StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
inlets-operatorinlets0.17.201 of 1See more

inlets-operator inlets 0.17.20

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/inlets/inlets-operator:0.17.2208265c006973
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

808
coreinstill-aiOfficialVerified publisher0.1.757 of 15See more

core instill-ai 0.1.75

7 of the 15 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
stdlib@go1.18.3
0.60.0
1.26.9
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.26.9
openfga/openfga:v1.9.25e94966c11df
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
temporalio/admin-tools:1.28cfde8170c92f
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

13,856
intel-gpu-resource-driverintelVerified publisher0.7.01 of 1See more

intel-gpu-resource-driver intel 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,012
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.6
0.60.0
1.26.9

Open the chart page →

3,358
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

4,999
amazon-eks-pod-identity-webhookjkroepkeVerified publisher2.6.51 of 1See more

amazon-eks-pod-identity-webhook jkroepke 2.6.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/eks/amazon-eks-pod-identity-webhook:v0.6.173071570e8e8c
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

394
k8s-ephemeral-storage-metricsk8s-ephemeral-storage-metrics1.21.31 of 1See more

k8s-ephemeral-storage-metrics k8s-ephemeral-storage-metrics 1.21.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/jmcgrath207/k8s-ephemeral-storage-metrics:1.21.38297aa4a9278
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

232
rustrial-k8s-gitops-secrets-controllerk8s-gitops-secrets0.6.01 of 1See more

rustrial-k8s-gitops-secrets-controller k8s-gitops-secrets 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rustrial/k8s-gitops-secrets-controller:0.6.093326a322a01
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

263
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.26.9

Open the chart page →

6,383
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

5,724
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.26.9

Open the chart page →

8,402
k8s-sftp-gcsk8s-sftp-gcsVerified publisher0.1.41 of 1See more

k8s-sftp-gcs k8s-sftp-gcs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.26.9

Open the chart page →

2,579
k8statusk8statusOfficialVerified publisher0.17.01 of 1See more

k8status k8status 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/stenic/k8status:0.17.093298e03089e
golang.org/x/net@v0.26.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,137
kanister-operatorkanister0.118.01 of 1See more

kanister-operator kanister 0.118.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
golang.org/x/net@v0.41.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

1,590
kiali-operatorkiali2.33.01 of 1See more

kiali-operator kiali 2.33.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kiali/kiali-operator:v2.33.0035995403eed
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,621
kividb-operator-chartkividb-operatorVerified publisher0.4.02 of 2See more

kividb-operator-chart kividb-operator 0.4.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kividbio/kividb-operator:0.4.0a2395d6f47b7
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/kividbio/kividb-operator-gui:0.4.0276352c04b9c
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

248
mysqldumpkokuwa7.0.31 of 1See more

mysqldump kokuwa 7.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
stdlib@go1.26.1
1.26.9

Open the chart page →

1,146
kong-operatorkongOfficialVerified publisher1.4.11 of 1See more

kong-operator kong 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kong/kong-operator:2.3.2814eaeee4cc8
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

145
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.26.9

Open the chart page →

3,423
kuadrant-operatorkuadrantOfficialVerified publisher1.5.34 of 4See more

kuadrant-operator kuadrant 1.5.3

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kuadrant/authorino-operator:v0.25.395a0670bffe6
golang.org/x/net@v0.55.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/kuadrant/dns-operator:v0.17.2da9ff8211856
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/kuadrant/kuadrant-operator:v1.5.318ad777aeb7a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/kuadrant/limitador-operator:v0.18.49a9c533e58bb
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

885
kubearmorkubearmor1.7.53 of 4See more

kubearmor kubearmor 1.7.5

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubearmor/kubearmor:stablea08141311045
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
kubearmor/kubearmor-controller:latest43674bb4806f
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
kubearmor/kubearmor-relay-server:latestf82b9c97e97d
golang.org/x/net@v0.53.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

2,013
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
neosu/kubebadges:v0.0.5256530d8e5c6
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

2,313
pyroscopekubeblocksVerified publisher0.2.921 of 1See more

pyroscope kubeblocks 0.2.92

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

2,339
kubepatternkubepattern0.0.51 of 1See more

kubepattern kubepattern 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubepattern/kubepattern:0.0.50762baa6d9b0
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

544
kuberay-operatorkuberay-operator1.7.11 of 1See more

kuberay-operator kuberay-operator 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kuberay/operator:v1.7.1e69b9cde8f1d
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

556
skywalkingkubesphere-testVerified publisher3.1.02 of 4See more

skywalking kubesphere-test 3.1.0

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.60.0
1.26.9
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.60.0
1.26.9

Open the chart page →

20,621
kubeviouskubevious1.2.23 of 7See more

kubevious kubevious 1.2.2

3 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubevious/ui:1.2.16233e84bdd59
golang.org/x/net@v0.0.0-20220812165438-1d4ff48094d1
stdlib@go1.19.1
0.60.0
1.26.9
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.26.9
redislabs/redisearch:2.4.1433561794c5c8
stdlib@go1.16.7
1.26.9

Open the chart page →

17,851
kubevpnkubevpn-charts2.11.91 of 1See more

kubevpn kubevpn-charts 2.11.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubenetworks/kubevpn:v2.11.93feb9da85270
golang.org/x/net@v0.52.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,026
kubewallkubewallVerified publisher0.0.231 of 1See more

kubewall kubewall 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubewall/kubewall:0.0.23d9a03cfb557b
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

398
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.05 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs-webhook:latestc1f19557bdcb
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

62,687
prometheus-pingmesh-exporterkubservice-chartsVerified publisher1.1.11 of 1See more

prometheus-pingmesh-exporter kubservice-charts 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:latest355fa4be8e97
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.60.0
1.26.9

Open the chart page →

1,322
karporkusionstackVerified publisher0.7.62 of 3See more

karpor kusionstack 0.7.6

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/net@v0.19.0
stdlib@go1.22.12
0.60.0
1.26.9
quay.io/coreos/etcd:v3.5.11842975891182
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.60.0
1.26.9

Open the chart page →

4,469
kwokkwokOfficialVerified publisher0.3.01 of 1See more

kwok kwok 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

1,074
machinarislib42Verified publisher0.2.01 of 1See more

machinaris lib42 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/guydavis/machinaris:test50a71a30f18e
stdlib@go1.26.5
1.26.9

Open the chart page →

39,653
litellm-operatorlitellm-operatorVerified publisher1.1.21 of 1See more

litellm-operator litellm-operator 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/bbdsoftware/litellm-operator:1.1.2167a51113d90
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

566
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.60.0
1.26.9

Open the chart page →

4,538
vcluster-k8sloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-k8s loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.60.0
1.26.9
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

8,119
vcluster-platformloftVerified publisher4.12.21 of 1See more

vcluster-platform loft 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-platform:4.12.271d869f989e9
golang.org/x/net@v0.52.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,105
logging-operatorlogging-operator6.9.01 of 1See more

logging-operator logging-operator 6.9.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/logging-operator:6.9.0527033b7032b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
lumigo-operatorlumigo-operatorOfficialVerified publisher69.0.06 of 8See more

lumigo-operator lumigo-operator 69.0.0

6 of the 8 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/opentelemetry-operator/target-allocator:0.124.08936271cf56a
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9
public.ecr.aws/lumigo/lumigo-kubernetes-operator:69491c39346b19
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
public.ecr.aws/lumigo/lumigo-kubernetes-telemetry-proxy:691d548e59c2c8
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9
public.ecr.aws/lumigo/lumigo-kubernetes-watchdog:696458fcd61e0c
golang.org/x/net@v0.37.0
stdlib@go1.23.12
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

9,385
lxcfs-on-kuberneteslxcfs-on-kubernetes0.2.81 of 2See more

lxcfs-on-kubernetes lxcfs-on-kubernetes 0.2.8

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cndoit18/lxcfs-agent:v0.2.8154741f8596e
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

2,582
mariadbmariadbVerified publisher0.4.01 of 1See more

mariadb mariadb 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:10.117db29378d4fd
stdlib@go1.24.6
1.26.9

Open the chart page →

2,765
marmotmarmotOfficialVerified publisher1.6.02 of 2See more

marmot marmot 1.6.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestab90e1058e5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/marmotdata/marmot:0.11.0cbc560cba46e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

349
mattermost-rtcdmattermostVerified publisher1.4.11 of 1See more

mattermost-rtcd mattermost 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mattermost/rtcd:latesta27058aaa53a
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

931
veleromesosphere3.2.51 of 1See more

velero mesosphere 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

2,730
kubecostmesosphere-stable0.37.57 of 9See more

kubecost mesosphere-stable 0.37.5

7 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
grafana/grafana:9.4.71a359d92f40e
golang.org/x/net@v0.4.0
stdlib@go1.20.1
0.60.0
1.26.9
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/thanos/thanos:v0.36.1e542959e1b36
golang.org/x/net@v0.26.0
stdlib@go1.21.13
0.60.0
1.26.9

Open the chart page →

22,738
m8b-stackmetricshubVerified publisher2.1.31 of 4See more

m8b-stack metricshub 2.1.3

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/prometheus:v3.13.36976aa8a60fe
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

259
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,807
helm-ai-kernelmindburn-labsOfficialVerified publisher0.11.12 of 2See more

helm-ai-kernel mindburn-labs 0.11.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/mindburn-labs/helm-ai-kernel:v0.11.10e7a5cd11858
golang.org/x/net@v0.58.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

2,809
mc-routerminecraft-server-chartsVerified publisher1.5.01 of 1See more

mc-router minecraft-server-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
itzg/mc-router:latest64ae69eaa7a6
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

168

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.60.0
1.26.9
1
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
stdlib@go1.19.10
0.60.0
1.26.9
1
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.26.9
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.60.0
1.26.9
1
enketo/enketo-express:3.0.4dcad9c2273f6
stdlib@go1.17.1
1.26.9
1
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9
1
envoyproxy/gateway:v0.5.02a9f99d28567
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.60.0
1.26.9
1
envoyproxy/gateway-dev:latest97b2a036f523
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
1
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14
0.60.0
1.26.9
1
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.13
0.60.0
1.26.9
1
envoyproxy/ratelimit:4d2efd61ede09a75a84c
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.15
0.60.0
1.26.9
1
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.19.6
0.60.0
1.26.9
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.18.3
0.60.0
1.26.9
1
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.4
0.60.0
1.26.9
1
epamedp/edp-headlamp:0.25.093417e18bb1a
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.60.0
1.26.9
1
epamedp/edp-tekton:0.2.4924939850655
golang.org/x/net@v0.1.0
stdlib@go1.18.3
0.60.0
1.26.9
1
epamedp/gerrit-operator:2.25.08de22fc5051c
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.60.0
1.26.9
1
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9
1
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9
1
epamedp/keycloak-operator:1.35.0a5398eaa7b80
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.2
0.60.0
1.26.9
1
epamedp/nexus-operator:3.6.09fede333ef27
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
1
epamedp/perf-operator:2.13.0bd2079b7bfcb
golang.org/x/net@v0.8.0
stdlib@go1.19.6
0.60.0
1.26.9
1
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.18.4
0.60.0
1.26.9
1
epamedp/sonar-operator:3.4.0661d1648a49a
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
1
epamedp/tekton-custom-task:0.2.067d896676f45
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.60.0
1.26.9
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.26.9
1
erenozcan17/go_backend:v4.250b4f23422b6
golang.org/x/net@v0.10.0
stdlib@go1.23.12
0.60.0
1.26.9
1
erigontech/erigon:latest28ee51ce29ec
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
erigontech/erigon:v2.61.288706754b627
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
1
erudikaltd/para:latest_stablea6aba08c21fa
stdlib@go1.26.7
1.26.9
1
escaping/core-keeper-dedicated:latest87fa79255962
stdlib@go1.24.4
1.26.9
1
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.60.0
1.26.9
1
ethereum/client-go:v1.10.2603604c12f612
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.8
0.60.0
1.26.9
1
ethereum/client-go:v1.15.101f36ca5922a5
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.60.0
1.26.9
1
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.60.0
1.26.9
1
ethereum/client-go:stable4753febf6e7c
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
ethereum/client-go:latest5ab9a76153b0
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
ethereum/client-go:v1.10.186d6d12a40465
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.18.2
0.60.0
1.26.9
1
ethereum/client-go:v1.14.8886ec69b35b0
golang.org/x/net@v0.24.0
stdlib@go1.22.6
0.60.0
1.26.9
1
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.5
0.60.0
1.26.9
1
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.60.0
1.26.9
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
stdlib@go1.19.3
1.26.9
1
ethereumoptimism/l2geth:0.5.315577036dc36d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18
0.60.0
1.26.9
1
etherpad/etherpad:latest6f87beef31d9
stdlib@go1.26.4
1.26.9
1
ethersphere/bee:2.2.0a884fd84b72f
golang.org/x/net@v0.25.0
stdlib@go1.22.7
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.