StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
nacosygqygq2Verified publisher2.1.102 of 4See more

nacos ygqygq2 2.1.10

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.26.9
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.26.9

Open the chart page →

7,077
sealed-secretsbitnamiVerified publisher2.5.191 of 1See more

sealed-secrets bitnami 2.5.19

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,055
mariadbcloudpirates-mariadbVerified publisher0.16.161 of 1See more

mariadb cloudpirates-mariadb 0.16.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:13.0.2f1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

1,782
difydoubanVerified publisher0.10.04 of 6See more

dify douban 0.10.0

4 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.26.9
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.60.0
1.26.9
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.60.0
1.26.9
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.26.9

Open the chart page →

83,750
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.5.02 of 3See more

kubeshark kubeshark-helm-charts 53.5.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubeshark/hub:v53.50532936678f8
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2
kubeshark/worker:v53.51f3e121224f8
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,281
secrets-store-csi-driversecret-store-csi-driver1.6.14 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/csi-secrets-store/driver-crds:v1.6.1cdacfdbe8966
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

2,941
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.31 of 2See more

stackgres-operator stackgres-charts 1.19.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

3,032
victoria-logs-singlevictoriametricsVerified publisher0.13.101 of 1See more

victoria-logs-single victoriametrics 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.53.0251121fa882a
stdlib@go1.27.1
1.27.2

Open the chart page →

89
mongodbcloudpirates-mongodbVerified publisher0.20.01 of 1See more

mongodb cloudpirates-mongodb 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:9.0.2bac22ea7710d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,244
kube-image-keeperenixVerified publisher2.3.11 of 1See more

kube-image-keeper enix 2.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/enix/kube-image-keeper:2.3.1d3ccf28495c3
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

229
mattermost-team-editionmattermostVerified publisher6.6.1081 of 4See more

mattermost-team-edition mattermost 6.6.108

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:11.11.16ad5912b4587
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

2,045
code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
stdlib@go1.16.4
1.26.9

Open the chart page →

18,186
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

706
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
stdlib@go1.26.5
1.26.9

Open the chart page →

2,186
pulsarapache4.7.06 of 10See more

pulsar apache 4.7.0

6 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
victoriametrics/operator:v0.68.3f52e1bd679cb
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

13,072
miniocloudpirates-minioVerified publisher0.14.01 of 1See more

minio cloudpirates-minio 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,670
vertical-pod-autoscalercowboysysopVerified publisher11.1.14 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

9,019
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.26.9
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
langgenius/dify-api:1.16.1dcefa5f7c47c
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

74,916
eclipse-cheeclipse-cheVerified publisher7.123.01 of 1See more

eclipse-che eclipse-che 7.123.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.123.0d926b6d183a1
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,116
pyroscopegrafana2.4.02 of 3See more

pyroscope grafana 2.4.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/alloy:v1.19.2b8ec653c4423
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,762
botkubeinfracloudioVerified publisher1.14.01 of 1See more

botkube infracloudio 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.60.0
1.26.9

Open the chart page →

1,587
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,332
thanosthanos-communityOfficialVerified publisher0.47.11 of 1See more

thanos thanos-community 0.47.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

426
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.26.9

Open the chart page →

2,435
tetragonciliumOfficialVerified publisher1.7.12 of 3See more

tetragon cilium 1.7.1

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/cilium/tetragon-operator:v1.7.1cd8b71f6860e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

512
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

5,565
k6-operatorgrafana4.6.01 of 1See more

k6-operator grafana 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/grafana/k6-operator:controller-v1.6.0ba7f0fc1e22e
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

283
rabbitmqgroundhog2k2.3.91 of 2See more

rabbitmq groundhog2k 2.3.9

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6446551b26c0b
stdlib@go1.22.2
1.26.9

Open the chart page →

1,296
telegrafinfluxdata1.8.771 of 1See more

telegraf influxdata 1.8.77

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/telegraf:1.40-alpine6606553b5019
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

141
k8tzk8tzOfficialVerified publisher0.20.01 of 1See more

k8tz k8tz 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/k8tz/k8tz:0.20.0361628e53fc8
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

218
kiali-serverkiali2.33.01 of 1See more

kiali-server kiali 2.33.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kiali/kiali:v2.33.0082246cfc99f
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

456
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

845
vela-corekubevela1.11.03 of 3See more

vela-core kubevela 1.11.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
oamdev/cluster-gateway:v1.9.0-alpha.25591e29d66a2
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
oamdev/kube-webhook-certgen:v2.4.1231c423c2b17
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.11
0.60.0
1.26.9
oamdev/vela-core:v1.11.095fa412c934e
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

6,663
oktetooktetoOfficialVerified publisher0.0.0-2026-08-317 of 10See more

okteto okteto 0.0.0-2026-08-31

7 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/okteto/backend:0.0.0-2026-08-316171cb2b2a72
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.60.0
1.26.9
ghcr.io/okteto/buildkit:0.0.0-2026-08-3114527ca5d2a9
golang.org/x/net@v0.55.0
stdlib@go1.25.7
0.60.0
1.26.9
ghcr.io/okteto/daemon:0.0.0-2026-08-31c6e716a3fbbe
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-31d6730eb9831b
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/okteto/okteto:3.23.0-beta.1a0483d47ba04
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/okteto/registry:0.0.0-2026-08-3169131511501f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/okteto/reloader:0.0.0-2026-08-3104a3fce657c4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

7,823
hydraory0.64.02 of 2See more

hydra ory 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,950
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

1,344
proxmox-csi-pluginproxmox-csi0.5.127 of 7See more

proxmox-csi-plugin proxmox-csi 0.5.12

7 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-csi-controller:v0.20.095ef74cce03e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

3,558
victoria-metrics-singlevictoriametricsVerified publisher0.48.01 of 1See more

victoria-metrics-single victoriametrics 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
victoriametrics/victoria-metrics:v1.153.05eff7af5341e
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

137
yourlsyourlsOfficialVerified publisher8.10.51 of 2See more

yourls yourls 8.10.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9

Open the chart page →

2,619
apisix-ingress-controllerapisix1.4.01 of 2See more

apisix-ingress-controller apisix 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

2,247
volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,833
concourseconcourseVerified publisher20.3.12 of 2See more

concourse concourse 20.3.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
concourse/concourse:8.3.1c9d48dfbf4f9
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

2,201
dynatrace-operatordynatraceVerified publisher1.11.01 of 1See more

dynatrace-operator dynatrace 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.11.05b772cfaad48
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.60.0
1.26.9

Open the chart page →

5,327
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

2,431
oncallgrafana1.16.57 of 12See more

oncall grafana 1.16.5

7 of the 12 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

23,232
k8sgpt-operatork8sgptOfficialVerified publisher0.2.292 of 2See more

k8sgpt-operator k8sgpt 0.2.29

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.2982d0adcce816
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,654
node-feature-discoverynode-feature-discoveryOfficialVerified publisher0.19.01 of 1See more

node-feature-discovery node-feature-discovery 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

480
openprojectopenproject-helm-chartsOfficialVerified publisher13.13.11 of 5See more

openproject openproject-helm-charts 13.13.1

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9

Open the chart page →

21,839
kratosory0.64.01 of 1See more

kratos ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
oryd/kratos:v26.2.02a13bb8d362c
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

1,227

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
automatischio/automatisch:0.15.03bace7a12d5f
stdlib@go1.23.8
1.26.9
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
1
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.60.0
1.26.9
1
axllent/mailpit:v1.31.198b916bd3c8d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
axllent/mailpit:v1.31.0c96991d9bef7
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
1
ayushsobti/kube-monkey:v0.7.0fc181870c60f
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
b3log/siyuan:v3.1.2595c0d129bc19
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
1
b3log/siyuan:v3.8.5d740a1d3ed6b
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
basa/spki-fingerprint-exporter:0.7.234cadcaa29c4
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
baserow/backend:2.4.0af9aa6fe8482
golang.org/x/net@v0.58.0
stdlib@go1.25.14
0.60.0
1.26.9
1
baserow/backend:1.31.1e0b3c8130b91
stdlib@go1.19.8
1.26.9
1
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
1
bbernhard/signal-cli-rest-api:latest2cf09d66a86f
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.17.8
0.60.0
1.26.9
1
beanbag/reviewboard:latest6b840f546e1c
stdlib@go1.18.1
1.26.9
1
bedag/goblackhole:0.2.0447a88598f4c
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.6
0.60.0
1.26.9
1
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/net@v0.37.0
stdlib@go1.23.12
0.60.0
1.26.9
1
beopenit/door-cd-operator:v3.0.4d3999cb8d026
golang.org/x/net@v0.17.0
stdlib@go1.23.9
0.60.0
1.26.9
1
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/net@v0.15.0
stdlib@go1.19.13
0.60.0
1.26.9
1
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
1
berkeleyskypilot/skypilot:0.14.0a8362d205365
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.60.0
1.26.9
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
golang.org/x/net@v0.38.0
stdlib@go1.23.5
0.60.0
1.26.9
1
betterdb/monitor:0.49.0-no-ai97dcd2d2192f
stdlib@go1.26.8
1.26.9
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.6
0.60.0
1.26.9
1
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/net@v0.2.0
stdlib@go1.17.6
0.60.0
1.26.9
1
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/net@v0.0.0-20220418201149-a630d4f3e7a2
stdlib@go1.19.3
0.60.0
1.26.9
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.26.9
1
binrc/headcni:1.0.10e199c334b957
golang.org/x/net@v0.53.0
stdlib@go1.22.10
0.60.0
1.26.9
1
binwiederhier/ntfy:v2.28.06ef4b819f722
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
1
binwiederhier/ntfy:v2.6.283e2e43d9956
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.60.0
1.26.9
1
bitnami/haproxy:latest5b57bac338a2
golang.org/x/net@v0.59.0
0.60.0
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.60.0
1.26.9
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
bitnamilegacy/git:latest4b08d0c5af8d
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.60.0
1.26.9
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
stdlib@go1.20.5
1.26.9
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
stdlib@go1.19.6
1.26.9
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
stdlib@go1.18.2
1.26.9
1
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.60.0
1.26.9
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
stdlib@go1.18.2
1.26.9
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
stdlib@go1.21.10
1.26.9
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.26.9
1
bitnamilegacy/kubectl:1.301249fc292e84
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.60.0
1.26.9
1
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.60.0
1.26.9
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.60.0
1.26.9
1
bitnamilegacy/kube-state-metrics:204a3044b384b
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
1
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.