StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
prometheus-statsd-exporterhelm-charts-nr0.1.51 of 1See more

prometheus-statsd-exporter helm-charts-nr 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.26.9

Open the chart page →

2,375
toxiproxyhelm-charts-nr1.3.91 of 2See more

toxiproxy helm-charts-nr 1.3.9

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
stdlib@go1.19.13
1.26.9

Open the chart page →

1,146
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.60.0
1.26.9

Open the chart page →

10,813
helm-controllerhelm-controllerVerified publisher0.1.41 of 1See more

helm-controller helm-controller 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/helm-controller:v0.17.4946ae0d13229
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

516
dbapphelmcourseVerified publisher0.3.31 of 2See more

dbapp helmcourse 0.3.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

4,870
mysqlhelmcourseVerified publisher0.2.41 of 1See more

mysql helmcourse 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

2,373
chart-bookhelm-deploy-book0.1.01 of 3See more

chart-book helm-deploy-book 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dannielkil/book-db:latest433290c5c1db
stdlib@go1.18.2
1.26.9

Open the chart page →

10,719
jasperreportshelm-dojo8.0.0-v1.31 of 2See more

jasperreports helm-dojo 8.0.0-v1.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
palopalepalo/jasperreports:8-v1.356b99b194d20
stdlib@go1.19.6
1.26.9

Open the chart page →

7,765
dwpkhelm-dwpkVerified publisher1.0.03 of 3See more

dwpk helm-dwpk 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/dwpk:1.0.0d76dbf82a81d
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/devops-ia/dwpk-gateway:1.0.02911d8b02c64
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/devops-ia/dwpk-ui:1.0.0b1af8311eba8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

690
helmfile-gitops-agenthelmfile-gitops-agentVerified publisher1.1.993 of 3See more

helmfile-gitops-agent helmfile-gitops-agent 1.1.99

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/git:v2.54.0832b1cd1a271
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
fluxcd/flux-cli:v2.9.6b1ac18156f22
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/helmfile/helmfile:v1.8.19c29ece2fb6e
golang.org/x/net@v0.57.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

2,832
adguard-homehelmforgeVerified publisher1.5.21 of 2See more

adguard-home helmforge 1.5.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.79aba9e3bf0613
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

417
affinehelmforgeVerified publisher1.0.21 of 3See more

affine helmforge 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.6-pg16-bookwormccc6e83d6e35
stdlib@go1.24.6
1.26.9

Open the chart page →

4,854
alfiohelmforgeVerified publisher1.2.121 of 3See more

alfio helmforge 1.2.12

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

2,539
answerhelmforgeVerified publisher1.5.31 of 1See more

answer helmforge 1.5.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
apache/answer:2.0.2a0d71b0e30a5
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

886
appwritehelmforgeVerified publisher2.0.32 of 5See more

appwrite helmforge 2.0.3

2 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
appwrite/appwrite:2.3.034ef77fb6e87
golang.org/x/net@v0.51.0
stdlib@go1.26.8
0.60.0
1.26.9
library/mariadb:13.0.2f1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

5,363
automatischhelmforgeVerified publisher1.3.92 of 4See more

automatisch helmforge 1.3.9

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
stdlib@go1.23.8
1.26.9
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

6,609
booklorehelmforgeVerified publisher2.0.21 of 3See more

booklore helmforge 2.0.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:13.0.2d4fdec0510ad
stdlib@go1.26.7
1.26.9

Open the chart page →

2,560
castopodhelmforgeVerified publisher1.2.102 of 3See more

castopod helmforge 1.2.10

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.60.0
1.26.9
library/mariadb:13.0.2f1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

10,832
certimatehelmforgeVerified publisher1.0.91 of 1See more

certimate helmforge 1.0.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
certimate/certimate:v0.4.34ff42541a047b
golang.org/x/net@v0.58.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

258
chiefonboardinghelmforgeVerified publisher1.1.151 of 3See more

chiefonboarding helmforge 1.1.15

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

8,764
ckanhelmforgeVerified publisher1.3.102 of 6See more

ckan helmforge 1.3.10

2 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
stdlib@go1.18.1
1.26.9
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

11,613
cloudflaredhelmforgeVerified publisher1.5.171 of 1See more

cloudflared helmforge 1.5.17

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.9.3072c067d25cc
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

625
countlyhelmforgeVerified publisher1.2.82 of 3See more

countly helmforge 1.2.8

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
stdlib@go1.21.11
1.26.9
library/mongo:8.3.115d7043a4ffe0
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

76,305
dawarichhelmforgeVerified publisher1.0.32 of 4See more

dawarich helmforge 1.0.3

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.2e58334ca5697
stdlib@go1.24.4
1.26.9
postgis/postgis:18-3.67e00e8c3539f
stdlib@go1.24.6
1.26.9

Open the chart page →

12,670
ddns-updaterhelmforgeVerified publisher1.4.121 of 1See more

ddns-updater helmforge 1.4.12

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
qmcgaw/ddns-updater:2.10.03e2aa558946b
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

574
discount-bandithelmforgeVerified publisher2.0.92 of 3See more

discount-bandit helmforge 2.0.9

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cybrarist/discount-bandit:v4.0.4e9e2447ac666
golang.org/x/net@v0.43.0
stdlib@go1.25.4
0.60.0
1.26.9
library/mysql:26.7.0ade067ae2fb1
stdlib@go1.24.6
1.26.9

Open the chart page →

36,249
druidhelmforgeVerified publisher1.3.62 of 4See more

druid helmforge 1.3.6

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie6737476511d4
stdlib@go1.24.6
1.26.9
library/zookeeper:3.9.5e6b279d01350
stdlib@go1.18.1
1.26.9

Open the chart page →

10,112
drupalhelmforgeVerified publisher1.2.151 of 2See more

drupal helmforge 1.2.15

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:26.7.0ade067ae2fb1
stdlib@go1.24.6
1.26.9

Open the chart page →

4,535
entehelmforgeVerified publisher1.0.22 of 4See more

ente helmforge 1.0.2

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie6737476511d4
stdlib@go1.24.6
1.26.9
ghcr.io/ente/server:0472c929b6070e61fecaf2013d47efce2dcda462f646b68a1b8d
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

5,246
ghosthelmforgeVerified publisher1.2.102 of 3See more

ghost helmforge 1.2.10

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/ghost:6.65.090592b712b6b
stdlib@go1.24.6
1.26.9
library/mysql:8.4.110744ee5ef89c
stdlib@go1.24.6
1.26.9

Open the chart page →

3,917
ghostfoliohelmforgeVerified publisher1.0.11 of 4See more

ghostfolio helmforge 1.0.1

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie74935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

5,157
giteahelmforgeVerified publisher1.1.211 of 1See more

gitea helmforge 1.1.21

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gitea/gitea:1.27.3-rootless1c17ecaead42
golang.org/x/net@v0.56.0
stdlib@go1.26.7-X:jsonv2
0.60.0
1.26.9

Open the chart page →

905
github-mcp-serverhelmforgeVerified publisher1.0.31 of 1See more

github-mcp-server helmforge 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/github/github-mcp-server:v1.9.0881b53d6f75f
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

745
glancehelmforgeVerified publisher1.0.01 of 1See more

glance helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.69dfb09470b20
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

376
gophishhelmforgeVerified publisher0.1.61 of 1See more

gophish helmforge 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gophish/gophish:0.12.18a57cd171999
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

4,200
hermes-agenthelmforgeVerified publisher1.0.11 of 1See more

hermes-agent helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
stdlib@go1.24.4
1.26.9

Open the chart page →

6,976
hoppscotchhelmforgeVerified publisher1.1.122 of 2See more

hoppscotch helmforge 1.1.12

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2026.8.2e7ba6061a286
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

2,807
immichhelmforgeVerified publisher1.2.101 of 5See more

immich helmforge 1.2.10

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.26.9

Open the chart page →

13,216
jenkinshelmforgeVerified publisher1.0.91 of 1See more

jenkins helmforge 1.0.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jenkins/jenkins:2.568.3-lts-jdk21c1e4c349365f
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

3,471
komgahelmforgeVerified publisher1.4.161 of 1See more

komga helmforge 1.4.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gotson/komga:1.27.19cf102f5fb78
stdlib@go1.17.8
1.26.9

Open the chart page →

37,589
kubernetes-mcp-serverhelmforgeVerified publisher1.0.71 of 1See more

kubernetes-mcp-server helmforge 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/containers/kubernetes-mcp-server:v0.0.67e47f6ccc5347
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

311
listmonkhelmforgeVerified publisher1.1.143 of 3See more

listmonk helmforge 1.1.14

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie6737476511d4
stdlib@go1.24.6
1.26.9
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9
listmonk/listmonk:v6.2.0f535d59e1499
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

3,710
medikeephelmforgeVerified publisher2.0.22 of 3See more

medikeep helmforge 2.0.2

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9
ghcr.io/afairgiant/medikeep:v0.71.0086579173033
stdlib@go1.19.8
1.26.9

Open the chart page →

6,700
memoshelmforgeVerified publisher2.0.21 of 2See more

memos helmforge 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
neosmemo/memos:0.31.024c2707ddd8f
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

509
metabasehelmforgeVerified publisher1.2.301 of 3See more

metabase helmforge 1.2.30

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

2,068
metrics-serverhelmforgeVerified publisher1.0.41 of 1See more

metrics-server helmforge 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

462
middlewarehelmforgeVerified publisher1.2.82 of 4See more

middleware helmforge 1.2.8

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9
middlewareeng/middleware:0.3.1747d880812f1
stdlib@go1.17.13
1.26.9

Open the chart page →

10,728
minecrafthelmforgeVerified publisher1.5.51 of 1See more

minecraft helmforge 1.5.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
itzg/minecraft-server:2026.9.2de5d1b1a83eb
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

5,167
mongodbhelmforgeVerified publisher1.8.21 of 1See more

mongodb helmforge 1.8.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:8.3.115d7043a4ffe0
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,499
moodlehelmforgeVerified publisher1.1.31 of 2See more

moodle helmforge 1.1.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

7,284

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/openshift/origin-cli:latest486bf8e8f5b5
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.60.0
1.26.9
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
4
quay.io/prometheus/blackbox-exporter:latest:v0.29.09613f2884689
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
4
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9
4
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
4
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.60.0
1.26.9
4
quay.io/prometheus/prometheus:latest:v3.14.05ce7540c3c00
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
4
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
4
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.60.0
1.26.9
4
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9
4
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-attacher:v4.13.0d1a26170efed
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.18.0b7fefd08651f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
4
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.20.6
0.60.0
1.26.9
3
alpine/git:latesta4bb51f1a355
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
3
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
stdlib@go1.14.12
0.60.0
1.26.9
3
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.60.0
1.26.9
3
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9
3
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.17.10
0.60.0
1.26.9
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.60.0
1.26.9
3
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.26.9
3
bitnami/sealed-secrets-controller:0.40.0b1ff382e9300
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
3
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
3
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
stdlib@go1.19.2
0.60.0
1.26.9
3
cloudflare/cloudflared:2026.9.3:latest072c067d25cc
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
3
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.19.13
0.60.0
1.26.9
3
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
3
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.17.3
0.60.0
1.26.9
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
stdlib@go1.26.5
1.26.9
3
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.