StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-7r9c-ff6c-hxjjCGA-gghc-78jw-f5q2CGA-rp37-mxv6-g5fjDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-vqxj-4gp6-23v9, CGA-w84h-9v6p-pf3x, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

15,471
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

14,925
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.26.9

Open the chart page →

6,466
fleetfleetVerified publisher0.16.21 of 1See more

fleet fleet 0.16.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
rancher/fleet:v0.16.231f39589e1f8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

222
flyte-binaryflyte2.0.511 of 4See more

flyte-binary flyte 2.0.51

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9

Open the chart page →

5,196
flyte-coreflyte2.0.511 of 3See more

flyte-core flyte 2.0.51

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9

Open the chart page →

931
frp-operatorfrpVerified publisher1.0.41 of 1See more

frp-operator frp 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/aureum-cloud/frp-operator:v1.0.196b01d7e7025
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

771
frp-operatorfrp-operator1.10.11 of 1See more

frp-operator frp-operator 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/zufardhiyaulhaq/frp-operator:v0.12.1c78d5bc90a8f
golang.org/x/net@v0.23.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,032
ascii-moviegabe565Verified publisher0.16.41 of 1See more

ascii-movie gabe565 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
stdlib@go1.24.0
1.26.9

Open the chart page →

1,622
domain-watchgabe565Verified publisher1.1.01 of 1See more

domain-watch gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/gabe565/domain-watch:latest34c5a1e351d6
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

1,519
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.7
0.60.0
1.26.9

Open the chart page →

4,102
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.26.9

Open the chart page →

2,023
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.60.0
1.26.9

Open the chart page →

2,919
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.10
0.60.0
1.26.9

Open the chart page →

9,352
multusgeek-cookbookVerified publisher3.5.22 of 3See more

multus geek-cookbook 3.5.2

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.26.9
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

7,081
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
stdlib@go1.18.4
1.26.9

Open the chart page →

10,816
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

11,749
smarter-device-managergeek-cookbookVerified publisher6.5.21 of 1See more

smarter-device-manager geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

3,506
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.13
0.60.0
1.26.9

Open the chart page →

4,594
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
stdlib@go1.17
0.60.0
1.26.9

Open the chart page →

3,752
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.26.9

Open the chart page →

12,197
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.60.0
1.26.9

Open the chart page →

3,489
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.26.9

Open the chart page →

13,100
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher2.0.22 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 2.0.2

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.46ea90827b110
stdlib@go1.24.6
1.26.9
ghcr.io/sredevopsorg/ghost-on-kubernetes:main8da4c9948421
stdlib@go1.26.4
1.26.9

Open the chart page →

1,836
openbaogitlabVerified publisher0.20.01 of 1See more

openbao gitlab 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.6.2-gitlab177907fa18465
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

1,864
gitlab-runnergitlab-jh0.93.01 of 1See more

gitlab-runner gitlab-jh 0.93.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

650
gitvotegitvoteVerified publisher1.5.02 of 6See more

gitvote gitvote 1.5.0

2 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.26.9
ghcr.io/cncf/gitvote/dbmigrator:v1.5.0f1e7efe440da
stdlib@go1.25.3
1.26.9

Open the chart page →

7,290
etcdgroundhog2k1.1.141 of 2See more

etcd groundhog2k 1.1.14

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.7.2e9afa62b1e91
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

238
giteagroundhog2k0.16.51 of 1See more

gitea groundhog2k 0.16.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gitea/gitea:28.1.0f505a0d3a413
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

218
nacosgujunxiang0.1.51 of 1See more

nacos gujunxiang 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.26.9

Open the chart page →

2,620
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.26.9

Open the chart page →

7,857
unifi-pollerhalkeye0.1.21 of 1See more

unifi-poller halkeye 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.7
0.60.0
1.26.9

Open the chart page →

2,874
haproxyhaproxytechVerified publisher1.30.21 of 1See more

haproxy haproxytech 1.30.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
haproxytech/haproxy-alpine:3.4.41fe3f201ebb5
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

804
whoamiharrytangVerified publisher0.2.01 of 1See more

whoami harrytang 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.26.9

Open the chart page →

752
monitoring-stackhaukitechVerified publisher0.1.113 of 3See more

monitoring-stack haukitech 0.1.11

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

3,800
prometheus-operatorhaukitechVerified publisher0.1.41 of 1See more

prometheus-operator haukitech 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

1,096
headscaleheadscaleVerified publisher1.0.203 of 3See more

headscale headscale 1.0.20

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/k8s:1.37.0b421c2e9419e
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/juanfont/headscale:0.29.4-debug2380cdb4951e
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/juanfont/headscale:0.29.48833f828b414
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

2,864
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

2,663
netbirdhelmforgeVerified publisher1.0.112 of 4See more

netbird helmforge 1.0.11

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9
netbirdio/netbird-server:0.79.0d1da0c0179c9
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

3,468
simple-krr-dashboardhelm-simple-krr-dashboardVerified publisher1.6.21 of 3See more

simple-krr-dashboard helm-simple-krr-dashboard 1.6.2

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

2,970
helm-watchdog-pod-deletehelm-watchdog-pod-delete0.3.01 of 1See more

helm-watchdog-pod-delete helm-watchdog-pod-delete 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,664
hermes-agenthermes-agentVerified publisher1.18.01 of 1See more

hermes-agent hermes-agent 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
stdlib@go1.24.4
1.26.9

Open the chart page →

6,976
home-assistanthome-assistantVerified publisher0.5.132 of 3See more

home-assistant home-assistant 0.5.13

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/nats:2.15.0-scratchc0d27f305460
stdlib@go1.27.1
1.27.2
ghcr.io/home-assistant/home-assistant:2026.10.01b64d38f38d9
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

3,015
keycloak-operatorhostzero-keycloak-operator0.13.11 of 1See more

keycloak-operator hostzero-keycloak-operator 0.13.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/hostzero-gmbh/keycloak-operator:v0.13.1ab4ee2b45444
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

201
hpe-cosi-driverhpe-storageVerified publisher2.0.02 of 2See more

hpe-cosi-driver hpe-storage 2.0.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
golang.org/x/net@v0.40.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

2,669
inference-manager-engineinference-manager-engine1.46.01 of 1See more

inference-manager-engine inference-manager-engine 1.46.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/inference-manager-engine:1.46.0c46f109c3d0b
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

628
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

3,759
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.21.31 of 5See more

infrahub-enterprise infrahub-enterprise 4.21.3

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9

Open the chart page →

12,725
inlets-operatorinlets0.17.201 of 1See more

inlets-operator inlets 0.17.20

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/inlets/inlets-operator:0.17.2208265c006973
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

884
coreinstill-aiOfficialVerified publisher0.1.757 of 15See more

core instill-ai 0.1.75

7 of the 15 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
stdlib@go1.18.3
0.60.0
1.26.9
library/postgres:15-alpinef7d23353e1b1
stdlib@go1.24.6
1.26.9
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.26.9
openfga/openfga:v1.9.25e94966c11df
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
temporalio/admin-tools:1.28cfde8170c92f
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

14,340

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
natsio/nats-server-config-reloader:0.24.0d758a82a9c20
stdlib@go1.26.5
1.26.9
1
natsio/nats-surveyor:0.9.9104a3e938b23
stdlib@go1.26.1
1.26.9
1
natsio/prometheus-nats-exporter:0.18.002469dc907bc
stdlib@go1.24.6
1.26.9
1
natsio/prometheus-nats-exporter:0.13.02adf791d9f9f
stdlib@go1.21.3
1.26.9
1
natsio/prometheus-nats-exporter:0.9.14665cdc7e749
stdlib@go1.16.13
1.26.9
1
natsio/prometheus-nats-exporter:0.20.14fbf6dacb847
stdlib@go1.26.3
1.26.9
1
natsio/prometheus-nats-exporter:0.19.25387a5923572
stdlib@go1.25.6
1.26.9
1
natsio/prometheus-nats-exporter:0.16.054b0d7ff058e
stdlib@go1.23.4
1.26.9
1
natsio/prometheus-nats-exporter:0.10.1bce728062c4f
stdlib@go1.19.3
1.26.9
1
ncabatoff/process-exporter6f0549dc24e9
golang.org/x/net@v0.33.0
stdlib@go1.23.1
0.60.0
1.26.9
1
neo4j/helm-charts-reverse-proxy:2026.09.00c6c9ee5f7dc
stdlib@go1.24.13
1.26.9
1
neosmemo/memos:0.293e1253477066
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9
1
neosmemo/memos:0.26.23eefcc231141
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
1
neosmemo/memos:0.24c6defc2dfb98
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9
1
neosu/kubebadges:v0.0.5256530d8e5c6
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
1
nerzhul/mc-arm64:2020.10.034215df511f31
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.2
0.60.0
1.26.9
1
netapp/controller:25.11.0-bxp-preview06f6c9a0653f
golang.org/x/net@v0.39.0
stdlib@go1.24.9
0.60.0
1.26.9
1
netapp/controller:26.09.0-console46a0066e1cf6
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
1
netapp/controller:26.06.08235a77cfc92
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
1
netapp/trident-operator:21.10.049cfe552d9c2
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9
1
netapp/trident-operator:26.06.24cef5a737bcf
golang.org/x/net@v0.59.0
0.60.0
1
netapp/trident-protect-connector:26.09.0-consolea982458a70f7
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
1
netapp/trident-protect-connector:25.11.0-bxp-previewec22fc6e5c5a
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.60.0
1.26.9
1
netapp/trident-protect-utils:v1.0.058b9fac358bd
golang.org/x/net@v0.38.0
stdlib@go1.24.8
0.60.0
1.26.9
1
netapp/trident-protect-utils:v3.0.0cad26cd945d1
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9
1
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
golang.org/x/net@v0.40.0
stdlib@go1.24.12
0.60.0
1.26.9
1
netbirdio/kubernetes-operator:0.3.157740157b4d7
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
1
netbirdio/management:0.45.10c9994b393ea
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
netbirdio/management:0.60.252682e5f48f9
golang.org/x/net@v0.42.0
stdlib@go1.23.12
0.60.0
1.26.9
1
netbirdio/management:latest8bb1b26f3c8d
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
netbirdio/management:0.46.0b0adc4ad4ec6
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
netbirdio/netbird-server:0.78.2ac6317722f6f
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
netbirdio/netbird-server:0.79.0d1da0c0179c9
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
netbirdio/relay:latest1aff236dc73f
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
netbirdio/relay:0.45.1872e3add0e1e
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
netbirdio/relay:0.60.2a10762533793
golang.org/x/net@v0.42.0
stdlib@go1.23.12
0.60.0
1.26.9
1
netbirdio/relay:0.46.0d32f82514a24
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
netbirdio/reverse-proxy:0.72.43104d5ca3a76
golang.org/x/net@v0.53.0
stdlib@go1.25.11
0.60.0
1.26.9
1
netbirdio/signal:0.45.146ce5a45538f
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
netbirdio/signal:0.60.267176bcbf6ab
golang.org/x/net@v0.42.0
stdlib@go1.23.12
0.60.0
1.26.9
1
netbirdio/signal:latestd0fe9d51cdba
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
netbirdio/signal:0.46.0e8f392611152
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
stdlib@go1.26.5
1.26.9
1
netdata/netdata:v2.12.01e50cc0b11f0
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2
1
nethermind/nethermind:latest25f72063f6fc
stdlib@go1.26.7
1.26.9
1
netrisai/bare-metal-dpu-agent:4.7.0.003c271efe749d0
golang.org/x/net@v0.50.0
stdlib@go1.26.1
0.60.0
1.26.9
1
netrisai/controller-grpc:4.6.0.00753178bf173c2
golang.org/x/net@v0.23.0
stdlib@go1.25.6
0.60.0
1.26.9
1
netrisai/controller-telescope:4.6.0.00414d82948a8b2
stdlib@go1.25.6
1.26.9
1
netrisai/controller-web-session-generator:0.2.0a030a31289f4
stdlib@go1.14.15
1.26.9
1
netrisai/mariadb:10.11.4-debian-11-r460aa742a0b906
stdlib@go1.19.11
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.