StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-7r9c-ff6c-hxjjCGA-gghc-78jw-f5q2CGA-rp37-mxv6-g5fjDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-vqxj-4gp6-23v9, CGA-w84h-9v6p-pf3x, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
kcmkcm1.12.012 of 12See more

kcm kcm 1.12.0

12 of the 12 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
velero/velero:v1.18.237396519f399
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/fluxcd/helm-controller:v1.6.2e17ab0e5885d
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/fluxcd/source-controller:v1.9.22b8d06650a1b
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/k0rdent/kcm/controller:1.12.00ec66900c2a9
golang.org/x/net@v0.59.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/k0rdent/kcm/telemetry:1.12.01718c4b14e65
golang.org/x/net@v0.59.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/stakater/reloader:v1.4.22def2480040ad
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

6,630
kcp-operatorkcp-devVerified publisher0.7.101 of 1See more

kcp-operator kcp-dev 0.7.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kcp-dev/kcp-operator:v0.9.0cd8bf46d98e0
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

399
keeper-injectorkeeper-injectorVerified publisher0.10.02 of 2See more

keeper-injector keeper-injector 0.10.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
keeper/injector-webhook:0.10.0aeb5476b95f0
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.60.0
1.26.9

Open the chart page →

1,680
keeper-injectorkeeper-securityVerified publisher0.11.32 of 2See more

keeper-injector keeper-security 0.11.3

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
keeper/injector-webhook:0.11.33eb609f3e60c
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.60.0
1.26.9

Open the chart page →

1,240
nodevitalskeiailabVerified publisher0.9.41 of 1See more

nodevitals keiailab 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/keiailab/nodevitals:0.9.4b07e506d4cb1
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

502
qdrant-operatorkeiailabVerified publisher0.10.21 of 1See more

qdrant-operator keiailab 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/keiailab/qdrant-operator:v0.10.23da83bf91aa1
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

201
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
stdlib@go1.20.7
1.26.9

Open the chart page →

6,374
kent-exporterkentVerified publisher0.4.01 of 1See more

kent-exporter kent 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
staslevchenko/kent:0.4.0e1b5de030254
golang.org/x/net@v0.57.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

372
kestra-starterkestraOfficialVerified publisher2.0.53 of 5See more

kestra-starter kestra 2.0.5

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/docker:dind-rootless3acba49741f1
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.26.9
versity/versitygw:v1.1.0f730e0dbc1ef
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

7,574
keyauthoritykeyauthorityVerified publisher0.2.271 of 5See more

keyauthority keyauthority 0.2.27

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
keyauthoritydh/backend:1.4.10b2519da39b25
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

2,270
keycloak-operator-legacykeycloak-operator-legacy1.0.01 of 1See more

keycloak-operator-legacy keycloak-operator-legacy 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.60.0
1.26.9

Open the chart page →

6,404
csi-driver-nfskeyporttech0.1.41 of 2See more

csi-driver-nfs keyporttech 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
golang.org/x/net@v0.0.0-20190415100556-4a65cf94b679
stdlib@go1.14.2
0.60.0
1.26.9

Open the chart page →

4,598
gogskeyporttech0.1.31 of 3See more

gogs keyporttech 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gogs/gogs:0.12.30195b095d0b2
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.7
0.60.0
1.26.9

Open the chart page →

4,770
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

10,227
connectkfirfer1.15.02 of 2See more

connect kfirfer 1.15.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
1password/connect-api:1.7.26aa94cf713f9
golang.org/x/net@v0.14.0
stdlib@go1.20.6
0.60.0
1.26.9
1password/connect-sync:1.7.2fe527ed9d81f
golang.org/x/net@v0.14.0
stdlib@go1.20.6
0.60.0
1.26.9

Open the chart page →

4,355
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.60.0
1.26.9

Open the chart page →

4,038
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
stdlib@go1.17.1
1.26.9

Open the chart page →

7,793
keelkfirfer1.0.51 of 1See more

keel kfirfer 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
keelhq/keel:0.19.202ac4ea616c4
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

2,789
kubernetes-replicatorkfirfer2.9.11 of 1See more

kubernetes-replicator kfirfer 2.9.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.9.1baf5f784398b
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

1,556
mysqldumpkfirfer2.8.01 of 1See more

mysqldump kfirfer 2.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

4,248
pod-cleanupkfirfer0.0.41 of 1See more

pod-cleanup kfirfer 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

1,240
prometheus-elasticsearch-exporterkfirfer6.5.11 of 1See more

prometheus-elasticsearch-exporter kfirfer 6.5.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.8.0073dd360de2c
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9

Open the chart page →

1,314
scriptskfirfer0.1.361 of 1See more

scripts kfirfer 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kfirfer/scripts:0.0.2481e5c4e5d70e
stdlib@go1.17.10
1.26.9

Open the chart page →

3,197
kiaekiae0.1.66 of 9See more

kiae kiae 0.1.6

6 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9
grafana/promtail:2.6.1072527b12cdf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9
istio/pilot:1.15.2db08d6963975
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.19.2
0.60.0
1.26.9
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.2
0.60.0
1.26.9
ghcr.io/kiaedev/kiae:latestebd03028ff6a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.18.9
0.60.0
1.26.9

Open the chart page →

25,362
kimai-helmchartkimai2tet0.1.01 of 2See more

kimai-helmchart kimai2tet 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

2,373
local-path-provisionerkir4hVerified publisher0.0.351 of 1See more

local-path-provisioner kir4h 0.0.35

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.3534ff0847cc47
golang.org/x/net@v0.38.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

1,179
process-exporterkir4hVerified publisher1.0.11 of 1See more

process-exporter kir4h 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ncabatoff/process-exporterdigest-pinned6f0549dc24e9
golang.org/x/net@v0.33.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

1,268
typebotiokitsune-itopsVerified publisher0.1.41 of 4See more

typebotio kitsune-itops 0.1.4

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.26.9

Open the chart page →

754
cdashkitwareVerified publisher0.20.01 of 3See more

cdash kitware 0.20.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
golang.org/x/net@v0.32.0
stdlib@go1.22.10
0.60.0
1.26.9

Open the chart page →

13,576
rabbitmq-cluster-operatorklicktippVerified publisher0.4.83 of 3See more

rabbitmq-cluster-operator klicktipp 0.4.8

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/klicktipp/kubectl:1.36.30c2402d92b5c
golang.org/x/net@v0.49.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/rabbitmq/cluster-operator:2.23.09236fb4f559b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/rabbitmq/messaging-topology-operator:1.20.3f377d3c3e221
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,029
rabbitmq-topology-operatorklicktippVerified publisher0.4.32 of 2See more

rabbitmq-topology-operator klicktipp 0.4.3

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/klicktipp/kubectl:1.36.30c2402d92b5c
golang.org/x/net@v0.49.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/rabbitmq/messaging-topology-operator:1.20.3f377d3c3e221
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

828
kloudlite-agentkloudlite1.1.51 of 3See more

kloudlite-agent kloudlite 1.1.5

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latest999d5eb28f40
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

218
kloudlite-platformkloudlite1.1.51 of 3See more

kloudlite-platform kloudlite 1.1.5

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

2,670
klustre-csi-pluginklustre-csi-plugin0.1.11 of 2See more

klustre-csi-plugin klustre-csi-plugin 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

2,157
knative-servingknative-servingVerified publisher1.18.37 of 7See more

knative-serving knative-serving 1.18.3

7 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

7,282
kollectkollectVerified publisher0.21.01 of 1See more

kollect kollect 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/platformrelay/kollect:v0.21.0a86edc5ec3a8
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

2,263
kollektorkollektorVerified publisher1.0.51 of 1See more

kollektor kollektor 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
pannoi/kollektor:1.0.59559617788fc
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

1,355
cert-managerkomailo-helm-charts1.10.14 of 4See more

cert-manager komailo-helm-charts 1.10.1

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

836
cloudflare-tunnel-remotekomailo-helm-charts1.3.21 of 1See more

cloudflare-tunnel-remote komailo-helm-charts 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.9.3072c067d25cc
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

625
external-dnskomailo-helm-charts1.11.01 of 1See more

external-dns komailo-helm-charts 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/external-dns/external-dns:v0.22.05fdcaf7deb5c
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

247
external-secretskomailo-helm-charts6.1.01 of 1See more

external-secrets komailo-helm-charts 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v2.10.0814117b0fd6d
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

304
ingress-nginxkomailo-helm-charts1.0.02 of 2See more

ingress-nginx komailo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
golang.org/x/net@v0.29.0
stdlib@go1.22.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.60.0
1.26.9

Open the chart page →

2,606
k8s-metrics-serverkomailo-helm-charts1.2.01 of 1See more

k8s-metrics-server komailo-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

462
longhornkomailo-helm-charts0.6.03 of 3See more

longhorn komailo-helm-charts 0.6.0

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.12.183b79f57043f
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
longhornio/longhorn-share-manager:v1.12.1efaf47aeb4e8
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
longhornio/longhorn-ui:v1.12.103a3ce6673df
stdlib@go1.25.12
1.26.9

Open the chart page →

1,498
metallbkomailo-helm-charts1.2.43 of 4See more

metallb komailo-helm-charts 1.2.4

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.16.1f51ab515de9c
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
golang.org/x/net@v0.39.0
stdlib@go1.25.8
0.60.0
1.26.9
quay.io/metallb/speaker:v0.16.116561e96531e
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

3,409
traefikkomailo-helm-charts5.1.01 of 1See more

traefik komailo-helm-charts 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/traefik:v3.7.1324841fe2de73
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

246
komiserkomiser-eks3.1.101 of 1See more

komiser komiser-eks 3.1.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
tailwarden/komiser:3.1.103f68c8ae7993
golang.org/x/net@v0.17.0
stdlib@go1.22.0
0.60.0
1.26.9

Open the chart page →

1,951
komoplanekomodorVerified publisher0.1.81 of 1See more

komoplane komodor 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
komodorio/komoplane:0.2.19678d02c3f2e
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

1,339
simple-oauth2-proxykostiantyn-matsebora-helm-chartsVerified publisher0.3.71 of 1See more

simple-oauth2-proxy kostiantyn-matsebora-helm-charts 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.7.09ed7eaf72050
golang.org/x/net@v0.29.0
stdlib@go1.22.8
0.60.0
1.26.9

Open the chart page →

1,476
kovi-tile38kovi-charts0.1.11 of 1See more

kovi-tile38 kovi-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
tile38/tile38:1.33.4afb7e82f9485
golang.org/x/net@v0.23.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,748

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
stdlib@go1.24.6
1.26.9
4
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.60.0
1.26.9
4
cockroachdb/cockroach-self-signer-cert:1.10b0fcc6c8147a
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.60.0
1.26.9
4
decisionrules/server:latestbb3a93224b5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
4
grafana/loki:3.6.73c8fd3570dd9
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
4
hyperledger/fabric-ca:latesta70b6ba64a08
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
4
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
4
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
4
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
4
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9
4
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.26.9
4
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
4
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
4
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.26.9
4
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.26.9
4
library/mariadb:13.0.2:latestd4fdec0510ad
stdlib@go1.26.7
1.26.9
4
library/mongo:5.0-focal5e15a3f014ed
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
4
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.26.9
4
library/nats:2.15.0-alpineac8f88a6494b
stdlib@go1.27.1
1.27.2
4
library/postgres:134689940c6838
stdlib@go1.24.6
1.26.9
4
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.26.9
4
linuxserver/plex:1.43.4:latest06e07af2851e
stdlib@go1.26.7
1.26.9
4
migrate/migrate:latest76cc2074cb66
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
4
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.60.0
1.26.9
4
natsio/nats-box:0.19.7ffce8bd10338
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
4
natsio/nats-server-config-reloader:0.21.110ff229eaf52
stdlib@go1.25.5
1.26.9
4
natsio/prometheus-nats-exporter:0.20.2:latestc623b608e148
stdlib@go1.26.6
1.26.9
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.26.9
4
otel/opentelemetry-collector-contrib:0.162.0:latest39923a8e431b
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
4
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
4
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
golang.org/x/net@v0.18.0
stdlib@go1.21.7
0.60.0
1.26.9
4
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
golang.org/x/net@v0.30.0
stdlib@go1.23.5
0.60.0
1.26.9
4
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
4
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
4
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
4
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
4
ghcr.io/kubedb/kubedb-provisioner:v0.66.0e7041c3b41e7
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9
4
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0e0f4431c4704
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9
4
ghcr.io/kubestash/kubestash:v0.29.00686b2a40280
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9
4
ghcr.io/kubevault/vault-operator:v0.25.0c8e042b5cee8
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.60.0
1.26.9
4
ghcr.io/sigstore/scaffolding/createtree:v0.7.334c845ced03d8
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
4
ghcr.io/stakater/reloader:v1.4.22def2480040ad
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
4
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
golang.org/x/net@v0.35.0
stdlib@go1.22.4
0.60.0
1.26.9
4
quay.io/argoproj/argocd:v3.5.449dff79439bb
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9
4
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
4
quay.io/ceems/ceems:v0.16.14633125698c3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
4
quay.io/jcmoraisjr/haproxy-ingress:v0.16.242bcf39842db
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.