StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-7r9c-ff6c-hxjjCGA-gghc-78jw-f5q2CGA-rp37-mxv6-g5fjDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-vqxj-4gp6-23v9, CGA-w84h-9v6p-pf3x, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
epinio-uiepinioVerified publisher1.7.21 of 1See more

epinio-ui epinio 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.20
0.60.0
1.26.9

Open the chart page →

2,596
upgrade-responderepinioVerified publisher0.2.02 of 5See more

upgrade-responder epinio 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:10.1.50679e877ba20
golang.org/x/net@v0.12.0
stdlib@go1.20.10
0.60.0
1.26.9
longhornio/upgrade-responder:v0.2.05875cef29348
stdlib@go1.17.13
1.26.9

Open the chart page →

9,218
admin-console-operatorepmdedpVerified publisher2.14.02 of 2See more

admin-console-operator epmdedp 2.14.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.19.6
0.60.0
1.26.9
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.18.3
0.60.0
1.26.9

Open the chart page →

6,188
cd-pipeline-operatorepmdedpVerified publisher2.32.01 of 1See more

cd-pipeline-operator epmdedp 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/cd-pipeline-operator:2.32.0fc858071b7a1
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

450
codebase-operatorepmdedpVerified publisher2.35.01 of 1See more

codebase-operator epmdedp 2.35.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/codebase-operator:2.35.0295a008abcef
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

405
edp-argocd-operatorepmdedpVerified publisher0.2.01 of 1See more

edp-argocd-operator epmdedp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.4
0.60.0
1.26.9

Open the chart page →

2,473
edp-headlampepmdedpVerified publisher0.25.01 of 1See more

edp-headlamp epmdedp 0.25.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/edp-headlamp:0.25.093417e18bb1a
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.60.0
1.26.9

Open the chart page →

1,868
edp-installepmdedpOfficialVerified publisher3.15.05 of 7See more

edp-install epmdedp 3.15.0

5 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/cd-pipeline-operator:2.32.0fc858071b7a1
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
epamedp/codebase-operator:2.35.0295a008abcef
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
epamedp/edp-tekton:0.27.088189f16f94b
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
epamedp/gitfusion:0.6.10b7eb7d5ca43
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
ghcr.io/kuberocketci/krci-cache:0.3.05f6cd61e6da6
golang.org/x/net@v0.55.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

3,776
edp-tektonepmdedpVerified publisher0.27.02 of 3See more

edp-tekton epmdedp 0.27.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/edp-tekton:0.27.088189f16f94b
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
ghcr.io/kuberocketci/krci-cache:0.3.05f6cd61e6da6
golang.org/x/net@v0.55.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,538
edp-tekton-interceptorepmdedpVerified publisher0.2.41 of 1See more

edp-tekton-interceptor epmdedp 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/edp-tekton:0.2.4924939850655
golang.org/x/net@v0.1.0
stdlib@go1.18.3
0.60.0
1.26.9

Open the chart page →

2,306
gerrit-operatorepmdedpVerified publisher2.25.01 of 2See more

gerrit-operator epmdedp 2.25.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/gerrit-operator:2.25.08de22fc5051c
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

1,634
gitfusionepmdedpVerified publisher0.6.11 of 1See more

gitfusion epmdedp 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/gitfusion:0.6.10b7eb7d5ca43
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

352
jenkins-operatorepmdedpVerified publisher2.15.31 of 3See more

jenkins-operator epmdedp 2.15.3

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.15.328ef56bc0ca3
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.60.0
1.26.9

Open the chart page →

2,789
keycloak-operatorepmdedpVerified publisher1.35.01 of 1See more

keycloak-operator epmdedp 1.35.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/keycloak-operator:1.35.0a5398eaa7b80
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

393
nexus-operatorepmdedpVerified publisher3.6.01 of 1See more

nexus-operator epmdedp 3.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/nexus-operator:3.6.09fede333ef27
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

384
perf-operatorepmdedpVerified publisher2.13.01 of 1See more

perf-operator epmdedp 2.13.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/perf-operator:2.13.0bd2079b7bfcb
golang.org/x/net@v0.8.0
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

1,894
reconcilerepmdedpVerified publisher2.12.01 of 1See more

reconciler epmdedp 2.12.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.18.4
0.60.0
1.26.9

Open the chart page →

3,098
sonar-operatorepmdedpVerified publisher3.4.01 of 1See more

sonar-operator epmdedp 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/sonar-operator:3.4.0661d1648a49a
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

384
tekton-cacheepmdedpVerified publisher0.4.51 of 2See more

tekton-cache epmdedp 0.4.5

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kuberocketci/krci-cache:0.3.05f6cd61e6da6
golang.org/x/net@v0.55.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,163
tekton-custom-taskepmdedpVerified publisher0.2.01 of 1See more

tekton-custom-task epmdedp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/tekton-custom-task:0.2.067d896676f45
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,053
codebase-operatorepmdedp-devVerified publisher2.12.0-MDTU-DDM-SNAPSHOT.101 of 1See more

codebase-operator epmdedp-dev 2.12.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,956
gerrit-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.21 of 1See more

gerrit-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,942
jenkins-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

jenkins-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,395
keycloak-operatorepmdedp-devVerified publisher1.11.0-MDTU-DDM-SNAPSHOT.101 of 1See more

keycloak-operator epmdedp-dev 1.11.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,362
equizequiz0.0.11 of 3See more

equiz equiz 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
stdlib@go1.16.7
1.26.9

Open the chart page →

9,781
equizequiz-chart0.0.11 of 3See more

equiz equiz-chart 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
stdlib@go1.16.7
1.26.9

Open the chart page →

9,781
erasereraser1.4.21 of 1See more

eraser eraser 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/eraser-dev/eraser-manager:v1.4.2cda6025d1152
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

372
yopassernail-yopass2.0.01 of 1See more

yopass ernail-yopass 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jhaals/yopass:12.4.0b64a1a8ace1b
stdlib@go1.25.3
1.26.9

Open the chart page →

1,733
escvmschedulerescvmscheduler1.0.71 of 3See more

escvmscheduler escvmscheduler 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

6,299
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:12.2.2b1cb255a9939
stdlib@go1.24.6
1.26.9

Open the chart page →

7,949
etcd-defragetcd-defragVerified publisher0.28.11 of 1See more

etcd-defrag etcd-defrag 0.28.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestab90e1058e5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

218
armiarmaethereum-helm-chartsVerified publisher0.1.21 of 2See more

armiarma ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/armiarma:master1a9c3264f0a9
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,835
assertoorethereum-helm-chartsVerified publisher1.2.01 of 1See more

assertoor ethereum-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/assertoor:latest1efa2fba6711
golang.org/x/net@v0.56.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

3,575
authenticatoorethereum-helm-chartsVerified publisher0.1.01 of 1See more

authenticatoor ethereum-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/service-authenticatoor:main27b8e5ea3125
stdlib@go1.25.12
1.26.9

Open the chart page →

508
benchmarkoor-apiethereum-helm-chartsVerified publisher0.1.01 of 1See more

benchmarkoor-api ethereum-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/benchmarkoor:latest5470b2ec3161
stdlib@go1.24.13
1.26.9

Open the chart page →

1,430
blob-me-babyethereum-helm-chartsVerified publisher0.1.21 of 1See more

blob-me-baby ethereum-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/blob-me-baby:latestad26158420dd
stdlib@go1.20.1
1.26.9

Open the chart page →

2,104
buildoor-overviewethereum-helm-chartsVerified publisher0.0.11 of 1See more

buildoor-overview ethereum-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/buildoor:maina04c231ce0e8
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

902
cbt-apiethereum-helm-chartsVerified publisher0.0.141 of 1See more

cbt-api ethereum-helm-charts 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/cbt-api:latestd60029a656db
golang.org/x/net@v0.52.0
stdlib@go1.26.3-X:jsonv2
0.60.0
1.26.9

Open the chart page →

613
chaos-meshethereum-helm-chartsVerified publisher0.0.34 of 4See more

chaos-mesh ethereum-helm-charts 0.0.3

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.19.7
0.60.0
1.26.9
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
golang.org/x/net@v0.44.0
stdlib@go1.24.4
0.60.0
1.26.9
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.0e7f9e8f1d565
golang.org/x/net@v0.44.0
stdlib@go1.24.4
0.60.0
1.26.9
ghcr.io/chaos-mesh/chaos-mesh:v2.8.0091b906a0b13
golang.org/x/net@v0.44.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

16,513
checkpointzethereum-helm-chartsVerified publisher0.1.31 of 1See more

checkpointz ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
samcm/checkpointz:latesta66b24a87766
golang.org/x/net@v0.47.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

1,198
contributoorethereum-helm-chartsVerified publisher0.0.21 of 1See more

contributoor ethereum-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/contributoor:latest1edd4074fd79
golang.org/x/net@v0.53.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

1,311
doraethereum-helm-chartsVerified publisher1.0.121 of 2See more

dora ethereum-helm-charts 1.0.12

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/dora:master13be067c3cf7
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

3,201
dugtrioethereum-helm-chartsVerified publisher0.0.71 of 1See more

dugtrio ethereum-helm-charts 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/dugtrio:1.0.0e261d1734e9f
golang.org/x/net@v0.10.0
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

1,812
erpcethereum-helm-chartsVerified publisher0.0.41 of 1See more

erpc ethereum-helm-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/erpc/erpc:0.0.49f5654f745d4c
golang.org/x/net@v0.36.0
stdlib@go1.23.9
0.60.0
1.26.9

Open the chart page →

1,452
eth2-fork-monethereum-helm-chartsVerified publisher0.1.31 of 1See more

eth2-fork-mon ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ralexstokes/eth2-fork-mon:latestc0d4bbefd31f
stdlib@go1.16.7
1.26.9

Open the chart page →

2,923
ethereum-address-metrics-exporterethereum-helm-chartsVerified publisher0.2.01 of 1See more

ethereum-address-metrics-exporter ethereum-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/ethereum-address-metrics-exporter:latest431cd3790ed2
stdlib@go1.26.1
1.26.9

Open the chart page →

854
ethereum-metrics-exporterethereum-helm-chartsVerified publisher0.2.11 of 1See more

ethereum-metrics-exporter ethereum-helm-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
samcm/ethereum-metrics-exporter:latestdc6cedebb24b
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

322
ethereum-validator-metrics-exporterethereum-helm-chartsVerified publisher0.0.11 of 1See more

ethereum-validator-metrics-exporter ethereum-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/ethereum-validator-metrics-exporter:latest38448e9d4aef
stdlib@go1.19.10
1.26.9

Open the chart page →

1,192
eth-faucetethereum-helm-chartsVerified publisher0.1.11 of 1See more

eth-faucet ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
chainflag/eth-faucet:latestac642796bcb6
stdlib@go1.17.13
1.26.9

Open the chart page →

2,773
execution-processorethereum-helm-chartsVerified publisher0.0.31 of 1See more

execution-processor ethereum-helm-charts 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethpandaops/execution-processor:latest5c4832e9588f
stdlib@go1.25.4
1.26.9

Open the chart page →

1,061

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
library/arangodb:3.11.81e75d74954a4
stdlib@go1.21.5
1.26.9
2
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.26.9
2
library/docker:dind:latest0b6d18a4a222
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
library/eclipse-temurin:213e3c176ffed1
stdlib@go1.26.7
1.26.9
2
library/ghost:6.69.055131b90d48c
stdlib@go1.24.6
1.26.9
2
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.60.0
1.26.9
2
library/influxdb:2.7b8d940ca9376
golang.org/x/net@v0.38.0
stdlib@go1.18.2
0.60.0
1.26.9
2
library/mariadb:10.8.30abf60f81588
stdlib@go1.16.7
1.26.9
2
library/mariadb:11.41292844148b3
stdlib@go1.24.6
1.26.9
2
library/mariadb:10.623616f0bd3af
stdlib@go1.24.6
1.26.9
2
library/mariadb:12.3.3:lts2bdff1534a7e
stdlib@go1.24.6
1.26.9
2
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.26.9
2
library/mariadb:12.0.2:12.0-noble607835cd628b
stdlib@go1.24.6
1.26.9
2
library/mariadb:11.3.2e101f9db3191
stdlib@go1.18.2
1.26.9
2
library/mongo:8.0.20098862b1339f
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
2
library/mongo:7.01f995ad6fdb9
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
library/mongo:5.041108d183e97
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
2
library/mongo:7.0-jammy:7-jammyf71f6d0913c9
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
library/mysql:8:8.4:8.4.110744ee5ef89c
stdlib@go1.24.6
1.26.9
2
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.26.9
2
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.26.9
2
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.26.9
2
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.26.9
2
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.26.9
2
library/nats:2.12.3-alpine88fe8e0e09d6
stdlib@go1.25.5
1.26.9
2
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.26.9
2
library/nats:2.15.0-scratchc0d27f305460
stdlib@go1.27.1
1.27.2
2
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.26.9
2
library/postgres:18.11090bc3a8ccf
stdlib@go1.24.6
1.26.9
2
library/postgres:17-bookworm3645570cccdf
stdlib@go1.24.6
1.26.9
2
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.26.9
2
library/postgres:18.3-alpine:18.3-alpine3.2354451ecb8ab3
stdlib@go1.24.6
1.26.9
2
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.26.9
2
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.26.9
2
library/postgres:14c2427de38f99
stdlib@go1.24.6
1.26.9
2
library/postgres:17c6222b54873a
stdlib@go1.24.6
1.26.9
2
library/postgres:16ca0bd484cb98
stdlib@go1.24.6
1.26.9
2
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.26.9
2
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.26.9
2
library/postgres:13-alpinefb9065b6e3e2
stdlib@go1.24.6
1.26.9
2
library/rabbitmq:4.3.6-management:4-management8dd6e3570dda
stdlib@go1.22.2
1.26.9
2
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.26.9
2
library/redis148bb5411c18
stdlib@go1.18.2
1.26.9
2
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.26.9
2
library/redmine:6.1.3-trixief474a901faec
stdlib@go1.24.6
1.26.9
2
library/telegraf:1.40-alpine6606553b5019
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
library/traefik:v3.7.16b9cbca6fac4
golang.org/x/net@v0.53.0
stdlib@go1.25.10
0.60.0
1.26.9
2
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
2
library/traefik:2.4.8eda951fd29a8
golang.org/x/net@v0.0.0-20210220033124-5f55cee0dc0d
stdlib@go1.16.2
0.60.0
1.26.9
2
library/traefik:2.2.8f5af5a5ce17f
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.14.6
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.