StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
glpieftechcombr-glpiVerified publisher2.12.01 of 5See more

glpi eftechcombr-glpi 2.12.0

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:12.3.2a02fe89cb597
stdlib@go1.24.6
1.26.9

Open the chart page →

3,796
egagenteginnovationsVerified publisher0.10.01 of 1See more

egagent eginnovations 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
eginnovations/agent:7.5.4e4dfe242fe9f
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,795
glideeinstackOfficialVerified publisher0.0.21 of 1See more

glide einstack 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9

Open the chart page →

1,993
elaraelaraVerified publisher0.5.21 of 1See more

elara elara 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/sergeyslonimsky/elara:0.5.2a410a7ed1ee8
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

220
elchi-discoveryelchi1.0.01 of 1See more

elchi-discovery elchi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jhonbrownn/elchi-discovery:v1.0.08f6551ecc98c
golang.org/x/net@v0.13.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

1,182
elchi-stackelchi2.0.44 of 10See more

elchi-stack elchi 2.0.4

4 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:12.2.074144189b384
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.26.9
otel/opentelemetry-collector-contrib:0.89.0995f17004231
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.60.0
1.26.9
victoriametrics/victoria-metrics:v1.93.577a9815d0640
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.60.0
1.26.9

Open the chart page →

17,674
navidromeemmas-chartsVerified publisher0.0.61 of 1See more

navidrome emmas-charts 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
deluan/navidrome:0.50.02cf4442b0099
golang.org/x/net@v0.18.0
stdlib@go1.21.0
0.60.0
1.26.9

Open the chart page →

2,899
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.26.9

Open the chart page →

37,005
eoapieoapiOfficialVerified publisher0.17.31 of 7See more

eoapi eoapi 0.17.3

1 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

4,551
nexus-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

nexus-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,393
error-pageserror-pagesOfficialVerified publisher4.2.51 of 1See more

error-pages error-pages 4.2.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:4.2.56d42b5d6e1a0
stdlib@go1.27.0
1.27.2

Open the chart page →

141
paraerudikaVerified publisher0.3.01 of 1See more

para erudika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
erudikaltd/para:latest_stablea6aba08c21fa
stdlib@go1.26.7
1.26.9

Open the chart page →

994
httpbingoestahnVerified publisher0.1.11 of 1See more

httpbingo estahn 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mccutchen/go-httpbin:v2.2.25994403ef75b
stdlib@go1.16.2
1.26.9

Open the chart page →

2,473
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

3,850
erigonethereum-helm-chartsVerified publisher2.0.21 of 2See more

erigon ethereum-helm-charts 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
erigontech/erigon:latest28ee51ce29ec
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,369
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
stdlib@go1.23.12
1.26.9

Open the chart page →

2,199
genesis-generatorethereum-helm-chartsVerified publisher0.2.31 of 2See more

genesis-generator ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
skylenet/ethereum-genesis-generator:latest210353ce7c89
stdlib@go1.17.13
1.26.9

Open the chart page →

4,548
ipfs-clusterethereum-helm-chartsVerified publisher0.1.143 of 3See more

ipfs-cluster ethereum-helm-charts 0.1.14

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ipfs/ipfs-cluster:latesta83266c524f1
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
ipfs/kubo:latestb293923d66e4
golang.org/x/net@v0.59.0
stdlib@go1.26.5
0.60.0
1.26.9
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

6,634
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
stdlib@go1.19.8
1.26.9

Open the chart page →

13,319
evccevccVerified publisher1.0.471 of 1See more

evcc evcc 1.0.47

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
evcc/evcc:0.300.8ddf2a25afce5
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

1,630
event-exporterevent-exporterVerified publisher0.1.171 of 1See more

event-exporter event-exporter 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubestar/event-exporter:latest656606941255
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

1,855
events-exporterevents-exporter0.0.41 of 1See more

events-exporter events-exporter 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

2,957
github-actions-runner-operatorevryfs-ossVerified publisher2.8.11 of 1See more

github-actions-runner-operator evryfs-oss 2.8.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
golang.org/x/net@v0.12.0
stdlib@go1.21.1
0.60.0
1.26.9

Open the chart page →

1,920
ext-postgres-operatorext-postgres-operatorVerified publisher3.0.01 of 1See more

ext-postgres-operator ext-postgres-operator 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/movetokube/postgres-operator:2.4.0def57d85a2da
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

814
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:latestbbd4e17f1ef8
stdlib@go1.24.5
1.26.9

Open the chart page →

4,944
vidcheckfactlyVerified publisher0.5.21 of 2See more

vidcheck factly 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
factly/vidcheck-server:0.12.087064eb0463c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.14.2
0.60.0
1.26.9

Open the chart page →

4,883
ecr-cleanupfairwinds-stableVerified publisher1.2.81 of 1See more

ecr-cleanup fairwinds-stable 1.2.8

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
danielfm/kube-ecr-cleanup-controller:0.1.1012485563b1d0
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

1,785
falco-operatorfalcosecurity0.3.11 of 1See more

falco-operator falcosecurity 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
falcosecurity/falco-operator:0.4.18a99fcc57a57
golang.org/x/net@v0.53.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

787
fastapi-microservice-appfast-api-microservice-app1.3.01 of 4See more

fastapi-microservice-app fast-api-microservice-app 1.3.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:7.01f995ad6fdb9
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

10,905
featurehubfeaturehub4.1.63 of 7See more

featurehub featurehub 4.1.6

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.26.9
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.26.9

Open the chart page →

11,057
federidfederidOfficialVerified publisher0.1.21 of 1See more

federid federid 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
federid/webhook:0.1.0fbfb7c6510a7
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

2,823
fencemasterfencemasterVerified publisher0.1.131 of 1See more

fencemaster fencemaster 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/rvbsalgado/fencemaster:1.0.0-rc.207056a6aae439
golang.org/x/net@v0.43.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

640
taigafermosit0.0.112 of 7See more

taiga fermosit 0.0.11

2 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
stdlib@go1.24.4
1.26.9
taigaio/taiga-protected:latestfd4568a97a59
stdlib@go1.24.4
1.26.9

Open the chart page →

10,160
ferriskeyferriskey0.9.01 of 3See more

ferriskey ferriskey 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

2,580
ai-gatewayferro-labsOfficialVerified publisher1.2.01 of 1See more

ai-gateway ferro-labs 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/ferro-labs/ai-gateway:1.2.0baa285ec0fc9
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

381
file-manager-serverfile-manager-server1.11.01 of 1See more

file-manager-server file-manager-server 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9

Open the chart page →

1,280
fission-corefission-chartsVerified publisher1.14.13 of 3See more

fission-core fission-charts 1.14.1

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
fission/fission-bundle:1.14.13fcfd8a0fa5d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.14
0.60.0
1.26.9
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.14
0.60.0
1.26.9
fission/reporter:1.14.104c6e06af175
stdlib@go1.15.14
1.26.9

Open the chart page →

10,386
openldapfluktuid0.1.11 of 2See more

openldap fluktuid 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.60.0
1.26.9

Open the chart page →

5,240
fluorite-chartfluorite-helmOfficialVerified publisher0.1.01 of 1See more

fluorite-chart fluorite-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/afcms/fluorite:master00f3a5219ac0
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

237
flyway-operatorflyway-operatorVerified publisher0.2.131 of 1See more

flyway-operator flyway-operator 0.2.13

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/davidkarlsen/flyway-operator:0.2.1366f60b461c0d
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,139
contentserverfoomoVerified publisher0.8.01 of 1See more

contentserver foomo 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
foomo/contentserver:1.21.28da4b33610c6
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

552
fqdn-controllerfqdn-controllerOfficialVerified publisher0.3.01 of 1See more

fqdn-controller fqdn-controller 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/konsole-is/fqdn-controller:0.3.08d5d41ab22aa
golang.org/x/net@v0.56.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

283
free5gcfree5gcVerified publisher0.1.312 of 12See more

free5gc free5gc 0.1.3

12 of the 12 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/mongodb:latestc8babafb7d15
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/udm:v3.4.32f68df062a50
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/upf:v3.4.3b6b362a39fdd
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

17,733
fsmfsmOfficialVerified publisher0.2.112 of 5See more

fsm fsm 0.2.11

2 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.60.0
1.26.9
flomesh/fsm-manager:0.2.1122f849c70b25
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.60.0
1.26.9

Open the chart page →

5,831
function-mesh-operatorfunction-mesh0.2.451 of 1See more

function-mesh-operator function-mesh 0.2.45

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
streamnative/function-mesh:v0.29.04176923db03c
golang.org/x/net@v0.56.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

479
adguard-homegabe565Verified publisher0.3.251 of 2See more

adguard-home gabe565 0.3.25

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.56c64a0b37f7b9
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,355
home-assistantgabe565Verified publisher0.17.01 of 1See more

home-assistant gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:latest3e6710a7ab2a
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

3,152
memosgabe565Verified publisher0.17.01 of 1See more

memos gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/usememos/memos:0.24.04723d86e6797
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

2,119
dexgabibbo974.0.41 of 1See more

dex gabibbo97 4.0.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

4,619
garage-uigarage-uiVerified publisher0.13.01 of 1See more

garage-ui garage-ui 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
noooste/garage-ui:v0.13.0a1444fa10585
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

218

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
golang.org/x/net@v0.8.0
stdlib@go1.19.1
0.60.0
1.26.9
1
deepflowce/deepflow-server:v6.2.21477e7334d13
golang.org/x/net@v0.2.0
stdlib@go1.18.10
0.60.0
1.26.9
1
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
1
defactops/defactops-ui:1.0.16825cdf9ba706
golang.org/x/net@v0.25.0
stdlib@go1.21.10
0.60.0
1.26.9
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.5
0.60.0
1.26.9
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.60.0
1.26.9
1
dellnoantechnp/cloudeye-exporter:v2.0.316873356c882d
stdlib@go1.19.6
1.26.9
1
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
1
deluan/navidrome:0.50.02cf4442b0099
golang.org/x/net@v0.18.0
stdlib@go1.21.0
0.60.0
1.26.9
1
deluan/navidrome:0.64.238dc2727bfcf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9
1
deluan/navidrome:0.61.29fa40b3d8dec
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
1
deluan/navidrome:0.41.1fc4d8b6ad9f9
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.60.0
1.26.9
1
denniswitt/yas3p:0.2.488a235619af6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
1
derailed/popeye:v0.21.363b2d2a8f674
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.60.0
1.26.9
1
devopsfaith/krakend:2.6.34c678c224f67
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.60.0
1.26.9
1
devopsfaith/krakend:2.7.09219cda867e2
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
1
devopstales/trivy-operator:2.575136aa7a26e
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.60.0
1.26.9
1
devsecurely/cview-issuer:0.0.4335675bd31bfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.60.0
1.26.9
1
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.7
0.60.0
1.26.9
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
golang.org/x/net@v0.35.0
stdlib@go1.22.12
0.60.0
1.26.9
1
dgraph/ratel:v25.0.34cae1ff95027
stdlib@go1.23.10
1.26.9
1
digitalocean/ceph_exporter:latest3ba058e9a48d
stdlib@go1.20
1.26.9
1
digitalocean/do-operator:v0.1.65e5deb4db76e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18.10
0.60.0
1.26.9
1
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
stdlib@go1.18.7
1.26.9
1
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
stdlib@go1.18.7
1.26.9
1
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.15.8
0.60.0
1.26.9
1
directus/directus:12.0.29c8470ea465c
stdlib@go1.23.12
1.26.9
1
directus/directus:11.1.0e3c8bb975350
stdlib@go1.20.7
1.26.9
1
distribution/distribution:3.1.1bca24727f400
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
1
distribution/distribution:2.8.3f84b2078238f
stdlib@go1.20.8
1.26.9
1
djjudas21/nova-exporter:0.0.10e9094580885c
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.60.0
1.26.9
1
djkormo/adcs-issuer:2.1.29f34e87e7586
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.60.0
1.26.9
1
dnsforge/xteve:latest4d9a685c8c28
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.16.2
0.60.0
1.26.9
1
dobtc/bitcoin:25.1a870f7cb1105
stdlib@go1.19.8
1.26.9
1
dockerdaemon0901/rolldice:v14e5bfe179c7e
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.60.0
1.26.9
1
documenso/documenso:v1.8.17f16a9449f18
stdlib@go1.20.12
1.26.9
1
dollarshaveclub/furan2:master14a257836529
golang.org/x/net@v0.0.0-20201002202402-0a1ea396d57c
stdlib@go1.17.2
0.60.0
1.26.9
1
dollarshaveclub/thermite:0.0.31663cbf25fcfe
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.1
0.60.0
1.26.9
1
don616/k8s-file-explorer-backend:v1.8.13e228fadb3a8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
donetick/donetick:v0.1.79a1cc21dd5a37
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.60.0
1.26.9
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
golang.org/x/net@v0.11.0
stdlib@go1.19.12
0.60.0
1.26.9
1
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9
1
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9
1
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
golang.org/x/net@v0.7.0
stdlib@go1.19.9
0.60.0
1.26.9
1
dongjiang1989/lxcfs-webhook:latestc1f19557bdcb
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9
1
dongjiang1989/node-metrics:latest3f1f266190bb
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
1
dongjiang1989/ns-node-affinity:latest451f7823723c
golang.org/x/net@v0.7.0
stdlib@go1.18.5
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.