StackRadar

CVE-2026-97032

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 server crash due to HPACK encoder race in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4653-rw6m-872gCGA-4h9w-grf4-6jppCGA-8xvx-5mh6-vrc3CGA-9hgh-r65w-7q99CGA-f937-jwj2-rj5jCGA-fjhw-67fq-pm89DEBIAN-CVE-2026-97032GO-2026-6617
Also known as
CGA-387c-5f4p-4rh4, CGA-3qgw-9846-f468, CGA-499x-7xc5-927w, CGA-4qpc-rjrp-f4h4, CGA-5pv4-5xjw-qg97, CGA-5rcr-cqmr-f8hp, CGA-5vh8-jrpp-m4r3, CGA-8g7x-r6mw-97j8, CGA-8mf9-xfh8-jx3h, CGA-923f-66wm-xfq4, CGA-fjfp-jwwq-vjp3, CGA-gg5j-j7wm-wf6w, CGA-jrgf-gwq3-rf5w, CGA-m46j-x3g6-mqj4, CGA-mq7q-c763-9cvx, CGA-p4p3-mvmj-v95v, CGA-qpfw-4v8x-3667, CGA-qpqr-hw3x-7qxj, CGA-qqxw-hjpg-6rhv, CGA-r654-5gg7-p6xf, CGA-rggh-6rrq-mfp4, CGA-rwc6-gqq6-4p7r, CGA-vh2x-9247-h576, CGA-w2j8-94m3-rxc6, CGA-w2rp-6hc9-f8qw, CGA-w39g-2gpg-cfqr
Trending
Rank 11 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
mysqlhelmforgeVerified publisher2.0.41 of 1See more

mysql helmforge 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:26.7.0ade067ae2fb1
stdlib@go1.24.6
1.26.9

Open the chart page →

797
netboxhelmforgeVerified publisher2.0.32 of 4See more

netbox helmforge 2.0.3

2 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
stdlib@go1.26.5
1.26.9

Open the chart page →

4,906
nextcloudhelmforgeVerified publisher2.0.01 of 3See more

nextcloud helmforge 2.0.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

7,688
ntfyhelmforgeVerified publisher1.2.21 of 1See more

ntfy helmforge 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.28.06ef4b819f722
golang.org/x/net@v0.58.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

401
oauth2-proxyhelmforgeVerified publisher1.0.61 of 1See more

oauth2-proxy helmforge 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.15.4b1b2021fe8f4
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

272
olivetinhelmforgeVerified publisher1.2.21 of 2See more

olivetin helmforge 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
jamesread/olivetin:3000.20.0f3066e207efd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

731
opencuthelmforgeVerified publisher1.1.111 of 5See more

opencut helmforge 1.1.11

1 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

3,805
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
stdlib@go1.20.7
1.26.9

Open the chart page →

3,745
pimcorehelmforgeVerified publisher2.0.42 of 6See more

pimcore helmforge 2.0.4

2 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
dunglas/mercure:v0.24.2916834e49961
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9
library/mariadb:13.0.2f1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

3,420
pocket-idhelmforgeVerified publisher1.0.01 of 2See more

pocket-id helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/pocket-id/pocket-id:v2.14.001540977dcf4
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

705
reactive-resumehelmforgeVerified publisher1.0.02 of 4See more

reactive-resume helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
stdlib@go1.26.4
1.26.9

Open the chart page →

4,056
ryothelmforgeVerified publisher1.0.02 of 2See more

ryot helmforge 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
golang.org/x/net@v0.33.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

7,418
siyuanhelmforgeVerified publisher1.0.11 of 1See more

siyuan helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
b3log/siyuan:v3.8.5d740a1d3ed6b
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

400
strapihelmforgeVerified publisher2.3.151 of 3See more

strapi helmforge 2.3.15

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie5a5a84b19854
stdlib@go1.24.6
1.26.9

Open the chart page →

3,010
strava-statisticshelmforgeVerified publisher1.1.161 of 2See more

strava-statistics helmforge 1.1.16

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
robiningelbrecht/strava-statistics:v5.0.040842cdfd616
golang.org/x/net@v0.55.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

1,221
supersethelmforgeVerified publisher1.3.82 of 5See more

superset helmforge 1.3.8

2 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
helmforge/kubectl:1.35.3c3f97e954c47
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

6,458
twentyhelmforgeVerified publisher1.0.41 of 5See more

twenty helmforge 1.0.4

1 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9

Open the chart page →

3,199
wallabaghelmforgeVerified publisher1.3.82 of 3See more

wallabag helmforge 1.3.8

2 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.6-trixiefc973eb97c9f
stdlib@go1.24.6
1.26.9
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.26.9

Open the chart page →

3,350
webodmhelmforgeVerified publisher1.0.01 of 4See more

webodm helmforge 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
postgis/postgis:17-3.501a6a70e41e6
stdlib@go1.18.2
1.26.9

Open the chart page →

22,597
zookeeperhelmforgeVerified publisher1.0.21 of 1See more

zookeeper helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5e6b279d01350
stdlib@go1.18.1
1.26.9

Open the chart page →

3,902
harborhelm-harborVerified publisher2.3.75 of 8See more

harbor helm-harbor 2.3.7

5 of the 8 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.47d2ba5304a72
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
goharbor/harbor-jobservice:v2.15.4f143578ef30e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
goharbor/harbor-registryctl:v2.15.430bd1ace4e3b
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
goharbor/registry-photon:v2.15.4dc0cb388a644
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
goharbor/trivy-adapter-photon:v2.15.4813ca81b4a4e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

1,577
openaevhelm-openbasVerified publisher2.0.121 of 7See more

openaev helm-openbas 2.0.12

1 of the 7 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
golang.org/x/net@v0.14.0
stdlib@go1.19.8
no fix listed
0.60.0
1.26.9

Open the chart page →

21,594
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
golang-1.19@1.19.8-2
golang.org/x/net@v0.14.0
stdlib@go1.19.8
no fix listed
0.60.0
1.26.9

Open the chart page →

26,397
release-cleanerhelm-release-cleanerVerified publisher1.0.01 of 1See more

release-cleaner helm-release-cleaner 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
alpine/helm:4.1.0905a068da431
golang.org/x/net@v0.48.0
stdlib@go1.25.6
0.60.0
1.26.9

Open the chart page →

2,554
pageshelm-repo1.0.01 of 3See more

pages helm-repo 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,310
steampipehelm-steampipeVerified publisher2.4.11 of 1See more

steampipe helm-steampipe 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
golang.org/x/net@v0.48.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

3,897
svacerhelm-svacer0.6.01 of 1See more

svacer helm-svacer 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ispras/svacer:11-2-042aa9fa9f189
golang.org/x/net@v0.37.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

7,182
hermes-operatorhermes-agent-operatorVerified publisher0.2.01 of 1See more

hermes-operator hermes-agent-operator 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/paperclipinc/hermes-operator:v0.2.07a491ec9b0ff
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

231
postgres-backup-localheywood8-helm-chartsVerified publisher0.1.131 of 1See more

postgres-backup-local heywood8-helm-charts 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
stdlib@go1.16
1.26.9

Open the chart page →

3,475
kubefaashfoxy-helm-charts0.1.63 of 4See more

kubefaas hfoxy-helm-charts 0.1.6

3 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hfoxy4/kubefaas-builder:main-2afc7570bfb65aaad93
golang.org/x/net@v0.26.0
stdlib@go1.21.11
0.60.0
1.26.9
hfoxy4/kubefaas-controller:main-2afc7570761fe08f14c
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.60.0
1.26.9
library/docker:27.0.1-dind2416984b43dd
golang.org/x/net@v0.23.0
stdlib@go1.21.11
0.60.0
1.26.9

Open the chart page →

7,965
tapo-prometheus-exporterhfoxy-helm-charts0.1.111 of 1See more

tapo-prometheus-exporter hfoxy-helm-charts 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hfoxy4/tapo-prometheus-exporter:v0.1.117e385eef6fc7
stdlib@go1.21.3
1.26.9

Open the chart page →

1,427
goshimmerhiveroad0.2.141 of 1See more

goshimmer hiveroad 0.2.14

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
iotaledger/goshimmer:v0.8.6b02a8f77474f
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.2
0.60.0
1.26.9

Open the chart page →

3,814
cratedb-adapterhmdmph0.1.01 of 1See more

cratedb-adapter hmdmph 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
stdlib@go1.16.3
0.60.0
1.26.9

Open the chart page →

4,117
printserverhmediadeVerified publisher1.0.22 of 4See more

printserver hmediade 1.0.2

2 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

12,885
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.60.0
1.26.9

Open the chart page →

3,311
holmesholmes0.1.01 of 1See more

holmes holmes 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/operator-framework/olm:master39081bf0c4a9
golang.org/x/net@v0.7.0
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

2,881
homeboxhomebox-helmVerified publisher0.3.01 of 2See more

homebox homebox-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
sysadminsmedia/homebox:0.26.056e880b62309
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,151
homecharthomechartVerified publisher1.0.11 of 1See more

homechart homechart 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/candiddev/homechart:latestb79b17e57af8
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

209
adguardhomeenterpriseinc0.12.01 of 1See more

adguard homeenterpriseinc 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.0-b.5a9668737b1d6
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.6
0.60.0
1.26.9

Open the chart page →

3,707
cert-managerhomeenterpriseinc1.10.13 of 3See more

cert-manager homeenterpriseinc 1.10.1

3 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

7,277
homeassistanthomeenterpriseinc0.3.01 of 1See more

homeassistant homeenterpriseinc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2022.3.5565751f33794
stdlib@go1.17.1
1.26.9

Open the chart page →

9,054
photoprismhomeenterpriseinc0.8.01 of 1See more

photoprism homeenterpriseinc 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
photoprism/photoprism:20211010f4687352985a
golang.org/x/net@v0.0.0-20210929193557-e81a3d93ecf6
stdlib@go1.17.1
0.60.0
1.26.9

Open the chart page →

3,224
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
stdlib@go1.19.8
1.26.9

Open the chart page →

18,551
honeydipperhoneydipperVerified publisher0.1.111 of 2See more

honeydipper honeydipper 0.1.11

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/redis:5fc5ecd863862
stdlib@go1.16.7
1.26.9

Open the chart page →

2,847
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
golang.org/x/net@v0.17.0
stdlib@go1.21.10
0.60.0
1.26.9

Open the chart page →

4,627
universal-web-apphotrungnhanVerified publisher0.2.61 of 2See more

universal-web-app hotrungnhan 0.2.6

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
traefik/whoami:latestc4717a8d1f01
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

350
hoverflyhoverflyVerified publisher0.2.01 of 1See more

hoverfly hoverfly 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
spectolabs/hoverfly:v1.12.13250986d58ed4
golang.org/x/net@v0.56.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

289
paperlesshpVerified publisher0.1.23 of 5See more

paperless hp 0.1.2

3 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.60.0
1.26.9
gotenberg/gotenberg:8.3467097317623a
golang.org/x/net@v0.55.0
stdlib@go1.26.2
0.60.0
1.26.9
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
stdlib@go1.24.4
1.26.9

Open the chart page →

35,136
wallabaghpVerified publisher0.1.71 of 1See more

wallabag hp 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.26.9

Open the chart page →

1,548
hammerspace-csihscsi1.2.86 of 6See more

hammerspace-csi hscsi 1.2.8

6 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

7,746

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.60.0
1.26.9
7
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
stdlib@go1.26.4
1.26.9
7
quay.io/jetstack/cert-manager-cainjector:v1.21.2c85268c64f2e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/jetstack/cert-manager-controller:v1.21.270f532fd9cfd
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/jetstack/cert-manager-startupapicheck:v1.21.246e75b686635
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/jetstack/cert-manager-webhook:v1.21.2a60e2dac46db
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.60.0
1.26.9
7
quay.io/prometheus-operator/prometheus-operator:v0.94.17c88d4e7bae6
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/net@v0.30.0
stdlib@go1.23.4
0.60.0
1.26.9
7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9
7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.60.0
1.26.9
7
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.60.0
1.26.9
7
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
7
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
7
bitnami/kubectl:latestab90e1058e5a
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
6
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.60.0
1.26.9
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
stdlib@go1.25.0
1.26.9
6
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
6
cloudflare/cloudflared:2026.10.0:latest9b49eed8f628
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
6
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.60.0
1.26.9
6
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
6
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.60.0
1.26.9
6
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.60.0
1.26.9
6
library/mariadb:10:10.117db29378d4fd
stdlib@go1.24.6
1.26.9
6
library/postgres:18.4a02db8cac496
stdlib@go1.24.6
1.26.9
6
library/postgres:17d74eeac9a635
stdlib@go1.24.6
1.26.9
6
library/registry:2:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.26.9
6
natsio/nats-server-config-reloader:0.23.064cb6c858e79
stdlib@go1.25.6
1.26.9
6
postgis/postgis:17-3.5:latest01a6a70e41e6
stdlib@go1.18.2
1.26.9
6
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.60.0
1.26.9
6
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
6
traefik/whoami:latest:v1.12.0c4717a8d1f01
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
6
victoriametrics/operator:v0.75.078da26b41a81
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
6
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.60.0
1.26.9
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.26.9
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.60.0
1.26.9
6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.60.0
1.26.9
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.60.0
1.26.9
6
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.26.9
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.60.0
1.26.9
6
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.60.0
1.26.9
6
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.60.0
1.26.9
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
6
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
stdlib@go1.25.3
0.60.0
1.26.9
6
quay.io/prometheus-operator/prometheus-config-reloader:v0.94.106b52bd4dbe3
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
6
quay.io/prometheus/pushgateway:v1.11.491a56b89b97d
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
6
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
6
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.901038e7de14b
golang.org/x/net@v0.52.0
stdlib@go1.26.1
0.60.0
1.26.9
6
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.60.0
1.26.9
6

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.