StackRadar

CVE-2026-78660

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
5 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r1no fix listed1
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-4c7c-vv7v-68rjCGA-8m3g-7799-mp4mCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-8p8v-px44-9x8q, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/net@v0.25.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

3,701
api-usage-cleanerapi-usage-cleaner1.16.01 of 1See more

api-usage-cleaner api-usage-cleaner 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.26.9

Open the chart page →

935
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.26.9
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.26.9

Open the chart page →

24,882
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.5
0.60.0
1.26.9
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.60.0
1.26.9
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.60.0
1.26.9

Open the chart page →

15,653
app-movies-seriesapp-movies-seriesVerified publisher0.1.01 of 2See more

app-movies-series app-movies-series 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.26.9

Open the chart page →

4,488
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

2,887
aceappscodeVerified publisher2026.9.112 of 2See more

ace appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

3,512
ace-installerappscodeVerified publisher2026.9.112 of 2See more

ace-installer appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

3,871
ace-installer-certifiedappscodeVerified publisher2026.9.112 of 2See more

ace-installer-certified appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
ghcr.io/appscode/b3:v2026.9.114b5993768740
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

4,039
acerproxyappscodeVerified publisher2026.9.111 of 1See more

acerproxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,753
aceshifterappscodeVerified publisher2026.9.111 of 1See more

aceshifter appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/aceshifter:v0.0.3e5f5c254a55a
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,415
appcatalogappscodeVerified publisher2023.3.231 of 1See more

appcatalog appscode 2023.3.23

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/appcatalog:v0.0.109709a346888
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

2,299
appscode-otel-stackappscodeVerified publisher2026.9.223 of 3See more

appscode-otel-stack appscode 2026.9.22

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.150.089490ef63b72
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

2,574
auditorappscodeVerified publisher2023.10.11 of 1See more

auditor appscode 2023.10.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

2,449
aws-credential-managerappscodeVerified publisher2026.4.161 of 1See more

aws-credential-manager appscode 2026.4.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/aws-credential-manager:v0.1.00511bbe501c3
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

910
azure-credential-managerappscodeVerified publisher2026.4.161 of 1See more

azure-credential-manager appscode 2026.4.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/azure-credential-manager:v0.1.0f5c797f7fbe7
golang.org/x/net@v0.49.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,189
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

2,887
capa-vpc-peering-operatorappscodeVerified publisher2023.12.111 of 1See more

capa-vpc-peering-operator appscode 2023.12.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

2,019
capi-ops-managerappscodeVerified publisher2024.8.142 of 2See more

capi-ops-manager appscode 2024.8.14

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
golang.org/x/net@v0.33.0
stdlib@go1.23.2
0.60.0
1.26.9
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.60.0
1.26.9

Open the chart page →

5,193
catalog-managerappscodeVerified publisher2026.9.111 of 1See more

catalog-manager appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/catalog-manager:v0.14.05e9a05238ed5
golang.org/x/net@v0.57.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

266
cattlesetappscodeVerified publisher2026.7.81 of 1See more

cattleset appscode 2026.7.8

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/cattleset:v0.0.145554a03e448
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

966
cert-manager-csi-driver-cacertsappscodeVerified publisher2026.9.183 of 3See more

cert-manager-csi-driver-cacerts appscode 2026.9.18

3 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/csi-driver-cacerts:v0.6.0ab213b156017
golang.org/x/net@v0.47.0
stdlib@go1.25.13
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

3,720
cert-manager-webhook-aceappscodeVerified publisher2026.9.111 of 1See more

cert-manager-webhook-ace appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/cert-manager-webhook-ace:v0.0.2dc6b5fdcec06
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,740
clickhouse-uiappscodeVerified publisher2026.3.301 of 1See more

clickhouse-ui appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/caioricciuti/ch-ui:v2.14.180f4d92c2d8d
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

128
cluster-auth-agentappscodeVerified publisher2026.2.161 of 1See more

cluster-auth-agent appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,360
cluster-auth-managerappscodeVerified publisher2026.2.161 of 1See more

cluster-auth-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,360
cluster-connectorappscodeVerified publisher2025.12.151 of 1See more

cluster-connector appscode 2025.12.15

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/cluster-connector:v0.0.140efd9d9ef6ca
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

982
cluster-gatewayappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

952
cluster-gateway-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

952
cluster-importerappscodeVerified publisher2026.9.111 of 1See more

cluster-importer appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/ace:v0.2.0b8e03da90e70
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,400
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,465
cluster-presetsappscodeVerified publisher2026.9.111 of 1See more

cluster-presets appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/cluster-presets:v0.0.128fbdd2479645
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

667
cluster-profile-managerappscodeVerified publisher2026.9.181 of 1See more

cluster-profile-manager appscode 2026.9.18

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-profile:v0.13.0b8b0aaef2543
golang.org/x/net@v0.58.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

320
cluster-proxyappscodeVerified publisher2024.2.251 of 1See more

cluster-proxy appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:latest27a5c64b7ea8
golang.org/x/net@v0.20.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,684
cluster-proxy-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-proxy-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:v0.10.1a7fce69e171c
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

2,193
crd-managerappscodeVerified publisher2026.10.101 of 1See more

crd-manager appscode 2026.10.10

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.4.04466bb77dc78
golang.org/x/net@v0.47.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

1,023
dns-proxyappscodeVerified publisher2026.9.111 of 1See more

dns-proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/cloudflare-dns-proxy:v0.0.5dfbef0285e14
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,017
docker-machine-operatorappscodeVerified publisher2024.7.91 of 1See more

docker-machine-operator appscode 2024.7.9

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/net@v0.14.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

2,878
external-dns-operatorappscodeVerified publisher2026.6.221 of 1See more

external-dns-operator appscode 2026.6.22

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/external-dns-operator:v0.4.05605f97e636d
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

603
falco-ui-serverappscodeVerified publisher2026.1.152 of 2See more

falco-ui-server appscode 2026.1.15

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/appscode/falco-ui-server:v0.0.66ec488d89b56
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

3,926
fargocdappscodeVerified publisher2026.9.181 of 1See more

fargocd appscode 2026.9.18

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/fargocd:v0.1.0c59d775d9a7c
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

653
fargocd-managerappscodeVerified publisher2026.9.181 of 1See more

fargocd-manager appscode 2026.9.18

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/fargocd:v0.1.0c59d775d9a7c
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

653
fluxcd-addon-managerappscodeVerified publisher2024.2.251 of 1See more

fluxcd-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/fluxcd-addon:v0.0.23acba3df8827
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,841
fluxcd-managerappscodeVerified publisher2026.9.181 of 1See more

fluxcd-manager appscode 2026.9.18

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/fluxcd-addon:v0.0.1137105f529ed0
golang.org/x/net@v0.47.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

612
gateway-converterappscodeVerified publisher2024.8.301 of 1See more

gateway-converter appscode 2024.8.30

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway-converter:v0.0.1b92123805584
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

1,761
gcp-credential-managerappscodeVerified publisher2026.3.111 of 1See more

gcp-credential-manager appscode 2026.3.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/gcp-credential-manager:v0.1.0b58345fe8209
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,403
gh-ci-webhookappscodeVerified publisher2026.9.111 of 1See more

gh-ci-webhook appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/gh-ci-webhook:v0.0.2036ce246d884e
golang.org/x/net@v0.33.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

1,922
grafanaappscodeVerified publisher2026.9.111 of 1See more

grafana appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

3,394
grafana-operatorappscodeVerified publisher2026.6.121 of 1See more

grafana-operator appscode 2026.6.12

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana-tools:v0.8.077c9d29080eb
golang.org/x/net@v0.52.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

558
grafana-opscenterappscodeVerified publisher2023.3.231 of 1See more

grafana-opscenter appscode 2023.3.23

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana-tools:v0.0.22c7b9b0a9101
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

2,143

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 5 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.16.10
0.60.0
1.26.9
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.15
0.60.0
1.26.9
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.60.0
1.26.9
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.60.0
1.26.9
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.26.9
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.19.2
0.60.0
1.26.9
3
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.26.9
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.26.9
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
stdlib@go1.21.5
0.60.0
1.26.9
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.10
0.60.0
1.26.9
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.9
0.60.0
1.26.9
3
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.60.0
1.26.9
3
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.26.9
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.0142a1f11df8d
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v3.10.07571a304e67f
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.60.0
1.26.9
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.60.0
1.26.9
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.60.0
1.26.9
3
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.60.0
1.26.9
3
quay.io/tigera/operator:v1.44.0066c2e8d6745
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
3
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.60.0
1.26.9
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.