StackRadar

CVE-2026-78669

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

Excessive CPU consumption from repeated initial window changes in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
DEBIAN-CVE-2026-78669GO-2026-6611CGA-3w4w-29g2-36g3CGA-4qjh-92j9-97fjCGA-76xr-xqfv-pj8rCGA-g6hf-4469-c7p8CGA-jxch-2x88-v4q3CGA-qj25-vfjp-rv4q
Also known as
CGA-33c5-5cfp-cvjx, CGA-3p87-5j3f-57xf, CGA-4fh2-gw9f-8fg8, CGA-4vpq-gwh4-vfh6, CGA-4xr3-wh4x-pgmw, CGA-67cj-prf6-6vgf, CGA-6cfh-5jqc-77x8, CGA-9qq7-44jw-h2p7, CGA-9vww-99xm-r24g, CGA-9w4c-68w5-r52f, CGA-c8vj-2gvm-vvx5, CGA-cvch-844x-r5jh, CGA-fx99-c5qv-v64f, CGA-gc3w-prcc-jwc9, CGA-j22p-m6q6-9jcj, CGA-jxq6-98g2-2pxv, CGA-m5rf-fj6p-qq2j, CGA-p59v-8mpx-gr9m, CGA-r8wv-qg84-pg9q, CGA-v628-qjv7-78rp, CGA-vwhx-47r5-26hf, CGA-w6c4-5355-g6w8, CGA-w74x-3c39-v8mc, CGA-wgfc-jqhq-h8pf, CGA-wh84-4hf6-r6xj, CGA-wwr2-qfhc-v9fj
Trending
Rank 3 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
pagesberrutig-pages1.0.01 of 3See more

pages berrutig-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
trident-operatorberyju-org21.10.01 of 1See more

trident-operator beryju-org 21.10.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
netapp/trident-operator:21.10.049cfe552d9c2
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

3,125
betacalendars-calendar-boundary-labbetacalendars-calendar-boundary-labVerified publisher0.1.21 of 1See more

betacalendars-calendar-boundary-lab betacalendars-calendar-boundary-lab 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/mateopedersen/betacalendars-calendar-boundary-lab:1.0.043da2a255584
stdlib@go1.25.14
1.26.9

Open the chart page →

89
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
golang.org/x/net@v0.35.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

8,296
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
golang.org/x/net@v0.39.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

6,109
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

76,822
mx-notifierbicarus-labs1.1.91 of 1See more

mx-notifier bicarus-labs 1.1.9

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/net@v0.2.0
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

4,906
wg-access-serverbicarus-labs0.9.91 of 1See more

wg-access-server bicarus-labs 0.9.9

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/net@v0.0.0-20220418201149-a630d4f3e7a2
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

3,519
tenzu-frontbiru-scop3.1.01 of 1See more

tenzu-front biru-scop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,145
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/net@v0.10.0
stdlib@go1.21.1
0.60.0
1.26.9

Open the chart page →

3,080
stackbitpokeVerified publisher0.12.46 of 6See more

stack bitpoke 0.12.4

6 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.60.0
1.26.9
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.60.0
1.26.9
bitpoke/stack-default-backend:latestc5eed1ddf692
stdlib@go1.16.6
1.26.9
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.60.0
1.26.9

Open the chart page →

15,648
wordpress-operatorbitpokeVerified publisher0.12.41 of 1See more

wordpress-operator bitpoke 0.12.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.60.0
1.26.9

Open the chart page →

1,920
sm-operatorbitwarden2.0.31 of 1See more

sm-operator bitwarden 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/bitwarden/sm-operator:2.1.0846624161f32
golang.org/x/net@v0.53.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

829
baserowblackbird-cloudVerified publisher1.0.172 of 6See more

baserow blackbird-cloud 1.0.17

2 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
stdlib@go1.19.8
1.26.9
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9

Open the chart page →

12,094
prometheus-domain-exporterblackbox-domain-exporter1.0.01 of 1See more

prometheus-domain-exporter blackbox-domain-exporter 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

2,132
bdbablackduck2026.9.04 of 9See more

bdba blackduck 2026.9.0

4 of the 9 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
blackducksoftware/bdba-pgupgrader:2026.9.0b805c1f607e0
stdlib@go1.18.2
1.26.9
library/postgres:15.19-bookworm539ceaaae49b
stdlib@go1.24.6
1.26.9
library/rabbitmq:4.3.5078107e03637
stdlib@go1.22.2
1.26.9
versity/versitygw:v1.8.030292fc2eeac
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

10,220
blackduck-alertblackduck8.4.11 of 4See more

blackduck-alert blackduck 8.4.1

1 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert-db:8.4.1ad33e84750f1
stdlib@go1.24.6
1.26.9

Open the chart page →

2,074
firehoseblip-firehoseVerified publisher0.0.183 of 11See more

firehose blip-firehose 0.0.18

3 of the 11 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
blipai/deckard:0.0.28737d5d19a312
golang.org/x/net@v0.10.0
stdlib@go1.18.10
0.60.0
1.26.9
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

15,923
blob-csi-driverblob-csi-driverVerified publisher1.27.115 of 5See more

blob-csi-driver blob-csi-driver 1.27.11

5 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/blob-csi:v1.27.11ccb9e1dbe4b0
golang.org/x/net@v0.57.0
stdlib@go1.25.11
0.60.0
1.26.9
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.17.0760c61825d2a
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v6.3.0adfd47ab0160
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v2.2.13519c45b932d
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.19.06d065f238d39
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

936
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.26.9

Open the chart page →

16,628
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-nti:logc947c3629371
stdlib@go1.23.12
1.26.9

Open the chart page →

30,929
csi-driver-nfsbook-k8sinfra-v24.12.16 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

6 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.3.0bc7be893ecc3
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.17.09b75b9ade162
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
golang.org/x/net@v0.37.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

9,128
grafanabook-k8sinfra-v28.8.21 of 1See more

grafana book-k8sinfra-v2 8.8.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

2,337
jaegerbook-k8sinfra-v23.4.04 of 5See more

jaeger book-k8sinfra-v2 3.4.0

4 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.26.9
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

22,700
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.60.0
1.26.9

Open the chart page →

9,421
kube-prometheus-stackbook-k8sinfra-v265.5.15 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

5 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

8,793
metallbbook-k8sinfra-v20.13.102 of 3See more

metallb book-k8sinfra-v2 0.13.10

2 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

5,343
nfs-subdir-external-provisionerbook-k8sinfra-v24.0.181 of 1See more

nfs-subdir-external-provisioner book-k8sinfra-v2 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

3,917
prometheusbook-k8sinfra-v226.0.16 of 6See more

prometheus book-k8sinfra-v2 26.0.1

6 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.60.0
1.26.9
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

8,278
pyroscopebook-k8sinfra-v21.10.03 of 3See more

pyroscope book-k8sinfra-v2 1.10.0

3 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.60.0
1.26.9
grafana/pyroscope:1.10.0319bf32ae06b
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.60.0
1.26.9
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.26.9

Open the chart page →

4,797
redisbook-k8sinfra-v21.0.01 of 1See more

redis book-k8sinfra-v2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.26.9

Open the chart page →

2,795
tempobook-k8sinfra-v21.10.31 of 1See more

tempo book-k8sinfra-v2 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/net@v0.24.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

2,485
boundary-softsciboundary-softsci0.2.41 of 1See more

boundary-softsci boundary-softsci 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
hashicorp/boundary:latest76a201954ca0
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,277
branchdbbranch-dbVerified publisher0.1.42 of 3See more

branchdb branch-db 0.1.4

2 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/masucchi/branchdb:0.1.47ea1820c1da1
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/masucchi/branchdb-operator:0.1.4c16578615a43
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

924
bitmagnetbrandan-schmitz-helm-chartsVerified publisher1.0.62 of 2See more

bitmagnet brandan-schmitz-helm-charts 1.0.6

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.26.9
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

2,545
Filebrowserbrandan-schmitz-helm-chartsVerified publisher1.3.11 of 1See more

Filebrowser brandan-schmitz-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.63.15-s6dbac07403040
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,283
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
tautullibryanalves0.1.01 of 1See more

tautulli bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
tautulli/tautulli:latesta4323bc09b27
stdlib@go1.24.4
1.26.9

Open the chart page →

2,563
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

80,435
plexbryopsida0.2.01 of 1See more

plex bryopsida 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
linuxserver/plex:latest06e07af2851e
stdlib@go1.26.7
1.26.9

Open the chart page →

618
postgresqlbuall-charts0.1.21 of 1See more

postgresql buall-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
buall/postgres-stack:18.6881a785642cb
stdlib@go1.24.6
1.26.9

Open the chart page →

4,737
buildkitbuildkit0.1.01 of 1See more

buildkit buildkit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
moby/buildkit:master-rootlessf3864381e463
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

654
buildkit-privilegedbuildkit-privileged0.1.01 of 1See more

buildkit-privileged buildkit-privileged 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
moby/buildkit:mastere7c131019aa9
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

654
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mongo:latestbac22ea7710d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

12,261
pages-microservicebusi-adsVerified publisher1.0.01 of 3See more

pages-microservice busi-ads 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
butane-operatorbutane-operatorVerified publisher0.3.02 of 2See more

butane-operator butane-operator 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/naval-group/butane-operator:v0.1.1-rc285818b510780
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.60.0
1.26.9
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9

Open the chart page →

2,344
butlercibutlerciVerified publisher0.1.01 of 1See more

butlerci butlerci 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.60.0
1.26.9

Open the chart page →

3,634
accelerationbuttahtoastVerified publisher0.1.01 of 1See more

acceleration buttahtoast 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
goharbor/harbor-acceld:0.2.13451103a6c8d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

2,027

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
2
linuxserver/cloud9:latest:version-1.29.245c5fe102ff3
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.11
0.60.0
1.26.9
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9
2
listmonk/listmonk:latest:v6.2.0f535d59e1499
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.60.0
1.26.9
2
localstack/localstack-pro:latest801a3dff7f6a
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:nojsonv2
0.60.0
1.27.2
2
longhornio/longhorn-manager:v1.2.3dca34321452c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.1
0.60.0
1.26.9
2
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.60.0
1.26.9
2
louislam/uptime-kuma:2.3.29aeb4e51d038
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
2
louislam/uptime-kuma:2.5.5c74379ac4509
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9
2
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
golang.org/x/net@v0.40.0
stdlib@go1.24.5
0.60.0
1.26.9
2
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/net@v0.7.0
stdlib@go1.21.1
0.60.0
1.26.9
2
maxrocketinternet/datadog-controller:0.1a867315facf8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
2
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.26.9
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.60.0
1.26.9
2
mesosphere/kubectl:v1.35.0-alpineea01a9387771
golang.org/x/net@v0.43.0
stdlib@go1.25.5
0.60.0
1.26.9
2
mikefarah/yq:4:latest4b3d9475d655
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
moby/buildkit:v0.32.2-rootless504731e577c2
golang.org/x/net@v0.43.0
stdlib@go1.25.7
0.60.0
1.26.9
2
nacos/nacos-server:latest1c191c30c8cd
stdlib@go1.26.5
1.26.9
2
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.1
0.60.0
1.26.9
2
natsio/nats-server-config-reloader:0.20.147094fcae2f4
stdlib@go1.24.8
1.26.9
2
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.26.9
2
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.26.9
2
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.26.9
2
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.26.9
2
neosmemo/memos:0.31.024c2707ddd8f
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
stdlib@go1.24.4
1.26.9
2
obolnetwork/charon:v1.10.0278c7e2897b6
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
2
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.26.9
2
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
golang.org/x/net@v0.14.0
stdlib@go1.19.8
no fix listed
0.60.0
1.26.9
2
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
golang.org/x/net@v0.38.0
stdlib@go1.24.2
0.60.0
1.26.9
2
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
2
openebs/mc:RELEASE.2024-11-21T17-21-54Z4d1b85539919
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2
openebs/minio:RELEASE.2024-12-18T13-15-44Zbb04e41fc1b8
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
2
openebs/provisioner-localpv:4.6.099f5116f5cb8
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
2
openfga/openfga:latest:v1.22.09cf9a20af32a
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
2
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
golang.org/x/net@v0.24.0
stdlib@go1.20.14
0.60.0
1.26.9
2
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.2
0.60.0
1.26.9
2
oryd/hydra-maester:v0.0.420a7a2bfd0e7d
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
2
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
2
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.60.0
1.26.9
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.60.0
1.26.9
2
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.145.0a7343f018690
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
2
otel/opentelemetry-collector-contrib:0.161.0:latestfd328de25524
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
2
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.26.9
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.