StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
aws-calicoaws0.3.111 of 1See more

aws-calico aws 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

3,403
aws-node-termination-handleraws-node-termination-handler0.27.61 of 1See more

aws-node-termination-handler aws-node-termination-handler 0.27.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.25.69ad31fb4e5be
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

844
snapschedulerbackube-helm-chartsVerified publisher3.5.02 of 2See more

snapscheduler backube-helm-charts 3.5.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/backube/snapscheduler:3.5.035ac95c51780
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

2,109
yataibentomlVerified publisher1.1.131 of 1See more

yatai bentoml 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.60.0
1.26.9

Open the chart page →

2,537
yatai-deploymentbentomlVerified publisher1.1.211 of 2See more

yatai-deployment bentoml 1.1.21

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9

Open the chart page →

1,788
boundaryboundaryVerified publisher0.1.01 of 1See more

boundary boundary 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/boundary:0.21.037bf86488b74
golang.org/x/net@v0.47.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

2,073
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.19.12
1.26.9

Open the chart page →

70,796
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

2,531
cadvisorcadvisorVerified publisher0.1.151 of 1See more

cadvisor cadvisor 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.60.0
1.26.9

Open the chart page →

2,339
geoservercloudcamptocamp23.0.17 of 7See more

geoservercloud camptocamp2 3.0.1

7 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
stdlib@go1.26.5
1.26.9
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
stdlib@go1.26.5
1.26.9
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
stdlib@go1.26.5
1.26.9
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
stdlib@go1.26.5
1.26.9
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
stdlib@go1.26.5
1.26.9
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
stdlib@go1.26.5
1.26.9
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
stdlib@go1.26.5
1.26.9

Open the chart page →

15,508
version-checkercert-managerVerified publisher0.11.01 of 1See more

version-checker cert-manager 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.11.0eae9a374d22f
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

500
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.60.0
1.26.9

Open the chart page →

11,442
popeyechristianhuthVerified publisher2.4.31 of 1See more

popeye christianhuth 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,875
sbom-operatorckotzbauerVerified publisher0.47.01 of 1See more

sbom-operator ckotzbauer 0.47.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/sbom-operator:0.46.05730dd185682
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

128
clabernetesclabernetesOfficialVerified publisher0.9.01 of 1See more

clabernetes clabernetes 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/clabernetes/clabernetes/clabernetes-manager:0.9.00758e9e032c0
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

217
hellocloudechoVerified publisher0.1.21 of 1See more

hello cloudecho 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.26.9

Open the chart page →

2,737
cloudflare-exportercloudflare-exporter0.2.31 of 1See more

cloudflare-exporter cloudflare-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/lablabs/cloudflare_exporter:0.0.1670d74ec46602
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,282
ghostcloudpirates-ghostVerified publisher0.20.293 of 3See more

ghost cloudpirates-ghost 0.20.29

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/ghost:6.69.055131b90d48c
stdlib@go1.24.6
1.26.9
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.26.9
library/mariadb:13.0.2f1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

8,357
cloudprobercloudproberOfficialVerified publisher1.14.281 of 1See more

cloudprober cloudprober 1.14.28

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cloudprober/cloudprober:v0.14.60902d8adf871
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

178
openstack-manila-csicloud-provider-openstack2.36.35 of 5See more

openstack-manila-csi cloud-provider-openstack 2.36.3

5 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

5,752
dumpscriptcloudscriptVerified publisher1.11.01 of 1See more

dumpscript cloudscript 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.45-alpine-edge99732098a0f3
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

145
clowardenclowarden0.2.32 of 4See more

clowarden clowarden 0.2.3

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.26.9
ghcr.io/cncf/clowarden/dbmigrator:v0.2.3c022fd42de45
stdlib@go1.25.3
1.26.9

Open the chart page →

7,158
cluster-manager-servercluster-manager-server1.8.01 of 1See more

cluster-manager-server cluster-manager-server 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

1,180
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
golang.org/x/net@v0.7.0
stdlib@go1.18
0.60.0
1.26.9

Open the chart page →

2,676
coder-observabilitycoder-observabilityVerified publisher0.7.513 of 21See more

coder-observability coder-observability 0.7.5

13 of the 21 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
burningalchemist/sql_exporter:latest6c554722facc
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.60.0
1.26.9
grafana/grafana:10.4.19a9043254ba16
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9
grafana/loki:3.1.0d947e68a84d9
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
grafana/loki-canary:3.1.039baf6d67f85
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.93.00ccb22ca9f3f
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.33.19e082985f56f
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.13.2508729e0e2d1
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheuscommunity/postgres-exporter:latestac5ec343104f
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

16,087
convertigoconvertigoOfficialVerified publisher8.4.52 of 5See more

convertigo convertigo 8.4.5

2 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
timescale/timescaledb:latest-pg166f139d560429
stdlib@go1.26.2
1.26.9

Open the chart page →

17,649
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.60.0
1.26.9

Open the chart page →

4,195
cosmocosmo-platformOfficialVerified publisher0.21.06 of 10See more

cosmo cosmo-platform 0.21.0

6 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.26.9
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
golang.org/x/net@v0.26.0
stdlib@go1.23.6
0.60.0
1.26.9
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
stdlib@go1.20.7
1.26.9

Open the chart page →

35,008
ocularcrashoverride-helm-chartsVerified publisher0.5.21 of 1See more

ocular crashoverride-helm-charts 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/ocular-controller:v0.4.122060cf61e0e
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

166
crossviewcrossviewOfficialVerified publisher4.6.02 of 2See more

crossview crossview 4.6.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:latest5a5a84b19854
stdlib@go1.24.6
1.26.9
ghcr.io/crossplane-contrib/crossview:v4.6.07b54c5ba60e5
golang.org/x/net@v0.57.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

2,177
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
golang.org/x/net@v0.25.0
stdlib@go1.21.13
0.60.0
1.26.9

Open the chart page →

1,857
db-operatordb-operator-ng3.16.01 of 1See more

db-operator db-operator-ng 3.16.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/db-operator/db-operator:2.42.0fb6531d509b9
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

153
deepflowdeepflow6.2.2015 of 8See more

deepflow deepflow 6.2.201

5 of the 8 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.26.9
deepflowce/deepflow-init-grafana:v6.2.27cd16719eb57
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.3
0.60.0
1.26.9
deepflowce/deepflow-server:v6.2.21477e7334d13
golang.org/x/net@v0.2.0
stdlib@go1.18.10
0.60.0
1.26.9
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.26.9
grafana/grafana:9.3.6e5a9655dabef
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

20,731
defensia-agentdefensia-agentOfficialVerified publisher0.6.01 of 1See more

defensia-agent defensia-agent 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/defensia/agent:1.4.669857f54bce8d
golang.org/x/net@v0.47.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

232
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
golang.org/x/net@v0.17.0
stdlib@go1.21.10
0.60.0
1.26.9

Open the chart page →

4,363
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9

Open the chart page →

2,224
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

3,594
prometheus-locust-exporterdeliveryheroVerified publisher1.2.31 of 1See more

prometheus-locust-exporter deliveryhero 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.26.9

Open the chart page →

2,259
distrdistrOfficialVerified publisher4.3.03 of 4See more

distr distr 4.3.0

3 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/loki:3.7.81107dd5274e0
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
rclone/rclone:1.75.145401ad7410d
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/distr-sh/distr-ce:4.3.01d3200f72f99
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

727
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.26.9

Open the chart page →

4,976
navidromedjjudas21Verified publisher6.8.61 of 1See more

navidrome djjudas21 6.8.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
deluan/navidrome:0.64.238dc2727bfcf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

209
bscdysnixVerified publisher0.6.592 of 4See more

bsc dysnix 0.6.59

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine7002c0b3cec5
stdlib@go1.26.6
1.26.9
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

2,519
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

3,420
postgres-pgdump-backupeugen0.7.61 of 1See more

postgres-pgdump-backup eugen 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.26.9

Open the chart page →

700
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

12,736
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

15,381
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

14,834
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.26.9

Open the chart page →

6,414
fleetfleetVerified publisher0.16.21 of 1See more

fleet fleet 0.16.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/fleet:v0.16.231f39589e1f8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

145
flyte-binaryflyte2.0.511 of 4See more

flyte-binary flyte 2.0.51

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9

Open the chart page →

5,130

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
goharbor/harbor-registryctl:devb8fa35c3d36e
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.60.0
1.26.9
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.60.0
1.26.9
1
goharbor/registry-photon:v2.11.15645d459af2b
stdlib@go1.22.6
1.26.9
1
goharbor/registry-photon:v2.14.36533fc396cbc
stdlib@go1.24.13
1.26.9
1
goharbor/registry-photon:v2.9.08a26e8cb7862
stdlib@go1.20.7
1.26.9
1
goharbor/registry-photon:devc34795d74b99
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
1
goharbor/registry-photon:v2.15.4dc0cb388a644
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
golang.org/x/net@v0.28.0
stdlib@go1.25.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.15.4813ca81b4a4e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.18.3
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:devd051158f1fd0
golang.org/x/net@v0.55.0
stdlib@go1.26.4-X:jsonv2
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.60.0
1.26.9
1
golift/unifi-poller:v2.9.5486a63339969
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
golift/unifi-poller:v2.9.2585a29a06d05
golang.org/x/net@v0.15.0
stdlib@go1.21.0
0.60.0
1.26.9
1
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.7
0.60.0
1.26.9
1
gomods/athens:v0.17.10f61d1e62359
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
1
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.13.4
0.60.0
1.26.9
1
gomods/athens:v0.19.2e1abe3005673
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
goofball222/pritunl:1.32.3602.807bf26032dfce
golang.org/x/net@v0.7.0
stdlib@go1.18.7
0.60.0
1.26.9
1
google/cloud-sdk:slimc70885ba9f04
stdlib@go1.26.6
1.26.9
1
google/cloud-sdk:alpineef78619c8239
stdlib@go1.26.6
1.26.9
1
gophish/gophish:0.12.18a57cd171999
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.15.2
0.60.0
1.26.9
1
gotenberg/gotenberg:8-chromium0d28ae9a9644
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
gotenberg/gotenberg:8.30206a6c708fc6
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.60.0
1.26.9
1
gotenberg/gotenberg:8.7.0437b9cd3c351
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
1
gotenberg/gotenberg:8.3467097317623a
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.60.0
1.26.9
1
gotify/server:2.9.1a3af47067ce6
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
1
gotify/server-arm7:2.0.23d91e302ad1d0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.60.0
1.26.9
1
gotson/komga:1.27.19cf102f5fb78
stdlib@go1.17.8
1.26.9
1
gotson/komga:1.22.0ba892ab3e082
stdlib@go1.17.8
1.26.9
1
gotson/komga:1.28.1d8f772dce7b3
stdlib@go1.26.7
1.26.9
1
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.60.0
1.26.9
1
gradiant/packetrusher:2b26573e9b46dc76af4
golang.org/x/net@v0.38.0
stdlib@go1.21.3
0.60.0
1.26.9
1
grafana/agent:v0.44.23364714a2f64
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.60.0
1.26.9
1
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16
0.60.0
1.26.9
1
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.60.0
1.26.9
1
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9
1
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/net@v0.31.0
stdlib@go1.22.7
0.60.0
1.26.9
1
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.60.0
1.26.9
1
grafana/alloy:v1.18.10f4434c92b3e
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
1
grafana/alloy:v1.20.12aa2099af76c
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
grafana/alloy:v1.18.0491b0578c049
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
1
grafana/alloy:v1.16.384b76d56c594
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
1
grafana/alloy:v1.11.38c7256f412fe
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
1
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.