StackRadar

CVE-2026-78663

Unscored

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,566
of 18,071 indexed, latest versions
Container images
6,425
deployed by those charts
Fix available
2 of 3
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,566 of 18,071 indexed charts deploy, on 6,425 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,411
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,172
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-78663GO-2026-6612
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,566 by stars
ChartLatestAffected imagesRadar Score
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,755
helm-ai-kernelmindburn-labsOfficialVerified publisher0.11.12 of 2See more

helm-ai-kernel mindburn-labs 0.11.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/mindburn-labs/helm-ai-kernel:v0.11.10e7a5cd11858
golang.org/x/net@v0.58.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

2,720
mc-routerminecraft-server-chartsVerified publisher1.5.01 of 1See more

mc-router minecraft-server-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
itzg/mc-router:latest64ae69eaa7a6
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

116
mocomoco0.27.01 of 1See more

moco moco 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cybozu-go/moco:0.37.032e7cab1bdd8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

122
mogenius-operatormogeniusOfficial2.30.01 of 2See more

mogenius-operator mogenius 2.30.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/mogenius/mogenius-operator:2.30.051bebfb32413
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

1,013
mongodb-kubernetesmongodb-helm-charts1.13.01 of 1See more

mongodb-kubernetes mongodb-helm-charts 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes:1.13.00184a96e324f
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

99
mortalgpumortalgpuOfficialVerified publisher1.3.71 of 1See more

mortalgpu mortalgpu 1.3.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/maxiv/mortalgpu:1.3.7e1c5c194bbf0
golang.org/x/net@v0.54.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

659
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

4,747
mycelmycelOfficialVerified publisher3.10.01 of 1See more

mycel mycel 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mdenda/mycel:3.10.09e559aa83030
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

266
nacknatsVerified publisher0.35.01 of 1See more

nack nats 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
natsio/jetstream-controller:0.24.058862daca582
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

391
ndb-operatorndb-operatorOfficialVerified publisher0.5.111 of 1See more

ndb-operator ndb-operator 0.5.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/nutanix-cloud-native/ndb-operator/controller:v0.5.8b3927d7b72b9
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

102
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
golang.org/x/net@v0.44.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

4,859
netbird-api-exporternetbird-api-exporterVerified publisher0.2.171 of 1See more

netbird-api-exporter netbird-api-exporter 0.2.17

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/matanbaruch/netbird-api-exporter:0.2.16fcbf2025207a
stdlib@go1.27.1
1.27.2

Open the chart page →

232
netbird-operatornetbird-operator0.8.01 of 1See more

netbird-operator netbird-operator 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/netbirdio/netbird-operator:v0.8.0ae2c26cfc547
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

192
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.60.0
1.26.9

Open the chart page →

6,280
mstreamnicholaswildeVerified publisher2.1.21 of 1See more

mstream nicholaswilde 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/mstream:version-v5.2.522c012bcc43c
golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b297
stdlib@go1.15.5
0.60.0
1.26.9

Open the chart page →

5,749
gateway-apinicklasfrahm-gateway-apiVerified publisher0.2.01 of 1See more

gateway-api nicklasfrahm-gateway-api 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/kubectl:1.33.32c59a3f0726c
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,664
observalobservalVerified publisher1.14.02 of 8See more

observal observal 1.14.0

2 of the 8 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9

Open the chart page →

6,380
aws-xrayokgoloveVerified publisher5.0.01 of 1See more

aws-xray okgolove 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/xray/aws-xray-daemon:3.6.243d051eed000
golang.org/x/net@v0.38.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

538
olivetinolivetinOfficialVerified publisher4.0.01 of 1See more

olivetin olivetin 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jamesread/olivetin:3000.19.0af9d7c4db6dc
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

620
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

7,970
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
stdlib@go1.17.1
1.26.9
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

23,855
secrets-injectoronepassword-connect1.2.01 of 1See more

secrets-injector onepassword-connect 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
1password/kubernetes-secrets-injector:1.0.25884757f7879
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

1,453
opentelemetry-ebpfopentelemetry-helmOfficialVerified publisher0.1.71 of 4See more

opentelemetry-ebpf opentelemetry-helm 0.1.7

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
golang.org/x/net@v0.7.0
stdlib@go1.20
0.60.0
1.26.9

Open the chart page →

3,628
opentelemetry-ebpf-instrumentationopentelemetry-helmOfficialVerified publisher0.14.31 of 1See more

opentelemetry-ebpf-instrumentation opentelemetry-helm 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/opentelemetry-ebpf-instrumentation/ebpf-instrument:v0.14.00b063b9ec47e
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

76
oesopsmxVerified publisher4.0.328 of 25See more

oes opsmx 4.0.32

8 of the 25 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
stdlib@go1.17.2
1.26.9
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
stdlib@go1.16.15
1.26.9
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.60.0
1.26.9
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.19.1
0.60.0
1.26.9
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.60.0
1.26.9
quay.io/opsmxpublic/opa:1.12.084fb1af7401c
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
stdlib@go1.22.2
1.26.9
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.1
0.60.0
1.26.9

Open the chart page →

110,685
pacto-operatorpacto-operatorOfficialVerified publisher5.4.21 of 1See more

pacto-operator pacto-operator 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/trianalab/pacto/operator:5.4.2fc2c05866911
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

99
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
golang.org/x/net@v0.0.0-20220517181318-183a9ca12b87
stdlib@go1.18.3
0.60.0
1.26.9
ipfs/ipfs-cluster:1.0.21511f6d57994
golang.org/x/net@v0.0.0-20220517181318-183a9ca12b87
stdlib@go1.18.3
0.60.0
1.26.9

Open the chart page →

5,472
permifypermifyVerified publisher0.5.01 of 1See more

permify permify 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/permify/permify:v1.3.5f0c6f7d7daa6
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,456
persespersesOfficialVerified publisher0.23.21 of 1See more

perses perses 0.23.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
persesdev/perses:v0.54.0a0e34ddaf9d7
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

324
platzioplatz-ioVerified publisher0.6.51 of 2See more

platzio platz-io 0.6.5

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
platzio/backend:v0.6.5d5e5972f344b
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

3,548
plecopleco0.24.01 of 1See more

pleco pleco 0.24.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/net@v0.39.0
stdlib@go1.21.6
0.60.0
1.26.9

Open the chart page →

1,923
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
stdlib@go1.13.10
1.26.9

Open the chart page →

4,287
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/net@v0.9.0
stdlib@go1.20.3
0.60.0
1.26.9

Open the chart page →

2,777
prometheus-memcached-exporterprometheus-communityVerified publisher0.6.01 of 1See more

prometheus-memcached-exporter prometheus-community 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/memcached-exporter:v0.17.0995c80e3ffbe
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

113
prometheus-pgbouncer-exporterprometheus-communityVerified publisher0.10.11 of 1See more

prometheus-pgbouncer-exporter prometheus-community 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/pgbouncer-exporter:v0.12.130f31b6c2efd
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

449
prometheus-systemd-exporterprometheus-communityVerified publisher0.5.21 of 1See more

prometheus-systemd-exporter prometheus-community 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/systemd-exporter:v0.7.078c03f875dfb
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

1,127
prometheus-yet-another-cloudwatch-exporterprometheus-communityVerified publisher0.48.01 of 1See more

prometheus-yet-another-cloudwatch-exporter prometheus-community 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/yet-another-cloudwatch-exporter:v0.68.0651b4041d9c3
stdlib@go1.26.8
1.26.9

Open the chart page →

52
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.60.0
1.26.9
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.14.12
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9

Open the chart page →

16,682
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

6,243
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

3,837
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.26.9

Open the chart page →

14,419
wordpress-hardenedriotkit-org2.0.02 of 2See more

wordpress-hardened riotkit-org 2.0.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/waf-proxy:snapshot683656fdace2
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.3
0.60.0
1.26.9
ghcr.io/riotkit-org/wordpress-hardened:v2.0edc6b69873be
stdlib@go1.17.9
1.26.9

Open the chart page →

8,265
backrestrobertobochetVerified publisher0.7.01 of 1See more

backrest robertobochet 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
garethgeorge/backrest:v1.14.1b85297975428
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

1,200
supabaserock8sVerified publisher0.0.61 of 1See more

supabase rock8s 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9

Open the chart page →

607
rqliterqliteOfficialVerified publisher2.0.01 of 1See more

rqlite rqlite 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rqlite/rqlite:9.1.37b992a526eee
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

1,682
qbittorrent-vpnrtomik-helm-chartsVerified publisher0.0.21 of 2See more

qbittorrent-vpn rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.40.02b42bfa04675
golang.org/x/net@v0.31.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,654
sabliersablier-helm-chartsOfficialVerified publisher1.8.11 of 1See more

sablier sablier-helm-charts 1.8.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
sablierapp/sablier:1.16.1413704376656
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

336
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
stdlib@go1.18.1
1.26.9

Open the chart page →

4,455
seaweedfs-csi-driverseaweedfs-csi-driver0.2.407 of 7See more

seaweedfs-csi-driver seaweedfs-csi-driver 0.2.40

7 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
chrislusf/seaweedfs-csi-driver:v1.4.341fca534c9001
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
chrislusf/seaweedfs-mount:v1.4.347c6250e96001
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9

Open the chart page →

8,130

Container images carrying it

6,425 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9
7
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
7
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/net@v0.30.0
stdlib@go1.23.4
0.60.0
1.26.9
7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9
7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9
7
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.60.0
1.26.9
7
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
7
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
7
bitnami/kubectl:latest999d5eb28f40
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
6
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.60.0
1.26.9
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9
6
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
6
cloudflare/cloudflared:2026.10.0:latest9b49eed8f628
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
6
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.60.0
1.26.9
6
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
6
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.60.0
1.26.9
6
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9
6
library/mariadb:10:10.117db29378d4fd
stdlib@go1.24.6
1.26.9
6
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.26.9
6
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9
6
library/registry:2:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.26.9
6
library/ubuntu:latestf144425ff09b
stdlib@go1.26.7
1.26.9
6
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.26.9
6
postgis/postgis:17-3.5:latest01a6a70e41e6
stdlib@go1.18.2
1.26.9
6
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.60.0
1.26.9
6
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
6
traefik/whoami:latest:v1.12.0c4717a8d1f01
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
6
victoriametrics/operator:v0.75.078da26b41a81
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
6
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.60.0
1.26.9
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.26.9
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.60.0
1.26.9
6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.60.0
1.26.9
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.60.0
1.26.9
6
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.26.9
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.60.0
1.26.9
6
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.60.0
1.26.9
6
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.60.0
1.26.9
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
6
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
6
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.106b52bd4dbe3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
6
quay.io/prometheus/pushgateway:v1.11.491a56b89b97d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
6
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
6
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
6
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9
6

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.