StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
monitoringkubegems44.3.41 of 1See more

monitoring kubegems 44.3.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubegems/alertproxy:v0.4.2eaee03055329
stdlib@go1.18.10
1.26.9

Open the chart page →

1,366
kube-monkeykubemonkey1.11.01 of 1See more

kube-monkey kubemonkey 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.7.0fc181870c60f
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

124
kubenursekubenurseVerified publisher1.15.41 of 1See more

kubenurse kubenurse 1.15.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
postfinance/kubenurse:v1.15.4f76ce08ab7b4
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

124
kube-oidc-proxykube-oidc-proxyVerified publisher1.8.11 of 1See more

kube-oidc-proxy kube-oidc-proxy 1.8.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/rafpe/kube-oidc-proxy:1.8.1300f51feb1a7
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

177
kubernetes-events-exporterkubernetes-events-exporter0.1.21 of 1See more

kubernetes-events-exporter kubernetes-events-exporter 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/ownkube/kubernetes-events-exporter:0.1.2bcb7f0f733f5
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

793
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.02 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:10.117db29378d4fd
stdlib@go1.24.6
1.26.9
owncloud/server:10.16.274c53d341076
golang.org/x/net@v0.52.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

11,774
tailscalekubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

tailscale kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
tailscale/tailscale:v1.96.5dbeff02d2337
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

1,431
kubernetes-stateless-chartkubernetes-stateless-chart1.0.31 of 1See more

kubernetes-stateless-chart kubernetes-stateless-chart 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

4,131
kubescoutkubescouteVerified publisher0.1.11 of 1See more

kubescout kubescoute 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/haedalwang/kubescout:0.1.107d51f838f0d
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,124
kubeseal-webguikubeseal-webgui6.0.41 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

5,097
kubeseckubesecVerified publisher1.1.01 of 1See more

kubesec kubesec 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubesec/kubesec:latest6735b7f3d1c8
stdlib@go1.27.1
1.27.2

Open the chart page →

283
kube-site-followerkube-site-follower0.1.141 of 2See more

kube-site-follower kube-site-follower 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,379
juicefskubesphere-stable0.16.21 of 4See more

juicefs kubesphere-stable 0.16.2

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/net@v0.9.0
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

3,421
mesherykubesphere-stable0.5.012 of 13See more

meshery kubesphere-stable 0.5.0

12 of the 13 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
layer5/meshery:stable-latest78a8be21bef3
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
layer5/meshery-app-mesh:stable-latest77d59943b3d6
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.60.0
1.26.9
layer5/meshery-consul:stable-latest25a4cc38abcd
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b297
stdlib@go1.13.1
0.60.0
1.26.9
layer5/meshery-istio:stable-latestfde47c141ec6
golang.org/x/net@v0.36.0
stdlib@go1.23.9
0.60.0
1.26.9
layer5/meshery-kuma:stable-latest9d25f029a8a2
golang.org/x/net@v0.17.0
stdlib@go1.23.4
0.60.0
1.26.9
layer5/meshery-linkerd:stable-latestb99c73bac1f5
golang.org/x/net@v0.19.0
stdlib@go1.23.6
0.60.0
1.26.9
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.60.0
1.26.9
layer5/meshery-nsm:stable-latestebd6a8faf21f
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.12
0.60.0
1.26.9
layer5/meshery-operator:stable-latest6f58a28fe422
golang.org/x/net@v0.33.0
stdlib@go1.23.9
0.60.0
1.26.9
layer5/meshery-osm:stable-latestec898e5786c6
golang.org/x/net@v0.5.0
stdlib@go1.19.8
0.60.0
1.26.9
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.60.0
1.26.9

Open the chart page →

33,960
aws-efs-csi-driverkubesphere-testVerified publisher0.1.01 of 3See more

aws-efs-csi-driver kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.60.0
1.26.9

Open the chart page →

3,825
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

8,519
kube-state-metricskubestar-state-metricsVerified publisher0.1.101 of 1See more

kube-state-metrics kubestar-state-metrics 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

2,393
kubetailkubetailVerified publisher0.26.03 of 3See more

kubetail kubetail 0.26.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubetail-org/kubetail-cluster-agent:0.7.1a5eee8cab215
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9
ghcr.io/kubetail-org/kubetail-cluster-api:0.8.28e6acd0da9ac
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.60.0
1.26.9
ghcr.io/kubetail-org/kubetail-dashboard:0.17.08617f0a7f703
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

2,982
kubeuserkubeuserOfficialVerified publisher0.1.21 of 1See more

kubeuser kubeuser 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/openkube-hub/kubeuser-controller:0.1.227cc7b4dfa0a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

131
kube-vault-controllerkube-vault-controller1.2.01 of 1See more

kube-vault-controller kube-vault-controller 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.60.0
1.26.9

Open the chart page →

2,160
kube-vip-cloud-providerkube-vip0.2.101 of 1See more

kube-vip-cloud-provider kube-vip 0.2.10

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubevip/kube-vip-cloud-provider:v0.0.12f8f4e3401f76
golang.org/x/net@v0.37.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,254
admission-controllerkubewardenVerified publisher6.1.02 of 2See more

admission-controller kubewarden 6.1.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubewarden/adm-controller/audit-scanner:v1.38.2c3dda1e1149a
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/kubewarden/adm-controller/controller:v1.38.2383f71d05b44
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

262
runtime-enforcerkubewardenVerified publisher0.2.13 of 3See more

runtime-enforcer kubewarden 0.2.1

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.161.0fd328de25524
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/kubewarden/runtime-enforcer/agent:v0.10.1dc463d8f7553
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/kubewarden/runtime-enforcer/controller:v0.10.1b005743f7868
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

406
kubiks-agentkubiksVerified publisher0.4.03 of 3See more

kubiks-agent kubiks 0.4.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/beyla:2.2.2a9cf4560472e
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.60.0
1.26.9
otel/opentelemetry-collector-contrib:0.128.01ab0baba0ee3
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9
ghcr.io/kubiks-inc/kubiks-k8s-agent:latest8611f74b4b99
golang.org/x/net@v0.34.0
stdlib@go1.23.10
0.60.0
1.26.9

Open the chart page →

4,568
kubemodkubmod0.5.22 of 2See more

kubemod kubmod 0.5.2

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.19.11f8154f7e80c
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.18
0.60.0
1.26.9
kubemod/kubemod-crt:v1.3.0028347c9fa77
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.18.1
0.60.0
1.26.9

Open the chart page →

6,471
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.15 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

5 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
golang.org/x/net@v0.11.0
stdlib@go1.19.12
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

10,236
kubeservice-cpupools-controllerkubservice-chartsVerified publisher0.1.12 of 2See more

kubeservice-cpupools-controller kubservice-charts 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9

Open the chart page →

4,376
kubeservice-custom-limitrangekubservice-chartsVerified publisher1.3.05 of 5See more

kubeservice-custom-limitrange kubservice-charts 1.3.0

5 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubeservice-stack/customlimitrange-manager:v1.3.0d3ed97d142d4
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

9,096
kubeservice-ebpf-exporterkubservice-chartsVerified publisher1.2.11 of 1See more

kubeservice-ebpf-exporter kubservice-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cloudflare/ebpf_exporter:v2.3.075370b2ec2bb
stdlib@go1.21.5
1.26.9

Open the chart page →

997
kubeservice-namespace-node-affinitykubservice-chartsVerified publisher1.1.25 of 5See more

kubeservice-namespace-node-affinity kubservice-charts 1.1.2

5 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dongjiang1989/ns-node-affinity:latest451f7823723c
golang.org/x/net@v0.7.0
stdlib@go1.18.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

10,181
kubeservice-scheduler-pluskubservice-chartsVerified publisher0.2.12 of 2See more

kubeservice-scheduler-plus kubservice-charts 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
golang.org/x/net@v0.7.0
stdlib@go1.19.9
0.60.0
1.26.9
dongjiang1989/node-metrics:latest3f1f266190bb
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

2,600
ingress-annotatorkuossOfficialVerified publisher0.3.01 of 1See more

ingress-annotator kuoss 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kuoss/ingress-annotator:v0.3.0ae179f65d869
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

888
kitcaddykvalitetsitVerified publisher1.5.111 of 2See more

kitcaddy kvalitetsit 1.5.11

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kvalitetsit/kitcaddy:1.5.110e66907ea266
golang.org/x/net@v0.55.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

336
kube-fencingkvaps2.4.12 of 2See more

kube-fencing kvaps 2.4.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.8
0.60.0
1.26.9
ghcr.io/kvaps/kube-fencing-switcher:v2.4.0f8c378e63b78
stdlib@go1.18.8
1.26.9

Open the chart page →

3,966
linstorkvaps1.14.04 of 11See more

linstor kvaps 1.14.0

4 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15.14
0.60.0
1.26.9
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.15.14
0.60.0
1.26.9
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.60.0
1.26.9
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.14
0.60.0
1.26.9

Open the chart page →

22,044
kymaroskymarosVerified publisher0.6.91 of 1See more

kymaros kymaros 0.6.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kymaroshq/kymaros:0.6.9fb3b88633381
golang.org/x/net@v0.50.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

566
chibisafel4gVerified publisher0.1.12 of 3See more

chibisafe l4g 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
stdlib@go1.20.12
1.26.9
library/caddy:2-alpined44355d3c214
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

5,940
auditflowlabs64io-helm-chartsVerified publisher0.15.171 of 3See more

auditflow labs64io-helm-charts 0.15.17

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinned9c1bd414fcfb
stdlib@go1.26.7
1.26.9

Open the chart page →

656
authz-pdplabs64io-helm-chartsVerified publisher0.8.71 of 1See more

authz-pdp labs64io-helm-charts 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cerbos/cerbosdigest-pinned540643bc67ba
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
checkoutlabs64io-helm-chartsVerified publisher0.11.82 of 3See more

checkout labs64io-helm-charts 0.11.8

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
labs64/checkoutdigest-pinned4009b8251b57
stdlib@go1.26.7
1.26.9
library/postgres:1874935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

2,388
payment-gatewaylabs64io-helm-chartsVerified publisher0.10.82 of 2See more

payment-gateway labs64io-helm-charts 0.10.8

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
labs64/payment-gatewaydigest-pinned5421f763b53e
stdlib@go1.26.7
1.26.9
library/postgres:1874935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

2,366
lagoon-remotelagoon-chartsVerified publisher0.107.01 of 1See more

lagoon-remote lagoon-charts 0.107.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

2,999
lakilakiOfficialVerified publisher1.11.01 of 2See more

laki laki 1.11.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/laki-n/laki:v1.6.0599a10c453a3
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

663
landelijketabellencataloguslandelijketabellencatalogus1.0.01 of 3See more

landelijketabellencatalogus landelijketabellencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,415
glancelbenicio-communityVerified publisher0.1.31 of 1See more

glance lbenicio-community 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
glanceapp/glance:latest9dfb09470b20
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

299
lgtmlgtmVerified publisher0.28.17 of 9See more

lgtm lgtm 0.28.1

7 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:13.2.2-distroless69a5d2d957ca
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
grafana/loki:3.7.81107dd5274e0
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
grafana/pyroscope:2.3.186a9ee744848
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
grafana/tempo:2.10.8f0561deb1c68
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.159.02ceb3b541295
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,067
lgtm-stacklgtm-stackVerified publisher0.1.35 of 8See more

lgtm-stack lgtm-stack 0.1.3

5 of the 8 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.10f4434c92b3e
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/grafana:13.1.0121a7a9ece6d
golang.org/x/net@v0.55.0
stdlib@go1.25.7
0.60.0
1.26.9
grafana/loki:3.7.6efd47c67f9ba
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/mimir:3.2.0736f7459913d
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/tempo:2.10.8f0561deb1c68
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

3,950
keptn-cert-managerlifecycle-toolkitVerified publisher0.3.01 of 1See more

keptn-cert-manager lifecycle-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

953
keptn-lifecycle-operatorlifecycle-toolkitVerified publisher0.6.01 of 1See more

keptn-lifecycle-operator lifecycle-toolkit 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,069
keptn-metrics-operatorlifecycle-toolkitVerified publisher0.5.01 of 1See more

keptn-metrics-operator lifecycle-toolkit 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
golang.org/x/net@v0.37.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,305

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
stdlib@go1.20.12
1.26.9
1
anchore/anchore-engine:v0.10.0bde9eedf639d
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.16.3
0.60.0
1.26.9
1
anchore/ecs-inventory:v1.5.12b424b3b9a03
stdlib@go1.26.8
1.26.9
1
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.60.0
1.26.9
1
anchore/kubernetes-admission-controller:v0.8.51a1a374658c8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.60.0
1.26.9
1
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.60.0
1.26.9
1
andreacioni/kube-workload-restarter:0.0.242938b310090a
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.60.0
1.26.9
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.26.9
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
stdlib@go1.18.2
1.26.9
1
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.26.9
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.26.9
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
golang.org/x/net@v0.58.0
stdlib@go1.25.7
0.60.0
1.26.9
1
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
antrea/antrea-ui-backend:v0.8.019f3c0113330
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
antrea/flow-aggregator:v2.7.0065193e7572f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.26.9
1
anujdatar/cups:25.07.01685df04a643b
stdlib@go1.19.8
1.26.9
1
apache/airflow:2.8.4-python3.964e58748b6b9
stdlib@go1.21.8
1.26.9
1
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
stdlib@go1.23.7
1.26.9
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
stdlib@go1.22.7
1.26.9
1
apache/airflow:2.8.1e5560ad0b86e
stdlib@go1.19.8
1.26.9
1
apache/answer:2.0.2a0d71b0e30a5
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
1
apache/apisix-dashboard:2.9.0c010ea7d1694
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.15
0.60.0
1.26.9
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.13.8
0.60.0
1.26.9
1
apache/camel-k:1.10.43bb13d14f64a
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.13
0.60.0
1.26.9
1
apache/camel-k:2.11.0d173e7efe258
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
1
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9
1
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.60.0
1.26.9
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.60.0
1.26.9
1
apache/solr-operator:v0.9.14db34508137f
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
1
apache/tika:3.3.1.090b7fa1dc018
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.60.0
1.26.9
1
apache/tika:latest-fullab9cc988828c
stdlib@go1.26.7
1.26.9
1
apache/yunikorn:scheduler-1.10.049fc54894fdf
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
apache/yunikorn:web-1.10.090e6a62a578a
stdlib@go1.26.7
1.26.9
1
apache/yunikorn:admission-1.10.095c6b951f38a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
apecloud/dt-platform:0.1.1d48bcbd38066
golang.org/x/net@v0.8.0
stdlib@go1.19.11
0.60.0
1.26.9
1
apecloud/gemini-scheduler:0.1.15832d1a9097a
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.60.0
1.26.9
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.60.0
1.26.9
1
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.13
0.60.0
1.26.9
1
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
1
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
stdlib@go1.19.6
0.60.0
1.26.9
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/net@v0.5.0
stdlib@go1.19.13
0.60.0
1.26.9
1
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/net@v0.40.0
stdlib@go1.25.7
0.60.0
1.26.9
1
appwrite/appwrite:2.3.034ef77fb6e87
golang.org/x/net@v0.51.0
stdlib@go1.26.8
0.60.0
1.26.9
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.60.0
1.26.9
1
aquasec/kube-bench:v0.6.176672264accce
stdlib@go1.20.4
1.26.9
1
aquasec/kube-bench:v0.15.07a8fa32dce21
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.