StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,521
of 18,087 indexed, latest versions
Container images
6,339
deployed by those charts
Fix available
2 of 3
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,521 of 18,087 indexed charts deploy, on 6,339 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,327
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,102
golang-1.19deb1.19.8-2no fix listed1
OSV records
GO-2026-6612DEBIAN-CVE-2026-78663
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,521 by stars
ChartLatestAffected imagesRadar Score
cluster-api-operatorcluster-api-operator0.29.01 of 1See more

cluster-api-operator cluster-api-operator 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/capi-operator/cluster-api-operator:v0.29.0465e72f8b06a
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

135
immudbcodenotaryVerified publisher1.9.71 of 1See more

immudb codenotary 1.9.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
codenotary/immudb:1.9.77c85d7cc4f22
golang.org/x/net@v0.17.0
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

1,957
routercosmo-routerOfficialVerified publisher0.18.01 of 1See more

router cosmo-router 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

2,198
dolibarrcowboysysopVerified publisher9.0.32 of 3See more

dolibarr cowboysysop 9.0.3

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
stdlib@go1.23.7
1.26.9
wait4x/wait4x:3.3.14dcd86307de1
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

11,097
csi-wekafsplugincsi-wekafsOfficialVerified publisher0.6.2-01 of 6See more

csi-wekafsplugin csi-wekafs 0.6.2-0

1 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.60.0
1.26.9

Open the chart page →

3,998
daskhubdask2024.1.13 of 9See more

daskhub dask 2024.1.1

3 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/traefik:2.10.61957e3314f43
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
quay.io/jupyterhub/k8s-image-awaiter:3.2.1f65b644ed6db
stdlib@go1.18.10
1.26.9
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.60.0
1.26.9

Open the chart page →

17,237
seafiledatamateVerified publisher0.6.05 of 6See more

seafile datamate 0.6.0

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
stdlib@go1.22.6
1.26.9
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
bitnamilegacy/os-shell:11-debian-11-r968643af4facff
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

85,124
k8s-event-loggerdeliveryheroVerified publisher1.4.01 of 1See more

k8s-event-logger deliveryhero 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
maxrocketinternet/k8s-event-logger:2.70234bdec4626
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

538
drone-runner-dockerdroneVerified publisher0.7.02 of 3See more

drone-runner-docker drone 0.7.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.15
0.60.0
1.26.9
library/docker:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9

Open the chart page →

7,345
gateway-helmenvoy-gateway0.0.0-latest1 of 1See more

gateway-helm envoy-gateway 0.0.0-latest

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
envoyproxy/gateway-dev:latest97b2a036f523
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

332
k8s-image-swapperestahnVerified publisher1.11.01 of 2See more

k8s-image-swapper estahn 1.11.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9

Open the chart page →

2,537
loadtesterflagger0.39.01 of 1See more

loadtester flagger 0.39.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.56.0
stdlib@go1.24.12
0.60.0
1.26.9

Open the chart page →

2,286
flannelflannel0.28.102 of 2See more

flannel flannel 0.28.10

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/flannel-io/flannel:v0.28.10f26b2403273c
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/flannel-io/flannel-cni-plugin:v1.9.1-flannel39fccdf677e6e
stdlib@go1.26.5
1.26.9

Open the chart page →

431
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.1
0.60.0
1.26.9

Open the chart page →

4,464
lndfold0.3.153 of 4See more

lnd fold 0.3.15

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.16.4-beta-c287129953689
golang.org/x/net@v0.8.0
stdlib@go1.21.0
0.60.0
1.26.9
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.60.0
1.26.9
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

11,647
geonode-k8sgeonode-k8sVerified publisher2.0.02 of 10See more

geonode-k8s geonode-k8s 2.0.0

2 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jwilder/dockerize:v0.10.0839cd6793d19
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.32.08ccae74fc039
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

62,128
gitops-promotergitops-promoterOfficialVerified publisher0.24.02 of 2See more

gitops-promoter gitops-promoter 0.24.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/gitops-promoter:v0.45.05ac7b6178ddc
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/brancz/kube-rbac-proxy:v0.23.0a6075902738e
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

3,301
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:latestf1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

12,962
grafana-mcpgrafana-communityVerified publisher0.27.11 of 1See more

grafana-mcp grafana-community 0.27.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/mcp-grafana:2.0.187b48c8fa1a0
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,015
mariadbgroundhog2k4.44.01 of 1See more

mariadb groundhog2k 4.44.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:11.8.46b848cb24fbb
stdlib@go1.24.6
1.26.9

Open the chart page →

3,488
mongodbgroundhog2k0.8.31 of 1See more

mongodb groundhog2k 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mongo:8.3.115d7043a4ffe0
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,370
haproxy-ingresshaproxy-ingressVerified publisher0.16.21 of 1See more

haproxy-ingress haproxy-ingress 0.16.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jcmoraisjr/haproxy-ingress:v0.16.242bcf39842db
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

106
heimdallheimdallOfficialVerified publisher3.3.31 of 2See more

heimdall heimdall 3.3.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

2,759
autheliahelmforgeVerified publisher1.5.141 of 1See more

authelia helmforge 1.5.14

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
authelia/authelia:4.39.28bd97cff4fcbf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

76
dolibarrhelmforgeVerified publisher1.2.191 of 3See more

dolibarr helmforge 1.2.19

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:26.7.0ade067ae2fb1
stdlib@go1.24.6
1.26.9

Open the chart page →

4,955
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
stdlib@go1.20.7
1.26.9

Open the chart page →

11,972
postgresqlhelmforgeVerified publisher2.0.51 of 1See more

postgresql helmforge 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

1,753
umamihelmforgeVerified publisher2.3.41 of 3See more

umami helmforge 2.3.4

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

2,058
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:15724292da1f2e
stdlib@go1.24.6
1.26.9
victoriametrics/victoria-metrics:v1.95.1f52723a08a44
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

16,634
infrahubinfrahubVerified publisher4.33.61 of 5See more

infrahub infrahub 4.33.6

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9

Open the chart page →

12,286
secret-manageritscontainedVerified publisher0.2.11 of 1See more

secret-manager itscontained 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
itscontained/secret-manager:0.3.07ec3e93c6469
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.3
0.60.0
1.26.9

Open the chart page →

4,171
jenkinsjenkins-helm-chartVerified publisher0.1.01 of 1See more

jenkins jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

1,925
kamu-api-serverkamuVerified publisher0.92.01 of 1See more

kamu-api-server kamu 0.92.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.92.016a23a285ffc
golang.org/x/net@v0.59.0
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

7,668
kerberneteskerbernetesVerified publisher1.1.111 of 1See more

kerbernetes kerbernetes 1.1.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/froz42/kerbernetes:v1.1.6d5c074be8366
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

271
percona-xtradb-clusterkfirfer1.5.101 of 3See more

percona-xtradb-cluster kfirfer 1.5.10

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
stdlib@go1.19.9
1.26.9

Open the chart page →

5,547
permission-managerkfirfer1.0.71 of 1See more

permission-manager kfirfer 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.60.0
1.26.9

Open the chart page →

3,264
klusterviewklusterviewVerified publisher0.1.02 of 4See more

klusterview klusterview 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:latestb28bae15e219
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/prometheus/prometheus:latestefd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

3,534
gateway-operatorkongOfficialVerified publisher0.6.11 of 1See more

gateway-operator kong 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kong/gateway-operator:1.603510967482b
golang.org/x/net@v0.39.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

1,238
kong-meshkong-meshVerified publisher2.14.53 of 3See more

kong-mesh kong-mesh 2.14.5

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kong/kuma-cp:2.14.5a154795691d1
golang.org/x/net@v0.58.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
kong/kumactl:2.14.58191df5c7019
golang.org/x/net@v0.58.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
registry.k8s.io/kubectl:v1.36.1d08f476d04d0
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

919
kubeflowkubeflow1.6.226 of 45See more

kubeflow kubeflow 1.6.2

26 of the 45 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.13
0.60.0
1.26.9
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.60.0
1.26.9
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/net@v0.0.0-20211205041911-012df41ee64c
stdlib@go1.17.7
0.60.0
1.26.9
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.11
0.60.0
1.26.9
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.60.0
1.26.9
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.60.0
1.26.9
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/mysql:5.7-debiandf28187b5455
stdlib@go1.16.7
1.26.9
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.11
0.60.0
1.26.9
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

188,880
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
stdlib@go1.20.6
1.26.9

Open the chart page →

12,137
testkubekubeshop2.14.16 of 6See more

testkube kubeshop 2.14.1

6 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubeshop/bitnami-mongodb:8.3.11e209888ede02
golang.org/x/net@v0.48.0
stdlib@go1.26.8
0.60.0
1.26.9
kubeshop/testkube-api-server:2.14.1ce04897e5ea2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
kubeshop/testkube-kubectl:1.37.15011b74081fa
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
kubeshop/testkube-minio:2025.10d8e1af6aca99
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
library/nats:2.15.0-alpineac8f88a6494b
stdlib@go1.27.1
1.27.2
natsio/nats-server-config-reloader:0.24.0d758a82a9c20
stdlib@go1.26.5
1.26.9

Open the chart page →

5,308
openelbkubesphere-stable0.5.02 of 2See more

openelb kubesphere-stable 0.5.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.60.0
1.26.9
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

6,372
operatorkube-starrocksVerified publisher1.11.71 of 1See more

operator kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/net@v0.17.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

963
sbomscannerkubewardenVerified publisher0.13.05 of 5See more

sbomscanner kubewarden 0.13.0

5 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/nats:2.14.6-alpinead7a43eb7e33
stdlib@go1.26.7
1.26.9
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.26.9
ghcr.io/kubewarden/sbomscanner/controller:v0.13.0611e21c44268
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/kubewarden/sbomscanner/storage:v0.13.064929d3a8ecf
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/kubewarden/sbomscanner/worker:v0.13.00a8e4e31c890
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,660
venti-stackkuossOfficialVerified publisher0.5.08 of 9See more

venti-stack kuoss 0.5.0

8 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kuoss/eventrouter:v0.4.156226040e1346
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.60.0
1.26.9
ghcr.io/kuoss/lethe:v0.3.3ebdf55fd5705
golang.org/x/net@v0.41.0
stdlib@go1.24.10
0.60.0
1.26.9
ghcr.io/kuoss/venti:v0.3.38ee3e70d77f1
golang.org/x/net@v0.42.0
stdlib@go1.24.10
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.93.1428f088fe6fe
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.13.2508729e0e2d1
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

5,630
librechatlibrechat-openshiftVerified publisher1.9.01 of 3See more

librechat librechat-openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

6,669
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestf1bc435659b9
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

3,934
vclustermainVerified publisher0.17.07 of 10See more

vcluster main 0.17.0

7 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.60.0
1.26.9
registry.k8s.io/etcd:3.6.4-0e36c08168342
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.60.0
1.26.9
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

16,201
stannatsVerified publisher0.13.01 of 2See more

stan nats 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
natsio/prometheus-nats-exporter:latestc623b608e148
stdlib@go1.26.6
1.26.9

Open the chart page →

251

Container images carrying it

6,339 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.2
0.60.0
1.26.9
2
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
2
ghcr.io/appscode/fargocd:v0.1.0c59d775d9a7c
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9
2
ghcr.io/appscode/grafana-tools:v0.8.077c9d29080eb
golang.org/x/net@v0.52.0
stdlib@go1.25.13
0.60.0
1.26.9
2
ghcr.io/appscode/grafana-tools:v0.0.1f60324bca644
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.4
0.60.0
1.26.9
2
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.60.0
1.26.9
2
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
stdlib@go1.24.9
0.60.0
1.26.9
2
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.60.0
1.26.9
2
ghcr.io/appscode/license-proxyserver:v0.1.28dfd7a44f362
golang.org/x/net@v0.57.0
stdlib@go1.25.13
0.60.0
1.26.9
2
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
2
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.60.0
1.26.9
2
ghcr.io/bank-vaults/vault-operator:v1.24.1b5529976f0f6
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
2
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.13
0.60.0
1.26.9
2
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
golang.org/x/net@v0.0.0-20170114055629-f2499483f923
stdlib@go1.15.2
0.60.0
1.26.9
2
ghcr.io/browserless/chromium:v2.57.06bac628b3d82
stdlib@go1.26.7
1.26.9
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.60.0
1.26.9
2
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.60.0
1.26.9
2
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/net@v0.43.0
stdlib@go1.24.7
0.60.0
1.26.9
2
ghcr.io/cerbos/cerbos:0.56.0540643bc67ba
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.25.5
0.60.0
1.26.9
2
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.19.7
0.60.0
1.26.9
2
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.60.0
1.26.9
2
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.60.0
1.26.9
2
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
2
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.15
0.60.0
1.26.9
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
stdlib@go1.18
1.26.9
2
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
stdlib@go1.16.6
1.26.9
2
ghcr.io/dellnoantechnp/bitnami/redis:8.4.029064423c369
stdlib@go1.25.6
1.26.9
2
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.16.2
0.60.0
1.26.9
2
ghcr.io/donkie/spoolman:0.27.07aba565eff77
stdlib@go1.19.8
1.26.9
2
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
golang.org/x/net@v0.15.0
stdlib@go1.21.10
0.60.0
1.26.9
2
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
2
ghcr.io/gotify/server:3.1.144fc5bbd1c06
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9
2
ghcr.io/grafana/grafana-operator:v5.25.0bc572995823f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
stdlib@go1.23.6
0.60.0
1.26.9
2
ghcr.io/headlamp-k8s/headlamp:v0.45.0db3f0e0fc58d
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.26.9
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.476a2170cd0c9
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
2
ghcr.io/jkroepke/kube-webhook-certgen:1.7.47a62bba56a7c
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.38ce13c365c8e
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.5d0e80b2f62fe
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
2
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.60.0
1.26.9
2
ghcr.io/juanfont/headscale:0.29.4:v0.29.48833f828b414
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
2
ghcr.io/juniorjpdj/containers/openssl-kubectl:1.36.1-r5136348264b41
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9
2
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
golang.org/x/net@v0.23.0
stdlib@go1.23.4
0.60.0
1.26.9
2
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
2
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
2
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
golang.org/x/net@v0.37.0
stdlib@go1.23.3
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.