StackRadar

CVE-2026-78669

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Excessive CPU consumption from repeated initial window changes in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4qjh-92j9-97fjCGA-4vpq-gwh4-vfh6CGA-76xr-xqfv-pj8rCGA-g6hf-4469-c7p8CGA-jxch-2x88-v4q3CGA-qj25-vfjp-rv4qDEBIAN-CVE-2026-78669GO-2026-6611
Also known as
CGA-33c5-5cfp-cvjx, CGA-3p87-5j3f-57xf, CGA-3w4w-29g2-36g3, CGA-4fh2-gw9f-8fg8, CGA-4xr3-wh4x-pgmw, CGA-67cj-prf6-6vgf, CGA-6cfh-5jqc-77x8, CGA-9qq7-44jw-h2p7, CGA-9vww-99xm-r24g, CGA-9w4c-68w5-r52f, CGA-c8vj-2gvm-vvx5, CGA-cvch-844x-r5jh, CGA-fx99-c5qv-v64f, CGA-gc3w-prcc-jwc9, CGA-j22p-m6q6-9jcj, CGA-jxq6-98g2-2pxv, CGA-m5rf-fj6p-qq2j, CGA-p59v-8mpx-gr9m, CGA-r8wv-qg84-pg9q, CGA-v628-qjv7-78rp, CGA-vwhx-47r5-26hf, CGA-w6c4-5355-g6w8, CGA-w74x-3c39-v8mc, CGA-wgfc-jqhq-h8pf, CGA-wh84-4hf6-r6xj, CGA-wwr2-qfhc-v9fj
Trending
Rank 3 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
passbolt-hachristianhuthVerified publisher6.0.13 of 4See more

passbolt-ha christianhuth 6.0.1

3 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.26.9
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
golang.org/x/net@v0.42.0
stdlib@go1.24.6
0.60.0
1.26.9
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.26.9

Open the chart page →

14,725
shlink-backendchristianhuthVerified publisher11.12.21 of 1See more

shlink-backend christianhuth 11.12.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
shlinkio/shlink:5.1.7844e1f2b6455
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

659
squestchristianhuthVerified publisher6.6.82 of 4See more

squest christianhuth 6.6.8

2 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.26.9
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9

Open the chart page →

12,371
syncstorage-rschristianhuthVerified publisher6.1.11 of 2See more

syncstorage-rs christianhuth 6.1.1

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnami/mariadb:latest354e5aec2045
stdlib@go1.26.8
1.26.9

Open the chart page →

1,177
typo3christianhuthVerified publisher7.8.11 of 2See more

typo3 christianhuth 7.8.1

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.26.9

Open the chart page →

10,160
challengerchronicleVerified publisher0.1.21 of 1See more

challenger chronicle 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
stdlib@go1.22.12
1.26.9

Open the chart page →

1,389
erpcchronicleVerified publisher0.7.11 of 1See more

erpc chronicle 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/erpc/erpc:0.1.18bfed3d49a08
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

679
spectrechronicleVerified publisher0.3.91 of 1See more

spectre chronicle 0.3.9

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,087
validatorchronicleVerified publisher0.8.21 of 1See more

validator chronicle 0.8.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/ghost:0.81.0417b664eee72
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

693
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.60.0
1.26.9

Open the chart page →

1,273
clairclair0.0.31 of 1See more

clair clair 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.7.28d38ffa8fad7
golang.org/x/net@v0.14.0
stdlib@go1.20.9
0.60.0
1.26.9

Open the chart page →

4,045
clamav-restclamav-rest-apiVerified publisher0.1.01 of 1See more

clamav-rest clamav-rest-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ajilaag/clamav-rest:latestad689c7b75b1
stdlib@go1.26.0
1.26.9

Open the chart page →

908
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.26.9

Open the chart page →

2,299
clickhouse-operator-helmclickhouse-operator0.0.81 of 1See more

clickhouse-operator-helm clickhouse-operator 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/clickhouse/clickhouse-operator:v0.0.880ff894a42fb
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

201
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.60.0
1.26.9
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.60.0
1.26.9

Open the chart page →

4,880
cloudflare-tunnelcloudflare-tunnelVerified publisher0.16.81 of 1See more

cloudflare-tunnel cloudflare-tunnel 0.16.8

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.10.09b49eed8f628
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

625
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.26.9
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

6,619
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.6
0.60.0
1.26.9
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.18.6
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.60.0
1.26.9

Open the chart page →

10,674
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.26.9

Open the chart page →

3,989
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.26.9

Open the chart page →

2,917
grafanacloudposse0.2.61 of 1See more

grafana cloudposse 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/grafana:latestb28bae15e219
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

335
cloudttycloudtty0.8.102 of 2See more

cloudtty cloudtty 0.8.10

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell:v0.8.1023e8d178e02c
golang.org/x/net@v0.45.0
stdlib@go1.25.2
0.60.0
1.26.9
ghcr.io/cloudtty/cloudshell-operator:v0.8.1014f036e33ef1
golang.org/x/net@v0.25.0
stdlib@go1.21.11
0.60.0
1.26.9

Open the chart page →

4,438
cluster-api-provider-oxidecluster-api-provider-oxide0.2.31 of 1See more

cluster-api-provider-oxide cluster-api-provider-oxide 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/oxidecomputer/cluster-api-provider-oxide:0.2.37b05d3bbfbfa
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

403
cluster-api-visualizercluster-api-visualizer1.5.01 of 1See more

cluster-api-visualizer cluster-api-visualizer 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

994
clustereye-stackclustereyeVerified publisher0.1.12 of 5See more

clustereye-stack clustereye 0.1.1

2 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
johnblack77/clustereye-api:latest816f4e2fea4a
golang.org/x/net@v0.50.0
stdlib@go1.25.14
0.60.0
1.26.9
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9

Open the chart page →

5,590
clusternet-hubclusternet1.0.01 of 1See more

clusternet-hub clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-hub:v1.0.059f75504c5d4
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

2,163
clusternet-schedulerclusternet1.0.01 of 1See more

clusternet-scheduler clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-scheduler:v1.0.0a6ae5aff81ce
golang.org/x/net@v0.42.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

2,163
cluster-setupcluster-setup1.5.07 of 8See more

cluster-setup cluster-setup 1.5.0

7 of the 8 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
golang.org/x/net@v0.37.0
stdlib@go1.24.3
0.60.0
1.26.9
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.26.9
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
golang.org/x/net@v0.33.0
stdlib@go1.22.7
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.17.2ec56edb1161d
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-startupapicheck:v1.17.2e18989b4f912
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9

Open the chart page →

14,978
cockroachdb-chartcockroachdbv226.3.21 of 1See more

cockroachdb-chart cockroachdbv2 26.3.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
cockroachdb/cockroach-self-signer-cert:1.10b0fcc6c8147a
golang.org/x/net@v0.38.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

663
istio-allcode4devsVerified publisher1.2.04 of 6See more

istio-all code4devs 1.2.0

4 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.60.0
1.26.9

Open the chart page →

7,105
istio-control-planecode4devsVerified publisher1.0.02 of 3See more

istio-control-plane code4devs 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

3,505
maintenancecodewithemadVerified publisher0.1.61 of 1See more

maintenance codewithemad 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/caddy:2.9-alpineb4e3952384eb
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9

Open the chart page →

2,076
dawarichcogitriVerified publisher2.9.31 of 3See more

dawarich cogitri 2.9.3

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.3589e3606b11b
stdlib@go1.24.4
1.26.9

Open the chart page →

7,054
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,303
cortex-tenantcortex-tenantVerified publisher0.8.11 of 1See more

cortex-tenant cortex-tenant 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/blind-oracle/cortex-tenant:v2.0.09f8896ffc15b
golang.org/x/net@v0.38.0
stdlib@go1.25.1
0.60.0
1.26.9

Open the chart page →

1,296
cosmo-controller-managercosmoVerified publisher0.9.01 of 2See more

cosmo-controller-manager cosmo 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-controller-manager:v0.9.08c7fa5552028
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

2,686
cosmo-dashboardcosmoVerified publisher0.9.11 of 1See more

cosmo-dashboard cosmo 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-dashboard:v0.9.16a1c4a81a924
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

2,699
cp-schema-registrycp-schema-registryVerified publisher1.0.01 of 1See more

cp-schema-registry cp-schema-registry 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
stdlib@go1.25.4
1.26.9

Open the chart page →

2,620
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.60.0
1.26.9

Open the chart page →

7,778
chalk-operatorcrashoverride-helm-chartsVerified publisher0.1.11 of 1See more

chalk-operator crashoverride-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/chalk-operator:v0.1.128eee62e9bfa
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

771
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.26.9

Open the chart page →

4,751
cronguardcronguardVerified publisher0.4.31 of 1See more

cronguard cronguard 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/dmazhukov/cronguard:0.4.37683dd5b26ba
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

201
cronjob-scale-down-operatorcronschedules0.4.41 of 1See more

cronjob-scale-down-operator cronschedules 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/cronschedules/cronjob-scale-down-operator:0.4.4fd521f0034a0
golang.org/x/net@v0.52.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

921
cruisekubecruisekubeOfficialVerified publisher0.3.41 of 5See more

cruisekube cruisekube 0.3.4

1 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2e8825994b7a2
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

963
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
stdlib@go1.19.8
1.26.9

Open the chart page →

16,007
revadcs3orgOfficialVerified publisher1.6.11 of 1See more

revad cs3org 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

2,461
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.4
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

25,383
CubeUniversecubeuniverseVerified publisher0.1.01 of 1See more

CubeUniverse cubeuniverse 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20.3
0.60.0
1.26.9

Open the chart page →

3,171
cview-issuercview-issuerVerified publisher0.0.431 of 1See more

cview-issuer cview-issuer 0.0.43

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
devsecurely/cview-issuer:0.0.4335675bd31bfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

205
cyphernetes-operatorcyphernetes-operatorVerified publisher0.1.01 of 1See more

cyphernetes-operator cyphernetes-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,002

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.7
0.60.0
1.26.9
1
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
goharbor/harbor-jobservice:v2.15.4f143578ef30e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.15.430bd1ace4e3b
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.7
0.60.0
1.26.9
1
goharbor/harbor-registryctl:devb8fa35c3d36e
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.60.0
1.26.9
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.60.0
1.26.9
1
goharbor/registry-photon:v2.11.15645d459af2b
stdlib@go1.22.6
1.26.9
1
goharbor/registry-photon:v2.14.36533fc396cbc
stdlib@go1.24.13
1.26.9
1
goharbor/registry-photon:v2.9.08a26e8cb7862
stdlib@go1.20.7
1.26.9
1
goharbor/registry-photon:devc34795d74b99
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
1
goharbor/registry-photon:v2.15.4dc0cb388a644
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
golang.org/x/net@v0.28.0
stdlib@go1.25.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.15.4813ca81b4a4e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.18.3
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:devd051158f1fd0
golang.org/x/net@v0.55.0
stdlib@go1.26.4-X:jsonv2
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.60.0
1.26.9
1
golift/unifi-poller:v2.9.5486a63339969
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
golift/unifi-poller:v2.9.2585a29a06d05
golang.org/x/net@v0.15.0
stdlib@go1.21.0
0.60.0
1.26.9
1
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.7
0.60.0
1.26.9
1
gomods/athens:v0.17.10f61d1e62359
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
1
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.13.4
0.60.0
1.26.9
1
gomods/athens:v0.19.2e1abe3005673
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
goofball222/pritunl:1.32.3602.807bf26032dfce
golang.org/x/net@v0.7.0
stdlib@go1.18.7
0.60.0
1.26.9
1
google/cloud-sdk:slimc70885ba9f04
stdlib@go1.26.6
1.26.9
1
google/cloud-sdk:alpineef78619c8239
stdlib@go1.26.6
1.26.9
1
gophish/gophish:0.12.18a57cd171999
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.15.2
0.60.0
1.26.9
1
gotenberg/gotenberg:8-chromium0d28ae9a9644
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
gotenberg/gotenberg:8.30206a6c708fc6
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.60.0
1.26.9
1
gotenberg/gotenberg:8.7.0437b9cd3c351
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
1
gotenberg/gotenberg:8.3467097317623a
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.60.0
1.26.9
1
gotify/server:2.9.1a3af47067ce6
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
1
gotify/server-arm7:2.0.23d91e302ad1d0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.60.0
1.26.9
1
gotson/komga:1.27.19cf102f5fb78
stdlib@go1.17.8
1.26.9
1
gotson/komga:1.22.0ba892ab3e082
stdlib@go1.17.8
1.26.9
1
gotson/komga:1.28.1d8f772dce7b3
stdlib@go1.26.7
1.26.9
1
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.60.0
1.26.9
1
gradiant/packetrusher:2b26573e9b46dc76af4
golang.org/x/net@v0.38.0
stdlib@go1.21.3
0.60.0
1.26.9
1
grafana/agent:v0.44.23364714a2f64
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.60.0
1.26.9
1
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16
0.60.0
1.26.9
1
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.60.0
1.26.9
1
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9
1
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/net@v0.31.0
stdlib@go1.22.7
0.60.0
1.26.9
1
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.60.0
1.26.9
1
grafana/alloy:v1.18.10f4434c92b3e
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.