StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
DEBIAN-CVE-2026-78663GO-2026-6612CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3x
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

13,777
aws-cloudwatch-metricsaws0.0.111 of 1See more

aws-cloudwatch-metrics aws 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

2,163
zabbixcetic3.1.33 of 5See more

zabbix cetic 3.1.3

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:14c2427de38f99
stdlib@go1.24.6
1.26.9
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.1
0.60.0
1.26.9
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
stdlib@go1.18.1
1.26.9

Open the chart page →

37,373
chatwootchatwootVerified publisher2.0.272 of 3See more

chatwoot chatwoot 2.0.27

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.26.9
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
stdlib@go1.16.7
1.26.9

Open the chart page →

8,728
plugin-barman-cloudcloudnative-pgVerified publisher0.8.11 of 1See more

plugin-barman-cloud cloudnative-pg 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/plugin-barman-cloud:v0.15.1c75acad19a36
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

124
csi-driver-smbcsi-driver-smbVerified publisher1.20.35 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

4,483
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

6,231
flux-operatorflux-operator0.61.01 of 1See more

flux-operator flux-operator 0.61.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/controlplaneio-fluxcd/flux-operator:v0.61.071041d9fff7f
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

135
gadgetgadgetOfficialVerified publisher0.56.11 of 1See more

gadget gadget 0.56.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/inspektor-gadget/inspektor-gadget:v0.56.1d1c34335183b
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

220
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.26.9

Open the chart page →

9,008
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
stdlib@go1.19.8
1.26.9

Open the chart page →

7,558
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
google/cloud-sdk:alpineef78619c8239
stdlib@go1.26.6
1.26.9

Open the chart page →

8,956
hpe-csi-driverhpe-storageVerified publisher3.3.013 of 14See more

hpe-csi-driver hpe-storage 3.3.0

13 of the 14 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/hpestorage/alletra-9000-primera-and-3par-csp:v3.3.0046215e41416
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/alletrastoragemp-b10000-nfs-csp:v1.3.0efaca660f9f0
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/alletrastoragemp-x10000-nfs-csp:v1.1.0043bb2ddb642
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/csi-driver:v3.3.0e58e22427b38
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/csi-extensions:v1.3.0df65cea35805
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-group-provisioner:v1.1.09ba017780f80
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-group-snapshotter:v1.1.0b26660528928
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/hpestorage/volume-mutator:v1.4.03890d0b3aa89
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

4,179
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

3,042
cloudflaredkubitodevVerified publisher1.7.91 of 1See more

cloudflared kubitodev 1.7.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,968
trident-operatornetapp-tridentVerified publisher100.2606.21 of 1See more

trident-operator netapp-trident 100.2606.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
netapp/trident-operator:26.06.24cef5a737bcf
golang.org/x/net@v0.59.0
0.60.0

Open the chart page →

39
ngrok-operatorngrokOfficialVerified publisher0.24.02 of 2See more

ngrok-operator ngrok 0.24.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
ngrok/ngrok-operator:0.22.0db8e6fecc52c
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

444
openbaoopenbaoVerified publisher0.30.12 of 2See more

openbao openbao 0.30.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:1.7.2ae3d307658b7
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
quay.io/openbao/openbao:2.7.071156a1c6623
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,708
prometheus-snmp-exporterprometheus-communityOfficialVerified publisher9.18.11 of 1See more

prometheus-snmp-exporter prometheus-community 9.18.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

857
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9

Open the chart page →

6,887
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.7
0.60.0
1.26.9

Open the chart page →

3,104
trivytrivy-operator0.27.01 of 1See more

trivy trivy-operator 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
aquasec/trivy:0.75.0af6acf9a6b85
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

235
zotzot0.1.1281 of 1See more

zot zot 0.1.128

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/project-zot/zot:v2.1.2296cda11459ce
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

495
aws-ebs-csi-driveraws-ebs-csi-driver2.66.15 of 6See more

aws-ebs-csi-driver aws-ebs-csi-driver 2.66.1

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/csi-components/csi-attacher:v4.12.0-eksbuild.9f8db68b6e3b3
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-node-driver-registrar:v2.17.0-eksbuild.89be2a65725f7
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-provisioner:v6.3.0-eksbuild.82fdf13756ccb
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/csi-components/csi-resizer:v2.2.1-eksbuild.7a2895cc5206d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.66.13ae75c8b0fdc
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

632
daskdask2024.1.11 of 2See more

dask dask 2024.1.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

14,274
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
golang.org/x/net@v0.35.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

3,751
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.60.0
1.26.9

Open the chart page →

9,156
netbirdjaconiVerified publisher0.15.14 of 4See more

netbird jaconi 0.15.1

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/golang:lateste0174e51e812
stdlib@go1.27.1
1.27.2
netbirdio/management:0.45.10c9994b393ea
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
netbirdio/relay:0.45.1872e3add0e1e
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
netbirdio/signal:0.45.146ce5a45538f
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9

Open the chart page →

10,263
k8upk8upVerified publisher4.10.01 of 1See more

k8up k8up 4.10.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.16.029458113b8b6
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,016
kube-starrockskube-starrocksOfficialVerified publisher1.11.71 of 1See more

kube-starrocks kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/net@v0.17.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

1,015
linkerd-jaegerlinkerd2Verified publisher30.12.112 of 4See more

linkerd-jaeger linkerd2 30.12.11

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.6
0.60.0
1.26.9
otel/opentelemetry-collector:0.59.0ee9da0b08d83
golang.org/x/net@v0.0.0-20220809184613-07c6da5e1ced
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

6,215
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest801a3dff7f6a
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:nojsonv2
0.60.0
1.27.2

Open the chart page →

2,177
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

15,239
renovate-operatormogenius6.4.02 of 2See more

renovate-operator mogenius 6.4.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/mogenius/renovate-operator:6.4.0e8f023764de4
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
registry.k8s.io/kubectl:v1.37.1b7cab618e281
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

282
argocdnicklasfrahm-argocdVerified publisher0.3.02 of 2See more

argocd nicklasfrahm-argocd 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.26.9
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
golang.org/x/net@v0.40.0
stdlib@go1.22.7
0.60.0
1.26.9

Open the chart page →

7,168
oneuptimeoneuptimeOfficialVerified publisher14.0.351See more

oneuptime oneuptime 14.0.35

1 container image this version deploys carries CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:latest74935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

—
open-feature-operatoropen-feature-operatorOfficialVerified publisher0.9.31 of 1See more

open-feature-operator open-feature-operator 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/open-feature/open-feature-operator:v0.9.3b37a442c0497
golang.org/x/net@v0.52.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

315
postgres-operatorpostgres-operator2.0.31 of 1See more

postgres-operator postgres-operator 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v2.0.32d3a7ca3950f
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

205
telepresence-osstelepresence-ossOfficialVerified publisher2.32.21 of 2See more

telepresence-oss telepresence-oss 2.32.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/telepresenceio/tel2:2.32.296f5a0f413b1
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

924
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
stdlib@go1.17.1
1.26.9

Open the chart page →

7,334
karmawiremindVerified publisher2.13.11 of 1See more

karma wiremind 2.13.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/prymitive/karma:v0.13190a10c5c6793
stdlib@go1.26.3
1.26.9

Open the chart page →

310
yugabyteyugabyteVerified publisher2026.1.21 of 1See more

yugabyte yugabyte 2026.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
yugabytedb/yugabyte:2026.1.2.0-b137b6dba322c734
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

359
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

1,676
autheliaautheliaOfficialVerified publisher0.11.221 of 1See more

authelia authelia 0.11.22

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/authelia/authelia:4.39.248f428b06bb07
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

8,089
camel-kcamel-kVerified publisher2.11.01 of 1See more

camel-k camel-k 2.11.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/camel-k:2.11.0d173e7efe258
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,782
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

6,661
falcosidekickfalcosecurity0.14.01 of 1See more

falcosidekick falcosecurity 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
falcosecurity/falcosidekick:2.32.01976da721518
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

2,275
flagsmithflagsmithOfficialVerified publisher0.83.01 of 4See more

flagsmith flagsmith 0.83.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,414
gitlab-operatorgitlabVerified publisher3.4.11 of 1See more

gitlab-operator gitlab 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:3.4.196efaea0d3bb
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

136

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
keeper/injector-webhook:0.11.33eb609f3e60c
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
1
keeper/injector-webhook:0.10.0aeb5476b95f0
golang.org/x/net@v0.47.0
stdlib@go1.25.6
0.60.0
1.26.9
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
golang.org/x/net@v0.41.0
stdlib@go1.25.9
0.60.0
1.26.9
1
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.13.7
0.60.0
1.26.9
1
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.60.0
1.26.9
1
keptn/distributor:0.8.472e17527a4f9
stdlib@go1.16.2
1.26.9
1
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.2
0.60.0
1.26.9
1
kesque/pulsar-monitor:1.0.8ce85c1e7d613
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.4
0.60.0
1.26.9
1
keyauthoritydh/backend:1.4.10b2519da39b25
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
golang.org/x/net@v0.0.0-20190415100556-4a65cf94b679
stdlib@go1.14.2
0.60.0
1.26.9
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
1
kfirfer/scripts:0.0.2481e5c4e5d70e
stdlib@go1.17.10
1.26.9
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.14
0.60.0
1.26.9
1
khairul169/garage-webui:1.1.017c793551873
stdlib@go1.23.12
1.26.9
1
khaliq/drl-exporter:latest8a7ed75c9aab
stdlib@go1.27.1
1.27.2
1
khaliq/pingme:v0.2.749f96888d2ab
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9
1
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.7
0.60.0
1.26.9
1
klutchell/dnscrypt-proxy:2.1.18a98e8d13314f
golang.org/x/net@v0.57.0
stdlib@go1.25.12
0.60.0
1.26.9
1
komodorio/helm-dashboard:2.1.3258a9044e658
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
1
komodorio/komoplane:0.2.19678d02c3f2e
golang.org/x/net@v0.47.0
stdlib@go1.26.2
0.60.0
1.26.9
1
kong/gateway-operator:1.603510967482b
golang.org/x/net@v0.39.0
stdlib@go1.24.5
0.60.0
1.26.9
1
kong/kong-operator:2.3.2814eaeee4cc8
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18
0.60.0
1.26.9
1
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.5
0.60.0
1.26.9
1
kong/kubernetes-ingress-controller:3.1999213b98257
golang.org/x/net@v0.23.0
stdlib@go1.21.9
0.60.0
1.26.9
1
kong/kuma-cp:2.14.5a154795691d1
golang.org/x/net@v0.58.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
1
kong/kumactl:2.14.58191df5c7019
golang.org/x/net@v0.58.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2
1
kronosorg/kronos-core:v0.4.0301da21c59a5
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
1
krontechnology/aapm-sidecar-injector:1.2.18b42fad987b3
golang.org/x/net@v0.57.0
stdlib@go1.25.13
0.60.0
1.26.9
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.60.0
1.26.9
1
kserve/kserve-controller:v0.10.022ff858b57c1
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.60.0
1.26.9
1
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/net@v0.0.0-20211205041911-012df41ee64c
stdlib@go1.17.7
0.60.0
1.26.9
1
kubearmor/kubearmor:stablea08141311045
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
kubearmor/kubearmor-controller:latest43674bb4806f
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
kubearmor/kubearmor-operator:v1.7.5f5d21795c0d7
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
kubearmor/kubearmor-relay-server:latestf82b9c97e97d
golang.org/x/net@v0.53.0
stdlib@go1.25.14
0.60.0
1.26.9
1
kubearmor/sidekick:latestb7b92a447f15
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9
1
kubebb/capsule-ce:v0.1.2-20221122a3dba2a95cef
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.18.8
0.60.0
1.26.9
1
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
1
kubebb/cert-manager-controller:v1.8.020509de4b399
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
1
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
1
kubebb/core:v0.1.62b9e7f451d6b
golang.org/x/net@v0.14.0
stdlib@go1.20.10
0.60.0
1.26.9
1
kubebb/core:lateste366c34a9b8d
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9
1
kubebb/iam-controller:v0.2.0-202401288ffbfa2d67e9
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.20.7
0.60.0
1.26.9
1
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.13
0.60.0
1.26.9
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.60.0
1.26.9
1
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18
0.60.0
1.26.9
1
kubebb/mesh-operator:v5.7.0163ebbfc7a82
golang.org/x/net@v0.7.0
stdlib@go1.18.4
0.60.0
1.26.9
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.17.8
0.60.0
1.26.9
1
kubebb/resource-viewer:v0.2.065bb40b353db
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.7
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.