StackRadar

CVE-2026-78660

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 transport accepts malformed framing-related headers in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4487-7phw-q6phCGA-8m3g-7799-mp4mCGA-8p8v-px44-9x8qCGA-8vqq-r2ff-395mCGA-f7qm-qm58-qq95CGA-gwrf-q2qw-xxw8DEBIAN-CVE-2026-78660GO-2026-6610
Also known as
CGA-35vx-wppw-x7qp, CGA-3h29-84h2-fpvm, CGA-4c7c-vv7v-68rj, CGA-549w-3rfh-p826, CGA-5m57-vjc9-f9p9, CGA-674h-jc7r-4mj3, CGA-69vp-383p-x5ch, CGA-75m2-prw5-hwgv, CGA-77wf-8wxg-xgm9, CGA-ch87-vjh7-q5c4, CGA-f6rm-vx2j-c4p8, CGA-g5qq-3wrm-946q, CGA-hhf5-4h2f-jxg6, CGA-hmfx-cqg4-6jpq, CGA-hw83-h7jc-7pmj, CGA-pxv9-259f-f7j4, CGA-q8wf-wv9q-7fmv, CGA-qfx8-xwj3-frq2, CGA-qp96-gpwf-9v2h, CGA-qrx4-5cp4-7xhr, CGA-rpwc-c4h5-9frv, CGA-rr68-65r8-g5vv, CGA-v6p6-9m54-x5pc, CGA-x66q-68px-v2f4, CGA-x9jv-g6mg-h4jq, CGA-xjhf-9jv7-7x78
Trending
Rank 9 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
krateo-frontendkrateo2.4.21 of 1See more

krateo-frontend krateo 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/krateo-frontend:2.4.26aff913c8bfe
stdlib@go1.23.8
1.26.9

Open the chart page →

3,839
kserve-controllerkrateo1.0.01 of 1See more

kserve-controller krateo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/kserve-controller:1.0.05683c5ae670e
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

667
kube-bridgekrateo1.0.01 of 1See more

kube-bridge krateo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/kube-bridge:1.0.0839e6b3f1a33
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18
0.60.0
1.26.9

Open the chart page →

2,428
logs-presenterkrateo0.1.01 of 1See more

logs-presenter krateo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/logs-presenter:0.1.0c52fa557d1d0
golang.org/x/net@v0.51.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

542
mlflow-providerkrateo0.0.31 of 1See more

mlflow-provider krateo 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/mlflow-rest-dynamic-controller-plugin:0.0.31106a62d1c06
golang.org/x/net@v0.23.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

985
mlflow-provider-kogkrateo0.0.71 of 1See more

mlflow-provider-kog krateo 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/mlflow-rest-dynamic-controller-plugin:0.0.7887968d0ba9c
golang.org/x/net@v0.23.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

985
oasgen-providerkrateo0.11.11 of 1See more

oasgen-provider krateo 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/oasgen-provider:0.10.0656ec60c6407
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

5,554
opa-kube-mgmtkrateo0.2.32 of 2See more

opa-kube-mgmt krateo 0.2.3

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/kube-mgmt:9.0.1482a00656c34
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.60.0
1.26.9
ghcr.io/krateoplatformops/opa:1.4.2-static3c995dc8a59f
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

2,638
opentofu-providerkrateo1.1.01 of 1See more

opentofu-provider krateo 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/opentofu-provider:1.1.09fa6736c91f2
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,111
patch-providerkrateo1.0.11 of 1See more

patch-provider krateo 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/patch-provider:1.0.00924cf45a3e9
golang.org/x/net@v0.27.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,111
resources-ingesterkrateo1.1.01 of 1See more

resources-ingester krateo 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/resources-ingester:1.1.0534777443059
golang.org/x/net@v0.52.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

813
resources-presenterkrateo0.10.41 of 1See more

resources-presenter krateo 0.10.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/resources-presenter:0.10.44900c4644aed
golang.org/x/net@v0.52.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

444
resource-tree-handlerkrateo0.3.01 of 1See more

resource-tree-handler krateo 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/resource-tree-handler:0.3.0e4bc3216769e
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,176
smitherykrateo0.10.11 of 1See more

smithery krateo 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/smithery:0.10.181a28a5959e0
golang.org/x/net@v0.38.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

1,705
snowplowkrateo0.20.71 of 1See more

snowplow krateo 0.20.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/snowplow:0.20.76aa36cff9bb7
golang.org/x/net@v0.38.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

756
status-informerkrateo0.1.11 of 1See more

status-informer krateo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/status-informer:0.1.14a8b40f4a050
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.60.0
1.26.9

Open the chart page →

1,978
sweeperkrateo0.2.12 of 2See more

sweeper krateo 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
alpine/kubectl:1.36.01ee9df6316d4
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9
ghcr.io/krateoplatformops/eventstack/sweeper:0.1.05d5e24119ff1
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

2,336
terraform-servicekrateo0.1.101 of 1See more

terraform-service krateo 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/terraform-service:0.1.105e731a23e703
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.60.0
1.26.9

Open the chart page →

3,849
vcluster-k8skrateo0.19.64 of 4See more

vcluster-k8s krateo 0.19.6

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/ghcr.io/loft-sh/vcluster:0.19.68849703f0ff8
golang.org/x/net@v0.17.0
stdlib@go1.22.4
0.60.0
1.26.9
ghcr.io/krateoplatformops/registry.k8s.io/etcd:3.5.10-03486c0f32467
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
ghcr.io/krateoplatformops/registry.k8s.io/kube-apiserver:v1.29.086076b5576c7
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/krateoplatformops/registry.k8s.io/kube-controller-manager:v1.29.067b0ece5573e
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

8,669
vm-azurekrateo0.1.21 of 1See more

vm-azure krateo 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/kubectl:1.32.0d69cd9c163db
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,796
krokro0.9.41 of 1See more

kro kro 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/kro/kro:v0.9.4eaf9fbaddd9d
golang.org/x/net@v0.58.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

363
kubeflowkromanow94-kubeflow0.5.117 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

17 of the 30 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
kubeflow/model-registry:v0.2.95783f6db428f
golang.org/x/net@v0.28.0
stdlib@go1.21.13
0.60.0
1.26.9
kubeflow/training-operator:v1-04f9f13dabb76dbda29
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
kubeflowkatib/katib-controller:v0.17.072f14e03b9e1
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
kubeflowkatib/katib-db-manager:v0.17.0916a7695b0dd
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
kubeflowkatib/katib-ui:v0.17.07a41c508deb1
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
kubeflownotebookswg/kfam:v1.9.22060a2ede788
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/poddefaults-webhook:v1.9.2bde88d98ad74
golang.org/x/net@v0.13.0
stdlib@go1.21.13
0.60.0
1.26.9
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/pvcviewer-controller:v1.9.29815e9b1728f
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9
kubeflownotebookswg/tensorboard-controller:v1.9.26536a9f61193
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.60.0
1.26.9
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9

Open the chart page →

86,921
kron-aapm-sidecarkron-aapm-sidecar1.1.01 of 1See more

kron-aapm-sidecar kron-aapm-sidecar 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.60.0
1.26.9

Open the chart page →

3,096
adventureworkskronkltdVerified publisher0.1.01 of 1See more

adventureworks kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
chriseaton/adventureworks:latest54c3384ce701
stdlib@go1.23.1
1.26.9

Open the chart page →

5,385
lndkronkltdVerified publisher0.3.93 of 4See more

lnd kronkltd 0.3.9

3 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.1
0.60.0
1.26.9
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.60.0
1.26.9
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

12,049
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
stdlib@go1.20.13
1.26.9

Open the chart page →

11,961
world-dbkronkltdVerified publisher0.1.01 of 1See more

world-db kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghusta/postgres-world-db:latest879d0919fdcc
stdlib@go1.24.6
1.26.9

Open the chart page →

2,424
kron-aapm-sidecarkron-pam-aapm-helmcharts1.2.71 of 1See more

kron-aapm-sidecar kron-pam-aapm-helmcharts 1.2.7

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.2.18b42fad987b3
golang.org/x/net@v0.57.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

536
casdoorkrzwiatrzyk1.0.01 of 1See more

casdoor krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
casbin/casdoor:v1.224.066f836ef778b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.5
0.60.0
1.26.9

Open the chart page →

4,724
nocodbkrzwiatrzyk0.0.11 of 1See more

nocodb krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
nocodb/nocodb:0.100.2b0b91ec2a2dd
golang.org/x/net@v0.0.0-20220805013720-a33c5aa5df48
stdlib@go1.18.2
0.60.0
1.26.9

Open the chart page →

3,314
pipecdkrzwiatrzyk0.39.01 of 3See more

pipecd krzwiatrzyk 0.39.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.6
0.60.0
1.26.9

Open the chart page →

5,092
postgresql-backup-to-miniokrzwiatrzyk0.0.11 of 2See more

postgresql-backup-to-minio krzwiatrzyk 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.26.9

Open the chart page →

3,716
traggokrzwiatrzyk1.0.01 of 1See more

traggo krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
traggo/server:0.2.3f1ced637510e
stdlib@go1.13.1
1.26.9

Open the chart page →

3,036
ksoc-pluginsksocOfficialVerified publisher1.9.105 of 5See more

ksoc-plugins ksoc 1.9.10

5 of the 5 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/n8h5y2v5/rad-security/rad-bootstrapper:v1.1.115ca2d500d374
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/n8h5y2v5/rad-security/rad-guard:v1.1.17a94d2d4aae85
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/n8h5y2v5/rad-security/rad-sync:v1.1.1514f3dfbc0225
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/n8h5y2v5/rad-security/rad-watch:v1.1.25b9a7d6bc2a0c
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

5,896
authorino-operatorkuadrantOfficialVerified publisher0.27.01 of 1See more

authorino-operator kuadrant 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kuadrant/authorino-operator:v0.27.02f1802c0f8d0
golang.org/x/net@v0.55.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

271
dns-operatorkuadrantOfficialVerified publisher0.18.01 of 1See more

dns-operator kuadrant 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kuadrant/dns-operator:v0.18.0bda96d422195
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

242
limitador-operatorkuadrantOfficialVerified publisher0.19.01 of 1See more

limitador-operator kuadrant 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
quay.io/kuadrant/limitador-operator:v0.19.09d55a070ba54
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

201
kubeadapt-k8s-pulsekubeadaptVerified publisher1.0.21 of 1See more

kubeadapt-k8s-pulse kubeadapt 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
stdlib@go1.25.9
1.26.9

Open the chart page →

2,961
kubearmor-operatorkubearmor1.7.51 of 1See more

kubearmor-operator kubearmor 1.7.5

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubearmor/kubearmor-operator:v1.7.5f5d21795c0d7
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

243
sidekickkubearmor0.1.01 of 1See more

sidekick kubearmor 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubearmor/sidekick:latestb7b92a447f15
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

2,651
bc-depositorykubebb0.0.31 of 1See more

bc-depository kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

2,738
bc-explorerkubebb0.0.31 of 1See more

bc-explorer kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

2,738
chartmuseumkubebb3.10.21 of 1See more

chartmuseum kubebb 3.10.2

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

3,018
cluster-componentkubebb0.2.24 of 4See more

cluster-component kubebb 0.2.2

4 of the 4 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
kubebb/cert-manager-controller:v1.8.020509de4b399
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.60.0
1.26.9

Open the chart page →

12,302
fabric-operatorkubebb0.1.01 of 1See more

fabric-operator kubebb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.4
0.60.0
1.26.9

Open the chart page →

4,955
ingress-nginxkubebb4.7.02 of 2See more

ingress-nginx kubebb 4.7.0

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
golang.org/x/net@v0.10.0
stdlib@go1.20.1
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9

Open the chart page →

4,642
kubebbkubebb0.0.11 of 1See more

kubebb kubebb 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubebb/core:lateste366c34a9b8d
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9

Open the chart page →

2,435
kubebb-corekubebb0.1.271 of 1See more

kubebb-core kubebb 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubebb/core:v0.1.62b9e7f451d6b
golang.org/x/net@v0.14.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

2,629
miniokubebb5.0.102 of 2See more

minio kubebb 5.0.10

2 of the 2 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

9,468
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2026-78660.

Container imageDigestPackageFixed in
kubebb/mesh-operator:v5.7.0163ebbfc7a82
golang.org/x/net@v0.7.0
stdlib@go1.18.4
0.60.0
1.26.9

Open the chart page →

7,515

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9
91
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
37
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9
36
library/postgres:18:18.6:18.6-trixie:latest74935e722416
stdlib@go1.24.6
1.26.9
31
library/postgres:16.15-alpine:16-alpine721873c34ceb
stdlib@go1.24.6
1.26.9
21
jenkins/jenkins:2.580.1-jdk21:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2
19
library/postgres:18:18.6-trixie:latestfc973eb97c9f
stdlib@go1.24.6
1.26.9
19
quay.io/prometheus/prometheus:latest:v3.15.0efd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
19
library/postgres:18:18.6:18.6-trixie:latest5a5a84b19854
stdlib@go1.24.6
1.26.9
18
library/postgres:18.6-alpine:18.6-alpine3.24:18-alpine:alpine77f585114c32
stdlib@go1.24.6
1.26.9
18
library/mysql:8:8.4:8.4.116ea90827b110
stdlib@go1.24.6
1.26.9
17
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
15
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9
14
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.26.9
14
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9
14
quay.io/prometheus/node-exporter:latest:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
14
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
13
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9
13
bitnami/mongodb:latestad05bb9a19fa
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
12
grafana/grafana:latestb28bae15e219
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
12
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9
12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
12
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
12
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
12
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.26.9
11
ethpandaops/xatu:latestef8eb43af9bb
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
10
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
10
library/mariadb:13.0.2:latestf1bba652ba57
stdlib@go1.26.7
1.26.9
10
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.26.9
10
library/mongo:9.0.2:latestbac22ea7710d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
10
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
10
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
9
library/mysql:26.7.0:latest9d48c42f8341
stdlib@go1.24.6
1.26.9
9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
9
ghcr.io/quenchworks/images/grafana4b7e7a134283
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
9
ghcr.io/quenchworks/images/kubectl4033ac5e5f35
golang.org/x/net@v0.57.0
helm-4@4.3.0-r0
kubernetes-1.37@1.37.1-r0
stdlib@go1.27.1
0.60.0
4.3.0-r2
1.37.1-r2
1.27.2
9
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9
8
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9
8
library/rabbitmq:3.13-management:3-managemente582c0bc7766
stdlib@go1.22.2
1.26.9
8
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9
8
quay.io/prometheus/alertmanager:latest:v0.34.1e9733bafb1bd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
8
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
8
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
8
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
8
bitnami/kubectl:latest999d5eb28f40
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
7
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9
7
bitnami/nginx:latestb8d42f076789
stdlib@go1.26.8
1.26.9
7
library/ubuntu:latestf144425ff09b
stdlib@go1.26.7
1.26.9
7
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.60.0
1.26.9
7

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.