StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
elastic-agentelasticVerified publisher9.5.51 of 2See more

elastic-agent elastic 9.5.5

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,257
kube-state-metricselasticVerified publisher6.1.01 of 1See more

kube-state-metrics elastic 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,257
netobserv-flowelastiflowVerified publisher0.12.01 of 1See more

netobserv-flow elastiflow 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
elastiflow/flow-collector:7.26.3d80d974a806e
golang.org/x/net@v0.53.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

1,467
seafileeleksbai0.1.12 of 3See more

seafile eleksbai 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:10.623616f0bd3af
stdlib@go1.24.6
1.26.9
seafileltd/seafile-mc:9.0.106693911bcc40
stdlib@go1.19
1.26.9

Open the chart page →

94,477
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
stdlib@go1.23.12
1.26.9

Open the chart page →

4,029
elsaelsa0.1.02 of 4See more

elsa elsa 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
geldata/gel:6b3a2815a3956
stdlib@go1.19.8
1.26.9
ghcr.io/stakater/reloader:v1.4.4a571c5b32c0f
golang.org/x/net@v0.39.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

5,473
rabbitmqemberstackVerified publisher1.0.221 of 1See more

rabbitmq emberstack 1.0.22

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/rabbitmq:management6ec83ef56205
stdlib@go1.22.2
1.26.9

Open the chart page →

1,348
emissary-ingressemissary-ingress4.1.01 of 1See more

emissary-ingress emissary-ingress 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,505
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

3,727
parrot-mirroremmas-chartsVerified publisher1.0.01 of 1See more

parrot-mirror emmas-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.60.0
1.26.9

Open the chart page →

3,005
cost-reportempathyco0.7.81 of 1See more

cost-report empathyco 0.7.8

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
empathyco/cost-report:0.0.124f1e26eaacbf
stdlib@go1.15.15
1.26.9

Open the chart page →

2,132
deadman-switchempathyco0.0.21 of 1See more

deadman-switch empathyco 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
stdlib@go1.16.3
1.26.9

Open the chart page →

2,286
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.26.9

Open the chart page →

11,945
yace-exporterempathyco0.1.01 of 1See more

yace-exporter empathyco 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
stdlib@go1.17.3
1.26.9

Open the chart page →

2,570
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
stdlib@go1.19.10
0.60.0
1.26.9

Open the chart page →

2,050
kube-ecp-stackemqx-operator2.5.111 of 16See more

kube-ecp-stack emqx-operator 2.5.1

11 of the 16 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
golang.org/x/net@v0.23.0
stdlib@go1.23.3
0.60.0
1.26.9
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/net@v0.30.0
stdlib@go1.22.0
0.60.0
1.26.9
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.60.0
1.26.9
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.60.0
1.26.9
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.1e2dc5623bcdd
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

31,310
cnpg-monitoringenixVerified publisher0.3.01 of 1See more

cnpg-monitoring enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

1,381
kube-packetloss-exporterenixVerified publisher0.2.12 of 2See more

kube-packetloss-exporter enix 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.60.0
1.26.9
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

7,738
mariadb-operator-monitoringenixVerified publisher0.1.01 of 1See more

mariadb-operator-monitoring enix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,230
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9

Open the chart page →

4,926
network-exporterenixVerified publisher0.3.01 of 1See more

network-exporter enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
syepes/network_exporter:1.8.000af1691570e
golang.org/x/net@v0.39.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

1,887
topomatikenixVerified publisher1.3.11 of 1See more

topomatik enix 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

2,677
zfs-exporterenixVerified publisher2.2.01 of 1See more

zfs-exporter enix 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/enix/zfs-exporter:2.3.1223b053f1cbd0
golang.org/x/net@v0.47.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,498
ai-gateway-helmenvoy-ai-gateway0.0.0-003ab39f36923b5d40609a601e2951b73f6318fb1 of 1See more

ai-gateway-helm envoy-ai-gateway 0.0.0-003ab39f36923b5d40609a601e2951b73f6318fb

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,347
eoapi-supporteoapiVerified publisher0.1.76 of 7See more

eoapi-support eoapi 0.1.7

6 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
grafana/grafana:10.3.38640e5038e83
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

12,952
backendeoc-chartsVerified publisher0.1.01 of 1See more

backend eoc-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/http-echo:latestfcb75f691c8b
stdlib@go1.21.1
1.26.9

Open the chart page →

1,082
databaseeoc-chartsVerified publisher0.1.01 of 1See more

database eoc-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:14-alpine4ea9e5ed0659
stdlib@go1.24.6
1.26.9

Open the chart page →

696
mariadbeoc-chartsVerified publisher0.3.141 of 1See more

mariadb eoc-charts 0.3.14

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.26.9

Open the chart page →

6,354
umbrella-appeoc-chartsVerified publisher0.1.02 of 3See more

umbrella-app eoc-charts 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hashicorp/http-echo:latestfcb75f691c8b
stdlib@go1.21.1
1.26.9
library/postgres:14-alpine4ea9e5ed0659
stdlib@go1.24.6
1.26.9

Open the chart page →

1,835
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.26.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.26.9

Open the chart page →

31,716
eoloPlanteolo-plannerVerified publisher0.1.03 of 7See more

eoloPlant eolo-planner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
library/mysql:885b9bf2e29cf
stdlib@go1.24.6
1.26.9

Open the chart page →

30,507
eoloplannereoloplannerVerified publisher0.1.03 of 7See more

eoloplanner eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.26.9
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.26.9

Open the chart page →

37,293
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.03 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

31,128
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.26.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.26.9

Open the chart page →

31,665
eoloplannereoloplanner-molynx-gat0.1.03 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.26.9
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.26.9

Open the chart page →

33,617
eolo-plannereolo-planner-repo0.1.03 of 7See more

eolo-planner eolo-planner-repo 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.26.9
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.26.9

Open the chart page →

33,069
eoloplanteoloplant1.0.03 of 7See more

eoloplant eoloplant 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

31,128
eoloplantseoloplants-urjcVerified publisher0.1.03 of 7See more

eoloplants eoloplants-urjc 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.26.9
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.26.9

Open the chart page →

32,836
servereoloserverVerified publisher0.1.03 of 7See more

server eoloserver 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.26.9
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.26.9

Open the chart page →

37,293
download-from-github-repoeosc-lot-1Verified publisher0.1.01 of 2See more

download-from-github-repo eosc-lot-1 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
golang.org/x/net@v0.15.0
stdlib@go1.21.10
0.60.0
1.26.9

Open the chart page →

1,579
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/git:v2.49.1c0280cf95723
golang.org/x/net@v0.45.0
stdlib@go1.24.8
0.60.0
1.26.9

Open the chart page →

74,272
mariadbeosc-lot-1Verified publisher0.2.01 of 2See more

mariadb eosc-lot-1 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:10.117db29378d4fd
stdlib@go1.24.6
1.26.9

Open the chart page →

2,816
mariadb-backupeosc-lot-1Verified publisher0.5.01 of 2See more

mariadb-backup eosc-lot-1 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:10.117db29378d4fd
stdlib@go1.24.6
1.26.9

Open the chart page →

2,816
mariadb-run-scripteosc-lot-1Verified publisher0.3.01 of 1See more

mariadb-run-script eosc-lot-1 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/mariadb:10.117db29378d4fd
stdlib@go1.24.6
1.26.9

Open the chart page →

2,816
postgresql-backupeosc-lot-1Verified publisher0.4.41 of 3See more

postgresql-backup eosc-lot-1 0.4.4

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.26.9

Open the chart page →

3,021
rabbitmqeosc-lot-1Verified publisher0.3.01 of 2See more

rabbitmq eosc-lot-1 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/rabbitmq:3.13-managemente582c0bc7766
stdlib@go1.22.2
1.26.9

Open the chart page →

3,288
rabbitmq-usereosc-lot-1Verified publisher0.1.01 of 1See more

rabbitmq-user eosc-lot-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
golang.org/x/net@v0.15.0
stdlib@go1.21.10
0.60.0
1.26.9

Open the chart page →

1,557
rsyslogeosc-lot-1Verified publisher0.2.11 of 2See more

rsyslog eosc-lot-1 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/logrotate:3-alpineb0e20d200f89
stdlib@go1.22.4
1.26.9

Open the chart page →

842
thanoseosc-lot-1Verified publisher0.2.01 of 1See more

thanos eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.39.21d022ef4b8ef
golang.org/x/net@v0.41.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

1,377
thanos-bucketeosc-lot-1Verified publisher0.1.01 of 1See more

thanos-bucket eosc-lot-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.39.21d022ef4b8ef
golang.org/x/net@v0.41.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

1,377

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.15
0.60.0
1.26.9
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.60.0
1.26.9
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.60.0
1.26.9
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.26.9
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.19.2
0.60.0
1.26.9
3
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.26.9
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.26.9
3
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
stdlib@go1.21.5
0.60.0
1.26.9
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.10
0.60.0
1.26.9
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.9
0.60.0
1.26.9
3
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.60.0
1.26.9
3
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.26.9
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.8.08a57af80a4c7
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.0142a1f11df8d
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-operator:v0.90.152a6a92d915e
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
3
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v3.10.07571a304e67f
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.60.0
1.26.9
3
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.60.0
1.26.9
3
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.60.0
1.26.9
3
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.60.0
1.26.9
3
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.60.0
1.26.9
3
quay.io/tigera/operator:v1.44.0066c2e8d6745
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
3
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.60.0
1.26.9
3
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
3
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.60.0
1.26.9
3
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.