StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
prometheus-pingmesh-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-pingmesh-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:v1.2.2c82de0272da0
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.60.0
1.26.9

Open the chart page →

1,399
prometheus-sql-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-sql-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/justwatchcom/sql_exporter:v0.8c4b1d3d0f052
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,943
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.26.9
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.26.9
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.60.0
1.26.9

Open the chart page →

15,870
dockerhub-exporterpromhippieVerified publisher2.16.01 of 1See more

dockerhub-exporter promhippie 2.16.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/promhippie/dockerhub-exporter:2.17.0cbf4ef61e675
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

218
hcloud-exporterpromhippieVerified publisher4.30.01 of 1See more

hcloud-exporter promhippie 4.30.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/promhippie/hcloud-exporter:3.30.0f1dba83dfd23
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

218
prowlerprowler-appVerified publisher0.0.92 of 5See more

prowler prowler-app 0.0.9

2 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9
prowlercloud/prowler-api:5.31.14f252d579be2
golang.org/x/net@v0.54.0
stdlib@go1.26.3-X:jsonv2
0.60.0
1.26.9

Open the chart page →

10,321
pulumi-kubernetes-operatorpulumi-kubernetes-operator2.9.31 of 1See more

pulumi-kubernetes-operator pulumi-kubernetes-operator 2.9.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
pulumi/pulumi-kubernetes-operator:v2.9.30a0f20eeb071
golang.org/x/net@v0.59.0
0.60.0

Open the chart page →

82
operatorpunchplatform8.1.131 of 1See more

operator punchplatform 8.1.13

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
golang.org/x/net@v0.20.0
stdlib@go1.22.0
0.60.0
1.26.9

Open the chart page →

1,372
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

2,557
go-kube-downscalerpy-kube-downscalerVerified publisher1.4.11 of 1See more

go-kube-downscaler py-kube-downscaler 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/caas-team/gokubedownscaler:1.4.1da4507aa387b
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

261
pyramidanalyticspyramidanalyticsVerified publisher2025.11.2761 of 9See more

pyramidanalytics pyramidanalytics 2025.11.276

1 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:latestefd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

280
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

64,173
qt-vaultqt-vaultVerified publisher0.1.21 of 1See more

qt-vault qt-vault 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/mcman2017/qt-vault:v0.1.2852edf54c850
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

728
caddyquench-caddyVerified publisher0.0.171 of 1See more

caddy quench-caddy 0.0.17

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/caddydigest-pinned015a4b181ab2
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

235
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

7,993
rabbitmqrabbitmq-magefleet1.2.01 of 1See more

rabbitmq rabbitmq-magefleet 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.26.9

Open the chart page →

3,595
jobs-managerraczylo-comVerified publisher0.1.311 of 1See more

jobs-manager raczylo-com 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/lukaszraczylo/jobs-manager-operator:0.1.31f0c966fb135e
stdlib@go1.26.8
1.26.9

Open the chart page →

141
kube-images-syncraczylo-comVerified publisher0.5.691 of 1See more

kube-images-sync raczylo-com 0.5.69

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/lukaszraczylo/kubernetes-images-sync-operator:0.5.69f32ace076a2d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

201
velero-s3-deploymentradar-baseVerified publisher0.4.32 of 4See more

velero-s3-deployment radar-base 0.4.3

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
velero/velero:v1.9.0277fbfaf8dcf
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.18
0.60.0
1.26.9
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.11
0.60.0
1.26.9

Open the chart page →

5,905
ravendb-operatorravendb-operatorOfficialVerified publisher2.1.01 of 1See more

ravendb-operator ravendb-operator 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ravendb/ravendb-operator:2.1.0511050205ac5
golang.org/x/net@v0.48.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

604
rbac-serverrbac-server1.19.11 of 1See more

rbac-server rbac-server 1.19.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/rbac-server:1.19.1df1adeb86679
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,201
rclonercloneVerified publisher2.2.01 of 1See more

rclone rclone 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rclone/rclone:1.6874c51b8817e5
golang.org/x/net@v0.27.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

2,229
redis-enterprise-operatorredis-enterprise-operatorVerified publisher7.13.4-121 of 1See more

redis-enterprise-operator redis-enterprise-operator 7.13.4-12

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
redislabs/operator:7.4.2-2ecb101af0506
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

3,389
redis-chartredis-ha-chartVerified publisher0.1.51 of 2See more

redis-chart redis-ha-chart 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
truebyteinnovationllp/redis-exporter:v1.86.01c6a945af653
stdlib@go1.25.11
1.26.9

Open the chart page →

515
redis-sentinel-gatewayredis-sentinel-gatewayVerified publisher1.0.21 of 1See more

redis-sentinel-gateway redis-sentinel-gateway 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
promzeus/redis-sentinel-gateway:v182f6d56e280b
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.60.0
1.26.9

Open the chart page →

3,475
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
stdlib@go1.24.6
1.26.9

Open the chart page →

5,809
kminionredpanda-dataOfficialVerified publisher0.15.31 of 1See more

kminion redpanda-data 0.15.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
redpandadata/kminion:v2.3.612bc33b3e334
golang.org/x/net@v0.55.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

452
docker-registry-mirrorregistry-mirror1.0.11 of 1See more

docker-registry-mirror registry-mirror 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.26.9

Open the chart page →

1,082
reportportalreportportal-ioOfficialVerified publisher26.8.127 of 15See more

reportportal reportportal-io 26.8.12

7 of the 15 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.26.9
library/rabbitmq:4.3.4-managementeb5295d08332
stdlib@go1.22.2
1.26.9
rancher/kubectl:v1.36.206c7a7a97727
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9
reportportal/k8s-wait-for:latest06cdf299b397
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9
reportportal/migrations:5.15.4464468240d7b
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
reportportal/service-index:5.15.1b1860ed33071
golang.org/x/net@v0.54.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

16,766
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.26.9

Open the chart page →

8,673
resurfaceresurfaceioVerified publisher3.9.03 of 3See more

resurface resurfaceio 3.9.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.60.0
1.26.9
jitesoft/kubectl:latest7f25594d4f33
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
resurfaceio/resurface:3.7.84d5cda2f64109
stdlib@go1.23.0
1.26.9

Open the chart page →

9,117
retyc-csiretyc-csi0.3.03 of 3See more

retyc-csi retyc-csi 0.3.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/retyc/retyc-k8s-csi:v0.3.0551757c204d1
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

2,068
right-sizerright-sizer0.6.21 of 1See more

right-sizer right-sizer 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
aavishay/right-sizer:0.6.23d7c4d79595c
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

671
backup-repository-serverriotkit-org4.0.01 of 1See more

backup-repository-server riotkit-org 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
stdlib@go1.17.13
0.60.0
1.26.9

Open the chart page →

3,042
rke2-canalrke2-charts3.13.32 of 2See more

rke2-canal rke2-charts 3.13.3

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.36d2cd61a338b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.60.0
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.60.0

Open the chart page →

7,401
rke2-ingress-nginxrke2-charts4.15.1112 of 2See more

rke2-ingress-nginx rke2-charts 4.15.111

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/kube-webhook-certgen:v1.14.5-hardened26bb869baf40b
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
rancher/nginx-ingress-controller:v1.14.5-hardened26cbc1e932b5b
golang.org/x/net@v0.52.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,713
cloudflare-tunnelrlex0.8.01 of 1See more

cloudflare-tunnel rlex 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2023.10.0c18744ae1767
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9

Open the chart page →

2,492
hcloud-fip-controllerrlex0.2.51 of 1See more

hcloud-fip-controller rlex 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.15.3
0.60.0
1.26.9

Open the chart page →

4,193
prometheus-webhook-dingtalkrlex0.0.31 of 1See more

prometheus-webhook-dingtalk rlex 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.26.9

Open the chart page →

3,013
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
stdlib@go1.22.6
1.26.9

Open the chart page →

10,854
kimai2robjuz5.0.151 of 2See more

kimai2 robjuz 5.0.15

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:10.6.12-debian-11-r1678847062532a
stdlib@go1.19.7
1.26.9

Open the chart page →

5,662
rocket-chatrocket-chatVerified publisher0.1.51 of 3See more

rocket-chat rocket-chat 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
pgvector/pgvector:pg167b822b0aac60
stdlib@go1.24.6
1.26.9

Open the chart page →

4,229
grafanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

grafana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:8.3.4cf81d2c753c8
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

3,939
jaeger-collectorromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-collector romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

2,690
jaeger-queryromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-query romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jaegertracing/jaeger-query:1.41.0b636f0f464bc
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

2,635
kube-state-metricsromanow-helm-chartsVerified publisher1.7.21 of 1See more

kube-state-metrics romanow-helm-charts 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/kube-state-metrics:204a3044b384b
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

3,437
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
stdlib@go1.19.3
1.26.9

Open the chart page →

8,636
node-exporterromanow-helm-chartsVerified publisher1.7.11 of 1See more

node-exporter romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,426
postgresromanow-helm-chartsVerified publisher1.7.11 of 1See more

postgres romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:15724292da1f2e
stdlib@go1.24.6
1.26.9

Open the chart page →

1,919
prometheusromanow-helm-chartsVerified publisher1.7.21 of 1See more

prometheus romanow-helm-charts 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,748

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.26.9
1
almasood/book-server:latest6ffac9b63cdf
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
1
almir/webhook:2.8.01698346f6077
stdlib@go1.14.7
1.26.9
1
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.15
0.60.0
1.26.9
1
alpine/git:2.47.2062a01ad7a0e
golang.org/x/net@v0.23.0
stdlib@go1.23.9
0.60.0
1.26.9
1
alpine/git:2.36.366b210a97bc0
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.7
0.60.0
1.26.9
1
alpine/git:v2.49.1c0280cf95723
golang.org/x/net@v0.45.0
stdlib@go1.24.8
0.60.0
1.26.9
1
alpine/helm105741fa6621
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
1
alpine/helm:4.1.0905a068da431
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.60.0
1.26.9
1
alpine/k8s:1.22.600ac10bcb759
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.17.6
0.60.0
1.26.9
1
alpine/k8s:1.27.321b24e6bf801
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.20.4
0.60.0
1.26.9
1
alpine/k8s:1.31.106dbe6f391eda
golang.org/x/net@v0.19.0
stdlib@go1.22.7
0.60.0
1.26.9
1
alpine/k8s:1.31.137a319b15cfc9
golang.org/x/net@v0.43.0
stdlib@go1.23.12
0.60.0
1.26.9
1
alpine/k8s:1.32.47e1e7d5b7a96
golang.org/x/net@v0.34.0
stdlib@go1.20.4
0.60.0
1.26.9
1
alpine/k8s:1.31.49c4976d47656
golang.org/x/net@v0.31.0
stdlib@go1.23.2
0.60.0
1.26.9
1
alpine/k8s:1.18.16a41efe02a041
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.60.0
1.26.9
1
alpine/k8s:1.35.6b7a12c5ddf26
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
1
alpine/k8s:1.30.0bd01dae02676
golang.org/x/net@v0.23.0
stdlib@go1.21.1
0.60.0
1.26.9
1
alpine/k8s:1.30.2cd560fce90f7
golang.org/x/net@v0.9.0
stdlib@go1.22.3
0.60.0
1.26.9
1
alpine/k8s:1.35.5d870622d0040
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
1
alpine/k8s:1.28.13e5c0b053fed7
golang.org/x/net@v0.12.0
stdlib@go1.22.5
0.60.0
1.26.9
1
alpine/k8s:1.32.3eec354133193
golang.org/x/net@v0.37.0
stdlib@go1.23.6
0.60.0
1.26.9
1
alpine/k8s:1.28.2fc059f056ad0
golang.org/x/net@v0.9.0
stdlib@go1.20.8
0.60.0
1.26.9
1
alpine/kubectl:1.36.01ee9df6316d4
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9
1
alpine/kubectl:1.33.32c59a3f0726c
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9
1
alpine/kubectl:1.35.0862d86046bbc
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
1
alpine/kubectl:1.35.3c4a11ae9a1cb
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
1
altinity/clickhouse-operator:0.25.41d6f18dbd599
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.60.0
1.26.9
1
altinity/clickhouse-operator:0.23.34baec90b20cd
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9
1
altinity/clickhouse-operator:0.23.774315beb57db
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.60.0
1.26.9
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.13
0.60.0
1.26.9
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.60.0
1.26.9
1
altinity/clickhouse-operator:0.27.1a802b3a19d20
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
1
altinity/clickhouse-operator:0.27.4c60c872fedd8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
1
altinity/metrics-exporter:0.20.01a46d104406d
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.60.0
1.26.9
1
altinity/metrics-exporter:0.23.32912a6c15b44
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9
1
altinity/metrics-exporter:0.25.46ecf67edfb71
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.60.0
1.26.9
1
altinity/metrics-exporter:0.23.7a4d7ff0c727e
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.60.0
1.26.9
1
altinity/metrics-exporter:latesta5206c713de7
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
1
altinity/metrics-exporter:0.27.4d257a72e6a6a
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
1
alustan/install-argocd:1.0.0c16c34f46ad3
golang.org/x/net@v0.19.0
stdlib@go1.22.5
0.60.0
1.26.9
1
amaanx86/oci-native-ingress-controller:masterd7206ac7a319
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.60.0
1.26.9
1
amacneil/dbmate:2.6.03fdce58cc189
stdlib@go1.21.0
1.26.9
1
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.60.0
1.26.9
1
amazon/cloudwatch-agent:latest-arm6432bd729ab859
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
1
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
1
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.15
0.60.0
1.26.9
1
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
golang.org/x/net@v0.11.0
stdlib@go1.20.6
0.60.0
1.26.9
1
ambassador/aes-eg-ext:v4.0.0-preview.1b7eb1be3345d
golang.org/x/net@v0.11.0
stdlib@go1.20.6
0.60.0
1.26.9
1
ambassador/aes-wafsvc:v4.0.0-preview.15fc571509b8c
golang.org/x/net@v0.11.0
stdlib@go1.20.6
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.