StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
DEBIAN-CVE-2026-78663GO-2026-6612CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3x
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
docker-composecoderstudio-strapi-devVerified publisher0.0.12 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9

Open the chart page →

6,017
strapi-devcoderstudio-strapi-devVerified publisher0.0.12 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9

Open the chart page →

6,017
coder-ai-gatewaycoder-v2Verified publisher2.38.01 of 1See more

coder-ai-gateway coder-v2 2.38.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/coder/coder:v2.38.038a4cfc548b0
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

295
coder-provisionercoder-v2OfficialVerified publisher2.38.01 of 1See more

coder-provisioner coder-v2 2.38.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/coder/coder:v2.38.038a4cfc548b0
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

295
codiac-deployment-bundle-chartcodiac-deployment-bundle-chart0.0.151 of 1See more

codiac-deployment-bundle-chart codiac-deployment-bundle-chart 0.0.15

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
codiacimages/codiac-deployment-bundle:0.0.15d7d1e91eccde
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

756
cohdicohdi0.2.23 of 3See more

cohdi cohdi 0.2.2

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/cohdi/composable-resource-operator:v0.2.23f45bf0a1bc0
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/cohdi/dynamic-device-scaler:v0.2.2b487e1d74632
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

4,917
colecole1.4.21 of 1See more

cole cole 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ntakashi/cole:1.2.3f7b68bee2a68
golang.org/x/net@v0.10.0
stdlib@go1.20.11
0.60.0
1.26.9

Open the chart page →

1,421
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.60.0
1.26.9

Open the chart page →

3,413
collectordcollectordOfficialVerified publisher2604.5.01 of 1See more

collectord collectord 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

89
collectord-elasticsearchcollectord-elasticsearchOfficialVerified publisher2604.5.01 of 1See more

collectord-elasticsearch collectord-elasticsearch 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

89
collectord-opensearchcollectord-opensearchOfficialVerified publisher2604.5.01 of 1See more

collectord-opensearch collectord-opensearch 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

89
collectord-splunk-kubernetescollectord-splunk-kubernetesOfficialVerified publisher2604.5.01 of 1See more

collectord-splunk-kubernetes collectord-splunk-kubernetes 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

89
collectord-splunk-openshiftcollectord-splunk-openshiftOfficialVerified publisher2604.5.01 of 1See more

collectord-splunk-openshift collectord-splunk-openshift 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforopenshift:26.04.55959c31596a0
stdlib@go1.26.8
1.26.9

Open the chart page →

89
collectord-syslogcollectord-syslogOfficialVerified publisher2604.5.01 of 1See more

collectord-syslog collectord-syslog 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

89
mysqlcomet-mysql-helmVerified publisher1.0.81 of 1See more

mysql comet-mysql-helm 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.26.9

Open the chart page →

1,869
loki-stackcommon-chartsVerified publisher1.0.39 of 12See more

loki-stack common-charts 1.0.3

9 of the 12 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.0491b0578c049
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/grafana:13.1.17cb8c64c4d57
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
grafana/loki:3.6.1144148ad243c0
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.5d0e80b2f62fe
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

8,187
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

10,093
opencloudcommunity-opencloud3.2.02 of 13See more

opencloud community-opencloud 3.2.0

2 of the 13 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/tika:latest-fullab9cc988828c
stdlib@go1.26.7
1.26.9
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

10,313
community-operator-v2community-operator-v21.0.01 of 2See more

community-operator-v2 community-operator-v2 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.60.0
1.26.9

Open the chart page →

2,372
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

15,635
conjur-k8s-csi-providerconjure0.2.91 of 1See more

conjur-k8s-csi-provider conjure 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cyberark/conjur-k8s-csi-provider:latest737a967088d9
golang.org/x/net@v0.54.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

532
consentbbconsentbbVerified publisher2023.12.41 of 5See more

consentbb consentbb 2023.12.4

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
golang.org/x/net@v0.17.0
stdlib@go1.18.8
0.60.0
1.26.9

Open the chart page →

3,950
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,018
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

10,927
agent-forge-operatorcontainerooVerified publisher1.2.31 of 1See more

agent-forge-operator containeroo 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/agent-forge-operator:v1.2.32cec21162d6d
golang.org/x/net@v0.57.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

567
autovpacontainerooVerified publisher0.4.21 of 1See more

autovpa containeroo 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/autovpa:v0.0.3425b801d8d1f7
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

606
cert-manager-webhook-bluecatcontainerooVerified publisher1.0.21 of 1See more

cert-manager-webhook-bluecat containeroo 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/cert-manager-webhook-bluecat:latest96f82d5840d4
golang.org/x/net@v0.57.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

795
filesystem-exportercontainerooVerified publisher1.5.21 of 1See more

filesystem-exporter containeroo 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/filesystem-exporter:v1.5.2a66121e16d4e
stdlib@go1.26.1
1.26.9

Open the chart page →

1,718
kube-ephemeral-container-exportercontainerooVerified publisher0.2.31 of 1See more

kube-ephemeral-container-exporter containeroo 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/kube-ephemeral-container-exporter:v0.0.14b238f3c58d83
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

606
terrascalercontainerooVerified publisher0.1.01 of 1See more

terrascaler containeroo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/terrascaler:v0.1.0b152a8514bd3
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

394
containers-security-chartscontainers-security0.1.03 of 7See more

containers-security-charts containers-security 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.26.9
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.26.9
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.18.1
0.60.0
1.26.9

Open the chart page →

12,220
falcocontainers-security2.4.62 of 2See more

falco containers-security 2.4.6

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.26.9
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.26.9

Open the chart page →

4,355
homeboxcoo-ops-spaceVerified publisher0.1.61 of 1See more

homebox coo-ops-space 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/hay-kot/homebox:v0.9.2e6e0fbd7cca9
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

2,524
coordimap-agentcoordimap-agentVerified publisher0.4.31 of 1See more

coordimap-agent coordimap-agent 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
coordimap/coordimap-agent:latest7748fd0fae9f
golang.org/x/net@v0.38.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,090
cortex-proxycortex-proxyVerified publisher0.4.11 of 1See more

cortex-proxy cortex-proxy 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/peak-scale/observability-tenancy/cortex-proxy:0.4.11838720c13b2
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

844
cortezacorteza1.1.02 of 3See more

corteza corteza 1.1.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.60.0
1.26.9
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
stdlib@go1.23.5
1.26.9

Open the chart page →

10,139
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
golang.org/x/net@v0.21.0
stdlib@go1.19.13
0.60.0
1.26.9

Open the chart page →

5,560
cosanetcosanet1.0.01 of 1See more

cosanet cosanet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cosanet/cosanet:1.0.098cb5d9fa215
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

2,885
ociscosmicrocks0.7.01 of 2See more

ocis cosmicrocks 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
owncloud/ocis:7.1.388e7c854517d
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

2,492
cosmo-traefikcosmoVerified publisher0.9.11 of 2See more

cosmo-traefik cosmo 0.9.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/traefik:v2.10.11489caffaedb
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.60.0
1.26.9

Open the chart page →

4,412
dev-code-servercosmoVerified publisher0.0.72 of 2See more

dev-code-server cosmo 0.0.7

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/docker:dind7dcdfc4a2024
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

16,938
cospacecospace0.0.343 of 3See more

cospace cospace 0.0.34

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/redis:latest33a5a129cadc
stdlib@go1.26.8
1.26.9
library/mariadb:latestd4fdec0510ad
stdlib@go1.26.7
1.26.9
ghcr.io/twigex/cospace:lateste5ecfd607e42
golang.org/x/net@v0.50.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

4,992
couchbase-monitor-stackcouchbaseVerified publisher2.1.22 of 5See more

couchbase-monitor-stack couchbase 2.1.2

2 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:8.1.5b7dd9cd0e59d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.1
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.60.0
1.26.9

Open the chart page →

9,266
grafana-mcpcowboysysopVerified publisher2.0.01 of 1See more

grafana-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mcp/grafana:latest9362bcf6aa0e
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,654
katibcowboysysopVerified publisher2.4.23 of 4See more

katib cowboysysop 2.4.2

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.1
0.60.0
1.26.9
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
stdlib@go1.13.3
0.60.0
1.26.9
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

9,878
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.14
0.60.0
1.26.9

Open the chart page →

5,400
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
golang.org/x/net@v0.42.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

2,385
mariadbcowboysysopVerified publisher20.4.21 of 1See more

mariadb cowboysysop 20.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
stdlib@go1.23.7
1.26.9

Open the chart page →

3,648
metacontrollercowboysysopVerified publisher1.2.21 of 1See more

metacontroller cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
metacontrollerio/metacontroller:v2.1.10336993b88e4
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

3,084
mongodbcowboysysopVerified publisher15.1.51 of 1See more

mongodb cowboysysop 15.1.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
golang.org/x/net@v0.22.0
stdlib@go1.20.12
0.60.0
1.26.9

Open the chart page →

8,004

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.00d23a6fd60c4
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/livenessprobe:v2.20.019f2cf2f40e1
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.60.0
1.26.9
3
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.16.8
0.60.0
1.26.9
2
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.26.9
2
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/net@v0.33.0
stdlib@go1.24.13
0.60.0
1.26.9
2
alpine/git:latest:v2.54.0832b1cd1a271
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
2
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
2
alpine/k8s:1.37.0b421c2e9419e
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
2
alpine/kubectl:1.35.49ccd82364762
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
2
alpine/kubectl:1.35.2ec8f734b0a10
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.60.0
1.26.9
2
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.13.15
0.60.0
1.26.9
2
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.13.15
0.60.0
1.26.9
2
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.60.0
1.26.9
2
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.60.0
1.26.9
2
amazon/aws-fsx-csi-driver:latestc9b14856fd22
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.60.0
1.26.9
2
apache/doris:operator-latest3a4422656592
golang.org/x/net@v0.33.0
stdlib@go1.23.12
0.60.0
1.26.9
2
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.60.0
1.26.9
2
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.60.0
1.26.9
2
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9
2
apecloud/apecloud-mcp:0.1.094041b080510
stdlib@go1.23.7
1.26.9
2
apecloud/servicemirror:0.5.38c8451abf728
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9
2
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.60.0
1.26.9
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.9
0.60.0
1.26.9
2
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
golang.org/x/net@v0.25.0
stdlib@go1.22.2
0.60.0
1.26.9
2
binwiederhier/ntfy:v2.29.04c599cf08189
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
bitnami/git:latest27e3b3fe7123
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.6
0.60.0
1.26.9
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
stdlib@go1.23.7
1.26.9
2
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
stdlib@go1.15.1
1.26.9
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.26.9
2
bitnamilegacy/redis:latest5927ff3702df
stdlib@go1.24.5
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.