StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
gitlab-operatorgitlabVerified publisher3.4.11 of 1See more

gitlab-operator gitlab 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:3.4.196efaea0d3bb
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

136
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

5,338
beylagrafana1.16.111 of 1See more

beyla grafana 1.16.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/beyla:3.32.03ff0f7cf2bbf
golang.org/x/net@v0.57.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

349
helm-dashboardkomodorVerified publisher2.0.71 of 1See more

helm-dashboard komodor 2.0.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
komodorio/helm-dashboard:2.1.3258a9044e658
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

592
kube-prometheus-stackkube-prometheus-stack-oci92.3.05 of 6See more

kube-prometheus-stack kube-prometheus-stack-oci 92.3.0

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,050
kubescape-operatorkubescape1.40.56 of 6See more

kubescape-operator kubescape 1.40.5

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kubescape/http-request:v0.2.234ff502a33423
stdlib@go1.26.7
1.26.9
quay.io/kubescape/kubescape:v4.0.14418fa941ecc0
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/kubescape/kubevuln:v0.3.4309bed2f723ea0
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
golang.org/x/net@v0.56.0
stdlib@go1.25.14
0.60.0
1.26.9
quay.io/kubescape/operator:v0.2.1721ddcd2788e1e
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
quay.io/kubescape/storage:v0.0.3486333d7845589
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

1,978
kube-vipkube-vip0.11.11 of 1See more

kube-vip kube-vip 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kube-vip/kube-vip:v1.2.32fcdbb014a2e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

332
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
stdlib@go1.20.12
1.26.9

Open the chart page →

6,465
linkerd-vizlinkerd2-edgeVerified publisher30.14.11-edge1 of 5See more

linkerd-viz linkerd2-edge 30.14.11-edge

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

1,951
plane-cemakeplaneOfficialVerified publisher1.8.43 of 11See more

plane-ce makeplane 1.8.4

3 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.26.9
pgsty/mc:RELEASE.2026-09-16T00-00-00Zcfc83108c3ab
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
pgsty/minio:RELEASE.2026-08-04T00-00-00Zb6bfe7239bfc
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

4,536
milvusmilvus-helm5.0.302 of 4See more

milvus milvus-helm 5.0.30

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.25-r1fededb2f2d63
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.60.0
1.26.9
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

13,058
mssqlmssqlVerified publisher1.10.31 of 1See more

mssql mssql 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.26.9

Open the chart page →

1,017
opa-kube-mgmtopa-kube-mgmtVerified publisher11.0.142 of 2See more

opa-kube-mgmt opa-kube-mgmt 11.0.14

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
openpolicyagent/kube-mgmt:11.0.14758ff3fb4727
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
openpolicyagent/opa:1.19.0852359995443
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,041
redis-operatorot-container-kit0.27.01 of 1See more

redis-operator ot-container-kit 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/opstree/redis-operator:v0.27.025799bf10231
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

214
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.26.9

Open the chart page →

5,602
s3-proxyoxyno-zetaVerified publisher2.28.01 of 1See more

s3-proxy oxyno-zeta 2.28.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
oxynozeta/s3-proxy:5.1.121115040e224
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

348
spirespiffeVerified publisher0.30.37 of 10See more

spire spiffe 0.30.3

7 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/spiffe/oidc-discovery-provider:1.15.3bb95f13c2b4e
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
golang.org/x/net@v0.42.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/spiffe/spire-agent:1.15.341b0dcd8b258
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/spiffe/spire-controller-manager:0.8.019e418e9d7f2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/spiffe/spire-server:1.15.34082f30d3e0d
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

3,359
wireguardwireguardVerified publisher0.32.01 of 3See more

wireguard wireguard 0.32.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-wireguard-mgr:mainc4febc0da1a4
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

336
altinity-clickhouse-operatoraltinity-clickhouse-operator0.27.43 of 3See more

altinity-clickhouse-operator altinity-clickhouse-operator 0.27.4

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.27.4c60c872fedd8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
altinity/metrics-exporter:0.27.4d257a72e6a6a
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.36.36e4fce3c8365
golang.org/x/net@v0.49.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

612
bytebasebytebase1.1.51 of 1See more

bytebase bytebase 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bytebase/bytebase:latest0b3a44dfac3e
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

378
cert-manager-csi-drivercert-managerOfficialVerified publisher0.16.03 of 3See more

cert-manager-csi-driver cert-manager 0.16.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-csi-driver:v0.16.09d13db6dc80e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,181
ansible-semaphorecloudhippieVerified publisher15.3.21 of 1See more

ansible-semaphore cloudhippie 15.3.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.19.163707a971a57f
golang.org/x/net@v0.36.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,771
etcdcloudpirates-etcdVerified publisher0.8.91 of 1See more

etcd cloudpirates-etcd 0.8.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/etcd-development/etcd:v3.7.27c6c239825d0
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

161
rabbitmq-cluster-operatorcloudpirates-rabbitmq-cluster-operatorVerified publisher0.6.192 of 2See more

rabbitmq-cluster-operator cloudpirates-rabbitmq-cluster-operator 0.6.19

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/rabbitmq/cluster-operator:2.23.09236fb4f559b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/rabbitmq/messaging-topology-operator:1.20.3f377d3c3e221
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

265
zookeepercloudpirates-zookeeperVerified publisher0.15.21 of 1See more

zookeeper cloudpirates-zookeeper 0.15.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/zookeeper:3.9.6d0ae1665a1e8
stdlib@go1.18.1
1.26.9

Open the chart page →

3,593
vertical-pod-autoscalercluster-autoscaler0.13.04 of 4See more

vertical-pod-autoscaler cluster-autoscaler 0.13.0

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.8.03d94f53e4c5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.8.0e743e3a7e58a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.8.01d0229e52f90
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

1,791
codefreshcodefresh-onpremOfficialVerified publisher2.12.216 of 42See more

codefresh codefresh-onprem 2.12.21

6 of the 42 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
golang.org/x/net@v0.27.0
stdlib@go1.21.12
0.60.0
1.26.9
bitnamilegacy/nats:2.11.8-debian-12-r0fa0cfba6034a
stdlib@go1.24.6
1.26.9
ghcr.io/helm/chartmuseum:v0.16.648bc27743c08
golang.org/x/net@v0.56.0
stdlib@go1.25.13
0.60.0
1.26.9
quay.io/codefresh/dind:3.0.250885ab519dac
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
stdlib@go1.23.8
1.26.9

Open the chart page →

19,378
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/projectcontour/contour:v1.33.7d88264ed084a
golang.org/x/net@v0.58.0
stdlib@go1.26.8-X:nodwarf5,nogreenteagc,norandomizedheapbase64
0.60.0
1.26.9

Open the chart page →

1,829
couchbase-operatorcouchbaseVerified publisher2.93.02 of 2See more

couchbase-operator couchbase 2.93.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
couchbase/admission-controller:2.9.3bf2d2e87e45f
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9
couchbase/operator:2.9.369a385b49e1f
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,230
dash0-operatordash0-operatorOfficialVerified publisher0.157.01 of 1See more

dash0-operator dash0-operator 0.157.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dash0hq/operator-controller:0.157.02103617548e2
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

135
aws-ebs-csi-driverdeliveryheroVerified publisher2.17.46 of 6See more

aws-ebs-csi-driver deliveryhero 2.17.4

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/net@v0.4.0
stdlib@go1.19.6
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/net@v0.4.0
stdlib@go1.19.8
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/livenessprobe:v2.9.0-eks-1-25-latest8a305e162caa
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/node-driver-registrar:v2.7.0-eks-1-25-latestf4345e67df8f
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

10,643
eck-exporterenixVerified publisher1.14.01 of 1See more

eck-exporter enix 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

237
loki-simple-scalablegrafana1.8.112 of 3See more

loki-simple-scalable grafana 1.8.11

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18
0.60.0
1.26.9
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9

Open the chart page →

8,697
memcachedkubelauncherVerified publisher0.1.331 of 1See more

memcached kubelauncher 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/memcacheddigest-pinned91f2066d2aa4
stdlib@go1.26.7
1.26.9

Open the chart page →

649
mysqlkubelauncherVerified publisher0.4.61 of 1See more

mysql kubelauncher 0.4.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnedb25f98e6a86f
stdlib@go1.26.7
1.26.9

Open the chart page →

633
postgresqlkubelauncherVerified publisher0.5.01 of 1See more

postgresql kubelauncher 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinneddb2369c4dd90
stdlib@go1.26.7
1.26.9

Open the chart page →

730
kubernetes-replicatorkubernetes-replicator2.12.41 of 1See more

kubernetes-replicator kubernetes-replicator 2.12.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.12.45dc9fc5ff59a
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

590
lakefslakefsVerified publisher1.12.431 of 1See more

lakefs lakefs 1.12.43

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
treeverse/lakefs:1.88.0237a17c6b2d8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

406
multi-juicermulti-juicer10.3.11 of 1See more

multi-juicer multi-juicer 10.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/juice-shop/multi-juicer/multi-juicer:v10.3.1de4f0de62e8b
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

153
coreneuvectorchartsVerified publisher2.11.23 of 5See more

core neuvectorcharts 2.11.2

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
neuvector/controller:5.6.2824e29cf32c5
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
neuvector/enforcer:5.6.272e1deee40fb
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
neuvector/scanner:6d9e8b2ee8d69
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,110
diunnicholaswildeVerified publisher1.0.01 of 1See more

diun nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/diun:4.19.0c94e32b888e4
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.5
0.60.0
1.26.9

Open the chart page →

4,868
openclawopenclawVerified publisher1.110.12 of 2See more

openclaw openclaw 1.110.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.57.06bac628b3d82
stdlib@go1.26.7
1.26.9
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.110.151e6f187064f
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

3,025
prometheus-stackdriver-exporterprometheus-communityVerified publisher5.2.01 of 1See more

prometheus-stackdriver-exporter prometheus-community 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prometheuscommunity/stackdriver-exporter:v0.19.0c0a0cbf76570
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

560
questdbquestdb1.0.271 of 2See more

questdb questdb 1.0.27

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
questdb/questdb:10.0.167eaed863ebb
stdlib@go1.25.14
1.26.9

Open the chart page →

112
adguard-homerm3lVerified publisher0.24.11 of 2See more

adguard-home rm3l 0.24.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.513a143e6c071c
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,644
spegelspegelVerified publisher0.7.41 of 1See more

spegel spegel 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/spegel-org/spegeldigest-pinned26c60b05e08a
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

423
supabasetokens-studioVerified publisher1.0.03 of 14See more

supabase tokens-studio 1.0.0

3 of the 14 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9
supabase/gotrue:v2.163.0ba4ddc594b0b
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

26,454
wekanwekanVerified publisher12.25.02 of 3See more

wekan wekan 12.25.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latestf5c33dc89d90
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2
ghcr.io/wekan/wekan:v12.2562ccbac56677
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,854
woodpeckerwoodpecker-ci3.7.52 of 2See more

woodpecker woodpecker-ci 3.7.5

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
woodpeckerci/woodpecker-agent:v3.19.0f85f163e0949
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
woodpeckerci/woodpecker-server:v3.19.06ca167a3c58b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

252
prometheus-operatorarldkaVerified publisher13.0.12 of 2See more

prometheus-operator arldka 13.0.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.73.204f2b98d71ef
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

3,394

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
codeskyblue/gohttpserver:latestcaa862590e34
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.16.3
0.60.0
1.26.9
1
codiacimages/codiac-deployment-bundle:0.0.15d7d1e91eccde
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.60.0
1.26.9
1
cometbft/cometbft:v0.38.1722c2ac018f40
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.60.0
1.26.9
1
concourse/concourse:8.3.1c9d48dfbf4f9
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
conduction/agendaservice-php:latest9cfeeb6c7c20
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9
1
conduction/balance-registration-php:devc36094a41369
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9
1
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9
1
conduction/cgrc-php:dev25415534d245
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9
1
conduction/checkin-component-php:dev3423845692c1
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9
1
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9
1
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9
1
conduction/kvk-php:dev8f177f9f8a7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9
1
conduction/pan-php:dev24f03c57568f
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9
1
confluentinc/cp-kafka:latest5e8f3ab5b497
stdlib@go1.27.1
1.27.2
1
confluentinc/cp-schema-registry:latest482d3048b3f6
stdlib@go1.27.1
1.27.2
1
consensys/web3signer:latest0a64d3b00613
stdlib@go1.26.7
1.26.9
1
containous/maesh:v1.3.2587162516502
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.14.4
0.60.0
1.26.9
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
1
coordimap/coordimap-agent:latest7748fd0fae9f
golang.org/x/net@v0.38.0
stdlib@go1.26.4
0.60.0
1.26.9
1
coredns/coredns:1.12.040384aa1f5ea
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.60.0
1.26.9
1
coredns/coredns:1.7.073ca82b4ce82
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.4
0.60.0
1.26.9
1
coredns/coredns:1.14.77efd3c635b03
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
1
coredns/coredns:1.11.39caabbf6238b
golang.org/x/net@v0.25.0
stdlib@go1.21.11
0.60.0
1.26.9
1
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/net@v0.4.0
stdlib@go1.20
0.60.0
1.26.9
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.60.0
1.26.9
1
cortezaproject/corteza:2024.9.08eb7a26605c9
golang.org/x/net@v0.21.0
stdlib@go1.19.13
0.60.0
1.26.9
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.60.0
1.26.9
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
stdlib@go1.23.5
1.26.9
1
couchbase/admission-controller:2.9.3bf2d2e87e45f
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9
1
couchbase/operator:2.9.369a385b49e1f
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9
1
countly/api:25.05.4f4cc7447c4f5
stdlib@go1.19.4
1.26.9
1
countly/countly-server:25.05.4e3c238248f99
stdlib@go1.21.11
1.26.9
1
countly/frontend:25.05.42acbc11499b6
stdlib@go1.19.4
1.26.9
1
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.60.0
1.26.9
1
crocodilestick/calibre-web-automated:v4.0.6c31a738b6d5e
stdlib@go1.17.8
1.26.9
1
crossplane/crossplane:v0.12.066666e6963af
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.60.0
1.26.9
1
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.14
0.60.0
1.26.9
1
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.60.0
1.26.9
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.2
0.60.0
1.26.9
1
csepulvedab/secret-sync:0.5227a6f2b0ff8
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.4
0.60.0
1.26.9
1
ctolon17/owui-cee-proxy:0.8.06023888bf007
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
1
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.16.13
0.60.0
1.26.9
1
cube8021/push-to-k8s:v1.2.2c5d1a1ec4c5e
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
1
curtismager20/mcp-chat-daemon:4.0.83dbf757dad657
stdlib@go1.26.8
1.26.9
1
curtismager20/mcp-inventory:4.0.83bf588de2c078
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
curtismager20/mcp-sync:4.0.83e407298e4756
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
cyberark/conjur-k8s-csi-provider:latest737a967088d9
golang.org/x/net@v0.54.0
stdlib@go1.26.5
0.60.0
1.26.9
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
golang.org/x/net@v0.43.0
stdlib@go1.25.4
0.60.0
1.26.9
1
cyverse/irods-csi-driver:v0.12.2c5877ea80e0e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.