StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:8.0.39ccb8f749bb5e
stdlib@go1.18.2
1.26.9

Open the chart page →

5,011
prometheus-blackbox-exporterbackbox-exporter7.8.01 of 1See more

prometheus-blackbox-exporter backbox-exporter 7.8.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

2,343
backlokto-operatorbacklokto0.0.11 of 1See more

backlokto-operator backlokto 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
piblokto/backlokto-operator:v0.0.20963cda71e393
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

1,339
backrestbackrest0.2.01 of 1See more

backrest backrest 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
garethgeorge/backrest:latestb85297975428
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

1,328
backup-operatorbackup-operatorVerified publisher1.2.31 of 1See more

backup-operator backup-operator 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/universal-backup-operator/backup-operator:1.2.306292b289dda
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,419
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

11,003
binderybdclark-helm-chartsVerified publisher0.1.41 of 1See more

bindery bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/vavallee/bindery:v1.35.0c4ebfc5470e1
stdlib@go1.26.6
1.26.9

Open the chart page →

145
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
stdlib@go1.24.4
1.26.9

Open the chart page →

5,341
qbittorrent-vpnbdclark-helm-chartsVerified publisher0.7.61 of 2See more

qbittorrent-vpn bdclark-helm-charts 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.41.11a5bf4b4820a
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,541
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
stdlib@go1.25.7
1.26.9

Open the chart page →

2,794
helm-samplebehnambm-helm-chart1.0.11 of 3See more

helm-sample behnambm-helm-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

3,095
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,342
pagesberrutig-pages1.0.01 of 3See more

pages berrutig-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,310
trident-operatorberyju-org21.10.01 of 1See more

trident-operator beryju-org 21.10.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
netapp/trident-operator:21.10.049cfe552d9c2
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

3,201
betacalendars-calendar-boundary-labbetacalendars-calendar-boundary-labVerified publisher0.1.21 of 1See more

betacalendars-calendar-boundary-lab betacalendars-calendar-boundary-lab 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/mateopedersen/betacalendars-calendar-boundary-lab:1.0.043da2a255584
stdlib@go1.25.14
1.26.9

Open the chart page →

141
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
golang.org/x/net@v0.35.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

8,373
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

6,187
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

76,897
mx-notifierbicarus-labs1.1.91 of 1See more

mx-notifier bicarus-labs 1.1.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/net@v0.2.0
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

4,982
wg-access-serverbicarus-labs0.9.91 of 1See more

wg-access-server bicarus-labs 0.9.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/net@v0.0.0-20220418201149-a630d4f3e7a2
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

3,595
tenzu-frontbiru-scop3.1.01 of 1See more

tenzu-front biru-scop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,221
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/net@v0.10.0
stdlib@go1.21.1
0.60.0
1.26.9

Open the chart page →

3,156
stackbitpokeVerified publisher0.12.46 of 6See more

stack bitpoke 0.12.4

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.60.0
1.26.9
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.60.0
1.26.9
bitpoke/stack-default-backend:latestc5eed1ddf692
stdlib@go1.16.6
1.26.9
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.60.0
1.26.9

Open the chart page →

16,083
wordpress-operatorbitpokeVerified publisher0.12.41 of 1See more

wordpress-operator bitpoke 0.12.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.60.0
1.26.9

Open the chart page →

1,997
sm-operatorbitwarden2.0.31 of 1See more

sm-operator bitwarden 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/bitwarden/sm-operator:2.1.0846624161f32
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

905
baserowblackbird-cloudVerified publisher1.0.172 of 6See more

baserow blackbird-cloud 1.0.17

2 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
stdlib@go1.19.8
1.26.9
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

12,239
prometheus-domain-exporterblackbox-domain-exporter1.0.01 of 1See more

prometheus-domain-exporter blackbox-domain-exporter 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

2,208
bdbablackduck2026.9.04 of 9See more

bdba blackduck 2026.9.0

4 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
blackducksoftware/bdba-pgupgrader:2026.9.0b805c1f607e0
stdlib@go1.18.2
1.26.9
library/postgres:15.19-bookworm539ceaaae49b
stdlib@go1.24.6
1.26.9
library/rabbitmq:4.3.5078107e03637
stdlib@go1.22.2
1.26.9
versity/versitygw:v1.8.030292fc2eeac
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

10,497
blackduck-alertblackduck8.4.11 of 4See more

blackduck-alert blackduck 8.4.1

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert-db:8.4.1ad33e84750f1
stdlib@go1.24.6
1.26.9

Open the chart page →

2,127
firehoseblip-firehoseVerified publisher0.0.183 of 11See more

firehose blip-firehose 0.0.18

3 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
blipai/deckard:0.0.28737d5d19a312
golang.org/x/net@v0.10.0
stdlib@go1.18.10
0.60.0
1.26.9
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

16,152
blob-csi-driverblob-csi-driverVerified publisher1.27.115 of 5See more

blob-csi-driver blob-csi-driver 1.27.11

5 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/blob-csi:v1.27.11ccb9e1dbe4b0
golang.org/x/net@v0.57.0
stdlib@go1.25.11
0.60.0
1.26.9
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.17.0760c61825d2a
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v6.3.0adfd47ab0160
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v2.2.13519c45b932d
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.19.06d065f238d39
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,320
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.26.9

Open the chart page →

16,680
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-nti:logc947c3629371
stdlib@go1.23.12
1.26.9

Open the chart page →

31,063
csi-driver-nfsbook-k8sinfra-v24.12.16 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.3.0bc7be893ecc3
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
golang.org/x/net@v0.37.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

9,603
grafanabook-k8sinfra-v28.8.21 of 1See more

grafana book-k8sinfra-v2 8.8.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

2,413
jaegerbook-k8sinfra-v23.4.04 of 5See more

jaeger book-k8sinfra-v2 3.4.0

4 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.26.9
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

22,980
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

9,516
kube-prometheus-stackbook-k8sinfra-v265.5.15 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

9,174
metallbbook-k8sinfra-v20.13.102 of 3See more

metallb book-k8sinfra-v2 0.13.10

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

5,497
nfs-subdir-external-provisionerbook-k8sinfra-v24.0.181 of 1See more

nfs-subdir-external-provisioner book-k8sinfra-v2 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

3,994
prometheusbook-k8sinfra-v226.0.16 of 6See more

prometheus book-k8sinfra-v2 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

8,736
pyroscopebook-k8sinfra-v21.10.03 of 3See more

pyroscope book-k8sinfra-v2 1.10.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.60.0
1.26.9
grafana/pyroscope:1.10.0319bf32ae06b
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.60.0
1.26.9
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.26.9

Open the chart page →

5,001
redisbook-k8sinfra-v21.0.01 of 1See more

redis book-k8sinfra-v2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.26.9

Open the chart page →

2,847
tempobook-k8sinfra-v21.10.31 of 1See more

tempo book-k8sinfra-v2 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/net@v0.24.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

2,561
boundary-softsciboundary-softsci0.2.41 of 1See more

boundary-softsci boundary-softsci 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/boundary:latest76a201954ca0
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,353
branchdbbranch-dbVerified publisher0.1.42 of 3See more

branchdb branch-db 0.1.4

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/masucchi/branchdb:0.1.47ea1820c1da1
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/masucchi/branchdb-operator:0.1.4c16578615a43
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,075
bitmagnetbrandan-schmitz-helm-chartsVerified publisher1.0.62 of 2See more

bitmagnet brandan-schmitz-helm-charts 1.0.6

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.26.9
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

2,673
Filebrowserbrandan-schmitz-helm-chartsVerified publisher1.3.11 of 1See more

Filebrowser brandan-schmitz-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.63.15-s6dbac07403040
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,359
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,310
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,310

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.17.5
0.60.0
1.26.9
1
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
golang.org/x/net@v0.8.0
stdlib@go1.19.3
0.60.0
1.26.9
1
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.17.8
0.60.0
1.26.9
1
chocobozzz/peertube:v8.1.5052712130691
stdlib@go1.24.4
1.26.9
1
chriseaton/adventureworks:latest54c3384ce701
stdlib@go1.23.1
1.26.9
1
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.60.0
1.26.9
1
chrislusf/seaweedfs:4.346620371e8af8
golang.org/x/net@v0.54.0
stdlib@go1.25.11
0.60.0
1.26.9
1
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9
1
chrislusf/seaweedfs-csi-driver:v1.4.341fca534c9001
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
chrislusf/seaweedfs-mount:v1.4.347c6250e96001
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
chriswells0/first-mate:1.0.5f3918ec8471c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
1
circleci/container-agent:34d8d0ae5efc3
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.60.0
1.26.9
1
circleci/runner:launch-agent9bdc62f02162
stdlib@go1.21.5
1.26.9
1
ciscolabs/msm-nc:0710202336d02faad958
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
stdlib@go1.18.1
1.26.9
1
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/net@v0.4.0
stdlib@go1.19.2
0.60.0
1.26.9
1
clastix/kamaji:latestbb4bd5e1d9eb
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
1
cleanstart/minio:latestf1156f7fd14a
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
clickhouse/clickhouse-server:23.8512bb8a21483
stdlib@go1.19.10
1.26.9
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
stdlib@go1.19.5
1.26.9
1
cloud37io/s3-encryption-gateway:0.12.310e791e98b62
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.60.0
1.26.9
1
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.60.0
1.26.9
1
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.26.9
1
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.16.6
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
1
cloudflare/cloudflared:2024.8.314d9c6b01b29
golang.org/x/net@v0.25.0
stdlib@go1.22.2-devel-cf
0.60.0
1.26.9
1
cloudflare/cloudflared:2024.5.05d5f70a59d5e
golang.org/x/net@v0.25.0
stdlib@go1.22.2-devel-cf
0.60.0
1.26.9
1
cloudflare/cloudflared:2024.11.1665dda65335e
golang.org/x/net@v0.25.0
stdlib@go1.22.5-devel-cf
0.60.0
1.26.9
1
cloudflare/cloudflared:2023.10.0c18744ae1767
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9
1
cloudflare/origin-ca-issuer:v0.15.09ee05675fa9c
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.60.0
1.26.9
1
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.26.9
1
cloudreve/cloudreve:3.8.009093aec5a20
golang.org/x/net@v0.0.0-20220630215102-69896b714898
stdlib@go1.20
0.60.0
1.26.9
1
cloudreve/cloudreve:4.18.0f7a464100bf6
golang.org/x/net@v0.55.0
stdlib@go1.25.5
0.60.0
1.26.9
1
cloudtooling/moodle:5.3.0.2d3e3607acf56
stdlib@go1.26.4
1.26.9
1
cloudtooling/wordpress:7.1.3fb4863035a05
stdlib@go1.26.4
1.26.9
1
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
stdlib@go1.15
1.26.9
1
cmacrae/lgtm:0.1.0dec8d490fe40
golang.org/x/net@v0.0.0-20181108082009-03003ca0c849
stdlib@go1.14.1
0.60.0
1.26.9
1
cockroachdb/cockroach-operator:v2.1.0983312754620
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.60.0
1.26.9
1
codecov/self-hosted-gateway:24.4.1de483faad6e5
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.60.0
1.26.9
1
codenotary/immudb:1.9.77c85d7cc4f22
golang.org/x/net@v0.17.0
stdlib@go1.18.10
0.60.0
1.26.9
1
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.26.9
1
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.26.9
1
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.