StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
external-monitoringwiremindVerified publisher0.3.01 of 1See more

external-monitoring wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

2,008
kubemodwiremindVerified publisher0.1.51 of 2See more

kubemod wiremind 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.13.0cadca39288ad
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.14.7
0.60.0
1.26.9

Open the chart page →

4,268
db-backup-retentionwjentner-chartsVerified publisher1.1.01 of 1See more

db-backup-retention wjentner-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wjentner/k8s-db-backup-retention:v1.1.08027bb46d1f4
golang.org/x/net@v0.26.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,624
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

9,523
wordpress-helmwordpress-helm0.2.92 of 4See more

wordpress-helm wordpress-helm 0.2.9

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
library/mysql:80744ee5ef89c
stdlib@go1.24.6
1.26.9

Open the chart page →

10,285
workflows-aggregatorworkflows-aggregatorVerified publisher0.16.121 of 1See more

workflows-aggregator workflows-aggregator 0.16.12

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-aggregator:0.16.12ce790a4023b6
stdlib@go1.26.7
1.26.9

Open the chart page →

1,043
workflows-informerworkflows-informerVerified publisher0.4.41 of 1See more

workflows-informer workflows-informer 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

1,900
wraftwraft0.1.122 of 9See more

wraft wraft 0.1.12

2 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:14-alpine4ea9e5ed0659
stdlib@go1.24.6
1.26.9
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
stdlib@go1.23.10
1.26.9

Open the chart page →

6,088
pi-hole-exporterwyrihaximusnetVerified publisher0.1.31 of 1See more

pi-hole-exporter wyrihaximusnet 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ekofr/pihole-exporter:0.0.109fdad6f352e0
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.7
0.60.0
1.26.9

Open the chart page →

3,019
redis-db-assignment-operatorwyrihaximusnetVerified publisher1.0.61 of 1See more

redis-db-assignment-operator wyrihaximusnet 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/kubernetes-redis-db-assignment-operator:v1.0.831060be60bec
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

3,286
x402-k8s-operatorx402-k8s-operator0.1.02 of 2See more

x402-k8s-operator x402-k8s-operator 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/kubectl:latestab90e1058e5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/razvanmacovei/x402-k8s-operator:0.1.0bf3407fad182
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

866
discord-botxxczakiVerified publisher0.34.161 of 2See more

discord-bot xxczaki 0.34.16

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/redisdigest-pinnedd75bda00b778
stdlib@go1.26.7
1.26.9

Open the chart page →

932
prometheusalertxxl-job-adminVerified publisher1.4.01 of 1See more

prometheusalert xxl-job-admin 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.28192368b0578
golang.org/x/net@v0.24.0
stdlib@go1.20.6
0.60.0
1.26.9

Open the chart page →

1,865
heistyouniqx-ossVerified publisher1.1.2091 of 1See more

heist youniqx-oss 1.1.209

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/youniqx/heist:v1.1.209c43b3a9d98ae
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.60.0
1.26.9

Open the chart page →

1,338
yugawareyugabyteVerified publisher2026.1.21 of 5See more

yugaware yugabyte 2026.1.2

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:14.232f439458ab6a
stdlib@go1.24.6
1.26.9

Open the chart page →

2,424
zcash-stackzcashVerified publisher0.4.51 of 2See more

zcash-stack zcash 0.4.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
electriccoinco/lightwalletd:v0.5.42ae3a551e111
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

3,650
tailscale-relayzeet0.1.51 of 1See more

tailscale-relay zeet 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
zeetdev/tailscale-relay:v1.24.21967aa2840b6
golang.org/x/net@v0.0.0-20220407224826-aac1ed45d8e3
stdlib@go1.18.1-ts710a0d8610
0.60.0
1.26.9

Open the chart page →

3,213
crowdsec-web-uizekker6Verified publisher0.55.01 of 1See more

crowdsec-web-ui zekker6 0.55.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.10.2c334d8fdf7a8
stdlib@go1.24.4
1.26.9

Open the chart page →

1,564
memoszekker6Verified publisher0.56.01 of 1See more

memos zekker6 0.56.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
neosmemo/memos:0.31.024c2707ddd8f
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

283
cloudflare-zero-trust-operatorzelic-io0.7.11 of 1See more

cloudflare-zero-trust-operator zelic-io 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/bojanzelic/cloudflare-zero-trust-operator:0.7.1f4b2dbc19a78
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,109
mikochizer0tonin1.12.01 of 1See more

mikochi zer0tonin 1.12.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
zer0tonin/mikochi:1.12.0f7ee3fe7ee6b
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

726
velero-notificationszokeber-velero-notificationsVerified publisher0.1.101 of 2See more

velero-notifications zokeber-velero-notifications 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/zokeber/velero-notifications:0.0.176d84f6c4ce20
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,130
backendzymtraceOfficialVerified publisher26.10.02 of 6See more

backend zymtrace 26.10.0

2 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:17.4304ab8135187
stdlib@go1.18.2
1.26.9
pgsty/silo:RELEASE.2026-09-03T13-18-01Zb616a0cf8cb2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

11,149
aaqaaqVerified publisher0.3.01 of 1See more

aaq aaq 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kubevirt/aaq-operator:v1.7.0d28a2daa5b15
golang.org/x/net@v0.47.0
stdlib@go1.24.12
0.60.0
1.26.9

Open the chart page →

1,446
cert-manager-webhook-bunnyaardbol-cert-manager-webhook-bunnyVerified publisher1.4.21 of 1See more

cert-manager-webhook-bunny aardbol-cert-manager-webhook-bunny 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/aardbol/cert-manager-webhook-bunny:v1.4.1be5e446c5ed5
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

229
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/abstract-foundation/zksync-external-node-sidecar:v1.0.03e705d0eb1ce
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

5,692
accurateaccurateOfficialVerified publisher2.1.01 of 1See more

accurate accurate 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cybozu-go/accurate:2.1.0b5cc37ab4d9c
golang.org/x/net@v0.57.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

363
rabbitmq-cluster-operatoradeptia-automate-operator5.2.02 of 2See more

rabbitmq-cluster-operator adeptia-automate-operator 5.2.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-rabbitmq-cluster-operator:5.2cf610f8c614c
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
adeptiainc/adeptia-connect-rabbitmq-messaging-topology-operator:5.27cdf6ac2e738
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,327
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
activepiecesadnoctemVerified publisher0.7.11 of 1See more

activepieces adnoctem 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
activepieces/activepieces:0.92.287295caa32a1
stdlib@go1.23.5
1.26.9

Open the chart page →

1,942
glanceadnoctemVerified publisher0.1.01 of 1See more

glance adnoctem 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.69dfb09470b20
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

376
gobackupadnoctemVerified publisher0.4.01 of 1See more

gobackup adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
huacnlee/gobackup:v3.1.1560be93229a5
golang.org/x/net@v0.47.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

2,621
gotenbergadnoctemVerified publisher0.5.01 of 1See more

gotenberg adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.37.0f29984bd1e22
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

11,096
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
stdlib@go1.23.7
1.26.9

Open the chart page →

5,136
ntfyadnoctemVerified publisher0.4.11 of 1See more

ntfy adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.29.04c599cf08189
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

218
popeyeadnoctemVerified publisher0.3.01 of 1See more

popeye adnoctem 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,952
uptime-kumaadnoctemVerified publisher0.4.31 of 1See more

uptime-kuma adnoctem 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.69912da7d7d9b
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

36,580
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,405
bootaerokube1.0.13 of 4See more

boot aerokube 1.0.1

3 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/aerokube/boot:1.0.13c269612053f
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9
quay.io/aerokube/keygen:1.0.1578934444f04
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
quay.io/aerokube/reloader:1.0.1e4a3661416a5
stdlib@go1.22.2
1.26.9

Open the chart page →

10,171
browser-opsaerokube2.6.71 of 1See more

browser-ops aerokube 2.6.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/aerokube/browser-ops:2.6.7807c1bb67086
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9

Open the chart page →

1,128
moonaerokube1.1.373 of 3See more

moon aerokube 1.1.37

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
aerokube/moon:1.9.17da76ca51220d
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
aerokube/moon-api:1.9.176b6323e75785
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
aerokube/selenoid-ui:1.10.113f3e299509fd
golang.org/x/net@v0.10.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

4,271
aerospike-kubernetes-operatoraerospike4.6.01 of 1See more

aerospike-kubernetes-operator aerospike 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
aerospike/aerospike-kubernetes-operator:4.6.0d0828d4c4db7
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

346
msockperfaetrius2.0.81 of 2See more

msockperf aetrius 2.0.8

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
stdlib@go1.22.1
1.26.9

Open the chart page →

5,118
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,094
agentgateway-route-reconcileragentgateway-route-reconciler0.3.11 of 1See more

agentgateway-route-reconciler agentgateway-route-reconciler 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/ricardozd/agentgateway-route-reconciler:0.3.1846f6e407c96
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

648
agentkube-operatoragentkube-operator0.3.01 of 1See more

agentkube-operator agentkube-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.60.0
1.26.9

Open the chart page →

2,523
mt-channel-brokerahhhhVerified publisher0.1.03 of 3See more

mt-channel-broker ahhhh 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/filterdigest-pinnedd675f211a40f
golang.org/x/net@v0.30.0
stdlib@go1.22.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/ingressdigest-pinnedec4b544499ba
golang.org/x/net@v0.30.0
stdlib@go1.22.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/eventing/cmd/mtchannel_brokerdigest-pinned395f4ff1bd34
golang.org/x/net@v0.30.0
stdlib@go1.22.8
0.60.0
1.26.9

Open the chart page →

4,245
net-istioahhhhVerified publisher0.1.12 of 2See more

net-istio ahhhh 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinnede70bc675f977
golang.org/x/net@v0.30.0
stdlib@go1.22.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned7d76a6d42d13
golang.org/x/net@v0.30.0
stdlib@go1.22.8
0.60.0
1.26.9

Open the chart page →

2,172
net-kourierahhhhVerified publisher0.18.11 of 1See more

net-kourier ahhhh 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned15a601147ef4
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,020
ai-k8s-agentai-k8s-agent0.1.11 of 2See more

ai-k8s-agent ai-k8s-agent 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/jdilsham/ai-k8s-agent-backend:0.1.1ec4b8534ded6
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

945

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
dagster/dagster-cloud-agent:1.13.26c9320c34f7ed
stdlib@go1.25.7
1.26.9
1
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.26.9
1
dalf/morty:latest248a4849c350
golang.org/x/net@v0.0.0-20220421235706-1d1ef9303861
stdlib@go1.18.2
0.60.0
1.26.9
1
danielfm/kube-ecr-cleanup-controller:0.1.1012485563b1d0
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.60.0
1.26.9
1
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9
1
dannielkil/book-db:latest433290c5c1db
stdlib@go1.18.2
1.26.9
1
danroux/sk8l-api:v0.19.0dee851fc72cc
golang.org/x/net@v0.57.0
stdlib@go1.26.4-X:loopvar
0.60.0
1.26.9
1
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.26.9
1
daprio/dashboard:0.15.04be696707bd1
golang.org/x/net@v0.25.0
stdlib@go1.21.13
0.60.0
1.26.9
1
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
stdlib@go1.19.13
0.60.0
1.26.9
1
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
darioackermann/cert-manager-webhook-regery:latest0d450bc4acc4
golang.org/x/net@v0.26.0
stdlib@go1.22.10
0.60.0
1.26.9
1
darkobas/ethexporter:latest62e6464491ba
stdlib@go1.19.1
1.26.9
1
darkobas/tokenexporter:latestf26e016a9d7e
stdlib@go1.27.1
1.27.2
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9
1
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/net@v0.7.0
stdlib@go1.20
0.60.0
1.26.9
1
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/net@v0.41.0
stdlib@go1.24.3
0.60.0
1.26.9
1
darthsim/imgproxy:latestc0d8c00be50c
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
dashops/dash-ops:latest23537693ff05
golang.org/x/net@v0.46.0
stdlib@go1.25.10
0.60.0
1.26.9
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
stdlib@go1.16.9
1.26.9
1
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.11
0.60.0
1.26.9
1
datadog/agent:6aad9994de6a7
golang.org/x/net@v0.33.0
stdlib@go1.21.11
0.60.0
1.26.9
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.15
0.60.0
1.26.9
1
datadog/operator:0.3.117f08a860090
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.2
0.60.0
1.26.9
1
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.21.4
0.60.0
1.26.9
1
datappeal/hive-metastore:lateste38c085a3567
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.4
0.60.0
1.26.9
1
datappeal/trino-exporter:latest325b91c2b09e
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.15
0.60.0
1.26.9
1
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.17.13
0.60.0
1.26.9
1
datasaker/dsk-container-agent:latest08b52999f67b
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.60.0
1.26.9
1
datasaker/dsk-k8s-agent:latest2542ee73be51
golang.org/x/net@v0.17.0
stdlib@go1.19.1
0.60.0
1.26.9
1
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.60.0
1.26.9
1
datasaker/dsk-node-agent:latest1b95913b6729
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
1
datasaker/dsk-process-agent:latest2f38720a637d
golang.org/x/net@v0.15.0
stdlib@go1.21.0
0.60.0
1.26.9
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
1
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
1
datawire/aes:3.11.195ec30b3c732
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.60.0
1.26.9
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.16.5
0.60.0
1.26.9
1
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
1
ddefrancesco/scoperunner-server:0.2.1daaac6657600
stdlib@go1.21.10
1.26.9
1
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.60.0
1.26.9
1
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
1
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
1
ddvk/rmfakecloud:latest2f5c45cbf0c5
golang.org/x/net@v0.38.0
stdlib@go1.26.3
0.60.0
1.26.9
1
deconzcommunity/deconz:2.29.2062de2362641
stdlib@go1.19.8
1.26.9
1
deconzcommunity/deconz:2.26.123c86008d73f
stdlib@go1.19.8
1.26.9
1
deepflowce/deepflow-init-grafana:v6.2.27cd16719eb57
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.3
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.