StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
DEBIAN-CVE-2026-78663GO-2026-6612CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3x
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
temporallemontechVerified publisher0.37.06 of 13See more

temporal lemontech 0.37.0

6 of the 13 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.60.0
1.26.9
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.26.9
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9
temporalio/server:1.22.4c0a44c26397b
golang.org/x/net@v0.7.0
stdlib@go1.20.11
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

21,530
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
golang.org/x/net@v0.40.0
stdlib@go1.25.0
0.60.0
1.26.9
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

8,925
netris-controllernetrisai2.8.27 of 14See more

netris-controller netrisai 2.8.2

7 of the 14 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.11
0.60.0
1.26.9
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.60.0
1.26.9
netrisai/controller-grpc:4.6.0.00753178bf173c2
golang.org/x/net@v0.23.0
stdlib@go1.25.6
0.60.0
1.26.9
netrisai/controller-telescope:4.6.0.00414d82948a8b2
stdlib@go1.25.6
1.26.9
netrisai/controller-web-session-generator:0.2.0a030a31289f4
stdlib@go1.14.15
1.26.9
netrisai/mariadb:10.11.4-debian-11-r460aa742a0b906
stdlib@go1.19.11
1.26.9
netrisai/mongodb:4.4.4-debian-10-r095abfb776bb4
stdlib@go1.15.1
1.26.9

Open the chart page →

38,380
nfs-server-provisionernfs-ganesha-server-and-external-provisioner1.8.01 of 1See more

nfs-server-provisioner nfs-ganesha-server-and-external-provisioner 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

3,435
nginx-service-meshnginxVerified publisher2.0.02 of 9See more

nginx-service-mesh nginx 2.0.0

2 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
library/nats:2.9-alpined402af4147fc
stdlib@go1.20.14
1.26.9

Open the chart page →

1,800
nuclionuclio0.23.92 of 2See more

nuclio nuclio 0.23.9

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/nuclio/controller:1.17.9-amd646e3913a56ca5
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/nuclio/dashboard:1.17.9-amd64708fe10f099a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,851
homarroben01Verified publisher1.4.01 of 1See more

homarr oben01 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
stdlib@go1.22.5
1.26.9

Open the chart page →

3,285
syftopenmined0.9.55 of 6See more

syft openmined 0.9.5

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.26.9
library/registry:2a3d8aaa63ed8
stdlib@go1.20.8
1.26.9
library/traefik:v2.11.00a5157f742d2
golang.org/x/net@v0.20.0
stdlib@go1.22.0
0.60.0
1.26.9
openmined/syft-frontend:0.9.5d11524a3854a
stdlib@go1.20.5
1.26.9
openmined/syft-seaweedfs:0.9.53a4144c0bb82
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.60.0
1.26.9

Open the chart page →

21,245
paperless-ngxpaperless-ngxVerified publisher0.3.241 of 3See more

paperless-ngx paperless-ngx 0.3.24

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.3.06b94799bc769
stdlib@go1.24.4
1.26.9

Open the chart page →

9,131
pmmpercona1.9.11 of 1See more

pmm percona 1.9.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
percona/pmm-server:3.9.1003f9c25f842
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,109
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9
platform9community/api-gateway:latest40a4970de568
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9
platform9community/customers-service:latest2089811e5cc6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.11
0.60.0
1.26.9
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

48,861
prometheus-nats-exporterprometheus-communityVerified publisher2.23.21 of 1See more

prometheus-nats-exporter prometheus-community 2.23.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
natsio/prometheus-nats-exporter:0.20.2c623b608e148
stdlib@go1.26.6
1.26.9

Open the chart page →

288
prometheus-rabbitmq-exporterprometheus-communityVerified publisher2.1.21 of 1See more

prometheus-rabbitmq-exporter prometheus-community 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kbudde/rabbitmq-exporter:1.0.012f27d6d84e6
stdlib@go1.21.8
1.26.9

Open the chart page →

898
pyrrarlex0.15.01 of 1See more

pyrra rlex 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/pyrra-dev/pyrra:v0.8.10e02ef538ef0
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,422
sealed-secretssealed-secretsVerified publisher2.20.01 of 1See more

sealed-secrets sealed-secrets 2.20.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.40.0b1ff382e9300
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

128
k8s-infrasignoz0.17.11 of 1See more

k8s-infra signoz 0.17.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.139.0faf125d656fa
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

1,651
radarskyhookOfficialVerified publisher1.16.01 of 1See more

radar skyhook 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/skyhook-io/radar:1.16.02e57d0465fba
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

135
helm-exportersstarcher0.5.01 of 1See more

helm-exporter sstarcher 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
sstarcher/helm-exporter:0.5.011769d01ba35
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.6
0.60.0
1.26.9

Open the chart page →

5,443
tailing-sidecar-operatortailing-sidecar-operatorOfficialVerified publisher0.111.02 of 2See more

tailing-sidecar-operator tailing-sidecar-operator 0.111.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/sumologic/tailing-sidecar-operator:0.111.0920b8f901aef
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

2,077
tailscale-operatortailscale1.102.41 of 1See more

tailscale-operator tailscale 1.102.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
tailscale/k8s-operator:v1.102.43c8958c42fb3
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

351
tbmq-clustertbmq-helm-chartOfficialVerified publisher2.3.11 of 3See more

tbmq-cluster tbmq-helm-chart 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
thingsboard/toolbox:1.29.00f6c14031777
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

3,248
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.26.9

Open the chart page →

8,353
elasticsearch-clusterwiremindVerified publisher4.5.41 of 2See more

elasticsearch-cluster wiremind 4.5.4

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.11.0a056739b095d
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

996
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.60.0
1.26.9

Open the chart page →

6,514
zigbee2mqttzigbee2mqtt2.14.21 of 2See more

zigbee2mqtt zigbee2mqtt 2.14.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mikefarah/yq:4.45.12c100efaca06
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,558
home-assistantandrenarchyVerified publisher14.104.01 of 1See more

home-assistant andrenarchy 14.104.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

3,149
config-syncerappscodeVerified publisher0.15.51 of 1See more

config-syncer appscode 0.15.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/config-syncer:v0.15.51858a68944cb
golang.org/x/net@v0.17.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

887
astarte-operatorastarteOfficialVerified publisher26.5.21 of 1See more

astarte-operator astarte 26.5.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
astarte/astarte-kubernetes-operator:26.5.1e3ff1b3c0c98
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,054
awx-operatorawx-operator-helm3.2.12 of 2See more

awx-operator awx-operator-helm 3.2.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
golang.org/x/net@v0.20.0
stdlib@go1.20.12
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.15.02c7b120590cb
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

11,149
cerboscerbosVerified publisher0.56.01 of 1See more

cerbos cerbos 0.56.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cerbos/cerbos:0.56.0540643bc67ba
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
cert-manager-istio-csrcert-managerOfficialVerified publisher0.18.01 of 1See more

cert-manager-istio-csr cert-manager 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-istio-csr:v0.18.0495dcdad72a4
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

220
cadvisorckotzbauerVerified publisher2.4.31 of 1See more

cadvisor ckotzbauer 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.52.1f40e65878e25
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

1,418
m365-exportercloudeteer-helm-chartsVerified publisher1.7.11 of 1See more

m365-exporter cloudeteer-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cloudeteer/m365-exporter:3.9.3a13a11fe9558
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

281
openstack-cloud-controller-managercloud-provider-openstack2.36.51 of 1See more

openstack-cloud-controller-manager cloud-provider-openstack 2.36.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/openstack-cloud-controller-manager:v1.36.0e354e40db2d0
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

809
passboltcnieg1.1.171 of 2See more

passbolt cnieg 1.1.17

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.26.9

Open the chart page →

5,372
codercoderOfficialVerified publisher1.44.61 of 2See more

coder coder 1.44.6

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.60.0
1.26.9

Open the chart page →

7,935
dronecommunity-chartsVerified publisher0.1.52 of 2See more

drone community-charts 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
drone/drone:2.28.255897c8fb22d
golang.org/x/net@v0.42.0
stdlib@go1.24.13
0.60.0
1.26.9
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

4,053
cloudflare-operatorcontainerooVerified publisher1.10.71 of 1See more

cloudflare-operator containeroo 1.10.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/cloudflare-operator:v1.10.60eda6d237a84
golang.org/x/net@v0.57.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

512
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9
getconvoy/convoy:v26.7.6f4934cc05e31
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

7,260
cortexcortex3.5.02 of 4See more

cortex cortex 3.5.0

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/memcached-exporter:v0.17.0995c80e3ffbe
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
quay.io/cortexproject/cortex:v1.21.18577eb292a01
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

3,931
whoamicowboysysopVerified publisher6.1.01 of 1See more

whoami cowboysysop 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
traefik/whoami:v1.12.0c4717a8d1f01
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

273
doris-operatordorisVerified publisher25.8.01 of 1See more

doris-operator doris 25.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/doris:operator-latest3a4422656592
golang.org/x/net@v0.33.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

837
uptime-kumaduyet0.1.81 of 1See more

uptime-kuma duyet 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

5,803
emqx-operatoremqx-operator2.3.32 of 2See more

emqx-operator emqx-operator 2.3.3

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/k8s:1.31.49c4976d47656
golang.org/x/net@v0.31.0
stdlib@go1.23.2
0.60.0
1.26.9
ghcr.io/emqx/emqx-operator:2.3.378d1c5eacebd
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

5,901
kube-routerenixVerified publisher1.10.01 of 1See more

kube-router enix 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

3,096
gethethereum-helm-chartsVerified publisher1.1.41 of 2See more

geth ethereum-helm-charts 1.1.4

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ethereum/client-go:stable4753febf6e7c
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

222
gotifygotifyVerified publisher0.8.11 of 1See more

gotify gotify 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gotify/server:2.9.1a3af47067ce6
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

915
alloy-operatorgrafana0.8.01 of 1See more

alloy-operator grafana 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.13.0a8ae76efd773
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

757
hcloud-csihcloud2.23.06 of 6See more

hcloud-csi hcloud 2.23.0

6 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

4,530
docmosthelmforgeVerified publisher1.4.11 of 4See more

docmost helmforge 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

4,619

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
gresearch/armada-lookout:latest2e924223c0f7
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
gresearch/armada-lookout-ingester:latestc6fce922dec3
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
gresearch/armada-operator:latest6c43743e2b2d
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.60.0
1.26.9
1
gresearch/armada-scheduler:latesta5f8c2d040c0
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
gresearch/fasttrackml:latest16d1228220fc
golang.org/x/net@v0.24.0
stdlib@go1.21.10
0.60.0
1.26.9
1
groundnuty/k8s-wait-for:v1.684edcf796267
stdlib@go1.18.1
1.26.9
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
1
grpl/grapple-cli:0.2.127c00aafee6629
golang.org/x/net@v0.26.0
stdlib@go1.18.10
0.60.0
1.26.9
1
gutmensch/podnat-controller:0.5.2566979793fc4
golang.org/x/net@v0.4.0
stdlib@go1.22.3
0.60.0
1.26.9
1
gvpaleevkz/xray-proxy:v1.0.046eb128d6c61
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
1
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9
1
haproxytech/haproxy-alpine:2.6.614e4afa90dfd
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9
1
haproxytech/haproxy-alpine:3.4.41fe3f201ebb5
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
haproxytech/haproxy-alpine:2.9.57f3dc8c7e031
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.60.0
1.26.9
1
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.60.0
1.26.9
1
haproxytech/haproxy-unified-gateway:1.0.7b9bffe2d0fd1
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
1
haproxytech/kubernetes-ingress:3.2.156185ab228aa6
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.60.0
1.26.9
1
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.60.0
1.26.9
1
hashicorp/boundary:0.21.037bf86488b74
golang.org/x/net@v0.47.0
stdlib@go1.25.1
0.60.0
1.26.9
1
hashicorp/boundary:latest76a201954ca0
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
1
hashicorp/boundary:0.8.1fb70bd9210ff
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.10
0.60.0
1.26.9
1
hashicorp/consul:1.17.0712fe02d2f84
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
1
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.60.0
1.26.9
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.60.0
1.26.9
1
hashicorp/hcp-terraform-operator:2.12.15a15932f6838
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
1
hashicorp/terraform:1.44dcb45513699
golang.org/x/net@v0.6.0
stdlib@go1.19.6
0.60.0
1.26.9
1
hashicorp/terraform:1.9.7b77efab1a448
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
1
hashicorp/terraform-cloud-operator:2.5.0c2f78a575a8a
golang.org/x/net@v0.24.0
stdlib@go1.22.4
0.60.0
1.26.9
1
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.18.8
0.60.0
1.26.9
1
hashicorp/vault:1.15.40b01ed3924e6
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
1
hashicorp/vault:2.1.0:latest5520cc26271c
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
hashicorp/vault:1.18750bb37c1638
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
1
hashicorp/vault:2.0.1755355002715
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
1
hashicorp/vault:1.14.0b2177a8bfe85
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
1
hashicorp/vault:1.19.0bbb7f98dc67d
golang.org/x/net@v0.35.0
stdlib@go1.23.6
0.60.0
1.26.9
1
hashicorp/vault:latestc2f666266f38
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.60.0
1.26.9
1
hashicorp/vault:1.9.2ff9b17b0cefe
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.5
0.60.0
1.26.9
1
hashicorp/vault-k8s:1.6.2103a2d817a74
golang.org/x/net@v0.35.0
stdlib@go1.23.6
0.60.0
1.26.9
1
hashicorp/vault-k8s:1.2.14500e988b7ce
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.60.0
1.26.9
1
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.13.5
0.60.0
1.26.9
1
hashicorp/vault-k8s:1.7.2ae3d307658b7
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
1
hashicorp/vault-k8s:0.14.0aff47b5ba39c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.2
0.60.0
1.26.9
1
hashicorp/vault-secrets-operator:1.6.002a79a046037
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
hashicorp/waypoint:0.11.397d521a27498
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9
1
hauler/hauler:2.1.13f36bf6bc92d
golang.org/x/net@v0.58.0
stdlib@go1.27.0-X:boringcrypto
0.60.0
1.27.2
1
hazelcast/hazelcast-platform-operator:5.20.0e10ca9d704b1
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.6
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.