StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
GO-2026-6612CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
kubevirt-cloud-controller-managerchristianhuthVerified publisher0.0.21 of 1See more

kubevirt-cloud-controller-manager christianhuth 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,000
kubevirt-managerchristianhuthVerified publisher0.7.01 of 1See more

kubevirt-manager christianhuth 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,435
mailcow-exporterchristianhuthVerified publisher1.5.01 of 1See more

mailcow-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
stdlib@go1.23.12
1.26.9

Open the chart page →

1,143
netbird-reverse-proxychristianhuthVerified publisher0.1.01 of 1See more

netbird-reverse-proxy christianhuth 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
netbirdio/reverse-proxy:0.72.43104d5ca3a76
golang.org/x/net@v0.53.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,328
netcupscp-exporterchristianhuthVerified publisher2.1.01 of 1See more

netcupscp-exporter christianhuth 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/mrueg/netcupscp-exporter:v0.5.25b86c2c0b0e0
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

274
nextcloud-exporterchristianhuthVerified publisher1.5.01 of 1See more

nextcloud-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
xperimental/nextcloud-exporter:0.9.13e90a3897651
stdlib@go1.26.1
1.26.9

Open the chart page →

431
ntp-exporterchristianhuthVerified publisher1.4.01 of 1See more

ntp-exporter christianhuth 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/sapcc/ntp_exporter:v2.9.079c40c65f5d4
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

771
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.26.9

Open the chart page →

6,653
promlenschristianhuthVerified publisher1.6.01 of 1See more

promlens christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/promlens:v0.4.04a377d1a0eaa
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

339
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

3,352
arbitrumchronicleVerified publisher0.3.51 of 1See more

arbitrum chronicle 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

8,015
basechronicleVerified publisher0.0.91 of 1See more

base chronicle 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/net@v0.30.0
stdlib@go1.22.10
0.60.0
1.26.9

Open the chart page →

5,702
ethereumchronicleVerified publisher0.3.21 of 1See more

ethereum chronicle 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

1,744
ethereum-metrics-exporterchronicleVerified publisher0.1.51 of 1See more

ethereum-metrics-exporter chronicle 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
samcm/ethereum-metrics-exporter:0.29.291a2d9a015c1
golang.org/x/net@v0.43.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

991
goferchronicleVerified publisher0.4.51 of 1See more

gofer chronicle 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/gofer:0.613915d2e41e04
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,301
mantlechronicleVerified publisher0.1.41 of 1See more

mantle chronicle 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9

Open the chart page →

2,756
sith-exporterschronicleVerified publisher0.2.61 of 1See more

sith-exporters chronicle 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/oracles-updates-exporter:0.0.4992d0e793af6
stdlib@go1.19.13
1.26.9

Open the chart page →

1,497
spirechronicleVerified publisher0.3.71 of 1See more

spire chronicle 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,010
zksyncchronicleVerified publisher0.1.21 of 2See more

zksync chronicle 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:143e7dd0bfd7bf
stdlib@go1.24.6
1.26.9

Open the chart page →

7,117
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9

Open the chart page →

4,833
ciliumcilium21.20.23 of 3See more

cilium cilium2 1.20.2

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.22939231d0d3e
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82af7382699576
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/cilium/operator-generic:v1.20.264d8798350e8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,840
tetragoncilium21.7.12 of 3See more

tetragon cilium2 1.7.1

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/cilium/tetragon-operator:v1.7.1cd8b71f6860e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

512
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/chekrdigest-pinnedf299baf467b5
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

4,567
vulnerability-operatorckotzbauerVerified publisher0.31.151 of 1See more

vulnerability-operator ckotzbauer 0.31.15

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/vulnerability-operator:0.28.167008df32715c
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

442
clairclair-helmVerified publisher0.12.02 of 3See more

clair clair-helm 0.12.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9
quay.io/projectquay/clair:4.9.023329c3368e4
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

2,335
calico-cniclastixVerified publisher3.28.13 of 3See more

calico-cni clastix 3.28.1

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
calico/cni:v3.28.1e486870cfde8
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

4,584
capi-kamaji-vsphere-fullclastixVerified publisher1.0.19 of 9See more

capi-kamaji-vsphere-full clastix 1.0.1

9 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/net@v0.32.0
stdlib@go1.23.0
0.60.0
1.26.9
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

10,135
capsule-rancher-addonclastixVerified publisher0.1.15 of 5See more

capsule-rancher-addon clastix 0.1.1

5 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/net@v0.4.0
stdlib@go1.19.2
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

10,934
kamajiclastixVerified publisher0.0.0+latest3 of 4See more

kamaji clastix 0.0.0+latest

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
clastix/kamaji:latestbb4bd5e1d9eb
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.60.0
1.26.9

Open the chart page →

6,450
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
golang.org/x/net@v0.23.0
stdlib@go1.23.7
0.60.0
1.26.9

Open the chart page →

3,350
kamaji-etcdclastixVerified publisher0.18.12 of 4See more

kamaji-etcd clastix 0.18.1

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.60.0
1.26.9

Open the chart page →

14,697
local-path-provisionerclastixVerified publisher0.0.301 of 1See more

local-path-provisioner clastix 0.0.30

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

1,672
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.60.0
1.26.9
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

11,743
cloudflare-ddnsclouddrove0.1.51 of 1See more

cloudflare-ddns clouddrove 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
favonia/cloudflare-ddns:15e61736b982b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
cloudflared-tunnelclouddrove0.1.41 of 1See more

cloudflared-tunnel clouddrove 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

2,350
cronjobclouddrove1.0.11 of 1See more

cronjob clouddrove 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/ubuntu:latestf144425ff09b
stdlib@go1.26.7
1.26.9

Open the chart page →

610
kube-acp-stackcloudentity2.29.13 of 7See more

kube-acp-stack cloudentity 2.29.1

3 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
stdlib@go1.23.8
1.26.9
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/net@v0.33.0
stdlib@go1.21.13
0.60.0
1.26.9
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.60.0
1.26.9

Open the chart page →

24,606
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.60.0
1.26.9
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.60.0
1.26.9
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.16.6
0.60.0
1.26.9
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

24,753
cloudflare-ddns-updatecloudflare-ddns-update0.1.21 of 1See more

cloudflare-ddns-update cloudflare-ddns-update 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,829
cloudflare-dyndnscloudflare-dyndnsVerified publisher1.1.01 of 1See more

cloudflare-dyndns cloudflare-dyndns 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/msueberkrueb/cloudflare-dyndns:1.0.0e5c945a3b000
stdlib@go1.25.1
1.26.9

Open the chart page →

622
cloudflare-tunnel-ingress-controllercloudflare-tunnel-ingress-controller0.2.31 of 1See more

cloudflare-tunnel-ingress-controller cloudflare-tunnel-ingress-controller 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/oliverbaehler/cloudflare-tunnel-ingress-controller:0.2.30aec31e36d95
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9

Open the chart page →

873
cloudfront-tenant-operatorcloudfront-tenant-operatorVerified publisher0.3.01 of 1See more

cloudfront-tenant-operator cloudfront-tenant-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

566
hcloud-ccm-mgmtcloudhippieVerified publisher1.13.01 of 1See more

hcloud-ccm-mgmt cloudhippie 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.39.0d6fee5698759
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

238
hcloud-csi-mgmtcloudhippieVerified publisher2.11.05 of 5See more

hcloud-csi-mgmt cloudhippie 2.11.0

5 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.13.0d1a26170efed
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.4.06ebe60fd8ed6
golang.org/x/net@v0.59.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.3.048fb3deb93cd
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.20.019f2cf2f40e1
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

953
hcloud-csi-usercloudhippieVerified publisher1.8.03 of 3See more

hcloud-csi-user cloudhippie 1.8.0

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.18.0b7fefd08651f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.20.019f2cf2f40e1
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

668
cloudian-exportercloudian-exporter0.1.41 of 1See more

cloudian-exporter cloudian-exporter 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/dodevops/cloudian-exporter:0.1.18b7f2816541c
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,311
mercurecloudnativeapp1.0.21 of 1See more

mercure cloudnativeapp 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dunglas/mercure:v0916834e49961
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,403
nginx-ingress-controllercloudnativeapp3.4.51 of 2See more

nginx-ingress-controller cloudnativeapp 3.4.5

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/nginx:latestb8d42f076789
stdlib@go1.26.8
1.26.9

Open the chart page →

111
argocd-operatorcloud-native-toolkit0.6.11 of 1See more

argocd-operator cloud-native-toolkit 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

141
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/net@v0.14.0
stdlib@go1.19.10
0.60.0
1.26.9

Open the chart page →

26,588

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.26.9
2
bitnami/redis:latest33a5a129cadc
stdlib@go1.26.8
1.26.9
2
bitnamisecure/git72ae5bd9715f
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.60.0
1.26.9
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.60.0
1.26.9
2
bloomberg/goldpinger:3.11.5f7c60d319150
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
burningalchemist/sql_exporter:0.24.9:latest6c554722facc
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
cagriekin/pg-ha:2.1.0-pg18111ccc617ce7
golang.org/x/net@v0.58.0
stdlib@go1.25.12
0.60.0
1.26.9
2
casbin/casdoor:3.62.17729da148c61
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.7
0.60.0
1.26.9
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.5
0.60.0
1.26.9
2
chrislusf/seaweedfs:2.92db095fe8a8d6
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.7
0.60.0
1.26.9
2
clickhouse/clickhouse-server:24.2ed9640bfff07
stdlib@go1.19.10
1.26.9
2
cloudflare/cloudflared:2022.1.361f608cd1123
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.1
0.60.0
1.26.9
2
cloudflare/cloudflared:2026.6.16d91c121b803
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
2
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.26.9
2
coredns/coredns:1.13.19b9128672209
golang.org/x/net@v0.45.0
stdlib@go1.25.2
0.60.0
1.26.9
2
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.60.0
1.26.9
2
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.17.3
0.60.0
1.26.9
2
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.60.0
1.26.9
2
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.4
0.60.0
1.26.9
2
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.60.0
1.26.9
2
danielfm/aws-limits-exporter:0.6.07152b84e57cb
stdlib@go1.17.2
1.26.9
2
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
2
danielqsj/kafka-exporter:latestd1014f41712d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
datawire/emissary:3.12.21f67a1292d2a
golang.org/x/net@v0.28.0
stdlib@go1.22.4
0.60.0
1.26.9
2
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.26.9
2
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.26.9
2
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.60.0
1.26.9
2
dexidp/dex:v2.39.1-distroless43655afd1a8f
golang.org/x/net@v0.24.0
stdlib@go1.21.6
0.60.0
1.26.9
2
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.60.0
1.26.9
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.60.0
1.26.9
2
dunglas/mercure:v0:v0.24.2916834e49961
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
2
envoyproxy/gateway:v1.9.10049bcb384c5
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
2
epamedp/cd-pipeline-operator:2.32.0fc858071b7a1
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
2
epamedp/codebase-operator:2.35.0295a008abcef
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
2
epamedp/edp-tekton:0.27.088189f16f94b
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
2
epamedp/gitfusion:0.6.10b7eb7d5ca43
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
2
eqalpha/keydb:latest6537505c4235
stdlib@go1.16.7
1.26.9
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.26.9
2
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.26.9
2
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.26.9
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.60.0
1.26.9
2
filebrowser/filebrowser:latest:v2.63.23a469ea076d4a
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
2
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.16.2
0.60.0
1.26.9
2
flanksource/incident-manager-ui:v1.4.3228d17f0c08b20
stdlib@go1.23.5
1.26.9
2
flashcatcloud/categraf:latest42e6ab16472e
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
2
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.60.0
1.26.9
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.