StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-7r9c-ff6c-hxjjCGA-gghc-78jw-f5q2CGA-rp37-mxv6-g5fjDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-vqxj-4gp6-23v9, CGA-w84h-9v6p-pf3x, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
gotifyalexvanderberkelVerified publisher0.7.21 of 1See more

gotify alexvanderberkel 0.7.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/gotify/server:3.1.144fc5bbd1c06
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

727
alibaba-rsocket-brokeralibaba-rsocket-brokerVerified publisher0.1.31 of 1See more

alibaba-rsocket-broker alibaba-rsocket-broker 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17.7
0.60.0
1.26.9

Open the chart page →

94,502
alluredeckalluredeckVerified publisher0.24.01 of 2See more

alluredeck alluredeck 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,983
book-serveral-masood-helm-charts0.1.01 of 1See more

book-server al-masood-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
almasood/book-server:latest6ffac9b63cdf
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

964
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.15
0.60.0
1.26.9

Open the chart page →

3,342
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

1,089
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

1,089
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

1,730
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
golang.org/x/net@v0.34.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,055
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

5,918
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,118
versitygwalpineworks0.1.21 of 1See more

versitygw alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
versity/versitygw:v1.0.145192635d0353
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

1,853
versitygw-webhook-pulsar-proxyalpineworks0.1.11 of 1See more

versitygw-webhook-pulsar-proxy alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,455
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,310
alustan-helmalustan-helm1.0.01 of 1See more

alustan-helm alustan-helm 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alustan/install-argocd:1.0.0c16c34f46ad3
golang.org/x/net@v0.19.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

2,538
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
stdlib@go1.19.13
0.60.0
1.26.9
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

35,135
ampsamps0.1.95 of 10See more

amps amps 0.1.9

5 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/vault:1.9.2ff9b17b0cefe
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.5
0.60.0
1.26.9
library/nats:2.7.2-alpine8b3fb2423a8c
stdlib@go1.17.6
1.26.9
natsio/nats-box:0.8.1b7f9328145f4
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.6
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.6.2ad0374303b13
stdlib@go1.15.14
1.26.9
natsio/prometheus-nats-exporter:0.9.14665cdc7e749
stdlib@go1.16.13
1.26.9

Open the chart page →

15,880
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

2,276
anchore-admission-controlleranchore-charts0.9.02 of 2See more

anchore-admission-controller anchore-charts 0.9.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
anchore/kubernetes-admission-controller:v0.8.51a1a374658c8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
cfssl/cfssl:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

8,891
ecs-inventoryanchore-charts0.1.01 of 1See more

ecs-inventory anchore-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
anchore/ecs-inventory:v1.5.12b424b3b9a03
stdlib@go1.26.8
1.26.9

Open the chart page →

145
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.60.0
1.26.9

Open the chart page →

2,118
cert-manager-webhook-inwxandibraeuVerified publisher0.9.01 of 1See more

cert-manager-webhook-inwx andibraeu 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,009
music-assistant-serverandibraeuVerified publisher2.1.31 of 1See more

music-assistant-server andibraeu 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.528023f8c0d96
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

4,755
opencloudandibraeuVerified publisher1.0.01 of 1See more

opencloud andibraeu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

277
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,839
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,310
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

3,155
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.26.9

Open the chart page →

3,296
dnsmadeeasy-webhookangelnu6.0.71 of 1See more

dnsmadeeasy-webhook angelnu 6.0.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/angelnu/dnsmadeeasy-webhook:v1.9.0a5ca158b1f02
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

1,354
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.26.9

Open the chart page →

122,659
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.6e1074e92a452
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

218
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

3,713
ddosifyanteonVerified publisher1.7.55 of 13See more

ddosify anteon 1.7.5

5 of the 13 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.60.0
1.26.9
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.26.9
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
stdlib@go1.19.11
0.60.0
1.26.9

Open the chart page →

31,691
antmediaantmediaVerified publisher3.1.03 of 4See more

antmedia antmedia 3.1.0

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mongo:8.0d0d926f94df0
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

6,346
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

5,024
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:latestb28bae15e219
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

2,323
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
antrea/antrea-ui-backend:v0.8.019f3c0113330
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

4,015
flow-aggregatorantreaVerified publisher2.7.01 of 1See more

flow-aggregator antrea 2.7.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
antrea/flow-aggregator:v2.7.0065193e7572f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,156
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

3,966
devenvanza-labsVerified publisher0.1.21 of 3See more

devenv anza-labs 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
tailscale/tailscale:stablec507f3a2a6ab
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

326
glauthanza-labsVerified publisher1.0.21 of 1See more

glauth anza-labs 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/glauth/glauth:v2.5.4905b5db533fc
golang.org/x/net@v0.58.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

1,170
imagepullerapache-pulsar-helm-chart-repo1.0.11 of 2See more

imagepuller apache-pulsar-helm-chart-repo 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/docker:latest0b6d18a4a222
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

298
kesque-dashboardapache-pulsar-helm-chart-repo0.0.51 of 5See more

kesque-dashboard apache-pulsar-helm-chart-repo 0.0.5

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:latestf1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

4,389
pulsar-monitorapache-pulsar-helm-chart-repo0.1.61 of 1See more

pulsar-monitor apache-pulsar-helm-chart-repo 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kesque/pulsar-monitor:1.0.8ce85c1e7d613
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.4
0.60.0
1.26.9

Open the chart page →

4,318
apipingapiping1.5.01 of 1See more

apiping apiping 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
udhos/apiping:1.5.041ab9bae6f3b
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

1,607
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/net@v0.25.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

3,819
api-usage-cleanerapi-usage-cleaner1.16.01 of 1See more

api-usage-cleaner api-usage-cleaner 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.26.9

Open the chart page →

987
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.26.9
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.26.9

Open the chart page →

24,982
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.5
0.60.0
1.26.9
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.60.0
1.26.9
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.60.0
1.26.9

Open the chart page →

15,882
app-movies-seriesapp-movies-seriesVerified publisher0.1.01 of 2See more

app-movies-series app-movies-series 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.26.9

Open the chart page →

4,537

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.60.0
1.26.9
1
axllent/mailpit:v1.31.198b916bd3c8d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
axllent/mailpit:v1.31.0c96991d9bef7
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
1
ayushsobti/kube-monkey:v0.7.0fc181870c60f
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
b3log/siyuan:v3.1.2595c0d129bc19
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
1
b3log/siyuan:v3.8.5d740a1d3ed6b
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
basa/spki-fingerprint-exporter:0.7.234cadcaa29c4
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
baserow/backend:2.4.0af9aa6fe8482
golang.org/x/net@v0.58.0
stdlib@go1.25.14
0.60.0
1.26.9
1
baserow/backend:1.31.1e0b3c8130b91
stdlib@go1.19.8
1.26.9
1
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
1
bbernhard/signal-cli-rest-api:latest2cf09d66a86f
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.17.8
0.60.0
1.26.9
1
beanbag/reviewboard:latest6b840f546e1c
stdlib@go1.18.1
1.26.9
1
bedag/goblackhole:0.2.0447a88598f4c
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.6
0.60.0
1.26.9
1
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/net@v0.37.0
stdlib@go1.23.12
0.60.0
1.26.9
1
beopenit/door-cd-operator:v3.0.4d3999cb8d026
golang.org/x/net@v0.17.0
stdlib@go1.23.9
0.60.0
1.26.9
1
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/net@v0.15.0
stdlib@go1.19.13
0.60.0
1.26.9
1
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
1
berkeleyskypilot/skypilot:0.14.0a8362d205365
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.60.0
1.26.9
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
golang.org/x/net@v0.38.0
stdlib@go1.23.5
0.60.0
1.26.9
1
betterdb/monitor:0.49.0-no-ai97dcd2d2192f
stdlib@go1.26.8
1.26.9
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.6
0.60.0
1.26.9
1
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/net@v0.2.0
stdlib@go1.17.6
0.60.0
1.26.9
1
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/net@v0.0.0-20220418201149-a630d4f3e7a2
stdlib@go1.19.3
0.60.0
1.26.9
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.26.9
1
binrc/headcni:1.0.10e199c334b957
golang.org/x/net@v0.53.0
stdlib@go1.22.10
0.60.0
1.26.9
1
binwiederhier/ntfy:v2.28.06ef4b819f722
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
1
binwiederhier/ntfy:v2.6.283e2e43d9956
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.60.0
1.26.9
1
bitnami/haproxy:latest5b57bac338a2
golang.org/x/net@v0.59.0
0.60.0
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.60.0
1.26.9
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
bitnamilegacy/git:latest4b08d0c5af8d
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.60.0
1.26.9
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
stdlib@go1.20.5
1.26.9
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
stdlib@go1.19.6
1.26.9
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
stdlib@go1.18.2
1.26.9
1
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.60.0
1.26.9
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
stdlib@go1.18.2
1.26.9
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
stdlib@go1.21.10
1.26.9
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.26.9
1
bitnamilegacy/kubectl:1.301249fc292e84
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.60.0
1.26.9
1
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.60.0
1.26.9
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.60.0
1.26.9
1
bitnamilegacy/kube-state-metrics:204a3044b384b
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
1
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.26.9
1
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
stdlib@go1.22.4
1.26.9
1
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
stdlib@go1.22.8
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.