StackRadar

CVE-2026-78669

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

Excessive CPU consumption from repeated initial window changes in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r71
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4qjh-92j9-97fjCGA-4vpq-gwh4-vfh6CGA-76xr-xqfv-pj8rCGA-g6hf-4469-c7p8CGA-jxch-2x88-v4q3CGA-qj25-vfjp-rv4qDEBIAN-CVE-2026-78669GO-2026-6611
Also known as
CGA-33c5-5cfp-cvjx, CGA-3p87-5j3f-57xf, CGA-3w4w-29g2-36g3, CGA-4fh2-gw9f-8fg8, CGA-4xr3-wh4x-pgmw, CGA-67cj-prf6-6vgf, CGA-6cfh-5jqc-77x8, CGA-9qq7-44jw-h2p7, CGA-9vww-99xm-r24g, CGA-9w4c-68w5-r52f, CGA-c8vj-2gvm-vvx5, CGA-cvch-844x-r5jh, CGA-fx99-c5qv-v64f, CGA-gc3w-prcc-jwc9, CGA-j22p-m6q6-9jcj, CGA-jxq6-98g2-2pxv, CGA-m5rf-fj6p-qq2j, CGA-p59v-8mpx-gr9m, CGA-r8wv-qg84-pg9q, CGA-v628-qjv7-78rp, CGA-vwhx-47r5-26hf, CGA-w6c4-5355-g6w8, CGA-w74x-3c39-v8mc, CGA-wgfc-jqhq-h8pf, CGA-wh84-4hf6-r6xj, CGA-wwr2-qfhc-v9fj
Trending
Rank 3 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
exalsius-operatorexalsius-operatorVerified publisher0.12.11 of 1See more

exalsius-operator exalsius-operator 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/exalsius/exalsius-operator:0.12.15e21ecd86281
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

232
exchange-hackexchange-hack0.1.01 of 1See more

exchange-hack exchange-hack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
oranhack7/solidproject:77c6453942223f
stdlib@go1.21.7
1.26.9

Open the chart page →

1,321
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.03 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/loki:2.9.66ca6e2cd3b6f
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
grafana/loki-canary:2.9.6549a40203e97
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
grafana/promtail:3.5.165bfae480b57
golang.org/x/net@v0.38.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

8,031
extended-ceph-exporterextended-ceph-exporterVerified publisher1.10.01 of 2See more

extended-ceph-exporter extended-ceph-exporter 1.10.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
galexrt/extended-ceph-exporter:v1.8.05373078a3a08
stdlib@go1.24.8
1.26.9

Open the chart page →

4,022
external-dns-watcherexternal-dns-watcherVerified publisher3.3.11 of 1See more

external-dns-watcher external-dns-watcher 3.3.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/kubehippie/external-dns-watcher:3.3.1d460a6fcd8ef
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

208
siyuanextrim-helm-chartsVerified publisher0.1.11 of 2See more

siyuan extrim-helm-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
b3log/siyuan:v3.1.2595c0d129bc19
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

2,203
faasnetfaasnet0.0.42 of 5See more

faasnet faasnet 0.0.4

2 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.1
0.60.0
1.26.9
mcr.microsoft.com/mssql/server:latest2b5b58162112
stdlib@go1.26.1
1.26.9

Open the chart page →

10,628
reverse-geocodingfaas-reverse-geocoding0.3.31 of 1See more

reverse-geocoding faas-reverse-geocoding 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/saidsef/faas-reverse-geocoding:latestaef8c7610ef0
stdlib@go1.27.1
1.27.2

Open the chart page →

153
degafactlyVerified publisher0.11.132 of 3See more

dega factly 0.11.13

2 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
factly/dega-api:0.15.166fafc7b0a17
stdlib@go1.16.2
1.26.9
factly/dega-server:0.15.194d21479382e
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

8,003
kavachfactlyVerified publisher0.9.51 of 2See more

kavach factly 0.9.5

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
factly/kavach-server:0.22.3be85ff1b9bd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

4,785
mandefactlyVerified publisher0.5.181 of 3See more

mande factly 0.5.18

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
factly/mande-server:0.34.1384d384310ef
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

5,686
basic-demofairwinds-incubator1.0.01 of 1See more

basic-demo fairwinds-incubator 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
stdlib@go1.20.4
1.26.9

Open the chart page →

2,155
datadog-apmfairwinds-incubator2.0.11 of 1See more

datadog-apm fairwinds-incubator 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
golang.org/x/net@v0.47.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

3,732
kubebenchfairwinds-incubator1.0.51 of 2See more

kubebench fairwinds-incubator 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.15.07a8fa32dce21
golang.org/x/net@v0.49.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

1,640
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.13
0.60.0
1.26.9

Open the chart page →

6,089
skopeo-syncfairwinds-incubator0.3.11 of 1See more

skopeo-sync fairwinds-incubator 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/skopeo/stable:v1.134853591bd1d2
golang.org/x/net@v0.11.0
stdlib@go1.21.0
0.60.0
1.26.9

Open the chart page →

2,464
stackdriver-metrics-adapterfairwinds-incubator0.3.01 of 1See more

stackdriver-metrics-adapter fairwinds-incubator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

2,636
yelbfairwinds-incubator0.1.11 of 5See more

yelb fairwinds-incubator 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/postgres:latest74935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

6,777
fairwinds-insightsfairwinds-stableVerified publisher10.7.24 of 13See more

fairwinds-insights fairwinds-stable 10.7.2

4 of the 13 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.49ccd82364762
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9
temporalio/admin-tools:1.32.0a9f84fb9a374
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
temporalio/server:1.32.0c3e752127759
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
temporalio/ui:2.54.1ff0943fe532b
golang.org/x/net@v0.49.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

3,855
fake-network-operatorfake-network-operatorVerified publisher0.1.01 of 1See more

fake-network-operator fake-network-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/muhmmadayan/fake-network-operator:0.1.03806b1fd4a4b
golang.org/x/net@v0.28.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

996
aspmrelayfalcon-helmVerified publisher1.1.01 of 1See more

aspmrelay falcon-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/bionicstork/bionicstork/relay:latest978a59e0f79f
stdlib@go1.25.14
1.26.9

Open the chart page →

210
event-generatorfalcosecurity0.4.01 of 1See more

event-generator falcosecurity 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
falcosecurity/event-generator:latest932956d86c99
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

4,504
k8s-metacollectorfalcosecurity0.3.21 of 1See more

k8s-metacollector falcosecurity 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
falcosecurity/k8s-metacollector:0.1.42c9b17ec36e8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

201
farm-observabilityfarm-observabilityOfficialVerified publisher0.27.214 of 18See more

farm-observability farm-observability 0.27.2

14 of the 18 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/alloy:v1.16.384b76d56c594
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
grafana/alloy:v1.12.2f94b1c82957a
golang.org/x/net@v0.46.0
stdlib@go1.25.5
0.60.0
1.26.9
grafana/grafana:13.0.1-security-012d1f9ae67c17
golang.org/x/net@v0.52.0
stdlib@go1.26.2
0.60.0
1.26.9
grafana/loki:3.6.73c8fd3570dd9
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
grafana/loki-canary:3.6.70dac7d5cb383
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9
grafana/pyroscope:2.0.3cfd00e7f73c2
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9
grafana/tempo:2.9.065a578975943
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/jkroepke/kube-webhook-certgen:1.8.38ce13c365c8e
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.91.07d9e4eea5f11
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.91.09e53e1313921
golang.org/x/net@v0.53.0
stdlib@go1.25.9
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.11.1-distroless6112664fd761
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

19,851
jenkinsfatihtepe-jenkins1.0.01 of 1See more

jenkins fatihtepe-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,129
fauxgpufauxgpuVerified publisher0.2.41 of 4See more

fauxgpu fauxgpu 0.2.4

1 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/devops-dojo7/fauxgpu/device-plugin:0.2.4e5a12388e3d8
golang.org/x/net@v0.29.0
stdlib@go1.23.12
0.60.0
1.26.9

Open the chart page →

4,017
featureformfeatureformVerified publisher0.15.101 of 12See more

featureform featureform 0.15.10

1 of the 12 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:latestefd719c99d83
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

250
quickstartfeatureformVerified publisher0.1.12 of 3See more

quickstart featureform 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
featureformcom/quickstart-loader:latest82396f8fb5e8
stdlib@go1.21.11
1.26.9
library/postgres:latest74935e722416
stdlib@go1.24.6
1.26.9

Open the chart page →

3,826
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
stdlib@go1.16.5
0.60.0
1.26.9

Open the chart page →

16,021
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.60.0
1.26.9

Open the chart page →

7,160
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.60.0
1.26.9

Open the chart page →

8,780
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.5
0.60.0
1.26.9

Open the chart page →

16,429
ferretdbferretdb-helm-chart0.2.31 of 1See more

ferretdb ferretdb-helm-chart 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/ferretdb/ferretdb:2.7.05706414241eb
golang.org/x/net@v0.46.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

1,212
infrafibonacci-cluster-infraVerified publisher1.0.02 of 4See more

infra fibonacci-cluster-infra 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.26.9
library/redis:7.4.1bb142a9c18ac
stdlib@go1.18.2
1.26.9

Open the chart page →

15,258
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.5
0.60.0
1.26.9

Open the chart page →

4,499
grgatefikaworks0.3.41 of 1See more

grgate fikaworks 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
stdlib@go1.20.2
1.26.9

Open the chart page →

1,728
filebrowserfilebrowser-rr0.1.01 of 1See more

filebrowser filebrowser-rr 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2-s6ee4ac79e5296
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

1,123
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
golang.org/x/net@v0.25.0
stdlib@go1.19.13
0.60.0
1.26.9

Open the chart page →

9,990
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mariadb:11.41292844148b3
stdlib@go1.24.6
1.26.9

Open the chart page →

8,886
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

6,617
first-matefirst-mateVerified publisher1.0.51 of 1See more

first-mate first-mate 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
chriswells0/first-mate:1.0.5f3918ec8471c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

2,417
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:3.6.213e51da56fc54
stdlib@go1.15.1
1.26.9

Open the chart page →

119,253
consent-owner-resolverfiware0.1.11 of 1See more

consent-owner-resolver fiware 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/seamware/consent-owner-resolver:0.0.8f1f8abe4fc5f
stdlib@go1.27.0
1.27.2

Open the chart page →

141
did-helperfiware0.1.221 of 1See more

did-helper fiware 0.1.22

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/seamware/did-helper:0.6.0799c5f566952
stdlib@go1.26.7
1.26.9

Open the chart page →

658
dsba-pdpfiware0.1.22 of 2See more

dsba-pdp fiware 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
golang.org/x/net@v0.1.0
stdlib@go1.18.10
0.60.0
1.26.9
quay.io/wi_stefan/dsba-db-migrations:0.0.125b986cd14a08
stdlib@go1.18.9
1.26.9

Open the chart page →

5,617
endpoint-auth-servicefiware0.1.43 of 4See more

endpoint-auth-service fiware 0.1.4

3 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.3
0.60.0
1.26.9
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.60.0
1.26.9
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
stdlib@go1.18.5
1.26.9

Open the chart page →

14,691
vcverifierfiware4.15.41 of 1See more

vcverifier fiware 4.15.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/fiware/vcverifier:6.24.07260751de292
golang.org/x/net@v0.38.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

701
grafanaflagger1.7.01 of 1See more

grafana flagger 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.5
0.60.0
1.26.9

Open the chart page →

4,594
podinfoflagger6.1.41 of 1See more

podinfo flagger 6.1.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.9
0.60.0
1.26.9

Open the chart page →

3,800
apm-hubflanksourceVerified publisher0.0.472 of 2See more

apm-hub flanksource 0.0.47

2 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
library/postgres:14bdc3027c1610
stdlib@go1.24.6
1.26.9

Open the chart page →

7,227

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.60.0
1.26.9
3
natsio/nats-account-server:1.0.0a3381560aab6
stdlib@go1.16.6
1.26.9
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.26.9
3
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.26.9
3
oamdev/kube-webhook-certgen:v2.4.1231c423c2b17
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.11
0.60.0
1.26.9
3
oliver006/redis_exporter:v1.93.06ca518a72f30
stdlib@go1.27.1
1.27.2
3
opencsghq/postgres:15.19b98600564e07
stdlib@go1.24.6
1.26.9
3
opencsghq/stakater-reloader:v1.4.190491782f7bac
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
3
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
3
openebs/provisioner-localpv:3.5.0aea39e49bb97
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
3
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.60.0
1.26.9
3
otel/opentelemetry-collector:latest310a800ad69e
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
pgsty/silo:RELEASE.2026-09-03T13-18-01Zb616a0cf8cb2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
3
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
3
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
3
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.60.0
1.26.9
3
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.26.9
3
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.26.9
3
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.26.9
3
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.26.9
3
qingcloud/cloud-controller-manager:v1.4.1210f66b5df886
stdlib@go1.18.2
1.26.9
3
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.60.0
1.26.9
3
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
3
rancher/system-upgrade-controller:v0.20.261b68d4372ba
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
3
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.26.9
3
solace/solace-pubsub-standard:latest3c8a8b7fdcae
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.60.0
1.26.9
3
tykio/tyk-dashboard:v5.13.21161bd297135
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
tykio/tyk-gateway-ee:v5.13.250b3e4f5398a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
3
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
3
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.26.9
3
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/net@v0.27.0
stdlib@go1.23.4
0.60.0
1.26.9
3
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.26.9
3
yugabytedb/yugabyte:2026.1.2.0-b137b6dba322c734
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
gcr.io/trillian-opensource-ci/db_server2a685a38dd01
stdlib@go1.18.2
1.26.9
3
ghcr.io/appscode/petset:v0.1.093fa0daf603c
golang.org/x/net@v0.47.0
stdlib@go1.25.10
0.60.0
1.26.9
3
ghcr.io/appscode/sidekick:v0.0.15d1036b07e348
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9
3
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.60.0
1.26.9
3
ghcr.io/coder/coder:v2.38.038a4cfc548b0
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9
3
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.60.0
1.26.9
3
ghcr.io/external-secrets/external-secrets:v2.12.07a3c4f7e038f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
3
ghcr.io/hatchet-dev/hatchet/hatchet-admin:v0.110.57c233e606095
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/hatchet-dev/hatchet/hatchet-api:v0.110.5be06a6b88299
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/hatchet-dev/hatchet/hatchet-frontend:v0.110.5136c6a29a81a
stdlib@go1.26.8
1.26.9
3
ghcr.io/hatchet-dev/hatchet/hatchet-migrate:v0.110.5b2112d73f37a
stdlib@go1.26.8
1.26.9
3

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.