StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
alertmanager-matrixalertmanager-matrixVerified publisher0.1.161 of 1See more

alertmanager-matrix alertmanager-matrix 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
silkeh/alertmanager_matrix:0.6.1900010497f8c
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

716
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
stdlib@go1.24.4
1.26.9

Open the chart page →

14,335
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.26.9

Open the chart page →

73,147
clearml-servingallegroaiVerified publisher1.6.26 of 9See more

clearml-serving allegroai 1.6.2

6 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
stdlib@go1.19.6
1.26.9
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
stdlib@go1.18.2
1.26.9
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.26.9
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

25,342
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.26.9

Open the chart page →

6,132
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.26.9

Open the chart page →

9,605
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

3,937
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

2,937
cloudflare-operatorankra-chartsVerified publisher0.2.01 of 1See more

cloudflare-operator ankra-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
adyanth/cloudflare-operatordigest-pinned6b168dc237d5
golang.org/x/net@v0.39.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

911
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
stdlib@go1.24.4
1.26.9

Open the chart page →

7,608
upcloud-csiankra-chartsVerified publisher0.4.18 of 8See more

upcloud-csi ankra-charts 0.4.1

8 of the 8 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
golang.org/x/net@v0.43.0
stdlib@go1.23.12
0.60.0
1.26.9
ghcr.io/upcloudltd/upcloud-csidigest-pinned5af91c663788
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

22,421
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

1,905
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

4,174
anteonanteonVerified publisher2.6.45 of 13See more

anteon anteon 2.6.4

5 of the 13 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.60.0
1.26.9
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.60.0
1.26.9
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.26.9
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
stdlib@go1.19.11
0.60.0
1.26.9

Open the chart page →

27,707
antreaantreaVerified publisher2.7.02 of 2See more

antrea antrea 2.7.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
golang.org/x/net@v0.58.0
stdlib@go1.25.7
0.60.0
1.26.9
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

4,769
api-usage-serverapi-usage-server1.16.01 of 1See more

api-usage-server api-usage-server 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,157
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

1,710
kubedb-opscenterappscodeVerified publisher2026.7.101 of 1See more

kubedb-opscenter appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-ui-server:v0.42.0e93dfe7454d4
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

484
kubedb-provisionerappscodeVerified publisher0.66.01 of 1See more

kubedb-provisioner appscode 0.66.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-provisioner:v0.66.0e7041c3b41e7
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

932
scannerappscodeVerified publisher2026.1.153 of 3See more

scanner appscode 2026.1.15

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/net@v0.26.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

7,093
smtprelayappscodeVerified publisher2026.9.111 of 1See more

smtprelay appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/net@v0.34.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,332
stash-enterpriseappscodeVerified publisher0.42.04 of 4See more

stash-enterprise appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
stdlib@go1.24.9
0.60.0
1.26.9
ghcr.io/stashed/stash-crd-installer:v0.42.1d6c9b7a1f7b8
golang.org/x/net@v0.38.0
stdlib@go1.25.5
0.60.0
1.26.9
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
golang.org/x/net@v0.38.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

5,874
virtual-secrets-serverappscodeVerified publisher2026.8.141 of 1See more

virtual-secrets-server appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/virtual-secrets-server:v0.4.0efa03f4c9551
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

536
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

6,543
argocd-rbac-operatorargocd-rbac-operator0.4.51 of 1See more

argocd-rbac-operator argocd-rbac-operator 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-rbac-operator:v0.2.451dded00137a
golang.org/x/net@v0.40.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

1,372
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

3,573
s3dartur9010Verified publisher1.0.11 of 1See more

s3d artur9010 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

2,204
arvancloud-webhookarvancloud-webhookVerified publisher1.0.11 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.1e58c98b4d28a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

787
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.15
0.60.0
1.26.9

Open the chart page →

3,949
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
stdlib@go1.18.2
1.26.9

Open the chart page →

20,328
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

12,404
dltbrokerassist-iot-distributed-broker0.2.05 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.60.0
1.26.9
hyperledger/fabric-ca:latesta70b6ba64a08
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

196,309
dltloggingassist-iot-logging-auditing0.2.05 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.13
0.60.0
1.26.9
hyperledger/fabric-ca:latesta70b6ba64a08
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

196,289
astradnsastradnsVerified publisher0.2.92 of 2See more

astradns astradns 0.2.9

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.60.0
1.26.9
ghcr.io/astradns/astradns-operator:v0.2.909e58b62416a
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

3,575
deployautoml0.1.02 of 3See more

deploy automl 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.26.9
muonsoft/openapi-mock:latestc9afe1295484
stdlib@go1.20.2
1.26.9

Open the chart page →

4,341
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
stdlib@go1.17.5
0.60.0
1.26.9

Open the chart page →

5,411
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

4,543
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.18.1
0.60.0
1.26.9

Open the chart page →

4,786
prismav1o-chartsVerified publisher0.3.11 of 1See more

prism av1o-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.26.9

Open the chart page →

2,248
avahi-controlleravahi-controllerVerified publisher0.1.191 of 1See more

avahi-controller avahi-controller 0.1.19

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/mm503/avahi-controller:0.6.42207e2ae2179
golang.org/x/net@v0.57.0
0.60.0

Open the chart page →

35
kubebrowseravistoOfficialVerified publisher1.4.01 of 1See more

kubebrowser avisto 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/kubebrowser:0.10.0a354b8dc7e6a
golang.org/x/net@v0.47.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

1,111
azuredisk-csi-driverazuredisk-csi-driverVerified publisher1.36.07 of 8See more

azuredisk-csi-driver azuredisk-csi-driver 1.36.0

7 of the 8 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.36.00b4df214c178
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-attacher:v4.12.03aadb9baa021
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.17.0264963e21f6d
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v6.3.05c9423e1046a
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v2.2.1f755aeee7277
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-snapshotter:v8.6.01ca5b663e3dd
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.19.03eb866c2c773
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

997
generic-appb3oVerified publisher0.1.61 of 1See more

generic-app b3o 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.26.9

Open the chart page →

2,307
gozonebabykart-helm-chartsVerified publisher0.18.11 of 1See more

gozone babykart-helm-charts 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/babykart/gozone:0.19.19c3331309120
stdlib@go1.27.1
1.27.2

Open the chart page →

160
vault-unsealbabykart-helm-chartsVerified publisher1.0.51 of 1See more

vault-unseal babykart-helm-charts 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/lrstanley/vault-unseal:1.0.1dd873930b6df
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

402
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

5,994
music-assistantbdclark-helm-chartsVerified publisher0.4.131 of 1See more

music-assistant bdclark-helm-charts 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.3885872224fa5
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

4,783
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.8
0.60.0
1.26.9
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.17.5
0.60.0
1.26.9
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

10,728
livekit-serverbeeinventor1.0.01 of 2See more

livekit-server beeinventor 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.10
0.60.0
1.26.9

Open the chart page →

3,767
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.60.0
1.26.9

Open the chart page →

2,423

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9
1
dannielkil/book-db:latest433290c5c1db
stdlib@go1.18.2
1.26.9
1
danroux/sk8l-api:v0.19.0dee851fc72cc
golang.org/x/net@v0.57.0
stdlib@go1.26.4-X:loopvar
0.60.0
1.26.9
1
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.26.9
1
daprio/dashboard:0.15.04be696707bd1
golang.org/x/net@v0.25.0
stdlib@go1.21.13
0.60.0
1.26.9
1
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
stdlib@go1.19.13
0.60.0
1.26.9
1
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
darioackermann/cert-manager-webhook-regery:latest0d450bc4acc4
golang.org/x/net@v0.26.0
stdlib@go1.22.10
0.60.0
1.26.9
1
darkobas/ethexporter:latest62e6464491ba
stdlib@go1.19.1
1.26.9
1
darkobas/tokenexporter:latestf26e016a9d7e
stdlib@go1.27.1
1.27.2
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9
1
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/net@v0.7.0
stdlib@go1.20
0.60.0
1.26.9
1
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
golang.org/x/net@v0.41.0
stdlib@go1.24.3
0.60.0
1.26.9
1
darthsim/imgproxy:latestc0d8c00be50c
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
dashops/dash-ops:latest23537693ff05
golang.org/x/net@v0.46.0
stdlib@go1.25.10
0.60.0
1.26.9
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
stdlib@go1.16.9
1.26.9
1
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.11
0.60.0
1.26.9
1
datadog/agent:6aad9994de6a7
golang.org/x/net@v0.33.0
stdlib@go1.21.11
0.60.0
1.26.9
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.15
0.60.0
1.26.9
1
datadog/operator:0.3.117f08a860090
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.2
0.60.0
1.26.9
1
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.21.4
0.60.0
1.26.9
1
datappeal/hive-metastore:lateste38c085a3567
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.4
0.60.0
1.26.9
1
datappeal/trino-exporter:latest325b91c2b09e
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.15
0.60.0
1.26.9
1
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.17.13
0.60.0
1.26.9
1
datasaker/dsk-container-agent:latest08b52999f67b
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.60.0
1.26.9
1
datasaker/dsk-k8s-agent:latest2542ee73be51
golang.org/x/net@v0.17.0
stdlib@go1.19.1
0.60.0
1.26.9
1
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
golang.org/x/net@v0.17.0
stdlib@go1.21.0
0.60.0
1.26.9
1
datasaker/dsk-node-agent:latest1b95913b6729
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
1
datasaker/dsk-process-agent:latest2f38720a637d
golang.org/x/net@v0.15.0
stdlib@go1.21.0
0.60.0
1.26.9
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
1
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
1
datawire/aes:3.11.195ec30b3c732
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.60.0
1.26.9
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.16.5
0.60.0
1.26.9
1
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
1
ddefrancesco/scoperunner-server:0.2.1daaac6657600
stdlib@go1.21.10
1.26.9
1
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.60.0
1.26.9
1
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
1
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
1
ddvk/rmfakecloud:latest2f5c45cbf0c5
golang.org/x/net@v0.38.0
stdlib@go1.26.3
0.60.0
1.26.9
1
deconzcommunity/deconz:2.29.2062de2362641
stdlib@go1.19.8
1.26.9
1
deconzcommunity/deconz:2.26.123c86008d73f
stdlib@go1.19.8
1.26.9
1
deepflowce/deepflow-init-grafana:v6.2.27cd16719eb57
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.3
0.60.0
1.26.9
1
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
golang.org/x/net@v0.8.0
stdlib@go1.19.1
0.60.0
1.26.9
1
deepflowce/deepflow-server:v6.2.21477e7334d13
golang.org/x/net@v0.2.0
stdlib@go1.18.10
0.60.0
1.26.9
1
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
1
defactops/defactops-ui:1.0.16825cdf9ba706
golang.org/x/net@v0.25.0
stdlib@go1.21.10
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.