StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
libredb-studiolibredb-studioOfficialVerified publisher0.1.831 of 1See more

libredb-studio libredb-studio 0.1.83

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.18.21b4051ca999a
stdlib@go1.24.4
1.26.9

Open the chart page →

1,457
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestf1bc435659b9
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

4,063
vclustermainVerified publisher0.17.07 of 10See more

vcluster main 0.17.0

7 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.60.0
1.26.9
registry.k8s.io/etcd:3.6.4-0e36c08168342
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.60.0
1.26.9
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

17,106
stannatsVerified publisher0.13.01 of 2See more

stan nats 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
natsio/prometheus-nats-exporter:latestc623b608e148
stdlib@go1.26.6
1.26.9

Open the chart page →

340
headplanenbcloudVerified publisher0.1.23 of 4See more

headplane nbcloud 0.1.2

3 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9
headscale/headscale:0.25.1a7a8ae9616bb
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9
ghcr.io/tale/headplane:0.5.50dbc52cffc19
stdlib@go1.23.4
1.26.9

Open the chart page →

10,302
netris-operatornetrisai3.0.21 of 2See more

netris-operator netrisai 3.0.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
netrisai/netris-operator:v4.0.244f60aa0d898
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

2,428
node-local-dnsnode-local-dns2.4.01 of 1See more

node-local-dns node-local-dns 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/net@v0.17.0
stdlib@go1.21.7
0.60.0
1.26.9

Open the chart page →

3,465
nri-memtierdnri-pluginsOfficialVerified publisher0.14.01 of 1See more

nri-memtierd nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memtierd:v0.14.09138314e12ba
stdlib@go1.26.0
1.26.9

Open the chart page →

582
goldpingerokgoloveVerified publisher6.2.01 of 1See more

goldpinger okgolove 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/net@v0.17.0
stdlib@go1.21.9
0.60.0
1.26.9

Open the chart page →

1,347
geonodeone-acre-fundVerified publisher0.1.161 of 7See more

geonode one-acre-fund 0.1.16

1 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,810
open5gsopen5gsVerified publisher2.3.83 of 5See more

open5gs open5gs 2.3.8

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/mongodb:latestad05bb9a19fa
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
stdlib@go1.15.1
1.26.9
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.60.0
1.26.9

Open the chart page →

12,843
psmdb-operatorpercona1.23.21 of 1See more

psmdb-operator percona 1.23.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
percona/percona-server-mongodb-operator:1.23.178c87b933e18
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

263
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/net@v0.17.0
stdlib@go1.20.7
0.60.0
1.26.9

Open the chart page →

9,958
capsuleprojectcapsuleOfficialVerified publisher0.14.62 of 2See more

capsule projectcapsule 0.14.6

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

2,072
prometheus-consul-exporterprometheus-communityVerified publisher1.1.11 of 1See more

prometheus-consul-exporter prometheus-community 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/consul-exporter:v0.13.04e4cfd809e96
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,326
prometheus-json-exporterprometheus-communityOfficialVerified publisher0.20.11 of 1See more

prometheus-json-exporter prometheus-community 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

1,252
prometheus-nginx-exporterprometheus-communityVerified publisher1.23.11 of 1See more

prometheus-nginx-exporter prometheus-community 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
nginx/nginx-prometheus-exporter:1.5.385666e7fde7e
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

243
prometheus-smartctl-exporterprometheus-communityVerified publisher0.17.11 of 1See more

prometheus-smartctl-exporter prometheus-community 0.17.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
golang.org/x/net@v0.35.0
stdlib@go1.23.7
0.60.0
1.26.9

Open the chart page →

1,803
prometheus-statsd-exporterprometheus-communityVerified publisher1.0.01 of 1See more

prometheus-statsd-exporter prometheus-community 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,326
proxmox-cloud-controller-managerproxmox-ccm0.2.321 of 1See more

proxmox-cloud-controller-manager proxmox-ccm 0.2.32

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-cloud-controller-manager:v0.16.1474dbfd3be5c
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

205
pvc-autoresizerpvc-autoresizerVerified publisher0.20.11 of 1See more

pvc-autoresizer pvc-autoresizer 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/topolvm/pvc-autoresizer:0.21.2d7885d57f6f9
golang.org/x/net@v0.56.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

214
rke2-multusrke2-charts3.7.1-build20210416011 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.60.0

Open the chart page →

4,738
popeyeself-hosters-by-nightVerified publisher0.6.11 of 1See more

popeye self-hosters-by-night 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,952
argo-watchershini4iVerified publisher1.4.11 of 1See more

argo-watcher shini4i 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/shini4i/argo-watcher:v1.4.20faab179997f
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

205
fulciosigstoreVerified publisher2.11.45 of 6See more

fulcio sigstore 2.11.4

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/sigstore/fulcio:v1.9.02de0226c5f82
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/sigstore/scaffolding/createcertsdigest-pinned4d64dac937e2
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.33e591f98e3899
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
ghcr.io/sigstore/scaffolding/createtree:v0.7.334c845ced03d8
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3324293fa1ed50
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

5,317
policy-controllersigstoreVerified publisher0.10.81 of 2See more

policy-controller sigstore 0.10.8

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/sigstore/policy-controller/policy-controllerdigest-pinned0bcd60beb93f
golang.org/x/net@v0.39.0
stdlib@go1.24.7
0.60.0
1.26.9

Open the chart page →

1,432
pubsubplus-hasolaceVerified publisher3.10.01 of 1See more

pubsubplus-ha solace 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
solace/solace-pubsub-standard:latest3c8a8b7fdcae
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

491
sops-secrets-operatorsops-secrets-operatorVerified publisher0.28.11 of 1See more

sops-secrets-operator sops-secrets-operator 0.28.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,345
steampipe-powerpipe-kubernetessteampipe-powerpipe-kubernetesVerified publisher0.13.12 of 2See more

steampipe-powerpipe-kubernetes steampipe-powerpipe-kubernetes 0.13.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.60.0
1.26.9
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

6,976
superstreamsuperstreamOfficialVerified publisher0.9.623 of 3See more

superstream superstream 0.9.62

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/nats:2.10.25-alpine3290c829aa05
stdlib@go1.23.5
1.26.9
natsio/nats-server-config-reloader:0.16.1bf97e5e9b9d2
stdlib@go1.23.3
1.26.9
natsio/prometheus-nats-exporter:0.16.054b0d7ff058e
stdlib@go1.23.4
1.26.9

Open the chart page →

5,084
topolvmtopolvmVerified publisher17.3.01 of 1See more

topolvm topolvm 17.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.42.0719ab11d974a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,583
trivy-operator-polr-adaptertrivy-operator-polr-adapterVerified publisher0.11.51 of 1See more

trivy-operator-polr-adapter trivy-operator-polr-adapter 0.11.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/fjogeleit/trivy-operator-polr-adapter:0.11.537029b4d464f
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

327
uffizzi-appuffizzi-app1.3.08 of 14See more

uffizzi-app uffizzi-app 1.3.0

8 of the 14 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
stdlib@go1.20.14
0.60.0
1.26.9
uffizzi/uffizzi-cluster-operator:v1.4.514e528bbd926
golang.org/x/net@v0.8.0
stdlib@go1.19.13
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

26,473
valdvald1.8.04 of 5See more

vald vald 1.8.0

4 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
vdaas/vald-agent-ngt:v1.8.032e3695fe585
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
vdaas/vald-discoverer-k8s:v1.8.0f6495f38ae92
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
vdaas/vald-lb-gateway:v1.8.061009e319a9a
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
vdaas/vald-manager-index:v1.8.0ab881d2262d8
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,088
vault-secrets-webhookvault-secrets-webhookVerified publisher1.23.11 of 1See more

vault-secrets-webhook vault-secrets-webhook 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-secrets-webhook:v1.23.198baf045a1c9
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

851
athens-proxyvolker-raschekVerified publisher2.0.31 of 1See more

athens-proxy volker-raschek 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gomods/athens:v0.17.10f61d1e62359
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

2,788
wg-easywg-easyVerified publisher0.1.61 of 1See more

wg-easy wg-easy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:150e7bc9d34e86
golang.org/x/net@v0.44.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,287
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

15,004
nfs-server-provisionerwso21.1.01 of 1See more

nfs-server-provisioner wso2 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.60.0
1.26.9

Open the chart page →

4,103
yunikornyunikornVerified publisher1.10.03 of 3See more

yunikorn yunikorn 1.10.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
apache/yunikorn:scheduler-1.10.049fc54894fdf
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
apache/yunikorn:web-1.10.090e6a62a578a
stdlib@go1.26.7
1.26.9
apache/yunikorn:admission-1.10.095c6b951f38a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

581
matrixzekker6Verified publisher3.32.01 of 4See more

matrix zekker6 3.32.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.162.06b84a7bbac36
stdlib@go1.24.4
1.26.9

Open the chart page →

6,175
eshoponabpabp-charts1.0.02 of 15See more

eshoponabp abp-charts 1.0.0

2 of the 15 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:4.2699d652ed674
stdlib@go1.18.2
1.26.9
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.26.9

Open the chart page →

24,186
moon2aerokube2.8.23 of 3See more

moon2 aerokube 2.8.2

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/aerokube/moon:2.8.2072f3c5592dc
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/aerokube/moon-conf:2.8.235c465ab25d8
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/aerokube/moon-ui:2.8.2f374d0b9953b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

603
microgatewayairlock-microgatewayOfficialVerified publisher5.2.01 of 1See more

microgateway airlock-microgateway 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/airlock/microgateway-operatordigest-pinned48518d704307
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

201
alerta-webalerta-webVerified publisher0.1.121 of 2See more

alerta-web alerta-web 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.2.0-debian-11-r113e65a6b89e38
stdlib@go1.18.2
1.26.9

Open the chart page →

4,797
pod-gatewayangelnu7.1.11 of 2See more

pod-gateway angelnu 7.1.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/angelnu/gateway-admision-controller:v3.12.06f6ab596afd5
golang.org/x/net@v0.30.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,859
tt-rssangelnu7.0.01 of 2See more

tt-rss angelnu 7.0.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/angelnu/tt-rss:2.0.100809fb02162f151
stdlib@go1.26.7
1.26.9

Open the chart page →

975
ansible-semaphoreansible-semaphore0.1.01 of 1See more

ansible-semaphore ansible-semaphore 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.26.9

Open the chart page →

5,085
aperture-controlleraperture2.34.04 of 5See more

aperture-controller aperture 2.34.0

4 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
fluxninja/aperture-operator:2.34.0356d7aa86632
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.26.9
quay.io/prometheus/prometheus:v2.33.591100b06e86d
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

7,631
k8upappuio2.0.51 of 1See more

k8up appuio 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.60.0
1.26.9

Open the chart page →

4,367

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.26.9
1
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.17.3
0.60.0
1.26.9
1
jaegertracing/all-in-one:1.53.060e65bfffe1f
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
jaegertracing/all-in-one:1.42.07d32a4eddec7
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
1
jaegertracing/all-in-one:1.22.0ca6b73330616
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15.8
0.60.0
1.26.9
1
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.60.0
1.26.9
1
jaegertracing/all-in-one:1.55f6b5d09073f1
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.60.0
1.26.9
1
jaegertracing/jaeger:2.21.03d0ac795ff98
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
jaegertracing/jaeger:2.20.046a886260e04
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
1
jaegertracing/jaeger:2.9.0e128b9adbb29
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.60.0
1.26.9
1
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
1
jaegertracing/jaeger-operator:1.61.03f036ec60e61
golang.org/x/net@v0.29.0
stdlib@go1.22.3
0.60.0
1.26.9
1
jaegertracing/jaeger-query:1.41.0b636f0f464bc
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
1
jakuboskera/todo-operator:v0.1.0a305b8ce5bff
golang.org/x/net@v0.47.0
stdlib@go1.25.3
0.60.0
1.26.9
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/net@v0.29.0
stdlib@go1.22.8
0.60.0
1.26.9
1
jamesread/olivetin:3000.19.0af9d7c4db6dc
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
1
jamesread/olivetin:3000.20.0f3066e207efd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
jdschulze/restinthemiddle:v2.3.13fde2dfbcacc2
stdlib@go1.27.1
1.27.2
1
jdvalencia422/observabilitysec:latesta80b6e47a7b8
stdlib@go1.18.4
1.26.9
1
jeboehm/mailserver-filter:5.0.92e756949e537d
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
1
jeboehm/mailserver-mta:5.0.925fb2f31c940d
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.60.0
1.26.9
1
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.60.0
1.26.9
1
jhaals/yopass:11.17.026873480863b
stdlib@go1.20.5
1.26.9
1
jhaals/yopass:11.15.16bca8d5a4914
stdlib@go1.20.5
1.26.9
1
jhaals/yopass:14.10.06c33d9c813f7
stdlib@go1.27.1
1.27.2
1
jhaals/yopass:12.5.0916a1cf45d36
stdlib@go1.25.5
1.26.9
1
jhaals/yopass:14.9.0934e4f2c016f
stdlib@go1.27.0
1.27.2
1
jhaals/yopass:11.4.69516e3b3e88c
stdlib@go1.19.1
1.26.9
1
jhaals/yopass:12.4.0b64a1a8ace1b
stdlib@go1.25.3
1.26.9
1
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/net@v0.1.0
stdlib@go1.17.13
0.60.0
1.26.9
1
jhonbrownn/elchi-discovery:latest:v1.0.08f6551ecc98c
golang.org/x/net@v0.13.0
stdlib@go1.23.1
0.60.0
1.26.9
1
jhonbrownn/merge-pilot-backend:1.6.068d6223ea366
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
1
jitesoft/kubectl:latest7f25594d4f33
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
jkaninda/grafana:11.0.08cfda26ecb7d
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
1
jkremser/log2rbac:v0.0.5e35cf56ef183
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
1
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.5
0.60.0
1.26.9
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.15
0.60.0
1.26.9
1
johnblack77/clustereye-api:latest816f4e2fea4a
golang.org/x/net@v0.50.0
stdlib@go1.25.14
0.60.0
1.26.9
1
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.60.0
1.26.9
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/net@v0.9.0
stdlib@go1.18.10
0.60.0
1.26.9
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.60.0
1.26.9
1
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/net@v0.11.0
stdlib@go1.18.7
0.60.0
1.26.9
1
jupyterhub/k8s-image-awaiter:3.0.1-0.dev.git.6287.hbfb05cd6a395326989c3
stdlib@go1.18.10
1.26.9
1
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.60.0
1.26.9
1
jwilder/dockerize:v0.10.0839cd6793d19
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9
1
jwkohnen/conntrack-stats-exporter:v0.4.488cb711bf3bcb
stdlib@go1.27.1
1.27.2
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.