StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-7r9c-ff6c-hxjjCGA-gghc-78jw-f5q2CGA-rp37-mxv6-g5fjDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-vqxj-4gp6-23v9, CGA-w84h-9v6p-pf3x, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
mysqlhelmforgeVerified publisher2.0.41 of 1See more

mysql helmforge 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:26.7.0ade067ae2fb1
stdlib@go1.24.6
1.26.9

Open the chart page →

797
netboxhelmforgeVerified publisher2.0.32 of 4See more

netbox helmforge 2.0.3

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
stdlib@go1.26.5
1.26.9

Open the chart page →

4,906
nextcloudhelmforgeVerified publisher2.0.01 of 3See more

nextcloud helmforge 2.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

7,688
ntfyhelmforgeVerified publisher1.2.21 of 1See more

ntfy helmforge 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.28.06ef4b819f722
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

401
oauth2-proxyhelmforgeVerified publisher1.0.61 of 1See more

oauth2-proxy helmforge 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.15.4b1b2021fe8f4
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

272
olivetinhelmforgeVerified publisher1.2.21 of 2See more

olivetin helmforge 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jamesread/olivetin:3000.20.0f3066e207efd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

731
opencuthelmforgeVerified publisher1.1.111 of 5See more

opencut helmforge 1.1.11

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

3,805
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
stdlib@go1.20.7
1.26.9

Open the chart page →

3,745
pimcorehelmforgeVerified publisher2.0.42 of 6See more

pimcore helmforge 2.0.4

2 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dunglas/mercure:v0.24.2916834e49961
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
library/mariadb:13.0.2f1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

3,420
pocket-idhelmforgeVerified publisher1.0.01 of 2See more

pocket-id helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/pocket-id/pocket-id:v2.14.001540977dcf4
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

705
reactive-resumehelmforgeVerified publisher1.0.02 of 4See more

reactive-resume helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
stdlib@go1.26.4
1.26.9

Open the chart page →

4,056
ryothelmforgeVerified publisher1.0.02 of 2See more

ryot helmforge 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
golang.org/x/net@v0.33.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

7,418
siyuanhelmforgeVerified publisher1.0.11 of 1See more

siyuan helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
b3log/siyuan:v3.8.5d740a1d3ed6b
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

400
strapihelmforgeVerified publisher2.3.151 of 3See more

strapi helmforge 2.3.15

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

3,010
strava-statisticshelmforgeVerified publisher1.1.161 of 2See more

strava-statistics helmforge 1.1.16

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
robiningelbrecht/strava-statistics:v5.0.040842cdfd616
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,221
supersethelmforgeVerified publisher1.3.82 of 5See more

superset helmforge 1.3.8

2 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
helmforge/kubectl:1.35.3c3f97e954c47
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

6,458
twentyhelmforgeVerified publisher1.0.41 of 5See more

twenty helmforge 1.0.4

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

3,199
wallabaghelmforgeVerified publisher1.3.82 of 3See more

wallabag helmforge 1.3.8

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.26.9

Open the chart page →

3,350
webodmhelmforgeVerified publisher1.0.01 of 4See more

webodm helmforge 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
postgis/postgis:17-3.501a6a70e41e6
stdlib@go1.18.2
1.26.9

Open the chart page →

22,597
zookeeperhelmforgeVerified publisher1.0.21 of 1See more

zookeeper helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5e6b279d01350
stdlib@go1.18.1
1.26.9

Open the chart page →

3,902
harborhelm-harborVerified publisher2.3.75 of 8See more

harbor helm-harbor 2.3.7

5 of the 8 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.47d2ba5304a72
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
goharbor/harbor-jobservice:v2.15.4f143578ef30e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
goharbor/harbor-registryctl:v2.15.430bd1ace4e3b
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
goharbor/registry-photon:v2.15.4dc0cb388a644
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
goharbor/trivy-adapter-photon:v2.15.4813ca81b4a4e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

1,577
openaevhelm-openbasVerified publisher2.0.121 of 7See more

openaev helm-openbas 2.0.12

1 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
golang.org/x/net@v0.14.0
stdlib@go1.19.8
no fix listed
0.60.0
1.26.9

Open the chart page →

21,594
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
golang.org/x/net@v0.14.0
stdlib@go1.19.8
no fix listed
0.60.0
1.26.9

Open the chart page →

26,397
release-cleanerhelm-release-cleanerVerified publisher1.0.01 of 1See more

release-cleaner helm-release-cleaner 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/helm:4.1.0905a068da431
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

2,554
pageshelm-repo1.0.01 of 3See more

pages helm-repo 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,310
steampipehelm-steampipeVerified publisher2.4.11 of 1See more

steampipe helm-steampipe 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

3,897
svacerhelm-svacer0.6.01 of 1See more

svacer helm-svacer 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ispras/svacer:11-2-042aa9fa9f189
golang.org/x/net@v0.37.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

7,182
hermes-operatorhermes-agent-operatorVerified publisher0.2.01 of 1See more

hermes-operator hermes-agent-operator 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/paperclipinc/hermes-operator:v0.2.07a491ec9b0ff
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

231
postgres-backup-localheywood8-helm-chartsVerified publisher0.1.131 of 1See more

postgres-backup-local heywood8-helm-charts 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
stdlib@go1.16
1.26.9

Open the chart page →

3,475
kubefaashfoxy-helm-charts0.1.63 of 4See more

kubefaas hfoxy-helm-charts 0.1.6

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hfoxy4/kubefaas-builder:main-2afc7570bfb65aaad93
golang.org/x/net@v0.26.0
stdlib@go1.21.11
0.60.0
1.26.9
hfoxy4/kubefaas-controller:main-2afc7570761fe08f14c
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
library/docker:27.0.1-dind2416984b43dd
golang.org/x/net@v0.23.0
stdlib@go1.21.11
0.60.0
1.26.9

Open the chart page →

7,965
tapo-prometheus-exporterhfoxy-helm-charts0.1.111 of 1See more

tapo-prometheus-exporter hfoxy-helm-charts 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hfoxy4/tapo-prometheus-exporter:v0.1.117e385eef6fc7
stdlib@go1.21.3
1.26.9

Open the chart page →

1,427
goshimmerhiveroad0.2.141 of 1See more

goshimmer hiveroad 0.2.14

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
iotaledger/goshimmer:v0.8.6b02a8f77474f
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,814
cratedb-adapterhmdmph0.1.01 of 1See more

cratedb-adapter hmdmph 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.60.0
1.26.9

Open the chart page →

4,117
printserverhmediadeVerified publisher1.0.22 of 4See more

printserver hmediade 1.0.2

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

12,885
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.60.0
1.26.9

Open the chart page →

3,311
holmesholmes0.1.01 of 1See more

holmes holmes 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/operator-framework/olm:master39081bf0c4a9
golang.org/x/net@v0.7.0
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

2,881
homeboxhomebox-helmVerified publisher0.3.01 of 2See more

homebox homebox-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
sysadminsmedia/homebox:0.26.056e880b62309
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,151
homecharthomechartVerified publisher1.0.11 of 1See more

homechart homechart 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/candiddev/homechart:latestb79b17e57af8
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

209
adguardhomeenterpriseinc0.12.01 of 1See more

adguard homeenterpriseinc 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.0-b.5a9668737b1d6
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.6
0.60.0
1.26.9

Open the chart page →

3,707
cert-managerhomeenterpriseinc1.10.13 of 3See more

cert-manager homeenterpriseinc 1.10.1

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

7,277
homeassistanthomeenterpriseinc0.3.01 of 1See more

homeassistant homeenterpriseinc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2022.3.5565751f33794
stdlib@go1.17.1
1.26.9

Open the chart page →

9,054
photoprismhomeenterpriseinc0.8.01 of 1See more

photoprism homeenterpriseinc 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
photoprism/photoprism:20211010f4687352985a
golang.org/x/net@v0.0.0-20210929193557-e81a3d93ecf6
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

3,224
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
stdlib@go1.19.8
1.26.9

Open the chart page →

18,551
honeydipperhoneydipperVerified publisher0.1.111 of 2See more

honeydipper honeydipper 0.1.11

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/redis:5fc5ecd863862
stdlib@go1.16.7
1.26.9

Open the chart page →

2,847
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
golang.org/x/net@v0.17.0
stdlib@go1.21.10
0.60.0
1.26.9

Open the chart page →

4,627
universal-web-apphotrungnhanVerified publisher0.2.61 of 2See more

universal-web-app hotrungnhan 0.2.6

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
traefik/whoami:latestc4717a8d1f01
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

350
hoverflyhoverflyVerified publisher0.2.01 of 1See more

hoverfly hoverfly 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
spectolabs/hoverfly:v1.12.13250986d58ed4
golang.org/x/net@v0.56.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

289
paperlesshpVerified publisher0.1.23 of 5See more

paperless hp 0.1.2

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.60.0
1.26.9
gotenberg/gotenberg:8.3467097317623a
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.26.9

Open the chart page →

35,136
wallabaghpVerified publisher0.1.71 of 1See more

wallabag hp 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.26.9

Open the chart page →

1,548
hammerspace-csihscsi1.2.86 of 6See more

hammerspace-csi hscsi 1.2.8

6 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

7,746

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/openshift/origin-cli:latest486bf8e8f5b5
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.60.0
1.26.9
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
4
quay.io/prometheus/blackbox-exporter:latest:v0.29.09613f2884689
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
4
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9
4
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
4
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.60.0
1.26.9
4
quay.io/prometheus/prometheus:latest:v3.14.05ce7540c3c00
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
4
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
4
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.60.0
1.26.9
4
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9
4
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-attacher:v4.13.0d1a26170efed
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.18.0b7fefd08651f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
4
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.20.6
0.60.0
1.26.9
3
alpine/git:latesta4bb51f1a355
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
3
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
stdlib@go1.14.12
0.60.0
1.26.9
3
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.60.0
1.26.9
3
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9
3
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.17.10
0.60.0
1.26.9
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.60.0
1.26.9
3
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.26.9
3
bitnami/sealed-secrets-controller:0.40.0b1ff382e9300
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
3
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
3
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
stdlib@go1.19.2
0.60.0
1.26.9
3
cloudflare/cloudflared:2026.9.3:latest072c067d25cc
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
3
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.19.13
0.60.0
1.26.9
3
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
3
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.17.3
0.60.0
1.26.9
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
stdlib@go1.26.5
1.26.9
3
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.