StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
spectrechronicleVerified publisher0.3.91 of 1See more

spectre chronicle 0.3.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,010
validatorchronicleVerified publisher0.8.21 of 1See more

validator chronicle 0.8.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/ghost:0.81.0417b664eee72
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

616
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.60.0
1.26.9

Open the chart page →

1,197
clairclair0.0.31 of 1See more

clair clair 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.7.28d38ffa8fad7
golang.org/x/net@v0.14.0
stdlib@go1.20.9
0.60.0
1.26.9

Open the chart page →

3,968
clamav-restclamav-rest-apiVerified publisher0.1.01 of 1See more

clamav-rest clamav-rest-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ajilaag/clamav-rest:latestad689c7b75b1
stdlib@go1.26.0
1.26.9

Open the chart page →

857
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.26.9

Open the chart page →

2,234
clickhouse-operator-helmclickhouse-operator0.0.81 of 1See more

clickhouse-operator-helm clickhouse-operator 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/clickhouse/clickhouse-operator:v0.0.880ff894a42fb
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.60.0
1.26.9
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.60.0
1.26.9

Open the chart page →

4,728
cloudflare-tunnelcloudflare-tunnelVerified publisher0.16.81 of 1See more

cloudflare-tunnel cloudflare-tunnel 0.16.8

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.10.09b49eed8f628
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

548
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.26.9
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

6,492
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.6
0.60.0
1.26.9
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.18.6
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

10,444
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.26.9

Open the chart page →

3,937
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.26.9

Open the chart page →

2,866
grafanacloudposse0.2.61 of 1See more

grafana cloudposse 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:latestb28bae15e219
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

258
cloudttycloudtty0.8.102 of 2See more

cloudtty cloudtty 0.8.10

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell:v0.8.1023e8d178e02c
golang.org/x/net@v0.45.0
stdlib@go1.25.2
0.60.0
1.26.9
ghcr.io/cloudtty/cloudshell-operator:v0.8.1014f036e33ef1
golang.org/x/net@v0.25.0
stdlib@go1.21.11
0.60.0
1.26.9

Open the chart page →

4,285
cluster-api-provider-oxidecluster-api-provider-oxide0.2.31 of 1See more

cluster-api-provider-oxide cluster-api-provider-oxide 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/oxidecomputer/cluster-api-provider-oxide:0.2.37b05d3bbfbfa
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

326
cluster-api-visualizercluster-api-visualizer1.5.01 of 1See more

cluster-api-visualizer cluster-api-visualizer 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

918
clustereye-stackclustereyeVerified publisher0.1.12 of 5See more

clustereye-stack clustereye 0.1.1

2 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
johnblack77/clustereye-api:latest816f4e2fea4a
golang.org/x/net@v0.50.0
stdlib@go1.25.14
0.60.0
1.26.9
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9

Open the chart page →

5,461
clusternet-hubclusternet1.0.01 of 1See more

clusternet-hub clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-hub:v1.0.059f75504c5d4
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

2,087
clusternet-schedulerclusternet1.0.01 of 1See more

clusternet-scheduler clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-scheduler:v1.0.0a6ae5aff81ce
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

2,087
cluster-setupcluster-setup1.5.07 of 8See more

cluster-setup cluster-setup 1.5.0

7 of the 8 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
golang.org/x/net@v0.37.0
stdlib@go1.24.3
0.60.0
1.26.9
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.26.9
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
golang.org/x/net@v0.33.0
stdlib@go1.22.7
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.17.2ec56edb1161d
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.17.2e18989b4f912
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

14,455
cockroachdb-chartcockroachdbv226.3.21 of 1See more

cockroachdb-chart cockroachdbv2 26.3.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.10b0fcc6c8147a
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

587
istio-allcode4devsVerified publisher1.2.04 of 6See more

istio-all code4devs 1.2.0

4 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.60.0
1.26.9

Open the chart page →

6,799
istio-control-planecode4devsVerified publisher1.0.02 of 3See more

istio-control-plane code4devs 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

3,352
maintenancecodewithemadVerified publisher0.1.61 of 1See more

maintenance codewithemad 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/caddy:2.9-alpineb4e3952384eb
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

2,000
dawarichcogitriVerified publisher2.9.31 of 3See more

dawarich cogitri 2.9.3

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.3589e3606b11b
stdlib@go1.24.4
1.26.9

Open the chart page →

6,993
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,227
cortex-tenantcortex-tenantVerified publisher0.8.11 of 1See more

cortex-tenant cortex-tenant 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/blind-oracle/cortex-tenant:v2.0.09f8896ffc15b
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

1,219
cosmo-controller-managercosmoVerified publisher0.9.01 of 2See more

cosmo-controller-manager cosmo 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-controller-manager:v0.9.08c7fa5552028
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

2,609
cosmo-dashboardcosmoVerified publisher0.9.11 of 1See more

cosmo-dashboard cosmo 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-dashboard:v0.9.16a1c4a81a924
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

2,622
cp-schema-registrycp-schema-registryVerified publisher1.0.01 of 1See more

cp-schema-registry cp-schema-registry 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
stdlib@go1.25.4
1.26.9

Open the chart page →

2,547
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.60.0
1.26.9

Open the chart page →

7,702
chalk-operatorcrashoverride-helm-chartsVerified publisher0.1.11 of 1See more

chalk-operator crashoverride-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/chalk-operator:v0.1.128eee62e9bfa
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

695
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.26.9

Open the chart page →

4,700
cronguardcronguardVerified publisher0.4.31 of 1See more

cronguard cronguard 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dmazhukov/cronguard:0.4.37683dd5b26ba
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
cronjob-scale-down-operatorcronschedules0.4.41 of 1See more

cronjob-scale-down-operator cronschedules 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cronschedules/cronjob-scale-down-operator:0.4.4fd521f0034a0
golang.org/x/net@v0.52.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

844
cruisekubecruisekubeOfficialVerified publisher0.3.41 of 5See more

cruisekube cruisekube 0.3.4

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

886
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
stdlib@go1.19.8
1.26.9

Open the chart page →

15,910
revadcs3orgOfficialVerified publisher1.6.11 of 1See more

revad cs3org 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

2,384
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.4
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

24,924
CubeUniversecubeuniverseVerified publisher0.1.01 of 1See more

CubeUniverse cubeuniverse 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20.3
0.60.0
1.26.9

Open the chart page →

3,095
cview-issuercview-issuerVerified publisher0.0.431 of 1See more

cview-issuer cview-issuer 0.0.43

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
devsecurely/cview-issuer:0.0.4335675bd31bfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

128
cyphernetes-operatorcyphernetes-operatorVerified publisher0.1.01 of 1See more

cyphernetes-operator cyphernetes-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

926
dagrondagron-workflowVerified publisher0.10.01 of 3See more

dagron dagron-workflow 0.10.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.26.9

Open the chart page →

1,556
dagster-cloud-agentdagster-cloudVerified publisher1.13.261 of 1See more

dagster-cloud-agent dagster-cloud 1.13.26

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dagster/dagster-cloud-agent:1.13.26c9320c34f7ed
stdlib@go1.25.7
1.26.9

Open the chart page →

1,180
aibrixdanchevVerified publisher0.7.02 of 5See more

aibrix danchev 0.7.0

2 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
aibrix/controller-manager:v0.7.076aabbbfda79
golang.org/x/net@v0.34.0
stdlib@go1.22.12
0.60.0
1.26.9
aibrix/gateway-plugins:v0.7.05b93ea4c753a
golang.org/x/net@v0.34.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

7,002
data-fairdata354-helmVerified publisher1.1.22 of 12See more

data-fair data354-helm 1.1.2

2 of the 12 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.26.9
quay.io/prometheus/prometheus:latestefd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

42,780
datacube-explorerdatacube-charts0.5.341 of 1See more

datacube-explorer datacube-charts 0.5.34

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/opendatacube/explorer:latest7c25578068cd
stdlib@go1.25.0
1.26.9

Open the chart page →

2,153
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.15
0.60.0
1.26.9

Open the chart page →

5,892
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.11
0.60.0
1.26.9

Open the chart page →

5,924

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9
1
dannielkil/book-db:latest433290c5c1db
stdlib@go1.18.2
1.26.9
1
danroux/sk8l-api:v0.19.0dee851fc72cc
golang.org/x/net@v0.57.0
stdlib@go1.26.4-X:loopvar
0.60.0
1.26.9
1
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.26.9
1
daprio/dashboard:0.15.04be696707bd1
golang.org/x/net@v0.25.0
stdlib@go1.21.13
0.60.0
1.26.9
1
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
stdlib@go1.19.13
0.60.0
1.26.9
1
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
darioackermann/cert-manager-webhook-regery:latest0d450bc4acc4
golang.org/x/net@v0.26.0
stdlib@go1.22.10
0.60.0
1.26.9
1
darkobas/ethexporter:latest62e6464491ba
stdlib@go1.19.1
1.26.9
1
darkobas/tokenexporter:latestf26e016a9d7e
stdlib@go1.27.1
1.27.2
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9
1
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/net@v0.7.0
stdlib@go1.20
0.60.0
1.26.9
1
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/net@v0.41.0
stdlib@go1.24.3
0.60.0
1.26.9
1
darthsim/imgproxy:latestc0d8c00be50c
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
dashops/dash-ops:latest23537693ff05
golang.org/x/net@v0.46.0
stdlib@go1.25.10
0.60.0
1.26.9
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
stdlib@go1.16.9
1.26.9
1
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.11
0.60.0
1.26.9
1
datadog/agent:6aad9994de6a7
golang.org/x/net@v0.33.0
stdlib@go1.21.11
0.60.0
1.26.9
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.15
0.60.0
1.26.9
1
datadog/operator:0.3.117f08a860090
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.2
0.60.0
1.26.9
1
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.21.4
0.60.0
1.26.9
1
datappeal/hive-metastore:lateste38c085a3567
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.4
0.60.0
1.26.9
1
datappeal/trino-exporter:latest325b91c2b09e
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.15
0.60.0
1.26.9
1
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.17.13
0.60.0
1.26.9
1
datasaker/dsk-container-agent:latest08b52999f67b
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.60.0
1.26.9
1
datasaker/dsk-k8s-agent:latest2542ee73be51
golang.org/x/net@v0.17.0
stdlib@go1.19.1
0.60.0
1.26.9
1
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.60.0
1.26.9
1
datasaker/dsk-node-agent:latest1b95913b6729
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
1
datasaker/dsk-process-agent:latest2f38720a637d
golang.org/x/net@v0.15.0
stdlib@go1.21.0
0.60.0
1.26.9
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
1
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
1
datawire/aes:3.11.195ec30b3c732
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.60.0
1.26.9
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.16.5
0.60.0
1.26.9
1
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
1
ddefrancesco/scoperunner-server:0.2.1daaac6657600
stdlib@go1.21.10
1.26.9
1
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.60.0
1.26.9
1
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
1
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
1
ddvk/rmfakecloud:latest2f5c45cbf0c5
golang.org/x/net@v0.38.0
stdlib@go1.26.3
0.60.0
1.26.9
1
deconzcommunity/deconz:2.29.2062de2362641
stdlib@go1.19.8
1.26.9
1
deconzcommunity/deconz:2.26.123c86008d73f
stdlib@go1.19.8
1.26.9
1
deepflowce/deepflow-init-grafana:v6.2.27cd16719eb57
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.3
0.60.0
1.26.9
1
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
golang.org/x/net@v0.8.0
stdlib@go1.19.1
0.60.0
1.26.9
1
deepflowce/deepflow-server:v6.2.21477e7334d13
golang.org/x/net@v0.2.0
stdlib@go1.18.10
0.60.0
1.26.9
1
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
1
defactops/defactops-ui:1.0.16825cdf9ba706
golang.org/x/net@v0.25.0
stdlib@go1.21.10
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.