StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-7r9c-ff6c-hxjjCGA-gghc-78jw-f5q2CGA-rp37-mxv6-g5fjDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-vqxj-4gp6-23v9, CGA-w84h-9v6p-pf3x, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

2,977
aceappscodeVerified publisher2026.9.112 of 2See more

ace appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

3,678
ace-installerappscodeVerified publisher2026.9.112 of 2See more

ace-installer appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

4,038
ace-installer-certifiedappscodeVerified publisher2026.9.112 of 2See more

ace-installer-certified appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
ghcr.io/appscode/b3:v2026.9.114b5993768740
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

4,207
acerproxyappscodeVerified publisher2026.9.111 of 1See more

acerproxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,830
aceshifterappscodeVerified publisher2026.9.111 of 1See more

aceshifter appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/aceshifter:v0.0.3e5f5c254a55a
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,492
appcatalogappscodeVerified publisher2023.3.231 of 1See more

appcatalog appscode 2023.3.23

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/appcatalog:v0.0.109709a346888
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

2,375
appscode-otel-stackappscodeVerified publisher2026.9.223 of 3See more

appscode-otel-stack appscode 2026.9.22

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.150.089490ef63b72
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

2,803
auditorappscodeVerified publisher2023.10.11 of 1See more

auditor appscode 2023.10.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

2,526
aws-credential-managerappscodeVerified publisher2026.4.161 of 1See more

aws-credential-manager appscode 2026.4.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/aws-credential-manager:v0.1.00511bbe501c3
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

986
azure-credential-managerappscodeVerified publisher2026.4.161 of 1See more

azure-credential-manager appscode 2026.4.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/azure-credential-manager:v0.1.0f5c797f7fbe7
golang.org/x/net@v0.49.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,265
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

2,977
capa-vpc-peering-operatorappscodeVerified publisher2023.12.111 of 1See more

capa-vpc-peering-operator appscode 2023.12.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

2,095
capi-ops-managerappscodeVerified publisher2024.8.142 of 2See more

capi-ops-manager appscode 2024.8.14

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
golang.org/x/net@v0.33.0
stdlib@go1.23.2
0.60.0
1.26.9
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.60.0
1.26.9

Open the chart page →

5,347
catalog-managerappscodeVerified publisher2026.9.111 of 1See more

catalog-manager appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/catalog-manager:v0.14.05e9a05238ed5
golang.org/x/net@v0.57.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

343
cattlesetappscodeVerified publisher2026.7.81 of 1See more

cattleset appscode 2026.7.8

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/cattleset:v0.0.145554a03e448
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,043
cert-manager-csi-driver-cacertsappscodeVerified publisher2026.9.183 of 3See more

cert-manager-csi-driver-cacerts appscode 2026.9.18

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/csi-driver-cacerts:v0.6.0ab213b156017
golang.org/x/net@v0.47.0
stdlib@go1.25.13
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.14.05244abbe87e0
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

3,962
cert-manager-webhook-aceappscodeVerified publisher2026.9.111 of 1See more

cert-manager-webhook-ace appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/cert-manager-webhook-ace:v0.0.2dc6b5fdcec06
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,816
clickhouse-uiappscodeVerified publisher2026.3.301 of 1See more

clickhouse-ui appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/caioricciuti/ch-ui:v2.14.180f4d92c2d8d
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

205
cluster-auth-agentappscodeVerified publisher2026.2.161 of 1See more

cluster-auth-agent appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,437
cluster-auth-managerappscodeVerified publisher2026.2.161 of 1See more

cluster-auth-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,437
cluster-connectorappscodeVerified publisher2025.12.151 of 1See more

cluster-connector appscode 2025.12.15

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/cluster-connector:v0.0.140efd9d9ef6ca
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,059
cluster-gatewayappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,049
cluster-gateway-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,049
cluster-importerappscodeVerified publisher2026.9.111 of 1See more

cluster-importer appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/ace:v0.2.0b8e03da90e70
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,477
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,562
cluster-presetsappscodeVerified publisher2026.9.111 of 1See more

cluster-presets appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/cluster-presets:v0.0.128fbdd2479645
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

743
cluster-profile-managerappscodeVerified publisher2026.9.181 of 1See more

cluster-profile-manager appscode 2026.9.18

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-profile:v0.13.0b8b0aaef2543
golang.org/x/net@v0.58.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

397
cluster-proxyappscodeVerified publisher2024.2.251 of 1See more

cluster-proxy appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:latest27a5c64b7ea8
golang.org/x/net@v0.20.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

1,761
cluster-proxy-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-proxy-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:v0.10.1a7fce69e171c
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

2,269
crd-managerappscodeVerified publisher2026.10.101 of 1See more

crd-manager appscode 2026.10.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.4.04466bb77dc78
golang.org/x/net@v0.47.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

1,100
dns-proxyappscodeVerified publisher2026.9.111 of 1See more

dns-proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/cloudflare-dns-proxy:v0.0.5dfbef0285e14
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,093
docker-machine-operatorappscodeVerified publisher2024.7.91 of 1See more

docker-machine-operator appscode 2024.7.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/net@v0.14.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

2,954
external-dns-operatorappscodeVerified publisher2026.6.221 of 1See more

external-dns-operator appscode 2026.6.22

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/external-dns-operator:v0.4.05605f97e636d
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

679
falco-ui-serverappscodeVerified publisher2026.1.152 of 2See more

falco-ui-server appscode 2026.1.15

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/appscode/falco-ui-server:v0.0.66ec488d89b56
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

4,079
fargocdappscodeVerified publisher2026.9.181 of 1See more

fargocd appscode 2026.9.18

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/fargocd:v0.1.0c59d775d9a7c
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

743
fargocd-managerappscodeVerified publisher2026.9.181 of 1See more

fargocd-manager appscode 2026.9.18

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/fargocd:v0.1.0c59d775d9a7c
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

743
fluxcd-addon-managerappscodeVerified publisher2024.2.251 of 1See more

fluxcd-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/fluxcd-addon:v0.0.23acba3df8827
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,917
fluxcd-managerappscodeVerified publisher2026.9.181 of 1See more

fluxcd-manager appscode 2026.9.18

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/fluxcd-addon:v0.0.1137105f529ed0
golang.org/x/net@v0.47.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

688
gateway-converterappscodeVerified publisher2024.8.301 of 1See more

gateway-converter appscode 2024.8.30

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway-converter:v0.0.1b92123805584
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

1,838
gcp-credential-managerappscodeVerified publisher2026.3.111 of 1See more

gcp-credential-manager appscode 2026.3.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/gcp-credential-manager:v0.1.0b58345fe8209
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,480
gh-ci-webhookappscodeVerified publisher2026.9.111 of 1See more

gh-ci-webhook appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/gh-ci-webhook:v0.0.2036ce246d884e
golang.org/x/net@v0.33.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

1,998
grafanaappscodeVerified publisher2026.9.111 of 1See more

grafana appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

3,471
grafana-operatorappscodeVerified publisher2026.6.121 of 1See more

grafana-operator appscode 2026.6.12

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana-tools:v0.8.077c9d29080eb
golang.org/x/net@v0.52.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

635
grafana-opscenterappscodeVerified publisher2023.3.231 of 1See more

grafana-opscenter appscode 2023.3.23

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana-tools:v0.0.22c7b9b0a9101
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

2,219
grafana-ui-serverappscodeVerified publisher2022.6.141 of 1See more

grafana-ui-server appscode 2022.6.14

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana-tools:v0.0.1f60324bca644
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

2,413
inbox-agentappscodeVerified publisher2026.6.22 of 2See more

inbox-agent appscode 2026.6.2

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-agent:v0.0.6f630e47772c9
golang.org/x/net@v0.47.0
stdlib@go1.25.13
0.60.0
1.26.9
ghcr.io/appscode/kube-rbac-proxy:v0.15.0d8cc6ffb9819
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

2,812
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.26.9

Open the chart page →

18,130
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.26.9

Open the chart page →

19,589
kube-auth-managerappscodeVerified publisher2023.11.141 of 1See more

kube-auth-manager appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

2,733

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
aquasec/kube-bench:v0.6.176672264accce
stdlib@go1.20.4
1.26.9
1
aquasec/kube-bench:v0.15.07a8fa32dce21
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.60.0
1.26.9
1
aquasec/kube-bench:v0.6.9c329d73fea58
stdlib@go1.19
1.26.9
1
aquasec/postee:2.12.0-amd640795cba777e7
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
1
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.60.0
1.26.9
1
aquasec/starboard-operator:0.15.38e0b1c7ddc843
golang.org/x/net@v0.41.0
stdlib@go1.26.3
0.60.0
1.26.9
1
aquasec/tracee:0.24.1cfbbfee972e6
golang.org/x/net@v0.42.0
stdlib@go1.24.9
0.60.0
1.26.9
1
aquasec/trivy:0.74.062b1e65e8869
golang.org/x/net@v0.58.0
stdlib@go1.26.6-X:jsonv2
0.60.0
1.26.9
1
aquasec/trivy:0.43.1944a04445179
golang.org/x/net@v0.11.0
stdlib@go1.19.10
0.60.0
1.26.9
1
aquasec/trivy:0.32.0973d0df16189
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
1
aquasec/trivy:0.75.0af6acf9a6b85
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
aquasec/trivy:0.69.3bcc376de8d77
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
1
arangodb/kube-arangodb:1.2.4108d1720cec3b
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9
1
arbuzov/claude-code-api:0.1.02d7dd8070610
stdlib@go1.23.10
1.26.9
1
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
golang.org/x/net@v0.34.0
stdlib@go1.22.10
0.60.0
1.26.9
1
arigaio/atlas-operator:0.7.111c4caa13c92b
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9
1
aristidetm/basic-notebook:3.6.5469dbc951224
golang.org/x/net@v0.7.0
stdlib@go1.22.5
0.60.0
1.26.9
1
articomio/articom-cx-operator:v1.2.389efda334136
golang.org/x/net@v0.47.0
stdlib@go1.25.14
0.60.0
1.26.9
1
artifacthub/db-migrator:v1.23.028c13565ac5c
stdlib@go1.26.4
1.26.9
1
artifacthub/db-migrator:v1.19.02a746b289fcd
stdlib@go1.22.4
1.26.9
1
artifacthub/hub:v1.19.0111918d8c399
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
1
artifacthub/hub:v1.23.07d3a91c539dc
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
1
artifacthub/scanner:v1.23.02d8365601f0e
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
1
artifacthub/scanner:v1.19.0323d026e78c3
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.60.0
1.26.9
1
artifacthub/tracker:v1.23.05368d21a6e5c
golang.org/x/net@v0.44.0
stdlib@go1.24.4
0.60.0
1.26.9
1
artifacthub/tracker:v1.19.06596c8c4d955
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
stdlib@go1.22.4
1.26.9
1
arunvelsriram/utils:latest655ad18fd8d6
golang.org/x/net@v0.24.0
stdlib@go1.23.8
0.60.0
1.26.9
1
ashupednekar535/litefunctions-ingestor:latestd605f539da90
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.60.0
1.26.9
1
ashupednekar535/litefunctions-operator:latest83c884ce260b
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
ashupednekar535/litefunctions-portal:latest460f010659fe
golang.org/x/net@v0.49.0
stdlib@go1.26.1
0.60.0
1.26.9
1
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.26.9
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.60.0
1.26.9
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
stdlib@go1.18.2
1.26.9
1
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.60.0
1.26.9
1
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.60.0
1.26.9
1
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.60.0
1.26.9
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.26.9
1
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.26.9
1
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.13
0.60.0
1.26.9
1
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.60.0
1.26.9
1
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.22.1
1.26.9
1
astarte/astarte-kubernetes-operator:26.5.1e3ff1b3c0c98
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.60.0
1.26.9
1
atlassian/bamboo:12.1.12eb98d6fbeee7
stdlib@go1.22.2
1.26.9
1
atlassian/bamboo-agent-base:12.1.12a8d7b10b667a
stdlib@go1.22.2
1.26.9
1
authelia/authelia:4.39.28bd97cff4fcbf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
authzed/spicedb:latestaa96009a0477
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
automatischio/automatisch:0.15.03bace7a12d5f
stdlib@go1.23.8
1.26.9
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.