StackRadar

CVE-2026-97032

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

HTTP/2 server crash due to HPACK encoder race in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-387c-5f4p-4rh4CGA-4653-rw6m-872gCGA-4h9w-grf4-6jppCGA-8xvx-5mh6-vrc3CGA-f937-jwj2-rj5jCGA-fjhw-67fq-pm89DEBIAN-CVE-2026-97032GO-2026-6617
Also known as
CGA-3qgw-9846-f468, CGA-499x-7xc5-927w, CGA-4qpc-rjrp-f4h4, CGA-5pv4-5xjw-qg97, CGA-5rcr-cqmr-f8hp, CGA-5vh8-jrpp-m4r3, CGA-8g7x-r6mw-97j8, CGA-8mf9-xfh8-jx3h, CGA-923f-66wm-xfq4, CGA-9hgh-r65w-7q99, CGA-fjfp-jwwq-vjp3, CGA-gg5j-j7wm-wf6w, CGA-jrgf-gwq3-rf5w, CGA-m46j-x3g6-mqj4, CGA-mq7q-c763-9cvx, CGA-p4p3-mvmj-v95v, CGA-qpfw-4v8x-3667, CGA-qpqr-hw3x-7qxj, CGA-qqxw-hjpg-6rhv, CGA-r654-5gg7-p6xf, CGA-rggh-6rrq-mfp4, CGA-rwc6-gqq6-4p7r, CGA-vh2x-9247-h576, CGA-w2j8-94m3-rxc6, CGA-w2rp-6hc9-f8qw, CGA-w39g-2gpg-cfqr
Trending
Rank 6 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
openstack-kamaji-clusteropenstack-kamaji-clusterVerified publisher0.2.41 of 1See more

openstack-kamaji-cluster openstack-kamaji-cluster 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
golang.org/x/net@v0.38.0
stdlib@go1.24.7
0.60.0
1.26.9

Open the chart page →

1,183
opentelemetry-demoopentelemetry-helmOfficialVerified publisher0.42.310 of 34See more

opentelemetry-demo opentelemetry-helm 0.42.3

10 of the 34 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
grafana/grafana:13.2.2-distroless69a5d2d957ca
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9
jaegertracing/jaeger:2.20.046a886260e04
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.26.9
otel/opentelemetry-collector-contrib:0.160.0799dc6cf12c9
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/open-feature/flagd:v0.16.032234e63c1d0
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.60.0
1.26.9
ghcr.io/open-telemetry/demo:3.1.0-cart17c881cf29af
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/open-telemetry/demo:3.1.0-opamp-server3b6c6220bf9c
stdlib@go1.27.1
1.27.2
ghcr.io/open-telemetry/demo:3.1.0-product-catalog7578cbf65fa4
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
ghcr.io/open-telemetry/demo:3.1.0-checkoutd4448ff54129
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/prometheus/prometheus:v3.14.05ce7540c3c00
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

26,079
openvaultopenvaultVerified publisher0.9.01 of 2See more

openvault openvault 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
stdlib@go1.23.7
1.26.9

Open the chart page →

8,097
openvox-operatoropenvox-operatorVerified publisher0.14.01 of 1See more

openvox-operator openvox-operator 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/slauger/openvox-operator:0.14.0178b6dab6c8c
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

147
opikopikOfficialVerified publisher2.2.966 of 12See more

opik opik 2.2.96

6 of the 12 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.0862d86046bbc
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9
altinity/clickhouse-operator:0.27.1a802b3a19d20
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.26.9
library/zookeeper:3.9.4dfa9ba46d14b
stdlib@go1.18.1
1.26.9
ghcr.io/comet-ml/opik/opik-python-backend:2.2.967cd6d608b6a4
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

15,883
opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest35575d4f2bfe
golang.org/x/net@v0.39.0
stdlib@go1.24.13
0.60.0
1.26.9
shaowenchen/ops-server:latest6bac5cebd125
golang.org/x/net@v0.39.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

100,859
orbitalregorbitalregVerified publisher0.4.03 of 5See more

orbitalreg orbitalreg 0.4.0

3 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
stdlib@go1.24.6
1.26.9
orbitalreg/orbitalreg-api:0.4.03ffa632cadb2
golang.org/x/net@v0.57.0
stdlib@go1.25.14
0.60.0
1.26.9
orbitalreg/orbitalreg-scanner:0.4.0f72711b94d11
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

5,271
kubernetes-dashboard-proxyosc0.7.23 of 4See more

kubernetes-dashboard-proxy osc 0.7.2

3 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.7.02e500d29e9d5
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9
kubernetesui/metrics-scraper:v1.0.876049887f07a
golang.org/x/net@v0.0.0-20220524220425-1d687d428aca
stdlib@go1.18.2
0.60.0
1.26.9
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16
0.60.0
1.26.9

Open the chart page →

8,871
osc-bsu-csi-driverosc-bsu-csi-driverVerified publisher2.2.06 of 6See more

osc-bsu-csi-driver osc-bsu-csi-driver 2.2.0

6 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
outscale/osc-bsu-csi-driver:v1.12.063871940b621
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.16.088092d100909
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

4,246
httpbinowan-charts0.1.91 of 1See more

httpbin owan-charts 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
mccutchen/go-httpbin:latest20739736d4eb
stdlib@go1.26.5
1.26.9

Open the chart page →

197
hlf-caowkin2.1.02 of 2See more

hlf-ca owkin 2.1.0

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.7
0.60.0
1.26.9
jwilder/dockerize:latestf94fb59fb4f6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

4,903
hlf-ordowkin3.1.01 of 1See more

hlf-ord owkin 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hyperledger/fabric-orderer:2.2.137294e05209b
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.4
0.60.0
1.26.9

Open the chart page →

4,531
hlf-peerowkin5.1.01 of 1See more

hlf-peer owkin 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hyperledger/fabric-peer:2.2.1bf4995c86af6
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.4
0.60.0
1.26.9

Open the chart page →

4,901
prometheus-cachethqoxyno-zetaVerified publisher1.1.11 of 1See more

prometheus-cachethq oxyno-zeta 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
oxynozeta/prometheus-cachethq:1.1.131f11669d597
stdlib@go1.15.1
1.26.9

Open the chart page →

2,715
p10logsp10logsOfficialVerified publisher1.1.42 of 2See more

p10logs p10logs 1.1.4

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/p10node/p10logs-agent:1.1.44bc72bd8ff5a
stdlib@go1.26.8
1.26.9
ghcr.io/p10node/p10logs-hub:1.1.44385afd18845
stdlib@go1.26.8
1.26.9

Open the chart page →

178
ngrok-operatorpaganuzzi0.0.21 of 1See more

ngrok-operator paganuzzi 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/paganuzzi/ngrokoperator:latest5a10cd095699
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

3,930
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
stdlib@go1.25.12
1.26.9

Open the chart page →

4,503
prowlarrpanzer1119Verified publisher0.4.181 of 2See more

prowlarr panzer1119 0.4.18

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,150
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
stdlib@go1.24.4
1.26.9

Open the chart page →

10,841
pardus-nginx-nodeportpardus-charts0.5.01 of 1See more

pardus-nginx-nodeport pardus-charts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
uderelier19/pardus-nginx:25-nodeport8ab640b44e3f
stdlib@go1.24.4
1.26.9

Open the chart page →

644
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

8,434
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.60.0
1.26.9
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.21.9
0.60.0
1.26.9

Open the chart page →

9,581
pbuf-registrypbuf-registry0.4.12 of 2See more

pbuf-registry pbuf-registry 0.4.1

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.1-alpine3.2144d837eb4c2e
stdlib@go1.24.6
1.26.9
ghcr.io/pbufio/registry:v0.4.177a36c035b4b
golang.org/x/net@v0.45.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,869
pdf-editor-helmpdf-editor-web1.0.02 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
stdlib@go1.18.7
1.26.9
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
stdlib@go1.18.7
1.26.9

Open the chart page →

5,605
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
stdlib@go1.24.4
1.26.9

Open the chart page →

8,640
pg-operatorpercona3.1.01 of 1See more

pg-operator percona 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
percona/percona-postgresql-operator:3.1.0a7c50ef1545e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

220
periscopeperiscopeVerified publisher1.1.61 of 1See more

periscope periscope 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,266
perspectivegraphperspectivegraphOfficialVerified publisher1.36.01 of 5See more

perspectivegraph perspectivegraph 1.36.0

1 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/nats:2.15.0-scratchc0d27f305460
stdlib@go1.27.1
1.27.2

Open the chart page →

97
pgbouncerpgbouncer-helm0.6.01 of 2See more

pgbouncer pgbouncer-helm 0.6.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
stdlib@go1.23.7
1.26.9

Open the chart page →

818
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

10,966
full-housephilmtd1.3.21 of 1See more

full-house philmtd 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
philmtd/full-house:1.10.0224d602420ba
golang.org/x/net@v0.59.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

290
chadbotphntom0.2.31 of 1See more

chadbot phntom 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
phntom/chadbot:0.2.397c28e4178ad
golang.org/x/net@v0.11.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

1,683
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
golang.org/x/net@v0.10.0
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

3,747
matterircdphntom0.1.71 of 2See more

matterircd phntom 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
42wim/matterircd:latest23c951580801
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

166
phonebook-chartphonebook-chart0.1.01 of 3See more

phonebook-chart phonebook-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

3,831
phpipamphpipam-helmVerified publisher1.0.121 of 3See more

phpipam phpipam-helm 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.26.9

Open the chart page →

4,663
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.15.8
0.60.0
1.26.9

Open the chart page →

3,253
piraeuspiraeus-operatorVerified publisher2.12.01 of 1See more

piraeus piraeus-operator 2.12.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/piraeusdatastore/piraeus-operator:v2.12.02fee47e187c1
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

138
pocket-id-operatorpocket-id-operatorVerified publisher0.15.01 of 1See more

pocket-id-operator pocket-id-operator 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/aclerici38/pocket-id-operator:v0.15.0e1f94e349df1
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
matomopockostVerified publisher1.4.01 of 3See more

matomo pockost 1.4.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mariadb:12.3.3dd9b303aed4f
stdlib@go1.24.6
1.26.9

Open the chart page →

6,224
podtracepodtraceOfficialVerified publisher0.14.82 of 2See more

podtrace podtrace 0.14.8

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
alpine/k8s:1.37.0b421c2e9419e
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/gma1k/podtrace:0.14.89a59d6301d74
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,302
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

3,325
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.26.9
treskon/portrait:DEV-latest88e813f22347
stdlib@go1.26.5
1.26.9

Open the chart page →

36,867
postfix-exporterpostfix-exporterVerified publisher0.2.11 of 1See more

postfix-exporter postfix-exporter 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/hsn723/postfix_exporter:0.21.28b0994de44a9
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
postgres-backuppostgres-backup0.3.02 of 2See more

postgres-backup postgres-backup 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.26.9
nerzhul/mc-arm64:2020.10.034215df511f31
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

5,471
postgresqlpostgresqlVerified publisher0.3.172 of 2See more

postgresql postgresql 0.3.17

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.6-alpine77f585114c32
stdlib@go1.24.6
1.26.9
pgautoupgrade/pgautoupgrade:18-alpine2245aabc5b80
stdlib@go1.24.6
1.26.9

Open the chart page →

1,306
postgresqlpostgresql-helm0.1.21 of 1See more

postgresql postgresql-helm 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9

Open the chart page →

1,853
rethinkdbpozetron1.1.91 of 1See more

rethinkdb pozetron 1.1.9

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

4,442
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,038
home-assistantpree-helm-chartsVerified publisher1.83.01 of 1See more

home-assistant pree-helm-charts 1.83.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.10.01b64d38f38d9
golang.org/x/net@v0.49.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

2,734

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.60.0
1.26.9
2
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
2
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.2
0.60.0
1.26.9
2
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
2
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/net@v0.0.0-20221004154528-8021a29435af
stdlib@go1.19.3
0.60.0
1.26.9
2
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.60.0
1.26.9
2
helmforge/kubectl:1.35.3c3f97e954c47
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
2
hetznercloud/hcloud-cloud-controller-manager:v1.39.0d6fee5698759
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.13.8
0.60.0
1.26.9
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
golang.org/x/net@v0.17.0
stdlib@go1.21.10
0.60.0
1.26.9
2
ilum/api:6.7.3624fd09528c8
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
2
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
stdlib@go1.20.12
0.60.0
1.26.9
2
inaccel/daemon:latest093e1ea90ab8
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9
2
inaccel/mkrt:latest187fd448b6f2
stdlib@go1.21.5
1.26.9
2
inaccel/reef:latestc967218739f3
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.60.0
1.26.9
2
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
2
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.60.0
1.26.9
2
iomesh/csi-snapshotter:v6.2.2becc53e25b96
golang.org/x/net@v0.8.0
stdlib@go1.19
0.60.0
1.26.9
2
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.13.1
0.60.0
1.26.9
2
iomesh/livenessprobe:v2.8.0560f01510f99
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
stdlib@go1.18
0.60.0
1.26.9
2
iomesh/localpv-manager:v0.2.0f13deacac3f4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20.3
0.60.0
1.26.9
2
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.7
0.60.0
1.26.9
2
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
golang.org/x/net@v0.8.0
stdlib@go1.19
0.60.0
1.26.9
2
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.60.0
1.26.9
2
ipfs/ipfs-cluster:latest:v1.1.6a83266c524f1
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
2
ipfs/kubo:v0.33.21a30f5ed8579
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
2
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
2
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.60.0
1.26.9
2
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.4
0.60.0
1.26.9
2
istio/proxyv2:1.18.0757d28c24100
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.60.0
1.26.9
2
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.13
0.60.0
1.26.9
2
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.4
0.60.0
1.26.9
2
istio/proxyv2:1.10.3a78b7a165744
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.6
0.60.0
1.26.9
2
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.6
0.60.0
1.26.9
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
golang.org/x/net@v0.7.0
stdlib@go1.20.6
0.60.0
1.26.9
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
stdlib@go1.13.11
0.60.0
1.26.9
2
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.60.0
1.26.9
2
jhaals/yopass:14.10.06c33d9c813f7
stdlib@go1.27.1
1.27.2
2
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17
0.60.0
1.26.9
2
juicedata/csi-dashboard:v0.33.05e5edb62a010
golang.org/x/net@v0.55.0
stdlib@go1.25.14
0.60.0
1.26.9
2
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
golang.org/x/net@v0.52.0
stdlib@go1.25.14
0.60.0
1.26.9
2
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.60.0
1.26.9
2
kbudde/rabbitmq-exporter:1.0.0:latest12f27d6d84e6
stdlib@go1.21.8
1.26.9
2
kong/kubernetes-ingress-controller:3.5979f12864a13
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
2
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.1
0.60.0
1.26.9
2
kubeshop/testkube-api-server:2.14.1ce04897e5ea2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
2
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.60.0
1.26.9
2
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.60.0
1.26.9
2
l7mp/stunner-auth-server:1.2.10d2094060b72
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.