StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
7 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
helm-4apk4.3.0-r04.3.0-r21
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-7r9c-ff6c-hxjjDEBIAN-CVE-2026-78663GO-2026-6612CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3x
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
ceems-exporterceemsVerified publisher0.9.01 of 1See more

ceems-exporter ceems 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/ceems/ceems:v0.16.14633125698c3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

141
ceems-lbceemsVerified publisher0.9.01 of 1See more

ceems-lb ceems 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/ceems/ceems:v0.16.14633125698c3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

141
kube-ceemsceemsOfficialVerified publisher1.49.04 of 5See more

kube-ceems ceems 1.49.0

4 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/ceems/ceems:v0.16.14633125698c3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

680
cellcastcellcast0.5.01 of 1See more

cellcast cellcast 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/ethan-kane-ops/cellcast-hub:v0.5.0c450eb54b7e4
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

134
ceph-csi-operatorceph-csi-operator1.1.01 of 1See more

ceph-csi-operator ceph-csi-operator 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/cephcsi/ceph-csi-operator:v1.1.0c42c95c36fa2
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

138
cerberuscerberusVerified publisher0.18.01 of 1See more

cerberus cerberus 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/tsouza/cerberus:1.22.0d181d9145aac
golang.org/x/net@v0.59.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

391
certforge-issuercertforge-issuer0.2.41 of 1See more

certforge-issuer certforge-issuer 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/certforge-llc/certforge-issuer:0.2.430f73d255939
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

136
cert-manager-csi-driver-spiffecert-managerOfficialVerified publisher0.15.04 of 4See more

cert-manager-csi-driver-spiffe cert-manager 0.15.0

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-csi-driver-spiffe:v0.15.01755a3802efd
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-csi-driver-spiffe-approver:v0.15.05f7a9bbb95fb
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,455
cert-manager-acm-synccert-manager-acm-sync0.7.41 of 1See more

cert-manager-acm-sync cert-manager-acm-sync 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/camilorivera/cert-manager-acm-sync:0.7.489a83796a550
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

358
cert-manager-alidns-webhookcert-manager-alidns-webhook0.1.41 of 1See more

cert-manager-alidns-webhook cert-manager-alidns-webhook 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/crazygit/cert-manager-alidns-webhook:0.1.4976be6506eb6
golang.org/x/net@v0.47.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

1,727
cert-manager-desec-webhookcert-manager-desec-webhook1.0.11 of 1See more

cert-manager-desec-webhook cert-manager-desec-webhook 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,967
cert-manager-webhook-abioncert-manager-webhook-abion1.3.21 of 1See more

cert-manager-webhook-abion cert-manager-webhook-abion 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
abiondevelopment/cert-manager-webhook-abion:latestc741988fbd23
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

1,741
cert-manager-webhook-bunnycert-manager-webhook-bunnyVerified publisher1.0.21 of 1See more

cert-manager-webhook-bunny cert-manager-webhook-bunny 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/o0th/cert-manager-webhook-bunny:1.0.2fe7ce555a12d
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,302
cert-manager-webhook-civocert-manager-webhook-civoVerified publisher0.0.0-05b683cb6efdc99135f68af18007954e74f184041 of 1See more

cert-manager-webhook-civo cert-manager-webhook-civo 0.0.0-05b683cb6efdc99135f68af18007954e74f18404

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
okteto/civo-webhook:0.5.357cd51176538
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

1,897
cert-manager-webhook-f5xccert-manager-webhook-f5xcVerified publisher0.6.01 of 1See more

cert-manager-webhook-f5xc cert-manager-webhook-f5xc 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/wenkow/cert-manager-webhook-f5xc:0.6.00988cebf89bb
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

133
cert-manager-webhook-hcloud-zonescert-manager-webhook-hcloud-zones0.1.51 of 1See more

cert-manager-webhook-hcloud-zones cert-manager-webhook-hcloud-zones 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/cert-manager-webhook-hcloud-zones:0.1.5a7a846bba3e8
golang.org/x/net@v0.52.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

657
cert-manager-webhook-infoblox-wapicert-manager-webhook-infoblox-wapiVerified publisher1.5.21 of 1See more

cert-manager-webhook-infoblox-wapi cert-manager-webhook-infoblox-wapi 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

3,320
cert-manager-webhook-namecheapcert-manager-webhook-namecheap0.1.21 of 1See more

cert-manager-webhook-namecheap cert-manager-webhook-namecheap 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.60.0
1.26.9

Open the chart page →

2,401
cert-manager-webhook-pdnscert-manager-webhook-pdns3.2.51 of 1See more

cert-manager-webhook-pdns cert-manager-webhook-pdns 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
zachomedia/cert-manager-webhook-pdns:v2.5.54940e227a39b
golang.org/x/net@v0.50.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

1,445
cert-manager-webhook-poweradmincert-manager-webhook-poweradmin0.2.161 of 1See more

cert-manager-webhook-poweradmin cert-manager-webhook-poweradmin 0.2.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/poweradmin/cert-manager-webhook-poweradmin:v0.2.166c788f9cb8c4
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

128
cert-manager-webhook-regerycert-manager-webhook-regery1.0.01 of 1See more

cert-manager-webhook-regery cert-manager-webhook-regery 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
darioackermann/cert-manager-webhook-regery:latest0d450bc4acc4
golang.org/x/net@v0.26.0
stdlib@go1.22.10
0.60.0
1.26.9

Open the chart page →

1,372
cert-manager-webhook-solidservercert-manager-webhook-solidserverVerified publisher1.0.21 of 1See more

cert-manager-webhook-solidserver cert-manager-webhook-solidserver 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/niklas-letz/cert-manager-webhook-solidserver:1.0.2f19a306ce759
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

780
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.13
0.60.0
1.26.9
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.60.0
1.26.9

Open the chart page →

9,614
getoutlinecfi20171.2.01 of 4See more

getoutline cfi2017 1.2.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.26.9

Open the chart page →

5,399
opencvecfi20170.1.23 of 7See more

opencve cfi2017 0.1.2

3 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.26.9
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
stdlib@go1.22.10
1.26.9

Open the chart page →

18,071
clechaosnative0.2.73 of 6See more

cle chaosnative 0.2.7

3 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.15
0.60.0
1.26.9
chaosnative/cle-license-module:2.7.062cf6adc355e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.15
0.60.0
1.26.9
chaosnative/cle-server:2.7.0e7bcff4a20c0
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

19,590
charon-relaycharonOfficialVerified publisher0.8.02 of 2See more

charon-relay charon 0.8.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

5,574
dv-podcharonOfficialVerified publisher0.19.13 of 5See more

dv-pod charon 0.19.1

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
obolnetwork/charon-dkg-sidecar:maine263be0a7440
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

9,276
chart-appchart-app0.3.01 of 2See more

chart-app chart-app 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

2,864
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

6,849
ghostchart-ghost0.1.71 of 2See more

ghost chart-ghost 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/ghost:6.69.0-alpine3.23db4c56c196d6
stdlib@go1.24.6
1.26.9

Open the chart page →

1,059
filebrowsercharts-derwitt-devVerified publisher1.1.11 of 1See more

filebrowser charts-derwitt-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.63.23a469ea076d4a
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

372
home-assistant-otbrcharts-derwitt-devVerified publisher2.1.61 of 1See more

home-assistant-otbr charts-derwitt-dev 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/homeassistant-otbr:4.2.7df1ba94bd5c0
stdlib@go1.26.5
1.26.9

Open the chart page →

2,867
paperless-ngxcharts-derwitt-devVerified publisher2.1.61 of 1See more

paperless-ngx charts-derwitt-dev 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.3.06b94799bc769
stdlib@go1.24.4
1.26.9

Open the chart page →

5,007
yas3pcharts-derwitt-devVerified publisher0.3.11 of 1See more

yas3p charts-derwitt-dev 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
denniswitt/yas3p:0.2.488a235619af6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

1,074
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
stdlib@go1.20.12
1.26.9

Open the chart page →

2,724
checker-edgechecker-edge1.1.111 of 1See more

checker-edge checker-edge 1.1.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/imcitius/checker-edge:1.1.1174426c1fe00f
golang.org/x/net@v0.50.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,176
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

10,927
aws-ecr-tokencheveo-charts0.1.01 of 1See more

aws-ecr-token cheveo-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
huzafach/aws-cli-k8:1.0.06e271d43ea48
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,592
pathling-serverchglVerified publisher0.10.141 of 3See more

pathling-server chgl 0.10.14

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,691
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.60.0
1.26.9

Open the chart page →

4,039
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.60.0
1.26.9

Open the chart page →

4,211
supersetchoerodon1.0.01 of 3See more

superset choerodon 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

2,068
argocd-metrics-serverchristianhuthVerified publisher1.1.11 of 1See more

argocd-metrics-server christianhuth 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
golang.org/x/net@v0.10.0
stdlib@go1.21.11
0.60.0
1.26.9

Open the chart page →

1,540
cluster-api-visualizerchristianhuthVerified publisher0.6.01 of 1See more

cluster-api-visualizer christianhuth 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

918
countlychristianhuthVerified publisher5.3.33 of 3See more

countly christianhuth 5.3.3

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/mongodb:latestad05bb9a19fa
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
countly/api:25.05.4f4cc7447c4f5
stdlib@go1.19.4
1.26.9
countly/frontend:25.05.42acbc11499b6
stdlib@go1.19.4
1.26.9

Open the chart page →

10,458
dnsbl-exporterchristianhuthVerified publisher1.4.01 of 2See more

dnsbl-exporter christianhuth 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/luzilla/dnsbl_exporter:v0.7.0-rc3d9767232a55e
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

2,023
github-exporterchristianhuthVerified publisher2.6.01 of 1See more

github-exporter christianhuth 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
githubexporter/github-exporter:v2.3.1a36fbedeedf8
stdlib@go1.26.4
1.26.9

Open the chart page →

215
goldpingerchristianhuthVerified publisher1.4.21 of 1See more

goldpinger christianhuth 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.11.5f7c60d319150
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
kubedoomchristianhuthVerified publisher1.1.21 of 1See more

kubedoom christianhuth 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/storax/kubedoom:0.6.0851ba8c80b93
stdlib@go1.17.6
1.26.9

Open the chart page →

1,882

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 7 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.26.9
2
library/docker:dind:latest0b6d18a4a222
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
library/eclipse-temurin:213e3c176ffed1
stdlib@go1.26.7
1.26.9
2
library/ghost:6.69.055131b90d48c
stdlib@go1.24.6
1.26.9
2
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.60.0
1.26.9
2
library/influxdb:2.7b8d940ca9376
golang.org/x/net@v0.38.0
stdlib@go1.18.2
0.60.0
1.26.9
2
library/mariadb:10.8.30abf60f81588
stdlib@go1.16.7
1.26.9
2
library/mariadb:11.41292844148b3
stdlib@go1.24.6
1.26.9
2
library/mariadb:10.623616f0bd3af
stdlib@go1.24.6
1.26.9
2
library/mariadb:12.3.3:lts2bdff1534a7e
stdlib@go1.24.6
1.26.9
2
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.26.9
2
library/mariadb:12.0.2:12.0-noble607835cd628b
stdlib@go1.24.6
1.26.9
2
library/mariadb:11.3.2e101f9db3191
stdlib@go1.18.2
1.26.9
2
library/mongo:8.0.20098862b1339f
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
2
library/mongo:7.01f995ad6fdb9
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
library/mongo:5.041108d183e97
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
2
library/mongo:7.0-jammy:7-jammyf71f6d0913c9
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
library/mysql:8:8.4:8.4.110744ee5ef89c
stdlib@go1.24.6
1.26.9
2
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.26.9
2
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.26.9
2
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.26.9
2
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.26.9
2
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.26.9
2
library/nats:2.12.3-alpine88fe8e0e09d6
stdlib@go1.25.5
1.26.9
2
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.26.9
2
library/nats:2.15.0-scratchc0d27f305460
stdlib@go1.27.1
1.27.2
2
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.26.9
2
library/postgres:18.11090bc3a8ccf
stdlib@go1.24.6
1.26.9
2
library/postgres:17-bookworm3645570cccdf
stdlib@go1.24.6
1.26.9
2
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.26.9
2
library/postgres:18.3-alpine:18.3-alpine3.2354451ecb8ab3
stdlib@go1.24.6
1.26.9
2
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.26.9
2
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.26.9
2
library/postgres:14c2427de38f99
stdlib@go1.24.6
1.26.9
2
library/postgres:17c6222b54873a
stdlib@go1.24.6
1.26.9
2
library/postgres:16ca0bd484cb98
stdlib@go1.24.6
1.26.9
2
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.26.9
2
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.26.9
2
library/postgres:13-alpinefb9065b6e3e2
stdlib@go1.24.6
1.26.9
2
library/rabbitmq:4.3.6-management:4-management8dd6e3570dda
stdlib@go1.22.2
1.26.9
2
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.26.9
2
library/redis148bb5411c18
stdlib@go1.18.2
1.26.9
2
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.26.9
2
library/redmine:6.1.3-trixief474a901faec
stdlib@go1.24.6
1.26.9
2
library/telegraf:1.40-alpine6606553b5019
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
library/traefik:v3.7.16b9cbca6fac4
golang.org/x/net@v0.53.0
stdlib@go1.25.10
0.60.0
1.26.9
2
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
2
library/traefik:2.4.8eda951fd29a8
golang.org/x/net@v0.0.0-20210220033124-5f55cee0dc0d
stdlib@go1.16.2
0.60.0
1.26.9
2
library/traefik:2.2.8f5af5a5ce17f
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.14.6
0.60.0
1.26.9
2
library/zookeeper:3.9.5e6b279d01350
stdlib@go1.18.1
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.