StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
glpieftechcombr-glpiVerified publisher2.12.01 of 5See more

glpi eftechcombr-glpi 2.12.0

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:12.3.2a02fe89cb597
stdlib@go1.24.6
1.26.9

Open the chart page →

3,796
egagenteginnovationsVerified publisher0.10.01 of 1See more

egagent eginnovations 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
eginnovations/agent:7.5.4e4dfe242fe9f
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,795
glideeinstackOfficialVerified publisher0.0.21 of 1See more

glide einstack 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9

Open the chart page →

1,993
elaraelaraVerified publisher0.5.21 of 1See more

elara elara 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/sergeyslonimsky/elara:0.5.2a410a7ed1ee8
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

220
elchi-discoveryelchi1.0.01 of 1See more

elchi-discovery elchi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jhonbrownn/elchi-discovery:v1.0.08f6551ecc98c
golang.org/x/net@v0.13.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

1,182
elchi-stackelchi2.0.44 of 10See more

elchi-stack elchi 2.0.4

4 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:12.2.074144189b384
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.26.9
otel/opentelemetry-collector-contrib:0.89.0995f17004231
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.60.0
1.26.9
victoriametrics/victoria-metrics:v1.93.577a9815d0640
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.60.0
1.26.9

Open the chart page →

17,674
navidromeemmas-chartsVerified publisher0.0.61 of 1See more

navidrome emmas-charts 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
deluan/navidrome:0.50.02cf4442b0099
golang.org/x/net@v0.18.0
stdlib@go1.21.0
0.60.0
1.26.9

Open the chart page →

2,899
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.26.9

Open the chart page →

37,005
eoapieoapiOfficialVerified publisher0.17.31 of 7See more

eoapi eoapi 0.17.3

1 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

4,551
nexus-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

nexus-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,393
error-pageserror-pagesOfficialVerified publisher4.2.51 of 1See more

error-pages error-pages 4.2.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:4.2.56d42b5d6e1a0
stdlib@go1.27.0
1.27.2

Open the chart page →

141
paraerudikaVerified publisher0.3.01 of 1See more

para erudika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
erudikaltd/para:latest_stablea6aba08c21fa
stdlib@go1.26.7
1.26.9

Open the chart page →

994
httpbingoestahnVerified publisher0.1.11 of 1See more

httpbingo estahn 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mccutchen/go-httpbin:v2.2.25994403ef75b
stdlib@go1.16.2
1.26.9

Open the chart page →

2,473
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

3,850
erigonethereum-helm-chartsVerified publisher2.0.21 of 2See more

erigon ethereum-helm-charts 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
erigontech/erigon:latest28ee51ce29ec
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,369
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
stdlib@go1.23.12
1.26.9

Open the chart page →

2,199
genesis-generatorethereum-helm-chartsVerified publisher0.2.31 of 2See more

genesis-generator ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
skylenet/ethereum-genesis-generator:latest210353ce7c89
stdlib@go1.17.13
1.26.9

Open the chart page →

4,548
ipfs-clusterethereum-helm-chartsVerified publisher0.1.143 of 3See more

ipfs-cluster ethereum-helm-charts 0.1.14

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ipfs/ipfs-cluster:latesta83266c524f1
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
ipfs/kubo:latestb293923d66e4
golang.org/x/net@v0.59.0
stdlib@go1.26.5
0.60.0
1.26.9
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

6,634
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
stdlib@go1.19.8
1.26.9

Open the chart page →

13,319
evccevccVerified publisher1.0.471 of 1See more

evcc evcc 1.0.47

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
evcc/evcc:0.300.8ddf2a25afce5
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

1,630
event-exporterevent-exporterVerified publisher0.1.171 of 1See more

event-exporter event-exporter 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubestar/event-exporter:latest656606941255
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

1,855
events-exporterevents-exporter0.0.41 of 1See more

events-exporter events-exporter 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

2,957
github-actions-runner-operatorevryfs-ossVerified publisher2.8.11 of 1See more

github-actions-runner-operator evryfs-oss 2.8.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
golang.org/x/net@v0.12.0
stdlib@go1.21.1
0.60.0
1.26.9

Open the chart page →

1,920
ext-postgres-operatorext-postgres-operatorVerified publisher3.0.01 of 1See more

ext-postgres-operator ext-postgres-operator 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/movetokube/postgres-operator:2.4.0def57d85a2da
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

814
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:latestbbd4e17f1ef8
stdlib@go1.24.5
1.26.9

Open the chart page →

4,944
vidcheckfactlyVerified publisher0.5.21 of 2See more

vidcheck factly 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
factly/vidcheck-server:0.12.087064eb0463c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.14.2
0.60.0
1.26.9

Open the chart page →

4,883
ecr-cleanupfairwinds-stableVerified publisher1.2.81 of 1See more

ecr-cleanup fairwinds-stable 1.2.8

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
danielfm/kube-ecr-cleanup-controller:0.1.1012485563b1d0
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

1,785
falco-operatorfalcosecurity0.3.11 of 1See more

falco-operator falcosecurity 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
falcosecurity/falco-operator:0.4.18a99fcc57a57
golang.org/x/net@v0.53.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

787
fastapi-microservice-appfast-api-microservice-app1.3.01 of 4See more

fastapi-microservice-app fast-api-microservice-app 1.3.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:7.01f995ad6fdb9
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

10,905
featurehubfeaturehub4.1.63 of 7See more

featurehub featurehub 4.1.6

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.26.9
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.26.9

Open the chart page →

11,057
federidfederidOfficialVerified publisher0.1.21 of 1See more

federid federid 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
federid/webhook:0.1.0fbfb7c6510a7
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

2,823
fencemasterfencemasterVerified publisher0.1.131 of 1See more

fencemaster fencemaster 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/rvbsalgado/fencemaster:1.0.0-rc.207056a6aae439
golang.org/x/net@v0.43.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

640
taigafermosit0.0.112 of 7See more

taiga fermosit 0.0.11

2 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
stdlib@go1.24.4
1.26.9
taigaio/taiga-protected:latestfd4568a97a59
stdlib@go1.24.4
1.26.9

Open the chart page →

10,160
ferriskeyferriskey0.9.01 of 3See more

ferriskey ferriskey 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

2,580
ai-gatewayferro-labsOfficialVerified publisher1.2.01 of 1See more

ai-gateway ferro-labs 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/ferro-labs/ai-gateway:1.2.0baa285ec0fc9
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

381
file-manager-serverfile-manager-server1.11.01 of 1See more

file-manager-server file-manager-server 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9

Open the chart page →

1,280
fission-corefission-chartsVerified publisher1.14.13 of 3See more

fission-core fission-charts 1.14.1

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
fission/fission-bundle:1.14.13fcfd8a0fa5d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.14
0.60.0
1.26.9
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.14
0.60.0
1.26.9
fission/reporter:1.14.104c6e06af175
stdlib@go1.15.14
1.26.9

Open the chart page →

10,386
openldapfluktuid0.1.11 of 2See more

openldap fluktuid 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.60.0
1.26.9

Open the chart page →

5,240
fluorite-chartfluorite-helmOfficialVerified publisher0.1.01 of 1See more

fluorite-chart fluorite-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/afcms/fluorite:master00f3a5219ac0
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

237
flyway-operatorflyway-operatorVerified publisher0.2.131 of 1See more

flyway-operator flyway-operator 0.2.13

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/davidkarlsen/flyway-operator:0.2.1366f60b461c0d
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,139
contentserverfoomoVerified publisher0.8.01 of 1See more

contentserver foomo 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
foomo/contentserver:1.21.28da4b33610c6
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

552
fqdn-controllerfqdn-controllerOfficialVerified publisher0.3.01 of 1See more

fqdn-controller fqdn-controller 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/konsole-is/fqdn-controller:0.3.08d5d41ab22aa
golang.org/x/net@v0.56.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

283
free5gcfree5gcVerified publisher0.1.312 of 12See more

free5gc free5gc 0.1.3

12 of the 12 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/mongodb:latestc8babafb7d15
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/udm:v3.4.32f68df062a50
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/upf:v3.4.3b6b362a39fdd
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

17,733
fsmfsmOfficialVerified publisher0.2.112 of 5See more

fsm fsm 0.2.11

2 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.60.0
1.26.9
flomesh/fsm-manager:0.2.1122f849c70b25
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.60.0
1.26.9

Open the chart page →

5,831
function-mesh-operatorfunction-mesh0.2.451 of 1See more

function-mesh-operator function-mesh 0.2.45

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
streamnative/function-mesh:v0.29.04176923db03c
golang.org/x/net@v0.56.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

479
adguard-homegabe565Verified publisher0.3.251 of 2See more

adguard-home gabe565 0.3.25

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.56c64a0b37f7b9
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,355
home-assistantgabe565Verified publisher0.17.01 of 1See more

home-assistant gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:latest3e6710a7ab2a
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

3,152
memosgabe565Verified publisher0.17.01 of 1See more

memos gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/usememos/memos:0.24.04723d86e6797
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

2,119
dexgabibbo974.0.41 of 1See more

dex gabibbo97 4.0.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

4,619
garage-uigarage-uiVerified publisher0.13.01 of 1See more

garage-ui garage-ui 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
noooste/garage-ui:v0.13.0a1444fa10585
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

218

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
kvalitetsit/myra-cert-manager-webhook:1.2.184ab59a1434e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
kvalitetsit/nsp-prometheus-exporter:1.0.190b397ff954ec
stdlib@go1.15.3
1.26.9
1
kvalitetsit/oauth2-proxy-injector:1.5.00c906908d632
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
1
kvalitetsit/stakit-adapter-alertmanager:0.2.6838db1e90c6b
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
golang.org/x/net@v0.0.0-20180906233101-161cd47e91fd
stdlib@go1.19.3
0.60.0
1.26.9
1
l7mp/stunner-auth-server:1.1.02f8114477ba6
golang.org/x/net@v0.36.0
stdlib@go1.23.8
0.60.0
1.26.9
1
l7mp/stunner-gateway-operator:1.2.10ea40a1d42d5
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
l7mp/stunner-gateway-operator:1.1.0c34f7c931491
golang.org/x/net@v0.36.0
stdlib@go1.23.8
0.60.0
1.26.9
1
l7mp/stunner-gateway-operator-premium:1.2.14383766e66c5
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
l7mp/stunner-gateway-operator-premium:devb2726bf5547d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
labs64/auditflow9c1bd414fcfb
stdlib@go1.26.7
1.26.9
1
labs64/checkout4009b8251b57
stdlib@go1.26.7
1.26.9
1
labs64/payment-gateway5421f763b53e
stdlib@go1.26.7
1.26.9
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
1
langgenius/dify-api:1.16.1dcefa5f7c47c
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
langgenius/dify-plugin-daemon:main-local4b07ca30ab2a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.60.0
1.26.9
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.60.0
1.26.9
1
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.26.9
1
langgenius/dify-web:1.0.0d64914ff0d6d
stdlib@go1.22.5
1.26.9
1
launchdarkly/ld-relay:8.22.0065f211f5d7c
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
lavr/express-botx:0.42.0-rootlessad6ec93952fc
golang.org/x/net@v0.38.0
stdlib@go1.25.14
0.60.0
1.26.9
1
layer5/meshery:stable-latest78a8be21bef3
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
layer5/meshery-app-mesh:stable-latest77d59943b3d6
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.60.0
1.26.9
1
layer5/meshery-consul:stable-latest25a4cc38abcd
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b297
stdlib@go1.13.1
0.60.0
1.26.9
1
layer5/meshery-istio:stable-latestfde47c141ec6
golang.org/x/net@v0.36.0
stdlib@go1.23.9
0.60.0
1.26.9
1
layer5/meshery-kuma:stable-latest9d25f029a8a2
golang.org/x/net@v0.17.0
stdlib@go1.23.4
0.60.0
1.26.9
1
layer5/meshery-linkerd:stable-latestb99c73bac1f5
golang.org/x/net@v0.19.0
stdlib@go1.23.6
0.60.0
1.26.9
1
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.60.0
1.26.9
1
layer5/meshery-nsm:stable-latestebd6a8faf21f
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.12
0.60.0
1.26.9
1
layer5/meshery-operator:stable-latest6f58a28fe422
golang.org/x/net@v0.33.0
stdlib@go1.23.9
0.60.0
1.26.9
1
layer5/meshery-osm:stable-latestec898e5786c6
golang.org/x/net@v0.5.0
stdlib@go1.19.8
0.60.0
1.26.9
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.60.0
1.26.9
1
lbenicio/kubernetes-dashboard-api:1.14.951d3d30206c8
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.60.0
1.26.9
1
lbenicio/kubernetes-dashboard-auth:1.4.1635eb784c03fa
golang.org/x/net@v0.46.0
stdlib@go1.25.12
0.60.0
1.26.9
1
lbenicio/kubernetes-dashboard-scraper:1.2.69202e96ad403
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.60.0
1.26.9
1
lbenicio/kubernetes-dashboard-web:1.7.142797937bc2a5
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.60.0
1.26.9
1
leonardomulticloud/svc-vault:v1.0.0e4acd2fbb7b1
stdlib@go1.23.1
1.26.9
1
leonardomulticloud/webhook:v1.0.0d119918900e8
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.