StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
helm-4apk4.3.0-r04.3.0-r21
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-8p8v-px44-9x8qDEBIAN-CVE-2026-78660GO-2026-6610CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.60.0
1.26.9

Open the chart page →

4,297
redminebotdossif0.1.71 of 1See more

redminebot dossif 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dossif/redminebot:0.2.296dcd2c0e9f2
stdlib@go1.17.13
1.26.9

Open the chart page →

1,496
aliyun-exporterdoubanVerified publisher0.1.21 of 1See more

aliyun-exporter douban 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/douban/aliyun-exporter:mainb7c694331362
stdlib@go1.24.2
1.26.9

Open the chart page →

1,306
channelsdoubanVerified publisher1.1.21 of 1See more

channels douban 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
everpcpc/channels:latestb378d137ae8b
stdlib@go1.17
1.26.9

Open the chart page →

3,472
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codecov/self-hosted-gateway:24.4.1de483faad6e5
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.60.0
1.26.9
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
stdlib@go1.19.1
1.26.9

Open the chart page →

27,573
corednsdoubanVerified publisher1.39.21 of 1See more

coredns douban 1.39.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
coredns/coredns:1.12.040384aa1f5ea
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,672
gatekeeperdoubanVerified publisher3.17.12 of 3See more

gatekeeper douban 3.17.1

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.17.1b7b4d7cfdd52
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.60.0
1.26.9
openpolicyagent/gatekeeper-crds:v3.17.177bc9bf3d163
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

3,447
goinceptiondoubanVerified publisher0.3.11 of 2See more

goinception douban 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hanchuanchuan/goinception:latestb3c0dd26fb50
golang.org/x/net@v0.23.0
stdlib@go1.22.1
0.60.0
1.26.9

Open the chart page →

1,754
k8s-crondoubanVerified publisher0.2.01 of 1See more

k8s-cron douban 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/k8s:1.28.2fc059f056ad0
golang.org/x/net@v0.9.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

4,456
overlorddoubanVerified publisher0.2.21 of 1See more

overlord douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
douz/overlord:latestf2bc7fc068c1
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.5
0.60.0
1.26.9

Open the chart page →

5,640
prometheus-memcached-exporterdoubanVerified publisher0.1.31 of 1See more

prometheus-memcached-exporter douban 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prom/memcached-exporter:v0.9.001267317c95d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

3,237
qiniu-exporterdoubanVerified publisher0.1.21 of 1See more

qiniu-exporter douban 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/douban/qiniu-exporter:maind1da3bcfad7d
stdlib@go1.19.5
1.26.9

Open the chart page →

1,970
service-proberdoubanVerified publisher0.1.01 of 1See more

service-prober douban 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.28.0e753ff9f3fc4
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

945
tencentcloud-exporterdoubanVerified publisher0.2.21 of 1See more

tencentcloud-exporter douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tencentcloud-exporter:masterca51b6bb15dd
stdlib@go1.21.1
1.26.9

Open the chart page →

1,919
tencentcloud-info-exporterdoubanVerified publisher0.2.21 of 1See more

tencentcloud-info-exporter douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.18.3
0.60.0
1.26.9

Open the chart page →

3,242
ucloud-exporterdoubanVerified publisher0.1.31 of 1See more

ucloud-exporter douban 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/douban/ucloud-exporter:mainb4bb8a9021a2
stdlib@go1.24.2
1.26.9

Open the chart page →

1,322
upyun-exporterdoubanVerified publisher0.1.21 of 1See more

upyun-exporter douban 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/douban/upyun-exporter:main6810900c9c4a
stdlib@go1.25.5
1.26.9

Open the chart page →

1,096
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.02 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.26.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.26.9

Open the chart page →

28,438
drogue-cloud-examplesdrogue-iotVerified publisher0.7.113 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

3 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.60.0
1.26.9
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
stdlib@go1.15.6
1.26.9
ghcr.io/ctron/kubectl:1.25e37d61b5277c
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

34,551
drogue-cloud-metricsdrogue-iotVerified publisher0.7.116 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

6 of the 8 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.60.0
1.26.9
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.26.9
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.26.9
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

20,186
drone-kubernetes-secretsdroneVerified publisher0.1.41 of 1See more

drone-kubernetes-secrets drone 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
drone/kubernetes-secrets:latest206df2280ecf
golang.org/x/net@v0.0.0-20180811021610-c39426892332
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

3,908
mtr-exporterdrpsychickVerified publisher0.0.51 of 1See more

mtr-exporter drpsychick 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/mgumz/mtr-exporter:0.4.0f4691c8fe8eb
stdlib@go1.22.8
1.26.9

Open the chart page →

756
piraeusdtrdnk-helm-chartsVerified publisher2.2.01 of 1See more

piraeus dtrdnk-helm-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/piraeusdatastore/piraeus-operator:v2.2.0ec4022c8b0e3
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

1,784
rook-cephdtrdnk-helm-chartsVerified publisher0.0.12 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.60.0
1.26.9
quay.io/cephcsi/ceph-csi-operator:v0.5.014fe2f1bffc3
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

2,839
tempo-operatordtrdnk-helm-chartsVerified publisher0.0.31 of 2See more

tempo-operator dtrdnk-helm-charts 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/grafana/tempo-operator/tempo-operator:v0.4.02627be646391
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.60.0
1.26.9

Open the chart page →

1,515
temporaldtrdnk-helm-chartsVerified publisher0.35.08 of 13See more

temporal dtrdnk-helm-charts 0.35.0

8 of the 13 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.60.0
1.26.9
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.26.9
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9
temporalio/admin-tools:1.22.4258958fe2ff2
golang.org/x/net@v0.8.0
stdlib@go1.20.10
0.60.0
1.26.9
temporalio/server:1.22.4c0a44c26397b
golang.org/x/net@v0.7.0
stdlib@go1.20.11
0.60.0
1.26.9
temporalio/ui:2.16.2af9c9349708f
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

28,079
cloudflaredduck-helm1.1.31 of 1See more

cloudflared duck-helm 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,968
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
stdlib@go1.22.6
1.26.9

Open the chart page →

4,211
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
stdlib@go1.20.12
1.26.9

Open the chart page →

5,165
duplicacyduplicacy0.1.31 of 2See more

duplicacy duplicacy 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
drumsergio/duplicacy-container:0.1.0dd3ee9703969
golang.org/x/net@v0.10.0
stdlib@go1.21.13
0.60.0
1.26.9

Open the chart page →

3,153
applause-btnduyet0.1.31 of 1See more

applause-btn duyet 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
duyetdev/applause-btn:latest25e59d223eaa
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.14.9
0.60.0
1.26.9

Open the chart page →

3,773
commentoduyet0.2.01 of 2See more

commento duyet 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/net@v0.0.0-20180811021610-c39426892332
stdlib@go1.14.2
0.60.0
1.26.9

Open the chart page →

3,910
kubernetes-database-scalerdvdlevanonVerified publisher0.1.21 of 1See more

kubernetes-database-scaler dvdlevanon 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dvdlevanon/kubernetes-database-scaler:v0.0.361e79c1643fe4
golang.org/x/net@v0.8.0
0.60.0

Open the chart page →

1,167
ai-scale-authdysnixVerified publisher0.1.12 of 3See more

ai-scale-auth dysnix 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alex6021710/ai-scale-auth:latest6c7a47e470c3
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.16.12
0.60.0
1.26.9
alex6021710/ai-scale-migrator:latest744b8a924f35
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

8,245
ai-scale-doerdysnixVerified publisher0.1.01 of 1See more

ai-scale-doer dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alex6021710/ai-scale-doer:latest31e533cf7cd3
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.16.10
0.60.0
1.26.9

Open the chart page →

3,828
ai-scale-providerdysnixVerified publisher0.1.01 of 1See more

ai-scale-provider dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alex6021710/ai-scale-provider:latest5837d9b30cc7
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.15.8
0.60.0
1.26.9

Open the chart page →

3,314
ai-scale-saverdysnixVerified publisher0.1.01 of 1See more

ai-scale-saver dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alex6021710/ai-scale-saver:latestf73e8d60fd03
golang.org/x/net@v0.0.0-20211105192438-b53810dc28af
stdlib@go1.17
0.60.0
1.26.9

Open the chart page →

3,202
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
golang.org/x/net@v0.21.0
stdlib@go1.21.10
0.60.0
1.26.9

Open the chart page →

10,364
bitcoinddysnixVerified publisher0.4.31 of 2See more

bitcoind dysnix 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
stdlib@go1.22.2
1.26.9

Open the chart page →

2,568
bordysnixVerified publisher0.0.81 of 1See more

bor dysnix 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
0xpolygon/bor:1.3.7396d3de26d8b
golang.org/x/net@v0.26.0
stdlib@go1.22.1
0.60.0
1.26.9

Open the chart page →

1,942
gcp-local-ssd-raiddysnixVerified publisher0.1.71 of 2See more

gcp-local-ssd-raid dysnix 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/net@v0.37.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

2,910
gke-upgrade-notification-handlerdysnixVerified publisher0.1.11 of 1See more

gke-upgrade-notification-handler dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.7
0.60.0
1.26.9

Open the chart page →

3,058
grafana-dashboardsdysnixVerified publisher0.2.21 of 2See more

grafana-dashboards dysnix 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:7.4.5d322192ed2fa
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.6
0.60.0
1.26.9

Open the chart page →

6,349
heimdalldysnixVerified publisher0.0.11 of 1See more

heimdall dysnix 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
0xpolygon/heimdall:1.0.134ddf259993c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

1,999
local-path-provisionerdysnixVerified publisher0.0.201 of 1See more

local-path-provisioner dysnix 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.16.6
0.60.0
1.26.9

Open the chart page →

3,997
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
stdlib@go1.16.12
1.26.9

Open the chart page →

6,934
servicemonitor-appsdysnixVerified publisher0.1.01 of 1See more

servicemonitor-apps dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

2,333
smokeping-proberdysnixVerified publisher0.3.11 of 1See more

smokeping-prober dysnix 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
superque/smokeping-prober:v0.11.028ca636d1dee
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

794
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,074
echoappechoapp0.1.01 of 1See more

echoapp echoapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/http-echo:1.0.0fcb75f691c8b
stdlib@go1.21.1
1.26.9

Open the chart page →

1,030

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
ethpandaops/tracoor:latest89424dbe2d6b
golang.org/x/net@v0.58.0
stdlib@go1.26.1
0.60.0
1.26.9
3
glanceapp/glance:latest:v0.8.69dfb09470b20
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
3
goharbor/harbor-core:v2.15.2d7b780d23721
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/harbor-jobservice:v2.15.2f71a4452a095
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/registry-photon:v2.15.2c4ebef61ceb5
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.60.0
1.26.9
3
grafana/grafana:13.1.0121a7a9ece6d
golang.org/x/net@v0.55.0
stdlib@go1.25.7
0.60.0
1.26.9
3
grafana/grafana:13.2.2-distroless69a5d2d957ca
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9
3
grafana/loki:3.7.8:latest1107dd5274e0
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
3
grafana/loki:3.6.1144148ad243c0
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
3
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.17.2
0.60.0
1.26.9
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
3
hashicorp/consul:2.0.41c59f007df8e
golang.org/x/net@v0.59.0
stdlib@go1.26.7
0.60.0
1.26.9
3
hashicorp/consul-k8s-control-plane:2.0.49334d7f4bcf0
golang.org/x/net@v0.59.0
stdlib@go1.26.7
0.60.0
1.26.9
3
hashicorp/http-echo:1.0.0:latestfcb75f691c8b
stdlib@go1.21.1
1.26.9
3
hashicorp/vault:2.0.45be49781ecf7
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
hashicorp/vault-k8s:1.7.655e27b080c9b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
3
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.26.9
3
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/net@v0.19.0
stdlib@go1.24.10
0.60.0
1.26.9
3
kubernetesui/dashboard-api:1.14.096a702cfd339
golang.org/x/net@v0.40.0
stdlib@go1.23.12
0.60.0
1.26.9
3
kubernetesui/dashboard-auth:1.4.053e9917898bf
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
3
kubernetesui/dashboard-metrics-scraper:1.2.25154b68252bd
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9
3
kubernetesui/dashboard-web:1.7.0cc7c31bd2d84
golang.org/x/net@v0.38.0
stdlib@go1.23.9
0.60.0
1.26.9
3
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9
3
l7mp/stunner-auth-server:devc4654dade66e
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
3
library/caddy:latestf2a1290d0463
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9
3
library/mongo:8:8.3.11:latest5d7043a4ffe0
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
library/mongo:7:7.09854f7139445
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
library/nats:2.10-alpineb83efabe3e7d
stdlib@go1.24.2
1.26.9
3
library/nats:latestcd3fcd4ecdda
stdlib@go1.27.1
1.27.2
3
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.26.9
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.26.9
3
library/postgres:14-alpine4ea9e5ed0659
stdlib@go1.24.6
1.26.9
3
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.26.9
3
library/postgres:1665b16a8b326e
stdlib@go1.24.6
1.26.9
3
library/postgres:18:18.6-trixie6737476511d4
stdlib@go1.24.6
1.26.9
3
library/postgres:15724292da1f2e
stdlib@go1.24.6
1.26.9
3
library/registry:3.1.1:latest1be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
3
library/traefik:v3.7.1324841fe2de73
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
mcp/grafana:latest9362bcf6aa0e
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
meshery/meshery:stable-latest44b64ee128fb
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
3
mikefarah/yq:2.4.16fc625c402de
stdlib@go1.13.3
1.26.9
3
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.17.4
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.