StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
kuttchristianhuthVerified publisher9.11.21 of 3See more

kutt christianhuth 9.11.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/redis:latest33a5a129cadc
stdlib@go1.26.8
1.26.9

Open the chart page →

833
clamavclamavVerified publisher1.10.391 of 2See more

clamav clamav 1.10.39

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-clamav/kubectl:1.10.397d7a46f5dc6d
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

353
cloudquerycloudquery39.0.41 of 1See more

cloudquery cloudquery 39.0.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/cloudquery/cloudquery:6.40.040b804fce7f9
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

953
cluster-api-operatorcluster-api-operator0.29.01 of 1See more

cluster-api-operator cluster-api-operator 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/capi-operator/cluster-api-operator:v0.29.0465e72f8b06a
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

264
immudbcodenotaryVerified publisher1.9.71 of 1See more

immudb codenotary 1.9.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codenotary/immudb:1.9.77c85d7cc4f22
golang.org/x/net@v0.17.0
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

2,086
routercosmo-routerOfficialVerified publisher0.18.01 of 1See more

router cosmo-router 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

2,311
dolibarrcowboysysopVerified publisher9.0.32 of 3See more

dolibarr cowboysysop 9.0.3

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
stdlib@go1.23.7
1.26.9
wait4x/wait4x:3.3.14dcd86307de1
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

11,489
csi-wekafsplugincsi-wekafsOfficialVerified publisher0.6.2-01 of 6See more

csi-wekafsplugin csi-wekafs 0.6.2-0

1 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.60.0
1.26.9

Open the chart page →

4,132
daskhubdask2024.1.13 of 9See more

daskhub dask 2024.1.1

3 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/traefik:2.10.61957e3314f43
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
quay.io/jupyterhub/k8s-image-awaiter:3.2.1f65b644ed6db
stdlib@go1.18.10
1.26.9
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.60.0
1.26.9

Open the chart page →

17,568
seafiledatamateVerified publisher0.6.05 of 6See more

seafile datamate 0.6.0

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
stdlib@go1.22.6
1.26.9
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
bitnamilegacy/os-shell:11-debian-11-r968643af4facff
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

85,814
k8s-event-loggerdeliveryheroVerified publisher1.4.01 of 1See more

k8s-event-logger deliveryhero 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
maxrocketinternet/k8s-event-logger:2.70234bdec4626
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

667
drone-runner-dockerdroneVerified publisher0.7.02 of 3See more

drone-runner-docker drone 0.7.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.15
0.60.0
1.26.9
library/docker:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9

Open the chart page →

7,603
gateway-helmenvoy-gateway0.0.0-latest1 of 1See more

gateway-helm envoy-gateway 0.0.0-latest

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
envoyproxy/gateway-dev:latest97b2a036f523
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

461
k8s-image-swapperestahnVerified publisher1.11.01 of 2See more

k8s-image-swapper estahn 1.11.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9

Open the chart page →

2,666
loadtesterflagger0.39.01 of 1See more

loadtester flagger 0.39.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.56.0
stdlib@go1.24.12
0.60.0
1.26.9

Open the chart page →

2,414
flannelflannel0.28.102 of 2See more

flannel flannel 0.28.10

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/flannel-io/flannel:v0.28.10f26b2403273c
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/flannel-io/flannel-cni-plugin:v1.9.1-flannel39fccdf677e6e
stdlib@go1.26.5
1.26.9

Open the chart page →

648
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.1
0.60.0
1.26.9

Open the chart page →

4,593
lndfold0.3.153 of 4See more

lnd fold 0.3.15

3 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.16.4-beta-c287129953689
golang.org/x/net@v0.8.0
stdlib@go1.21.0
0.60.0
1.26.9
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.60.0
1.26.9
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

12,035
geonode-k8sgeonode-k8sVerified publisher2.0.02 of 10See more

geonode-k8s geonode-k8s 2.0.0

2 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jwilder/dockerize:v0.10.0839cd6793d19
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.32.08ccae74fc039
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

62,384
gitops-promotergitops-promoterOfficialVerified publisher0.24.02 of 2See more

gitops-promoter gitops-promoter 0.24.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/gitops-promoter:v0.45.05ac7b6178ddc
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/brancz/kube-rbac-proxy:v0.23.0a6075902738e
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

3,631
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:latestf1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

13,178
grafana-mcpgrafana-communityVerified publisher0.27.21 of 1See more

grafana-mcp grafana-community 0.27.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/mcp-grafana:2.0.278d208116ec5
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,201
mariadbgroundhog2k4.44.01 of 1See more

mariadb groundhog2k 4.44.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:11.8.46b848cb24fbb
stdlib@go1.24.6
1.26.9

Open the chart page →

3,557
mongodbgroundhog2k0.8.31 of 1See more

mongodb groundhog2k 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:8.3.115d7043a4ffe0
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,499
haproxy-ingresshaproxy-ingressVerified publisher0.16.21 of 1See more

haproxy-ingress haproxy-ingress 0.16.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/jcmoraisjr/haproxy-ingress:v0.16.242bcf39842db
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

236
heimdallheimdallOfficialVerified publisher3.3.31 of 2See more

heimdall heimdall 3.3.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

2,943
autheliahelmforgeVerified publisher1.5.141 of 1See more

authelia helmforge 1.5.14

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
authelia/authelia:4.39.28bd97cff4fcbf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

205
dolibarrhelmforgeVerified publisher1.2.191 of 3See more

dolibarr helmforge 1.2.19

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mysql:26.7.0ade067ae2fb1
stdlib@go1.24.6
1.26.9

Open the chart page →

5,192
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
stdlib@go1.20.7
1.26.9

Open the chart page →

12,157
postgresqlhelmforgeVerified publisher2.0.51 of 1See more

postgresql helmforge 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

1,919
umamihelmforgeVerified publisher2.3.41 of 3See more

umami helmforge 2.3.4

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

2,223
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:15724292da1f2e
stdlib@go1.24.6
1.26.9
victoriametrics/victoria-metrics:v1.95.1f52723a08a44
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

16,818
infrahubinfrahubVerified publisher4.33.61 of 5See more

infrahub infrahub 4.33.6

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9

Open the chart page →

12,575
secret-manageritscontainedVerified publisher0.2.11 of 1See more

secret-manager itscontained 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
itscontained/secret-manager:0.3.07ec3e93c6469
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.3
0.60.0
1.26.9

Open the chart page →

4,300
jenkinsjenkins-helm-chartVerified publisher0.1.01 of 1See more

jenkins jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
kamu-api-serverkamuVerified publisher0.92.01 of 1See more

kamu-api-server kamu 0.92.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.92.016a23a285ffc
golang.org/x/net@v0.59.0
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

7,756
kerberneteskerbernetesVerified publisher1.1.111 of 1See more

kerbernetes kerbernetes 1.1.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/froz42/kerbernetes:v1.1.6d5c074be8366
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

401
percona-xtradb-clusterkfirfer1.5.101 of 3See more

percona-xtradb-cluster kfirfer 1.5.10

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
stdlib@go1.19.9
1.26.9

Open the chart page →

5,631
permission-managerkfirfer1.0.71 of 1See more

permission-manager kfirfer 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.60.0
1.26.9

Open the chart page →

3,393
klusterviewklusterviewVerified publisher0.1.02 of 4See more

klusterview klusterview 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:latestb28bae15e219
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/prometheus/prometheus:latestefd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

3,791
gateway-operatorkongOfficialVerified publisher0.6.11 of 1See more

gateway-operator kong 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kong/gateway-operator:1.603510967482b
golang.org/x/net@v0.39.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

1,367
kong-meshkong-meshVerified publisher2.14.53 of 3See more

kong-mesh kong-mesh 2.14.5

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kong/kuma-cp:2.14.5a154795691d1
golang.org/x/net@v0.58.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
kong/kumactl:2.14.58191df5c7019
golang.org/x/net@v0.58.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
registry.k8s.io/kubectl:v1.36.1d08f476d04d0
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

1,305
kubeflowkubeflow1.6.226 of 45See more

kubeflow kubeflow 1.6.2

26 of the 45 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.13
0.60.0
1.26.9
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.60.0
1.26.9
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/net@v0.0.0-20211205041911-012df41ee64c
stdlib@go1.17.7
0.60.0
1.26.9
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.11
0.60.0
1.26.9
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.60.0
1.26.9
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/mysql:5.7-debiandf28187b5455
stdlib@go1.16.7
1.26.9
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.11
0.60.0
1.26.9
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

192,264
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
stdlib@go1.20.6
1.26.9

Open the chart page →

12,208
testkubekubeshop2.14.16 of 6See more

testkube kubeshop 2.14.1

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubeshop/bitnami-mongodb:8.3.11e209888ede02
golang.org/x/net@v0.48.0
stdlib@go1.26.8
0.60.0
1.26.9
kubeshop/testkube-api-server:2.14.1ce04897e5ea2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
kubeshop/testkube-kubectl:1.37.15011b74081fa
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
kubeshop/testkube-minio:2025.10d8e1af6aca99
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
library/nats:2.15.0-alpineac8f88a6494b
stdlib@go1.27.1
1.27.2
natsio/nats-server-config-reloader:0.24.0d758a82a9c20
stdlib@go1.26.5
1.26.9

Open the chart page →

6,078
openelbkubesphere-stable0.5.02 of 2See more

openelb kubesphere-stable 0.5.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.60.0
1.26.9
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

6,631
operatorkube-starrocksVerified publisher1.11.71 of 1See more

operator kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/net@v0.17.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

1,092
sbomscannerkubewardenVerified publisher0.13.05 of 5See more

sbomscanner kubewarden 0.13.0

5 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/nats:2.14.6-alpinead7a43eb7e33
stdlib@go1.26.7
1.26.9
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.26.9
ghcr.io/kubewarden/sbomscanner/controller:v0.13.0611e21c44268
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/kubewarden/sbomscanner/storage:v0.13.064929d3a8ecf
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/kubewarden/sbomscanner/worker:v0.13.00a8e4e31c890
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

2,211
venti-stackkuossOfficialVerified publisher0.5.08 of 9See more

venti-stack kuoss 0.5.0

8 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kuoss/eventrouter:v0.4.156226040e1346
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.60.0
1.26.9
ghcr.io/kuoss/lethe:v0.3.3ebdf55fd5705
golang.org/x/net@v0.41.0
stdlib@go1.24.10
0.60.0
1.26.9
ghcr.io/kuoss/venti:v0.3.38ee3e70d77f1
golang.org/x/net@v0.42.0
stdlib@go1.24.10
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.93.1428f088fe6fe
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.13.2508729e0e2d1
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

6,632
librechatlibrechat-openshiftVerified publisher1.9.01 of 3See more

librechat librechat-openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

6,835

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
kubernetesui/dashboard:v2.7.02e500d29e9d5
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
1
kubernetesui/dashboard-api:1.7.060595892c2cf
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
1
kubernetesui/dashboard-auth:1.1.307135c09e9ff
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.60.0
1.26.9
1
kubernetesui/dashboard-metrics-scraper:1.1.17747d363c9fe
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.60.0
1.26.9
1
kubernetesui/dashboard-web:1.4.04445b31a2c25
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
1
kubernetesui/metrics-scraper:v1.0.876049887f07a
golang.org/x/net@v0.0.0-20220524220425-1d687d428aca
stdlib@go1.18.2
0.60.0
1.26.9
1
kubesec/kubesec:latest6735b7f3d1c8
stdlib@go1.27.1
1.27.2
1
kubesec/kubesec:v2.13.0c0f3b0673578
stdlib@go1.19.7
1.26.9
1
kubeshark/hub:v53.50532936678f8
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2
1
kubeshark/worker:v53.51f3e121224f8
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
1
kubeshop/bitnami-mongodb:8.3.11e209888ede02
golang.org/x/net@v0.48.0
stdlib@go1.26.8
0.60.0
1.26.9
1
kubeshop/kube-webhook-certgen:0.0.7866827c379ae
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
1
kubeshop/kusk-gateway:v1.5.48b5bfd57a3ce
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.4
0.60.0
1.26.9
1
kubeshop/kusk-gateway-api:v1.5.4126c713cf7d8
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.10
0.60.0
1.26.9
1
kubeshop/kusk-gateway-api-websocket:v1.5.43b4f8345ca5c
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.10
0.60.0
1.26.9
1
kubeshop/testkube-api-server:0.11.160ad97f07a78b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
golang.org/x/net@v0.40.0
stdlib@go1.23.10
0.60.0
1.26.9
1
kubeshop/testkube-kubectl:1.37.15011b74081fa
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
kubeshop/testkube-logs-server:latest094186b19698
golang.org/x/net@v0.34.0
stdlib@go1.24.1
0.60.0
1.26.9
1
kubeshop/testkube-minio:2025.10d8e1af6aca99
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
1
kubeshop/testkube-operator:2.1.154def0d0f0d4ab
golang.org/x/net@v0.34.0
stdlib@go1.23.9
0.60.0
1.26.9
1
kubeshop/tracetest:v1.7.173d7e3a2db43
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.60.0
1.26.9
1
kubeskoop/agent:v1.0.0-rc.19031d9f74832
golang.org/x/net@v0.10.0
stdlib@go1.22.1
0.60.0
1.26.9
1
kubeskoop/controller:v1.0.0-rc.137a3eb73325d
golang.org/x/net@v0.10.0
stdlib@go1.22.1
0.60.0
1.26.9
1
kubesphere/fluentbit-operator:v0.9.0b87db3c57cb3
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
1
kubesphere/fluent-operator:v1.0.2702df77228c6
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.6
0.60.0
1.26.9
1
kubesphere/ks-extensions-museum:latest29681958f220
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.60.0
1.26.9
1
kubesphere/kubectl:v1.27.1649b445b1b732
golang.org/x/net@v0.23.0
stdlib@go1.18.10
0.60.0
1.26.9
1
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.60.0
1.26.9
1
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.10
0.60.0
1.26.9
1
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.10
0.60.0
1.26.9
1
kubestar/event-exporter:latest656606941255
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9
1
kubestar/security-webhook:latest156d495afe77
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9
1
kubesuite/kubereport:latest0262424ee702
golang.org/x/net@v0.29.0
stdlib@go1.22.0
0.60.0
1.26.9
1
kubevious/ui:1.2.16233e84bdd59
golang.org/x/net@v0.0.0-20220812165438-1d4ff48094d1
stdlib@go1.19.1
0.60.0
1.26.9
1
kubevip/kube-vip-cloud-provider:v0.0.12f8f4e3401f76
golang.org/x/net@v0.37.0
stdlib@go1.24.2
0.60.0
1.26.9
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.60.0
1.26.9
1
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9
1
kudobuilder/controller:v0.9.069072d979708
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13
0.60.0
1.26.9
1
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.60.0
1.26.9
1
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9
1
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/net@v0.19.0
stdlib@go1.22.12
0.60.0
1.26.9
1
kusionstack/kuperator:v0.7.4d2f72ae1d2f2
golang.org/x/net@v0.28.0
stdlib@go1.24.13
0.60.0
1.26.9
1
kusionstack/kusion:v0.14.0126c8f0b0976
golang.org/x/net@v0.31.0
stdlib@go1.22.10
0.60.0
1.26.9
1
kusionstack/operating:v0.5.0c28bd96b986b
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
1
kvalitetsit/go-loop:1.1.0d07f449d75ed
stdlib@go1.25.1
1.26.9
1
kvalitetsit/kitargus:2026-03-09-091234-10013c4c5cde2d9371c
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
1
kvalitetsit/kitcaddy:1.5.110e66907ea266
golang.org/x/net@v0.55.0
stdlib@go1.26.6
0.60.0
1.26.9
1
kvalitetsit/metadoc-app:maine89e351733ad
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.19.5
0.60.0
1.26.9
1
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.