StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
javascriptweeklyjavascriptweekly2.1.01 of 1See more

javascriptweekly javascriptweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.60.0
1.26.9

Open the chart page →

2,112
sql-exporterjdstoneVerified publisher0.2.11 of 1See more

sql-exporter jdstone 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
burningalchemist/sql_exporter:0.16.0b8e4757c7def
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,448
newtjeffrescVerified publisher0.2.11 of 1See more

newt jeffresc 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
fosrl/newt:1.10.4ccd2b0e9a049
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,510
jenkinsjenkins-automation-tool0.1.01 of 1See more

jenkins jenkins-automation-tool 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
jenkinsjenkins-automation-tool-by-helm0.1.01 of 1See more

jenkins jenkins-automation-tool-by-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
jenkinsjenkins-chartVerified publisher0.1.01 of 1See more

jenkins jenkins-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
athens-proxyjenkins-x0.2.21 of 2See more

athens-proxy jenkins-x 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

1,824
jx-app-athensjenkins-x0.0.181 of 1See more

jx-app-athens jenkins-x 0.0.18

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.13.4
0.60.0
1.26.9

Open the chart page →

5,552
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
golang.org/x/net@v0.33.0
stdlib@go1.21.11
0.60.0
1.26.9

Open the chart page →

4,978
jx-app-flaggerjenkins-x0.0.52 of 2See more

jx-app-flagger jenkins-x 0.0.5

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:6.5.1befcd84da2c1
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9
weaveworks/flagger:1.0.0-rc.5174307de1b36
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.2
0.60.0
1.26.9

Open the chart page →

8,607
jx-app-jenkinsjenkins-x0.0.151 of 2See more

jx-app-jenkins jenkins-x 0.0.15

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
knative-servingjenkins-x0.19.124 of 4See more

knative-serving jenkins-x 0.19.12

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned1e3db4f2eeed
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinneddb6ceff2aab4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedb2cd45b8a8a4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedd27b4495ccc3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.60.0
1.26.9

Open the chart page →

14,652
jetspotterjetspotter1.49.01 of 1See more

jetspotter jetspotter 1.49.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/vvanouytsel/jetspotter:1.49.0d6f9149a36db
golang.org/x/net@v0.39.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,136
ingress-nginxjfrog4.5.22 of 2See more

ingress-nginx jfrog 4.5.2

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

5,483
vaultjfrog0.25.02 of 2See more

vault jfrog 0.25.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/vault:1.14.0b2177a8bfe85
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
hashicorp/vault-k8s:1.2.14500e988b7ce
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.60.0
1.26.9

Open the chart page →

5,470
kafka-offset-lag-for-prometheusjhidalgo3-githubVerified publisher2.3.01 of 1See more

kafka-offset-lag-for-prometheus jhidalgo3-github 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/net@v0.1.0
stdlib@go1.17.13
0.60.0
1.26.9

Open the chart page →

2,358
missing-container-metricsjimdo-missing-container-metrics0.5.01 of 1See more

missing-container-metrics jimdo-missing-container-metrics 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

3,644
cloudflare-tunneljmmaloney40.1.31 of 1See more

cloudflare-tunnel jmmaloney4 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2022.1.361f608cd1123
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

3,746
ipfsjmmaloney40.9.231 of 1See more

ipfs jmmaloney4 0.9.23

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.27.0bfce363b878b
golang.org/x/net@v0.21.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

2,135
job-manager-syncerjob-manager-syncer1.27.01 of 1See more

job-manager-syncer job-manager-syncer 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-syncer:1.27.086957bbeeff5
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

944
job-pod-reaperjob-pod-reaper0.14.01 of 1See more

job-pod-reaper job-pod-reaper 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/ohiosupercomputercenter/job-pod-reaper:v0.14.0775449888968
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

340
haven-complinacy-dashboardjolle-devVerified publisher1.0.01 of 2See more

haven-complinacy-dashboard jolle-dev 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

6,270
BNSdeployjongseo220.1.01 of 8See more

BNSdeploy jongseo22 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

218
cloudnative-pgjouveVerified publisher0.27.01 of 1See more

cloudnative-pg jouve 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.28.034198e85b6e6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,085
corednsjouveVerified publisher1.45.01 of 1See more

coredns jouve 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
golang.org/x/net@v0.45.0
stdlib@go1.25.2
0.60.0
1.26.9

Open the chart page →

1,408
distributionjouveVerified publisher0.2.31 of 1See more

distribution jouve 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
distribution/distribution:3.1.1bca24727f400
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,263
etcd-defragjouveVerified publisher0.1.11 of 1See more

etcd-defrag jouve 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/ahrtr/etcd-defrag:v0.45.0b2a97f7fac6e
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

243
api-key-managerjtektVerified publisher0.3.02 of 4See more

api-key-manager jtekt 0.3.0

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:172d2b8998d310
stdlib@go1.24.6
1.26.9
public.ecr.aws/jtekt-corporation/api-key-manager-api:v0.1.175a48d987e0f
stdlib@go1.20.7
1.26.9

Open the chart page →

7,868
image-storage-servicejtektVerified publisher0.5.11 of 4See more

image-storage-service jtekt 0.5.1

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.60.0
1.26.9

Open the chart page →

25,612
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

19,122
firstchartjuanjmerono0.2.01 of 1See more

firstchart juanjmerono 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17
0.60.0
1.26.9

Open the chart page →

2,558
daily-restartjuniorjpdj0.1.721 of 1See more

daily-restart juniorjpdj 0.1.72

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/juniorjpdj/containers/openssl-kubectl:1.36.1-r5136348264b41
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

730
mumbledjjuniorjpdj0.1.2052 of 2See more

mumbledj juniorjpdj 0.1.205

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/juniorjpdj/containers/openssl-kubectl:1.36.1-r5136348264b41
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/juniorjpdj/mumbledj:latestd56a7a042e13
stdlib@go1.27.1
1.27.2

Open the chart page →

1,395
alertmanager-irc-relayjuppi880.0.11 of 1See more

alertmanager-irc-relay juppi88 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
maldridge/alertmanager-irc-relay:v0.4.1391de2b76128
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

2,785
nginx-gateway-fabricjupyter-jscVerified publisher2.4.11 of 1See more

nginx-gateway-fabric jupyter-jsc 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/nginx/nginx-gateway-fabric:2.4.180f3a0a51af5
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

762
jupyter-notebook-validator-operatorjupyter-notebook-validatorVerified publisher1.0.101 of 1See more

jupyter-notebook-validator-operator jupyter-notebook-validator 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

218
k10appk10app0.2.11 of 11See more

k10app k10app 0.2.1

1 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k10app/businit:latest94c9a3e799c2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

12,074
multusk3s4.0.201+upv4.0.2-build20240208012 of 2See more

multus k3s 4.0.201+upv4.0.2-build2024020801

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/hardened-cni-plugins:v1.4.0-build202401222581c5490bab
stdlib@go1.20.7
1.26.9
rancher/hardened-multus-cni:v4.0.2-build202402087d0f41b72eb7
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.60.0
1.26.9

Open the chart page →

2,891
snapshot-controllerk3s1.6.1+up1.6.01 of 1See more

snapshot-controller k3s 1.6.1+up1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/mirrored-sig-storage-snapshot-controller:v6.1.0934863015367
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.60.0
1.26.9

Open the chart page →

2,397
snapshot-validation-webhookk3s1.6.1+up1.6.01 of 1See more

snapshot-validation-webhook k3s 1.6.1+up1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/mirrored-sig-storage-snapshot-validation-webhook:v6.1.0deac027820ae
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.60.0
1.26.9

Open the chart page →

2,397
traefikk3s20.3.1+up20.3.01 of 1See more

traefik k3s 20.3.1+up20.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/mirrored-library-traefik:2.9.40842af6afcdf
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.2
0.60.0
1.26.9

Open the chart page →

4,248
k8-ldap-configmapk8-ldap-configmap0.16.01 of 1See more

k8-ldap-configmap k8-ldap-configmap 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/ohiosupercomputercenter/k8-ldap-configmap:v0.16.040d0b67afd77
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

381
k8-namespace-reaperk8-namespace-reaper0.11.01 of 1See more

k8-namespace-reaper k8-namespace-reaper 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/ohiosupercomputercenter/k8-namespace-reaper:v0.11.0ead1f817e8c2
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

340
k8quk8qu1.4.01 of 1See more

k8qu k8qu 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/gijsvandulmen/k8qu:1.4e897b18db13d
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.60.0
1.26.9

Open the chart page →

1,111
k8s-aibomk8s-aibomVerified publisher1.5.11 of 1See more

k8s-aibom k8s-aibom 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/googlecloudplatform/k8s-aibomdigest-pinned7b02731563a5
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

253
k8s-ai-srek8s-ai-sreVerified publisher3.1.21 of 1See more

k8s-ai-sre k8s-ai-sre 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mohankrishna999/k8s-ai-agent:3.1.27f980f8c650c
golang.org/x/net@v0.57.0
stdlib@go1.26.5-X:jsonv2
0.60.0
1.26.9

Open the chart page →

974
clonarrk8s-chartsVerified publisher0.10.11 of 1See more

clonarr k8s-charts 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/prophetse7en/clonarr:latest9400d298b37a
stdlib@go1.26.4
1.26.9

Open the chart page →

762
deltabadgerk8s-chartsVerified publisher2.0.01 of 1See more

deltabadger k8s-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
stdlib@go1.24.4
1.26.9

Open the chart page →

7,118
palworld-serverk8s-chartsVerified publisher1.2.11 of 1See more

palworld-server k8s-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
stdlib@go1.26.3
1.26.9

Open the chart page →

4,195
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
stdlib@go1.18.1
1.26.9

Open the chart page →

66,013

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
stdlib@go1.24.6
1.26.9
4
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.60.0
1.26.9
4
cockroachdb/cockroach-self-signer-cert:1.10b0fcc6c8147a
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.60.0
1.26.9
4
decisionrules/server:latestbb3a93224b5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
4
grafana/loki:3.6.73c8fd3570dd9
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
4
hyperledger/fabric-ca:latesta70b6ba64a08
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
4
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
4
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
4
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
4
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9
4
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.26.9
4
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
4
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
4
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.26.9
4
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.26.9
4
library/mariadb:13.0.2:latestd4fdec0510ad
stdlib@go1.26.7
1.26.9
4
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
4
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.26.9
4
library/nats:2.15.0-alpineac8f88a6494b
stdlib@go1.27.1
1.27.2
4
library/postgres:134689940c6838
stdlib@go1.24.6
1.26.9
4
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.26.9
4
linuxserver/plex:1.43.4:latest06e07af2851e
stdlib@go1.26.7
1.26.9
4
migrate/migrate:latest76cc2074cb66
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
4
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.60.0
1.26.9
4
natsio/nats-box:0.19.7ffce8bd10338
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
4
natsio/nats-server-config-reloader:0.21.110ff229eaf52
stdlib@go1.25.5
1.26.9
4
natsio/prometheus-nats-exporter:0.20.2:latestc623b608e148
stdlib@go1.26.6
1.26.9
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.26.9
4
otel/opentelemetry-collector-contrib:0.162.0:latest39923a8e431b
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
4
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
4
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
golang.org/x/net@v0.18.0
stdlib@go1.21.7
0.60.0
1.26.9
4
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
golang.org/x/net@v0.30.0
stdlib@go1.23.5
0.60.0
1.26.9
4
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
4
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
4
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
4
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
4
ghcr.io/kubedb/kubedb-provisioner:v0.66.0e7041c3b41e7
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9
4
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0e0f4431c4704
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9
4
ghcr.io/kubestash/kubestash:v0.29.00686b2a40280
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9
4
ghcr.io/kubevault/vault-operator:v0.25.0c8e042b5cee8
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.60.0
1.26.9
4
ghcr.io/sigstore/scaffolding/createtree:v0.7.334c845ced03d8
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
4
ghcr.io/stakater/reloader:v1.4.22def2480040ad
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
4
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
golang.org/x/net@v0.35.0
stdlib@go1.22.4
0.60.0
1.26.9
4
quay.io/argoproj/argocd:v3.5.449dff79439bb
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9
4
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
4
quay.io/ceems/ceems:v0.16.14633125698c3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
4
quay.io/jcmoraisjr/haproxy-ingress:v0.16.242bcf39842db
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.