StackRadar

CVE-2026-78663

Critical

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-7r9c-ff6c-hxjjCGA-gghc-78jw-f5q2CGA-rp37-mxv6-g5fjDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-25j5-q798-fwm3, CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-vqxj-4gp6-23v9, CGA-w84h-9v6p-pf3x, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
nacosygqygq2Verified publisher2.1.102 of 4See more

nacos ygqygq2 2.1.10

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.26.9
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.26.9

Open the chart page →

7,181
sealed-secretsbitnamiVerified publisher2.5.191 of 1See more

sealed-secrets bitnami 2.5.19

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:0.31.0-debian-12-r074eaff41382b
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,132
mariadbcloudpirates-mariadbVerified publisher0.16.161 of 1See more

mariadb cloudpirates-mariadb 0.16.16

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mariadb:13.0.2f1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

1,834
difydoubanVerified publisher0.10.04 of 6See more

dify douban 0.10.0

4 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.26.9
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
golang.org/x/net@v0.42.0
stdlib@go1.25.5
0.60.0
1.26.9
langgenius/dify-sandbox:0.2.124e65e8a351a2
golang.org/x/net@v0.40.0
stdlib@go1.23.3
0.60.0
1.26.9
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.26.9

Open the chart page →

84,033
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.5.02 of 3See more

kubeshark kubeshark-helm-charts 53.5.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kubeshark/hub:v53.50532936678f8
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2
kubeshark/worker:v53.51f3e121224f8
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,434
secrets-store-csi-driversecret-store-csi-driver1.6.14 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/csi-secrets-store/driver-crds:v1.6.1cdacfdbe8966
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

3,259
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.31 of 2See more

stackgres-operator stackgres-charts 1.19.3

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9

Open the chart page →

3,130
victoria-logs-singlevictoriametricsVerified publisher0.13.101 of 1See more

victoria-logs-single victoriametrics 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.53.0251121fa882a
stdlib@go1.27.1
1.27.2

Open the chart page →

141
mongodbcloudpirates-mongodbVerified publisher0.20.01 of 1See more

mongodb cloudpirates-mongodb 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mongo:9.0.2bac22ea7710d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,322
kube-image-keeperenixVerified publisher2.3.11 of 1See more

kube-image-keeper enix 2.3.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/enix/kube-image-keeper:2.3.1d3ccf28495c3
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

306
mattermost-team-editionmattermostVerified publisher6.6.1081 of 4See more

mattermost-team-edition mattermost 6.6.108

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:11.11.16ad5912b4587
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

2,122
code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
stdlib@go1.16.4
1.26.9

Open the chart page →

18,237
opensearch-operatoropensearch-operatorVerified publisher3.0.141 of 1See more

opensearch-operator opensearch-operator 3.0.14

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
opensearchproject/opensearch-operator:3.0.099d4fb8144cd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

219
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

803
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
stdlib@go1.26.5
1.26.9

Open the chart page →

2,237
pulsarapache4.7.06 of 10See more

pulsar apache 4.7.0

6 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
grafana/grafana:12.4.1e932bd6ed0e0
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
victoriametrics/operator:v0.68.3f52e1bd679cb
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

13,529
miniocloudpirates-minioVerified publisher0.14.01 of 1See more

minio cloudpirates-minio 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,746
vertical-pod-autoscalercowboysysopVerified publisher11.1.14 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-admission-controller:1.5.19928d59477fb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.5.1e629c61b75eb
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.5.1cba2aa4b3239
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

9,338
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.26.9
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
langgenius/dify-api:1.16.1dcefa5f7c47c
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
langgenius/dify-sandbox:0.2.15750e1111426e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

75,334
eclipse-cheeclipse-cheVerified publisher7.123.01 of 1See more

eclipse-che eclipse-che 7.123.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.123.0d926b6d183a1
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,192
pyroscopegrafana2.4.02 of 3See more

pyroscope grafana 2.4.0

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/alloy:v1.19.2b8ec653c4423
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,915
botkubeinfracloudioVerified publisher1.14.01 of 1See more

botkube infracloudio 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.60.0
1.26.9

Open the chart page →

1,663
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,418
thanosthanos-communityOfficialVerified publisher0.47.11 of 1See more

thanos thanos-community 0.47.1

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

502
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.26.9

Open the chart page →

2,484
tetragonciliumOfficialVerified publisher1.7.12 of 3See more

tetragon cilium 1.7.1

2 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/cilium/tetragon-operator:v1.7.1cd8b71f6860e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

666
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

5,641
k6-operatorgrafana4.6.01 of 1See more

k6-operator grafana 4.6.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/grafana/k6-operator:controller-v1.6.0ba7f0fc1e22e
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

360
rabbitmqgroundhog2k2.3.91 of 2See more

rabbitmq groundhog2k 2.3.9

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6446551b26c0b
stdlib@go1.22.2
1.26.9

Open the chart page →

1,348
telegrafinfluxdata1.8.771 of 1See more

telegraf influxdata 1.8.77

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/telegraf:1.40-alpine6606553b5019
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

218
k8tzk8tzOfficialVerified publisher0.20.01 of 1See more

k8tz k8tz 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/k8tz/k8tz:0.20.0361628e53fc8
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

295
kiali-serverkiali2.33.01 of 1See more

kiali-server kiali 2.33.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/kiali/kiali:v2.33.0082246cfc99f
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

553
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

922
vela-corekubevela1.11.03 of 3See more

vela-core kubevela 1.11.0

3 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
oamdev/cluster-gateway:v1.9.0-alpha.25591e29d66a2
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
oamdev/kube-webhook-certgen:v2.4.1231c423c2b17
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.11
0.60.0
1.26.9
oamdev/vela-core:v1.11.095fa412c934e
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

6,891
oktetooktetoOfficialVerified publisher0.0.0-2026-08-317 of 10See more

okteto okteto 0.0.0-2026-08-31

7 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/okteto/backend:0.0.0-2026-08-316171cb2b2a72
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.60.0
1.26.9
ghcr.io/okteto/buildkit:0.0.0-2026-08-3114527ca5d2a9
golang.org/x/net@v0.55.0
stdlib@go1.25.7
0.60.0
1.26.9
ghcr.io/okteto/daemon:0.0.0-2026-08-31c6e716a3fbbe
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-31d6730eb9831b
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/okteto/okteto:3.23.0-beta.1a0483d47ba04
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9
ghcr.io/okteto/registry:0.0.0-2026-08-3169131511501f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/okteto/reloader:0.0.0-2026-08-3104a3fce657c4
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

8,372
hydraory0.64.02 of 2See more

hydra ory 0.64.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

2,102
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

1,421
proxmox-csi-pluginproxmox-csi0.5.127 of 7See more

proxmox-csi-plugin proxmox-csi 0.5.12

7 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-csi-controller:v0.20.095ef74cce03e
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

4,090
victoria-metrics-singlevictoriametricsVerified publisher0.48.01 of 1See more

victoria-metrics-single victoriametrics 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
victoriametrics/victoria-metrics:v1.153.05eff7af5341e
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

214
yourlsyourlsOfficialVerified publisher8.10.51 of 2See more

yourls yourls 8.10.5

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9

Open the chart page →

2,685
apisix-ingress-controllerapisix1.4.01 of 2See more

apisix-ingress-controller apisix 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

2,334
volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,931
concourseconcourseVerified publisher20.3.12 of 2See more

concourse concourse 20.3.1

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
concourse/concourse:8.3.1c9d48dfbf4f9
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9

Open the chart page →

2,344
dynatrace-operatordynatraceVerified publisher1.11.01 of 1See more

dynatrace-operator dynatrace 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.11.05b772cfaad48
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

227
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.60.0
1.26.9

Open the chart page →

5,404
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

2,507
oncallgrafana1.16.57 of 12See more

oncall grafana 1.16.5

7 of the 12 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

23,769
k8sgpt-operatork8sgptOfficialVerified publisher0.2.292 of 2See more

k8sgpt-operator k8sgpt 0.2.29

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.2982d0adcce816
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,806
node-feature-discoverynode-feature-discoveryOfficialVerified publisher0.19.01 of 1See more

node-feature-discovery node-feature-discovery 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

557
openprojectopenproject-helm-chartsOfficialVerified publisher13.13.11 of 5See more

openproject openproject-helm-charts 13.13.1

1 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9

Open the chart page →

21,974

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.60.0
1.26.9
1
platzio/backend:v0.6.5d5e5972f344b
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.60.0
1.26.9
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
stdlib@go1.21.2
1.26.9
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.12
0.60.0
1.26.9
1
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
stdlib@go1.13.10
1.26.9
1
pnnlmiscscripts/pixiecore:1.0.1-1c6f17741a0d7
golang.org/x/net@v0.7.0
stdlib@go1.24.1
0.60.0
1.26.9
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
golang.org/x/net@v0.48.0
stdlib@go1.19.13
0.60.0
1.26.9
1
polyaxon/training-operator:2.1.0b5b29deaec9a
golang.org/x/net@v0.17.0
stdlib@go1.20.13
0.60.0
1.26.9
1
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/net@v0.9.0
stdlib@go1.20.3
0.60.0
1.26.9
1
pomerium/verify:latestaf9ac2c98007
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
portainer/portainer-ce:2.45.203f94a406496
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.60.0
1.26.9
1
posit/package-manager:2026.09.0-ubuntu-24.04641d5874ccd3
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2
1
postfinance/kubenurse:v1.15.4f76ce08ab7b4
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
stdlib@go1.18.2
1.26.9
1
postgis/postgis:18-3.67e00e8c3539f
stdlib@go1.24.6
1.26.9
1
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.26.9
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
stdlib@go1.13.12
0.60.0
1.26.9
1
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.9
0.60.0
1.26.9
1
prathamkrishna/dicedb:v1a7298180cd24
stdlib@go1.23.2
1.26.9
1
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.60.0
1.26.9
1
pritunl/pritunl-zero:1.0.3648.460f2943e0d41b
golang.org/x/net@v0.42.0
stdlib@go1.25.4
0.60.0
1.26.9
1
probely/farcaster-onprem-agent:v3741b34e8166f
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
stdlib@go1.16
1.26.9
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
stdlib@go1.22.6
1.26.9
1
projectdiscovery/nuclei:v3.5.1d76713284ad0
golang.org/x/net@v0.46.0
stdlib@go1.24.4
0.60.0
1.26.9
1
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
stdlib@go1.19.3
0.60.0
1.26.9
1
projectsveltos/access-manager:v1.16.03518240977ab
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/addon-controller:v1.16.0459452358fce
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/classifier:v1.16.0b738da42f6c4
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/crd-manager:v1.16.0b723bd22df0b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/event-manager:v1.16.0f5a52803beba
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/healthcheck-manager:v1.16.0564304068dd7
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/mcp-server:v1.16.0349d9fd4f265
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/register-mgmt-cluster:v1.16.03d7639cd680f
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/shard-controller:v1.16.07d31160f4aef
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/sveltoscluster-manager:v1.16.012b498869a16
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/techsupport:v1.16.04e12d6454ace
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
projectsveltos/ui-backend:v1.16.1f6fa338637eb
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
prom/blackbox-exporter:v0.22.0608acee5704a
golang.org/x/net@v0.0.0-20220728211354-c7608f3a8462
stdlib@go1.18.5
0.60.0
1.26.9
1
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9
1
prom/consul-exporter:v0.13.04e4cfd809e96
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
1
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.26.9
1
prometheuscommunity/postgres-exporter:v0.17.0f8381eb4326a
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9
1
prometheuscommunity/pushprox:v0.2.02f32058f4fae
stdlib@go1.22.1
1.26.9
1
prometheuscommunity/stackdriver-exporter:v0.19.0c0a0cbf76570
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
prom/graphite-exporter:v0.16.0e54bca6645ea
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9
1
prom/influxdb-exporter:v0.11.427e33e18634a
stdlib@go1.19.9
1.26.9
1
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.