StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
nacosygqygq2Verified publisher2.1.102 of 4See more

nacos ygqygq2 2.1.10

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.26.9
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.26.9

Open the chart page →

7,077
sealed-secretsbitnamiVerified publisher2.5.191 of 1See more

sealed-secrets bitnami 2.5.19

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,055
mariadbcloudpirates-mariadbVerified publisher0.16.161 of 1See more

mariadb cloudpirates-mariadb 0.16.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:13.0.2f1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

1,782
difydoubanVerified publisher0.10.04 of 6See more

dify douban 0.10.0

4 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.26.9
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.60.0
1.26.9
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.60.0
1.26.9
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.26.9

Open the chart page →

83,750
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.5.02 of 3See more

kubeshark kubeshark-helm-charts 53.5.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubeshark/hub:v53.50532936678f8
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2
kubeshark/worker:v53.51f3e121224f8
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,281
secrets-store-csi-driversecret-store-csi-driver1.6.14 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/csi-secrets-store/driver-crds:v1.6.1cdacfdbe8966
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

2,941
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.31 of 2See more

stackgres-operator stackgres-charts 1.19.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

3,032
victoria-logs-singlevictoriametricsVerified publisher0.13.101 of 1See more

victoria-logs-single victoriametrics 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.53.0251121fa882a
stdlib@go1.27.1
1.27.2

Open the chart page →

89
mongodbcloudpirates-mongodbVerified publisher0.20.01 of 1See more

mongodb cloudpirates-mongodb 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:9.0.2bac22ea7710d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,244
kube-image-keeperenixVerified publisher2.3.11 of 1See more

kube-image-keeper enix 2.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/enix/kube-image-keeper:2.3.1d3ccf28495c3
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

229
mattermost-team-editionmattermostVerified publisher6.6.1081 of 4See more

mattermost-team-edition mattermost 6.6.108

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:11.11.16ad5912b4587
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

2,045
code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
stdlib@go1.16.4
1.26.9

Open the chart page →

18,186
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

706
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
stdlib@go1.26.5
1.26.9

Open the chart page →

2,186
pulsarapache4.7.06 of 10See more

pulsar apache 4.7.0

6 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
victoriametrics/operator:v0.68.3f52e1bd679cb
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

13,072
miniocloudpirates-minioVerified publisher0.14.01 of 1See more

minio cloudpirates-minio 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,670
vertical-pod-autoscalercowboysysopVerified publisher11.1.14 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

9,019
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.26.9
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
langgenius/dify-api:1.16.1dcefa5f7c47c
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

74,916
eclipse-cheeclipse-cheVerified publisher7.123.01 of 1See more

eclipse-che eclipse-che 7.123.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.123.0d926b6d183a1
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,116
pyroscopegrafana2.4.02 of 3See more

pyroscope grafana 2.4.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/alloy:v1.19.2b8ec653c4423
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,762
botkubeinfracloudioVerified publisher1.14.01 of 1See more

botkube infracloudio 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.60.0
1.26.9

Open the chart page →

1,587
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,332
thanosthanos-communityOfficialVerified publisher0.47.11 of 1See more

thanos thanos-community 0.47.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

426
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.26.9

Open the chart page →

2,435
tetragonciliumOfficialVerified publisher1.7.12 of 3See more

tetragon cilium 1.7.1

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/cilium/tetragon-operator:v1.7.1cd8b71f6860e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

512
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

5,565
k6-operatorgrafana4.6.01 of 1See more

k6-operator grafana 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/grafana/k6-operator:controller-v1.6.0ba7f0fc1e22e
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

283
rabbitmqgroundhog2k2.3.91 of 2See more

rabbitmq groundhog2k 2.3.9

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6446551b26c0b
stdlib@go1.22.2
1.26.9

Open the chart page →

1,296
telegrafinfluxdata1.8.771 of 1See more

telegraf influxdata 1.8.77

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/telegraf:1.40-alpine6606553b5019
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

141
k8tzk8tzOfficialVerified publisher0.20.01 of 1See more

k8tz k8tz 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/k8tz/k8tz:0.20.0361628e53fc8
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

218
kiali-serverkiali2.33.01 of 1See more

kiali-server kiali 2.33.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kiali/kiali:v2.33.0082246cfc99f
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

456
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

845
vela-corekubevela1.11.03 of 3See more

vela-core kubevela 1.11.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
oamdev/cluster-gateway:v1.9.0-alpha.25591e29d66a2
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
oamdev/kube-webhook-certgen:v2.4.1231c423c2b17
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.11
0.60.0
1.26.9
oamdev/vela-core:v1.11.095fa412c934e
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

6,663
oktetooktetoOfficialVerified publisher0.0.0-2026-08-317 of 10See more

okteto okteto 0.0.0-2026-08-31

7 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/okteto/backend:0.0.0-2026-08-316171cb2b2a72
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.60.0
1.26.9
ghcr.io/okteto/buildkit:0.0.0-2026-08-3114527ca5d2a9
golang.org/x/net@v0.55.0
stdlib@go1.25.7
0.60.0
1.26.9
ghcr.io/okteto/daemon:0.0.0-2026-08-31c6e716a3fbbe
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-31d6730eb9831b
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/okteto/okteto:3.23.0-beta.1a0483d47ba04
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/okteto/registry:0.0.0-2026-08-3169131511501f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/okteto/reloader:0.0.0-2026-08-3104a3fce657c4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

7,823
hydraory0.64.02 of 2See more

hydra ory 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,950
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

1,344
proxmox-csi-pluginproxmox-csi0.5.127 of 7See more

proxmox-csi-plugin proxmox-csi 0.5.12

7 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-csi-controller:v0.20.095ef74cce03e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

3,558
victoria-metrics-singlevictoriametricsVerified publisher0.48.01 of 1See more

victoria-metrics-single victoriametrics 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
victoriametrics/victoria-metrics:v1.153.05eff7af5341e
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

137
yourlsyourlsOfficialVerified publisher8.10.51 of 2See more

yourls yourls 8.10.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9

Open the chart page →

2,619
apisix-ingress-controllerapisix1.4.01 of 2See more

apisix-ingress-controller apisix 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

2,247
volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,833
concourseconcourseVerified publisher20.3.12 of 2See more

concourse concourse 20.3.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
concourse/concourse:8.3.1c9d48dfbf4f9
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

2,201
dynatrace-operatordynatraceVerified publisher1.11.01 of 1See more

dynatrace-operator dynatrace 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.11.05b772cfaad48
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.60.0
1.26.9

Open the chart page →

5,327
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

2,431
oncallgrafana1.16.57 of 12See more

oncall grafana 1.16.5

7 of the 12 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

23,232
k8sgpt-operatork8sgptOfficialVerified publisher0.2.292 of 2See more

k8sgpt-operator k8sgpt 0.2.29

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.2982d0adcce816
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,654
node-feature-discoverynode-feature-discoveryOfficialVerified publisher0.19.01 of 1See more

node-feature-discovery node-feature-discovery 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

480
openprojectopenproject-helm-chartsOfficialVerified publisher13.13.11 of 5See more

openproject openproject-helm-charts 13.13.1

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9

Open the chart page →

21,839
kratosory0.64.01 of 1See more

kratos ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
oryd/kratos:v26.2.02a13bb8d362c
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

1,227

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
stdlib@go1.22.4
1.26.9
1
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
stdlib@go1.22.8
1.26.9
1
bitnamilegacy/mariadb:10.6.12-debian-11-r1678847062532a
stdlib@go1.19.7
1.26.9
1
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
stdlib@go1.22.6
1.26.9
1
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
stdlib@go1.23.8
1.26.9
1
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
stdlib@go1.23.10
1.26.9
1
bitnamilegacy/mariadb:latestbbd4e17f1ef8
stdlib@go1.24.5
1.26.9
1
bitnamilegacy/mariadb-galera:10.6.12-debian-11-r1643a70df0e7c6
stdlib@go1.19.7
1.26.9
1
bitnamilegacy/mariadb-galera:11.3.2-debian-12-r9aee9c668098f
stdlib@go1.22.5
1.26.9
1
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
stdlib@go1.22.6
1.26.9
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
stdlib@go1.25.0
1.26.9
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
golang.org/x/net@v0.19.0
stdlib@go1.20.13
0.60.0
1.26.9
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/net@v0.4.0
stdlib@go1.18.9
0.60.0
1.26.9
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
1
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
golang.org/x/net@v0.26.0
stdlib@go1.21.12
0.60.0
1.26.9
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.60.0
1.26.9
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
golang.org/x/net@v0.32.0
stdlib@go1.22.10
0.60.0
1.26.9
1
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
golang.org/x/net@v0.27.0
stdlib@go1.21.12
0.60.0
1.26.9
1
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
golang.org/x/net@v0.40.0
stdlib@go1.25.0
0.60.0
1.26.9
1
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
golang.org/x/net@v0.22.0
stdlib@go1.20.12
0.60.0
1.26.9
1
bitnamilegacy/mongodb:5.0.103bb1deeaf9d0
golang.org/x/net@v0.0.0-20220708220712-1185a9018129
stdlib@go1.18.4
0.60.0
1.26.9
1
bitnamilegacy/mongodb:3.6.213e51da56fc54
stdlib@go1.15.1
1.26.9
1
bitnamilegacy/mongodb:7.0.5-debian-11-r66fe59ed5d79f
golang.org/x/net@v0.19.0
stdlib@go1.20.12
0.60.0
1.26.9
1
bitnamilegacy/mongodb:latestb0652af9c8d0
golang.org/x/net@v0.40.0
stdlib@go1.23.8
0.60.0
1.26.9
1
bitnamilegacy/mongodb:4.4.5e3c9d6b4bc92
stdlib@go1.15.8
1.26.9
1
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.60.0
1.26.9
1
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
stdlib@go1.23.8
1.26.9
1
bitnamilegacy/mysql:8.0.36-debian-11-r38aad73aa0c6d
stdlib@go1.21.6
1.26.9
1
bitnamilegacy/mysql:8.0.35-debian-11-r2be03e8ea6129
stdlib@go1.21.5
1.26.9
1
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.8
0.60.0
1.26.9
1
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
golang.org/x/net@v0.17.0
stdlib@go1.21.12
0.60.0
1.26.9
1
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.16.4
0.60.0
1.26.9
1
bitnamilegacy/nats:2.11.8-debian-12-r0fa0cfba6034a
stdlib@go1.24.6
1.26.9
1
bitnamilegacy/nginx:1.27.1934d1acd5ca8
stdlib@go1.22.7
1.26.9
1
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
stdlib@go1.23.8
1.26.9
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
golang.org/x/net@v0.27.0
stdlib@go1.22.8
0.60.0
1.26.9
1
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
golang.org/x/net@v0.27.0
stdlib@go1.22.8
0.60.0
1.26.9
1
bitnamilegacy/os-shell:11-debian-11-r968643af4facff
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9
1
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
golang.org/x/net@v0.33.0
stdlib@go1.23.8
0.60.0
1.26.9
1
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
1
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9
1
bitnamilegacy/pgbouncer:1.23.192356da09704
stdlib@go1.22.10
1.26.9
1
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/net@v0.33.0
stdlib@go1.23.7
0.60.0
1.26.9
1
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
golang.org/x/net@v0.17.0
stdlib@go1.22.8
0.60.0
1.26.9
1
bitnamilegacy/postgresql:15.2.0-debian-11-r113e65a6b89e38
stdlib@go1.18.2
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.