StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
versitygw-webhook-pulsar-proxyalpineworks0.1.11 of 1See more

versitygw-webhook-pulsar-proxy alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,379
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
alustan-helmalustan-helm1.0.01 of 1See more

alustan-helm alustan-helm 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alustan/install-argocd:1.0.0c16c34f46ad3
golang.org/x/net@v0.19.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

2,449
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
stdlib@go1.19.13
0.60.0
1.26.9
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

34,526
ampsamps0.1.95 of 10See more

amps amps 0.1.9

5 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/vault:1.9.2ff9b17b0cefe
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.5
0.60.0
1.26.9
library/nats:2.7.2-alpine8b3fb2423a8c
stdlib@go1.17.6
1.26.9
natsio/nats-box:0.8.1b7f9328145f4
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.6
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.6.2ad0374303b13
stdlib@go1.15.14
1.26.9
natsio/prometheus-nats-exporter:0.9.14665cdc7e749
stdlib@go1.16.13
1.26.9

Open the chart page →

15,571
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

2,199
anchore-admission-controlleranchore-charts0.9.02 of 2See more

anchore-admission-controller anchore-charts 0.9.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
anchore/kubernetes-admission-controller:v0.8.51a1a374658c8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
cfssl/cfssl:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

8,723
ecs-inventoryanchore-charts0.1.01 of 1See more

ecs-inventory anchore-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
anchore/ecs-inventory:v1.5.12b424b3b9a03
stdlib@go1.26.8
1.26.9

Open the chart page →

93
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.60.0
1.26.9

Open the chart page →

2,041
cert-manager-webhook-inwxandibraeuVerified publisher0.9.01 of 1See more

cert-manager-webhook-inwx andibraeu 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

933
music-assistant-serverandibraeuVerified publisher2.1.31 of 1See more

music-assistant-server andibraeu 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.528023f8c0d96
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

4,664
opencloudandibraeuVerified publisher1.0.01 of 1See more

opencloud andibraeu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

200
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,764
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

3,078
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.26.9

Open the chart page →

3,244
dnsmadeeasy-webhookangelnu6.0.71 of 1See more

dnsmadeeasy-webhook angelnu 6.0.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/angelnu/dnsmadeeasy-webhook:v1.9.0a5ca158b1f02
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

1,278
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.26.9

Open the chart page →

122,605
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.6e1074e92a452
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

141
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

3,637
ddosifyanteonVerified publisher1.7.55 of 13See more

ddosify anteon 1.7.5

5 of the 13 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.60.0
1.26.9
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.26.9
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
stdlib@go1.19.11
0.60.0
1.26.9

Open the chart page →

31,303
antmediaantmediaVerified publisher3.1.03 of 4See more

antmedia antmedia 3.1.0

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mongo:8.0d0d926f94df0
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

6,115
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

4,871
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:latestb28bae15e219
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

2,246
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
antrea/antrea-ui-backend:v0.8.019f3c0113330
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

3,923
flow-aggregatorantreaVerified publisher2.7.01 of 1See more

flow-aggregator antrea 2.7.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
antrea/flow-aggregator:v2.7.0065193e7572f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,079
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

3,890
devenvanza-labsVerified publisher0.1.21 of 3See more

devenv anza-labs 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
tailscale/tailscale:stablec507f3a2a6ab
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

249
glauthanza-labsVerified publisher1.0.21 of 1See more

glauth anza-labs 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/glauth/glauth:v2.5.4905b5db533fc
golang.org/x/net@v0.58.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

1,093
imagepullerapache-pulsar-helm-chart-repo1.0.11 of 2See more

imagepuller apache-pulsar-helm-chart-repo 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/docker:latest0b6d18a4a222
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

222
kesque-dashboardapache-pulsar-helm-chart-repo0.0.51 of 5See more

kesque-dashboard apache-pulsar-helm-chart-repo 0.0.5

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:latestf1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

4,322
pulsar-monitorapache-pulsar-helm-chart-repo0.1.61 of 1See more

pulsar-monitor apache-pulsar-helm-chart-repo 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kesque/pulsar-monitor:1.0.8ce85c1e7d613
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.4
0.60.0
1.26.9

Open the chart page →

4,242
apipingapiping1.5.01 of 1See more

apiping apiping 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
udhos/apiping:1.5.041ab9bae6f3b
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

1,531
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/net@v0.25.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

3,701
api-usage-cleanerapi-usage-cleaner1.16.01 of 1See more

api-usage-cleaner api-usage-cleaner 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.26.9

Open the chart page →

935
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.26.9
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.26.9

Open the chart page →

24,882
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.5
0.60.0
1.26.9
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.60.0
1.26.9
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.60.0
1.26.9

Open the chart page →

15,653
app-movies-seriesapp-movies-seriesVerified publisher0.1.01 of 2See more

app-movies-series app-movies-series 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.26.9

Open the chart page →

4,488
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

2,887
aceappscodeVerified publisher2026.9.112 of 2See more

ace appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

3,512
ace-installerappscodeVerified publisher2026.9.112 of 2See more

ace-installer appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

3,871
ace-installer-certifiedappscodeVerified publisher2026.9.112 of 2See more

ace-installer-certified appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
ghcr.io/appscode/b3:v2026.9.114b5993768740
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

4,039
acerproxyappscodeVerified publisher2026.9.111 of 1See more

acerproxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,753
aceshifterappscodeVerified publisher2026.9.111 of 1See more

aceshifter appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/aceshifter:v0.0.3e5f5c254a55a
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,415
appcatalogappscodeVerified publisher2023.3.231 of 1See more

appcatalog appscode 2023.3.23

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/appcatalog:v0.0.109709a346888
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

2,299
appscode-otel-stackappscodeVerified publisher2026.9.223 of 3See more

appscode-otel-stack appscode 2026.9.22

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.150.089490ef63b72
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

2,574
auditorappscodeVerified publisher2023.10.11 of 1See more

auditor appscode 2023.10.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

2,449
aws-credential-managerappscodeVerified publisher2026.4.161 of 1See more

aws-credential-manager appscode 2026.4.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/aws-credential-manager:v0.1.00511bbe501c3
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

910
azure-credential-managerappscodeVerified publisher2026.4.161 of 1See more

azure-credential-manager appscode 2026.4.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/azure-credential-manager:v0.1.0f5c797f7fbe7
golang.org/x/net@v0.49.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,189
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

2,887

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/knative-releases/knative.dev/serving/cmd/activator031408ec516f
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
2
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler3502bb5aa60f
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
2
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa7405faeb7636
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
2
gcr.io/knative-releases/knative.dev/serving/cmd/controller5b93308a392c
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
2
gcr.io/knative-releases/knative.dev/serving/cmd/webhook50831d9aaa69
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
2
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.2
0.60.0
1.26.9
2
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
2
ghcr.io/appscode/fargocd:v0.1.0c59d775d9a7c
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9
2
ghcr.io/appscode/grafana-tools:v0.8.077c9d29080eb
golang.org/x/net@v0.52.0
stdlib@go1.25.13
0.60.0
1.26.9
2
ghcr.io/appscode/grafana-tools:v0.0.1f60324bca644
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.4
0.60.0
1.26.9
2
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.60.0
1.26.9
2
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
stdlib@go1.24.9
0.60.0
1.26.9
2
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.60.0
1.26.9
2
ghcr.io/appscode/license-proxyserver:v0.1.28dfd7a44f362
golang.org/x/net@v0.57.0
stdlib@go1.25.13
0.60.0
1.26.9
2
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
2
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.60.0
1.26.9
2
ghcr.io/bank-vaults/vault-operator:v1.24.1b5529976f0f6
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
2
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.13
0.60.0
1.26.9
2
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
golang.org/x/net@v0.0.0-20170114055629-f2499483f923
stdlib@go1.15.2
0.60.0
1.26.9
2
ghcr.io/browserless/chromium:v2.57.06bac628b3d82
stdlib@go1.26.7
1.26.9
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.60.0
1.26.9
2
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.60.0
1.26.9
2
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/net@v0.43.0
stdlib@go1.24.7
0.60.0
1.26.9
2
ghcr.io/cerbos/cerbos:0.56.0540643bc67ba
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.25.5
0.60.0
1.26.9
2
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.19.7
0.60.0
1.26.9
2
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.60.0
1.26.9
2
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
golang.org/x/net@v0.8.0
stdlib@go1.18.10
0.60.0
1.26.9
2
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
2
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.15
0.60.0
1.26.9
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
stdlib@go1.18
1.26.9
2
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
stdlib@go1.16.6
1.26.9
2
ghcr.io/dellnoantechnp/bitnami/redis:8.4.029064423c369
stdlib@go1.25.6
1.26.9
2
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.16.2
0.60.0
1.26.9
2
ghcr.io/donkie/spoolman:0.27.07aba565eff77
stdlib@go1.19.8
1.26.9
2
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
golang.org/x/net@v0.15.0
stdlib@go1.21.10
0.60.0
1.26.9
2
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
2
ghcr.io/gotify/server:3.1.144fc5bbd1c06
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9
2
ghcr.io/grafana/grafana-operator:v5.25.0bc572995823f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/net@v0.23.0
stdlib@go1.23.6
0.60.0
1.26.9
2
ghcr.io/hatchet-dev/hatchet/hatchet-engine:v0.110.5185c4311d23f
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
ghcr.io/headlamp-k8s/headlamp:v0.45.0db3f0e0fc58d
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.26.9
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.476a2170cd0c9
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
2
ghcr.io/jkroepke/kube-webhook-certgen:1.7.47a62bba56a7c
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.38ce13c365c8e
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
2
ghcr.io/jkroepke/kube-webhook-certgen:1.8.5d0e80b2f62fe
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
2
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.