StackRadar

CVE-2026-78669

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

Excessive CPU consumption from repeated initial window changes in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-3w4w-29g2-36g3CGA-4qjh-92j9-97fjCGA-76xr-xqfv-pj8rCGA-g6hf-4469-c7p8CGA-jxch-2x88-v4q3CGA-qj25-vfjp-rv4qDEBIAN-CVE-2026-78669GO-2026-6611
Also known as
CGA-33c5-5cfp-cvjx, CGA-3p87-5j3f-57xf, CGA-4fh2-gw9f-8fg8, CGA-4vpq-gwh4-vfh6, CGA-4xr3-wh4x-pgmw, CGA-67cj-prf6-6vgf, CGA-6cfh-5jqc-77x8, CGA-9qq7-44jw-h2p7, CGA-9vww-99xm-r24g, CGA-9w4c-68w5-r52f, CGA-c8vj-2gvm-vvx5, CGA-cvch-844x-r5jh, CGA-fx99-c5qv-v64f, CGA-gc3w-prcc-jwc9, CGA-j22p-m6q6-9jcj, CGA-jxq6-98g2-2pxv, CGA-m5rf-fj6p-qq2j, CGA-p59v-8mpx-gr9m, CGA-r8wv-qg84-pg9q, CGA-v628-qjv7-78rp, CGA-vwhx-47r5-26hf, CGA-w6c4-5355-g6w8, CGA-w74x-3c39-v8mc, CGA-wgfc-jqhq-h8pf, CGA-wh84-4hf6-r6xj, CGA-wwr2-qfhc-v9fj
Trending
Rank 3 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
librechatlibrechat-openshiftVerified publisher1.9.01 of 3See more

librechat librechat-openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

6,745
libredb-studiolibredb-studioOfficialVerified publisher0.1.811 of 1See more

libredb-studio libredb-studio 0.1.81

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.18.21b4051ca999a
stdlib@go1.24.4
1.26.9

Open the chart page →

1,405
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestf1bc435659b9
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

3,986
vclustermainVerified publisher0.17.07 of 10See more

vcluster main 0.17.0

7 of the 10 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.60.0
1.26.9
registry.k8s.io/etcd:3.6.4-0e36c08168342
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/net@v0.7.0
stdlib@go1.19.6
0.60.0
1.26.9
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

16,571
stannatsVerified publisher0.13.01 of 2See more

stan nats 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
natsio/prometheus-nats-exporter:latestc623b608e148
stdlib@go1.26.6
1.26.9

Open the chart page →

288
headplanenbcloudVerified publisher0.1.23 of 4See more

headplane nbcloud 0.1.2

3 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9
headscale/headscale:0.25.1a7a8ae9616bb
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.60.0
1.26.9
ghcr.io/tale/headplane:0.5.50dbc52cffc19
stdlib@go1.23.4
1.26.9

Open the chart page →

10,086
netris-operatornetrisai3.0.21 of 2See more

netris-operator netrisai 3.0.2

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
netrisai/netris-operator:v4.0.244f60aa0d898
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

2,352
node-local-dnsnode-local-dns2.4.01 of 1See more

node-local-dns node-local-dns 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/net@v0.17.0
stdlib@go1.21.7
0.60.0
1.26.9

Open the chart page →

3,388
nri-memtierdnri-pluginsOfficialVerified publisher0.14.01 of 1See more

nri-memtierd nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memtierd:v0.14.09138314e12ba
stdlib@go1.26.0
1.26.9

Open the chart page →

531
goldpingerokgoloveVerified publisher6.2.01 of 1See more

goldpinger okgolove 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/net@v0.17.0
stdlib@go1.21.9
0.60.0
1.26.9

Open the chart page →

1,270
geonodeone-acre-fundVerified publisher0.1.161 of 7See more

geonode one-acre-fund 0.1.16

1 of the 7 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,733
open5gsopen5gsVerified publisher2.3.83 of 5See more

open5gs open5gs 2.3.8

3 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnami/mongodb:latestad05bb9a19fa
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
stdlib@go1.15.1
1.26.9
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.60.0
1.26.9

Open the chart page →

12,640
psmdb-operatorpercona1.23.21 of 1See more

psmdb-operator percona 1.23.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
percona/percona-server-mongodb-operator:1.23.178c87b933e18
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

164
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/net@v0.17.0
stdlib@go1.20.7
0.60.0
1.26.9

Open the chart page →

9,882
capsuleprojectcapsuleOfficialVerified publisher0.14.62 of 2See more

capsule projectcapsule 0.14.6

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,920
prometheus-consul-exporterprometheus-communityVerified publisher1.1.11 of 1See more

prometheus-consul-exporter prometheus-community 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
prom/consul-exporter:v0.13.04e4cfd809e96
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,249
prometheus-json-exporterprometheus-communityOfficialVerified publisher0.20.11 of 1See more

prometheus-json-exporter prometheus-community 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

1,175
prometheus-nginx-exporterprometheus-communityVerified publisher1.23.11 of 1See more

prometheus-nginx-exporter prometheus-community 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
nginx/nginx-prometheus-exporter:1.5.385666e7fde7e
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

166
prometheus-smartctl-exporterprometheus-communityVerified publisher0.17.11 of 1See more

prometheus-smartctl-exporter prometheus-community 0.17.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
golang.org/x/net@v0.35.0
stdlib@go1.23.7
0.60.0
1.26.9

Open the chart page →

1,727
prometheus-statsd-exporterprometheus-communityVerified publisher1.0.01 of 1See more

prometheus-statsd-exporter prometheus-community 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,249
proxmox-cloud-controller-managerproxmox-ccm0.2.321 of 1See more

proxmox-cloud-controller-manager proxmox-ccm 0.2.32

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-cloud-controller-manager:v0.16.1474dbfd3be5c
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
pvc-autoresizerpvc-autoresizerVerified publisher0.20.11 of 1See more

pvc-autoresizer pvc-autoresizer 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/topolvm/pvc-autoresizer:0.21.2d7885d57f6f9
golang.org/x/net@v0.56.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

137
rke2-multusrke2-charts3.7.1-build20210416011 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.60.0

Open the chart page →

4,708
popeyeself-hosters-by-nightVerified publisher0.6.11 of 1See more

popeye self-hosters-by-night 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9

Open the chart page →

1,875
argo-watchershini4iVerified publisher1.4.11 of 1See more

argo-watcher shini4i 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/shini4i/argo-watcher:v1.4.20faab179997f
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
fulciosigstoreVerified publisher2.11.45 of 6See more

fulcio sigstore 2.11.4

5 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/sigstore/fulcio:v1.9.02de0226c5f82
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/sigstore/scaffolding/createcertsdigest-pinned4d64dac937e2
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.33e591f98e3899
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
ghcr.io/sigstore/scaffolding/createtree:v0.7.334c845ced03d8
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3324293fa1ed50
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

4,935
policy-controllersigstoreVerified publisher0.10.81 of 2See more

policy-controller sigstore 0.10.8

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/sigstore/policy-controller/policy-controllerdigest-pinned0bcd60beb93f
golang.org/x/net@v0.39.0
stdlib@go1.24.7
0.60.0
1.26.9

Open the chart page →

1,355
pubsubplus-hasolaceVerified publisher3.10.01 of 1See more

pubsubplus-ha solace 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
solace/solace-pubsub-standard:latest3c8a8b7fdcae
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

393
sops-secrets-operatorsops-secrets-operatorVerified publisher0.28.11 of 1See more

sops-secrets-operator sops-secrets-operator 0.28.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,268
steampipe-powerpipe-kubernetessteampipe-powerpipe-kubernetesVerified publisher0.13.12 of 2See more

steampipe-powerpipe-kubernetes steampipe-powerpipe-kubernetes 0.13.1

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.60.0
1.26.9
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

6,796
superstreamsuperstreamOfficialVerified publisher0.9.623 of 3See more

superstream superstream 0.9.62

3 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/nats:2.10.25-alpine3290c829aa05
stdlib@go1.23.5
1.26.9
natsio/nats-server-config-reloader:0.16.1bf97e5e9b9d2
stdlib@go1.23.3
1.26.9
natsio/prometheus-nats-exporter:0.16.054b0d7ff058e
stdlib@go1.23.4
1.26.9

Open the chart page →

4,928
topolvmtopolvmVerified publisher17.3.01 of 1See more

topolvm topolvm 17.3.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.42.0719ab11d974a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,508
trivy-operator-polr-adaptertrivy-operator-polr-adapterVerified publisher0.11.51 of 1See more

trivy-operator-polr-adapter trivy-operator-polr-adapter 0.11.5

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/fjogeleit/trivy-operator-polr-adapter:0.11.537029b4d464f
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

251
uffizzi-appuffizzi-app1.3.08 of 14See more

uffizzi-app uffizzi-app 1.3.0

8 of the 14 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
stdlib@go1.20.14
0.60.0
1.26.9
uffizzi/uffizzi-cluster-operator:v1.4.514e528bbd926
golang.org/x/net@v0.8.0
stdlib@go1.19.13
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

25,848
valdvald1.8.04 of 5See more

vald vald 1.8.0

4 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
vdaas/vald-agent-ngt:v1.8.032e3695fe585
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
vdaas/vald-discoverer-k8s:v1.8.0f6495f38ae92
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
vdaas/vald-lb-gateway:v1.8.061009e319a9a
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
vdaas/vald-manager-index:v1.8.0ab881d2262d8
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

780
vault-secrets-webhookvault-secrets-webhookVerified publisher1.23.11 of 1See more

vault-secrets-webhook vault-secrets-webhook 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-secrets-webhook:v1.23.198baf045a1c9
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

775
athens-proxyvolker-raschekVerified publisher2.0.31 of 1See more

athens-proxy volker-raschek 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
gomods/athens:v0.17.10f61d1e62359
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

2,713
wg-easywg-easyVerified publisher0.1.61 of 1See more

wg-easy wg-easy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:150e7bc9d34e86
golang.org/x/net@v0.44.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,214
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

14,927
nfs-server-provisionerwso21.1.01 of 1See more

nfs-server-provisioner wso2 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.60.0
1.26.9

Open the chart page →

4,027
yunikornyunikornVerified publisher1.10.03 of 3See more

yunikorn yunikorn 1.10.0

3 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
apache/yunikorn:scheduler-1.10.049fc54894fdf
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
apache/yunikorn:web-1.10.090e6a62a578a
stdlib@go1.26.7
1.26.9
apache/yunikorn:admission-1.10.095c6b951f38a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

375
matrixzekker6Verified publisher3.32.01 of 4See more

matrix zekker6 3.32.0

1 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.162.06b84a7bbac36
stdlib@go1.24.4
1.26.9

Open the chart page →

6,109
eshoponabpabp-charts1.0.02 of 15See more

eshoponabp abp-charts 1.0.0

2 of the 15 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mongo:4.2699d652ed674
stdlib@go1.18.2
1.26.9
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.26.9

Open the chart page →

24,081
moon2aerokube2.8.23 of 3See more

moon2 aerokube 2.8.2

3 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/aerokube/moon:2.8.2072f3c5592dc
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/aerokube/moon-conf:2.8.235c465ab25d8
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/aerokube/moon-ui:2.8.2f374d0b9953b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

372
microgatewayairlock-microgatewayOfficialVerified publisher5.2.01 of 1See more

microgateway airlock-microgateway 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/airlock/microgateway-operatordigest-pinned48518d704307
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
alerta-webalerta-webVerified publisher0.1.121 of 2See more

alerta-web alerta-web 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.2.0-debian-11-r113e65a6b89e38
stdlib@go1.18.2
1.26.9

Open the chart page →

4,744
pod-gatewayangelnu7.1.11 of 2See more

pod-gateway angelnu 7.1.1

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/angelnu/gateway-admision-controller:v3.12.06f6ab596afd5
golang.org/x/net@v0.30.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

1,783
tt-rssangelnu7.0.01 of 2See more

tt-rss angelnu 7.0.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/angelnu/tt-rss:2.0.100809fb02162f151
stdlib@go1.26.7
1.26.9

Open the chart page →

923
ansible-semaphoreansible-semaphore0.1.01 of 1See more

ansible-semaphore ansible-semaphore 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.26.9

Open the chart page →

5,034
aperture-controlleraperture2.34.04 of 5See more

aperture-controller aperture 2.34.0

4 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
fluxninja/aperture-operator:2.34.0356d7aa86632
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.26.9
quay.io/prometheus/prometheus:v2.33.591100b06e86d
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

7,350

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/quenchworks/images/victoriametricsf4fa0ea58187
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
ghcr.io/rabbitmq/cluster-operator:2.23.09236fb4f559b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
2
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
stdlib@go1.18.10
1.26.9
2
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
stdlib@go1.19.7
1.26.9
2
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
stdlib@go1.19.13
1.26.9
2
ghcr.io/sigstore/fulcio:v1.9.02de0226c5f82
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
2
ghcr.io/sigstore/rekor/rekor-server:v1.5.4100d793d68d0
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
2
ghcr.io/sigstore/scaffolding/createcerts4d64dac937e2
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
2
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9
2
ghcr.io/spiffe/oidc-discovery-provider:1.15.3bb95f13c2b4e
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
2
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9
2
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
golang.org/x/net@v0.42.0
stdlib@go1.25.3
0.60.0
1.26.9
2
ghcr.io/spiffe/spire-controller-manager:0.8.019e418e9d7f2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
2
ghcr.io/spiffe/spire-server:1.15.34082f30d3e0d
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
2
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/net@v0.17.0
stdlib@go1.20.2
0.60.0
1.26.9
2
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
stdlib@go1.20.1
1.26.9
2
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13076a87738b13
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2
2
ghcr.io/voyagermesh/crd-manager:v0.4.04466bb77dc78
golang.org/x/net@v0.47.0
stdlib@go1.25.13
0.60.0
1.26.9
2
ghcr.io/voyagermesh/echoserver:v20221109:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.26.9
2
ghcr.io/voyagermesh/gateway:v1.8.24237fd16a3cb
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
golang.org/x/net@v0.44.0
stdlib@go1.26.3
0.60.0
1.26.9
2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.17.0760c61825d2a
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v6.3.0adfd47ab0160
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
2
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.19.06d065f238d39
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
2
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.7_local:latest6b75164ae737
stdlib@go1.26.7
1.26.9
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
stdlib@go1.25.4
1.26.9
2
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.0:latest1eb61443d68e
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
stdlib@go1.23.12
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-agent:0.10.26769c2275a43
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/inference-manager-engine:1.46.0c46f109c3d0b
golang.org/x/net@v0.48.0
stdlib@go1.25.9
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/model-manager-server:1.27.0c057dcdd9ef3
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/rbac-server:1.19.1df1adeb86679
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/session-manager-agent:1.9.0b9f23db99051
golang.org/x/net@v0.38.0
stdlib@go1.23.11
0.60.0
1.26.9
2
public.ecr.aws/cloudnatix/llmariner/user-manager-server:1.27.1628a14449241
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9
2
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/net@v0.4.0
stdlib@go1.19.6
0.60.0
1.26.9
2
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
2
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.60.0
1.26.9
2
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.60.0
1.26.9
2
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/net@v0.4.0
stdlib@go1.19.8
0.60.0
1.26.9
2
public.ecr.aws/eks-distro/kubernetes-csi/livenessprobe:v2.9.0-eks-1-25-latest8a305e162caa
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
2
public.ecr.aws/eks-distro/kubernetes-csi/node-driver-registrar:v2.7.0-eks-1-25-latestf4345e67df8f
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.60.0
1.26.9
2
public.ecr.aws/eks-distro/kubernetes/kube-apiserver:v1.24.9-eks-1-24-772e06b605692
stdlib@go1.18.9
1.26.9
2
public.ecr.aws/eks-distro/kubernetes/kube-controller-manager:v1.24.9-eks-1-24-7eaea8c230432
stdlib@go1.18.9
1.26.9
2
public.ecr.aws/gravitational/tbot-distroless:18.11.39aaef195f82c
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.