StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-7r9c-ff6c-hxjjCGA-gghc-78jw-f5q2CGA-rp37-mxv6-g5fjDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-vqxj-4gp6-23v9, CGA-w84h-9v6p-pf3x, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
intel-gpu-resource-driverintelVerified publisher0.7.01 of 1See more

intel-gpu-resource-driver intel 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,088
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.6
0.60.0
1.26.9

Open the chart page →

3,434
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

5,075
amazon-eks-pod-identity-webhookjkroepkeVerified publisher2.6.51 of 1See more

amazon-eks-pod-identity-webhook jkroepke 2.6.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/eks/amazon-eks-pod-identity-webhook:v0.6.173071570e8e8c
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

469
k8s-ephemeral-storage-metricsk8s-ephemeral-storage-metrics1.21.31 of 1See more

k8s-ephemeral-storage-metrics k8s-ephemeral-storage-metrics 1.21.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/jmcgrath207/k8s-ephemeral-storage-metrics:1.21.38297aa4a9278
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

309
rustrial-k8s-gitops-secrets-controllerk8s-gitops-secrets0.6.01 of 1See more

rustrial-k8s-gitops-secrets-controller k8s-gitops-secrets 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rustrial/k8s-gitops-secrets-controller:0.6.093326a322a01
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

340
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.26.9

Open the chart page →

6,435
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

5,800
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.26.9

Open the chart page →

8,455
k8s-sftp-gcsk8s-sftp-gcsVerified publisher0.1.41 of 1See more

k8s-sftp-gcs k8s-sftp-gcs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.26.9

Open the chart page →

2,631
k8statusk8statusOfficialVerified publisher0.17.01 of 1See more

k8status k8status 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/stenic/k8status:0.17.093298e03089e
golang.org/x/net@v0.26.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,213
kanister-operatorkanister0.118.01 of 1See more

kanister-operator kanister 0.118.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
golang.org/x/net@v0.41.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

1,687
kiali-operatorkiali2.33.01 of 1See more

kiali-operator kiali 2.33.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kiali/kiali-operator:v2.33.0035995403eed
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,719
kividb-operator-chartkividb-operatorVerified publisher0.4.02 of 2See more

kividb-operator-chart kividb-operator 0.4.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kividbio/kividb-operator:0.4.0a2395d6f47b7
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/kividbio/kividb-operator-gui:0.4.0276352c04b9c
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

402
mysqldumpkokuwa7.0.31 of 1See more

mysqldump kokuwa 7.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
stdlib@go1.26.1
1.26.9

Open the chart page →

1,197
kong-operatorkongOfficialVerified publisher1.4.11 of 1See more

kong-operator kong 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kong/kong-operator:2.3.2814eaeee4cc8
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

222
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.26.9

Open the chart page →

3,486
kuadrant-operatorkuadrantOfficialVerified publisher1.5.34 of 4See more

kuadrant-operator kuadrant 1.5.3

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kuadrant/authorino-operator:v0.25.395a0670bffe6
golang.org/x/net@v0.55.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/kuadrant/dns-operator:v0.17.2da9ff8211856
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/kuadrant/kuadrant-operator:v1.5.318ad777aeb7a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/kuadrant/limitador-operator:v0.18.49a9c533e58bb
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

1,214
kubearmorkubearmor1.7.53 of 4See more

kubearmor kubearmor 1.7.5

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubearmor/kubearmor:stablea08141311045
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
kubearmor/kubearmor-controller:latest43674bb4806f
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
kubearmor/kubearmor-relay-server:latestf82b9c97e97d
golang.org/x/net@v0.53.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

2,262
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
neosu/kubebadges:v0.0.5256530d8e5c6
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

2,389
pyroscopekubeblocksVerified publisher0.2.921 of 1See more

pyroscope kubeblocks 0.2.92

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

2,415
kubepatternkubepattern0.0.51 of 1See more

kubepattern kubepattern 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubepattern/kubepattern:0.0.50762baa6d9b0
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

621
kuberay-operatorkuberay-operator1.7.11 of 1See more

kuberay-operator kuberay-operator 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kuberay/operator:v1.7.1e69b9cde8f1d
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

633
skywalkingkubesphere-testVerified publisher3.1.02 of 4See more

skywalking kubesphere-test 3.1.0

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.60.0
1.26.9
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.60.0
1.26.9

Open the chart page →

20,774
kubeviouskubevious1.2.23 of 7See more

kubevious kubevious 1.2.2

3 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubevious/ui:1.2.16233e84bdd59
golang.org/x/net@v0.0.0-20220812165438-1d4ff48094d1
stdlib@go1.19.1
0.60.0
1.26.9
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.26.9
redislabs/redisearch:2.4.1433561794c5c8
stdlib@go1.16.7
1.26.9

Open the chart page →

18,023
kubevpnkubevpn-charts2.11.91 of 1See more

kubevpn kubevpn-charts 2.11.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubenetworks/kubevpn:v2.11.93feb9da85270
golang.org/x/net@v0.52.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,116
kubewallkubewallVerified publisher0.0.231 of 1See more

kubewall kubewall 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubewall/kubewall:0.0.23d9a03cfb557b
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

473
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.05 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs-webhook:latestc1f19557bdcb
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

63,069
prometheus-pingmesh-exporterkubservice-chartsVerified publisher1.1.11 of 1See more

prometheus-pingmesh-exporter kubservice-charts 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:latest355fa4be8e97
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.60.0
1.26.9

Open the chart page →

1,399
karporkusionstackVerified publisher0.7.62 of 3See more

karpor kusionstack 0.7.6

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/net@v0.19.0
stdlib@go1.22.12
0.60.0
1.26.9
quay.io/coreos/etcd:v3.5.11842975891182
golang.org/x/net@v0.17.0
stdlib@go1.20.12
0.60.0
1.26.9

Open the chart page →

4,621
kwokkwokOfficialVerified publisher0.3.01 of 1See more

kwok kwok 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
golang.org/x/net@v0.51.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

1,150
machinarislib42Verified publisher0.2.01 of 1See more

machinaris lib42 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/guydavis/machinaris:test50a71a30f18e
stdlib@go1.26.5
1.26.9

Open the chart page →

39,695
litellm-operatorlitellm-operatorVerified publisher1.1.21 of 1See more

litellm-operator litellm-operator 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/bbdsoftware/litellm-operator:1.1.2167a51113d90
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

642
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.60.0
1.26.9

Open the chart page →

4,615
vcluster-k8sloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-k8s loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.60.0
1.26.9
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

8,347
vcluster-platformloftVerified publisher4.12.21 of 1See more

vcluster-platform loft 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-platform:4.12.271d869f989e9
golang.org/x/net@v0.52.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,180
logging-operatorlogging-operator6.9.01 of 1See more

logging-operator logging-operator 6.9.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/logging-operator:6.9.0527033b7032b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

201
lumigo-operatorlumigo-operatorOfficialVerified publisher69.0.06 of 8See more

lumigo-operator lumigo-operator 69.0.0

6 of the 8 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/opentelemetry-operator/target-allocator:0.124.08936271cf56a
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9
public.ecr.aws/lumigo/lumigo-kubernetes-operator:69491c39346b19
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
public.ecr.aws/lumigo/lumigo-kubernetes-telemetry-proxy:691d548e59c2c8
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9
public.ecr.aws/lumigo/lumigo-kubernetes-watchdog:696458fcd61e0c
golang.org/x/net@v0.37.0
stdlib@go1.23.12
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

9,844
lxcfs-on-kuberneteslxcfs-on-kubernetes0.2.81 of 2See more

lxcfs-on-kubernetes lxcfs-on-kubernetes 0.2.8

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cndoit18/lxcfs-agent:v0.2.8154741f8596e
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

2,658
mariadbmariadbVerified publisher0.4.01 of 1See more

mariadb mariadb 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:10.117db29378d4fd
stdlib@go1.24.6
1.26.9

Open the chart page →

2,816
marmotmarmotOfficialVerified publisher1.6.02 of 2See more

marmot marmot 1.6.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latest999d5eb28f40
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/marmotdata/marmot:0.11.0cbc560cba46e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

503
mattermost-rtcdmattermostVerified publisher1.4.11 of 1See more

mattermost-rtcd mattermost 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mattermost/rtcd:latesta27058aaa53a
golang.org/x/net@v0.50.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,008
veleromesosphere3.2.51 of 1See more

velero mesosphere 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

2,806
kubecostmesosphere-stable0.37.57 of 9See more

kubecost mesosphere-stable 0.37.5

7 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
grafana/grafana:9.4.71a359d92f40e
golang.org/x/net@v0.4.0
stdlib@go1.20.1
0.60.0
1.26.9
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/thanos/thanos:v0.36.1e542959e1b36
golang.org/x/net@v0.26.0
stdlib@go1.21.13
0.60.0
1.26.9

Open the chart page →

23,289
m8b-stackmetricshubVerified publisher2.1.31 of 4See more

m8b-stack metricshub 2.1.3

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/prometheus:v3.13.36976aa8a60fe
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

336
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,884
helm-ai-kernelmindburn-labsOfficialVerified publisher0.11.12 of 2See more

helm-ai-kernel mindburn-labs 0.11.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/mindburn-labs/helm-ai-kernel:v0.11.10e7a5cd11858
golang.org/x/net@v0.58.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

2,963
mc-routerminecraft-server-chartsVerified publisher1.5.01 of 1See more

mc-router minecraft-server-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
itzg/mc-router:latest64ae69eaa7a6
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

245
mocomoco0.27.01 of 1See more

moco moco 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cybozu-go/moco:0.37.032e7cab1bdd8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

251
mogenius-operatormogeniusOfficial2.30.01 of 2See more

mogenius-operator mogenius 2.30.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/mogenius/mogenius-operator:2.30.051bebfb32413
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

1,142

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
kvalitetsit/myra-cert-manager-webhook:1.2.184ab59a1434e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
kvalitetsit/nsp-prometheus-exporter:1.0.190b397ff954ec
stdlib@go1.15.3
1.26.9
1
kvalitetsit/oauth2-proxy-injector:1.5.00c906908d632
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
1
kvalitetsit/stakit-adapter-alertmanager:0.2.6838db1e90c6b
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
golang.org/x/net@v0.0.0-20180906233101-161cd47e91fd
stdlib@go1.19.3
0.60.0
1.26.9
1
l7mp/stunner-auth-server:1.1.02f8114477ba6
golang.org/x/net@v0.36.0
stdlib@go1.23.8
0.60.0
1.26.9
1
l7mp/stunner-gateway-operator:1.2.10ea40a1d42d5
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
l7mp/stunner-gateway-operator:1.1.0c34f7c931491
golang.org/x/net@v0.36.0
stdlib@go1.23.8
0.60.0
1.26.9
1
l7mp/stunner-gateway-operator-premium:1.2.14383766e66c5
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
l7mp/stunner-gateway-operator-premium:devb2726bf5547d
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
labs64/auditflow9c1bd414fcfb
stdlib@go1.26.7
1.26.9
1
labs64/checkout4009b8251b57
stdlib@go1.26.7
1.26.9
1
labs64/payment-gateway5421f763b53e
stdlib@go1.26.7
1.26.9
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
1
langgenius/dify-api:1.16.1dcefa5f7c47c
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
langgenius/dify-plugin-daemon:main-local4b07ca30ab2a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.60.0
1.26.9
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.60.0
1.26.9
1
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.26.9
1
langgenius/dify-web:1.0.0d64914ff0d6d
stdlib@go1.22.5
1.26.9
1
launchdarkly/ld-relay:8.22.0065f211f5d7c
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
lavr/express-botx:0.42.0-rootlessad6ec93952fc
golang.org/x/net@v0.38.0
stdlib@go1.25.14
0.60.0
1.26.9
1
layer5/meshery:stable-latest78a8be21bef3
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
layer5/meshery-app-mesh:stable-latest77d59943b3d6
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.60.0
1.26.9
1
layer5/meshery-consul:stable-latest25a4cc38abcd
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b297
stdlib@go1.13.1
0.60.0
1.26.9
1
layer5/meshery-istio:stable-latestfde47c141ec6
golang.org/x/net@v0.36.0
stdlib@go1.23.9
0.60.0
1.26.9
1
layer5/meshery-kuma:stable-latest9d25f029a8a2
golang.org/x/net@v0.17.0
stdlib@go1.23.4
0.60.0
1.26.9
1
layer5/meshery-linkerd:stable-latestb99c73bac1f5
golang.org/x/net@v0.19.0
stdlib@go1.23.6
0.60.0
1.26.9
1
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.60.0
1.26.9
1
layer5/meshery-nsm:stable-latestebd6a8faf21f
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.12
0.60.0
1.26.9
1
layer5/meshery-operator:stable-latest6f58a28fe422
golang.org/x/net@v0.33.0
stdlib@go1.23.9
0.60.0
1.26.9
1
layer5/meshery-osm:stable-latestec898e5786c6
golang.org/x/net@v0.5.0
stdlib@go1.19.8
0.60.0
1.26.9
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
golang.org/x/net@v0.9.0
stdlib@go1.19.11
0.60.0
1.26.9
1
lbenicio/kubernetes-dashboard-api:1.14.951d3d30206c8
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.60.0
1.26.9
1
lbenicio/kubernetes-dashboard-auth:1.4.1635eb784c03fa
golang.org/x/net@v0.46.0
stdlib@go1.25.12
0.60.0
1.26.9
1
lbenicio/kubernetes-dashboard-scraper:1.2.69202e96ad403
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.60.0
1.26.9
1
lbenicio/kubernetes-dashboard-web:1.7.142797937bc2a5
golang.org/x/net@v0.46.0
stdlib@go1.25.11
0.60.0
1.26.9
1
leonardomulticloud/svc-vault:v1.0.0e4acd2fbb7b1
stdlib@go1.23.1
1.26.9
1
leonardomulticloud/webhook:v1.0.0d119918900e8
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.