StackRadar

CVE-2026-78669

High

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

Excessive CPU consumption from repeated initial window changes in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
DEBIAN-CVE-2026-78669GO-2026-6611CGA-3w4w-29g2-36g3CGA-4qjh-92j9-97fjCGA-76xr-xqfv-pj8rCGA-g6hf-4469-c7p8CGA-jxch-2x88-v4q3CGA-qj25-vfjp-rv4q
Also known as
CGA-33c5-5cfp-cvjx, CGA-3p87-5j3f-57xf, CGA-4fh2-gw9f-8fg8, CGA-4vpq-gwh4-vfh6, CGA-4xr3-wh4x-pgmw, CGA-67cj-prf6-6vgf, CGA-6cfh-5jqc-77x8, CGA-9qq7-44jw-h2p7, CGA-9vww-99xm-r24g, CGA-9w4c-68w5-r52f, CGA-c8vj-2gvm-vvx5, CGA-cvch-844x-r5jh, CGA-fx99-c5qv-v64f, CGA-gc3w-prcc-jwc9, CGA-j22p-m6q6-9jcj, CGA-jxq6-98g2-2pxv, CGA-m5rf-fj6p-qq2j, CGA-p59v-8mpx-gr9m, CGA-r8wv-qg84-pg9q, CGA-v628-qjv7-78rp, CGA-vwhx-47r5-26hf, CGA-w6c4-5355-g6w8, CGA-w74x-3c39-v8mc, CGA-wgfc-jqhq-h8pf, CGA-wh84-4hf6-r6xj, CGA-wwr2-qfhc-v9fj
Trending
Rank 3 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
kubevirt-cloud-controller-managerchristianhuthVerified publisher0.0.21 of 1See more

kubevirt-cloud-controller-manager christianhuth 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,000
kubevirt-managerchristianhuthVerified publisher0.7.01 of 1See more

kubevirt-manager christianhuth 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,435
mailcow-exporterchristianhuthVerified publisher1.5.01 of 1See more

mailcow-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
stdlib@go1.23.12
1.26.9

Open the chart page →

1,143
netbird-reverse-proxychristianhuthVerified publisher0.1.01 of 1See more

netbird-reverse-proxy christianhuth 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
netbirdio/reverse-proxy:0.72.43104d5ca3a76
golang.org/x/net@v0.53.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,328
netcupscp-exporterchristianhuthVerified publisher2.1.01 of 1See more

netcupscp-exporter christianhuth 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/mrueg/netcupscp-exporter:v0.5.25b86c2c0b0e0
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

274
nextcloud-exporterchristianhuthVerified publisher1.5.01 of 1See more

nextcloud-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
xperimental/nextcloud-exporter:0.9.13e90a3897651
stdlib@go1.26.1
1.26.9

Open the chart page →

431
ntp-exporterchristianhuthVerified publisher1.4.01 of 1See more

ntp-exporter christianhuth 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/sapcc/ntp_exporter:v2.9.079c40c65f5d4
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

771
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.26.9

Open the chart page →

6,653
promlenschristianhuthVerified publisher1.6.01 of 1See more

promlens christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
prom/promlens:v0.4.04a377d1a0eaa
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

339
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

3,352
arbitrumchronicleVerified publisher0.3.51 of 1See more

arbitrum chronicle 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

8,015
basechronicleVerified publisher0.0.91 of 1See more

base chronicle 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/net@v0.30.0
stdlib@go1.22.10
0.60.0
1.26.9

Open the chart page →

5,702
ethereumchronicleVerified publisher0.3.21 of 1See more

ethereum chronicle 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

1,744
ethereum-metrics-exporterchronicleVerified publisher0.1.51 of 1See more

ethereum-metrics-exporter chronicle 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
samcm/ethereum-metrics-exporter:0.29.291a2d9a015c1
golang.org/x/net@v0.43.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

991
goferchronicleVerified publisher0.4.51 of 1See more

gofer chronicle 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/gofer:0.613915d2e41e04
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,301
mantlechronicleVerified publisher0.1.41 of 1See more

mantle chronicle 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9

Open the chart page →

2,756
sith-exporterschronicleVerified publisher0.2.61 of 1See more

sith-exporters chronicle 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/oracles-updates-exporter:0.0.4992d0e793af6
stdlib@go1.19.13
1.26.9

Open the chart page →

1,497
spirechronicleVerified publisher0.3.71 of 1See more

spire chronicle 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,010
zksyncchronicleVerified publisher0.1.21 of 2See more

zksync chronicle 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/postgres:143e7dd0bfd7bf
stdlib@go1.24.6
1.26.9

Open the chart page →

7,117
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9

Open the chart page →

4,833
ciliumcilium21.20.23 of 3See more

cilium cilium2 1.20.2

3 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.22939231d0d3e
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82af7382699576
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/cilium/operator-generic:v1.20.264d8798350e8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,840
tetragoncilium21.7.12 of 3See more

tetragon cilium2 1.7.1

2 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/cilium/tetragon-operator:v1.7.1cd8b71f6860e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

512
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/chekrdigest-pinnedf299baf467b5
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

4,567
vulnerability-operatorckotzbauerVerified publisher0.31.151 of 1See more

vulnerability-operator ckotzbauer 0.31.15

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/vulnerability-operator:0.28.167008df32715c
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

442
clairclair-helmVerified publisher0.12.02 of 3See more

clair clair-helm 0.12.0

2 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9
quay.io/projectquay/clair:4.9.023329c3368e4
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

2,335
calico-cniclastixVerified publisher3.28.13 of 3See more

calico-cni clastix 3.28.1

3 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
calico/cni:v3.28.1e486870cfde8
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

4,584
capi-kamaji-vsphere-fullclastixVerified publisher1.0.19 of 9See more

capi-kamaji-vsphere-full clastix 1.0.1

9 of the 9 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/net@v0.32.0
stdlib@go1.23.0
0.60.0
1.26.9
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

10,135
capsule-rancher-addonclastixVerified publisher0.1.15 of 5See more

capsule-rancher-addon clastix 0.1.1

5 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/net@v0.4.0
stdlib@go1.19.2
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

10,934
kamajiclastixVerified publisher0.0.0+latest3 of 4See more

kamaji clastix 0.0.0+latest

3 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
clastix/kamaji:latestbb4bd5e1d9eb
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.60.0
1.26.9

Open the chart page →

6,450
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
golang.org/x/net@v0.23.0
stdlib@go1.23.7
0.60.0
1.26.9

Open the chart page →

3,350
kamaji-etcdclastixVerified publisher0.18.12 of 4See more

kamaji-etcd clastix 0.18.1

2 of the 4 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.60.0
1.26.9

Open the chart page →

14,697
local-path-provisionerclastixVerified publisher0.0.301 of 1See more

local-path-provisioner clastix 0.0.30

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

1,672
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.60.0
1.26.9
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

11,743
cloudflare-ddnsclouddrove0.1.51 of 1See more

cloudflare-ddns clouddrove 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
favonia/cloudflare-ddns:15e61736b982b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
cloudflared-tunnelclouddrove0.1.41 of 1See more

cloudflared-tunnel clouddrove 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

2,350
cronjobclouddrove1.0.11 of 1See more

cronjob clouddrove 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
library/ubuntu:latestf144425ff09b
stdlib@go1.26.7
1.26.9

Open the chart page →

610
kube-acp-stackcloudentity2.29.13 of 7See more

kube-acp-stack cloudentity 2.29.1

3 of the 7 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
stdlib@go1.23.8
1.26.9
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/net@v0.33.0
stdlib@go1.21.13
0.60.0
1.26.9
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.60.0
1.26.9

Open the chart page →

24,606
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.60.0
1.26.9
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.60.0
1.26.9
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.16.6
0.60.0
1.26.9
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

24,753
cloudflare-ddns-updatecloudflare-ddns-update0.1.21 of 1See more

cloudflare-ddns-update cloudflare-ddns-update 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/dploeger/cloudflare-ddns-update:v0.1.0ec06685b9ff4
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,829
cloudflare-dyndnscloudflare-dyndnsVerified publisher1.1.01 of 1See more

cloudflare-dyndns cloudflare-dyndns 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/msueberkrueb/cloudflare-dyndns:1.0.0e5c945a3b000
stdlib@go1.25.1
1.26.9

Open the chart page →

622
cloudflare-tunnel-ingress-controllercloudflare-tunnel-ingress-controller0.2.31 of 1See more

cloudflare-tunnel-ingress-controller cloudflare-tunnel-ingress-controller 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/oliverbaehler/cloudflare-tunnel-ingress-controller:0.2.30aec31e36d95
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9

Open the chart page →

873
cloudfront-tenant-operatorcloudfront-tenant-operatorVerified publisher0.3.01 of 1See more

cloudfront-tenant-operator cloudfront-tenant-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
golang.org/x/net@v0.51.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

566
hcloud-ccm-mgmtcloudhippieVerified publisher1.13.01 of 1See more

hcloud-ccm-mgmt cloudhippie 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.39.0d6fee5698759
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

238
hcloud-csi-mgmtcloudhippieVerified publisher2.11.05 of 5See more

hcloud-csi-mgmt cloudhippie 2.11.0

5 of the 5 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.13.0d1a26170efed
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.4.06ebe60fd8ed6
golang.org/x/net@v0.59.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.3.048fb3deb93cd
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.20.019f2cf2f40e1
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

953
hcloud-csi-usercloudhippieVerified publisher1.8.03 of 3See more

hcloud-csi-user cloudhippie 1.8.0

3 of the 3 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.18.0b7fefd08651f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.20.019f2cf2f40e1
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

668
cloudian-exportercloudian-exporter0.1.41 of 1See more

cloudian-exporter cloudian-exporter 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
ghcr.io/dodevops/cloudian-exporter:0.1.18b7f2816541c
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.60.0
1.26.9

Open the chart page →

1,311
mercurecloudnativeapp1.0.21 of 1See more

mercure cloudnativeapp 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
dunglas/mercure:v0916834e49961
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,403
nginx-ingress-controllercloudnativeapp3.4.51 of 2See more

nginx-ingress-controller cloudnativeapp 3.4.5

1 of the 2 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnami/nginx:latestb8d42f076789
stdlib@go1.26.8
1.26.9

Open the chart page →

111
argocd-operatorcloud-native-toolkit0.6.11 of 1See more

argocd-operator cloud-native-toolkit 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

141
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78669.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/net@v0.14.0
stdlib@go1.19.10
0.60.0
1.26.9

Open the chart page →

26,588

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kuberocketci/krci-cache:0.3.05f6cd61e6da6
golang.org/x/net@v0.55.0
stdlib@go1.25.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/alertmanagerd1e7285865d8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/caddy015a4b181ab2
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/cert-manager-cainjectorcdb9b39d2eaf
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/cert-manager-controllerb4e5fb144442
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/cert-manager-webhookd342342b50a6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/kube-state-metrics15a1f0e114c0
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
3
ghcr.io/quenchworks/images/kyvernofe359fcd4ff7
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/loki42ab0d3d3b27
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/node-exporter33cb1038d69b
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/otel-collectora3b591872cdb
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/seaweedfsd884b75765cf
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/quenchworks/images/tempo21bde52fb227
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
3
ghcr.io/rabbitmq/messaging-topology-operator:1.20.3f377d3c3e221
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
3
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.33e591f98e3899
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
3
ghcr.io/sigstore/scaffolding/createdb16673c1099a5
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
3
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3324293fa1ed50
golang.org/x/net@v0.47.0
stdlib@go1.25.0
0.60.0
1.26.9
3
ghcr.io/sigstore/scaffolding/trillian_log_server32ee491f4d00
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2
3
ghcr.io/sigstore/scaffolding/trillian_log_signer3d0152303816
golang.org/x/net@v0.59.0
stdlib@go1.27.0
0.60.0
1.27.2
3
ghcr.io/spiffe/spire-agent:1.15.341b0dcd8b258
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
3
ghcr.io/victoriametrics/sync-job:v0.0.17b6f233532a85
golang.org/x/net@v0.56.0
stdlib@go1.26.4-X:jsonv2
0.60.0
1.26.9
3
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.26.9
3
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.7
0.60.0
1.26.9
3
quay.io/argoproj/argocli:v4.1.5e0824b55297b
stdlib@go1.26.5
1.26.9
3
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
golang.org/x/net@v0.57.0
stdlib@go1.25.6
0.60.0
1.26.9
3
quay.io/argoproj/argo-rollouts:v1.10.0187630ba7228
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
3
quay.io/argoproj/argo-workflows-crdinstaller:v4.1.593534a0d0ba3
golang.org/x/net@v0.49.0
stdlib@go1.26.5
0.60.0
1.26.9
3
quay.io/argoproj/workflow-controller:v4.1.5328307c9436f
stdlib@go1.26.5
1.26.9
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.60.0
1.26.9
3
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
stdlib@go1.19.8
0.60.0
1.26.9
3
quay.io/cilium/cilium:v1.20.22939231d0d3e
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
3
quay.io/cilium/operator-generic:v1.20.264d8798350e8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
3
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.60.0
1.26.9
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.17.13
0.60.0
1.26.9
3
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.60.0
1.26.9
3
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.60.0
1.26.9
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.60.0
1.26.9
3
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.26.9
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
golang.org/x/net@v0.48.0
stdlib@go1.24.0
0.60.0
1.26.9
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
3
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.6
0.60.0
1.26.9
3
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
golang.org/x/net@v0.40.0
stdlib@go1.24.13
0.60.0
1.26.9
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
golang.org/x/net@v0.48.0
stdlib@go1.25.0
0.60.0
1.26.9
3
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.26.9
3
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
stdlib@go1.18
1.26.9
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.60.0
1.26.9
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.16.10
0.60.0
1.26.9
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
stdlib@go1.25.5
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.