StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-7r9c-ff6c-hxjjCGA-gghc-78jw-f5q2CGA-rp37-mxv6-g5fjDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-vqxj-4gp6-23v9, CGA-w84h-9v6p-pf3x, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
prometheus-operatorarldkaVerified publisher13.0.12 of 2See more

prometheus-operator arldka 13.0.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.73.204f2b98d71ef
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

3,546
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
stdlib@go1.22.4
1.26.9
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
stdlib@go1.26.0
1.26.9

Open the chart page →

9,944
nsqbeeinventor1.3.01 of 1See more

nsq beeinventor 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
nsqio/nsq:v1.3.01a369c146af7
stdlib@go1.21.5
1.26.9

Open the chart page →

1,374
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
golang.org/x/net@v0.8.0
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

4,303
kube-prometheuschoerodon9.3.14 of 7See more

kube-prometheus choerodon 9.3.1

4 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.60.0
1.26.9
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
stdlib@go1.13.11
0.60.0
1.26.9
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
stdlib@go1.13.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.3
0.60.0
1.26.9

Open the chart page →

17,449
cloudflare-ddnscloudflareVerified publisher1.0.31 of 1See more

cloudflare-ddns cloudflare 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/aureum-cloud/cloudflare-ddns:latestaeb75d1605f4
stdlib@go1.23.12
1.26.9

Open the chart page →

674
timescaledbcloudpirates-timescaledbVerified publisher0.13.121 of 1See more

timescaledb cloudpirates-timescaledb 0.13.12

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
timescale/timescaledb:2.30.2-pg17b346edcdb51a
stdlib@go1.24.6
1.26.9

Open the chart page →

1,136
openstack-cinder-csicloud-provider-openstack2.36.57 of 7See more

openstack-cinder-csi cloud-provider-openstack 2.36.5

7 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/cinder-csi-plugin:v1.36.078adaeb154c7
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.10.0be59d0556508
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

6,956
csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher1.8.25 of 5See more

csi-secrets-store-provider-azure csi-secrets-store-provider-azure 1.8.2

5 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.8.2519f3891316a
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.14.06cb172e3de7e
golang.org/x/net@v0.40.0
stdlib@go1.26.5
0.60.0
1.26.9
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
golang.org/x/net@v0.39.0
stdlib@go1.25.7
0.60.0
1.26.9
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
golang.org/x/net@v0.47.0
stdlib@go1.26.3
0.60.0
1.26.9
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver-crds:v1.5.6cb0112636dc4
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

5,195
paperless-ngxfmjstudios0.2.83 of 5See more

paperless-ngx fmjstudios 0.2.8

3 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/redis:latestf4797b37502e
stdlib@go1.26.8
1.26.9
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
stdlib@go1.19.8
1.26.9

Open the chart page →

35,312
minifluxgabe565Verified publisher0.9.21 of 2See more

miniflux gabe565 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

2,033
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.24.061d866e93b56
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.60.0
1.26.9

Open the chart page →

4,023
waypointhashicorpVerified publisher0.1.211 of 2See more

waypoint hashicorp 0.1.21

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/waypoint:0.11.397d521a27498
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

5,039
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

9,485
jaeger-all-in-onejaeger-all-in-oneVerified publisher0.1.121 of 1See more

jaeger-all-in-one jaeger-all-in-one 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.55f6b5d09073f1
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.60.0
1.26.9

Open the chart page →

1,910
cassandrakubelauncherVerified publisher0.1.291 of 1See more

cassandra kubelauncher 0.1.29

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinned4a2625365fc6
stdlib@go1.26.7
1.26.9

Open the chart page →

1,596
etcdkubelauncherVerified publisher0.4.61 of 1See more

etcd kubelauncher 0.4.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinnedd139ad1e93ea
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

759
kafkakubelauncherVerified publisher0.1.281 of 1See more

kafka kubelauncher 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned0b761e55e9ef
stdlib@go1.26.7
1.26.9

Open the chart page →

1,458
keycloakkubelauncherVerified publisher0.5.01 of 1See more

keycloak kubelauncher 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinned85e8ad3172a2
stdlib@go1.26.7
1.26.9

Open the chart page →

707
kubectlkubelauncherVerified publisher0.3.01 of 1See more

kubectl kubelauncher 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned15ce1bd84ddc
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,058
mariadbkubelauncherVerified publisher1.0.01 of 1See more

mariadb kubelauncher 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mariadbdigest-pinned6f03ec42a46d
stdlib@go1.26.7
1.26.9

Open the chart page →

1,057
mongodbkubelauncherVerified publisher0.4.71 of 1See more

mongodb kubelauncher 0.4.7

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinnedf70e33e17161
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

987
rabbitmqkubelauncherVerified publisher0.2.161 of 1See more

rabbitmq kubelauncher 0.2.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinned7be1b7704a6a
stdlib@go1.22.2
1.26.9

Open the chart page →

1,332
rediskubelauncherVerified publisher0.5.41 of 1See more

redis kubelauncher 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedcb826b867e4b
stdlib@go1.26.7
1.26.9

Open the chart page →

662
zookeeperkubelauncherVerified publisher0.2.121 of 1See more

zookeeper kubelauncher 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/zookeeperdigest-pinned9a85b8701c5e
stdlib@go1.26.7
1.26.9

Open the chart page →

1,261
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
itzg/bungeecord:latest7b7ff61d2a60
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

3,344
ntfyntfyVerified publisher0.5.231 of 1See more

ntfy ntfy 0.5.23

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.29.04c599cf08189
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

218
mauticone-acre-fundVerified publisher0.1.71 of 3See more

mautic one-acre-fund 0.1.7

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

3,779
opentelemetry-kube-stackopentelemetry-helmOfficialVerified publisher0.24.32 of 2See more

opentelemetry-kube-stack opentelemetry-helm 0.24.3

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.159.02ceb3b541295
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,104
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.15
0.60.0
1.26.9

Open the chart page →

5,623
dex-k8s-authenticatorsagikazarmarkVerified publisher0.0.31 of 1See more

dex-k8s-authenticator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.60.0
1.26.9

Open the chart page →

4,038
thanosstevehipwellVerified publisher1.24.11 of 1See more

thanos stevehipwell 1.24.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

502
gatustwin1.5.01 of 1See more

gatus twin 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
twinproduction/gatus:v5.34.03fff895e77d3
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,206
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
stdlib@go1.24.6
1.26.9

Open the chart page →

4,221
caddyalekcVerified publisher0.9.21 of 1See more

caddy alekc 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/caddy:2.11.7-alpined76116d819d5
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

218
aspnet-corebitnamiVerified publisher9.5.11 of 3See more

aspnet-core bitnami 9.5.1

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/git:latest27e3b3fe7123
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

243
haproxybitnamiVerified publisher4.2.111 of 1See more

haproxy bitnami 4.2.11

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/haproxy:latest5b57bac338a2
golang.org/x/net@v0.59.0
0.60.0

Open the chart page →

61
connaisseurconnaisseurVerified publisher2.13.02 of 2See more

connaisseur connaisseur 2.13.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
stdlib@go1.18.2
1.26.9
securesystemsengineering/connaisseur:v3.13.0cef2efbd8bd3
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

4,251
kubeviewcowboysysopVerified publisher6.0.01 of 1See more

kubeview cowboysysop 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

2,617
dependabot-gitlabdependabot-gitlabVerified publisher6.3.03 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.60.0
1.26.9
library/postgres:18.6-alpine77f585114c32
stdlib@go1.24.6
1.26.9
pgautoupgrade/pgautoupgrade:18-alpine2245aabc5b80
stdlib@go1.24.6
1.26.9

Open the chart page →

43,493
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.26.9

Open the chart page →

6,454
devtron-operatordevtron0.23.310 of 11See more

devtron-operator devtron 0.23.3

10 of the 11 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.60.0
1.26.9
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.26.9
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.60.0
1.26.9
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.60.0
1.26.9
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.60.0
1.26.9
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.60.0
1.26.9
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.26.9
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

42,391
drone-runner-kubedroneVerified publisher0.1.101 of 1See more

drone-runner-kube drone 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

3,102
fluent-operatorfluent4.3.01 of 1See more

fluent-operator fluent 4.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluent-operator/fluent-operator:3.10.03108194a4ecc
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

438
gatekeepergogatekeeperVerified publisher0.1.661 of 1See more

gatekeeper gogatekeeper 0.1.66

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/gogatekeeper/gatekeeper:5.0.03d45202b06be
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

208
grafana-operatorgrafana5.25.01 of 1See more

grafana-operator grafana 5.25.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/grafana/grafana-operator:v5.25.0bc572995823f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

230
kubernetes-ingresshaproxytechVerified publisher1.54.21 of 1See more

kubernetes-ingress haproxytech 1.54.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:3.2.156185ab228aa6
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

601
envoy-gatewayhelmforgeVerified publisher2.1.23 of 3See more

envoy-gateway helmforge 2.1.2

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.9.10049bcb384c5
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
helmforge/kubectl:1.35.3c3f97e954c47
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
mccutchen/go-httpbin:v2.15.024528cf5229d
stdlib@go1.23.1
1.26.9

Open the chart page →

3,591
n8nhelmforgeVerified publisher2.1.31 of 2See more

n8n helmforge 2.1.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
n8nio/runners:2.41.31522f8179b76
stdlib@go1.25.11
1.26.9

Open the chart page →

2,000
ilumilumOfficialVerified publisher6.7.36 of 19See more

ilum ilum 6.7.3

6 of the 19 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
bitnamisecure/gitdigest-pinned72ae5bd9715f
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
gitea/gitea:1.22.376f516a1a8c2
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.60.0
1.26.9
ilum/api:6.7.3624fd09528c8
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
stdlib@go1.20.12
0.60.0
1.26.9

Open the chart page →

28,057

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
mirrorgitlabcontainers/kubectl:1.13.1299931bd06b41
stdlib@go1.13.3
1.26.9
1
misalbasynchrotron/visa-k8s:latest48e4dcba8f6e
golang.org/x/net@v0.49.0
stdlib@go1.26.8
0.60.0
1.26.9
1
missuo/deeplx:v1.2.232e492587678
golang.org/x/net@v0.55.0
stdlib@go1.25.10
0.60.0
1.26.9
1
mitre/vulcan:latest2bc4dfb8150f
stdlib@go1.25.5
1.26.9
1
moby/buildkit:v0.33.06c2fa84a6b61
golang.org/x/net@v0.43.0
stdlib@go1.26.8
0.60.0
1.26.9
1
moby/buildkit:v0.33.0-rootless80b15f0735e8
golang.org/x/net@v0.43.0
stdlib@go1.26.8
0.60.0
1.26.9
1
moby/buildkit:v0.31.0a095b3d11ce1
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
moby/buildkit:v0.10.0c2aeafaed434
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.8
0.60.0
1.26.9
1
moby/buildkit:mastere7c131019aa9
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
moby/buildkit:master-rootlessf3864381e463
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9
1
mohankrishna999/k8s-ai-agent:3.1.27f980f8c650c
golang.org/x/net@v0.57.0
stdlib@go1.26.5-X:jsonv2
0.60.0
1.26.9
1
moikot/basic-git-server:0.0.20d941bd30ffa
stdlib@go1.14.9
1.26.9
1
moikot/smartthings-metrics:0.1.08625f53aa9b7
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.13
0.60.0
1.26.9
1
moikot/smartthings-metrics:feat-log-detailsfb8565140106
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.15
0.60.0
1.26.9
1
mongodb/mongodb-atlas-kubernetes-operator:2.17.061541fc583b6
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
mongodb/mongodb-atlas-local:83a8affee01fd
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
monitoror/monitoror:44b88edcf51ff
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.6
0.60.0
1.26.9
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
stdlib@go1.20.12
1.26.9
1
moul/sshportal:v1.19.3332b603727c3
stdlib@go1.17.6
1.26.9
1
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.15.13
0.60.0
1.26.9
1
mrnim94/metrics-server-exporter:v2.4.086c4807a4bca
golang.org/x/net@v0.47.0
stdlib@go1.26.3
0.60.0
1.26.9
1
muonsoft/openapi-mock:latestc9afe1295484
stdlib@go1.20.2
1.26.9
1
murtazashah46/helmfile:latest4d11726cf803
golang.org/x/net@v0.5.0
stdlib@go1.22.8
0.60.0
1.26.9
1
mvisonneau/tailscale:v1.68.1fc45ad8abf10
golang.org/x/net@v0.24.0
stdlib@go1.22.4
0.60.0
1.26.9
1
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.1
0.60.0
1.26.9
1
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
golang.org/x/net@v0.7.0
stdlib@go1.19.13
0.60.0
1.26.9
1
n8nio/n8n:1.86.08b39ed5a2de9
stdlib@go1.24.0
1.26.9
1
n8nio/n8n:1.115.1ed16e560c40e
stdlib@go1.24.6
1.26.9
1
n8nio/runners:2.41.31522f8179b76
stdlib@go1.25.11
1.26.9
1
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.26.9
1
nadoo/glider:0.1638aadefbd607
golang.org/x/net@v0.28.0
stdlib@go1.20.14
0.60.0
1.26.9
1
nathanfirmo/dbgate:latest6b0487e6e987
stdlib@go1.24.5
1.26.9
1
natsio/jetstream-controller:0.24.058862daca582
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
1
natsio/nats-box:0.14.31cc420186664
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.60.0
1.26.9
1
natsio/nats-box:0.13.559cf2e949181
stdlib@go1.19.5
1.26.9
1
natsio/nats-box:0.19.55d513bf0bb82
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9
1
natsio/nats-box:0.18.0abdc9f9f0120
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9
1
natsio/nats-box:0.8.1b7f9328145f4
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.6
0.60.0
1.26.9
1
natsio/nats-box:0.13.3c507bd7e3831
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
1
natsio/nats-box:0.14.2e808e0644ce1
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
1
natsio/nats-kafka:1.4.2bb241956b0dc
golang.org/x/net@v0.18.0
stdlib@go1.20
0.60.0
1.26.9
1
natsio/nats-operator:0.8.31261dae38389
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.10
0.60.0
1.26.9
1
natsio/nats-server-config-reloader:0.14.10d50270fa374
stdlib@go1.20.5
1.26.9
1
natsio/nats-server-config-reloader:0.15.05b21830a9e9d
stdlib@go1.22.4
1.26.9
1
natsio/nats-server-config-reloader:0.8.06bdaceb63aa5
stdlib@go1.19.4
1.26.9
1
natsio/nats-server-config-reloader:0.19.181edf32a3680
stdlib@go1.24.5
1.26.9
1
natsio/nats-server-config-reloader:0.14.08c28b75bc416
stdlib@go1.20.5
1.26.9
1
natsio/nats-server-config-reloader:0.6.2ad0374303b13
stdlib@go1.15.14
1.26.9
1
natsio/nats-server-config-reloader:0.16.1bf97e5e9b9d2
stdlib@go1.23.3
1.26.9
1
natsio/nats-server-config-reloader:0.11.0c3a755eab2cc
stdlib@go1.20.5
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.