StackRadar

CVE-2026-78669

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

Excessive CPU consumption from repeated initial window changes in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-3w4w-29g2-36g3CGA-4qjh-92j9-97fjCGA-76xr-xqfv-pj8rCGA-g6hf-4469-c7p8CGA-jxch-2x88-v4q3CGA-qj25-vfjp-rv4qDEBIAN-CVE-2026-78669GO-2026-6611
Also known as
CGA-33c5-5cfp-cvjx, CGA-3p87-5j3f-57xf, CGA-4fh2-gw9f-8fg8, CGA-4vpq-gwh4-vfh6, CGA-4xr3-wh4x-pgmw, CGA-67cj-prf6-6vgf, CGA-6cfh-5jqc-77x8, CGA-9qq7-44jw-h2p7, CGA-9vww-99xm-r24g, CGA-9w4c-68w5-r52f, CGA-c8vj-2gvm-vvx5, CGA-cvch-844x-r5jh, CGA-fx99-c5qv-v64f, CGA-gc3w-prcc-jwc9, CGA-j22p-m6q6-9jcj, CGA-jxq6-98g2-2pxv, CGA-m5rf-fj6p-qq2j, CGA-p59v-8mpx-gr9m, CGA-r8wv-qg84-pg9q, CGA-v628-qjv7-78rp, CGA-vwhx-47r5-26hf, CGA-w6c4-5355-g6w8, CGA-w74x-3c39-v8mc, CGA-wgfc-jqhq-h8pf, CGA-wh84-4hf6-r6xj, CGA-wwr2-qfhc-v9fj
Trending
Rank 3 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
agentareaagentareaVerified publisher0.0.268 of 17See more

agentarea agentarea 0.0.26

8 of the 17 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
agentarea/agentarea-events:latest71a89daaa2c6
stdlib@go1.25.14
1.26.9
agentarea/agentarea-mcp-manager:latest0e7e53fef298
golang.org/x/net@v0.58.0
stdlib@go1.25.14
0.60.0
1.26.9
agentarea/agentarea-mcp-runner:latest9030cc19a0fc
stdlib@go1.19.8
1.26.9
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.26.9
library/postgres:alpine77f585114c32
stdlib@go1.24.6
1.26.9
openfga/openfga:v1.18.036097b960f66
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.60.0
1.26.9
temporalio/auto-setup:1.29.15b3502a3b685
golang.org/x/net@v0.35.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

17,666
traefikaigisukVerified publisher0.1.11 of 1See more

traefik aigisuk 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/traefik:2.7.0-rc2b70710baceeb
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

3,870
ais-operatoraistoreVerified publisher4.1.01 of 1See more

ais-operator aistore 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
aistorage/ais-operator:v4.1.0151fc5b9f917
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

124
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.281 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.28

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
stdlib@go1.26.3
1.26.9

Open the chart page →

3,048
visa-k8s-controlleralba-visa-helm-charts1.0.01 of 1See more

visa-k8s-controller alba-visa-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
misalbasynchrotron/visa-k8s:latest48e4dcba8f6e
golang.org/x/net@v0.49.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

313
adguard-homealekcVerified publisher3.2.01 of 2See more

adguard-home alekc 3.2.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.79aba9e3bf0613
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

340
cloudflaredalekcVerified publisher1.9.01 of 1See more

cloudflared alekc 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.10.09b49eed8f628
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

548
alertmanager-discordalertmanagerdiscordVerified publisher0.3.21 of 1See more

alertmanager-discord alertmanagerdiscord 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
speckle/alertmanager-discord:latestf6221ff308e9
stdlib@go1.22.4
1.26.9

Open the chart page →

803
alertmanager-matrixalertmanager-matrixVerified publisher0.1.161 of 1See more

alertmanager-matrix alertmanager-matrix 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
silkeh/alertmanager_matrix:0.6.1900010497f8c
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

716
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
stdlib@go1.24.4
1.26.9

Open the chart page →

14,335
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.26.9

Open the chart page →

73,147
clearml-servingallegroaiVerified publisher1.6.26 of 9See more

clearml-serving allegroai 1.6.2

6 of the 9 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
stdlib@go1.19.6
1.26.9
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
stdlib@go1.18.2
1.26.9
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
jimmidyson/configmap-reload:v0.8.05af9d3041d12
stdlib@go1.19.2
1.26.9
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

25,342
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.26.9

Open the chart page →

6,132
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.26.9

Open the chart page →

9,605
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.60.0
1.26.9

Open the chart page →

3,937
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

2,937
cloudflare-operatorankra-chartsVerified publisher0.2.01 of 1See more

cloudflare-operator ankra-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
adyanth/cloudflare-operatordigest-pinned6b168dc237d5
golang.org/x/net@v0.39.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

911
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
stdlib@go1.24.4
1.26.9

Open the chart page →

7,608
upcloud-csiankra-chartsVerified publisher0.4.18 of 8See more

upcloud-csi ankra-charts 0.4.1

8 of the 8 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
golang.org/x/net@v0.43.0
stdlib@go1.23.12
0.60.0
1.26.9
ghcr.io/upcloudltd/upcloud-csidigest-pinned5af91c663788
golang.org/x/net@v0.48.0
stdlib@go1.24.13
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

22,421
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

1,905
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
golang.org/x/net@v0.20.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

4,174
anteonanteonVerified publisher2.6.45 of 13See more

anteon anteon 2.6.4

5 of the 13 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.60.0
1.26.9
ddosify/selfhosted_hammer:2.0.0181965edb12e
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.60.0
1.26.9
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.26.9
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
stdlib@go1.19.11
0.60.0
1.26.9

Open the chart page →

27,707
antreaantreaVerified publisher2.7.02 of 2See more

antrea antrea 2.7.0

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
golang.org/x/net@v0.58.0
stdlib@go1.25.7
0.60.0
1.26.9
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

4,769
api-usage-serverapi-usage-server1.16.01 of 1See more

api-usage-server api-usage-server 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,157
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

1,710
kubedb-opscenterappscodeVerified publisher2026.7.101 of 1See more

kubedb-opscenter appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-ui-server:v0.42.0e93dfe7454d4
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

484
kubedb-provisionerappscodeVerified publisher0.66.01 of 1See more

kubedb-provisioner appscode 0.66.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-provisioner:v0.66.0e7041c3b41e7
golang.org/x/net@v0.55.0
stdlib@go1.25.13
0.60.0
1.26.9

Open the chart page →

932
scannerappscodeVerified publisher2026.1.153 of 3See more

scanner appscode 2026.1.15

3 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/net@v0.26.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

7,093
smtprelayappscodeVerified publisher2026.9.111 of 1See more

smtprelay appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/net@v0.34.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,332
stash-enterpriseappscodeVerified publisher0.42.04 of 4See more

stash-enterprise appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
stdlib@go1.24.9
0.60.0
1.26.9
ghcr.io/stashed/stash-crd-installer:v0.42.1d6c9b7a1f7b8
golang.org/x/net@v0.38.0
stdlib@go1.25.5
0.60.0
1.26.9
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
golang.org/x/net@v0.38.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

5,874
virtual-secrets-serverappscodeVerified publisher2026.8.141 of 1See more

virtual-secrets-server appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/appscode/virtual-secrets-server:v0.4.0efa03f4c9551
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

536
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

6,543
argocd-rbac-operatorargocd-rbac-operator0.4.51 of 1See more

argocd-rbac-operator argocd-rbac-operator 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-rbac-operator:v0.2.451dded00137a
golang.org/x/net@v0.40.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

1,372
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

3,573
s3dartur9010Verified publisher1.0.11 of 1See more

s3d artur9010 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
golang.org/x/net@v0.53.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

2,204
arvancloud-webhookarvancloud-webhookVerified publisher1.0.11 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.1e58c98b4d28a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

787
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.15
0.60.0
1.26.9

Open the chart page →

3,949
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
stdlib@go1.18.2
1.26.9

Open the chart page →

20,328
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.60.0
1.26.9

Open the chart page →

12,404
dltbrokerassist-iot-distributed-broker0.2.05 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.60.0
1.26.9
hyperledger/fabric-ca:latesta70b6ba64a08
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

196,309
dltloggingassist-iot-logging-auditing0.2.05 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.13
0.60.0
1.26.9
hyperledger/fabric-ca:latesta70b6ba64a08
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

196,289
astradnsastradnsVerified publisher0.2.92 of 2See more

astradns astradns 0.2.9

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
golang.org/x/net@v0.51.0
stdlib@go1.26.1
0.60.0
1.26.9
ghcr.io/astradns/astradns-operator:v0.2.909e58b62416a
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

3,575
deployautoml0.1.02 of 3See more

deploy automl 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.26.9
muonsoft/openapi-mock:latestc9afe1295484
stdlib@go1.20.2
1.26.9

Open the chart page →

4,341
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
stdlib@go1.17.5
0.60.0
1.26.9

Open the chart page →

5,411
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

4,543
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.18.1
0.60.0
1.26.9

Open the chart page →

4,786
prismav1o-chartsVerified publisher0.3.11 of 1See more

prism av1o-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.26.9

Open the chart page →

2,248
avahi-controlleravahi-controllerVerified publisher0.1.191 of 1See more

avahi-controller avahi-controller 0.1.19

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/mm503/avahi-controller:0.6.42207e2ae2179
golang.org/x/net@v0.57.0
0.60.0

Open the chart page →

35
kubebrowseravistoOfficialVerified publisher1.4.01 of 1See more

kubebrowser avisto 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/kubebrowser:0.10.0a354b8dc7e6a
golang.org/x/net@v0.47.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

1,111
azuredisk-csi-driverazuredisk-csi-driverVerified publisher1.36.07 of 8See more

azuredisk-csi-driver azuredisk-csi-driver 1.36.0

7 of the 8 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.36.00b4df214c178
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-attacher:v4.12.03aadb9baa021
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.17.0264963e21f6d
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v6.3.05c9423e1046a
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v2.2.1f755aeee7277
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-snapshotter:v8.6.01ca5b663e3dd
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.19.03eb866c2c773
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

997

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
l7mp/stunner-gateway-operator:devee34f1c04b9b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
2
langgenius/dify-sandbox:0.2.009b7e8705673
golang.org/x/net@v0.20.0
stdlib@go1.20.6
0.60.0
1.26.9
2
library/arangodb:3.11.81e75d74954a4
stdlib@go1.21.5
1.26.9
2
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.26.9
2
library/docker:dind:latest0b6d18a4a222
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
library/eclipse-temurin:213e3c176ffed1
stdlib@go1.26.7
1.26.9
2
library/ghost:6.69.055131b90d48c
stdlib@go1.24.6
1.26.9
2
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.60.0
1.26.9
2
library/influxdb:2.7b8d940ca9376
golang.org/x/net@v0.38.0
stdlib@go1.18.2
0.60.0
1.26.9
2
library/mariadb:10.8.30abf60f81588
stdlib@go1.16.7
1.26.9
2
library/mariadb:11.41292844148b3
stdlib@go1.24.6
1.26.9
2
library/mariadb:10.623616f0bd3af
stdlib@go1.24.6
1.26.9
2
library/mariadb:12.3.3:lts2bdff1534a7e
stdlib@go1.24.6
1.26.9
2
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.26.9
2
library/mariadb:12.0.2:12.0-noble607835cd628b
stdlib@go1.24.6
1.26.9
2
library/mariadb:11.3.2e101f9db3191
stdlib@go1.18.2
1.26.9
2
library/mongo:8.0.20098862b1339f
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
2
library/mongo:7.01f995ad6fdb9
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
library/mongo:5.041108d183e97
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
2
library/mongo:7.0-jammy:7-jammyf71f6d0913c9
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
library/mysql:8:8.4:8.4.110744ee5ef89c
stdlib@go1.24.6
1.26.9
2
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.26.9
2
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.26.9
2
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.26.9
2
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.26.9
2
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.26.9
2
library/nats:2.12.3-alpine88fe8e0e09d6
stdlib@go1.25.5
1.26.9
2
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.26.9
2
library/nats:2.15.0-scratchc0d27f305460
stdlib@go1.27.1
1.27.2
2
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.26.9
2
library/postgres:18.11090bc3a8ccf
stdlib@go1.24.6
1.26.9
2
library/postgres:17-bookworm3645570cccdf
stdlib@go1.24.6
1.26.9
2
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.26.9
2
library/postgres:18.3-alpine:18.3-alpine3.2354451ecb8ab3
stdlib@go1.24.6
1.26.9
2
library/postgres:18.06f3e42ad37de
stdlib@go1.24.6
1.26.9
2
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.26.9
2
library/postgres:17c6222b54873a
stdlib@go1.24.6
1.26.9
2
library/postgres:16ca0bd484cb98
stdlib@go1.24.6
1.26.9
2
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.26.9
2
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.26.9
2
library/postgres:13-alpinefb9065b6e3e2
stdlib@go1.24.6
1.26.9
2
library/rabbitmq:4.3.6-management:4-management8dd6e3570dda
stdlib@go1.22.2
1.26.9
2
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.26.9
2
library/redis148bb5411c18
stdlib@go1.18.2
1.26.9
2
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.26.9
2
library/redmine:6.1.3-trixief474a901faec
stdlib@go1.24.6
1.26.9
2
library/telegraf:1.40-alpine6606553b5019
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
library/traefik:v3.7.16b9cbca6fac4
golang.org/x/net@v0.53.0
stdlib@go1.25.10
0.60.0
1.26.9
2
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.