StackRadar

CVE-2026-78669

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Excessive CPU consumption from repeated initial window changes in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4qjh-92j9-97fjCGA-4vpq-gwh4-vfh6CGA-76xr-xqfv-pj8rCGA-g6hf-4469-c7p8CGA-jxch-2x88-v4q3CGA-qj25-vfjp-rv4qDEBIAN-CVE-2026-78669GO-2026-6611
Also known as
CGA-33c5-5cfp-cvjx, CGA-3p87-5j3f-57xf, CGA-3w4w-29g2-36g3, CGA-4fh2-gw9f-8fg8, CGA-4xr3-wh4x-pgmw, CGA-67cj-prf6-6vgf, CGA-6cfh-5jqc-77x8, CGA-9qq7-44jw-h2p7, CGA-9vww-99xm-r24g, CGA-9w4c-68w5-r52f, CGA-c8vj-2gvm-vvx5, CGA-cvch-844x-r5jh, CGA-fx99-c5qv-v64f, CGA-gc3w-prcc-jwc9, CGA-j22p-m6q6-9jcj, CGA-jxq6-98g2-2pxv, CGA-m5rf-fj6p-qq2j, CGA-p59v-8mpx-gr9m, CGA-r8wv-qg84-pg9q, CGA-v628-qjv7-78rp, CGA-vwhx-47r5-26hf, CGA-w6c4-5355-g6w8, CGA-w74x-3c39-v8mc, CGA-wgfc-jqhq-h8pf, CGA-wh84-4hf6-r6xj, CGA-wwr2-qfhc-v9fj
Trending
Rank 3 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
javascriptweeklyjavascriptweekly2.1.01 of 1See more

javascriptweekly javascriptweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.60.0
1.26.9

Open the chart page →

2,112
sql-exporterjdstoneVerified publisher0.2.11 of 1See more

sql-exporter jdstone 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
burningalchemist/sql_exporter:0.16.0b8e4757c7def
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,448
newtjeffrescVerified publisher0.2.11 of 1See more

newt jeffresc 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
fosrl/newt:1.10.4ccd2b0e9a049
golang.org/x/net@v0.51.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,510
jenkinsjenkins-automation-tool0.1.01 of 1See more

jenkins jenkins-automation-tool 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
jenkinsjenkins-automation-tool-by-helm0.1.01 of 1See more

jenkins jenkins-automation-tool-by-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
jenkinsjenkins-chartVerified publisher0.1.01 of 1See more

jenkins jenkins-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
athens-proxyjenkins-x0.2.21 of 2See more

athens-proxy jenkins-x 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

1,824
jx-app-athensjenkins-x0.0.181 of 1See more

jx-app-athens jenkins-x 0.0.18

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.13.4
0.60.0
1.26.9

Open the chart page →

5,552
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
golang.org/x/net@v0.33.0
stdlib@go1.21.11
0.60.0
1.26.9

Open the chart page →

4,978
jx-app-flaggerjenkins-x0.0.52 of 2See more

jx-app-flagger jenkins-x 0.0.5

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/grafana:6.5.1befcd84da2c1
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9
weaveworks/flagger:1.0.0-rc.5174307de1b36
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.2
0.60.0
1.26.9

Open the chart page →

8,607
jx-app-jenkinsjenkins-x0.0.151 of 2See more

jx-app-jenkins jenkins-x 0.0.15

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
knative-servingjenkins-x0.19.124 of 4See more

knative-serving jenkins-x 0.19.12

4 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned1e3db4f2eeed
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinneddb6ceff2aab4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedb2cd45b8a8a4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.60.0
1.26.9
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedd27b4495ccc3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.60.0
1.26.9

Open the chart page →

14,652
jetspotterjetspotter1.49.01 of 1See more

jetspotter jetspotter 1.49.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/vvanouytsel/jetspotter:1.49.0d6f9149a36db
golang.org/x/net@v0.39.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

1,136
ingress-nginxjfrog4.5.22 of 2See more

ingress-nginx jfrog 4.5.2

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

5,483
vaultjfrog0.25.02 of 2See more

vault jfrog 0.25.0

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
hashicorp/vault:1.14.0b2177a8bfe85
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
hashicorp/vault-k8s:1.2.14500e988b7ce
golang.org/x/net@v0.7.0
stdlib@go1.20.3
0.60.0
1.26.9

Open the chart page →

5,470
kafka-offset-lag-for-prometheusjhidalgo3-githubVerified publisher2.3.01 of 1See more

kafka-offset-lag-for-prometheus jhidalgo3-github 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/net@v0.1.0
stdlib@go1.17.13
0.60.0
1.26.9

Open the chart page →

2,358
missing-container-metricsjimdo-missing-container-metrics0.5.01 of 1See more

missing-container-metrics jimdo-missing-container-metrics 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

3,644
cloudflare-tunneljmmaloney40.1.31 of 1See more

cloudflare-tunnel jmmaloney4 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2022.1.361f608cd1123
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

3,746
ipfsjmmaloney40.9.231 of 1See more

ipfs jmmaloney4 0.9.23

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.27.0bfce363b878b
golang.org/x/net@v0.21.0
stdlib@go1.19.8
0.60.0
1.26.9

Open the chart page →

2,135
job-manager-syncerjob-manager-syncer1.27.01 of 1See more

job-manager-syncer job-manager-syncer 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-syncer:1.27.086957bbeeff5
golang.org/x/net@v0.38.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

944
job-pod-reaperjob-pod-reaper0.14.01 of 1See more

job-pod-reaper job-pod-reaper 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/ohiosupercomputercenter/job-pod-reaper:v0.14.0775449888968
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

340
haven-complinacy-dashboardjolle-devVerified publisher1.0.01 of 2See more

haven-complinacy-dashboard jolle-dev 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

6,270
BNSdeployjongseo220.1.01 of 8See more

BNSdeploy jongseo22 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

218
cloudnative-pgjouveVerified publisher0.27.01 of 1See more

cloudnative-pg jouve 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.28.034198e85b6e6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,085
corednsjouveVerified publisher1.45.01 of 1See more

coredns jouve 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
golang.org/x/net@v0.45.0
stdlib@go1.25.2
0.60.0
1.26.9

Open the chart page →

1,408
distributionjouveVerified publisher0.2.31 of 1See more

distribution jouve 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
distribution/distribution:3.1.1bca24727f400
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,263
etcd-defragjouveVerified publisher0.1.11 of 1See more

etcd-defrag jouve 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/ahrtr/etcd-defrag:v0.45.0b2a97f7fac6e
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

243
api-key-managerjtektVerified publisher0.3.02 of 4See more

api-key-manager jtekt 0.3.0

2 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/postgres:172d2b8998d310
stdlib@go1.24.6
1.26.9
public.ecr.aws/jtekt-corporation/api-key-manager-api:v0.1.175a48d987e0f
stdlib@go1.20.7
1.26.9

Open the chart page →

7,868
image-storage-servicejtektVerified publisher0.5.11 of 4See more

image-storage-service jtekt 0.5.1

1 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.60.0
1.26.9

Open the chart page →

25,612
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.6
0.60.0
1.26.9

Open the chart page →

19,122
firstchartjuanjmerono0.2.01 of 1See more

firstchart juanjmerono 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17
0.60.0
1.26.9

Open the chart page →

2,558
daily-restartjuniorjpdj0.1.721 of 1See more

daily-restart juniorjpdj 0.1.72

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/juniorjpdj/containers/openssl-kubectl:1.36.1-r5136348264b41
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

730
mumbledjjuniorjpdj0.1.2052 of 2See more

mumbledj juniorjpdj 0.1.205

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/juniorjpdj/containers/openssl-kubectl:1.36.1-r5136348264b41
golang.org/x/net@v0.55.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/juniorjpdj/mumbledj:latestd56a7a042e13
stdlib@go1.27.1
1.27.2

Open the chart page →

1,395
alertmanager-irc-relayjuppi880.0.11 of 1See more

alertmanager-irc-relay juppi88 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
maldridge/alertmanager-irc-relay:v0.4.1391de2b76128
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

2,785
nginx-gateway-fabricjupyter-jscVerified publisher2.4.11 of 1See more

nginx-gateway-fabric jupyter-jsc 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/nginx/nginx-gateway-fabric:2.4.180f3a0a51af5
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

762
jupyter-notebook-validator-operatorjupyter-notebook-validatorVerified publisher1.0.101 of 1See more

jupyter-notebook-validator-operator jupyter-notebook-validator 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

218
k10appk10app0.2.11 of 11See more

k10app k10app 0.2.1

1 of the 11 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/k10app/businit:latest94c9a3e799c2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

12,074
multusk3s4.0.201+upv4.0.2-build20240208012 of 2See more

multus k3s 4.0.201+upv4.0.2-build2024020801

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
rancher/hardened-cni-plugins:v1.4.0-build202401222581c5490bab
stdlib@go1.20.7
1.26.9
rancher/hardened-multus-cni:v4.0.2-build202402087d0f41b72eb7
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.60.0
1.26.9

Open the chart page →

2,891
snapshot-controllerk3s1.6.1+up1.6.01 of 1See more

snapshot-controller k3s 1.6.1+up1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
rancher/mirrored-sig-storage-snapshot-controller:v6.1.0934863015367
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.60.0
1.26.9

Open the chart page →

2,397
snapshot-validation-webhookk3s1.6.1+up1.6.01 of 1See more

snapshot-validation-webhook k3s 1.6.1+up1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
rancher/mirrored-sig-storage-snapshot-validation-webhook:v6.1.0deac027820ae
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.60.0
1.26.9

Open the chart page →

2,397
traefikk3s20.3.1+up20.3.01 of 1See more

traefik k3s 20.3.1+up20.3.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
rancher/mirrored-library-traefik:2.9.40842af6afcdf
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.2
0.60.0
1.26.9

Open the chart page →

4,248
k8-ldap-configmapk8-ldap-configmap0.16.01 of 1See more

k8-ldap-configmap k8-ldap-configmap 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/ohiosupercomputercenter/k8-ldap-configmap:v0.16.040d0b67afd77
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

381
k8-namespace-reaperk8-namespace-reaper0.11.01 of 1See more

k8-namespace-reaper k8-namespace-reaper 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/ohiosupercomputercenter/k8-namespace-reaper:v0.11.0ead1f817e8c2
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

340
k8quk8qu1.4.01 of 1See more

k8qu k8qu 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/gijsvandulmen/k8qu:1.4e897b18db13d
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.60.0
1.26.9

Open the chart page →

1,111
k8s-aibomk8s-aibomVerified publisher1.5.11 of 1See more

k8s-aibom k8s-aibom 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/googlecloudplatform/k8s-aibomdigest-pinned7b02731563a5
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

253
k8s-ai-srek8s-ai-sreVerified publisher3.1.21 of 1See more

k8s-ai-sre k8s-ai-sre 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
mohankrishna999/k8s-ai-agent:3.1.27f980f8c650c
golang.org/x/net@v0.57.0
stdlib@go1.26.5-X:jsonv2
0.60.0
1.26.9

Open the chart page →

974
clonarrk8s-chartsVerified publisher0.10.11 of 1See more

clonarr k8s-charts 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/prophetse7en/clonarr:latest9400d298b37a
stdlib@go1.26.4
1.26.9

Open the chart page →

762
deltabadgerk8s-chartsVerified publisher2.0.01 of 1See more

deltabadger k8s-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
stdlib@go1.24.4
1.26.9

Open the chart page →

7,118
palworld-serverk8s-chartsVerified publisher1.2.11 of 1See more

palworld-server k8s-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
stdlib@go1.26.3
1.26.9

Open the chart page →

4,195
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
stdlib@go1.18.1
1.26.9

Open the chart page →

66,013

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
4
quay.io/openshift/origin-cli:latest486bf8e8f5b5
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.60.0
1.26.9
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
4
quay.io/prometheus/blackbox-exporter:latest:v0.29.09613f2884689
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
4
quay.io/prometheus/node-exporter:v1.11.10f422f62c15f
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9
4
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
4
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.60.0
1.26.9
4
quay.io/prometheus/prometheus:latest:v3.14.05ce7540c3c00
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
4
quay.io/thanos/thanos:v0.42.4b567818fe608
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
4
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.60.0
1.26.9
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.60.0
1.26.9
4
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9
4
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-attacher:v4.13.0d1a26170efed
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.18.0b7fefd08651f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
golang.org/x/net@v0.49.0
stdlib@go1.26.3
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
4
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.60.0
1.26.9
4
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.20.6
0.60.0
1.26.9
3
alpine/git:latesta4bb51f1a355
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
3
apache/apisix-ingress-controller:2.2.05c5efa4c7f2a
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
stdlib@go1.14.12
0.60.0
1.26.9
3
bitnamilegacy/etcd:latest99b408c15272
golang.org/x/net@v0.38.0
stdlib@go1.23.10
0.60.0
1.26.9
3
bitnamilegacy/kubectl:latestcd354d5b2556
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9
3
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.17.10
0.60.0
1.26.9
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
golang.org/x/net@v0.42.0
stdlib@go1.25.0
0.60.0
1.26.9
3
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.26.9
3
bitnami/sealed-secrets-controller:0.40.0b1ff382e9300
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
3
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
3
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
stdlib@go1.19.2
0.60.0
1.26.9
3
cloudflare/cloudflared:2026.9.3:latest072c067d25cc
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
3
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.19.13
0.60.0
1.26.9
3
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9
3
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.17.3
0.60.0
1.26.9
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
stdlib@go1.26.5
1.26.9
3
envoyproxy/gateway:v1.7.5156b7d32c73b
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.