StackRadar

CVE-2026-78663

Unscored

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,566
of 18,071 indexed, latest versions
Container images
6,425
deployed by those charts
Fix available
2 of 3
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,566 of 18,071 indexed charts deploy, on 6,425 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,411
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,172
golang-1.19deb1.19.8-2no fix listed1
OSV records
DEBIAN-CVE-2026-78663GO-2026-6612
Trending
Rank 5 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,566 by stars
ChartLatestAffected imagesRadar Score
n8nhelmforgeVerified publisher2.1.31 of 2See more

n8n helmforge 2.1.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
n8nio/runners:2.41.31522f8179b76
stdlib@go1.25.11
1.26.9

Open the chart page →

1,909
ilumilumOfficialVerified publisher6.7.36 of 19See more

ilum ilum 6.7.3

6 of the 19 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
bitnamisecure/gitdigest-pinned72ae5bd9715f
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
gitea/gitea:1.22.376f516a1a8c2
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.60.0
1.26.9
ilum/api:6.7.3624fd09528c8
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
stdlib@go1.20.12
0.60.0
1.26.9

Open the chart page →

27,186
syncthingk8s-home-lab-repo5.2.01 of 1See more

syncthing k8s-home-lab-repo 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
syncthing/syncthing:2.1.1775c4aac4862
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,413
kube-greenkube-green-officialOfficialVerified publisher0.7.11 of 1See more

kube-green kube-green-official 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubegreen/kube-green:0.7.12dc0f0a6034c
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

858
lakekeeperlakekeeperVerified publisher0.12.01 of 2See more

lakekeeper lakekeeper 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.26.9

Open the chart page →

2,586
temporallemontechVerified publisher0.37.06 of 13See more

temporal lemontech 0.37.0

6 of the 13 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.60.0
1.26.9
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.26.9
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9
temporalio/server:1.22.4c0a44c26397b
golang.org/x/net@v0.7.0
stdlib@go1.20.11
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

21,228
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
golang.org/x/net@v0.40.0
stdlib@go1.25.0
0.60.0
1.26.9
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

8,733
netris-controllernetrisai2.8.27 of 14See more

netris-controller netrisai 2.8.2

7 of the 14 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.11
0.60.0
1.26.9
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.60.0
1.26.9
netrisai/controller-grpc:4.6.0.00753178bf173c2
golang.org/x/net@v0.23.0
stdlib@go1.25.6
0.60.0
1.26.9
netrisai/controller-telescope:4.6.0.00414d82948a8b2
stdlib@go1.25.6
1.26.9
netrisai/controller-web-session-generator:0.2.0a030a31289f4
stdlib@go1.14.15
1.26.9
netrisai/mariadb:10.11.4-debian-11-r460aa742a0b906
stdlib@go1.19.11
1.26.9
netrisai/mongodb:4.4.4-debian-10-r095abfb776bb4
stdlib@go1.15.1
1.26.9

Open the chart page →

38,093
nfs-server-provisionernfs-ganesha-server-and-external-provisioner1.8.01 of 1See more

nfs-server-provisioner nfs-ganesha-server-and-external-provisioner 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

3,382
nginx-service-meshnginxVerified publisher2.0.02 of 9See more

nginx-service-mesh nginx 2.0.0

2 of the 9 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
library/nats:2.9-alpined402af4147fc
stdlib@go1.20.14
1.26.9

Open the chart page →

1,712
nuclionuclio0.23.92 of 2See more

nuclio nuclio 0.23.9

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/nuclio/controller:1.17.9-amd646e3913a56ca5
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/nuclio/dashboard:1.17.9-amd64708fe10f099a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,746
homarroben01Verified publisher1.4.01 of 1See more

homarr oben01 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
stdlib@go1.22.5
1.26.9

Open the chart page →

3,248
syftopenmined0.9.55 of 6See more

syft openmined 0.9.5

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.26.9
library/registry:2a3d8aaa63ed8
stdlib@go1.20.8
1.26.9
library/traefik:v2.11.00a5157f742d2
golang.org/x/net@v0.20.0
stdlib@go1.22.0
0.60.0
1.26.9
openmined/syft-frontend:0.9.5d11524a3854a
stdlib@go1.20.5
1.26.9
openmined/syft-seaweedfs:0.9.53a4144c0bb82
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.60.0
1.26.9

Open the chart page →

21,017
paperless-ngxpaperless-ngxVerified publisher0.3.241 of 3See more

paperless-ngx paperless-ngx 0.3.24

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.3.06b94799bc769
stdlib@go1.24.4
1.26.9

Open the chart page →

8,776
pmmpercona1.9.11 of 1See more

pmm percona 1.9.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
percona/pmm-server:3.9.1003f9c25f842
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,056
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9
platform9community/api-gateway:latest40a4970de568
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9
platform9community/customers-service:latest2089811e5cc6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.11
0.60.0
1.26.9
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

48,687
prometheus-nats-exporterprometheus-communityVerified publisher2.23.21 of 1See more

prometheus-nats-exporter prometheus-community 2.23.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
natsio/prometheus-nats-exporter:0.20.2c623b608e148
stdlib@go1.26.6
1.26.9

Open the chart page →

251
prometheus-rabbitmq-exporterprometheus-communityVerified publisher2.1.21 of 1See more

prometheus-rabbitmq-exporter prometheus-community 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kbudde/rabbitmq-exporter:1.0.012f27d6d84e6
stdlib@go1.21.8
1.26.9

Open the chart page →

861
pyrrarlex0.15.01 of 1See more

pyrra rlex 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/pyrra-dev/pyrra:v0.8.10e02ef538ef0
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,386
sealed-secretssealed-secretsVerified publisher2.20.01 of 1See more

sealed-secrets sealed-secrets 2.20.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.40.0b1ff382e9300
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

76
k8s-infrasignoz0.17.11 of 1See more

k8s-infra signoz 0.17.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.139.0faf125d656fa
golang.org/x/net@v0.46.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

1,594
radarskyhookOfficialVerified publisher1.16.01 of 1See more

radar skyhook 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/skyhook-io/radar:1.16.02e57d0465fba
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

83
helm-exportersstarcher0.5.01 of 1See more

helm-exporter sstarcher 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
sstarcher/helm-exporter:0.5.011769d01ba35
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.6
0.60.0
1.26.9

Open the chart page →

5,390
tailing-sidecar-operatortailing-sidecar-operatorOfficialVerified publisher0.111.02 of 2See more

tailing-sidecar-operator tailing-sidecar-operator 0.111.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/sumologic/tailing-sidecar-operator:0.111.0920b8f901aef
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,971
tailscale-operatortailscale1.102.41 of 1See more

tailscale-operator tailscale 1.102.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
tailscale/k8s-operator:v1.102.43c8958c42fb3
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

299
tbmq-clustertbmq-helm-chartOfficialVerified publisher2.3.11 of 3See more

tbmq-cluster tbmq-helm-chart 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
thingsboard/toolbox:1.29.00f6c14031777
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

3,075
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.26.9

Open the chart page →

8,350
elasticsearch-clusterwiremindVerified publisher4.5.41 of 2See more

elasticsearch-cluster wiremind 4.5.4

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.11.0a056739b095d
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

944
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.60.0
1.26.9

Open the chart page →

6,481
zigbee2mqttzigbee2mqtt2.14.21 of 2See more

zigbee2mqtt zigbee2mqtt 2.14.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mikefarah/yq:4.45.12c100efaca06
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

1,522
home-assistantalekcVerified publisher2.12.01 of 1See more

home-assistant alekc 2.12.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.10.01b64d38f38d9
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

2,683
home-assistantandrenarchyVerified publisher14.104.01 of 1See more

home-assistant andrenarchy 14.104.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

3,098
config-syncerappscodeVerified publisher0.15.51 of 1See more

config-syncer appscode 0.15.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/appscode/config-syncer:v0.15.51858a68944cb
golang.org/x/net@v0.17.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

834
astarte-operatorastarteOfficialVerified publisher26.5.21 of 1See more

astarte-operator astarte 26.5.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
astarte/astarte-kubernetes-operator:26.5.1e3ff1b3c0c98
golang.org/x/net@v0.30.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,002
awx-operatorawx-operator-helm3.2.12 of 2See more

awx-operator awx-operator-helm 3.2.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
golang.org/x/net@v0.20.0
stdlib@go1.20.12
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.15.02c7b120590cb
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

11,050
beaverdeckbeaverdeckOfficialVerified publisher2.2.81 of 1See more

beaverdeck beaverdeck 2.2.8

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
arequs/beaverdeck:1.6.36135900cb2c6
golang.org/x/net@v0.56.0
0.60.0

Open the chart page →

20
cerboscerbosVerified publisher0.56.01 of 1See more

cerbos cerbos 0.56.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cerbos/cerbos:0.56.0540643bc67ba
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

76
cert-manager-istio-csrcert-managerOfficialVerified publisher0.18.01 of 1See more

cert-manager-istio-csr cert-manager 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-istio-csr:v0.18.0495dcdad72a4
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

167
cadvisorckotzbauerVerified publisher2.4.31 of 1See more

cadvisor ckotzbauer 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.52.1f40e65878e25
golang.org/x/net@v0.33.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

1,365
m365-exportercloudeteer-helm-chartsVerified publisher1.7.11 of 1See more

m365-exporter cloudeteer-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/cloudeteer/m365-exporter:3.9.3a13a11fe9558
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

229
openstack-cloud-controller-managercloud-provider-openstack2.36.51 of 1See more

openstack-cloud-controller-manager cloud-provider-openstack 2.36.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/openstack-cloud-controller-manager:v1.36.0e354e40db2d0
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

757
passboltcnieg1.1.171 of 2See more

passbolt cnieg 1.1.17

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.26.9

Open the chart page →

5,335
codercoderOfficialVerified publisher1.44.61 of 2See more

coder coder 1.44.6

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.60.0
1.26.9

Open the chart page →

7,890
dronecommunity-chartsVerified publisher0.1.52 of 2See more

drone community-charts 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
drone/drone:2.28.255897c8fb22d
golang.org/x/net@v0.42.0
stdlib@go1.24.13
0.60.0
1.26.9
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

3,947
cloudflare-operatorcontainerooVerified publisher1.10.71 of 1See more

cloudflare-operator containeroo 1.10.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/containeroo/cloudflare-operator:v1.10.60eda6d237a84
golang.org/x/net@v0.57.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

460
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9
getconvoy/convoy:v26.7.6f4934cc05e31
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

7,113
cortexcortex3.5.02 of 4See more

cortex cortex 3.5.0

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/memcached-exporter:v0.17.0995c80e3ffbe
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
quay.io/cortexproject/cortex:v1.21.18577eb292a01
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

3,765
whoamicowboysysopVerified publisher6.1.01 of 1See more

whoami cowboysysop 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
traefik/whoami:v1.12.0c4717a8d1f01
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

221
doris-operatordorisVerified publisher25.8.01 of 1See more

doris-operator doris 25.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/doris:operator-latest3a4422656592
golang.org/x/net@v0.33.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

784
uptime-kumaduyet0.1.81 of 1See more

uptime-kuma duyet 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

5,750

Container images carrying it

6,425 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
ethpandaops/tracoor:latest89424dbe2d6b
golang.org/x/net@v0.58.0
stdlib@go1.26.1
0.60.0
1.26.9
3
glanceapp/glance:latest:v0.8.69dfb09470b20
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
3
goharbor/harbor-core:v2.15.2d7b780d23721
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/harbor-jobservice:v2.15.2f71a4452a095
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/registry-photon:v2.15.2c4ebef61ceb5
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
3
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.60.0
1.26.9
3
grafana/grafana:13.1.0121a7a9ece6d
golang.org/x/net@v0.55.0
stdlib@go1.25.7
0.60.0
1.26.9
3
grafana/grafana:13.2.2-distroless69a5d2d957ca
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9
3
grafana/loki:3.7.8:latest1107dd5274e0
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
3
grafana/loki:3.6.1144148ad243c0
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
3
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.17.2
0.60.0
1.26.9
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
3
hashicorp/consul:2.0.41c59f007df8e
golang.org/x/net@v0.59.0
stdlib@go1.26.7
0.60.0
1.26.9
3
hashicorp/consul-k8s-control-plane:2.0.49334d7f4bcf0
golang.org/x/net@v0.59.0
stdlib@go1.26.7
0.60.0
1.26.9
3
hashicorp/http-echo:1.0.0:latestfcb75f691c8b
stdlib@go1.21.1
1.26.9
3
hashicorp/vault:2.0.45be49781ecf7
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
hashicorp/vault-k8s:1.7.655e27b080c9b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
3
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
jacobalberty/unifi:v10.0.162896c0ab82d33
stdlib@go1.24.6
1.26.9
3
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/net@v0.19.0
stdlib@go1.24.10
0.60.0
1.26.9
3
kubernetesui/dashboard-api:1.14.096a702cfd339
golang.org/x/net@v0.40.0
stdlib@go1.23.12
0.60.0
1.26.9
3
kubernetesui/dashboard-auth:1.4.053e9917898bf
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
3
kubernetesui/dashboard-metrics-scraper:1.2.25154b68252bd
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9
3
kubernetesui/dashboard-web:1.7.0cc7c31bd2d84
golang.org/x/net@v0.38.0
stdlib@go1.23.9
0.60.0
1.26.9
3
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9
3
library/mongo:8:8.3.11:latest5d7043a4ffe0
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
library/mongo:7:7.09854f7139445
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
library/nats:2.10-alpineb83efabe3e7d
stdlib@go1.24.2
1.26.9
3
library/nats:latestcd3fcd4ecdda
stdlib@go1.27.1
1.27.2
3
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.26.9
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.26.9
3
library/postgres:14-alpine4ea9e5ed0659
stdlib@go1.24.6
1.26.9
3
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.26.9
3
library/postgres:1665b16a8b326e
stdlib@go1.24.6
1.26.9
3
library/postgres:18:18.6-trixie6737476511d4
stdlib@go1.24.6
1.26.9
3
library/postgres:15724292da1f2e
stdlib@go1.24.6
1.26.9
3
library/registry:3.1.1:latest1be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
3
library/traefik:v3.7.1324841fe2de73
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
linuxserver/plex:latest06e07af2851e
stdlib@go1.26.7
1.26.9
3
louislam/uptime-kuma:2.5.5c74379ac4509
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
3
mcp/grafana:latest9362bcf6aa0e
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
3
meshery/meshery:stable-latest44b64ee128fb
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
3
mikefarah/yq:2.4.16fc625c402de
stdlib@go1.13.3
1.26.9
3

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.