StackRadar

CVE-2026-78663

Unscored

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,566
of 18,071 indexed, latest versions
Container images
6,425
deployed by those charts
Fix available
2 of 3
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,566 of 18,071 indexed charts deploy, on 6,425 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,411
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,172
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-78663GO-2026-6612
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,566 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-communityOfficialVerified publisher92.2.05 of 6See more

kube-prometheus-stack prometheus-community 92.2.0

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

788
cert-managercert-managerOfficialVerified publisher1.21.24 of 4See more

cert-manager cert-manager 1.21.2

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

318
argo-cdargoOfficialVerified publisher10.10.12 of 3See more

argo-cd argo 10.10.1

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/argoproj/argocd:v3.5.449dff79439bb
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

2,402
ingress-nginxingress-nginx4.15.12 of 2See more

ingress-nginx ingress-nginx 4.15.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

2,110
prometheusprometheus-communityOfficialVerified publisher29.36.16 of 6See more

prometheus prometheus-community 29.36.1

6 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.106b52bd4dbe3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.34.1e9733bafb1bd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.15.0efd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/prometheus/pushgateway:v1.11.491a56b89b97d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

830
redisbitnamiVerified publisher28.3.11 of 1See more

redis bitnami 28.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9

Open the chart page →

52
traefiktraefikOfficialVerified publisher41.7.01 of 1See more

traefik traefik 41.7.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/traefik:v3.7.14575fa15b1350
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

89
kubernetes-dashboardk8s-dashboard7.14.04 of 5See more

kubernetes-dashboard k8s-dashboard 7.14.0

4 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubernetesui/dashboard-api:1.14.096a702cfd339
golang.org/x/net@v0.40.0
stdlib@go1.23.12
0.60.0
1.26.9
kubernetesui/dashboard-auth:1.4.053e9917898bf
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
kubernetesui/dashboard-metrics-scraper:1.2.25154b68252bd
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9
kubernetesui/dashboard-web:1.7.0cc7c31bd2d84
golang.org/x/net@v0.38.0
stdlib@go1.23.9
0.60.0
1.26.9

Open the chart page →

4,484
lokigrafana7.3.03 of 6See more

loki grafana 7.3.0

3 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/loki:3.6.1144148ad243c0
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
grafana/loki-canary:3.6.121e9bfcff3867
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

4,981
metrics-servermetrics-serverVerified publisher3.14.01 of 1See more

metrics-server metrics-server 3.14.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

333
vaulthashicorpVerified publisher0.34.12 of 2See more

vault hashicorp 0.34.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/vault:2.0.45be49781ecf7
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
hashicorp/vault-k8s:1.7.655e27b080c9b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

928
gitlabgitlabVerified publisher10.4.118 of 21See more

gitlab gitlab 10.4.1

18 of the 21 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.9.10049bcb384c5
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.0142a1f11df8d
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.14.05ce7540c3c00
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.104019bb2e325
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/cfssl-self-sign:v19.4.15dd7827fa474
golang.org/x/net@v0.20.0
stdlib@go1.22.0
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.198d46dc7e071
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.19df7d5aa03fe
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabb21661438ee9
golang.org/x/net@v0.55.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.2693bfdee8aa8
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-kas:v19.4.14ed6de4d77e1
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3180688274b2c
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.17419aa33eb17
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.1a072f0a41f28
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

19,183
harborharborOfficialVerified publisher1.19.25 of 8See more

harbor harbor 1.19.2

5 of the 8 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.2d7b780d23721
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
goharbor/harbor-jobservice:v2.15.2f71a4452a095
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
goharbor/registry-photon:v2.15.2c4ebef61ceb5
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

2,723
jenkinsjenkinsciOfficialVerified publisher5.9.671 of 2See more

jenkins jenkinsci 5.9.67

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jenkins/jenkins:2.580.1-jdk21a660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,035
external-secretsexternal-secrets-operatorVerified publisher2.12.01 of 1See more

external-secrets external-secrets-operator 2.12.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v2.12.07a3c4f7e038f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

133
external-dnsexternal-dnsVerified publisher1.23.01 of 1See more

external-dns external-dns 1.23.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/external-dns/external-dns:v0.23.01854499e2b08
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

76
longhornlonghorn1.13.03 of 3See more

longhorn longhorn 1.13.0

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.13.07372f3c59239
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
longhornio/longhorn-share-manager:v1.13.053950f78b7af
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
longhornio/longhorn-ui:v1.13.0f22fb0254ae5
stdlib@go1.26.8
1.26.9

Open the chart page →

300
gitlab-runnergitlabVerified publisher0.93.01 of 1See more

gitlab-runner gitlab 0.93.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

523
ciliumciliumOfficialVerified publisher1.20.23 of 3See more

cilium cilium 1.20.2

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.22939231d0d3e
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82af7382699576
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/cilium/operator-generic:v1.20.264d8798350e8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,685
airflowapache-airflowOfficialVerified publisher1.22.01 of 4See more

airflow apache-airflow 1.22.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheus/statsd-exporter:v0.30.0378cb79c4ac7
golang.org/x/net@v0.51.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

3,672
mongodbbitnamiVerified publisher20.0.01 of 1See more

mongodb bitnami 20.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/mongodb:latestad05bb9a19fa
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

379
velerovmware-tanzu12.2.11 of 1See more

velero vmware-tanzu 12.2.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
velero/velero:v1.18.237396519f399
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,393
metallbmetallbVerified publisher0.16.13 of 4See more

metallb metallb 0.16.1

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.16.1f51ab515de9c
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
golang.org/x/net@v0.39.0
stdlib@go1.25.8
0.60.0
1.26.9
quay.io/metallb/speaker:v0.16.116561e96531e
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

3,036
rancherrancher-stable2.15.22 of 2See more

rancher rancher-stable 2.15.2

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.20c3d8e570255
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9
rancher/shell:v0.8.21eeed72d4eda
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,326
cloudnative-pgcloudnative-pgVerified publisher0.29.11 of 1See more

cloudnative-pg cloudnative-pg 0.29.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.30.1923c267ec296
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

72
kyvernokyvernoOfficialVerified publisher3.9.11 of 7See more

kyverno kyverno 3.9.1

1 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kyverno/readiness-checker:v1.19.131bb42ce7f5b
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

106
argo-workflowsargoOfficialVerified publisher2.0.113 of 3See more

argo-workflows argo 2.0.11

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-workflows-crdinstaller:v4.1.4111ea7bba0ec
golang.org/x/net@v0.49.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/argoproj/argocli:v4.1.4c3c2bc505a7d
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/argoproj/workflow-controller:v4.1.486a1acba574f
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

680
giteagiteaOfficialVerified publisher12.7.02 of 4See more

gitea gitea 12.7.0

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.26.9
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
stdlib@go1.24.6
1.26.9

Open the chart page →

10,159
oauth2-proxyoauth2-proxyOfficialVerified publisher10.7.11 of 1See more

oauth2-proxy oauth2-proxy 10.7.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.15.58498b0d0ef0a
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

76
nginxbitnamiVerified publisher25.2.11 of 1See more

nginx bitnami 25.2.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/nginx:latestb8d42f076789
stdlib@go1.26.8
1.26.9

Open the chart page →

74
wordpressbitnamiVerified publisher34.1.32 of 2See more

wordpress bitnami 34.1.3

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9
bitnami/wordpress:latest845d250ecd73
stdlib@go1.26.8
1.26.9

Open the chart page →

544
sealed-secretsbitnami-labsVerified publisher2.18.61 of 1See more

sealed-secrets bitnami-labs 2.18.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.37.03fe0103896b8
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

547
kedakedacore2.21.03 of 3See more

keda kedacore 2.21.0

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.21.081fe6547ce8d
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/kedacore/keda-admission-webhooks:2.21.0e1969628cca6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/kedacore/keda-metrics-apiserver:2.21.0255375037fe5
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

228
nginx-ingressnginxVerified publisher2.7.31 of 1See more

nginx-ingress nginx 2.7.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
nginx/nginx-ingress:5.6.313dafd0b7bf5
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,514
nfs-subdir-external-provisionernfs-subdir-external-provisioner4.0.181 of 1See more

nfs-subdir-external-provisioner nfs-subdir-external-provisioner 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

3,865
artifact-hubartifact-hubVerified publisher1.23.06 of 7See more

artifact-hub artifact-hub 1.23.0

6 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
artifacthub/db-migrator:v1.23.028c13565ac5c
stdlib@go1.26.4
1.26.9
artifacthub/hub:v1.23.07d3a91c539dc
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.26.9
artifacthub/scanner:v1.23.02d8365601f0e
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
artifacthub/tracker:v1.23.05368d21a6e5c
golang.org/x/net@v0.44.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

14,174
kube-state-metricsprometheus-communityVerified publisher8.6.01 of 1See more

kube-state-metrics prometheus-community 8.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

185
consulhashicorpVerified publisher2.0.42 of 2See more

consul hashicorp 2.0.4

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/consul:2.0.41c59f007df8e
golang.org/x/net@v0.59.0
stdlib@go1.26.7
0.60.0
1.26.9
hashicorp/consul-k8s-control-plane:2.0.49334d7f4bcf0
golang.org/x/net@v0.59.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

187
mariadbbitnamiVerified publisher28.1.11 of 1See more

mariadb bitnami 28.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9

Open the chart page →

52
alloygrafana1.13.12 of 2See more

alloy grafana 1.13.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/alloy:v1.20.12aa2099af76c
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.0142a1f11df8d
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

692
prometheus-blackbox-exporterprometheus-communityOfficialVerified publisher11.20.01 of 1See more

prometheus-blackbox-exporter prometheus-community 11.20.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.29.09613f2884689
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

76
reloaderstakaterVerified publisher2.2.181 of 1See more

reloader stakater 2.2.18

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/stakater/reloader:v1.4.22def2480040ad
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

72
argo-rolloutsargoOfficialVerified publisher2.43.61 of 1See more

argo-rollouts argo 2.43.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-rollouts:v1.10.0187630ba7228
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

232
deschedulerdescheduler0.37.01 of 1See more

descheduler descheduler 0.37.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/descheduler/descheduler:v0.37.088deef34ff5c
golang.org/x/net@v0.58.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

488
argo-cdargo-cd-oci10.10.12 of 3See more

argo-cd argo-cd-oci 10.10.1

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/argoproj/argocd:v3.5.449dff79439bb
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

2,402
jaegerjaegertracingOfficialVerified publisher4.14.11 of 1See more

jaeger jaegertracing 4.14.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jaegertracing/jaeger:2.21.03d0ac795ff98
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

271
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-image-awaiter:4.4.2c4df1176d152
stdlib@go1.23.12
1.26.9
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/net@v0.23.0
stdlib@go1.23.10
0.60.0
1.26.9

Open the chart page →

9,827
mimir-distributedgrafana6.2.13 of 5See more

mimir-distributed grafana 6.2.1

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/mimir:3.2.192838f113ba5
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
grafana/rollout-operator:v0.38.132fe838b79dd
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
pgsty/silo:RELEASE.2026-09-03T13-18-01Zb616a0cf8cb2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

2,665
headlampheadlampOfficialVerified publisher0.45.01 of 1See more

headlamp headlamp 0.45.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.45.0db3f0e0fc58d
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

396
argocd-image-updaterargoOfficialVerified publisher1.3.11 of 1See more

argocd-image-updater argo 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,111

Container images carrying it

6,425 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.60.0
1.26.9
2
filebrowser/filebrowser:latest:v2.63.23a469ea076d4a
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
2
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.16.2
0.60.0
1.26.9
2
flanksource/incident-manager-ui:v1.4.3228d17f0c08b20
stdlib@go1.23.5
1.26.9
2
flashcatcloud/categraf:latest42e6ab16472e
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
2
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/net@v0.36.0
stdlib@go1.23.7
0.60.0
1.26.9
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/net@v0.24.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/udm:v3.4.32f68df062a50
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/upf:v3.4.3b6b362a39fdd
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/net@v0.23.0
stdlib@go1.21.8
0.60.0
1.26.9
2
freikin/dawarich:1.15.3589e3606b11b
stdlib@go1.24.4
1.26.9
2
friendsofgo/killgrave:0.4.139cfbecca342
stdlib@go1.16.3
1.26.9
2
frinx/krakend:7.0.0bf8edd4f52f3
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.60.0
1.26.9
2
frinx/resource-manager:6.1.09cd0147a09bd
stdlib@go1.21.7
1.26.9
2
frinx/schellar:6.1.04693dc627d32
stdlib@go1.21.11
1.26.9
2
garethgeorge/backrest:latest:v1.14.1b85297975428
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9
2
garugaru/aws-cloudwatch-exporter:latest541852cafda5
stdlib@go1.16.15
1.26.9
2
githubexporter/github-exporter:v2.3.1a36fbedeedf8
stdlib@go1.26.4
1.26.9
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
stdlib@go1.18
0.60.0
1.26.9
2
gomods/athens:v0.11.0efb811df7844
golang.org/x/net@v0.0.0-20200222125558-5a598a2470a0
stdlib@go1.13.10
0.60.0
1.26.9
2
gotenberg/gotenberg:8.36.087c16b9f3642
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
2
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.60.0
1.26.9
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18
0.60.0
1.26.9
2
grafana/alloy:v1.8.17790f6f7fbd8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
2
grafana/alloy:v1.19.2b8ec653c4423
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
2
grafana/grafana:9.2.4057896e23443
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.60.0
1.26.9
2
grafana/grafana:11.1.0079600c9517b
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
2
grafana/grafana:13.0.10f86bada30d6
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.60.0
1.26.9
2
grafana/grafana:12.3.12175aaa91c96
golang.org/x/net@v0.46.0
stdlib@go1.25.5
0.60.0
1.26.9
2
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.17.9
0.60.0
1.26.9
2
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.5
0.60.0
1.26.9
2
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
2
grafana/grafana:12.3.39e1e77ade304
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
2
grafana/grafana:latestac461fb352ab
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9
2
grafana/grafana:11.4.0d8ea37798ccc
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9
2
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
2
grafana/loki:3.6.5847c287ada0e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
2
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.60.0
1.26.9
2
grafana/loki:3.1.0d947e68a84d9
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
2
grafana/loki:2.5.0f9ef133793af
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.8
0.60.0
1.26.9
2
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.60.0
1.26.9
2
grafana/promtail:2.9.3b338a29de45e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.