StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
sealed-secretsbitnamiVerified publisher2.5.191 of 1See more

sealed-secrets bitnami 2.5.19

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,055
mariadbcloudpirates-mariadbVerified publisher0.16.161 of 1See more

mariadb cloudpirates-mariadb 0.16.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:13.0.2f1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

1,782
difydoubanVerified publisher0.10.04 of 6See more

dify douban 0.10.0

4 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.26.9
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.60.0
1.26.9
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.60.0
1.26.9
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.26.9

Open the chart page →

83,750
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.5.02 of 3See more

kubeshark kubeshark-helm-charts 53.5.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubeshark/hub:v53.50532936678f8
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2
kubeshark/worker:v53.51f3e121224f8
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,281
secrets-store-csi-driversecret-store-csi-driver1.6.14 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/csi-secrets-store/driver-crds:v1.6.1cdacfdbe8966
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

2,941
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.31 of 2See more

stackgres-operator stackgres-charts 1.19.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

3,032
victoria-logs-singlevictoriametricsVerified publisher0.13.101 of 1See more

victoria-logs-single victoriametrics 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.53.0251121fa882a
stdlib@go1.27.1
1.27.2

Open the chart page →

89
mongodbcloudpirates-mongodbVerified publisher0.20.01 of 1See more

mongodb cloudpirates-mongodb 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mongo:9.0.2bac22ea7710d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,244
kube-image-keeperenixVerified publisher2.3.11 of 1See more

kube-image-keeper enix 2.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/enix/kube-image-keeper:2.3.1d3ccf28495c3
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

229
mattermost-team-editionmattermostVerified publisher6.6.1081 of 4See more

mattermost-team-edition mattermost 6.6.108

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:11.11.16ad5912b4587
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

2,045
code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
stdlib@go1.16.4
1.26.9

Open the chart page →

18,186
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

706
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
stdlib@go1.26.5
1.26.9

Open the chart page →

2,186
pulsarapache4.7.06 of 10See more

pulsar apache 4.7.0

6 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
victoriametrics/operator:v0.68.3f52e1bd679cb
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

13,072
miniocloudpirates-minioVerified publisher0.14.01 of 1See more

minio cloudpirates-minio 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,670
vertical-pod-autoscalercowboysysopVerified publisher11.1.14 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

9,019
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.26.9
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
langgenius/dify-api:1.16.1dcefa5f7c47c
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

74,916
eclipse-cheeclipse-cheVerified publisher7.123.01 of 1See more

eclipse-che eclipse-che 7.123.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.123.0d926b6d183a1
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,116
pyroscopegrafana2.4.02 of 3See more

pyroscope grafana 2.4.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/alloy:v1.19.2b8ec653c4423
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,762
botkubeinfracloudioVerified publisher1.14.01 of 1See more

botkube infracloudio 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.60.0
1.26.9

Open the chart page →

1,587
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,332
thanosthanos-communityOfficialVerified publisher0.47.11 of 1See more

thanos thanos-community 0.47.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

426
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.26.9

Open the chart page →

2,435
tetragonciliumOfficialVerified publisher1.7.12 of 3See more

tetragon cilium 1.7.1

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/cilium/tetragon-operator:v1.7.1cd8b71f6860e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

512
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

5,565
k6-operatorgrafana4.6.01 of 1See more

k6-operator grafana 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/grafana/k6-operator:controller-v1.6.0ba7f0fc1e22e
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

283
rabbitmqgroundhog2k2.3.91 of 2See more

rabbitmq groundhog2k 2.3.9

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6446551b26c0b
stdlib@go1.22.2
1.26.9

Open the chart page →

1,296
telegrafinfluxdata1.8.771 of 1See more

telegraf influxdata 1.8.77

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/telegraf:1.40-alpine6606553b5019
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

141
k8tzk8tzOfficialVerified publisher0.20.01 of 1See more

k8tz k8tz 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/k8tz/k8tz:0.20.0361628e53fc8
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

218
kiali-serverkiali2.33.01 of 1See more

kiali-server kiali 2.33.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kiali/kiali:v2.33.0082246cfc99f
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

456
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

845
vela-corekubevela1.11.03 of 3See more

vela-core kubevela 1.11.0

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
oamdev/cluster-gateway:v1.9.0-alpha.25591e29d66a2
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
oamdev/kube-webhook-certgen:v2.4.1231c423c2b17
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.11
0.60.0
1.26.9
oamdev/vela-core:v1.11.095fa412c934e
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

6,663
oktetooktetoOfficialVerified publisher0.0.0-2026-08-317 of 10See more

okteto okteto 0.0.0-2026-08-31

7 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/okteto/backend:0.0.0-2026-08-316171cb2b2a72
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.60.0
1.26.9
ghcr.io/okteto/buildkit:0.0.0-2026-08-3114527ca5d2a9
golang.org/x/net@v0.55.0
stdlib@go1.25.7
0.60.0
1.26.9
ghcr.io/okteto/daemon:0.0.0-2026-08-31c6e716a3fbbe
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-31d6730eb9831b
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/okteto/okteto:3.23.0-beta.1a0483d47ba04
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/okteto/registry:0.0.0-2026-08-3169131511501f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/okteto/reloader:0.0.0-2026-08-3104a3fce657c4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

7,823
hydraory0.64.02 of 2See more

hydra ory 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,950
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

1,344
proxmox-csi-pluginproxmox-csi0.5.127 of 7See more

proxmox-csi-plugin proxmox-csi 0.5.12

7 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-csi-controller:v0.20.095ef74cce03e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

3,558
victoria-metrics-singlevictoriametricsVerified publisher0.48.01 of 1See more

victoria-metrics-single victoriametrics 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
victoriametrics/victoria-metrics:v1.153.05eff7af5341e
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

137
yourlsyourlsOfficialVerified publisher8.10.51 of 2See more

yourls yourls 8.10.5

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9

Open the chart page →

2,619
apisix-ingress-controllerapisix1.4.01 of 2See more

apisix-ingress-controller apisix 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

2,247
volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,833
concourseconcourseVerified publisher20.3.12 of 2See more

concourse concourse 20.3.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
concourse/concourse:8.3.1c9d48dfbf4f9
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

2,201
dynatrace-operatordynatraceVerified publisher1.11.01 of 1See more

dynatrace-operator dynatrace 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.11.05b772cfaad48
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.60.0
1.26.9

Open the chart page →

5,327
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

2,431
oncallgrafana1.16.57 of 12See more

oncall grafana 1.16.5

7 of the 12 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

23,232
k8sgpt-operatork8sgptOfficialVerified publisher0.2.292 of 2See more

k8sgpt-operator k8sgpt 0.2.29

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.2982d0adcce816
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,654
node-feature-discoverynode-feature-discoveryOfficialVerified publisher0.19.01 of 1See more

node-feature-discovery node-feature-discovery 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

480
openprojectopenproject-helm-chartsOfficialVerified publisher13.13.11 of 5See more

openproject openproject-helm-charts 13.13.1

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9

Open the chart page →

21,839
kratosory0.64.01 of 1See more

kratos ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
oryd/kratos:v26.2.02a13bb8d362c
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

1,227
sftpgosftpgoOfficialVerified publisher0.48.01 of 1See more

sftpgo sftpgo 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
golang.org/x/net@v0.57.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

1,664

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
keeper/injector-webhook:0.11.33eb609f3e60c
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
1
keeper/injector-webhook:0.10.0aeb5476b95f0
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.60.0
1.26.9
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
golang.org/x/net@v0.41.0
stdlib@go1.25.9
0.60.0
1.26.9
1
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.13.7
0.60.0
1.26.9
1
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.60.0
1.26.9
1
keptn/distributor:0.8.472e17527a4f9
stdlib@go1.16.2
1.26.9
1
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.2
0.60.0
1.26.9
1
kesque/pulsar-monitor:1.0.8ce85c1e7d613
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.4
0.60.0
1.26.9
1
keyauthoritydh/backend:1.4.10b2519da39b25
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
golang.org/x/net@v0.0.0-20190415100556-4a65cf94b679
stdlib@go1.14.2
0.60.0
1.26.9
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
1
kfirfer/scripts:0.0.2481e5c4e5d70e
stdlib@go1.17.10
1.26.9
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.14
0.60.0
1.26.9
1
khairul169/garage-webui:1.1.017c793551873
stdlib@go1.23.12
1.26.9
1
khaliq/drl-exporter:latest8a7ed75c9aab
stdlib@go1.27.1
1.27.2
1
khaliq/pingme:v0.2.749f96888d2ab
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9
1
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.7
0.60.0
1.26.9
1
klutchell/dnscrypt-proxy:2.1.18a98e8d13314f
golang.org/x/net@v0.57.0
stdlib@go1.25.12
0.60.0
1.26.9
1
komodorio/helm-dashboard:2.1.3258a9044e658
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
1
komodorio/komoplane:0.2.19678d02c3f2e
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.60.0
1.26.9
1
kong/gateway-operator:1.603510967482b
golang.org/x/net@v0.39.0
stdlib@go1.24.5
0.60.0
1.26.9
1
kong/kong-operator:2.3.2814eaeee4cc8
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18
0.60.0
1.26.9
1
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.5
0.60.0
1.26.9
1
kong/kubernetes-ingress-controller:3.1999213b98257
golang.org/x/net@v0.23.0
stdlib@go1.21.9
0.60.0
1.26.9
1
kong/kuma-cp:2.14.5a154795691d1
golang.org/x/net@v0.58.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
1
kong/kumactl:2.14.58191df5c7019
golang.org/x/net@v0.58.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
1
kronosorg/kronos-core:v0.4.0301da21c59a5
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
1
krontechnology/aapm-sidecar-injector:1.2.18b42fad987b3
golang.org/x/net@v0.57.0
stdlib@go1.25.13
0.60.0
1.26.9
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.60.0
1.26.9
1
kserve/kserve-controller:v0.10.022ff858b57c1
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.60.0
1.26.9
1
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/net@v0.0.0-20211205041911-012df41ee64c
stdlib@go1.17.7
0.60.0
1.26.9
1
kubearmor/kubearmor:stablea08141311045
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
kubearmor/kubearmor-controller:latest43674bb4806f
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
kubearmor/kubearmor-operator:v1.7.5f5d21795c0d7
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
kubearmor/kubearmor-relay-server:latestf82b9c97e97d
golang.org/x/net@v0.53.0
stdlib@go1.25.14
0.60.0
1.26.9
1
kubearmor/sidekick:latestb7b92a447f15
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9
1
kubebb/capsule-ce:v0.1.2-20221122a3dba2a95cef
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.18.8
0.60.0
1.26.9
1
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
1
kubebb/cert-manager-controller:v1.8.020509de4b399
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
1
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
1
kubebb/core:v0.1.62b9e7f451d6b
golang.org/x/net@v0.14.0
stdlib@go1.20.10
0.60.0
1.26.9
1
kubebb/core:lateste366c34a9b8d
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9
1
kubebb/iam-controller:v0.2.0-202401288ffbfa2d67e9
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.20.7
0.60.0
1.26.9
1
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.13
0.60.0
1.26.9
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.60.0
1.26.9
1
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18
0.60.0
1.26.9
1
kubebb/mesh-operator:v5.7.0163ebbfc7a82
golang.org/x/net@v0.7.0
stdlib@go1.18.4
0.60.0
1.26.9
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.17.8
0.60.0
1.26.9
1
kubebb/resource-viewer:v0.2.065bb40b353db
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.7
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.