StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
cluster-monitor-agentcluster-monitor-agent0.10.21 of 1See more

cluster-monitor-agent cluster-monitor-agent 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-agent:0.10.26769c2275a43
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9

Open the chart page →

890
cluster-monitor-servercluster-monitor-server0.10.21 of 1See more

cluster-monitor-server cluster-monitor-server 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9

Open the chart page →

1,180
clusternet-controller-managerclusternet1.0.01 of 1See more

clusternet-controller-manager clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-controller-manager:v1.0.02ce077d3d02d
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

2,087
cluster-network-policy-operatorcluster-network-policy-operatorVerified publisher1.1.01 of 1See more

cluster-network-policy-operator cluster-network-policy-operator 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/desuuuu/cluster-network-policy-operator:v1.1.0d943d13c5281
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

525
cluster-octopuscluster-octopus1.0.01 of 1See more

cluster-octopus cluster-octopus 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.60.0
1.26.9

Open the chart page →

1,638
clusterpedia-coreclusterpedia0.1.13 of 3See more

clusterpedia-core clusterpedia 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/clusterpedia-io/clusterpedia/apiserver:v0.6.03d089d9078f8
stdlib@go1.19.4
1.26.9
ghcr.io/clusterpedia-io/clusterpedia/clustersynchro-manager:v0.6.082cc9a77f6d6
stdlib@go1.19.4
1.26.9
ghcr.io/clusterpedia-io/clusterpedia/controller-manager:v0.6.081669df338e0
stdlib@go1.19.4
1.26.9

Open the chart page →

5,007
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
linuxserver/plex:latest06e07af2851e
stdlib@go1.26.7
1.26.9

Open the chart page →

4,085
d2-prometheus-exportercmacraeVerified publisher0.1.01 of 1See more

d2-prometheus-exporter cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
stdlib@go1.15
1.26.9

Open the chart page →

2,307
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.17
0.60.0
1.26.9

Open the chart page →

3,152
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16
0.60.0
1.26.9

Open the chart page →

3,339
lgtmcmacraeVerified publisher0.1.01 of 1See more

lgtm cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cmacrae/lgtm:0.1.0dec8d490fe40
golang.org/x/net@v0.0.0-20181108082009-03003ca0c849
stdlib@go1.14.1
0.60.0
1.26.9

Open the chart page →

3,064
storage-local-pathcnapVerified publisher1.0.11 of 1See more

storage-local-path cnap 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.3534ff0847cc47
golang.org/x/net@v0.38.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

1,103
storage-piraeuscnapVerified publisher1.0.11 of 1See more

storage-piraeus cnap 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/piraeusdatastore/piraeus-operator:v2.10.5dd68a66332de
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

656
door-agentcnoVerified publisher3.0.1512 of 15See more

door-agent cno 3.0.15

12 of the 15 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/net@v0.37.0
stdlib@go1.23.12
0.60.0
1.26.9
beopenit/door-cd-operator:v3.0.4d3999cb8d026
golang.org/x/net@v0.17.0
stdlib@go1.23.9
0.60.0
1.26.9
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/net@v0.15.0
stdlib@go1.19.13
0.60.0
1.26.9
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
doorcloud/apim-operator:v3.0.44e6ef8d72c3e
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.60.0
1.26.9
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.13
0.60.0
1.26.9
library/docker:27-cli851f91d24121
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.60.0
1.26.9
library/docker:27-dindaa3df78ecf32
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.60.0
1.26.9
ghcr.io/projectcontour/contour:v1.30.0b12824d7eb58
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/projectcontour/contour:v1.33.0cd6e13fa882d
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.1
0.60.0
1.26.9
quay.io/prometheus/prometheus:latestefd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

26,698
cobbler-tftpcobbler0.1.11 of 1See more

cobbler-tftp cobbler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cobbler/cobbler-tftp:v0.1.0a7fef3ca80baa4
stdlib@go1.25.10
1.26.9

Open the chart page →

634
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

15,180
coder-logstream-kubecoder-logstream-kube0.0.161 of 1See more

coder-logstream-kube coder-logstream-kube 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/coder/coder-logstream-kube:v0.0.1614af1b1903d2
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

181
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.12 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9

Open the chart page →

6,017
docker-composecoderstudio-strapi-devVerified publisher0.0.12 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9

Open the chart page →

6,017
strapi-devcoderstudio-strapi-devVerified publisher0.0.12 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9

Open the chart page →

6,017
coder-ai-gatewaycoder-v2Verified publisher2.38.01 of 1See more

coder-ai-gateway coder-v2 2.38.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/coder/coder:v2.38.038a4cfc548b0
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

295
coder-provisionercoder-v2OfficialVerified publisher2.38.01 of 1See more

coder-provisioner coder-v2 2.38.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/coder/coder:v2.38.038a4cfc548b0
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

295
codiac-deployment-bundle-chartcodiac-deployment-bundle-chart0.0.151 of 1See more

codiac-deployment-bundle-chart codiac-deployment-bundle-chart 0.0.15

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
codiacimages/codiac-deployment-bundle:0.0.15d7d1e91eccde
golang.org/x/net@v0.38.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

756
cohdicohdi0.2.23 of 3See more

cohdi cohdi 0.2.2

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/cohdi/composable-resource-operator:v0.2.23f45bf0a1bc0
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/cohdi/dynamic-device-scaler:v0.2.2b487e1d74632
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

4,917
colecole1.4.21 of 1See more

cole cole 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ntakashi/cole:1.2.3f7b68bee2a68
golang.org/x/net@v0.10.0
stdlib@go1.20.11
0.60.0
1.26.9

Open the chart page →

1,421
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.60.0
1.26.9

Open the chart page →

3,413
collectordcollectordOfficialVerified publisher2604.5.01 of 1See more

collectord collectord 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

89
collectord-elasticsearchcollectord-elasticsearchOfficialVerified publisher2604.5.01 of 1See more

collectord-elasticsearch collectord-elasticsearch 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

89
collectord-opensearchcollectord-opensearchOfficialVerified publisher2604.5.01 of 1See more

collectord-opensearch collectord-opensearch 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

89
collectord-splunk-kubernetescollectord-splunk-kubernetesOfficialVerified publisher2604.5.01 of 1See more

collectord-splunk-kubernetes collectord-splunk-kubernetes 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

89
collectord-splunk-openshiftcollectord-splunk-openshiftOfficialVerified publisher2604.5.01 of 1See more

collectord-splunk-openshift collectord-splunk-openshift 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforopenshift:26.04.55959c31596a0
stdlib@go1.26.8
1.26.9

Open the chart page →

89
collectord-syslogcollectord-syslogOfficialVerified publisher2604.5.01 of 1See more

collectord-syslog collectord-syslog 2604.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9

Open the chart page →

89
mysqlcomet-mysql-helmVerified publisher1.0.81 of 1See more

mysql comet-mysql-helm 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.26.9

Open the chart page →

1,869
loki-stackcommon-chartsVerified publisher1.0.39 of 12See more

loki-stack common-charts 1.0.3

9 of the 12 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.0491b0578c049
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/grafana:13.1.17cb8c64c4d57
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
grafana/loki:3.6.1144148ad243c0
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.5d0e80b2f62fe
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.1-distroless8c9bac11973b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

8,187
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

10,093
opencloudcommunity-opencloud3.2.02 of 13See more

opencloud community-opencloud 3.2.0

2 of the 13 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/tika:latest-fullab9cc988828c
stdlib@go1.26.7
1.26.9
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

10,313
community-operator-v2community-operator-v21.0.01 of 2See more

community-operator-v2 community-operator-v2 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.60.0
1.26.9

Open the chart page →

2,372
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

15,635
conjur-k8s-csi-providerconjure0.2.91 of 1See more

conjur-k8s-csi-provider conjure 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cyberark/conjur-k8s-csi-provider:latest737a967088d9
golang.org/x/net@v0.54.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

532
consentbbconsentbbVerified publisher2023.12.41 of 5See more

consentbb consentbb 2023.12.4

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
golang.org/x/net@v0.17.0
stdlib@go1.18.8
0.60.0
1.26.9

Open the chart page →

3,950
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,018
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

10,927
agent-forge-operatorcontainerooVerified publisher1.2.31 of 1See more

agent-forge-operator containeroo 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/agent-forge-operator:v1.2.32cec21162d6d
golang.org/x/net@v0.57.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

567
autovpacontainerooVerified publisher0.4.21 of 1See more

autovpa containeroo 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/autovpa:v0.0.3425b801d8d1f7
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

606
cert-manager-webhook-bluecatcontainerooVerified publisher1.0.21 of 1See more

cert-manager-webhook-bluecat containeroo 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/cert-manager-webhook-bluecat:latest96f82d5840d4
golang.org/x/net@v0.57.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

795
filesystem-exportercontainerooVerified publisher1.5.21 of 1See more

filesystem-exporter containeroo 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/filesystem-exporter:v1.5.2a66121e16d4e
stdlib@go1.26.1
1.26.9

Open the chart page →

1,718
kube-ephemeral-container-exportercontainerooVerified publisher0.2.31 of 1See more

kube-ephemeral-container-exporter containeroo 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/kube-ephemeral-container-exporter:v0.0.14b238f3c58d83
golang.org/x/net@v0.56.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

606
terrascalercontainerooVerified publisher0.1.01 of 1See more

terrascaler containeroo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/terrascaler:v0.1.0b152a8514bd3
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

394
containers-security-chartscontainers-security0.1.03 of 7See more

containers-security-charts containers-security 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.26.9
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.26.9
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.18.1
0.60.0
1.26.9

Open the chart page →

12,220
falcocontainers-security2.4.62 of 2See more

falco containers-security 2.4.6

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.26.9
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.26.9

Open the chart page →

4,355

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
ethpandaops/tracoor:latest89424dbe2d6b
golang.org/x/net@v0.58.0
stdlib@go1.26.1
0.60.0
1.26.9
3
glanceapp/glance:latest:v0.8.69dfb09470b20
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
3
goharbor/harbor-core:v2.15.2d7b780d23721
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/harbor-jobservice:v2.15.2f71a4452a095
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/registry-photon:v2.15.2c4ebef61ceb5
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.60.0
1.26.9
3
grafana/grafana:13.1.0121a7a9ece6d
golang.org/x/net@v0.55.0
stdlib@go1.25.7
0.60.0
1.26.9
3
grafana/grafana:13.2.2-distroless69a5d2d957ca
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9
3
grafana/loki:3.7.8:latest1107dd5274e0
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
3
grafana/loki:3.6.1144148ad243c0
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
3
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.17.2
0.60.0
1.26.9
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
3
hashicorp/consul:2.0.41c59f007df8e
golang.org/x/net@v0.59.0
stdlib@go1.26.7
0.60.0
1.26.9
3
hashicorp/consul-k8s-control-plane:2.0.49334d7f4bcf0
golang.org/x/net@v0.59.0
stdlib@go1.26.7
0.60.0
1.26.9
3
hashicorp/http-echo:1.0.0:latestfcb75f691c8b
stdlib@go1.21.1
1.26.9
3
hashicorp/vault:2.0.45be49781ecf7
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
hashicorp/vault-k8s:1.7.655e27b080c9b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
3
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.26.9
3
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/net@v0.19.0
stdlib@go1.24.10
0.60.0
1.26.9
3
kubernetesui/dashboard-api:1.14.096a702cfd339
golang.org/x/net@v0.40.0
stdlib@go1.23.12
0.60.0
1.26.9
3
kubernetesui/dashboard-auth:1.4.053e9917898bf
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
3
kubernetesui/dashboard-metrics-scraper:1.2.25154b68252bd
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9
3
kubernetesui/dashboard-web:1.7.0cc7c31bd2d84
golang.org/x/net@v0.38.0
stdlib@go1.23.9
0.60.0
1.26.9
3
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9
3
l7mp/stunner-auth-server:devc4654dade66e
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
3
library/caddy:latestf2a1290d0463
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9
3
library/mongo:8:8.3.11:latest5d7043a4ffe0
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
library/mongo:7:7.09854f7139445
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
library/nats:2.10-alpineb83efabe3e7d
stdlib@go1.24.2
1.26.9
3
library/nats:latestcd3fcd4ecdda
stdlib@go1.27.1
1.27.2
3
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.26.9
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.26.9
3
library/postgres:14-alpine4ea9e5ed0659
stdlib@go1.24.6
1.26.9
3
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.26.9
3
library/postgres:1665b16a8b326e
stdlib@go1.24.6
1.26.9
3
library/postgres:18:18.6-trixie6737476511d4
stdlib@go1.24.6
1.26.9
3
library/postgres:15724292da1f2e
stdlib@go1.24.6
1.26.9
3
library/postgres:14c2427de38f99
stdlib@go1.24.6
1.26.9
3
library/registry:3.1.1:latest1be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
3
library/traefik:v3.7.1324841fe2de73
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
linuxserver/plex:latest06e07af2851e
stdlib@go1.26.7
1.26.9
3
mcp/grafana:latest9362bcf6aa0e
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
meshery/meshery:stable-latest44b64ee128fb
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.