StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
DEBIAN-CVE-2026-78660GO-2026-6610CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
natsnatsVerified publisher2.15.03 of 3See more

nats nats 2.15.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/nats:2.15.0-alpineac8f88a6494b
stdlib@go1.27.1
1.27.2
natsio/nats-box:0.19.7ffce8bd10338
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.26.9

Open the chart page →

2,805
dexdexVerified publisher0.26.01 of 1See more

dex dex 0.26.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

464
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

36,633
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
stdlib@go1.21.8
1.26.9

Open the chart page →

12,712
falcofalcosecurity9.2.03 of 3See more

falco falcosecurity 9.2.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
falcosecurity/falco:0.45.0788f1129c542
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
falcosecurity/falco-driver-loader:0.45.0d7d287d4dcee
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
falcosecurity/falcoctl:0.14.290ba9627886e
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

3,665
kubeviewkubeviewVerified publisher2.2.11 of 1See more

kubeview kubeview 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/benc-uk/kubeview:latest45b64d7c7016
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

295
alertmanagerprometheus-communityOfficialVerified publisher2.1.02 of 2See more

alertmanager prometheus-community 2.1.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.106b52bd4dbe3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.34.1e9733bafb1bd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

333
kongkongOfficialVerified publisher3.4.11 of 2See more

kong kong 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

845
nfs-server-provisionerkvaps1.8.01 of 1See more

nfs-server-provisioner kvaps 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

3,435
chartmuseumchartmuseumVerified publisher3.10.41 of 1See more

chartmuseum chartmuseum 3.10.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.16.3c81f105c3682
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

2,061
prometheus-node-exporterprometheus-communityOfficialVerified publisher4.59.01 of 1See more

prometheus-node-exporter prometheus-community 4.59.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

274
rook-cephrookOfficialVerified publisher1.21.02 of 2See more

rook-ceph rook 1.21.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rook/ceph:v1.21.02c3a65786d3c
golang.org/x/net@v0.58.0
stdlib@go1.22.10
0.60.0
1.26.9
quay.io/cephcsi/ceph-csi-operator:v1.1.0c42c95c36fa2
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,898
grafanagrafana-communityVerified publisher13.5.01 of 1See more

grafana grafana-community 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

237
argo-eventsargoOfficialVerified publisher2.4.271 of 1See more

argo-events argo 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
golang.org/x/net@v0.57.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

1,529
victoria-metrics-k8s-stackvictoriametricsVerified publisher0.95.25 of 7See more

victoria-metrics-k8s-stack victoriametrics 0.95.2

5 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
victoriametrics/operator:v0.75.078da26b41a81
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/victoriametrics/sync-job:v0.0.17b6f233532a85
golang.org/x/net@v0.56.0
stdlib@go1.26.4-X:jsonv2
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,249
aws-node-termination-handleraws0.21.01 of 1See more

aws-node-termination-handler aws 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.19.0844478ebd5b8
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

2,202
kuredkuredOfficialVerified publisher6.1.01 of 1See more

kured kured 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubereboot/kured:1.23.08dfd3c2e8893
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

448
prometheus-adapterprometheus-communityOfficialVerified publisher5.3.01 of 1See more

prometheus-adapter prometheus-community 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9

Open the chart page →

1,474
openebsopenebsOfficialVerified publisher4.6.220 of 35See more

openebs openebs 4.6.2

20 of the 35 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.26.9
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.26.9
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.26.9
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
openebs/lvm-driver:1.10.141f73aba7f31
golang.org/x/net@v0.48.0
stdlib@go1.24.7
0.60.0
1.26.9
openebs/mc:RELEASE.2024-11-21T17-21-54Z4d1b85539919
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
openebs/minio:RELEASE.2024-12-18T13-15-44Zbb04e41fc1b8
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
openebs/provisioner-localpv:4.6.099f5116f5cb8
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
openebs/zfs-driver:2.11.20234692bb4a4
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

34,272
tigera-operatorprojectcalico3.33.01 of 1See more

tigera-operator projectcalico 3.33.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.44.0066c2e8d6745
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2

Open the chart page →

128
open-webuiopen-webui17.0.01See more

open-webui open-webui 17.0.0

1 container image this version deploys carries CVE-2026-78660.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.26.9

Open the chart page →

—
actions-runner-controlleractions-runner-controller0.23.72 of 2See more

actions-runner-controller actions-runner-controller 0.23.7

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
summerwind/actions-runner-controller:v0.27.62128f81dbede
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

4,312
aws-for-fluent-bitaws0.2.01 of 1See more

aws-for-fluent-bit aws 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-for-fluent-bit:3.2.1a480a1241720
stdlib@go1.25.6
1.26.9

Open the chart page →

497
corednscorednsVerified publisher1.48.21 of 1See more

coredns coredns 1.48.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
coredns/coredns:1.14.77efd3c635b03
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

462
apisixapisix2.18.01 of 3See more

apisix apisix 2.18.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.60.0
1.26.9

Open the chart page →

3,560
vpafairwinds-stableVerified publisher5.1.04 of 4See more

vpa fairwinds-stable 5.1.0

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9

Open the chart page →

2,502
x509-certificate-exporterenixOfficialVerified publisher4.2.01 of 1See more

x509-certificate-exporter enix 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/enix/x509-certificate-exporter:4.2.0afef14dc3862
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

274
terraformhashicorpVerified publisher1.1.21 of 1See more

terraform hashicorp 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.18.8
0.60.0
1.26.9

Open the chart page →

2,859
opentelemetry-operatoropentelemetry-helmOfficialVerified publisher0.124.11 of 1See more

opentelemetry-operator opentelemetry-helm 0.124.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.160.05323a0df9508
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

124
trinotrino1.42.21 of 1See more

trino trino 1.42.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
trinodb/trino:4801565e8cac299
stdlib@go1.26.1
1.26.9

Open the chart page →

1,782
prometheus-pushgatewayprometheus-communityOfficialVerified publisher3.9.11 of 1See more

prometheus-pushgateway prometheus-community 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus/pushgateway:v1.11.491a56b89b97d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
dagsterdagsterVerified publisher1.13.261 of 5See more

dagster dagster 1.13.26

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.26.9

Open the chart page →

4,058
prometheus-redis-exporterprometheus-communityVerified publisher6.33.01 of 1See more

prometheus-redis-exporter prometheus-community 6.33.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.93.06ca518a72f30
stdlib@go1.27.1
1.27.2

Open the chart page →

93
zabbixzabbix-communityVerified publisher7.1.03 of 5See more

zabbix zabbix-community 7.1.0

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
golang.org/x/net@v0.41.0
stdlib@go1.24.10
0.60.0
1.26.9
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
stdlib@go1.24.10
1.26.9

Open the chart page →

15,981
keycloakcloudpirates-keycloakVerified publisher0.21.462 of 3See more

keycloak cloudpirates-keycloak 0.21.46

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
stdlib@go1.24.6
1.26.9
library/postgres:18.674935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

5,162
graylogkong-zVerified publisher3.0.361 of 5See more

graylog kong-z 3.0.36

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

3,212
netdatanetdataVerified publisher3.7.1751 of 1See more

netdata netdata 3.7.175

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
netdata/netdata:v2.12.01e50cc0b11f0
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,938
connectonepassword-connect2.4.22 of 2See more

connect onepassword-connect 2.4.2

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
1password/connect-api:1.8.3656e4b10df83
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1password/connect-sync:1.8.3a760350c941a
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

328
node-problem-detectordeliveryheroVerified publisher2.4.11 of 1See more

node-problem-detector deliveryhero 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,517
opencostopencostOfficialVerified publisher2.5.321 of 2See more

opencost opencost 2.5.32

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost:1.121.34cdd173253e5
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

401
openfaasopenfaas15.0.136 of 6See more

openfaas openfaas 15.0.13

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/nats-streaming:0.25.60ad6861379c9
stdlib@go1.20.11
1.26.9
ghcr.io/openfaas/faas-netes:0.18.176cfe35401d25
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
ghcr.io/openfaas/gateway:0.27.14ee0eaecc490c
stdlib@go1.24.13
1.26.9
ghcr.io/openfaas/queue-worker:0.14.2c18da04d70f6
stdlib@go1.23.4
1.26.9
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.14.05ce7540c3c00
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

5,305
prometheus-elasticsearch-exporterprometheus-communityVerified publisher7.4.01 of 1See more

prometheus-elasticsearch-exporter prometheus-community 7.4.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.11.0a056739b095d
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

300
flux2fluxcd-community2.19.17 of 7See more

flux2 fluxcd-community 2.19.1

7 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
fluxcd/flux-cli:v2.9.5704d55295355
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9
ghcr.io/fluxcd/helm-controller:v1.6.48ff15409e46d
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/image-automation-controller:v1.2.5e1a2720d3951
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/image-reflector-controller:v1.2.5c83ce5c06fed
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/kustomize-controller:v1.9.5a3a955eb2bc4
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/notification-controller:v1.9.4840f318265ee
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/source-controller:v1.9.56f20d232d596
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

3,883
gitlab-agentgitlabVerified publisher2.32.01 of 1See more

gitlab-agent gitlab 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cluster-integration/gitlab-agent/agentk:v19.4.04d3498887bee
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

153
jaeger-operatorjaegertracingOfficialVerified publisher2.57.01 of 1See more

jaeger-operator jaegertracing 2.57.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
jaegertracing/jaeger-operator:1.61.03f036ec60e61
golang.org/x/net@v0.29.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,073
policy-reporterpolicy-reporterOfficialVerified publisher3.11.01 of 1See more

policy-reporter policy-reporter 3.11.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kyverno/policy-reporter:3.11.00f6eabff483b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

153
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.26.9

Open the chart page →

6,589
netboxnetboxOfficialVerified publisher8.3.913 of 5See more

netbox netbox 8.3.91

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9
rancher/kubectl:v1.36.206c7a7a97727
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/netbox-community/netbox:v4.7.26f7177d3ff4d
stdlib@go1.26.7
1.26.9

Open the chart page →

1,755
valkeybitnamiVerified publisher6.3.41 of 1See more

valkey bitnami 6.3.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9

Open the chart page →

89
postgrescloudpirates-postgresVerified publisher0.21.21 of 1See more

postgres cloudpirates-postgres 0.21.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:18.674935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

1,736

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.5
0.60.0
1.26.9
1
library/cassandra:4.00909b1681015
stdlib@go1.24.6
1.26.9
1
library/chronograf:1.9.496d8a3f65a4f
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.60.0
1.26.9
1
library/docker:29.3.0-dind-alpine3.231ba18449911d
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
1
library/docker:24.0.2-dind1d148deae16a
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.60.0
1.26.9
1
library/docker:27.0.1-dind2416984b43dd
golang.org/x/net@v0.23.0
stdlib@go1.21.11
0.60.0
1.26.9
1
library/docker:28.5.2-dind2a232a42256f
golang.org/x/net@v0.39.0
stdlib@go1.24.9
0.60.0
1.26.9
1
library/docker:20.10.21-dind3153fa63f546
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.7
0.60.0
1.26.9
1
library/docker:dind-rootless3acba49741f1
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9
1
library/docker:29.8.1-dind:dind:latest3f3c01aaaebf
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
library/docker:dind7dcdfc4a2024
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
library/docker:27-cli851f91d24121
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.60.0
1.26.9
1
library/docker:28.3.3-dinda56b3bdde893
golang.org/x/net@v0.39.0
stdlib@go1.24.5
0.60.0
1.26.9
1
library/docker:27-dindaa3df78ecf32
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.60.0
1.26.9
1
library/docker:23.0.6-dindafa5d5134900
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.60.0
1.26.9
1
library/docker:23.0.1-dindd9a0fd8bdd15
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.60.0
1.26.9
1
library/docker:26.1-dinddd43b430341a
golang.org/x/net@v0.25.0
stdlib@go1.21.11
0.60.0
1.26.9
1
library/ghost:6.37.01ef2e532ca4d
stdlib@go1.23.12
1.26.9
1
library/ghost:6.25.12654b1e90413
stdlib@go1.24.6
1.26.9
1
library/ghost:6.41.129773d6be407
stdlib@go1.24.6
1.26.9
1
library/ghost:6.39.0-alpine77196da4b0df
stdlib@go1.24.6
1.26.9
1
library/ghost:5.79.083f7bf209844
stdlib@go1.18.2
1.26.9
1
library/ghost:6.65.090592b712b6b
stdlib@go1.24.6
1.26.9
1
library/ghost:6.69.0-alpine3.23db4c56c196d6
stdlib@go1.24.6
1.26.9
1
library/golang:lateste0174e51e812
stdlib@go1.27.1
1.27.2
1
library/influxdb:1.12.3-meta8812029260b5
stdlib@go1.24.13
1.26.9
1
library/influxdb:2.8983c696655e8
golang.org/x/net@v0.41.0
stdlib@go1.24.9
0.60.0
1.26.9
1
library/influxdb:2.7.4-alpinea10d46445d68
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
1
library/influxdb:1.12.3-datab0f9fc41ed79
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
library/influxdb:2.0.8ba10ac9ba17a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.5
0.60.0
1.26.9
1
library/influxdb:latestcdd3dbdea45c
golang.org/x/net@v0.51.0
stdlib@go1.25.9
0.60.0
1.26.9
1
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
stdlib@go1.18.3
0.60.0
1.26.9
1
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.17.2
0.60.0
1.26.9
1
library/logstash:7.17.817a4f64e9cf5
stdlib@go1.19.3
1.26.9
1
library/logstash:9.1.233eae14f0867
stdlib@go1.23.12
1.26.9
1
library/mariadb:10.7.307e06f2e7ae9
stdlib@go1.16.7
1.26.9
1
library/mariadb:10.11.21c33370a599c
stdlib@go1.16.7
1.26.9
1
library/mariadb:10.422edfe1c7834
stdlib@go1.18.2
1.26.9
1
library/mariadb:10.8.2-focal490f01279be1
stdlib@go1.16.7
1.26.9
1
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.26.9
1
library/mariadb:12.3.2628f228f0fd5
stdlib@go1.24.6
1.26.9
1
library/mariadb:116422478cb8e1
stdlib@go1.24.6
1.26.9
1
library/mariadb:11.8.46b848cb24fbb
stdlib@go1.24.6
1.26.9
1
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.26.9
1
library/mariadb:10.79a48ac9f196f
stdlib@go1.16.7
1.26.9
1
library/mariadb:12.3.2a02fe89cb597
stdlib@go1.24.6
1.26.9
1
library/mariadb:12.2.2b1cb255a9939
stdlib@go1.24.6
1.26.9
1
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.26.9
1
library/mariadb:12.3.3:latest:ltsdd9b303aed4f
stdlib@go1.24.6
1.26.9
1
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.