StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
gitlab-operatorgitlabVerified publisher3.4.11 of 1See more

gitlab-operator gitlab 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:3.4.196efaea0d3bb
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

136
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

5,338
beylagrafana1.16.111 of 1See more

beyla grafana 1.16.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/beyla:3.32.03ff0f7cf2bbf
golang.org/x/net@v0.57.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

349
helm-dashboardkomodorVerified publisher2.0.71 of 1See more

helm-dashboard komodor 2.0.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
komodorio/helm-dashboard:2.1.3258a9044e658
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

592
kube-prometheus-stackkube-prometheus-stack-oci92.3.05 of 6See more

kube-prometheus-stack kube-prometheus-stack-oci 92.3.0

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,050
kubescape-operatorkubescape1.40.56 of 6See more

kubescape-operator kubescape 1.40.5

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kubescape/http-request:v0.2.234ff502a33423
stdlib@go1.26.7
1.26.9
quay.io/kubescape/kubescape:v4.0.14418fa941ecc0
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/kubescape/kubevuln:v0.3.4309bed2f723ea0
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
golang.org/x/net@v0.56.0
stdlib@go1.25.14
0.60.0
1.26.9
quay.io/kubescape/operator:v0.2.1721ddcd2788e1e
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
quay.io/kubescape/storage:v0.0.3486333d7845589
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

1,978
kube-vipkube-vip0.11.11 of 1See more

kube-vip kube-vip 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kube-vip/kube-vip:v1.2.32fcdbb014a2e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

332
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
stdlib@go1.20.12
1.26.9

Open the chart page →

6,465
linkerd-vizlinkerd2-edgeVerified publisher30.14.11-edge1 of 5See more

linkerd-viz linkerd2-edge 30.14.11-edge

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

1,951
plane-cemakeplaneOfficialVerified publisher1.8.43 of 11See more

plane-ce makeplane 1.8.4

3 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.26.9
pgsty/mc:RELEASE.2026-09-16T00-00-00Zcfc83108c3ab
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
pgsty/minio:RELEASE.2026-08-04T00-00-00Zb6bfe7239bfc
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

4,536
milvusmilvus-helm5.0.302 of 4See more

milvus milvus-helm 5.0.30

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.25-r1fededb2f2d63
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.60.0
1.26.9
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

13,058
mssqlmssqlVerified publisher1.10.31 of 1See more

mssql mssql 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.26.9

Open the chart page →

1,017
opa-kube-mgmtopa-kube-mgmtVerified publisher11.0.142 of 2See more

opa-kube-mgmt opa-kube-mgmt 11.0.14

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
openpolicyagent/kube-mgmt:11.0.14758ff3fb4727
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
openpolicyagent/opa:1.19.0852359995443
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,041
redis-operatorot-container-kit0.27.01 of 1See more

redis-operator ot-container-kit 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/opstree/redis-operator:v0.27.025799bf10231
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

214
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.26.9

Open the chart page →

5,602
s3-proxyoxyno-zetaVerified publisher2.28.01 of 1See more

s3-proxy oxyno-zeta 2.28.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
oxynozeta/s3-proxy:5.1.121115040e224
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

348
spirespiffeVerified publisher0.30.37 of 10See more

spire spiffe 0.30.3

7 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/spiffe/oidc-discovery-provider:1.15.3bb95f13c2b4e
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
golang.org/x/net@v0.42.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/spiffe/spire-agent:1.15.341b0dcd8b258
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/spiffe/spire-controller-manager:0.8.019e418e9d7f2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/spiffe/spire-server:1.15.34082f30d3e0d
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

3,359
wireguardwireguardVerified publisher0.32.01 of 3See more

wireguard wireguard 0.32.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-wireguard-mgr:mainc4febc0da1a4
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

336
altinity-clickhouse-operatoraltinity-clickhouse-operator0.27.43 of 3See more

altinity-clickhouse-operator altinity-clickhouse-operator 0.27.4

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.27.4c60c872fedd8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
altinity/metrics-exporter:0.27.4d257a72e6a6a
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.36.36e4fce3c8365
golang.org/x/net@v0.49.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

612
bytebasebytebase1.1.51 of 1See more

bytebase bytebase 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bytebase/bytebase:latest0b3a44dfac3e
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

378
cert-manager-csi-drivercert-managerOfficialVerified publisher0.16.03 of 3See more

cert-manager-csi-driver cert-manager 0.16.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-csi-driver:v0.16.09d13db6dc80e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,181
ansible-semaphorecloudhippieVerified publisher15.3.21 of 1See more

ansible-semaphore cloudhippie 15.3.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.19.163707a971a57f
golang.org/x/net@v0.36.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,771
etcdcloudpirates-etcdVerified publisher0.8.91 of 1See more

etcd cloudpirates-etcd 0.8.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/etcd-development/etcd:v3.7.27c6c239825d0
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

161
rabbitmq-cluster-operatorcloudpirates-rabbitmq-cluster-operatorVerified publisher0.6.192 of 2See more

rabbitmq-cluster-operator cloudpirates-rabbitmq-cluster-operator 0.6.19

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/rabbitmq/cluster-operator:2.23.09236fb4f559b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/rabbitmq/messaging-topology-operator:1.20.3f377d3c3e221
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

265
zookeepercloudpirates-zookeeperVerified publisher0.15.21 of 1See more

zookeeper cloudpirates-zookeeper 0.15.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/zookeeper:3.9.6d0ae1665a1e8
stdlib@go1.18.1
1.26.9

Open the chart page →

3,593
vertical-pod-autoscalercluster-autoscaler0.13.04 of 4See more

vertical-pod-autoscaler cluster-autoscaler 0.13.0

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.8.03d94f53e4c5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.8.0e743e3a7e58a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.8.01d0229e52f90
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

1,791
codefreshcodefresh-onpremOfficialVerified publisher2.12.216 of 42See more

codefresh codefresh-onprem 2.12.21

6 of the 42 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
golang.org/x/net@v0.27.0
stdlib@go1.21.12
0.60.0
1.26.9
bitnamilegacy/nats:2.11.8-debian-12-r0fa0cfba6034a
stdlib@go1.24.6
1.26.9
ghcr.io/helm/chartmuseum:v0.16.648bc27743c08
golang.org/x/net@v0.56.0
stdlib@go1.25.13
0.60.0
1.26.9
quay.io/codefresh/dind:3.0.250885ab519dac
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
stdlib@go1.23.8
1.26.9

Open the chart page →

19,378
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/projectcontour/contour:v1.33.7d88264ed084a
golang.org/x/net@v0.58.0
stdlib@go1.26.8-X:nodwarf5,nogreenteagc,norandomizedheapbase64
0.60.0
1.26.9

Open the chart page →

1,829
couchbase-operatorcouchbaseVerified publisher2.93.02 of 2See more

couchbase-operator couchbase 2.93.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
couchbase/admission-controller:2.9.3bf2d2e87e45f
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9
couchbase/operator:2.9.369a385b49e1f
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,230
dash0-operatordash0-operatorOfficialVerified publisher0.157.01 of 1See more

dash0-operator dash0-operator 0.157.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dash0hq/operator-controller:0.157.02103617548e2
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

135
aws-ebs-csi-driverdeliveryheroVerified publisher2.17.46 of 6See more

aws-ebs-csi-driver deliveryhero 2.17.4

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/net@v0.4.0
stdlib@go1.19.6
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/net@v0.4.0
stdlib@go1.19.8
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/livenessprobe:v2.9.0-eks-1-25-latest8a305e162caa
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/node-driver-registrar:v2.7.0-eks-1-25-latestf4345e67df8f
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

10,643
eck-exporterenixVerified publisher1.14.01 of 1See more

eck-exporter enix 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

237
loki-simple-scalablegrafana1.8.112 of 3See more

loki-simple-scalable grafana 1.8.11

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18
0.60.0
1.26.9
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9

Open the chart page →

8,697
memcachedkubelauncherVerified publisher0.1.331 of 1See more

memcached kubelauncher 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/memcacheddigest-pinned91f2066d2aa4
stdlib@go1.26.7
1.26.9

Open the chart page →

649
mysqlkubelauncherVerified publisher0.4.61 of 1See more

mysql kubelauncher 0.4.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnedb25f98e6a86f
stdlib@go1.26.7
1.26.9

Open the chart page →

633
postgresqlkubelauncherVerified publisher0.5.01 of 1See more

postgresql kubelauncher 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinneddb2369c4dd90
stdlib@go1.26.7
1.26.9

Open the chart page →

730
kubernetes-replicatorkubernetes-replicator2.12.41 of 1See more

kubernetes-replicator kubernetes-replicator 2.12.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.12.45dc9fc5ff59a
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

590
lakefslakefsVerified publisher1.12.431 of 1See more

lakefs lakefs 1.12.43

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
treeverse/lakefs:1.88.0237a17c6b2d8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

406
multi-juicermulti-juicer10.3.11 of 1See more

multi-juicer multi-juicer 10.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/juice-shop/multi-juicer/multi-juicer:v10.3.1de4f0de62e8b
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

153
coreneuvectorchartsVerified publisher2.11.23 of 5See more

core neuvectorcharts 2.11.2

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
neuvector/controller:5.6.2824e29cf32c5
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
neuvector/enforcer:5.6.272e1deee40fb
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
neuvector/scanner:6d9e8b2ee8d69
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,110
diunnicholaswildeVerified publisher1.0.01 of 1See more

diun nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/diun:4.19.0c94e32b888e4
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.5
0.60.0
1.26.9

Open the chart page →

4,868
openclawopenclawVerified publisher1.110.12 of 2See more

openclaw openclaw 1.110.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.57.06bac628b3d82
stdlib@go1.26.7
1.26.9
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.110.151e6f187064f
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

3,025
prometheus-stackdriver-exporterprometheus-communityVerified publisher5.2.01 of 1See more

prometheus-stackdriver-exporter prometheus-community 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prometheuscommunity/stackdriver-exporter:v0.19.0c0a0cbf76570
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

560
questdbquestdb1.0.271 of 2See more

questdb questdb 1.0.27

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
questdb/questdb:10.0.167eaed863ebb
stdlib@go1.25.14
1.26.9

Open the chart page →

112
adguard-homerm3lVerified publisher0.24.11 of 2See more

adguard-home rm3l 0.24.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.513a143e6c071c
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,644
spegelspegelVerified publisher0.7.41 of 1See more

spegel spegel 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/spegel-org/spegeldigest-pinned26c60b05e08a
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

423
supabasetokens-studioVerified publisher1.0.03 of 14See more

supabase tokens-studio 1.0.0

3 of the 14 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9
supabase/gotrue:v2.163.0ba4ddc594b0b
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

26,454
wekanwekanVerified publisher12.25.02 of 3See more

wekan wekan 12.25.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latestf5c33dc89d90
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2
ghcr.io/wekan/wekan:v12.2562ccbac56677
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,854
woodpeckerwoodpecker-ci3.7.52 of 2See more

woodpecker woodpecker-ci 3.7.5

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
woodpeckerci/woodpecker-agent:v3.19.0f85f163e0949
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
woodpeckerci/woodpecker-server:v3.19.06ca167a3c58b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

252
prometheus-operatorarldkaVerified publisher13.0.12 of 2See more

prometheus-operator arldka 13.0.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.73.204f2b98d71ef
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

3,394

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.17.5
0.60.0
1.26.9
1
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
golang.org/x/net@v0.8.0
stdlib@go1.19.3
0.60.0
1.26.9
1
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.17.8
0.60.0
1.26.9
1
chocobozzz/peertube:v8.1.5052712130691
stdlib@go1.24.4
1.26.9
1
chriseaton/adventureworks:latest54c3384ce701
stdlib@go1.23.1
1.26.9
1
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.60.0
1.26.9
1
chrislusf/seaweedfs:4.346620371e8af8
golang.org/x/net@v0.54.0
stdlib@go1.25.11
0.60.0
1.26.9
1
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9
1
chrislusf/seaweedfs-csi-driver:v1.4.341fca534c9001
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
chrislusf/seaweedfs-mount:v1.4.347c6250e96001
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
chriswells0/first-mate:1.0.5f3918ec8471c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
1
circleci/container-agent:34d8d0ae5efc3
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.60.0
1.26.9
1
circleci/runner:launch-agent9bdc62f02162
stdlib@go1.21.5
1.26.9
1
ciscolabs/msm-nc:0710202336d02faad958
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
stdlib@go1.18.1
1.26.9
1
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/net@v0.4.0
stdlib@go1.19.2
0.60.0
1.26.9
1
clastix/kamaji:latestbb4bd5e1d9eb
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
1
cleanstart/minio:latestf1156f7fd14a
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
clickhouse/clickhouse-server:23.8512bb8a21483
stdlib@go1.19.10
1.26.9
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
stdlib@go1.19.5
1.26.9
1
cloud37io/s3-encryption-gateway:0.12.310e791e98b62
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.60.0
1.26.9
1
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.60.0
1.26.9
1
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.26.9
1
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.16.6
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
1
cloudflare/cloudflared:2024.8.314d9c6b01b29
golang.org/x/net@v0.25.0
stdlib@go1.22.2-devel-cf
0.60.0
1.26.9
1
cloudflare/cloudflared:2024.5.05d5f70a59d5e
golang.org/x/net@v0.25.0
stdlib@go1.22.2-devel-cf
0.60.0
1.26.9
1
cloudflare/cloudflared:2024.11.1665dda65335e
golang.org/x/net@v0.25.0
stdlib@go1.22.5-devel-cf
0.60.0
1.26.9
1
cloudflare/cloudflared:2023.10.0c18744ae1767
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9
1
cloudflare/origin-ca-issuer:v0.15.09ee05675fa9c
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.60.0
1.26.9
1
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.26.9
1
cloudreve/cloudreve:3.8.009093aec5a20
golang.org/x/net@v0.0.0-20220630215102-69896b714898
stdlib@go1.20
0.60.0
1.26.9
1
cloudreve/cloudreve:4.18.0f7a464100bf6
golang.org/x/net@v0.55.0
stdlib@go1.25.5
0.60.0
1.26.9
1
cloudtooling/moodle:5.3.0.2d3e3607acf56
stdlib@go1.26.4
1.26.9
1
cloudtooling/wordpress:7.1.3fb4863035a05
stdlib@go1.26.4
1.26.9
1
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
stdlib@go1.15
1.26.9
1
cmacrae/lgtm:0.1.0dec8d490fe40
golang.org/x/net@v0.0.0-20181108082009-03003ca0c849
stdlib@go1.14.1
0.60.0
1.26.9
1
cockroachdb/cockroach-operator:v2.1.0983312754620
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.60.0
1.26.9
1
codecov/self-hosted-gateway:24.4.1de483faad6e5
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.60.0
1.26.9
1
codenotary/immudb:1.9.77c85d7cc4f22
golang.org/x/net@v0.17.0
stdlib@go1.18.10
0.60.0
1.26.9
1
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.26.9
1
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.26.9
1
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.