StackRadar

CVE-2026-78669

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

Excessive CPU consumption from repeated initial window changes in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-3w4w-29g2-36g3CGA-4qjh-92j9-97fjCGA-76xr-xqfv-pj8rCGA-g6hf-4469-c7p8CGA-jxch-2x88-v4q3CGA-qj25-vfjp-rv4qDEBIAN-CVE-2026-78669GO-2026-6611
Also known as
CGA-33c5-5cfp-cvjx, CGA-3p87-5j3f-57xf, CGA-4fh2-gw9f-8fg8, CGA-4vpq-gwh4-vfh6, CGA-4xr3-wh4x-pgmw, CGA-67cj-prf6-6vgf, CGA-6cfh-5jqc-77x8, CGA-9qq7-44jw-h2p7, CGA-9vww-99xm-r24g, CGA-9w4c-68w5-r52f, CGA-c8vj-2gvm-vvx5, CGA-cvch-844x-r5jh, CGA-fx99-c5qv-v64f, CGA-gc3w-prcc-jwc9, CGA-j22p-m6q6-9jcj, CGA-jxq6-98g2-2pxv, CGA-m5rf-fj6p-qq2j, CGA-p59v-8mpx-gr9m, CGA-r8wv-qg84-pg9q, CGA-v628-qjv7-78rp, CGA-vwhx-47r5-26hf, CGA-w6c4-5355-g6w8, CGA-w74x-3c39-v8mc, CGA-wgfc-jqhq-h8pf, CGA-wh84-4hf6-r6xj, CGA-wwr2-qfhc-v9fj
Trending
Rank 3 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
natsnatsVerified publisher2.15.03 of 3See more

nats nats 2.15.0

3 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/nats:2.15.0-alpineac8f88a6494b
stdlib@go1.27.1
1.27.2
natsio/nats-box:0.19.7ffce8bd10338
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.26.9

Open the chart page →

2,805
dexdexVerified publisher0.26.01 of 1See more

dex dex 0.26.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

464
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
golang.org/x/net@v0.55.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

36,633
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
stdlib@go1.21.8
1.26.9

Open the chart page →

12,712
falcofalcosecurity9.2.03 of 3See more

falco falcosecurity 9.2.0

3 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
falcosecurity/falco:0.45.0788f1129c542
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
falcosecurity/falco-driver-loader:0.45.0d7d287d4dcee
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
falcosecurity/falcoctl:0.14.290ba9627886e
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

3,665
kubeviewkubeviewVerified publisher2.2.11 of 1See more

kubeview kubeview 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/benc-uk/kubeview:latest45b64d7c7016
golang.org/x/net@v0.57.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

295
alertmanagerprometheus-communityOfficialVerified publisher2.1.02 of 2See more

alertmanager prometheus-community 2.1.0

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.106b52bd4dbe3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/alertmanager:v0.34.1e9733bafb1bd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

333
kongkongOfficialVerified publisher3.4.11 of 2See more

kong kong 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

845
nfs-server-provisionerkvaps1.8.01 of 1See more

nfs-server-provisioner kvaps 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

3,435
chartmuseumchartmuseumVerified publisher3.10.41 of 1See more

chartmuseum chartmuseum 3.10.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.16.3c81f105c3682
golang.org/x/net@v0.38.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

2,061
prometheus-node-exporterprometheus-communityOfficialVerified publisher4.59.01 of 1See more

prometheus-node-exporter prometheus-community 4.59.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

274
rook-cephrookOfficialVerified publisher1.21.02 of 2See more

rook-ceph rook 1.21.0

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
rook/ceph:v1.21.02c3a65786d3c
golang.org/x/net@v0.58.0
stdlib@go1.22.10
0.60.0
1.26.9
quay.io/cephcsi/ceph-csi-operator:v1.1.0c42c95c36fa2
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,898
grafanagrafana-communityVerified publisher13.5.01 of 1See more

grafana grafana-community 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

237
argo-eventsargoOfficialVerified publisher2.4.271 of 1See more

argo-events argo 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
golang.org/x/net@v0.57.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

1,529
victoria-metrics-k8s-stackvictoriametricsVerified publisher0.95.25 of 7See more

victoria-metrics-k8s-stack victoriametrics 0.95.2

5 of the 7 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/grafana:13.2.3-distroless202e5d5b3f84
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
victoriametrics/operator:v0.75.078da26b41a81
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/victoriametrics/sync-job:v0.0.17b6f233532a85
golang.org/x/net@v0.56.0
stdlib@go1.26.4-X:jsonv2
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.12.11b4e4438faca
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,249
aws-node-termination-handleraws0.21.01 of 1See more

aws-node-termination-handler aws 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.19.0844478ebd5b8
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

2,202
kuredkuredOfficialVerified publisher6.1.01 of 1See more

kured kured 6.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/kubereboot/kured:1.23.08dfd3c2e8893
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

448
home-assistanthelm-hassVerified publisher0.3.851 of 1See more

home-assistant helm-hass 0.3.85

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.10.01b64d38f38d9
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

2,734
prometheus-adapterprometheus-communityOfficialVerified publisher5.3.01 of 1See more

prometheus-adapter prometheus-community 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9

Open the chart page →

1,474
openebsopenebsOfficialVerified publisher4.6.220 of 35See more

openebs openebs 4.6.2

20 of the 35 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.26.9
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.26.9
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.26.9
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9
openebs/lvm-driver:1.10.141f73aba7f31
golang.org/x/net@v0.48.0
stdlib@go1.24.7
0.60.0
1.26.9
openebs/mc:RELEASE.2024-11-21T17-21-54Z4d1b85539919
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
openebs/minio:RELEASE.2024-12-18T13-15-44Zbb04e41fc1b8
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.60.0
1.26.9
openebs/provisioner-localpv:4.6.099f5116f5cb8
golang.org/x/net@v0.55.0
stdlib@go1.25.0
0.60.0
1.26.9
openebs/zfs-driver:2.11.20234692bb4a4
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

34,272
tigera-operatorprojectcalico3.33.01 of 1See more

tigera-operator projectcalico 3.33.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.44.0066c2e8d6745
golang.org/x/net@v0.59.0
stdlib@go1.27.1-X:boringcrypto
0.60.0
1.27.2

Open the chart page →

128
open-webuiopen-webui16.6.01 of 4See more

open-webui open-webui 16.6.0

1 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.26.9

Open the chart page →

2,297
actions-runner-controlleractions-runner-controller0.23.72 of 2See more

actions-runner-controller actions-runner-controller 0.23.7

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
summerwind/actions-runner-controller:v0.27.62128f81dbede
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.60.0
1.26.9
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

4,312
aws-for-fluent-bitaws0.2.01 of 1See more

aws-for-fluent-bit aws 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-for-fluent-bit:3.2.1a480a1241720
stdlib@go1.25.6
1.26.9

Open the chart page →

497
corednscorednsVerified publisher1.48.21 of 1See more

coredns coredns 1.48.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
coredns/coredns:1.14.77efd3c635b03
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

462
apisixapisix2.18.01 of 3See more

apisix apisix 2.18.0

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.60.0
1.26.9

Open the chart page →

3,560
vpafairwinds-stableVerified publisher5.1.04 of 4See more

vpa fairwinds-stable 5.1.0

4 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/vpa-admission-controller:1.7.1be29624f7f12
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-recommender:1.7.189cea705535f
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/autoscaling/vpa-updater:1.7.1feb42a526970
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9

Open the chart page →

2,502
x509-certificate-exporterenixOfficialVerified publisher4.2.01 of 1See more

x509-certificate-exporter enix 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/enix/x509-certificate-exporter:4.2.0afef14dc3862
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

274
terraformhashicorpVerified publisher1.1.21 of 1See more

terraform hashicorp 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.18.8
0.60.0
1.26.9

Open the chart page →

2,859
opentelemetry-operatoropentelemetry-helmOfficialVerified publisher0.124.11 of 1See more

opentelemetry-operator opentelemetry-helm 0.124.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.160.05323a0df9508
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

124
trinotrino1.42.21 of 1See more

trino trino 1.42.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
trinodb/trino:4801565e8cac299
stdlib@go1.26.1
1.26.9

Open the chart page →

1,782
prometheus-pushgatewayprometheus-communityOfficialVerified publisher3.9.11 of 1See more

prometheus-pushgateway prometheus-community 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/prometheus/pushgateway:v1.11.491a56b89b97d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
dagsterdagsterVerified publisher1.13.261 of 5See more

dagster dagster 1.13.26

1 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.26.9

Open the chart page →

4,058
prometheus-redis-exporterprometheus-communityVerified publisher6.33.01 of 1See more

prometheus-redis-exporter prometheus-community 6.33.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.93.06ca518a72f30
stdlib@go1.27.1
1.27.2

Open the chart page →

93
zabbixzabbix-communityVerified publisher7.1.03 of 5See more

zabbix zabbix-community 7.1.0

3 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
golang.org/x/net@v0.41.0
stdlib@go1.24.10
0.60.0
1.26.9
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
stdlib@go1.24.10
1.26.9

Open the chart page →

15,981
keycloakcloudpirates-keycloakVerified publisher0.21.462 of 3See more

keycloak cloudpirates-keycloak 0.21.46

2 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
stdlib@go1.24.6
1.26.9
library/postgres:18.674935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

5,162
graylogkong-zVerified publisher3.0.361 of 5See more

graylog kong-z 3.0.36

1 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

3,212
netdatanetdataVerified publisher3.7.1751 of 1See more

netdata netdata 3.7.175

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
netdata/netdata:v2.12.01e50cc0b11f0
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,938
connectonepassword-connect2.4.22 of 2See more

connect onepassword-connect 2.4.2

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
1password/connect-api:1.8.3656e4b10df83
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1password/connect-sync:1.8.3a760350c941a
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

328
node-problem-detectordeliveryheroVerified publisher2.4.11 of 1See more

node-problem-detector deliveryhero 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,517
opencostopencostOfficialVerified publisher2.5.321 of 2See more

opencost opencost 2.5.32

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost:1.121.34cdd173253e5
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

401
openfaasopenfaas15.0.136 of 6See more

openfaas openfaas 15.0.13

6 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/nats-streaming:0.25.60ad6861379c9
stdlib@go1.20.11
1.26.9
ghcr.io/openfaas/faas-netes:0.18.176cfe35401d25
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
ghcr.io/openfaas/gateway:0.27.14ee0eaecc490c
stdlib@go1.24.13
1.26.9
ghcr.io/openfaas/queue-worker:0.14.2c18da04d70f6
stdlib@go1.23.4
1.26.9
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.14.05ce7540c3c00
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

5,305
prometheus-elasticsearch-exporterprometheus-communityVerified publisher7.4.01 of 1See more

prometheus-elasticsearch-exporter prometheus-community 7.4.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/elasticsearch-exporter:v1.11.0a056739b095d
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

300
flux2fluxcd-community2.19.17 of 7See more

flux2 fluxcd-community 2.19.1

7 of the 7 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
fluxcd/flux-cli:v2.9.5704d55295355
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9
ghcr.io/fluxcd/helm-controller:v1.6.48ff15409e46d
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/image-automation-controller:v1.2.5e1a2720d3951
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/image-reflector-controller:v1.2.5c83ce5c06fed
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/kustomize-controller:v1.9.5a3a955eb2bc4
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/notification-controller:v1.9.4840f318265ee
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/fluxcd/source-controller:v1.9.56f20d232d596
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

3,883
gitlab-agentgitlabVerified publisher2.32.01 of 1See more

gitlab-agent gitlab 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cluster-integration/gitlab-agent/agentk:v19.4.04d3498887bee
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

153
jaeger-operatorjaegertracingOfficialVerified publisher2.57.01 of 1See more

jaeger-operator jaegertracing 2.57.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jaegertracing/jaeger-operator:1.61.03f036ec60e61
golang.org/x/net@v0.29.0
stdlib@go1.22.3
0.60.0
1.26.9

Open the chart page →

1,073
policy-reporterpolicy-reporterOfficialVerified publisher3.11.01 of 1See more

policy-reporter policy-reporter 3.11.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/kyverno/policy-reporter:3.11.00f6eabff483b
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

153
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.26.9

Open the chart page →

6,589
netboxnetboxOfficialVerified publisher8.3.913 of 5See more

netbox netbox 8.3.91

3 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9
rancher/kubectl:v1.36.206c7a7a97727
golang.org/x/net@v0.49.0
stdlib@go1.26.4
0.60.0
1.26.9
ghcr.io/netbox-community/netbox:v4.7.26f7177d3ff4d
stdlib@go1.26.7
1.26.9

Open the chart page →

1,755
valkeybitnamiVerified publisher6.3.41 of 1See more

valkey bitnami 6.3.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9

Open the chart page →

89

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
goharbor/harbor-core:v2.14.3a30e5a8be3d9
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
goharbor/harbor-core:v2.11.1c017dd84ee96
golang.org/x/net@v0.24.0
stdlib@go1.22.6
0.60.0
1.26.9
1
goharbor/harbor-jobservice:v2.9.039435daedd0c
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
1
goharbor/harbor-jobservice:dev563eb6cfd199
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.7
0.60.0
1.26.9
1
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
goharbor/harbor-jobservice:v2.15.4f143578ef30e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.15.430bd1ace4e3b
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.7
0.60.0
1.26.9
1
goharbor/harbor-registryctl:devb8fa35c3d36e
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
1
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.60.0
1.26.9
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.60.0
1.26.9
1
goharbor/registry-photon:v2.11.15645d459af2b
stdlib@go1.22.6
1.26.9
1
goharbor/registry-photon:v2.14.36533fc396cbc
stdlib@go1.24.13
1.26.9
1
goharbor/registry-photon:v2.9.08a26e8cb7862
stdlib@go1.20.7
1.26.9
1
goharbor/registry-photon:devc34795d74b99
golang.org/x/net@v0.54.0
stdlib@go1.26.4
0.60.0
1.26.9
1
goharbor/registry-photon:v2.15.4dc0cb388a644
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
golang.org/x/net@v0.28.0
stdlib@go1.25.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.15.4813ca81b4a4e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.18.3
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:devd051158f1fd0
golang.org/x/net@v0.55.0
stdlib@go1.26.4-X:jsonv2
0.60.0
1.26.9
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.60.0
1.26.9
1
golift/unifi-poller:v2.9.5486a63339969
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
golift/unifi-poller:v2.9.2585a29a06d05
golang.org/x/net@v0.15.0
stdlib@go1.21.0
0.60.0
1.26.9
1
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.7
0.60.0
1.26.9
1
gomods/athens:v0.17.10f61d1e62359
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9
1
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.13.4
0.60.0
1.26.9
1
gomods/athens:v0.19.2e1abe3005673
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
goofball222/pritunl:1.32.3602.807bf26032dfce
golang.org/x/net@v0.7.0
stdlib@go1.18.7
0.60.0
1.26.9
1
google/cloud-sdk:slimc70885ba9f04
stdlib@go1.26.6
1.26.9
1
google/cloud-sdk:alpineef78619c8239
stdlib@go1.26.6
1.26.9
1
gophish/gophish:0.12.18a57cd171999
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.15.2
0.60.0
1.26.9
1
gotenberg/gotenberg:8-chromium0d28ae9a9644
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
gotenberg/gotenberg:8.30206a6c708fc6
golang.org/x/net@v0.52.0
stdlib@go1.26.0
0.60.0
1.26.9
1
gotenberg/gotenberg:8.7.0437b9cd3c351
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
1
gotenberg/gotenberg:8.3467097317623a
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
1
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.60.0
1.26.9
1
gotify/server:2.9.1a3af47067ce6
golang.org/x/net@v0.48.0
stdlib@go1.26.0
0.60.0
1.26.9
1
gotify/server-arm7:2.0.23d91e302ad1d0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.60.0
1.26.9
1
gotson/komga:1.27.19cf102f5fb78
stdlib@go1.17.8
1.26.9
1
gotson/komga:1.22.0ba892ab3e082
stdlib@go1.17.8
1.26.9
1
gotson/komga:1.28.1d8f772dce7b3
stdlib@go1.26.7
1.26.9
1
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.60.0
1.26.9
1
gradiant/packetrusher:2b26573e9b46dc76af4
golang.org/x/net@v0.38.0
stdlib@go1.21.3
0.60.0
1.26.9
1
grafana/agent:v0.44.23364714a2f64
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.60.0
1.26.9
1
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16
0.60.0
1.26.9
1
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.