StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
carettagroundcover0.0.163 of 3See more

caretta groundcover 0.0.16

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18
0.60.0
1.26.9
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.60.0
1.26.9
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

9,649
ghostgroundhog2k0.212.161 of 1See more

ghost groundhog2k 0.212.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/ghost:6.69.055131b90d48c
stdlib@go1.24.6
1.26.9

Open the chart page →

1,962
growthbookgrowthbook5.1.01 of 2See more

growthbook growthbook 5.1.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/mongodb:latestad05bb9a19fa
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,420
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.46ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

5,095
oscargrycapOfficialVerified publisher4.2.01 of 2See more

oscar grycap 4.2.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/grycap/oscar:latest1afdce33dacf
golang.org/x/net@v0.51.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

570
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
stdlib@go1.21.13
1.26.9

Open the chart page →

11,392
haproxy-unified-gatewayhaproxytechVerified publisher1.2.01 of 1See more

haproxy-unified-gateway haproxytech 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
haproxytech/haproxy-unified-gateway:1.0.7b9bffe2d0fd1
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

925
boundary-controllerhashicorpVerified publisher0.2.01 of 1See more

boundary-controller hashicorp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/boundary-enterprise:1.0.2-ent3a8061968ee4
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

344
boundary-workerhashicorpVerified publisher0.2.01 of 1See more

boundary-worker hashicorp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/boundary-enterprise:1.0.2-ent3a8061968ee4
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

344
terraform-cloud-operatorhashicorpVerified publisher2.5.02 of 2See more

terraform-cloud-operator hashicorp 2.5.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
golang.org/x/net@v0.24.0
stdlib@go1.22.4
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.18.0754ab2a723c8
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

2,450
hawkhawk1.1.53 of 4See more

hawk hawk 1.1.5

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.17.9
0.60.0
1.26.9
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.26.9
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
golang.org/x/net@v0.19.0
stdlib@go1.20.11
0.60.0
1.26.9

Open the chart page →

17,346
hcloud-cloud-controller-managerhcloud1.39.01 of 1See more

hcloud-cloud-controller-manager hcloud 1.39.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.39.0d6fee5698759
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

238
clickstackhdx-oss-v21.1.11 of 5See more

clickstack hdx-oss-v2 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mongo:5.0.32-focal3b6c281e1c08
golang.org/x/net@v0.47.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

5,420
guacamolehelmforgeVerified publisher1.5.32 of 5See more

guacamole helmforge 1.5.3

2 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.26.9

Open the chart page →

10,587
mariadbhelmforgeVerified publisher2.1.21 of 1See more

mariadb helmforge 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:13.0.2d4fdec0510ad
stdlib@go1.26.7
1.26.9

Open the chart page →

1,928
matomohelmforgeVerified publisher2.3.21 of 3See more

matomo helmforge 2.3.2

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:26.7.0ade067ae2fb1
stdlib@go1.24.6
1.26.9

Open the chart page →

3,302
opencloudhelmforgeVerified publisher1.0.01 of 1See more

opencloud helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
opencloudeu/opencloud:7.2.46d992ccc5f1c
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,092
uptime-kumahelmforgeVerified publisher1.5.151 of 1See more

uptime-kuma helmforge 1.5.15

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.5c74379ac4509
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

36,482
velerohelmforgeVerified publisher1.4.122 of 2See more

velero helmforge 1.4.12

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
velero/velero:v1.18.4c89fb5b6d1fd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
velero/velero-plugin-for-aws:v1.14.07e82f717f44e
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,737
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

5,369
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

8,269
spirehelm-spireVerified publisher0.30.37 of 10See more

spire helm-spire 0.30.3

7 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/spiffe/oidc-discovery-provider:1.15.3bb95f13c2b4e
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
golang.org/x/net@v0.42.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/spiffe/spire-agent:1.15.341b0dcd8b258
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/spiffe/spire-controller-manager:0.8.019e418e9d7f2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/spiffe/spire-server:1.15.34082f30d3e0d
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

3,359
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
golang.org/x/net@v0.15.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

18,788
buildbarnhermetiq-buildbarnVerified publisher0.9.52 of 4See more

buildbarn hermetiq-buildbarn 0.9.5

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/buildbarn/bb-scheduler:20260908T142432Z-77f7642f627ab242890
golang.org/x/net@v0.55.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/buildbarn/bb-storage:20260908T142448Z-db6204132ebc54b769b
golang.org/x/net@v0.55.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

534
hivemq-platform-operatorhivemqOfficialVerified publisher0.2.261 of 1See more

hivemq-platform-operator hivemq 0.2.26

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hivemq/hivemq-platform-operator:2.2.2a919f990141b
stdlib@go1.26.5
1.26.9

Open the chart page →

1,423
hivemq-swarmhivemqOfficialVerified publisher0.2.711 of 1See more

hivemq-swarm hivemq 0.2.71

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hivemq/hivemq-swarm:4.56.08d5f6a6f48b0
stdlib@go1.26.7
1.26.9

Open the chart page →

676
hiverhiverVerified publisher0.1.459 of 10See more

hiver hiver 0.1.45

9 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hiversh/antigravity:0.1.45-microvm0e36d98402bc
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
hiversh/browser:0.1.45-microvmb5048c6342ce
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
hiversh/claude:0.1.45-microvm2fbf9f264498
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
hiversh/codex:0.1.45-microvm4f43130f51e5
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
hiversh/controller:0.1.45b0b85f8942c7
golang.org/x/net@v0.56.0
stdlib@go1.19.8
0.60.0
1.26.9
hiversh/copilot:0.1.45-microvm50c07b84f298
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
hiversh/node:0.1.45-alpine-microvm836a37641941
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
golang.org/x/net@v0.56.0
stdlib@go1.19.8
0.60.0
1.26.9
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
golang.org/x/net@v0.56.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

29,933
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.60.0
1.26.9

Open the chart page →

4,041
holoinsightholoinsight0.2.53 of 6See more

holoinsight holoinsight 0.2.5

3 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
holoinsight/otelcontribcol:latest42ba8dc3113c
golang.org/x/net@v0.8.0
stdlib@go1.19
0.60.0
1.26.9
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9
quay.io/prometheus/prometheus:latestefd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

29,949
holoinsight-agentholoinsight0.2.51 of 2See more

holoinsight-agent holoinsight 0.2.5

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
holoinsight/agent:latest5c3994e742f8
golang.org/x/net@v0.5.0
stdlib@go1.22.1
0.60.0
1.26.9

Open the chart page →

2,405
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.26.9

Open the chart page →

8,857
homer-operatorhomer-operator0.3.41 of 2See more

homer-operator homer-operator 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/arch-anes/homer-operator:0.3.404e3b7d1bfa6
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

500
honeycombhoneycomb1.9.41 of 1See more

honeycomb honeycomb 1.9.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
honeycombio/honeycomb-kubernetes-agent:2.8.044bfbb103ebb
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

617
refineryhoneycomb3.4.01 of 2See more

refinery honeycomb 3.4.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/honeycombio/refinery/refinery:3.4.0d437676941d6
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

786
hpe-greenlake-file-csi-driverhpe-storageVerified publisher2.6.45 of 7See more

hpe-greenlake-file-csi-driver hpe-storage 2.6.4

5 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

8,746
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
golang.org/x/net@v0.24.0
stdlib@go1.21.12
0.60.0
1.26.9

Open the chart page →

5,061
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
golang.org/x/net@v0.0.0-20210907225631-ff17edfbf26d
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

2,603
hybrid-csi-pluginhybrid-csi-plugin0.1.121 of 1See more

hybrid-csi-plugin hybrid-csi-plugin 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/hybrid-csi-provisioner:v0.3.1221e07794a8a
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

721
spoolmanideaplexusVerified publisher2.10.21 of 1See more

spoolman ideaplexus 2.10.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.27.07aba565eff77
stdlib@go1.19.8
1.26.9

Open the chart page →

2,563
idle-reaperidle-reaperVerified publisher0.1.41 of 1See more

idle-reaper idle-reaper 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/b100to/idle-reaper:0.1.447b4a0e091f0
golang.org/x/net@v0.49.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

313
backendikusi-bk-chart1.0.31 of 3See more

backend ikusi-bk-chart 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:15724292da1f2e
stdlib@go1.24.6
1.26.9

Open the chart page →

6,823
ilum-coreilumOfficialVerified publisher6.7.32 of 5See more

ilum-core ilum 6.7.3

2 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
stdlib@go1.20.12
0.60.0
1.26.9

Open the chart page →

4,859
ilum-jupyterilumVerified publisher6.7.31 of 2See more

ilum-jupyter ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamisecure/gitdigest-pinned72ae5bd9715f
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,059
odooimioVerified publisher3.2.11 of 3See more

odoo imio 3.2.1

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:17.10ebba4f4de37f
stdlib@go1.24.6
1.26.9

Open the chart page →

3,868
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.26.9

Open the chart page →

18,447
webhook-broker-chartimytech0.2.41 of 1See more

webhook-broker-chart imytech 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
golang.org/x/net@v0.33.0
stdlib@go1.23.0
0.60.0
1.26.9

Open the chart page →

1,741
inbucketinbucketVerified publisher2.5.01 of 1See more

inbucket inbucket 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
inbucket/inbucket:3.0.01f10a0efea69
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

3,193
inference-manager-serverinference-manager-server1.46.01 of 1See more

inference-manager-server inference-manager-server 1.46.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/inference-manager-server:1.46.00bbb5f5ddf71
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

542
telegraf-operatorinfluxdata1.4.01 of 1See more

telegraf-operator influxdata 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
golang.org/x/net@v0.17.0
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

1,666
valkey-clusterinnagoVerified publisher1.1.01 of 2See more

valkey-cluster innago 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.66.0d98e6db8094f
stdlib@go1.23.2
1.26.9

Open the chart page →

3,270

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/p3k6k6h3/mdai-event-hub:0.1.1118cae836e9c7
golang.org/x/net@v0.52.0
stdlib@go1.25.11
0.60.0
1.26.9
2
public.ecr.aws/p3k6k6h3/mdai-gateway:0.1.100dfb323978f6
golang.org/x/net@v0.52.0
stdlib@go1.25.11
0.60.0
1.26.9
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/net@v0.34.0
stdlib@go1.22.2
0.60.0
1.26.9
2
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9
2
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.60.0
1.26.9
2
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.1
0.60.0
1.26.9
2
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
golang.org/x/net@v0.28.0
stdlib@go1.23.0
0.60.0
1.26.9
2
quay.io/cephcsi/cephcsi:v3.18.1a8c0653a9565
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9
2
quay.io/cephcsi/cephcsi:v3.14.2dc4bbac6efe1
golang.org/x/net@v0.37.0
stdlib@go1.23.4
0.60.0
1.26.9
2
quay.io/cephcsi/ceph-csi-operator:v1.1.0c42c95c36fa2
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82af7382699576
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
2
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
2
quay.io/cilium/tetragon-operator:v1.7.1cd8b71f6860e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
2
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
2
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.60.0
1.26.9
2
quay.io/coreos/etcd:v3.7.2e9afa62b1e91
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.10
0.60.0
1.26.9
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.60.0
1.26.9
2
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18.1
0.60.0
1.26.9
2
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.60.0
1.26.9
2
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.60.0
1.26.9
2
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.60.0
1.26.9
2
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-cainjector:v1.17.2ec56edb1161d
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-startupapicheck:v1.17.2e18989b4f912
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9
2
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
2
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.60.0
1.26.9
2
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.60.0
1.26.9
2
quay.io/kubevirt/kubevirt-csi-driver:latestbbc43bc25025
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.60.0
1.26.9
2
quay.io/metallb/controller:v0.16.1f51ab515de9c
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
2
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
golang.org/x/net@v0.39.0
stdlib@go1.25.8
0.60.0
1.26.9
2
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.60.0
1.26.9
2
quay.io/metallb/speaker:v0.16.116561e96531e
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
2
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.