StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

4,573
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.5
0.60.0
1.26.9

Open the chart page →

5,213
gollumgeek-cookbookVerified publisher3.4.21 of 3See more

gollum geek-cookbook 3.4.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/git:latesta4bb51f1a355
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

5,367
influxdb-exportergeek-cookbookVerified publisher1.2.21 of 1See more

influxdb-exporter geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.26.9

Open the chart page →

1,874
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.26.9

Open the chart page →

15,289
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.7
0.60.0
1.26.9

Open the chart page →

3,548
owncastgeek-cookbookVerified publisher3.4.21 of 1See more

owncast geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gabekangas/owncast:0.0.797461aedb580
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

4,305
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

9,428
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.26.9

Open the chart page →

13,050
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.26.9

Open the chart page →

11,695
sambageek-cookbookVerified publisher6.2.21 of 1See more

samba geek-cookbook 6.2.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.26.9

Open the chart page →

3,219
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.26.9

Open the chart page →

14,375
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

17,748
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.5
0.60.0
1.26.9

Open the chart page →

6,695
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latest19f55bcf7bb6
stdlib@go1.24.1
1.26.9

Open the chart page →

2,893
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.26.9

Open the chart page →

8,938
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.32 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

2 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.8512bb8a21483
stdlib@go1.19.10
1.26.9
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.26.9

Open the chart page →

16,832
geo-checkergeo-checkerVerified publisher5.0.01 of 1See more

geo-checker geo-checker 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ymuski/geo-checker:5.0.05ba7fd8c7bdc
stdlib@go1.25.3
1.26.9

Open the chart page →

1,909
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9

Open the chart page →

3,761
gigapipegigapipeVerified publisher0.3.01 of 1See more

gigapipe gigapipe 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/metrico/gigapipe:v4.1.6caeb2652ce5e
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

1,013
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.26.9

Open the chart page →

7,583
gitea-sonarqube-botgitea-sonarqube-botOfficialVerified publisher0.4.01 of 1See more

gitea-sonarqube-bot gitea-sonarqube-bot 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,608
git-hubbygit-hubbyOfficialVerified publisher1.20.111 of 1See more

git-hubby git-hubby 1.20.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/interhyp/git-hubby:0.8.1724b8257c0bda
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

177
github-platform-operatorgithub-platform-operatorVerified publisher0.7.81 of 1See more

github-platform-operator github-platform-operator 0.7.8

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/pierinho13/github-platform-operator:v0.7.88b5cb8098f76
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

183
github-stsgithub-sts-helmVerified publisher0.1.11 of 1See more

github-sts github-sts-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/depthmark/github-sts:0.1.129fda68298da
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

180
gitops-reversergitops-reverserVerified publisher0.52.01 of 1See more

gitops-reverser gitops-reverser 0.52.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/configbutler/gitops-reverser:0.52.0a44138514b30
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
prometheus-kafka-exportergkarthiks0.1.31 of 1See more

prometheus-kafka-exporter gkarthiks 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:latestd1014f41712d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
temporalglasskubeVerified publisher0.45.2-gk.110 of 14See more

temporal glasskube 0.45.2-gk.1

10 of the 14 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
golang.org/x/net@v0.27.0
stdlib@go1.22.3
0.60.0
1.26.9
temporalio/server:1.25.08a5798191dea
golang.org/x/net@v0.28.0
stdlib@go1.22.3
0.60.0
1.26.9
temporalio/ui:2.30.25c2a3645d09c
golang.org/x/net@v0.28.0
stdlib@go1.22.1
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

22,494
daos-operatorgluesysVerified publisher0.1.51 of 1See more

daos-operator gluesys 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/gluesys/daos-operator:v0.1.0-rc.4c38bd9a7691c
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

131
relay-proxygo-feature-flagOfficialVerified publisher1.56.01 of 1See more

relay-proxy go-feature-flag 1.56.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gofeatureflag/go-feature-flag:v1.56.0cd0923bccbd1
golang.org/x/net@v0.59.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

128
go-hello-world-chartgo-hello-worldVerified publisher1.8.31 of 1See more

go-hello-world-chart go-hello-world 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wasilak/go-hello-world:1.8.366d353e7693f
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

1,162
gomenhashaigomenhashaiOfficialVerified publisher1.3.41 of 1See more

gomenhashai gomenhashai 1.3.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/gomenhashai/gomenhashai:v1.3.36f031172a5ec
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

987
gorse-enterprisegorse-io0.4.23 of 5See more

gorse-enterprise gorse-io 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9

Open the chart page →

6,576
gotosocialgotosocialVerified publisher0.2.321 of 1See more

gotosocial gotosocial 0.2.32

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
superseriousbusiness/gotosocial:0.22.10078ca451dda
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

579
meta-monitoringgrafana1.3.02 of 2See more

meta-monitoring grafana 1.3.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.60.0
1.26.9
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.26.9

Open the chart page →

4,767
phlaregrafana0.5.41 of 1See more

phlare grafana 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/phlare:0.5.1330f990cdad9
golang.org/x/net@v0.5.0
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

2,810
gkograviteeioVerified publisher4.12.211 of 1See more

gko graviteeio 4.12.21

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
graviteeio/kubernetes-operator:4.12.2182548747c6c5
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

240
greenkubegreenkubeVerified publisher0.3.01 of 3See more

greenkube greenkube 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.26.9

Open the chart page →

2,110
gremlingremlin0.30.01 of 2See more

gremlin gremlin 0.30.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gremlin/chao:latest298100e062b8
golang.org/x/net@v0.56.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

293
armada-operatorgresearch0.7.02 of 2See more

armada-operator gresearch 0.7.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gresearch/armada-operator:latest6c43743e2b2d
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.60.0
1.26.9
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9

Open the chart page →

2,624
carettagroundcover0.0.163 of 3See more

caretta groundcover 0.0.16

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18
0.60.0
1.26.9
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.60.0
1.26.9
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

9,649
ghostgroundhog2k0.212.161 of 1See more

ghost groundhog2k 0.212.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/ghost:6.69.055131b90d48c
stdlib@go1.24.6
1.26.9

Open the chart page →

1,962
growthbookgrowthbook5.1.01 of 2See more

growthbook growthbook 5.1.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/mongodb:latestad05bb9a19fa
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,420
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:8.46ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

5,095
oscargrycapOfficialVerified publisher4.2.01 of 2See more

oscar grycap 4.2.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/grycap/oscar:latest1afdce33dacf
golang.org/x/net@v0.51.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

570
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
stdlib@go1.21.13
1.26.9

Open the chart page →

11,392
haproxy-unified-gatewayhaproxytechVerified publisher1.2.01 of 1See more

haproxy-unified-gateway haproxytech 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
haproxytech/haproxy-unified-gateway:1.0.7b9bffe2d0fd1
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

925
boundary-controllerhashicorpVerified publisher0.2.01 of 1See more

boundary-controller hashicorp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/boundary-enterprise:1.0.2-ent3a8061968ee4
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

344
boundary-workerhashicorpVerified publisher0.2.01 of 1See more

boundary-worker hashicorp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/boundary-enterprise:1.0.2-ent3a8061968ee4
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

344
terraform-cloud-operatorhashicorpVerified publisher2.5.02 of 2See more

terraform-cloud-operator hashicorp 2.5.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
golang.org/x/net@v0.24.0
stdlib@go1.22.4
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.18.0754ab2a723c8
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

2,450

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.26.9
1
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.26.9
1
bitnamilegacy/redis:7.2.5-debian-12-r05261cae9e407
stdlib@go1.21.10
1.26.9
1
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.26.9
1
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
stdlib@go1.23.7
1.26.9
1
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.26.9
1
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.26.9
1
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.26.9
1
bitnamilegacy/redis:7.0.8-debian-11-r0bf01d031ba8c
stdlib@go1.18.2
1.26.9
1
bitnamilegacy/redis:8.0.2-debian-12-r4cdc2efa9c306
stdlib@go1.24.4
1.26.9
1
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
stdlib@go1.19.12
1.26.9
1
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
stdlib@go1.23.8
1.26.9
1
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
stdlib@go1.23.7
1.26.9
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/net@v0.0.0-20220614195744-fb05da6f9022
stdlib@go1.17
0.60.0
1.26.9
1
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
golang.org/x/net@v0.39.0
stdlib@go1.24.1
0.60.0
1.26.9
1
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
golang.org/x/net@v0.30.0
stdlib@go1.23.4
0.60.0
1.26.9
1
bitnamilegacy/valkey:latest0384ca2eec63
stdlib@go1.23.10
1.26.9
1
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
stdlib@go1.24.6
1.26.9
1
bitnamilegacy/valkey:8.1.3-debian-12-r1a185655855b3
stdlib@go1.24.4
1.26.9
1
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
stdlib@go1.21.5
1.26.9
1
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
stdlib@go1.18.2
1.26.9
1
bitnami/mariadb:11.7.216a7dae804fb
stdlib@go1.22.12
1.26.9
1
bitnami/mongodb:8.0.8b3bd5b6be9a0
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.60.0
1.26.9
1
bitnami/mongodb:latestc8babafb7d15
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
bitnami/mongodb-exporter:latestfb4874bb3d07
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
bitnami/nginx:latest46acb2546866
stdlib@go1.26.8
1.26.9
1
bitnami/redis:7.4.24e65bf641805
stdlib@go1.23.8
1.26.9
1
bitnami/redisd75bda00b778
stdlib@go1.26.7
1.26.9
1
bitnami/redis-exporter:latestc6a2883c0bb7
stdlib@go1.26.8
1.26.9
1
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.6
0.60.0
1.26.9
1
bitnami/sealed-secrets-controller:0.37.03fe0103896b8
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
1
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9
1
bitnami/tomcat:latesta364a0270d35
stdlib@go1.26.8
1.26.9
1
bitnami/wordpress:latest845d250ecd73
stdlib@go1.26.8
1.26.9
1
bitpoke/stack-default-backend:latestc5eed1ddf692
stdlib@go1.16.6
1.26.9
1
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.60.0
1.26.9
1
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.60.0
1.26.9
1
blackducksoftware/bdba-pgupgrader:2026.9.0b805c1f607e0
stdlib@go1.18.2
1.26.9
1
blackducksoftware/blackduck-alert-db:8.4.1ad33e84750f1
stdlib@go1.24.6
1.26.9
1
blipai/deckard:0.0.28737d5d19a312
golang.org/x/net@v0.10.0
stdlib@go1.18.10
0.60.0
1.26.9
1
blipai/deckard:0.1.8db8cd873d0eb
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
1
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/net@v0.17.0
stdlib@go1.21.9
0.60.0
1.26.9
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.60.0
1.26.9
1
bluenviron/mediamtx:1.17.19e39256d1ba3
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.60.0
1.26.9
1
bluenviron/mediamtx:latest-ffmpegc0feb4acc548
golang.org/x/net@v0.59.0
0.60.0
1
bolkedebruin/rdpgw:masterc0dc0589373a
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.60.0
1.26.9
1
bonovoo/secrethor:1.1.2bb93b68fcd17
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9
1
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.60.0
1.26.9
1
broadinstitute/dsde-toolbox:master656131886a08
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.10
0.60.0
1.26.9
1
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.12
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.