StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
castai-evictorcastaiVerified publisher0.35.1483 of 3See more

castai-evictor castai 0.35.148

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/castai/images/cpa/cpvpa:v0.8.14dd5743f37f60
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/castai/images/evictor:v0.35.148937cc7ab4d5d
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.35.64d8c68e8c2bf
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

984
castai-livecastaiVerified publisher0.140.21 of 1See more

castai-live castai 0.140.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/castai/images/clm:v0.140.2566f0c5ff554
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

989
castai-tetragoncastaiVerified publisher0.6.12 of 4See more

castai-tetragon castai 0.6.1

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.19.2
0.60.0
1.26.9
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.18.3
0.60.0
1.26.9

Open the chart page →

6,124
castai-watchdogcastaiVerified publisher0.2.4821 of 1See more

castai-watchdog castai 0.2.482

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/castai/images/watchdog:v0.2.4828f70018e61ca
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

317
castware-componentscastaiVerified publisher0.4.01 of 1See more

castware-components castai 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

4,310
oci-csi-drivercastaiVerified publisher1.13.86 of 7See more

oci-csi-driver castai 1.13.8

6 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

3,733
temporalcastaiVerified publisher0.54.210 of 14See more

temporal castai 0.54.2

10 of the 14 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
temporalio/admin-tools:1.26.237e2e33dbd7b
golang.org/x/net@v0.31.0
stdlib@go1.22.5
0.60.0
1.26.9
temporalio/server:1.26.21e2626efcbc1
golang.org/x/net@v0.31.0
stdlib@go1.23.2
0.60.0
1.26.9
temporalio/ui:2.33.05c586a3c8ec5
golang.org/x/net@v0.17.0
stdlib@go1.23.0
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

23,074
catalyst-agentscatalyst-agents0.1.3514 of 18See more

catalyst-agents catalyst-agents 0.1.35

14 of the 18 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
golang.org/x/net@v0.37.0
stdlib@go1.23.6
0.60.0
1.26.9
grafana/grafana:13.1.3ab5cb380e3ff
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/loki:3.0.0757b5fadf816
golang.org/x/net@v0.22.0
stdlib@go1.21.9
0.60.0
1.26.9
grafana/loki-canary:3.0.028d7c00588aa
golang.org/x/net@v0.22.0
stdlib@go1.21.9
0.60.0
1.26.9
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/net@v0.24.0
stdlib@go1.21.3
0.60.0
1.26.9
otel/opentelemetry-collector-contrib:0.156.0125bdbeb7590
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.25.5
0.60.0
1.26.9
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
golang.org/x/net@v0.52.0
stdlib@go1.25.11
0.60.0
1.26.9
ghcr.io/chaos-mesh/chaos-mesh:v2.8.3bdb31f3121a2
golang.org/x/net@v0.52.0
stdlib@go1.25.11
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.5d0e80b2f62fe
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.93.0a001ed10a382
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

24,898
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.10
0.60.0
1.26.9

Open the chart page →

7,714
openldapccowleyVerified publisher2.0.41 of 3See more

openldap ccowley 2.0.4

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.60.0
1.26.9

Open the chart page →

9,232
openldap_exporterccowleyVerified publisher0.1.01 of 1See more

openldap_exporter ccowley 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
stdlib@go1.15.7
1.26.9

Open the chart page →

3,180
ceems-api-serverceemsVerified publisher0.10.12 of 2See more

ceems-api-server ceems 0.10.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/ceems/ceems:v0.16.14633125698c3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

419
ceems-exporterceemsVerified publisher0.9.01 of 1See more

ceems-exporter ceems 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/ceems/ceems:v0.16.14633125698c3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

218
ceems-lbceemsVerified publisher0.9.01 of 1See more

ceems-lb ceems 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/ceems/ceems:v0.16.14633125698c3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

218
kube-ceemsceemsOfficialVerified publisher1.49.04 of 5See more

kube-ceems ceems 1.49.0

4 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/ceems/ceems:v0.16.14633125698c3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

988
cellcastcellcast0.5.01 of 1See more

cellcast cellcast 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/ethan-kane-ops/cellcast-hub:v0.5.0c450eb54b7e4
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

211
ceph-csi-operatorceph-csi-operator1.1.01 of 1See more

ceph-csi-operator ceph-csi-operator 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/cephcsi/ceph-csi-operator:v1.1.0c42c95c36fa2
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

215
cerberuscerberusVerified publisher0.18.01 of 1See more

cerberus cerberus 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/tsouza/cerberus:1.22.0d181d9145aac
golang.org/x/net@v0.59.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

467
certforge-issuercertforge-issuer0.2.41 of 1See more

certforge-issuer certforge-issuer 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/certforge-llc/certforge-issuer:0.2.430f73d255939
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

213
cert-manager-csi-driver-spiffecert-managerOfficialVerified publisher0.15.04 of 4See more

cert-manager-csi-driver-spiffe cert-manager 0.15.0

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-csi-driver-spiffe:v0.15.01755a3802efd
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-csi-driver-spiffe-approver:v0.15.05f7a9bbb95fb
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,759
cert-manager-acm-synccert-manager-acm-sync0.7.41 of 1See more

cert-manager-acm-sync cert-manager-acm-sync 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/camilorivera/cert-manager-acm-sync:0.7.489a83796a550
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

434
cert-manager-alidns-webhookcert-manager-alidns-webhook0.1.41 of 1See more

cert-manager-alidns-webhook cert-manager-alidns-webhook 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/crazygit/cert-manager-alidns-webhook:0.1.4976be6506eb6
golang.org/x/net@v0.47.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

1,804
cert-manager-desec-webhookcert-manager-desec-webhook1.0.11 of 1See more

cert-manager-desec-webhook cert-manager-desec-webhook 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

2,044
cert-manager-webhook-abioncert-manager-webhook-abion1.3.21 of 1See more

cert-manager-webhook-abion cert-manager-webhook-abion 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
abiondevelopment/cert-manager-webhook-abion:latestc741988fbd23
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

1,817
cert-manager-webhook-bunnycert-manager-webhook-bunnyVerified publisher1.0.21 of 1See more

cert-manager-webhook-bunny cert-manager-webhook-bunny 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/o0th/cert-manager-webhook-bunny:1.0.2fe7ce555a12d
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,379
cert-manager-webhook-civocert-manager-webhook-civoVerified publisher0.0.0-05b683cb6efdc99135f68af18007954e74f184041 of 1See more

cert-manager-webhook-civo cert-manager-webhook-civo 0.0.0-05b683cb6efdc99135f68af18007954e74f18404

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
okteto/civo-webhook:0.5.357cd51176538
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

1,974
cert-manager-webhook-f5xccert-manager-webhook-f5xcVerified publisher0.6.01 of 1See more

cert-manager-webhook-f5xc cert-manager-webhook-f5xc 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wenkow/cert-manager-webhook-f5xc:0.6.00988cebf89bb
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

210
cert-manager-webhook-hcloud-zonescert-manager-webhook-hcloud-zones0.1.51 of 1See more

cert-manager-webhook-hcloud-zones cert-manager-webhook-hcloud-zones 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/cert-manager-webhook-hcloud-zones:0.1.5a7a846bba3e8
golang.org/x/net@v0.52.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

733
cert-manager-webhook-infoblox-wapicert-manager-webhook-infoblox-wapiVerified publisher1.5.21 of 1See more

cert-manager-webhook-infoblox-wapi cert-manager-webhook-infoblox-wapi 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

3,396
cert-manager-webhook-namecheapcert-manager-webhook-namecheap0.1.21 of 1See more

cert-manager-webhook-namecheap cert-manager-webhook-namecheap 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.60.0
1.26.9

Open the chart page →

2,478
cert-manager-webhook-pdnscert-manager-webhook-pdns3.2.51 of 1See more

cert-manager-webhook-pdns cert-manager-webhook-pdns 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
zachomedia/cert-manager-webhook-pdns:v2.5.54940e227a39b
golang.org/x/net@v0.50.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

1,521
cert-manager-webhook-poweradmincert-manager-webhook-poweradmin0.2.161 of 1See more

cert-manager-webhook-poweradmin cert-manager-webhook-poweradmin 0.2.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/poweradmin/cert-manager-webhook-poweradmin:v0.2.166c788f9cb8c4
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

205
cert-manager-webhook-regerycert-manager-webhook-regery1.0.01 of 1See more

cert-manager-webhook-regery cert-manager-webhook-regery 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
darioackermann/cert-manager-webhook-regery:latest0d450bc4acc4
golang.org/x/net@v0.26.0
stdlib@go1.22.10
0.60.0
1.26.9

Open the chart page →

1,448
cert-manager-webhook-solidservercert-manager-webhook-solidserverVerified publisher1.0.21 of 1See more

cert-manager-webhook-solidserver cert-manager-webhook-solidserver 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/niklas-letz/cert-manager-webhook-solidserver:1.0.2f19a306ce759
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

855
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.13
0.60.0
1.26.9
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.60.0
1.26.9

Open the chart page →

9,767
getoutlinecfi20171.2.01 of 4See more

getoutline cfi2017 1.2.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.26.9

Open the chart page →

5,479
opencvecfi20170.1.23 of 7See more

opencve cfi2017 0.1.2

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.26.9
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
stdlib@go1.22.10
1.26.9

Open the chart page →

18,337
clechaosnative0.2.73 of 6See more

cle chaosnative 0.2.7

3 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.15
0.60.0
1.26.9
chaosnative/cle-license-module:2.7.062cf6adc355e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.15
0.60.0
1.26.9
chaosnative/cle-server:2.7.0e7bcff4a20c0
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

19,820
charon-relaycharonOfficialVerified publisher0.8.02 of 2See more

charon-relay charon 0.8.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

5,740
dv-podcharonOfficialVerified publisher0.19.13 of 5See more

dv-pod charon 0.19.1

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
obolnetwork/charon-dkg-sidecar:maine263be0a7440
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

9,517
chart-appchart-app0.3.01 of 2See more

chart-app chart-app 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

2,916
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

6,916
ghostchart-ghost0.1.71 of 2See more

ghost chart-ghost 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/ghost:6.69.0-alpine3.23db4c56c196d6
stdlib@go1.24.6
1.26.9

Open the chart page →

1,110
calibre-webcharts-derwitt-devVerified publisher1.1.41 of 1See more

calibre-web charts-derwitt-dev 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.31086aac67a05
stdlib@go1.17.8
1.26.9

Open the chart page →

6,158
filebrowsercharts-derwitt-devVerified publisher1.1.11 of 1See more

filebrowser charts-derwitt-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.63.23a469ea076d4a
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

448
home-assistant-otbrcharts-derwitt-devVerified publisher2.1.61 of 1See more

home-assistant-otbr charts-derwitt-dev 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/homeassistant-otbr:4.2.7df1ba94bd5c0
stdlib@go1.26.5
1.26.9

Open the chart page →

2,932
paperless-ngxcharts-derwitt-devVerified publisher2.1.61 of 1See more

paperless-ngx charts-derwitt-dev 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.3.06b94799bc769
stdlib@go1.24.4
1.26.9

Open the chart page →

5,102
yas3pcharts-derwitt-devVerified publisher0.3.11 of 1See more

yas3p charts-derwitt-dev 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
denniswitt/yas3p:0.2.488a235619af6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

1,150
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
stdlib@go1.20.12
1.26.9

Open the chart page →

2,772
checker-edgechecker-edge1.1.111 of 1See more

checker-edge checker-edge 1.1.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/imcitius/checker-edge:1.1.1174426c1fe00f
golang.org/x/net@v0.50.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,253

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.60.0
1.26.9
1
axllent/mailpit:v1.31.198b916bd3c8d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
axllent/mailpit:v1.31.0c96991d9bef7
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
1
ayushsobti/kube-monkey:v0.7.0fc181870c60f
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
b3log/siyuan:v3.1.2595c0d129bc19
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
1
b3log/siyuan:v3.8.5d740a1d3ed6b
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
basa/spki-fingerprint-exporter:0.7.234cadcaa29c4
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
baserow/backend:2.4.0af9aa6fe8482
golang.org/x/net@v0.58.0
stdlib@go1.25.14
0.60.0
1.26.9
1
baserow/backend:1.31.1e0b3c8130b91
stdlib@go1.19.8
1.26.9
1
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
1
bbernhard/signal-cli-rest-api:latest2cf09d66a86f
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.17.8
0.60.0
1.26.9
1
beanbag/reviewboard:latest6b840f546e1c
stdlib@go1.18.1
1.26.9
1
bedag/goblackhole:0.2.0447a88598f4c
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.6
0.60.0
1.26.9
1
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/net@v0.37.0
stdlib@go1.23.12
0.60.0
1.26.9
1
beopenit/door-cd-operator:v3.0.4d3999cb8d026
golang.org/x/net@v0.17.0
stdlib@go1.23.9
0.60.0
1.26.9
1
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/net@v0.15.0
stdlib@go1.19.13
0.60.0
1.26.9
1
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
1
berkeleyskypilot/skypilot:0.14.0a8362d205365
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.60.0
1.26.9
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
golang.org/x/net@v0.38.0
stdlib@go1.23.5
0.60.0
1.26.9
1
betterdb/monitor:0.49.0-no-ai97dcd2d2192f
stdlib@go1.26.8
1.26.9
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.6
0.60.0
1.26.9
1
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/net@v0.2.0
stdlib@go1.17.6
0.60.0
1.26.9
1
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/net@v0.0.0-20220418201149-a630d4f3e7a2
stdlib@go1.19.3
0.60.0
1.26.9
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.26.9
1
binrc/headcni:1.0.10e199c334b957
golang.org/x/net@v0.53.0
stdlib@go1.22.10
0.60.0
1.26.9
1
binwiederhier/ntfy:v2.28.06ef4b819f722
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
1
binwiederhier/ntfy:v2.6.283e2e43d9956
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.60.0
1.26.9
1
bitnami/haproxy:latest5b57bac338a2
golang.org/x/net@v0.59.0
0.60.0
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.60.0
1.26.9
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
bitnamilegacy/git:latest4b08d0c5af8d
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.60.0
1.26.9
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
stdlib@go1.20.5
1.26.9
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
stdlib@go1.19.6
1.26.9
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
stdlib@go1.18.2
1.26.9
1
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.60.0
1.26.9
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
stdlib@go1.18.2
1.26.9
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
stdlib@go1.21.10
1.26.9
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.26.9
1
bitnamilegacy/kubectl:1.301249fc292e84
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.60.0
1.26.9
1
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.60.0
1.26.9
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.60.0
1.26.9
1
bitnamilegacy/kube-state-metrics:204a3044b384b
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
1
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.26.9
1
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
stdlib@go1.22.4
1.26.9
1
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
stdlib@go1.22.8
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.