StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
flagsmithflagsmithOfficialVerified publisher0.83.01 of 4See more

flagsmith flagsmith 0.83.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,492
gitlab-operatorgitlabVerified publisher3.4.11 of 1See more

gitlab-operator gitlab 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:3.4.196efaea0d3bb
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

222
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

5,414
beylagrafana1.16.111 of 1See more

beyla grafana 1.16.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/beyla:3.32.03ff0f7cf2bbf
golang.org/x/net@v0.57.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

426
helm-dashboardkomodorVerified publisher2.0.71 of 1See more

helm-dashboard komodor 2.0.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
komodorio/helm-dashboard:2.1.3258a9044e658
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

668
kube-prometheus-stackkube-prometheus-stack-oci92.3.05 of 6See more

kube-prometheus-stack kube-prometheus-stack-oci 92.3.0

5 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,434
kubescape-operatorkubescape1.40.56 of 6See more

kubescape-operator kubescape 1.40.5

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kubescape/http-request:v0.2.234ff502a33423
stdlib@go1.26.7
1.26.9
quay.io/kubescape/kubescape:v4.0.14418fa941ecc0
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/kubescape/kubevuln:v0.3.4309bed2f723ea0
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
golang.org/x/net@v0.56.0
stdlib@go1.25.14
0.60.0
1.26.9
quay.io/kubescape/operator:v0.2.1721ddcd2788e1e
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
quay.io/kubescape/storage:v0.0.3486333d7845589
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

2,414
kube-vipkube-vip0.11.11 of 1See more

kube-vip kube-vip 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kube-vip/kube-vip:v1.2.32fcdbb014a2e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

408
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
stdlib@go1.20.12
1.26.9

Open the chart page →

6,527
linkerd-vizlinkerd2-edgeVerified publisher30.14.11-edge1 of 5See more

linkerd-viz linkerd2-edge 30.14.11-edge

1 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

2,027
plane-cemakeplaneOfficialVerified publisher1.8.43 of 11See more

plane-ce makeplane 1.8.4

3 of the 11 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.26.9
pgsty/mc:RELEASE.2026-09-16T00-00-00Zcfc83108c3ab
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
pgsty/minio:RELEASE.2026-08-04T00-00-00Zb6bfe7239bfc
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

4,758
milvusmilvus-helm5.0.302 of 4See more

milvus milvus-helm 5.0.30

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.25-r1fededb2f2d63
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.60.0
1.26.9
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

13,219
mssqlmssqlVerified publisher1.10.31 of 1See more

mssql mssql 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.26.9

Open the chart page →

1,069
opa-kube-mgmtopa-kube-mgmtVerified publisher11.0.142 of 2See more

opa-kube-mgmt opa-kube-mgmt 11.0.14

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
openpolicyagent/kube-mgmt:11.0.14758ff3fb4727
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
openpolicyagent/opa:1.19.0852359995443
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,193
redis-operatorot-container-kit0.27.01 of 1See more

redis-operator ot-container-kit 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/opstree/redis-operator:v0.27.025799bf10231
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

291
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.26.9

Open the chart page →

5,652
s3-proxyoxyno-zetaVerified publisher2.28.01 of 1See more

s3-proxy oxyno-zeta 2.28.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
oxynozeta/s3-proxy:5.1.121115040e224
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

425
spirespiffeVerified publisher0.30.37 of 10See more

spire spiffe 0.30.3

7 of the 10 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/spiffe/oidc-discovery-provider:1.15.3bb95f13c2b4e
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
golang.org/x/net@v0.42.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/spiffe/spire-agent:1.15.341b0dcd8b258
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/spiffe/spire-controller-manager:0.8.019e418e9d7f2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/spiffe/spire-server:1.15.34082f30d3e0d
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

3,897
wireguardwireguardVerified publisher0.32.01 of 3See more

wireguard wireguard 0.32.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-wireguard-mgr:mainc4febc0da1a4
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

413
altinity-clickhouse-operatoraltinity-clickhouse-operator0.27.43 of 3See more

altinity-clickhouse-operator altinity-clickhouse-operator 0.27.4

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.27.4c60c872fedd8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
altinity/metrics-exporter:0.27.4d257a72e6a6a
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.36.36e4fce3c8365
golang.org/x/net@v0.49.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

842
bytebasebytebase1.1.51 of 1See more

bytebase bytebase 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bytebase/bytebase:latest0b3a44dfac3e
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

455
cert-manager-csi-drivercert-managerOfficialVerified publisher0.16.03 of 3See more

cert-manager-csi-driver cert-manager 0.16.0

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-csi-driver:v0.16.09d13db6dc80e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,409
ansible-semaphorecloudhippieVerified publisher15.3.21 of 1See more

ansible-semaphore cloudhippie 15.3.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.19.163707a971a57f
golang.org/x/net@v0.36.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,847
etcdcloudpirates-etcdVerified publisher0.8.91 of 1See more

etcd cloudpirates-etcd 0.8.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/etcd-development/etcd:v3.7.27c6c239825d0
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

238
rabbitmq-cluster-operatorcloudpirates-rabbitmq-cluster-operatorVerified publisher0.6.192 of 2See more

rabbitmq-cluster-operator cloudpirates-rabbitmq-cluster-operator 0.6.19

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/rabbitmq/cluster-operator:2.23.09236fb4f559b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/rabbitmq/messaging-topology-operator:1.20.3f377d3c3e221
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

419
zookeepercloudpirates-zookeeperVerified publisher0.15.21 of 1See more

zookeeper cloudpirates-zookeeper 0.15.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/zookeeper:3.9.6d0ae1665a1e8
stdlib@go1.18.1
1.26.9

Open the chart page →

3,646
vertical-pod-autoscalercluster-autoscaler0.13.04 of 4See more

vertical-pod-autoscaler cluster-autoscaler 0.13.0

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.8.03d94f53e4c5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.8.0e743e3a7e58a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.8.01d0229e52f90
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

2,099
codefreshcodefresh-onpremOfficialVerified publisher2.12.216 of 42See more

codefresh codefresh-onprem 2.12.21

6 of the 42 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
golang.org/x/net@v0.27.0
stdlib@go1.21.12
0.60.0
1.26.9
bitnamilegacy/nats:2.11.8-debian-12-r0fa0cfba6034a
stdlib@go1.24.6
1.26.9
ghcr.io/helm/chartmuseum:v0.16.648bc27743c08
golang.org/x/net@v0.56.0
stdlib@go1.25.13
0.60.0
1.26.9
quay.io/codefresh/dind:3.0.250885ab519dac
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
stdlib@go1.23.8
1.26.9

Open the chart page →

19,845
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/projectcontour/contour:v1.33.7d88264ed084a
golang.org/x/net@v0.58.0
stdlib@go1.26.8-X:nodwarf5,nogreenteagc,norandomizedheapbase64
0.60.0
1.26.9

Open the chart page →

1,906
couchbase-operatorcouchbaseVerified publisher2.93.02 of 2See more

couchbase-operator couchbase 2.93.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
couchbase/admission-controller:2.9.3bf2d2e87e45f
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9
couchbase/operator:2.9.369a385b49e1f
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,382
dash0-operatordash0-operatorOfficialVerified publisher0.157.01 of 1See more

dash0-operator dash0-operator 0.157.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dash0hq/operator-controller:0.157.02103617548e2
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

212
aws-ebs-csi-driverdeliveryheroVerified publisher2.17.46 of 6See more

aws-ebs-csi-driver deliveryhero 2.17.4

6 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/net@v0.4.0
stdlib@go1.19.6
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/net@v0.4.0
stdlib@go1.19.8
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/livenessprobe:v2.9.0-eks-1-25-latest8a305e162caa
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/node-driver-registrar:v2.7.0-eks-1-25-latestf4345e67df8f
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

11,105
eck-exporterenixVerified publisher1.14.01 of 1See more

eck-exporter enix 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

314
loki-simple-scalablegrafana1.8.112 of 3See more

loki-simple-scalable grafana 1.8.11

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18
0.60.0
1.26.9
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9

Open the chart page →

8,849
memcachedkubelauncherVerified publisher0.1.331 of 1See more

memcached kubelauncher 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/memcacheddigest-pinned91f2066d2aa4
stdlib@go1.26.7
1.26.9

Open the chart page →

701
mysqlkubelauncherVerified publisher0.4.61 of 1See more

mysql kubelauncher 0.4.6

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnedb25f98e6a86f
stdlib@go1.26.7
1.26.9

Open the chart page →

685
postgresqlkubelauncherVerified publisher0.5.01 of 1See more

postgresql kubelauncher 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinneddb2369c4dd90
stdlib@go1.26.7
1.26.9

Open the chart page →

782
kubernetes-replicatorkubernetes-replicator2.12.41 of 1See more

kubernetes-replicator kubernetes-replicator 2.12.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.12.45dc9fc5ff59a
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

667
lakefslakefsVerified publisher1.12.431 of 1See more

lakefs lakefs 1.12.43

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
treeverse/lakefs:1.88.0237a17c6b2d8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

483
multi-juicermulti-juicer10.3.11 of 1See more

multi-juicer multi-juicer 10.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/juice-shop/multi-juicer/multi-juicer:v10.3.1de4f0de62e8b
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

230
coreneuvectorchartsVerified publisher2.11.23 of 5See more

core neuvectorcharts 2.11.2

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
neuvector/controller:5.6.2824e29cf32c5
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
neuvector/enforcer:5.6.272e1deee40fb
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
neuvector/scanner:6d9e8b2ee8d69
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,341
diunnicholaswildeVerified publisher1.0.01 of 1See more

diun nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/diun:4.19.0c94e32b888e4
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.5
0.60.0
1.26.9

Open the chart page →

4,945
openclawopenclawVerified publisher1.110.12 of 2See more

openclaw openclaw 1.110.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.57.06bac628b3d82
stdlib@go1.26.7
1.26.9
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.110.151e6f187064f
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

3,151
prometheus-stackdriver-exporterprometheus-communityVerified publisher5.2.01 of 1See more

prometheus-stackdriver-exporter prometheus-community 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prometheuscommunity/stackdriver-exporter:v0.19.0c0a0cbf76570
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

635
questdbquestdb1.0.271 of 2See more

questdb questdb 1.0.27

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
questdb/questdb:10.0.167eaed863ebb
stdlib@go1.25.14
1.26.9

Open the chart page →

163
adguard-homerm3lVerified publisher0.24.11 of 2See more

adguard-home rm3l 0.24.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.513a143e6c071c
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,720
spegelspegelVerified publisher0.7.41 of 1See more

spegel spegel 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/spegel-org/spegeldigest-pinned26c60b05e08a
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

498
supabasetokens-studioVerified publisher1.0.03 of 14See more

supabase tokens-studio 1.0.0

3 of the 14 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9
supabase/gotrue:v2.163.0ba4ddc594b0b
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

26,708
wekanwekanVerified publisher12.27.02 of 3See more

wekan wekan 12.27.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latest41786dd49068
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2
ghcr.io/wekan/wekan:v12.27f2fc85bbe762
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

2,008
woodpeckerwoodpecker-ci3.7.52 of 2See more

woodpecker woodpecker-ci 3.7.5

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
woodpeckerci/woodpecker-agent:v3.19.0f85f163e0949
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
woodpeckerci/woodpecker-server:v3.19.06ca167a3c58b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

406

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.26.9
1
library/mariadb:10.79a48ac9f196f
stdlib@go1.16.7
1.26.9
1
library/mariadb:12.3.2a02fe89cb597
stdlib@go1.24.6
1.26.9
1
library/mariadb:12.2.2b1cb255a9939
stdlib@go1.24.6
1.26.9
1
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.26.9
1
library/mariadb:12.3.3:latest:ltsdd9b303aed4f
stdlib@go1.24.6
1.26.9
1
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.26.9
1
library/mariadb:10.9.4fbb8456ebdb1
stdlib@go1.16.7
1.26.9
1
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.26.9
1
library/mongo:7.0.140032d2ca20db
stdlib@go1.21.12
1.26.9
1
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.26.9
1
library/mongo:5.0.32-focal3b6c281e1c08
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.60.0
1.26.9
1
library/mongo:4.4-bionic3d0e6df9fd5b
stdlib@go1.16.3
1.26.9
1
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.26.9
1
library/mongo:noble61dd87ff554d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.26.9
1
library/mongo:4.2699d652ed674
stdlib@go1.18.2
1.26.9
1
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.26.9
1
library/mongo:5.0.217c81758cb295
stdlib@go1.19.12
1.26.9
1
library/mongo:7.0.28-jammy88785f6f665a
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.60.0
1.26.9
1
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.21.12
1.26.9
1
library/mongo:8.0d0d926f94df0
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.26.9
1
library/mongo:8d731d77bfd7a
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
library/mongo:8.0.11dca8d11fe467
golang.org/x/net@v0.40.0
stdlib@go1.23.8
0.60.0
1.26.9
1
library/mongo:8.2.12e0ce8c35124d
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
1
library/mysql:8.4.3106d5197fd8e
stdlib@go1.18.2
1.26.9
1
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.26.9
1
library/mysql:8:8.4:8.4.1185b9bf2e29cf
stdlib@go1.24.6
1.26.9
1
library/mysql:8.4.108dbcf531a03a
stdlib@go1.24.6
1.26.9
1
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.26.9
1
library/mysql:8.0-debian9382e4f6f7f0
stdlib@go1.24.6
1.26.9
1
library/mysql:8.0.41bf577825b52a
stdlib@go1.18.2
1.26.9
1
library/mysql:8.0.39ccb8f749bb5e
stdlib@go1.18.2
1.26.9
1
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.26.9
1
library/mysql:9.7.2e2bde46db656
stdlib@go1.24.6
1.26.9
1
library/nats:2.12.150764f1952d72
stdlib@go1.25.12
1.26.9
1
library/nats:2.12.6-alpine1cfc36e2e5e6
stdlib@go1.25.8
1.26.9
1
library/nats:2.12.2-alpine2d5fce3229ae
stdlib@go1.25.4
1.26.9
1
library/nats:2.10.25-alpine3290c829aa05
stdlib@go1.23.5
1.26.9
1
library/nats:2.14-alpine4063edae0717
stdlib@go1.26.8
1.26.9
1
library/nats:2.11.9-alpine777787bbb4c7
stdlib@go1.24.7
1.26.9
1
library/nats:2.7.2-alpine8b3fb2423a8c
stdlib@go1.17.6
1.26.9
1
library/nats:2.14.2-alpine952d157e28d5
stdlib@go1.26.3
1.26.9
1
library/nats:2.14.6-alpinead7a43eb7e33
stdlib@go1.26.7
1.26.9
1
library/nats:2.12-alpineb270f5e24283
stdlib@go1.25.12
1.26.9
1
library/nats:2.12.1-alpineb3f2bd84176a
stdlib@go1.25.3
1.26.9
1
library/nats:2.10.17-alpineb7752304692b
stdlib@go1.22.4
1.26.9
1
library/nats:2.10.12-alpinebca70839d953
stdlib@go1.21.8
1.26.9
1
library/nats:2.11.4c8cd23806eef
stdlib@go1.24.3
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.