StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
stdlib@go1.22.4
1.26.9
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
stdlib@go1.26.0
1.26.9

Open the chart page →

9,813
nsqbeeinventor1.3.01 of 1See more

nsq beeinventor 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
nsqio/nsq:v1.3.01a369c146af7
stdlib@go1.21.5
1.26.9

Open the chart page →

1,322
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
golang.org/x/net@v0.8.0
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

4,227
kube-prometheuschoerodon9.3.14 of 7See more

kube-prometheus choerodon 9.3.1

4 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.60.0
1.26.9
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
stdlib@go1.13.11
0.60.0
1.26.9
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
stdlib@go1.13.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.3
0.60.0
1.26.9

Open the chart page →

17,143
cloudflare-ddnscloudflareVerified publisher1.0.31 of 1See more

cloudflare-ddns cloudflare 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/aureum-cloud/cloudflare-ddns:latestaeb75d1605f4
stdlib@go1.23.12
1.26.9

Open the chart page →

622
timescaledbcloudpirates-timescaledbVerified publisher0.13.121 of 1See more

timescaledb cloudpirates-timescaledb 0.13.12

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
timescale/timescaledb:2.30.2-pg17b346edcdb51a
stdlib@go1.24.6
1.26.9

Open the chart page →

1,085
openstack-cinder-csicloud-provider-openstack2.36.57 of 7See more

openstack-cinder-csi cloud-provider-openstack 2.36.5

7 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/cinder-csi-plugin:v1.36.078adaeb154c7
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.10.0be59d0556508
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

6,419
csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher1.8.25 of 5See more

csi-secrets-store-provider-azure csi-secrets-store-provider-azure 1.8.2

5 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.8.2519f3891316a
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.14.06cb172e3de7e
golang.org/x/net@v0.40.0
stdlib@go1.26.5
0.60.0
1.26.9
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
golang.org/x/net@v0.39.0
stdlib@go1.25.7
0.60.0
1.26.9
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
golang.org/x/net@v0.47.0
stdlib@go1.26.3
0.60.0
1.26.9
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver-crds:v1.5.6cb0112636dc4
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

4,813
paperless-ngxfmjstudios0.2.83 of 5See more

paperless-ngx fmjstudios 0.2.8

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
stdlib@go1.19.8
1.26.9

Open the chart page →

35,065
minifluxgabe565Verified publisher0.9.21 of 2See more

miniflux gabe565 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,957
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.24.061d866e93b56
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.60.0
1.26.9

Open the chart page →

3,934
waypointhashicorpVerified publisher0.1.211 of 2See more

waypoint hashicorp 0.1.21

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/waypoint:0.11.397d521a27498
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

4,963
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

9,407
jaeger-all-in-onejaeger-all-in-oneVerified publisher0.1.121 of 1See more

jaeger-all-in-one jaeger-all-in-one 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.55f6b5d09073f1
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.60.0
1.26.9

Open the chart page →

1,834
cassandrakubelauncherVerified publisher0.1.291 of 1See more

cassandra kubelauncher 0.1.29

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinned4a2625365fc6
stdlib@go1.26.7
1.26.9

Open the chart page →

1,545
etcdkubelauncherVerified publisher0.4.61 of 1See more

etcd kubelauncher 0.4.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinnedd139ad1e93ea
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

682
kafkakubelauncherVerified publisher0.1.281 of 1See more

kafka kubelauncher 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned0b761e55e9ef
stdlib@go1.26.7
1.26.9

Open the chart page →

1,406
keycloakkubelauncherVerified publisher0.5.01 of 1See more

keycloak kubelauncher 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinned85e8ad3172a2
stdlib@go1.26.7
1.26.9

Open the chart page →

655
kubectlkubelauncherVerified publisher0.3.01 of 1See more

kubectl kubelauncher 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned15ce1bd84ddc
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

981
mariadbkubelauncherVerified publisher1.0.01 of 1See more

mariadb kubelauncher 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mariadbdigest-pinned6f03ec42a46d
stdlib@go1.26.7
1.26.9

Open the chart page →

1,006
mongodbkubelauncherVerified publisher0.4.71 of 1See more

mongodb kubelauncher 0.4.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinnedf70e33e17161
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

910
rabbitmqkubelauncherVerified publisher0.2.161 of 1See more

rabbitmq kubelauncher 0.2.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinned7be1b7704a6a
stdlib@go1.22.2
1.26.9

Open the chart page →

1,280
rediskubelauncherVerified publisher0.5.41 of 1See more

redis kubelauncher 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedcb826b867e4b
stdlib@go1.26.7
1.26.9

Open the chart page →

610
zookeeperkubelauncherVerified publisher0.2.121 of 1See more

zookeeper kubelauncher 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/zookeeperdigest-pinned9a85b8701c5e
stdlib@go1.26.7
1.26.9

Open the chart page →

1,209
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
itzg/bungeecord:latest7b7ff61d2a60
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

3,267
ntfyntfyVerified publisher0.5.231 of 1See more

ntfy ntfy 0.5.23

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.29.04c599cf08189
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

141
mauticone-acre-fundVerified publisher0.1.71 of 3See more

mautic one-acre-fund 0.1.7

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

3,701
opentelemetry-kube-stackopentelemetry-helmOfficialVerified publisher0.24.32 of 2See more

opentelemetry-kube-stack opentelemetry-helm 0.24.3

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.159.02ceb3b541295
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

951
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.15
0.60.0
1.26.9

Open the chart page →

5,546
dex-k8s-authenticatorsagikazarmarkVerified publisher0.0.31 of 1See more

dex-k8s-authenticator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.60.0
1.26.9

Open the chart page →

3,961
thanosstevehipwellVerified publisher1.24.11 of 1See more

thanos stevehipwell 1.24.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

426
gatustwin1.5.01 of 1See more

gatus twin 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
twinproduction/gatus:v5.34.03fff895e77d3
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,130
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
stdlib@go1.24.6
1.26.9

Open the chart page →

4,158
caddyalekcVerified publisher0.9.21 of 1See more

caddy alekc 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/caddy:2.11.7-alpined76116d819d5
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

141
aspnet-corebitnamiVerified publisher9.5.11 of 3See more

aspnet-core bitnami 9.5.1

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/git:latest27e3b3fe7123
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

166
haproxybitnamiVerified publisher4.2.111 of 1See more

haproxy bitnami 4.2.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/haproxy:latest5b57bac338a2
golang.org/x/net@v0.59.0
0.60.0

Open the chart page →

35
yopasscloudhippieVerified publisher9.19.01 of 1See more

yopass cloudhippie 9.19.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jhaals/yopass:14.10.06c33d9c813f7
stdlib@go1.27.1
1.27.2

Open the chart page →

476
connaisseurconnaisseurVerified publisher2.13.02 of 2See more

connaisseur connaisseur 2.13.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
stdlib@go1.18.2
1.26.9
securesystemsengineering/connaisseur:v3.13.0cef2efbd8bd3
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

4,109
kubeviewcowboysysopVerified publisher6.0.01 of 1See more

kubeview cowboysysop 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

2,541
dependabot-gitlabdependabot-gitlabVerified publisher6.3.03 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.60.0
1.26.9
library/postgres:18.6-alpine77f585114c32
stdlib@go1.24.6
1.26.9
pgautoupgrade/pgautoupgrade:18-alpine2245aabc5b80
stdlib@go1.24.6
1.26.9

Open the chart page →

43,319
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.26.9

Open the chart page →

6,403
devtron-operatordevtron0.23.310 of 11See more

devtron-operator devtron 0.23.3

10 of the 11 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.60.0
1.26.9
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.26.9
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.60.0
1.26.9
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.60.0
1.26.9
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.60.0
1.26.9
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.60.0
1.26.9
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.26.9
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

41,631
drone-runner-kubedroneVerified publisher0.1.101 of 1See more

drone-runner-kube drone 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

3,026
fluent-operatorfluent4.3.01 of 1See more

fluent-operator fluent 4.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluent-operator/fluent-operator:3.10.03108194a4ecc
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

362
gatekeepergogatekeeperVerified publisher0.1.661 of 1See more

gatekeeper gogatekeeper 0.1.66

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/gogatekeeper/gatekeeper:5.0.03d45202b06be
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

131
grafana-operatorgrafana5.25.01 of 1See more

grafana-operator grafana 5.25.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/grafana/grafana-operator:v5.25.0bc572995823f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

153
kubernetes-ingresshaproxytechVerified publisher1.54.21 of 1See more

kubernetes-ingress haproxytech 1.54.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:3.2.156185ab228aa6
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

524
envoy-gatewayhelmforgeVerified publisher2.1.23 of 3See more

envoy-gateway helmforge 2.1.2

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.9.10049bcb384c5
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
helmforge/kubectl:1.35.3c3f97e954c47
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
mccutchen/go-httpbin:v2.15.024528cf5229d
stdlib@go1.23.1
1.26.9

Open the chart page →

3,386
n8nhelmforgeVerified publisher2.1.31 of 2See more

n8n helmforge 2.1.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
n8nio/runners:2.41.31522f8179b76
stdlib@go1.25.11
1.26.9

Open the chart page →

1,948
ilumilumOfficialVerified publisher6.7.36 of 19See more

ilum ilum 6.7.3

6 of the 19 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
bitnamisecure/gitdigest-pinned72ae5bd9715f
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
gitea/gitea:1.22.376f516a1a8c2
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.60.0
1.26.9
ilum/api:6.7.3624fd09528c8
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
stdlib@go1.20.12
0.60.0
1.26.9

Open the chart page →

27,560

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
adguard/adguardhome:v0.107.3843ec119419a9
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.595d5e3aef39a8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.767157eb1dc3b2
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.737fbf01d73ecb
golang.org/x/net@v0.50.0
stdlib@go1.25.7
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.0-b.5a9668737b1d6
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.6
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.7b9974aed13d0
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.9
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.56c64a0b37f7b9
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.65d765078d2140
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
1
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.2
0.60.0
1.26.9
1
adyanth/cloudflare-operator6b168dc237d5
golang.org/x/net@v0.39.0
stdlib@go1.24.4
0.60.0
1.26.9
1
aerokube/moon:1.9.17da76ca51220d
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
1
aerokube/moon-api:1.9.176b6323e75785
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
1
aerokube/selenoid-ui:1.10.113f3e299509fd
golang.org/x/net@v0.10.0
stdlib@go1.21.5
0.60.0
1.26.9
1
aerospike/aerospike-kubernetes-operator:4.5.070a9eeb991b8
golang.org/x/net@v0.54.0
stdlib@go1.25.10
0.60.0
1.26.9
1
afgane/galaxy-k8s-monitor:latest457173db5640
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.60.0
1.26.9
1
agentarea/agentarea-events:latest71a89daaa2c6
stdlib@go1.25.14
1.26.9
1
agentarea/agentarea-mcp-manager:latest0e7e53fef298
golang.org/x/net@v0.58.0
stdlib@go1.25.14
0.60.0
1.26.9
1
agentarea/agentarea-mcp-runner:latest9030cc19a0fc
stdlib@go1.19.8
1.26.9
1
aibrix/controller-manager:v0.7.076aabbbfda79
golang.org/x/net@v0.34.0
stdlib@go1.22.12
0.60.0
1.26.9
1
aibrix/gateway-plugins:v0.7.05b93ea4c753a
golang.org/x/net@v0.34.0
stdlib@go1.22.12
0.60.0
1.26.9
1
airbyte/db:2.4.091f7b485f019
stdlib@go1.24.6
1.26.9
1
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
1
airbyte/pod-sweeper:1.5.198d2c39d512e
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.60.0
1.26.9
1
aistorage/ais-operator:v4.1.0151fc5b9f917
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
ajilaag/clamav-rest:latestad689c7b75b1
stdlib@go1.26.0
1.26.9
1
akeyless/akeyless-csi-provider:lateste48bddc5dd72
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
akeyless/base:latest759e4289fae8
stdlib@go1.26.3
1.26.9
1
akeyless/base-rhel:0.0.14ba8900a0061
stdlib@go1.22.1
1.26.9
1
akeyless/gateway:5.5.053301745cb50
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
akeyless/k8s-webhook-server:0.39.0996cd9afb3b4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
stdlib@go1.22.5
1.26.9
1
aktosecurity/akto-threat-detection-backend:1.18.75a0c66e59678
stdlib@go1.26.7
1.26.9
1
aktosecurity/akto-threat-detection-backend:latestd9d0e7c78578
stdlib@go1.26.7
1.26.9
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.60.0
1.26.9
1
aktosecurity/guardrails-service:2.40.663e9235153a3
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
1
aktosecurity/guardrails-service:2.14.8a6218d07e84f
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
stdlib@go1.26.5
1.26.9
1
aktosecurity/mirror-api-logging:api-gateway-logging-openapi12ed2544756f
stdlib@go1.23.3
1.26.9
1
aktosecurity/mirror-api-logging:api-gateway-logging-multi-logging1a1bc76d50fe
stdlib@go1.23.3
1.26.9
1
aktosecurity/mirror-api-logging:k8s_ebpf3e506f5e5f47
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.60.0
1.26.9
1
aktosecurity/mirror-api-logging:k8s_agentc8266e943ff9
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
1
alazidis/stornx:1.1.1602d4f7f090c
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
1
alcounit/browser-controller:v1.0.1c64222f9e663
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
1
alcounit/browser-service:v0.0.94bd10defc324
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
1
alcounit/browser-ui:v1.0.0668e7aee5e5c
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
1
alcounit/selenosis:v2.1.2f0964cda6da6
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
1
alex6021710/ai-scale-auth:latest6c7a47e470c3
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.16.12
0.60.0
1.26.9
1
alex6021710/ai-scale-doer:latest31e533cf7cd3
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.16.10
0.60.0
1.26.9
1
alex6021710/ai-scale-migrator:latest744b8a924f35
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.2
0.60.0
1.26.9
1
alex6021710/ai-scale-provider:latest5837d9b30cc7
golang.org/x/net@v0.0.0-20211104170005-ce137452f963
stdlib@go1.15.8
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.