StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
7 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
helm-4apk4.3.0-r04.3.0-r21
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-7r9c-ff6c-hxjjDEBIAN-CVE-2026-78663GO-2026-6612CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3x
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
rustrial-k8s-gitops-secrets-controllerk8s-gitops-secrets0.6.01 of 1See more

rustrial-k8s-gitops-secrets-controller k8s-gitops-secrets 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rustrial/k8s-gitops-secrets-controller:0.6.093326a322a01
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

263
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.26.9

Open the chart page →

6,383
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

5,724
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.26.9

Open the chart page →

8,402
k8s-sftp-gcsk8s-sftp-gcsVerified publisher0.1.41 of 1See more

k8s-sftp-gcs k8s-sftp-gcs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.26.9

Open the chart page →

2,579
k8statusk8statusOfficialVerified publisher0.17.01 of 1See more

k8status k8status 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/stenic/k8status:0.17.093298e03089e
golang.org/x/net@v0.26.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,137
kanister-operatorkanister0.118.01 of 1See more

kanister-operator kanister 0.118.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
golang.org/x/net@v0.41.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

1,590
kiali-operatorkiali2.33.01 of 1See more

kiali-operator kiali 2.33.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kiali/kiali-operator:v2.33.0035995403eed
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,621
kividb-operator-chartkividb-operatorVerified publisher0.4.02 of 2See more

kividb-operator-chart kividb-operator 0.4.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kividbio/kividb-operator:0.4.0a2395d6f47b7
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/kividbio/kividb-operator-gui:0.4.0276352c04b9c
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

248
mysqldumpkokuwa7.0.31 of 1See more

mysqldump kokuwa 7.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
stdlib@go1.26.1
1.26.9

Open the chart page →

1,146
kong-operatorkongOfficialVerified publisher1.4.11 of 1See more

kong-operator kong 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kong/kong-operator:2.3.2814eaeee4cc8
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

145
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.26.9

Open the chart page →

3,423
kuadrant-operatorkuadrantOfficialVerified publisher1.5.34 of 4See more

kuadrant-operator kuadrant 1.5.3

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kuadrant/authorino-operator:v0.25.395a0670bffe6
golang.org/x/net@v0.55.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/kuadrant/dns-operator:v0.17.2da9ff8211856
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/kuadrant/kuadrant-operator:v1.5.318ad777aeb7a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/kuadrant/limitador-operator:v0.18.49a9c533e58bb
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

885
kubearmorkubearmor1.7.53 of 4See more

kubearmor kubearmor 1.7.5

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubearmor/kubearmor:stablea08141311045
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
kubearmor/kubearmor-controller:latest43674bb4806f
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
kubearmor/kubearmor-relay-server:latestf82b9c97e97d
golang.org/x/net@v0.53.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

2,013
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
neosu/kubebadges:v0.0.5256530d8e5c6
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

2,313
pyroscopekubeblocksVerified publisher0.2.921 of 1See more

pyroscope kubeblocks 0.2.92

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

2,339
kubepatternkubepattern0.0.51 of 1See more

kubepattern kubepattern 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubepattern/kubepattern:0.0.50762baa6d9b0
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

544
kuberay-operatorkuberay-operator1.7.11 of 1See more

kuberay-operator kuberay-operator 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kuberay/operator:v1.7.1e69b9cde8f1d
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

556
skywalkingkubesphere-testVerified publisher3.1.02 of 4See more

skywalking kubesphere-test 3.1.0

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.60.0
1.26.9
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.60.0
1.26.9

Open the chart page →

20,621
kubeviouskubevious1.2.23 of 7See more

kubevious kubevious 1.2.2

3 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubevious/ui:1.2.16233e84bdd59
golang.org/x/net@v0.0.0-20220812165438-1d4ff48094d1
stdlib@go1.19.1
0.60.0
1.26.9
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.26.9
redislabs/redisearch:2.4.1433561794c5c8
stdlib@go1.16.7
1.26.9

Open the chart page →

17,851
kubevpnkubevpn-charts2.11.91 of 1See more

kubevpn kubevpn-charts 2.11.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubenetworks/kubevpn:v2.11.93feb9da85270
golang.org/x/net@v0.52.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,026
kubewallkubewallVerified publisher0.0.231 of 1See more

kubewall kubewall 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubewall/kubewall:0.0.23d9a03cfb557b
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

398
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.05 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs-webhook:latestc1f19557bdcb
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

62,687
prometheus-pingmesh-exporterkubservice-chartsVerified publisher1.1.11 of 1See more

prometheus-pingmesh-exporter kubservice-charts 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:latest355fa4be8e97
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.60.0
1.26.9

Open the chart page →

1,322
karporkusionstackVerified publisher0.7.62 of 3See more

karpor kusionstack 0.7.6

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/net@v0.19.0
stdlib@go1.22.12
0.60.0
1.26.9
quay.io/coreos/etcd:v3.5.11842975891182
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.60.0
1.26.9

Open the chart page →

4,469
kwokkwokOfficialVerified publisher0.3.01 of 1See more

kwok kwok 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

1,074
machinarislib42Verified publisher0.2.01 of 1See more

machinaris lib42 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/guydavis/machinaris:test50a71a30f18e
stdlib@go1.26.5
1.26.9

Open the chart page →

39,653
litellm-operatorlitellm-operatorVerified publisher1.1.21 of 1See more

litellm-operator litellm-operator 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/bbdsoftware/litellm-operator:1.1.2167a51113d90
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

566
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.60.0
1.26.9

Open the chart page →

4,538
vcluster-k8sloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-k8s loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.60.0
1.26.9
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

8,119
vcluster-platformloftVerified publisher4.12.21 of 1See more

vcluster-platform loft 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-platform:4.12.271d869f989e9
golang.org/x/net@v0.52.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,105
logging-operatorlogging-operator6.9.01 of 1See more

logging-operator logging-operator 6.9.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/logging-operator:6.9.0527033b7032b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
lumigo-operatorlumigo-operatorOfficialVerified publisher69.0.06 of 8See more

lumigo-operator lumigo-operator 69.0.0

6 of the 8 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/opentelemetry-operator/target-allocator:0.124.08936271cf56a
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9
public.ecr.aws/lumigo/lumigo-kubernetes-operator:69491c39346b19
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
public.ecr.aws/lumigo/lumigo-kubernetes-telemetry-proxy:691d548e59c2c8
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9
public.ecr.aws/lumigo/lumigo-kubernetes-watchdog:696458fcd61e0c
golang.org/x/net@v0.37.0
stdlib@go1.23.12
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

9,385
lxcfs-on-kuberneteslxcfs-on-kubernetes0.2.81 of 2See more

lxcfs-on-kubernetes lxcfs-on-kubernetes 0.2.8

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cndoit18/lxcfs-agent:v0.2.8154741f8596e
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

2,582
mariadbmariadbVerified publisher0.4.01 of 1See more

mariadb mariadb 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:10.117db29378d4fd
stdlib@go1.24.6
1.26.9

Open the chart page →

2,765
marmotmarmotOfficialVerified publisher1.6.02 of 2See more

marmot marmot 1.6.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latest999d5eb28f40
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/marmotdata/marmot:0.11.0cbc560cba46e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

349
mattermost-rtcdmattermostVerified publisher1.4.11 of 1See more

mattermost-rtcd mattermost 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mattermost/rtcd:latesta27058aaa53a
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

931
veleromesosphere3.2.51 of 1See more

velero mesosphere 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

2,730
kubecostmesosphere-stable0.37.57 of 9See more

kubecost mesosphere-stable 0.37.5

7 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
grafana/grafana:9.4.71a359d92f40e
golang.org/x/net@v0.4.0
stdlib@go1.20.1
0.60.0
1.26.9
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/thanos/thanos:v0.36.1e542959e1b36
golang.org/x/net@v0.26.0
stdlib@go1.21.13
0.60.0
1.26.9

Open the chart page →

22,738
m8b-stackmetricshubVerified publisher2.1.31 of 4See more

m8b-stack metricshub 2.1.3

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/prometheus:v3.13.36976aa8a60fe
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

259
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,807
helm-ai-kernelmindburn-labsOfficialVerified publisher0.11.12 of 2See more

helm-ai-kernel mindburn-labs 0.11.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/mindburn-labs/helm-ai-kernel:v0.11.10e7a5cd11858
golang.org/x/net@v0.58.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

2,809
mc-routerminecraft-server-chartsVerified publisher1.5.01 of 1See more

mc-router minecraft-server-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
itzg/mc-router:latest64ae69eaa7a6
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

168
mocomoco0.27.01 of 1See more

moco moco 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cybozu-go/moco:0.37.032e7cab1bdd8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

174
mogenius-operatormogeniusOfficial2.30.01 of 2See more

mogenius-operator mogenius 2.30.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/mogenius/mogenius-operator:2.30.051bebfb32413
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

1,065
mongodb-kubernetesmongodb-helm-charts1.13.01 of 1See more

mongodb-kubernetes mongodb-helm-charts 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes:1.13.00184a96e324f
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

151
mortalgpumortalgpuOfficialVerified publisher1.3.71 of 1See more

mortalgpu mortalgpu 1.3.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/maxiv/mortalgpu:1.3.7e1c5c194bbf0
golang.org/x/net@v0.54.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

711
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

4,795
mycelmycelOfficialVerified publisher3.10.01 of 1See more

mycel mycel 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mdenda/mycel:3.10.09e559aa83030
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

323
nacknatsVerified publisher0.35.01 of 1See more

nack nats 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
natsio/jetstream-controller:0.24.058862daca582
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

444

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 7 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
goharbor/harbor-registryctl:devb8fa35c3d36e
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.60.0
1.26.9
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.60.0
1.26.9
1
goharbor/registry-photon:v2.11.15645d459af2b
stdlib@go1.22.6
1.26.9
1
goharbor/registry-photon:v2.14.36533fc396cbc
stdlib@go1.24.13
1.26.9
1
goharbor/registry-photon:v2.9.08a26e8cb7862
stdlib@go1.20.7
1.26.9
1
goharbor/registry-photon:devc34795d74b99
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
1
goharbor/registry-photon:v2.15.4dc0cb388a644
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
golang.org/x/net@v0.28.0
stdlib@go1.25.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.15.4813ca81b4a4e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.18.3
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:devd051158f1fd0
golang.org/x/net@v0.55.0
stdlib@go1.26.4-X:jsonv2
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.60.0
1.26.9
1
golift/unifi-poller:v2.9.5486a63339969
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
golift/unifi-poller:v2.9.2585a29a06d05
golang.org/x/net@v0.15.0
stdlib@go1.21.0
0.60.0
1.26.9
1
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.7
0.60.0
1.26.9
1
gomods/athens:v0.17.10f61d1e62359
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
1
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.13.4
0.60.0
1.26.9
1
gomods/athens:v0.19.2e1abe3005673
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
goofball222/pritunl:1.32.3602.807bf26032dfce
golang.org/x/net@v0.7.0
stdlib@go1.18.7
0.60.0
1.26.9
1
google/cloud-sdk:slimc70885ba9f04
stdlib@go1.26.6
1.26.9
1
google/cloud-sdk:alpineef78619c8239
stdlib@go1.26.6
1.26.9
1
gophish/gophish:0.12.18a57cd171999
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.15.2
0.60.0
1.26.9
1
gotenberg/gotenberg:8-chromium0d28ae9a9644
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
gotenberg/gotenberg:8.30206a6c708fc6
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.60.0
1.26.9
1
gotenberg/gotenberg:8.7.0437b9cd3c351
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
1
gotenberg/gotenberg:8.3467097317623a
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.60.0
1.26.9
1
gotify/server:2.9.1a3af47067ce6
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
1
gotify/server-arm7:2.0.23d91e302ad1d0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.60.0
1.26.9
1
gotson/komga:1.27.19cf102f5fb78
stdlib@go1.17.8
1.26.9
1
gotson/komga:1.22.0ba892ab3e082
stdlib@go1.17.8
1.26.9
1
gotson/komga:1.28.1d8f772dce7b3
stdlib@go1.26.7
1.26.9
1
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.60.0
1.26.9
1
gradiant/packetrusher:2b26573e9b46dc76af4
golang.org/x/net@v0.38.0
stdlib@go1.21.3
0.60.0
1.26.9
1
grafana/agent:v0.44.23364714a2f64
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.60.0
1.26.9
1
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16
0.60.0
1.26.9
1
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.60.0
1.26.9
1
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9
1
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/net@v0.31.0
stdlib@go1.22.7
0.60.0
1.26.9
1
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.60.0
1.26.9
1
grafana/alloy:v1.18.10f4434c92b3e
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
1
grafana/alloy:v1.20.12aa2099af76c
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
grafana/alloy:v1.18.0491b0578c049
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
1
grafana/alloy:v1.16.384b76d56c594
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
1
grafana/alloy:v1.11.38c7256f412fe
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
1
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.