StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-7r9c-ff6c-hxjjCGA-gghc-78jw-f5q2CGA-rp37-mxv6-g5fjDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-vqxj-4gp6-23v9, CGA-w84h-9v6p-pf3x, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
flagsmithflagsmithOfficialVerified publisher0.83.01 of 4See more

flagsmith flagsmith 0.83.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,492
gitlab-operatorgitlabVerified publisher3.4.11 of 1See more

gitlab-operator gitlab 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:3.4.196efaea0d3bb
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

222
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

5,414
beylagrafana1.16.111 of 1See more

beyla grafana 1.16.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/beyla:3.32.03ff0f7cf2bbf
golang.org/x/net@v0.57.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

426
helm-dashboardkomodorVerified publisher2.0.71 of 1See more

helm-dashboard komodor 2.0.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
komodorio/helm-dashboard:2.1.3258a9044e658
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

668
kube-prometheus-stackkube-prometheus-stack-oci92.3.05 of 6See more

kube-prometheus-stack kube-prometheus-stack-oci 92.3.0

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,434
kubescape-operatorkubescape1.40.56 of 6See more

kubescape-operator kubescape 1.40.5

6 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kubescape/http-request:v0.2.234ff502a33423
stdlib@go1.26.7
1.26.9
quay.io/kubescape/kubescape:v4.0.14418fa941ecc0
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/kubescape/kubevuln:v0.3.4309bed2f723ea0
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
golang.org/x/net@v0.56.0
stdlib@go1.25.14
0.60.0
1.26.9
quay.io/kubescape/operator:v0.2.1721ddcd2788e1e
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
quay.io/kubescape/storage:v0.0.3486333d7845589
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

2,414
kube-vipkube-vip0.11.11 of 1See more

kube-vip kube-vip 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kube-vip/kube-vip:v1.2.32fcdbb014a2e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

408
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
stdlib@go1.20.12
1.26.9

Open the chart page →

6,527
linkerd-vizlinkerd2-edgeVerified publisher30.14.11-edge1 of 5See more

linkerd-viz linkerd2-edge 30.14.11-edge

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

2,027
plane-cemakeplaneOfficialVerified publisher1.8.43 of 11See more

plane-ce makeplane 1.8.4

3 of the 11 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.26.9
pgsty/mc:RELEASE.2026-09-16T00-00-00Zcfc83108c3ab
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
pgsty/minio:RELEASE.2026-08-04T00-00-00Zb6bfe7239bfc
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

4,758
milvusmilvus-helm5.0.302 of 4See more

milvus milvus-helm 5.0.30

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.25-r1fededb2f2d63
golang.org/x/net@v0.38.0
stdlib@go1.24.10
0.60.0
1.26.9
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

13,219
mssqlmssqlVerified publisher1.10.31 of 1See more

mssql mssql 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-mssql/mssql:1.10.3f923d842bc47
stdlib@go1.23.1
1.26.9

Open the chart page →

1,069
opa-kube-mgmtopa-kube-mgmtVerified publisher11.0.142 of 2See more

opa-kube-mgmt opa-kube-mgmt 11.0.14

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
openpolicyagent/kube-mgmt:11.0.14758ff3fb4727
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
openpolicyagent/opa:1.19.0852359995443
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,193
redis-operatorot-container-kit0.27.01 of 1See more

redis-operator ot-container-kit 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/opstree/redis-operator:v0.27.025799bf10231
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

291
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.26.9

Open the chart page →

5,652
s3-proxyoxyno-zetaVerified publisher2.28.01 of 1See more

s3-proxy oxyno-zeta 2.28.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
oxynozeta/s3-proxy:5.1.121115040e224
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

425
spirespiffeVerified publisher0.30.37 of 10See more

spire spiffe 0.30.3

7 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/spiffe/oidc-discovery-provider:1.15.3bb95f13c2b4e
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
golang.org/x/net@v0.42.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/spiffe/spire-agent:1.15.341b0dcd8b258
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/spiffe/spire-controller-manager:0.8.019e418e9d7f2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/spiffe/spire-server:1.15.34082f30d3e0d
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

3,897
wireguardwireguardVerified publisher0.32.01 of 3See more

wireguard wireguard 0.32.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-wireguard-mgr:mainc4febc0da1a4
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

413
altinity-clickhouse-operatoraltinity-clickhouse-operator0.27.43 of 3See more

altinity-clickhouse-operator altinity-clickhouse-operator 0.27.4

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.27.4c60c872fedd8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
altinity/metrics-exporter:0.27.4d257a72e6a6a
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.36.36e4fce3c8365
golang.org/x/net@v0.49.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

842
bytebasebytebase1.1.51 of 1See more

bytebase bytebase 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bytebase/bytebase:latest0b3a44dfac3e
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

455
cert-manager-csi-drivercert-managerOfficialVerified publisher0.16.03 of 3See more

cert-manager-csi-driver cert-manager 0.16.0

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-csi-driver:v0.16.09d13db6dc80e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,409
ansible-semaphorecloudhippieVerified publisher15.3.21 of 1See more

ansible-semaphore cloudhippie 15.3.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.19.163707a971a57f
golang.org/x/net@v0.36.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,847
etcdcloudpirates-etcdVerified publisher0.8.91 of 1See more

etcd cloudpirates-etcd 0.8.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gcr.io/etcd-development/etcd:v3.7.27c6c239825d0
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

238
rabbitmq-cluster-operatorcloudpirates-rabbitmq-cluster-operatorVerified publisher0.6.192 of 2See more

rabbitmq-cluster-operator cloudpirates-rabbitmq-cluster-operator 0.6.19

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/rabbitmq/cluster-operator:2.23.09236fb4f559b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/rabbitmq/messaging-topology-operator:1.20.3f377d3c3e221
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

419
zookeepercloudpirates-zookeeperVerified publisher0.15.21 of 1See more

zookeeper cloudpirates-zookeeper 0.15.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/zookeeper:3.9.6d0ae1665a1e8
stdlib@go1.18.1
1.26.9

Open the chart page →

3,646
vertical-pod-autoscalercluster-autoscaler0.13.04 of 4See more

vertical-pod-autoscaler cluster-autoscaler 0.13.0

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.8.03d94f53e4c5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.8.0e743e3a7e58a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.8.01d0229e52f90
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

2,099
codefreshcodefresh-onpremOfficialVerified publisher2.12.216 of 42See more

codefresh codefresh-onprem 2.12.21

6 of the 42 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
golang.org/x/net@v0.27.0
stdlib@go1.21.12
0.60.0
1.26.9
bitnamilegacy/nats:2.11.8-debian-12-r0fa0cfba6034a
stdlib@go1.24.6
1.26.9
ghcr.io/helm/chartmuseum:v0.16.648bc27743c08
golang.org/x/net@v0.56.0
stdlib@go1.25.13
0.60.0
1.26.9
quay.io/codefresh/dind:3.0.250885ab519dac
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
stdlib@go1.23.8
1.26.9

Open the chart page →

19,845
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/projectcontour/contour:v1.33.7d88264ed084a
golang.org/x/net@v0.58.0
stdlib@go1.26.8-X:nodwarf5,nogreenteagc,norandomizedheapbase64
0.60.0
1.26.9

Open the chart page →

1,906
couchbase-operatorcouchbaseVerified publisher2.93.02 of 2See more

couchbase-operator couchbase 2.93.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
couchbase/admission-controller:2.9.3bf2d2e87e45f
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9
couchbase/operator:2.9.369a385b49e1f
golang.org/x/net@v0.43.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,382
dash0-operatordash0-operatorOfficialVerified publisher0.157.01 of 1See more

dash0-operator dash0-operator 0.157.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/dash0hq/operator-controller:0.157.02103617548e2
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

212
aws-ebs-csi-driverdeliveryheroVerified publisher2.17.46 of 6See more

aws-ebs-csi-driver deliveryhero 2.17.4

6 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/net@v0.4.0
stdlib@go1.19.6
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/net@v0.4.0
stdlib@go1.19.8
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/livenessprobe:v2.9.0-eks-1-25-latest8a305e162caa
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
public.ecr.aws/eks-distro/kubernetes-csi/node-driver-registrar:v2.7.0-eks-1-25-latestf4345e67df8f
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

11,105
eck-exporterenixVerified publisher1.14.01 of 1See more

eck-exporter enix 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

314
loki-simple-scalablegrafana1.8.112 of 3See more

loki-simple-scalable grafana 1.8.11

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18
0.60.0
1.26.9
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9

Open the chart page →

8,849
memcachedkubelauncherVerified publisher0.1.331 of 1See more

memcached kubelauncher 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/memcacheddigest-pinned91f2066d2aa4
stdlib@go1.26.7
1.26.9

Open the chart page →

701
mysqlkubelauncherVerified publisher0.4.61 of 1See more

mysql kubelauncher 0.4.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnedb25f98e6a86f
stdlib@go1.26.7
1.26.9

Open the chart page →

685
postgresqlkubelauncherVerified publisher0.5.01 of 1See more

postgresql kubelauncher 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinneddb2369c4dd90
stdlib@go1.26.7
1.26.9

Open the chart page →

782
kubernetes-replicatorkubernetes-replicator2.12.41 of 1See more

kubernetes-replicator kubernetes-replicator 2.12.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.12.45dc9fc5ff59a
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

667
lakefslakefsVerified publisher1.12.431 of 1See more

lakefs lakefs 1.12.43

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
treeverse/lakefs:1.88.0237a17c6b2d8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

483
multi-juicermulti-juicer10.3.11 of 1See more

multi-juicer multi-juicer 10.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/juice-shop/multi-juicer/multi-juicer:v10.3.1de4f0de62e8b
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

230
coreneuvectorchartsVerified publisher2.11.23 of 5See more

core neuvectorcharts 2.11.2

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
neuvector/controller:5.6.2824e29cf32c5
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
neuvector/enforcer:5.6.272e1deee40fb
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
neuvector/scanner:6d9e8b2ee8d69
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,341
diunnicholaswildeVerified publisher1.0.01 of 1See more

diun nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/diun:4.19.0c94e32b888e4
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.5
0.60.0
1.26.9

Open the chart page →

4,945
openclawopenclawVerified publisher1.110.12 of 2See more

openclaw openclaw 1.110.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.57.06bac628b3d82
stdlib@go1.26.7
1.26.9
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.110.151e6f187064f
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

3,151
prometheus-stackdriver-exporterprometheus-communityVerified publisher5.2.01 of 1See more

prometheus-stackdriver-exporter prometheus-community 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prometheuscommunity/stackdriver-exporter:v0.19.0c0a0cbf76570
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

635
questdbquestdb1.0.271 of 2See more

questdb questdb 1.0.27

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
questdb/questdb:10.0.167eaed863ebb
stdlib@go1.25.14
1.26.9

Open the chart page →

163
adguard-homerm3lVerified publisher0.24.11 of 2See more

adguard-home rm3l 0.24.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.513a143e6c071c
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,720
spegelspegelVerified publisher0.7.41 of 1See more

spegel spegel 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/spegel-org/spegeldigest-pinned26c60b05e08a
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

498
supabasetokens-studioVerified publisher1.0.03 of 14See more

supabase tokens-studio 1.0.0

3 of the 14 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9
supabase/gotrue:v2.163.0ba4ddc594b0b
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

26,708
wekanwekanVerified publisher12.27.02 of 3See more

wekan wekan 12.27.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latest41786dd49068
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2
ghcr.io/wekan/wekan:v12.27f2fc85bbe762
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

2,008
woodpeckerwoodpecker-ci3.7.52 of 2See more

woodpecker woodpecker-ci 3.7.5

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
woodpeckerci/woodpecker-agent:v3.19.0f85f163e0949
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
woodpeckerci/woodpecker-server:v3.19.06ca167a3c58b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

406

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
lishimeng/zoo:v0.4.0e0b8d2d8ca28
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9
1
listmonk/listmonk:v6.0.0bf3903d54a46
golang.org/x/net@v0.47.0
stdlib@go1.24.1
0.60.0
1.26.9
1
litestream/litestream:0.3c5a1e1b01916
golang.org/x/net@v0.14.0
stdlib@go1.21.3
0.60.0
1.26.9
1
livekit/ingress:v1.2.21ab01641b366
golang.org/x/net@v0.18.0
stdlib@go1.20.7
0.60.0
1.26.9
1
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/net@v0.0.0-20211004195052-b30845b58a23
stdlib@go1.16.2
0.60.0
1.26.9
1
livekit/livekit-server:v1.9.03602a85840d5
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9
1
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.10
0.60.0
1.26.9
1
livekit/livekit-server:v1.12.0b1281e66e35e
golang.org/x/net@v0.53.0
stdlib@go1.26.4
0.60.0
1.26.9
1
lmierzwa/karma:v0.503751e5eed656
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.60.0
1.26.9
1
lmierzwa/karma:latest57c7f1e63e76
stdlib@go1.27.1
1.27.2
1
lmierzwa/karma:v0.70d417abe7ddb5
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.60.0
1.26.9
1
lmierzwa/karma:latest:v0.133f5d0a0ff4062
stdlib@go1.27.1
1.27.2
1
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.10
0.60.0
1.26.9
1
localstack/localstack:latestdf6b89814326
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
loeken/home-assistant:2026.5.14ce6abc553b3
golang.org/x/net@v0.49.0
stdlib@go1.23.3
0.60.0
1.26.9
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.6
0.60.0
1.26.9
1
loftsh/jspolicy:0.2.225deb9bd2683
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.60.0
1.26.9
1
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.60.0
1.26.9
1
log10x/filebeat-10x:1.1.39-native7d6a79dacd58
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.18.7
0.60.0
1.26.9
1
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/net@v0.20.0
stdlib@go1.21.13
0.60.0
1.26.9
1
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.18.9
0.60.0
1.26.9
1
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.7
0.60.0
1.26.9
1
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.60.0
1.26.9
1
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.60.0
1.26.9
1
lokxy/lokxy:v0.9.0e4ac800dc55d
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
golang.org/x/net@v0.44.0
stdlib@go1.24.6
0.60.0
1.26.9
1
longhornio/longhorn-manager:v1.13.07372f3c59239
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
longhornio/longhorn-manager:v1.12.183b79f57043f
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.1
0.60.0
1.26.9
1
longhornio/longhorn-manager:v1.12.0fd245bae2e82
golang.org/x/net@v0.53.0
stdlib@go1.25.10
0.60.0
1.26.9
1
longhornio/longhorn-share-manager:v1.13.053950f78b7af
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
1
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
1
longhornio/longhorn-share-manager:v1.12.1efaf47aeb4e8
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
1
longhornio/longhorn-ui:v1.12.103a3ce6673df
stdlib@go1.25.12
1.26.9
1
longhornio/longhorn-ui:v1.12.03870d52a2b0a
stdlib@go1.25.10
1.26.9
1
longhornio/longhorn-ui:v1.10.0e60f36161511
stdlib@go1.24.6
1.26.9
1
longhornio/longhorn-ui:v1.13.0f22fb0254ae5
stdlib@go1.26.8
1.26.9
1
longhornio/upgrade-responder:v0.2.05875cef29348
stdlib@go1.17.13
1.26.9
1
looplj/axonhub:latest2c71eeaef295
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
lotest/locust-k8s-operator:2.3.1859b0d36f371
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
louislam/its-mytabs:1.7.02e478d3170bd
stdlib@go1.24.4
1.26.9
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
golang.org/x/net@v0.9.0
stdlib@go1.19.6
0.60.0
1.26.9
1
louislam/uptime-kuma:2.0.24c364ef96aad
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9
1
louislam/uptime-kuma:170233f4acb51
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9
1
louislam/uptime-kuma:2.5.4917318f9d7be
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
1
louislam/uptime-kuma:2.4.091e963bfda56
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9
1
louislam/uptime-kuma:2.5.69912da7d7d9b
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.