StackRadar

CVE-2026-97032

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

HTTP/2 server crash due to HPACK encoder race in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-387c-5f4p-4rh4CGA-4653-rw6m-872gCGA-4h9w-grf4-6jppCGA-8xvx-5mh6-vrc3CGA-f937-jwj2-rj5jCGA-fjhw-67fq-pm89DEBIAN-CVE-2026-97032GO-2026-6617
Also known as
CGA-3qgw-9846-f468, CGA-499x-7xc5-927w, CGA-4qpc-rjrp-f4h4, CGA-5pv4-5xjw-qg97, CGA-5rcr-cqmr-f8hp, CGA-5vh8-jrpp-m4r3, CGA-8g7x-r6mw-97j8, CGA-8mf9-xfh8-jx3h, CGA-923f-66wm-xfq4, CGA-9hgh-r65w-7q99, CGA-fjfp-jwwq-vjp3, CGA-gg5j-j7wm-wf6w, CGA-jrgf-gwq3-rf5w, CGA-m46j-x3g6-mqj4, CGA-mq7q-c763-9cvx, CGA-p4p3-mvmj-v95v, CGA-qpfw-4v8x-3667, CGA-qpqr-hw3x-7qxj, CGA-qqxw-hjpg-6rhv, CGA-r654-5gg7-p6xf, CGA-rggh-6rrq-mfp4, CGA-rwc6-gqq6-4p7r, CGA-vh2x-9247-h576, CGA-w2j8-94m3-rxc6, CGA-w2rp-6hc9-f8qw, CGA-w39g-2gpg-cfqr
Trending
Rank 11 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
celestia-nodeastria0.7.11 of 1See more

celestia-node astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
golang.org/x/net@v0.43.0
stdlib@go1.24.7
0.60.0
1.26.9

Open the chart page →

1,962
evm-faucetastria0.1.51 of 1See more

evm-faucet astria 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.26.9

Open the chart page →

2,462
evm-rollupastria4.1.01 of 2See more

evm-rollup astria 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

4,747
evm-stackastria5.0.31 of 2See more

evm-stack astria 5.0.3

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

4,747
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.60.0
1.26.9

Open the chart page →

4,632
graph-nodeastria0.2.23 of 3See more

graph-node astria 0.2.2

3 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
graphprotocol/graph-node:latestb0436347fb24
stdlib@go1.26.5
1.26.9
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/net@v0.1.0
stdlib@go1.19.1
0.60.0
1.26.9
library/postgres:latestfc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

6,856
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.60.0
1.26.9
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.6
0.60.0
1.26.9

Open the chart page →

8,316
sequencer-faucetastria0.9.21 of 1See more

sequencer-faucet astria 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
golang.org/x/net@v0.28.0
stdlib@go1.22.6
0.60.0
1.26.9

Open the chart page →

1,786
phonebook-chartasumankamberoglu0.1.51 of 3See more

phonebook-chart asumankamberoglu 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

3,975
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

10,833
hcloud-csi-driveratem181.5.12 of 6See more

hcloud-csi-driver atem18 1.5.1

2 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.3
0.60.0
1.26.9
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.60.0
1.26.9

Open the chart page →

8,868
bamboo-agentatlassian-data-centerVerified publisher2.0.171 of 1See more

bamboo-agent atlassian-data-center 2.0.17

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
atlassian/bamboo-agent-base:12.1.12a8d7b10b667a
stdlib@go1.22.2
1.26.9

Open the chart page →

2,018
alertmanager-discordatrox3.1.01 of 1See more

alertmanager-discord atrox 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/atrox/alertmanager-discord:v1.0.0ac011a4b6df1
stdlib@go1.20.5
1.26.9

Open the chart page →

1,085
attestkeepattestkeepVerified publisher1.3.62 of 2See more

attestkeep attestkeep 1.3.6

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:16.15-alpine721873c34ceb
stdlib@go1.24.6
1.26.9
ghcr.io/attestkeep/attestkeep-k8s:1.3.62e93f7cd839f
golang.org/x/net@v0.58.0
stdlib@go1.26.6-X:jsonv2
0.60.0
1.26.9

Open the chart page →

1,154
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,460
autopushautopushVerified publisher0.0.501 of 4See more

autopush autopush 0.0.50

1 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.31.01d5d341c4eb7
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

3,507
okd-webhookav1o-chartsVerified publisher0.1.01 of 1See more

okd-webhook av1o-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16
0.60.0
1.26.9

Open the chart page →

2,843
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.60.0
1.26.9

Open the chart page →

6,472
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

7,925
kubeslice-workeraveshaVerified publisher1.5.02 of 14See more

kubeslice-worker avesha 1.5.0

2 of the 14 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.1f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9

Open the chart page →

2,812
amazon-ec2-metadata-mockaws1.11.21 of 1See more

amazon-ec2-metadata-mock aws 1.11.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/amazon-ec2-metadata-mock:v1.11.2dd02d3569da0
stdlib@go1.17.13
1.26.9

Open the chart page →

1,546
appmesh-jaegeraws1.0.31 of 1See more

appmesh-jaeger aws 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

3,513
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9

Open the chart page →

4,042
aws-node-termination-handler-2aws0.2.02 of 2See more

aws-node-termination-handler-2 aws 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.3
0.60.0
1.26.9
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

4,490
aws-sigv4-proxy-admission-controlleraws0.1.21 of 1See more

aws-sigv4-proxy-admission-controller aws 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.60.0
1.26.9

Open the chart page →

3,293
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
stdlib@go1.21.2
1.26.9

Open the chart page →

10,637
axonops-developer-operatoraxonops-developer-operator0.1.01 of 1See more

axonops-developer-operator axonops-developer-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/axonops/axonops-developer-operator:v0.1.0b3d6600c8ba5
golang.org/x/net@v0.25.0
stdlib@go1.22.10
0.60.0
1.26.9

Open the chart page →

1,209
axonops-operatoraxonops-operator0.1.01 of 1See more

axonops-operator axonops-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/axonops/axonops-operator:0.1.0e0cdb993f0b1
golang.org/x/net@v0.51.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

586
azerothcoreazerothcoreVerified publisher0.2.01 of 6See more

azerothcore azerothcore 0.2.0

1 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.35.9436cbaa8a019
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,960
azure-advanced-backupazure-advanced-backup0.4.11 of 1See more

azure-advanced-backup azure-advanced-backup 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.60.0
1.26.9

Open the chart page →

5,618
kubernetes-providerazureappconfiguration-kubernetesprovider2.6.71 of 1See more

kubernetes-provider azureappconfiguration-kubernetesprovider 2.6.7

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-app-configuration/kubernetes-provider:2.6.7da4db80de17e
golang.org/x/net@v0.56.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

616
azurefile-csi-driverazurefile-csi-driverVerified publisher1.35.76 of 7See more

azurefile-csi-driver azurefile-csi-driver 1.35.7

6 of the 7 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.7a92afd76fb0d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.17.0760c61825d2a
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v6.3.0adfd47ab0160
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v2.2.0357a13745ca5
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-snapshotter:v8.5.08f8a0ea1e0c6
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.19.06d065f238d39
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,380
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

6,999
helm-controllerazureorkestra0.1.12 of 2See more

helm-controller azureorkestra 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.60.0
1.26.9
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.60.0
1.26.9

Open the chart page →

10,039
keptn-addonsazureorkestra0.1.04 of 4See more

keptn-addons azureorkestra 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.60.0
1.26.9
keptn/distributor:0.8.472e17527a4f9
stdlib@go1.16.2
1.26.9
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.13.7
0.60.0
1.26.9
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

15,048
prometheusazureorkestra14.8.05 of 6See more

prometheus azureorkestra 14.8.0

5 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.26.9
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.26.9
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.60.0
1.26.9

Open the chart page →

15,086
webserverazureorkestra1.0.01 of 1See more

webserver azureorkestra 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
nmalhotr/webserver:v1.0.03419361fb0dd
stdlib@go1.13.10
1.26.9

Open the chart page →

5,192
krakendbaboulinet0.1.341 of 1See more

krakend baboulinet 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
devopsfaith/krakend:2.7.09219cda867e2
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

1,850
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:8.0.39ccb8f749bb5e
stdlib@go1.18.2
1.26.9

Open the chart page →

4,958
prometheus-blackbox-exporterbackbox-exporter7.8.01 of 1See more

prometheus-blackbox-exporter backbox-exporter 7.8.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

2,267
backlokto-operatorbacklokto0.0.11 of 1See more

backlokto-operator backlokto 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
piblokto/backlokto-operator:v0.0.20963cda71e393
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

1,263
backrestbackrest0.2.01 of 1See more

backrest backrest 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
garethgeorge/backrest:latestb85297975428
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

1,252
backup-operatorbackup-operatorVerified publisher1.2.31 of 1See more

backup-operator backup-operator 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/universal-backup-operator/backup-operator:1.2.306292b289dda
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,343
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

10,927
binderybdclark-helm-chartsVerified publisher0.1.41 of 1See more

bindery bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/vavallee/bindery:v1.35.0c4ebfc5470e1
stdlib@go1.26.6
1.26.9

Open the chart page →

93
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
stdlib@go1.24.4
1.26.9

Open the chart page →

5,273
qbittorrent-vpnbdclark-helm-chartsVerified publisher0.7.61 of 2See more

qbittorrent-vpn bdclark-helm-charts 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.41.11a5bf4b4820a
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,464
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
stdlib@go1.25.7
1.26.9

Open the chart page →

2,745
helm-samplebehnambm-helm-chart1.0.11 of 3See more

helm-sample behnambm-helm-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:86ea90827b110
stdlib@go1.24.6
1.26.9

Open the chart page →

3,031
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

9,266

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
temporalio/admin-tools:1.32.0a9f84fb9a374
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
temporalio/server:1.22.4c0a44c26397b
golang.org/x/net@v0.7.0
stdlib@go1.20.11
0.60.0
1.26.9
2
temporalio/server:1.32.0c3e752127759
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
2
temporalio/server:1.15.1e26758f5a1bf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.60.0
1.26.9
2
temporalio/ui:2.16.2af9c9349708f
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
2
testinprod/op-erigon:latest0a125bd77a2d
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
2
thanosio/thanos:v0.41.0cf3e9b292e43
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
2
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.60.0
1.26.9
2
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.60.0
1.26.9
2
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
stdlib@go1.15.6
1.26.9
2
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
2
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.60.0
1.26.9
2
thoughtmachine/aws-service-quotas-exporter:v1.3.2c6065ba55c72
stdlib@go1.19.4
1.26.9
2
timescale/timescaledb:latest-pg156343bdc87ca1
stdlib@go1.24.6
1.26.9
2
timescale/timescaledb:2.30.2-pg17:latest-pg17b346edcdb51a
stdlib@go1.24.6
1.26.9
2
tkpd/gripmock:1.10.174441dadcfbd
stdlib@go1.14.6
1.26.9
2
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.26.9
2
tykio/tyk-mdcb-docker:v2.13.047c25173146e
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
2
tykio/tyk-pump-docker-pub:v1.17.09cc53e58abc4
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
2
ubercadence/server:0.23.22ac5491d13bb
golang.org/x/net@v0.0.0-20201031054903-ff519b6c9102
stdlib@go1.13.6
0.60.0
1.26.9
2
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
stdlib@go1.20.14
0.60.0
1.26.9
2
uselagoon/docker-host:v3.6.12c89ed939b8b
golang.org/x/net@v0.39.0
stdlib@go1.24.3
0.60.0
1.26.9
2
velero/velero:v1.18.237396519f399
golang.org/x/net@v0.55.0
stdlib@go1.25.11
0.60.0
1.26.9
2
victoriametrics/operator:v0.74.0c4fde419a4f0
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
2
victoriametrics/victoria-logs:v1.53.0251121fa882a
stdlib@go1.27.1
1.27.2
2
victoriametrics/victoria-traces:v0.11.09947b14b6b9b
stdlib@go1.26.5
1.26.9
2
victoriametrics/vmalert:v1.95.1a83e5db0897a
golang.org/x/net@v0.18.0
stdlib@go1.21.4
0.60.0
1.26.9
2
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.60.0
1.26.9
2
voltha/voltha-openolt-adapter:4.5.16d6d79c08350a
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.60.0
1.26.9
2
voltha/voltha-openonu-adapter-go:2.12.25d8f2eb5f2a7e
golang.org/x/net@v0.33.0
stdlib@go1.23.1
0.60.0
1.26.9
2
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.60.0
1.26.9
2
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.60.0
1.26.9
2
wener/frpc:v0.37.0cc9fd4da44c0
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.60.0
1.26.9
2
wener/frps:v0.37.05c92cc9e8597
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.60.0
1.26.9
2
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.60.0
1.26.9
2
yzhou442/equiz:latesta3f7ca69e28d
stdlib@go1.16.7
1.26.9
2
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
2
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
2
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.10
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.60.0
1.26.9
2
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.60.0
1.26.9
2
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.60.0
1.26.9
2
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller0d5f740b4224
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
2
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook697668be7893
golang.org/x/net@v0.39.0
stdlib@go1.24.6
0.60.0
1.26.9
2

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.