher0.45.2-gk.110 of 14See more

temporal glasskube 0.45.2-gk.1

10 of the 14 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
golang.org/x/net@v0.27.0
stdlib@go1.22.3
0.60.0
1.26.9
temporalio/server:1.25.08a5798191dea
golang.org/x/net@v0.28.0
stdlib@go1.22.3
0.60.0
1.26.9
temporalio/ui:2.30.25c2a3645d09c
golang.org/x/net@v0.28.0
stdlib@go1.22.1
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

21,966
daos-operatorgluesysVerified publisher0.1.51 of 1See more

daos-operator gluesys 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/gluesys/daos-operator:v0.1.0-rc.4c38bd9a7691c
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

78
relay-proxygo-feature-flagOfficialVerified publisher1.56.01 of 1See more

relay-proxy go-feature-flag 1.56.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gofeatureflag/go-feature-flag:v1.56.0cd0923bccbd1
golang.org/x/net@v0.59.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

76
go-hello-world-chartgo-hello-worldVerified publisher1.8.31 of 1See more

go-hello-world-chart go-hello-world 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wasilak/go-hello-world:1.8.366d353e7693f
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

1,109
gomenhashaigomenhashaiOfficialVerified publisher1.3.41 of 1See more

gomenhashai gomenhashai 1.3.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/gomenhashai/gomenhashai:v1.3.36f031172a5ec
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

935
gorse-enterprisegorse-io0.4.23 of 5See more

gorse-enterprise gorse-io 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9

Open the chart page →

6,417
gotosocialgotosocialVerified publisher0.2.321 of 1See more

gotosocial gotosocial 0.2.32

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
superseriousbusiness/gotosocial:0.22.10078ca451dda
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

528
meta-monitoringgrafana1.3.02 of 2See more

meta-monitoring grafana 1.3.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.60.0
1.26.9
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.26.9

Open the chart page →

4,694

Container images carrying it

6,425 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9
7
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
7
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/net@v0.30.0
stdlib@go1.23.4
0.60.0
1.26.9
7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9
7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9
7
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.60.0
1.26.9
7
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
7
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
7
bitnami/kubectl:latest999d5eb28f40
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
6
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.60.0
1.26.9
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9
6
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
6
cloudflare/cloudflared:2026.10.0:latest9b49eed8f628
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
6
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.60.0
1.26.9
6
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
6
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.60.0
1.26.9
6
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9
6
library/mariadb:10:10.117db29378d4fd
stdlib@go1.24.6
1.26.9
6
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.26.9
6
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9
6
library/registry:2:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.26.9
6
library/ubuntu:latestf144425ff09b
stdlib@go1.26.7
1.26.9
6
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.26.9
6
postgis/postgis:17-3.5:latest01a6a70e41e6
stdlib@go1.18.2
1.26.9
6
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.60.0
1.26.9
6
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
6
traefik/whoami:latest:v1.12.0c4717a8d1f01
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
6
victoriametrics/operator:v0.75.078da26b41a81
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
6
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.60.0
1.26.9
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.26.9
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.60.0
1.26.9
6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.60.0
1.26.9
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.60.0
1.26.9
6
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.26.9
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.60.0
1.26.9
6
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.60.0
1.26.9
6
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.60.0
1.26.9
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
6
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
6
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.106b52bd4dbe3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
6
quay.io/prometheus/pushgateway:v1.11.491a56b89b97d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
6
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
6
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
6
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9
6

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.