StackRadar

CVE-2026-78662

Unscored

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,012
of 17,797 indexed, latest versions
Container images
3,391
deployed by those charts
Fix available
1 of 1
affected package

Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

Carried by container images the latest versions of 3,012 of 17,797 indexed charts deploy, on 3,391 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+157 more0.56.03,391
OSV records
GO-2026-6354
Trending
Rank 44 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

3,012 by stars
ChartLatestAffected imagesRadar Score
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
golang.org/x/crypto@v0.7.0
0.56.0

Open the chart page →

7,714
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
golang.org/x/crypto@v0.7.0
0.56.0

Open the chart page →

1,998
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
golang.org/x/crypto@v0.13.0
0.56.0

Open the chart page →

1,955
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
golang.org/x/crypto@v0.54.0
0.56.0
murtazashah46/helmfile:latest4d11726cf803
golang.org/x/crypto@v0.5.0
0.56.0

Open the chart page →

13,813
ygdrassil-monitoringygdrassilVerified publisher0.4.07 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

7 of the 10 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
golang.org/x/crypto@v0.32.0
0.56.0
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/crypto@v0.31.0
0.56.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/crypto@v0.31.0
0.56.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/crypto@v0.21.0
0.56.0
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/crypto@v0.31.0
0.56.0
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/crypto@v0.32.0
0.56.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/crypto@v0.28.0
0.56.0

Open the chart page →

9,401
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
golang.org/x/crypto@v0.22.0
0.56.0

Open the chart page →

1,610
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/crypto@v0.0.0-20211115234514-b4de73f9ece8
0.56.0

Open the chart page →

1,965
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.56.0
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.56.0

Open the chart page →

8,000
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.56.0

Open the chart page →

3,024
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
golang.org/x/crypto@v0.52.0
0.56.0
quay.io/prometheus/alertmanager:latest690c7b525f43
golang.org/x/crypto@v0.54.0
0.56.0
quay.io/prometheus/prometheus:latest5ce7540c3c00
golang.org/x/crypto@v0.54.0
0.56.0

Open the chart page →

899
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.56.0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.56.0

Open the chart page →

5,047
zahori-moonzahoriVerified publisher1.0.11 of 3See more

zahori-moon zahori 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-78662.

Container imageDigestPackageFixed in
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/crypto@v0.10.0
0.56.0

Open the chart page →

2,908

Container images carrying it

3,391 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/mysqld-exporter:latest:v0.20.0abed8dac117b
golang.org/x/crypto@v0.54.0
0.56.0
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.56.0
4
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/crypto@v0.36.0
0.56.0
4
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/crypto@v0.53.0
0.56.0
4
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/crypto@v0.38.0
0.56.0
4
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
golang.org/x/crypto@v0.53.0
0.56.0
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/crypto@v0.22.0
0.56.0
4
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
golang.org/x/crypto@v0.52.0
0.56.0
4
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.56.0
3
alpine/git:latest:v2.54.06f3b5029566d
golang.org/x/crypto@v0.52.0
0.56.0
3
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.56.0
3
binwiederhier/ntfy:v2.28.06ef4b819f722
golang.org/x/crypto@v0.55.0
0.56.0
3
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.56.0
3
bitnami/mongodb:latest9aa916500f02
golang.org/x/crypto@v0.54.0
0.56.0
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/crypto@v0.14.0
0.56.0
3
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.56.0
3
cloudflare/cloudflared:2026.8.3:latest51c9cefcb456
golang.org/x/crypto@v0.53.0
0.56.0
3
cloudflare/cloudflared:2026.9.1b269e8abd07a
golang.org/x/crypto@v0.53.0
0.56.0
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/crypto@v0.43.0
0.56.0
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.56.0
3
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/crypto@v0.32.0
0.56.0
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.56.0
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
golang.org/x/crypto@v0.45.0
0.56.0
3
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/crypto@v0.53.0
0.56.0
3
ethpandaops/tracoor:latestd8514b9f4c59
golang.org/x/crypto@v0.38.0
0.56.0
3
goharbor/harbor-core:v2.15.2d7b780d23721
golang.org/x/crypto@v0.52.0
0.56.0
3
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
golang.org/x/crypto@v0.52.0
0.56.0
3
goharbor/registry-photon:v2.15.2c4ebef61ceb5
golang.org/x/crypto@v0.52.0
0.56.0
3
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/crypto@v0.53.0
0.56.0
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.56.0
3
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/crypto@v0.21.0
0.56.0
3
grafana/grafana:13.2.1-distroless3600073f45a9
golang.org/x/crypto@v0.52.0
0.56.0
3
grafana/grafana:13.1.17cb8c64c4d57
golang.org/x/crypto@v0.52.0
0.56.0
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/crypto@v0.27.0
0.56.0
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/crypto@v0.32.0
0.56.0
3
grafana/loki:3.7.7:latestd70e4659623f
golang.org/x/crypto@v0.55.0
0.56.0
3
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/crypto@v0.45.0
0.56.0
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.56.0
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.56.0
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/crypto@v0.45.0
0.56.0
3
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/crypto@v0.17.0
0.56.0
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/crypto@v0.2.0
0.56.0
3
library/nats:2.14.6-alpinead7a43eb7e33
golang.org/x/crypto@v0.55.0
0.56.0
3
library/nats:2.10-alpineb83efabe3e7d
golang.org/x/crypto@v0.37.0
0.56.0
3
library/nats:latestd4a8980c1ee5
golang.org/x/crypto@v0.55.0
0.56.0
3
louislam/uptime-kuma:2.5.4917318f9d7be
golang.org/x/crypto@v0.51.0
0.56.0
3
migrate/migrate:latestcc4ad8e19d66
golang.org/x/crypto@v0.45.0
0.56.0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/crypto@v0.0.0-20201124201722-c8d3bf9c5392
0.56.0
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.56.0
3
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/crypto@v0.31.0
0.56.0
3

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.