StackRadar

CVE-2026-78663

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

Double flow control refund on HTTP/2 server streams in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-25j5-q798-fwm3CGA-2gqg-cwwv-gpq8CGA-47rc-6mj7-j49qCGA-52wv-3w8x-88q8CGA-gghc-78jw-f5q2CGA-w84h-9v6p-pf3xDEBIAN-CVE-2026-78663GO-2026-6612
Also known as
CGA-34ww-96mj-f68f, CGA-496v-v9f7-gg5g, CGA-63wp-c4jp-8rp3, CGA-69c7-fg3r-x52j, CGA-6q57-jhhm-h4wv, CGA-7h68-428w-v8rx, CGA-7r9c-ff6c-hxjj, CGA-83p5-fjgf-7f3c, CGA-8657-wr97-3mfx, CGA-92vv-8vvj-9395, CGA-9fgf-3526-83c2, CGA-9vvh-3x7q-fg3m, CGA-cx87-7wm6-85w4, CGA-frvr-2pgq-38cg, CGA-g5vc-6qvm-vhqf, CGA-mmhx-33v2-g868, CGA-qq63-42gf-c64c, CGA-r8gj-3cwq-xgqj, CGA-r8gm-456m-hwcc, CGA-rc2p-74g8-rgfr, CGA-rp37-mxv6-g5fj, CGA-vqxj-4gp6-23v9, CGA-wfqc-4mv3-qjv3, CGA-wjfh-8wph-66g7, CGA-x3qg-fv98-5j72, CGA-x57q-8qv6-g2j7
Trending
Rank 1 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
mpi-operatorcowboysysopVerified publisher1.2.21 of 1See more

mpi-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.15.13
0.60.0
1.26.9

Open the chart page →

3,801
notebook-controllercowboysysopVerified publisher1.1.21 of 1See more

notebook-controller cowboysysop 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.15.15
0.60.0
1.26.9

Open the chart page →

3,841
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
stdlib@go1.13.1
1.26.9

Open the chart page →

6,997
rediscowboysysopVerified publisher21.2.61 of 1See more

redis cowboysysop 21.2.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.0.2-debian-12-r4cdc2efa9c306
stdlib@go1.24.4
1.26.9

Open the chart page →

3,215
training-operatorcowboysysopVerified publisher1.2.21 of 1See more

training-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.9
0.60.0
1.26.9

Open the chart page →

3,430
crashloop-operatorcrashloop-operator0.0.61 of 1See more

crashloop-operator crashloop-operator 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/yeonghoo2/crashloop-operator:0.0.6565d1115e6bd
golang.org/x/net@v0.13.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

893
chalkularcrashoverride-helm-chartsVerified publisher0.0.81 of 1See more

chalkular crashoverride-helm-charts 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/chalkular-controller:v0.0.8d31986456626
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

195
pod-killercriblio1.0.01 of 1See more

pod-killer criblio 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

141
crossplane-controllerscrossplane0.12.01 of 1See more

crossplane-controllers crossplane 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
crossplane/crossplane:v0.12.066666e6963af
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.60.0
1.26.9

Open the chart page →

3,490
oam-kubernetes-runtimecrossplane0.0.3-71.g0f235901 of 2See more

oam-kubernetes-runtime crossplane 0.0.3-71.g0f23590

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.14
0.60.0
1.26.9

Open the chart page →

3,409
oam-kubernetes-runtime-legacycrossplane0.3.1-5.g11e18941 of 1See more

oam-kubernetes-runtime-legacy crossplane 0.3.1-5.g11e1894

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

3,379
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.2
0.60.0
1.26.9

Open the chart page →

5,834
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

4,253
electric-mailcryptexlabsVerified publisher0.0.12 of 5See more

electric-mail cryptexlabs 0.0.1

2 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.60.0
1.26.9
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.60.0
1.26.9

Open the chart page →

8,196
iam-zencryptexlabsVerified publisher0.12.232 of 4See more

iam-zen cryptexlabs 0.12.23

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

4,745
purple-piecryptexlabsVerified publisher0.0.12 of 4See more

purple-pie cryptexlabs 0.0.1

2 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.60.0
1.26.9
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.60.0
1.26.9

Open the chart page →

8,196
pagescrypticcode-helmchart1.0.01 of 3See more

pages crypticcode-helmchart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
agent-sandboxcsghubVerified publisher0.5.61 of 1See more

agent-sandbox csghub 0.5.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.6dc23fb0d5624
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

166
csghubcsghubVerified publisher2.5.025 of 34See more

csghub csghub 2.5.0

25 of the 34 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
library/nats:2.12.150764f1952d72
stdlib@go1.25.12
1.26.9
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.26.9
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
stdlib@go1.19.8
1.26.9
opencsghq/csgbot:v0.6.9-ee7d0271e26521
stdlib@go1.24.4
1.26.9
opencsghq/csghub-portal:v2.5.0-ee1cb36b49151e
golang.org/x/net@v0.28.0
stdlib@go1.23.3
0.60.0
1.26.9
opencsghq/csghub-server:v2.5.0-ee587046575c2c
golang.org/x/net@v0.57.0
stdlib@go1.26.0
0.60.0
1.26.9
opencsghq/csghub-xnet:v2.5.0-ee86ea22f495c7
golang.org/x/net@v0.39.0
stdlib@go1.24.10
0.60.0
1.26.9
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.60.0
1.26.9
opencsghq/gitlab-shell:v19.2.580a65ac370da
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
opencsghq/kube-state-metrics:v2.19.15ea147562ec8
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
opencsghq/lws:v0.6.1de15437db41b
golang.org/x/net@v0.37.0
stdlib@go1.24.0
0.60.0
1.26.9
opencsghq/postgres:15.19b98600564e07
stdlib@go1.24.6
1.26.9
opencsghq/prometheus:v3.13.00aac0d04749e
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
opencsghq/prometheus-config-reloader:v0.92.144e6ec00729b
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
opencsghq/stakater-reloader:v1.4.190491782f7bac
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
temporalio/admin-tools:1.32.0a9f84fb9a374
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
temporalio/server:1.32.0c3e752127759
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/operator/cmd/operator:v1.22.3733f21dc06f9
golang.org/x/net@v0.53.0
stdlib@go1.26.4
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/operator/cmd/webhook:v1.22.366ae76179a80
golang.org/x/net@v0.53.0
stdlib@go1.26.4
0.60.0
1.26.9
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
quay.io/argoproj/workflow-controller:v3.7.11c46aa0ded8ed
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.4be477ba317d8
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

62,708
csgshipcsghubVerified publisher0.4.64 of 10See more

csgship csghub 0.4.6

4 of the 10 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
golang.org/x/net@v0.49.0
stdlib@go1.25.8
0.60.0
1.26.9
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
opencsghq/postgres:15.19b98600564e07
stdlib@go1.24.6
1.26.9
opencsghq/stakater-reloader:v1.4.190491782f7bac
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

14,073
dataflowcsghubVerified publisher2.5.03 of 7See more

dataflow csghub 2.5.0

3 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
opencsghq/postgres:15.19b98600564e07
stdlib@go1.24.6
1.26.9
opencsghq/stakater-reloader:v1.4.190491782f7bac
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

8,674
ocscsic-charts1.0.01 of 4See more

ocs csic-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

2,321
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.60.0
1.26.9

Open the chart page →

7,684
rtcsic-charts0.1.12 of 5See more

rt csic-charts 0.1.1

2 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
golang.org/x/net@v0.5.0
stdlib@go1.19.6
0.60.0
1.26.9
library/postgres:13.11-bullseye5c265bf1fd30
stdlib@go1.18.2
1.26.9

Open the chart page →

17,709
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
golang.org/x/net@v0.5.0
stdlib@go1.18.9
0.60.0
1.26.9

Open the chart page →

15,964
csi-driver-ipfscsi-driver-ipfs0.2.06 of 6See more

csi-driver-ipfs csi-driver-ipfs 0.2.0

6 of the 6 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

5,669
ipfs-clustercsi-driver-ipfs0.2.02 of 2See more

ipfs-cluster csi-driver-ipfs 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ipfs/ipfs-cluster:v1.1.6a83266c524f1
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
ipfs/kubo:v0.41.00661819c2e09
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

2,609
cursor-admin-api-exportercursor-admin-api-exporterVerified publisher0.1.91 of 1See more

cursor-admin-api-exporter cursor-admin-api-exporter 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/matanbaruch/cursor-admin-api-exporter:0.1.8ba3a29fc479a
stdlib@go1.24.5
1.26.9

Open the chart page →

997
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.8
0.60.0
1.26.9

Open the chart page →

1,992
custom-rhcl-consolecustom-rhcl-consoleVerified publisher0.1.21 of 3See more

custom-rhcl-console custom-rhcl-console 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:latest10fef10863a3
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

2,345
cw-container-insightcwci0.7.01 of 1See more

cw-container-insight cwci 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:latest-arm6432bd729ab859
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

401
cloudflaredcyberjakeVerified publisher0.3.201 of 1See more

cloudflared cyberjake 0.3.20

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.6.16d91c121b803
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,009
irods-csi-drivercyverse0.12.24 of 4See more

irods-csi-driver cyverse 0.12.2

4 of the 4 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cyverse/irods-csi-driver:v0.12.2c5877ea80e0e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
golang.org/x/net@v0.17.0
stdlib@go1.20.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

7,730
domain-exporterd0main-exp0rter0.1.01 of 1See more

domain-exporter d0main-exp0rter 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.2
0.60.0
1.26.9

Open the chart page →

2,613
jupyterhubd4nVerified publisher3.3.73 of 7See more

jupyterhub d4n 3.3.7

3 of the 7 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
golang.org/x/net@v0.7.0
stdlib@go1.22.5
0.60.0
1.26.9
quay.io/jupyterhub/k8s-image-awaiter:3.3.7ada70832a345
stdlib@go1.18.10
1.26.9
registry.k8s.io/kube-scheduler:v1.28.1146cf7475c8da
golang.org/x/net@v0.23.0
stdlib@go1.21.11
0.60.0
1.26.9

Open the chart page →

19,784
heimdalldadrus-heimdall0.16.231 of 1See more

heimdall dadrus-heimdall 0.16.23

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/dadrus/heimdall:0.17.23deb6931bd162
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
daejeon_2-3daejeon2-30.1.01 of 2See more

daejeon_2-3 daejeon2-3 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-for-fluent-bit:stableaee01ceceb6c
stdlib@go1.27.1
1.27.2

Open the chart page →

1,231
dagster-prometheus-exporterdagster-prometheus-exporterVerified publisher0.1.101 of 1See more

dagster-prometheus-exporter dagster-prometheus-exporter 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/hirofumitsuda/dagster-prometheus-exporter:0.6.147b0b6b2a8c1
stdlib@go1.26.8
1.26.9

Open the chart page →

102
pagesdalston-pages1.0.01 of 3See more

pages dalston-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
pagesdaman-dell-kuber1.0.01 of 3See more

pages daman-dell-kuber 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
damap-chartdamapVerified publisher0.3.12 of 5See more

damap-chart damap 0.3.1

2 of the 5 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8f29984bd1e22
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
library/postgres:16ca0bd484cb98
stdlib@go1.24.6
1.26.9

Open the chart page →

19,069
cloudflareddamounVerified publisher3.3.01 of 1See more

cloudflared damoun 3.3.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.5.05d5f70a59d5e
golang.org/x/net@v0.25.0
stdlib@go1.22.2-devel-cf
0.60.0
1.26.9

Open the chart page →

1,947
gickupdamounVerified publisher1.11.01 of 1See more

gickup damoun 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
buddyspencer/gickup:0.10.309e7dbf923c12
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.60.0
1.26.9

Open the chart page →

1,538
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
stdlib@go1.17.1
1.26.9

Open the chart page →

7,472
speedtest-exporterdamounVerified publisher1.0.61 of 1See more

speedtest-exporter damoun 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
stdlib@go1.16.6
1.26.9

Open the chart page →

2,127
nvidia-gpu-exporterdanchevVerified publisher1.0.31 of 1See more

nvidia-gpu-exporter danchev 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
ghcr.io/utkuozdemir/nvidia_gpu_exporter:1.5.0d75967a4dd72
golang.org/x/net@v0.40.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,719
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16
0.60.0
1.26.9

Open the chart page →

4,732
dapr-agentsdapr-agents-devVerified publisher0.1.520 of 31See more

dapr-agents dapr-agents-dev 0.1.5

20 of the 31 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
grafana/grafana:12.3.39e1e77ade304
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
grafana/loki:3.6.5847c287ada0e
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
grafana/loki-canary:3.6.5fbb984bab741
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
grafana/tempo:2.9.065a578975943
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9
mcp/grafana:latest9362bcf6aa0e
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
otel/opentelemetry-collector-contrib:0.145.0a7343f018690
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/dapr/injector:1.17.0-rc.37a2fd888ed5f
golang.org/x/net@v0.48.0
stdlib@go1.24.11
0.60.0
1.26.9
ghcr.io/dapr/operator:1.17.0-rc.3d5cc61cbe735
golang.org/x/net@v0.48.0
stdlib@go1.24.11
0.60.0
1.26.9
ghcr.io/dapr/placement:1.17.0-rc.3a237b43cd5c6
golang.org/x/net@v0.48.0
stdlib@go1.24.11
0.60.0
1.26.9
ghcr.io/dapr/scheduler:1.17.0-rc.36c62e01e736b
golang.org/x/net@v0.48.0
stdlib@go1.24.11
0.60.0
1.26.9
ghcr.io/dapr/sentry:1.17.0-rc.3bf79b03591e0
golang.org/x/net@v0.48.0
stdlib@go1.24.11
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.7.7b18964551d8e
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.60.0
1.26.9
ghcr.io/kagent-dev/kagent/tools:0.0.13c8882543f693
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.60.0
1.26.9
ghcr.io/kagent-dev/kmcp/controller:0.2.283276357d448
golang.org/x/net@v0.30.0
stdlib@go1.24.11
0.60.0
1.26.9
public.ecr.aws/diagrid-dev/diagrid-dashboard:latestf1348a65664a
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.88.1d3d65efa3bee
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

30,817
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
library/postgres:1665b16a8b326e
stdlib@go1.24.6
1.26.9

Open the chart page →

3,939
dns-mesh-controllerdashdns2.0.82 of 2See more

dns-mesh-controller dashdns 2.0.8

2 of the 2 container images this version deploys carry CVE-2026-78663.

Container imageDigestPackageFixed in
emirozbir/dashdns-admission-webhook:v2.0.56801ba2a3fc3
golang.org/x/net@v0.47.0
stdlib@go1.25.8
0.60.0
1.26.9
emirozbir/dashdns-controller:v2.0.5d3a5c1063425
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,748

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.60.0
1.26.9
3
natsio/nats-account-server:1.0.0a3381560aab6
stdlib@go1.16.6
1.26.9
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.26.9
3
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.26.9
3
oamdev/kube-webhook-certgen:v2.4.1231c423c2b17
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.11
0.60.0
1.26.9
3
oliver006/redis_exporter:v1.93.06ca518a72f30
stdlib@go1.27.1
1.27.2
3
opencsghq/postgres:15.19b98600564e07
stdlib@go1.24.6
1.26.9
3
opencsghq/stakater-reloader:v1.4.190491782f7bac
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
3
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
3
openebs/provisioner-localpv:3.5.0aea39e49bb97
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
3
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.60.0
1.26.9
3
otel/opentelemetry-collector:latest310a800ad69e
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
pgsty/silo:RELEASE.2026-09-03T13-18-01Zb616a0cf8cb2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
3
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
3
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
3
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.60.0
1.26.9
3
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.26.9
3
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.26.9
3
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.26.9
3
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.26.9
3
qingcloud/cloud-controller-manager:v1.4.1210f66b5df886
stdlib@go1.18.2
1.26.9
3
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.60.0
1.26.9
3
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
3
rancher/system-upgrade-controller:v0.20.261b68d4372ba
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
3
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.26.9
3
solace/solace-pubsub-standard:latest3c8a8b7fdcae
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.60.0
1.26.9
3
tykio/tyk-dashboard:v5.13.21161bd297135
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
tykio/tyk-gateway-ee:v5.13.250b3e4f5398a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
3
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
3
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.26.9
3
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/net@v0.27.0
stdlib@go1.23.4
0.60.0
1.26.9
3
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.26.9
3
yugabytedb/yugabyte:2026.1.2.0-b137b6dba322c734
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
gcr.io/trillian-opensource-ci/db_server2a685a38dd01
stdlib@go1.18.2
1.26.9
3
ghcr.io/appscode/petset:v0.1.093fa0daf603c
golang.org/x/net@v0.47.0
stdlib@go1.25.10
0.60.0
1.26.9
3
ghcr.io/appscode/sidekick:v0.0.15d1036b07e348
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9
3
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.60.0
1.26.9
3
ghcr.io/coder/coder:v2.38.038a4cfc548b0
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9
3
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.60.0
1.26.9
3
ghcr.io/external-secrets/external-secrets:v2.12.07a3c4f7e038f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
3
ghcr.io/hatchet-dev/hatchet/hatchet-admin:v0.110.57c233e606095
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/hatchet-dev/hatchet/hatchet-api:v0.110.5be06a6b88299
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/hatchet-dev/hatchet/hatchet-frontend:v0.110.5136c6a29a81a
stdlib@go1.26.8
1.26.9
3
ghcr.io/hatchet-dev/hatchet/hatchet-migrate:v0.110.5b2112d73f37a
stdlib@go1.26.8
1.26.9
3

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.