StackRadar

CVE-2026-78660

Unscored

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,566
of 18,071 indexed, latest versions
Container images
6,425
deployed by those charts
Fix available
2 of 3
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,566 of 18,071 indexed charts deploy, on 6,425 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,411
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,172
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-78660GO-2026-6610
Trending
Rank 4 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,566 by stars
ChartLatestAffected imagesRadar Score
sftpgosftpgoOfficialVerified publisher0.48.01 of 1See more

sftpgo sftpgo 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
golang.org/x/net@v0.57.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

1,613
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

13,686
aws-cloudwatch-metricsaws0.0.111 of 1See more

aws-cloudwatch-metrics aws 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

2,111
zabbixcetic3.1.33 of 5See more

zabbix cetic 3.1.3

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:14c2427de38f99
stdlib@go1.24.6
1.26.9
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.1
0.60.0
1.26.9
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
stdlib@go1.18.1
1.26.9

Open the chart page →

37,344
chatwootchatwootVerified publisher2.0.272 of 3See more

chatwoot chatwoot 2.0.27

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.26.9
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
stdlib@go1.16.7
1.26.9

Open the chart page →

8,654
plugin-barman-cloudcloudnative-pgVerified publisher0.8.11 of 1See more

plugin-barman-cloud cloudnative-pg 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/plugin-barman-cloud:v0.15.1c75acad19a36
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

72
csi-driver-smbcsi-driver-smbVerified publisher1.20.35 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

4,163
daprdapr1.18.55 of 5See more

dapr dapr 1.18.5

5 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dapr/injector:1.18.50c6735a025dc
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/dapr/operator:1.18.59bc91e9d1f8e
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/dapr/placement:1.18.52a2b99d466e8
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/dapr/scheduler:1.18.5734c1e29d1d9
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/dapr/sentry:1.18.556faf97016d6
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

380
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

6,178
flux-operatorflux-operator0.61.01 of 1See more

flux-operator flux-operator 0.61.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/controlplaneio-fluxcd/flux-operator:v0.61.071041d9fff7f
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

82
gadgetgadgetOfficialVerified publisher0.56.11 of 1See more

gadget gadget 0.56.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/inspektor-gadget/inspektor-gadget:v0.56.1d1c34335183b
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

167
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.26.9

Open the chart page →

8,971
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
stdlib@go1.19.8
1.26.9

Open the chart page →

7,477
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
google/cloud-sdk:alpineef78619c8239
stdlib@go1.26.6
1.26.9

Open the chart page →

8,830
hpe-csi-driverhpe-storageVerified publisher3.3.013 of 14See more

hpe-csi-driver hpe-storage 3.3.0

13 of the 14 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/hpestorage/alletra-9000-primera-and-3par-csp:v3.3.0046215e41416
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/alletrastoragemp-b10000-nfs-csp:v1.3.0efaca660f9f0
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/alletrastoragemp-x10000-nfs-csp:v1.1.0043bb2ddb642
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/csi-driver:v3.3.0e58e22427b38
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/csi-extensions:v1.3.0df65cea35805
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-group-provisioner:v1.1.09ba017780f80
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-group-snapshotter:v1.1.0b26660528928
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-mutator:v1.4.03890d0b3aa89
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

3,496
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

3,008
cloudflaredkubitodevVerified publisher1.7.91 of 1See more

cloudflared kubitodev 1.7.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,930
trident-operatornetapp-tridentVerified publisher100.2606.21 of 1See more

trident-operator netapp-trident 100.2606.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
netapp/trident-operator:26.06.24cef5a737bcf
golang.org/x/net@v0.59.0
0.60.0

Open the chart page →

24
ngrok-operatorngrokOfficialVerified publisher0.24.02 of 2See more

ngrok-operator ngrok 0.24.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
ngrok/ngrok-operator:0.22.0db8e6fecc52c
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

339
openbaoopenbaoVerified publisher0.30.12 of 2See more

openbao openbao 0.30.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:1.7.2ae3d307658b7
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
quay.io/openbao/openbao:2.7.071156a1c6623
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,618
prometheus-snmp-exporterprometheus-communityOfficialVerified publisher9.18.11 of 1See more

prometheus-snmp-exporter prometheus-community 9.18.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

804
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9

Open the chart page →

6,757
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.7
0.60.0
1.26.9

Open the chart page →

3,051
trivytrivy-operator0.27.01 of 1See more

trivy trivy-operator 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
aquasec/trivy:0.75.0af6acf9a6b85
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

183
zotzot0.1.1281 of 1See more

zot zot 0.1.128

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/project-zot/zot:v2.1.2296cda11459ce
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

443
aws-ebs-csi-driveraws-ebs-csi-driver2.66.15 of 6See more

aws-ebs-csi-driver aws-ebs-csi-driver 2.66.1

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/csi-components/csi-attacher:v4.12.0-eksbuild.9f8db68b6e3b3
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-node-driver-registrar:v2.17.0-eksbuild.89be2a65725f7
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-provisioner:v6.3.0-eksbuild.82fdf13756ccb
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-resizer:v2.2.1-eksbuild.7a2895cc5206d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.66.13ae75c8b0fdc
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

372
daskdask2024.1.11 of 2See more

dask dask 2024.1.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

14,275
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
golang.org/x/net@v0.35.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

3,719
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.60.0
1.26.9

Open the chart page →

9,103
netbirdjaconiVerified publisher0.15.14 of 4See more

netbird jaconi 0.15.1

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/golang:lateste0174e51e812
stdlib@go1.27.1
1.27.2
netbirdio/management:0.45.10c9994b393ea
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
netbirdio/relay:0.45.1872e3add0e1e
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
netbirdio/signal:0.45.146ce5a45538f
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9

Open the chart page →

10,057
k8upk8upVerified publisher4.10.01 of 1See more

k8up k8up 4.10.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.16.029458113b8b6
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

964
kube-starrockskube-starrocksOfficialVerified publisher1.11.71 of 1See more

kube-starrocks kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/net@v0.17.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

963
linkerd-jaegerlinkerd2Verified publisher30.12.112 of 4See more

linkerd-jaeger linkerd2 30.12.11

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.6
0.60.0
1.26.9
otel/opentelemetry-collector:0.59.0ee9da0b08d83
golang.org/x/net@v0.0.0-20220809184613-07c6da5e1ced
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

6,109
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest801a3dff7f6a
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:nojsonv2
0.60.0
1.27.2

Open the chart page →

2,064
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

15,021
renovate-operatormogenius6.4.02 of 2See more

renovate-operator mogenius 6.4.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/mogenius/renovate-operator:6.4.0e8f023764de4
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
registry.k8s.io/kubectl:v1.37.1b7cab618e281
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

177
argocdnicklasfrahm-argocdVerified publisher0.3.02 of 2See more

argocd nicklasfrahm-argocd 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.26.9
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
golang.org/x/net@v0.40.0
stdlib@go1.22.7
0.60.0
1.26.9

Open the chart page →

7,106
oneuptimeoneuptimeOfficialVerified publisher14.0.242 of 7See more

oneuptime oneuptime 14.0.24

2 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:latest74935e722416
stdlib@go1.24.6
1.26.9
oneuptime/runner:release50de5525019d
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

8,871
open-feature-operatoropen-feature-operatorOfficialVerified publisher0.9.31 of 1See more

open-feature-operator open-feature-operator 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/open-feature/open-feature-operator:v0.9.3b37a442c0497
golang.org/x/net@v0.52.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

263
postgres-operatorpostgres-operator2.0.31 of 1See more

postgres-operator postgres-operator 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v2.0.32d3a7ca3950f
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

152
telepresence-osstelepresence-ossOfficialVerified publisher2.32.21 of 2See more

telepresence-oss telepresence-oss 2.32.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/telepresenceio/tel2:2.32.296f5a0f413b1
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

872
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
stdlib@go1.17.1
1.26.9

Open the chart page →

7,297
karmawiremindVerified publisher2.13.11 of 1See more

karma wiremind 2.13.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/prymitive/karma:v0.13190a10c5c6793
stdlib@go1.26.3
1.26.9

Open the chart page →

273
yugabyteyugabyteVerified publisher2026.1.21 of 1See more

yugabyte yugabyte 2026.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
yugabytedb/yugabyte:2026.1.2.0-b137b6dba322c734
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

306
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

1,640
autheliaautheliaOfficialVerified publisher0.11.221 of 1See more

authelia authelia 0.11.22

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/authelia/authelia:4.39.248f428b06bb07
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

76
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

8,041
camel-kcamel-kVerified publisher2.11.01 of 1See more

camel-k camel-k 2.11.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
apache/camel-k:2.11.0d173e7efe258
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,732
cert-manager-webhook-ovhcert-manager-webhook-ovhVerified publisher0.9.171 of 1See more

cert-manager-webhook-ovh cert-manager-webhook-ovh 0.9.17

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/aureq/cert-manager-webhook-ovh:0.9.17b375e501172d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

89
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

6,608

Container images carrying it

6,425 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0:v2.8.1f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
6
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
5
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9
5
containous/whoami:latest:v1.5.07d6a3c8f9147
stdlib@go1.14
1.26.9
5
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
5
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.60.0
1.26.9
5
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
5
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.60.0
1.26.9
5
grafana/tempo:2.9.065a578975943
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9
5
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
5
library/mariadb:13.0.2:latestd4fdec0510ad
stdlib@go1.26.7
1.26.9
5
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.26.9
5
library/mysql:26.7.0:latest9d48c42f8341
stdlib@go1.24.6
1.26.9
5
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.26.9
5
library/redis:7.4.2-alpine:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.26.9
5
library/redis:5:5.0fc5ecd863862
stdlib@go1.16.7
1.26.9
5
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.60.0
1.26.9
5
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9
5
rancher/rancher:v2.15.20c3d8e570255
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9
5
rancher/shell:v0.8.21eeed72d4eda
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
5
sigma2as/goidc-proxy:next656ac798963a
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.60.0
1.26.9
5
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
5
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.26.9
5
ghcr.io/paperless-ngx/paperless-ngx:3.3.06b94799bc769
stdlib@go1.24.4
1.26.9
5
ghcr.io/quenchworks/images/prometheusa9dc21133c23
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.60.0
1.26.9
5
quay.io/prometheus/mysqld-exporter:latest:v0.20.0abed8dac117b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
5
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
5
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9
5
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
5
quay.io/prometheus/prometheus:latest:v3.14.05ce7540c3c00
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
5
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.60.0
1.26.9
5
adguard/adguardhome:v0.107.79aba9e3bf0613
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
4
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.26.9
4

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.