StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
sftpgosftpgoOfficialVerified publisher0.48.01 of 1See more

sftpgo sftpgo 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
golang.org/x/net@v0.57.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

1,664
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

13,777
aws-cloudwatch-metricsaws0.0.111 of 1See more

aws-cloudwatch-metrics aws 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

2,163
zabbixcetic3.1.33 of 5See more

zabbix cetic 3.1.3

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:14c2427de38f99
stdlib@go1.24.6
1.26.9
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.1
0.60.0
1.26.9
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
stdlib@go1.18.1
1.26.9

Open the chart page →

37,373
chatwootchatwootVerified publisher2.0.272 of 3See more

chatwoot chatwoot 2.0.27

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.26.9
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
stdlib@go1.16.7
1.26.9

Open the chart page →

8,728
plugin-barman-cloudcloudnative-pgVerified publisher0.8.11 of 1See more

plugin-barman-cloud cloudnative-pg 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/plugin-barman-cloud:v0.15.1c75acad19a36
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

124
csi-driver-smbcsi-driver-smbVerified publisher1.20.35 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

4,483
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

6,231
flux-operatorflux-operator0.61.01 of 1See more

flux-operator flux-operator 0.61.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/controlplaneio-fluxcd/flux-operator:v0.61.071041d9fff7f
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

135
gadgetgadgetOfficialVerified publisher0.56.11 of 1See more

gadget gadget 0.56.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/inspektor-gadget/inspektor-gadget:v0.56.1d1c34335183b
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

220
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.26.9

Open the chart page →

9,008
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
stdlib@go1.19.8
1.26.9

Open the chart page →

7,558
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
google/cloud-sdk:alpineef78619c8239
stdlib@go1.26.6
1.26.9

Open the chart page →

8,956
hpe-csi-driverhpe-storageVerified publisher3.3.013 of 14See more

hpe-csi-driver hpe-storage 3.3.0

13 of the 14 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/hpestorage/alletra-9000-primera-and-3par-csp:v3.3.0046215e41416
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/alletrastoragemp-b10000-nfs-csp:v1.3.0efaca660f9f0
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/alletrastoragemp-x10000-nfs-csp:v1.1.0043bb2ddb642
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/csi-driver:v3.3.0e58e22427b38
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/csi-extensions:v1.3.0df65cea35805
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-group-provisioner:v1.1.09ba017780f80
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-group-snapshotter:v1.1.0b26660528928
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-mutator:v1.4.03890d0b3aa89
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

4,179
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

3,042
cloudflaredkubitodevVerified publisher1.7.91 of 1See more

cloudflared kubitodev 1.7.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,968
trident-operatornetapp-tridentVerified publisher100.2606.21 of 1See more

trident-operator netapp-trident 100.2606.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
netapp/trident-operator:26.06.24cef5a737bcf
golang.org/x/net@v0.59.0
0.60.0

Open the chart page →

39
ngrok-operatorngrokOfficialVerified publisher0.24.02 of 2See more

ngrok-operator ngrok 0.24.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
ngrok/ngrok-operator:0.22.0db8e6fecc52c
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

444
openbaoopenbaoVerified publisher0.30.12 of 2See more

openbao openbao 0.30.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:1.7.2ae3d307658b7
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
quay.io/openbao/openbao:2.7.071156a1c6623
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,708
prometheus-snmp-exporterprometheus-communityOfficialVerified publisher9.18.11 of 1See more

prometheus-snmp-exporter prometheus-community 9.18.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

857
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9

Open the chart page →

6,887
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.7
0.60.0
1.26.9

Open the chart page →

3,104
trivytrivy-operator0.27.01 of 1See more

trivy trivy-operator 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
aquasec/trivy:0.75.0af6acf9a6b85
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

235
zotzot0.1.1281 of 1See more

zot zot 0.1.128

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/project-zot/zot:v2.1.2296cda11459ce
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

495
aws-ebs-csi-driveraws-ebs-csi-driver2.66.15 of 6See more

aws-ebs-csi-driver aws-ebs-csi-driver 2.66.1

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/csi-components/csi-attacher:v4.12.0-eksbuild.9f8db68b6e3b3
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-node-driver-registrar:v2.17.0-eksbuild.89be2a65725f7
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-provisioner:v6.3.0-eksbuild.82fdf13756ccb
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-resizer:v2.2.1-eksbuild.7a2895cc5206d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.66.13ae75c8b0fdc
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

632
daskdask2024.1.11 of 2See more

dask dask 2024.1.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

14,274
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
golang.org/x/net@v0.35.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

3,751
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.60.0
1.26.9

Open the chart page →

9,156
netbirdjaconiVerified publisher0.15.14 of 4See more

netbird jaconi 0.15.1

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/golang:lateste0174e51e812
stdlib@go1.27.1
1.27.2
netbirdio/management:0.45.10c9994b393ea
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
netbirdio/relay:0.45.1872e3add0e1e
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
netbirdio/signal:0.45.146ce5a45538f
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9

Open the chart page →

10,263
k8upk8upVerified publisher4.10.01 of 1See more

k8up k8up 4.10.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.16.029458113b8b6
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,016
kube-starrockskube-starrocksOfficialVerified publisher1.11.71 of 1See more

kube-starrocks kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/net@v0.17.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

1,015
linkerd-jaegerlinkerd2Verified publisher30.12.112 of 4See more

linkerd-jaeger linkerd2 30.12.11

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.6
0.60.0
1.26.9
otel/opentelemetry-collector:0.59.0ee9da0b08d83
golang.org/x/net@v0.0.0-20220809184613-07c6da5e1ced
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

6,215
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest801a3dff7f6a
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:nojsonv2
0.60.0
1.27.2

Open the chart page →

2,177
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

15,239
renovate-operatormogenius6.4.02 of 2See more

renovate-operator mogenius 6.4.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/mogenius/renovate-operator:6.4.0e8f023764de4
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
registry.k8s.io/kubectl:v1.37.1b7cab618e281
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

282
argocdnicklasfrahm-argocdVerified publisher0.3.02 of 2See more

argocd nicklasfrahm-argocd 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.26.9
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
golang.org/x/net@v0.40.0
stdlib@go1.22.7
0.60.0
1.26.9

Open the chart page →

7,168
oneuptimeoneuptimeOfficialVerified publisher14.0.282 of 7See more

oneuptime oneuptime 14.0.28

2 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:latest74935e722416
stdlib@go1.24.6
1.26.9
oneuptime/runner:releasec2e5e54f0b2c
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

9,221
open-feature-operatoropen-feature-operatorOfficialVerified publisher0.9.31 of 1See more

open-feature-operator open-feature-operator 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/open-feature/open-feature-operator:v0.9.3b37a442c0497
golang.org/x/net@v0.52.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

315
postgres-operatorpostgres-operator2.0.31 of 1See more

postgres-operator postgres-operator 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v2.0.32d3a7ca3950f
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

205
telepresence-osstelepresence-ossOfficialVerified publisher2.32.21 of 2See more

telepresence-oss telepresence-oss 2.32.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/telepresenceio/tel2:2.32.296f5a0f413b1
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

924
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
stdlib@go1.17.1
1.26.9

Open the chart page →

7,334
karmawiremindVerified publisher2.13.11 of 1See more

karma wiremind 2.13.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/prymitive/karma:v0.13190a10c5c6793
stdlib@go1.26.3
1.26.9

Open the chart page →

310
yugabyteyugabyteVerified publisher2026.1.21 of 1See more

yugabyte yugabyte 2026.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
yugabytedb/yugabyte:2026.1.2.0-b137b6dba322c734
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

359
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

1,676
autheliaautheliaOfficialVerified publisher0.11.221 of 1See more

authelia authelia 0.11.22

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/authelia/authelia:4.39.248f428b06bb07
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

8,089
camel-kcamel-kVerified publisher2.11.01 of 1See more

camel-k camel-k 2.11.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/camel-k:2.11.0d173e7efe258
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,782
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

6,661
falcosidekickfalcosecurity0.14.01 of 1See more

falcosidekick falcosecurity 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
falcosecurity/falcosidekick:2.32.01976da721518
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

2,275
flagsmithflagsmithOfficialVerified publisher0.83.01 of 4See more

flagsmith flagsmith 0.83.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,414

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.60.0
1.26.9
1
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
stdlib@go1.19.10
0.60.0
1.26.9
1
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.26.9
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.60.0
1.26.9
1
enketo/enketo-express:3.0.4dcad9c2273f6
stdlib@go1.17.1
1.26.9
1
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9
1
envoyproxy/gateway:v0.5.02a9f99d28567
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.60.0
1.26.9
1
envoyproxy/gateway-dev:latest97b2a036f523
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
1
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14
0.60.0
1.26.9
1
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.13
0.60.0
1.26.9
1
envoyproxy/ratelimit:4d2efd61ede09a75a84c
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.15
0.60.0
1.26.9
1
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.19.6
0.60.0
1.26.9
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.18.3
0.60.0
1.26.9
1
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.4
0.60.0
1.26.9
1
epamedp/edp-headlamp:0.25.093417e18bb1a
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.60.0
1.26.9
1
epamedp/edp-tekton:0.2.4924939850655
golang.org/x/net@v0.1.0
stdlib@go1.18.3
0.60.0
1.26.9
1
epamedp/gerrit-operator:2.25.08de22fc5051c
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.60.0
1.26.9
1
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9
1
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.17.2
0.60.0
1.26.9
1
epamedp/keycloak-operator:1.35.0a5398eaa7b80
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.2
0.60.0
1.26.9
1
epamedp/nexus-operator:3.6.09fede333ef27
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
1
epamedp/perf-operator:2.13.0bd2079b7bfcb
golang.org/x/net@v0.8.0
stdlib@go1.19.6
0.60.0
1.26.9
1
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
stdlib@go1.18.4
0.60.0
1.26.9
1
epamedp/sonar-operator:3.4.0661d1648a49a
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
1
epamedp/tekton-custom-task:0.2.067d896676f45
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.60.0
1.26.9
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.26.9
1
erenozcan17/go_backend:v4.250b4f23422b6
golang.org/x/net@v0.10.0
stdlib@go1.23.12
0.60.0
1.26.9
1
erigontech/erigon:latest28ee51ce29ec
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
erigontech/erigon:v2.61.288706754b627
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
1
erudikaltd/para:latest_stablea6aba08c21fa
stdlib@go1.26.7
1.26.9
1
escaping/core-keeper-dedicated:latest87fa79255962
stdlib@go1.24.4
1.26.9
1
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.60.0
1.26.9
1
ethereum/client-go:v1.10.2603604c12f612
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.8
0.60.0
1.26.9
1
ethereum/client-go:v1.15.101f36ca5922a5
golang.org/x/net@v0.36.0
stdlib@go1.24.2
0.60.0
1.26.9
1
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.60.0
1.26.9
1
ethereum/client-go:stable4753febf6e7c
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
ethereum/client-go:latest5ab9a76153b0
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
ethereum/client-go:v1.10.186d6d12a40465
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.18.2
0.60.0
1.26.9
1
ethereum/client-go:v1.14.8886ec69b35b0
golang.org/x/net@v0.24.0
stdlib@go1.22.6
0.60.0
1.26.9
1
ethereum/client-go:v1.10.23cce21b423165
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.5
0.60.0
1.26.9
1
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.5
0.60.0
1.26.9
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
stdlib@go1.19.3
1.26.9
1
ethereumoptimism/l2geth:0.5.315577036dc36d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18
0.60.0
1.26.9
1
etherpad/etherpad:latest6f87beef31d9
stdlib@go1.26.4
1.26.9
1
ethersphere/bee:2.2.0a884fd84b72f
golang.org/x/net@v0.25.0
stdlib@go1.22.7
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.