StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
toolhive-operatortoolhive-operator0.51.41 of 1See more

toolhive-operator toolhive-operator 0.51.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/stacklok/toolhive/operator:v0.51.401d8f1c9e432
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
tor-snowflake-proxytor-snowflake-proxyVerified publisher1.2.01 of 1See more

tor-snowflake-proxy tor-snowflake-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
thetorproject/snowflake-proxy:v2.11.01ddc5069d354
golang.org/x/net@v0.35.0
stdlib@go1.23.7
0.60.0
1.26.9

Open the chart page →

1,185
spa-reloadertoucanVerified publisher0.1.01 of 1See more

spa-reloader toucan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

3,385
traefikeetraefikOfficialVerified publisher4.2.111 of 2See more

traefikee traefik 4.2.11

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
traefik/traefikee:v2.12.116259bdda7aa6
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

478
traefik-hubtraefikOfficialVerified publisher4.2.01 of 1See more

traefik-hub traefik 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

3,823
transfergwtransfergwVerified publisher1.0.01 of 1See more

transfergw transfergw 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
thev1ndu/transfergw:latesta07203713933
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

124
starboard-operatortrivy-operator0.10.251 of 1See more

starboard-operator trivy-operator 0.10.25

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.38e0b1c7ddc843
golang.org/x/net@v0.41.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

632
atlantistrozz3.12.111 of 1See more

atlantis trozz 3.12.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.16.145fbaf7e207c
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.14.7
0.60.0
1.26.9

Open the chart page →

6,524
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
golang.org/x/net@v0.26.0
stdlib@go1.22.8
0.60.0
1.26.9

Open the chart page →

4,777
tyk-operatortyk-helm1.5.01 of 1See more

tyk-operator tyk-helm 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
tykio/tyk-operator:v1.5.010f678bfdc27
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

128
boundaryundergridVerified publisher0.1.02 of 3See more

boundary undergrid 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v1.684edcf796267
stdlib@go1.18.1
1.26.9
hashicorp/boundary:0.8.1fb70bd9210ff
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.10
0.60.0
1.26.9

Open the chart page →

6,699
understudyunderstudyVerified publisher0.4.21 of 1See more

understudy understudy 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kylan11/understudy:0.4.24454589d3884
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

154
u-storeunifieVerified publisher1.2.01 of 1See more

u-store unifie 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
stdlib@go1.20.12
1.26.9

Open the chart page →

17,093
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
stdlib@go1.24.4
1.26.9
taigaio/taiga-protected:latestfd4568a97a59
stdlib@go1.24.4
1.26.9

Open the chart page →

10,711
upbot-operatorupbot-operator0.0.202 of 2See more

upbot-operator upbot-operator 0.0.20

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/k8s:1.28.13e5c0b053fed7
golang.org/x/net@v0.12.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/upbothq/upbot-operator:v0.0.20e5da24947c91
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

5,561
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,227
user-manager-serveruser-manager-server1.27.11 of 1See more

user-manager-server user-manager-server 1.27.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/user-manager-server:1.27.1628a14449241
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,181
phonebook-chartusuladamsVerified publisher0.1.51 of 3See more

phonebook-chart usuladams 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

3,975
v2ray-proxyv2ray-proxy0.2.41 of 1See more

v2ray-proxy v2ray-proxy 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
pinclr/v2ray-proxy:latestf37f250b7091
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

2,672
vault-config-operatorvault-config-operator1.0.31 of 1See more

vault-config-operator vault-config-operator 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/redhat-cop/vault-config-operator:v1.0.3f93c876596d4
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

192
vault-gcp-secretsvault-gcp-secrets1.19.51 of 1See more

vault-gcp-secrets vault-gcp-secrets 1.19.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

3,047
vearchvearch3.3.42 of 4See more

vearch vearch 3.3.4

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9
vearch/vearch:3.3.40768af33f9d9
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.60.0
1.26.9

Open the chart page →

6,902
vector-store-manager-servervector-store-manager-server1.8.01 of 1See more

vector-store-manager-server vector-store-manager-server 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/vector-store-manager-server:1.8.0ced619de4c6d
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,116
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

6,158
victoria-traces-clustervictoriametricsVerified publisher0.2.101 of 1See more

victoria-traces-cluster victoriametrics 0.2.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
victoriametrics/victoria-traces:v0.11.09947b14b6b9b
stdlib@go1.26.5
1.26.9

Open the chart page →

197
riveruivirtualrootVerified publisher0.1.31 of 1See more

riverui virtualroot 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/riverqueue/riverui:0.5.32dc54179b25a
golang.org/x/net@v0.23.0
stdlib@go1.23.0
0.60.0
1.26.9

Open the chart page →

1,618
go-egvoid-xmh1.1.13 of 3See more

go-eg void-xmh 1.1.1

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
voidxmh/xmh-auther:v193e42a569ca8
stdlib@go1.16.5
1.26.9
voidxmh/xmh-cacher:v11b7397412320
stdlib@go1.16.5
1.26.9
voidxmh/xmh-ui:v12ff3f2146547
stdlib@go1.16.5
1.26.9

Open the chart page →

10,317
phpipamvquieVerified publisher1.0.31 of 3See more

phpipam vquie 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:10.11.21c33370a599c
stdlib@go1.16.7
1.26.9

Open the chart page →

8,241
vultr-ccmvultrVerified publisher1.3.01 of 1See more

vultr-ccm vultr 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.7
0.60.0
1.26.9

Open the chart page →

4,099
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

10,108
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,783
waardepapieren-registerwaardepapieren-register1.1.01 of 4See more

waardepapieren-register waardepapieren-register 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,311
wachdwachdVerified publisher0.4.371 of 1See more

wachd wachd 0.4.37

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/wachd/wachd:0.4.1805b05c56da94
stdlib@go1.25.10
1.26.9

Open the chart page →

1,565
waldurwaldur-chartsVerified publisher8.1.21 of 3See more

waldur waldur-charts 8.1.2

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

6,085
warpgate-operatorwarpgate-operator0.4.111 of 1See more

warpgate-operator warpgate-operator 0.4.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/thereisnotime/warpgate-operator:0.4.15e3ce6905a7a4
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

132
azure-metrics-exporterwebdevopsVerified publisher1.2.111 of 1See more

azure-metrics-exporter webdevops 1.2.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
webdevops/azure-metrics-exporter:25.12.01d3b453fba99
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

857
webhookrelay-operatorwebhookrelay-operator0.7.01 of 1See more

webhookrelay-operator webhookrelay-operator 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
webhookrelay/webhookrelay-operator:0.8.0afffa826f068
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
webhookswebhooks0.1.51 of 1See more

webhooks webhooks 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
stdlib@go1.20.1
1.26.9

Open the chart page →

2,615
webhook-testerwebhook-testerVerified publisher2.3.01 of 1See more

webhook-tester webhook-tester 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/webhook-tester:2.3.085818267b450
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

501
well-knownwell-knownOfficialVerified publisher1.11.01 of 1See more

well-known well-known 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/stenic/well-known:1.11.0ae85f257a10f
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

572
frpcwener1.0.11 of 1See more

frpc wener 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
wener/frpc:v0.37.0cc9fd4da44c0
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

4,389
frpswener1.0.11 of 1See more

frps wener 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
wener/frps:v0.37.05c92cc9e8597
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

4,389
harborwener1.19.25 of 8See more

harbor wener 1.19.2

5 of the 8 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.2d7b780d23721
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
goharbor/harbor-jobservice:v2.15.2f71a4452a095
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
goharbor/registry-photon:v2.15.2c4ebef61ceb5
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

2,986
prometheus-snmp-exporterwener9.18.11 of 1See more

prometheus-snmp-exporter wener 9.18.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheus/snmp-exporter:v0.30.1e5fd5e8b43ac
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

857
seaweedfswener2.92.01 of 1See more

seaweedfs wener 2.92.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:2.92db095fe8a8d6
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.7
0.60.0
1.26.9

Open the chart page →

3,783
cockroachdbwenerme22.0.41 of 3See more

cockroachdb wenerme 22.0.4

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.10b0fcc6c8147a
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

620
frpswenerme1.0.11 of 1See more

frps wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
wener/frps:v0.37.05c92cc9e8597
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

4,389
ingress-nginxwenerme4.15.12 of 2See more

ingress-nginx wenerme 4.15.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

2,200
kube-prometheus-stackwenerme92.3.05 of 6See more

kube-prometheus-stack wenerme 92.3.0

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,050
natswenerme2.15.03 of 3See more

nats wenerme 2.15.0

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/nats:2.15.0-alpineac8f88a6494b
stdlib@go1.27.1
1.27.2
natsio/nats-box:0.19.7ffce8bd10338
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.26.9

Open the chart page →

2,805

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/openshift/origin-cli:latest486bf8e8f5b5
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.60.0
1.26.9
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
4
quay.io/prometheus/blackbox-exporter:latest:v0.29.09613f2884689
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
4
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9
4
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
4
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.60.0
1.26.9
4
quay.io/prometheus/prometheus:latest:v3.14.05ce7540c3c00
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
4
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
4
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.60.0
1.26.9
4
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9
4
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-attacher:v4.13.0d1a26170efed
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.18.0b7fefd08651f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
4
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.20.6
0.60.0
1.26.9
3
alpine/git:latesta4bb51f1a355
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
3
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
stdlib@go1.14.12
0.60.0
1.26.9
3
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.60.0
1.26.9
3
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9
3
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.17.10
0.60.0
1.26.9
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.60.0
1.26.9
3
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.26.9
3
bitnami/sealed-secrets-controller:0.40.0b1ff382e9300
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
3
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
3
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
stdlib@go1.19.2
0.60.0
1.26.9
3
cloudflare/cloudflared:2026.9.3:latest072c067d25cc
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
3
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.19.13
0.60.0
1.26.9
3
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
3
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.17.3
0.60.0
1.26.9
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
stdlib@go1.26.5
1.26.9
3
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.