StackRadar

CVE-2026-97032

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,530
of 18,090 indexed, latest versions
Container images
6,374
deployed by those charts
Fix available
6 of 9
affected packages

HTTP/2 server crash due to HPACK encoder race in net/http

Carried by container images the latest versions of 5,530 of 18,090 indexed charts deploy, on 6,374 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,355
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,126
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-387c-5f4p-4rh4CGA-4653-rw6m-872gCGA-4h9w-grf4-6jppCGA-8xvx-5mh6-vrc3CGA-f937-jwj2-rj5jCGA-fjhw-67fq-pm89DEBIAN-CVE-2026-97032GO-2026-6617
Also known as
CGA-3qgw-9846-f468, CGA-499x-7xc5-927w, CGA-4qpc-rjrp-f4h4, CGA-5pv4-5xjw-qg97, CGA-5rcr-cqmr-f8hp, CGA-5vh8-jrpp-m4r3, CGA-8g7x-r6mw-97j8, CGA-8mf9-xfh8-jx3h, CGA-923f-66wm-xfq4, CGA-9hgh-r65w-7q99, CGA-fjfp-jwwq-vjp3, CGA-gg5j-j7wm-wf6w, CGA-jrgf-gwq3-rf5w, CGA-m46j-x3g6-mqj4, CGA-mq7q-c763-9cvx, CGA-p4p3-mvmj-v95v, CGA-qpfw-4v8x-3667, CGA-qpqr-hw3x-7qxj, CGA-qqxw-hjpg-6rhv, CGA-r654-5gg7-p6xf, CGA-rggh-6rrq-mfp4, CGA-rwc6-gqq6-4p7r, CGA-vh2x-9247-h576, CGA-w2j8-94m3-rxc6, CGA-w2rp-6hc9-f8qw, CGA-w39g-2gpg-cfqr
Trending
Rank 6 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,530 by stars
ChartLatestAffected imagesRadar Score
hlf-peerowkin5.1.01 of 1See more

hlf-peer owkin 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hyperledger/fabric-peer:2.2.1bf4995c86af6
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.4
0.60.0
1.26.9

Open the chart page →

4,901
prometheus-cachethqoxyno-zetaVerified publisher1.1.11 of 1See more

prometheus-cachethq oxyno-zeta 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
oxynozeta/prometheus-cachethq:1.1.131f11669d597
stdlib@go1.15.1
1.26.9

Open the chart page →

2,715
p10logsp10logsOfficialVerified publisher1.1.42 of 2See more

p10logs p10logs 1.1.4

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/p10node/p10logs-agent:1.1.44bc72bd8ff5a
stdlib@go1.26.8
1.26.9
ghcr.io/p10node/p10logs-hub:1.1.44385afd18845
stdlib@go1.26.8
1.26.9

Open the chart page →

178
ngrok-operatorpaganuzzi0.0.21 of 1See more

ngrok-operator paganuzzi 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/paganuzzi/ngrokoperator:latest5a10cd095699
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

3,930
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
stdlib@go1.25.12
1.26.9

Open the chart page →

4,503
prowlarrpanzer1119Verified publisher0.4.181 of 2See more

prowlarr panzer1119 0.4.18

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

1,150
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
stdlib@go1.24.4
1.26.9

Open the chart page →

10,841
pardus-nginx-nodeportpardus-charts0.5.01 of 1See more

pardus-nginx-nodeport pardus-charts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
uderelier19/pardus-nginx:25-nodeport8ab640b44e3f
stdlib@go1.24.4
1.26.9

Open the chart page →

644
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
golang.org/x/net@v0.40.0
stdlib@go1.20.5
0.60.0
1.26.9

Open the chart page →

8,434
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.60.0
1.26.9
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.21.9
0.60.0
1.26.9

Open the chart page →

9,581
pbuf-registrypbuf-registry0.4.12 of 2See more

pbuf-registry pbuf-registry 0.4.1

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.1-alpine3.2144d837eb4c2e
stdlib@go1.24.6
1.26.9
ghcr.io/pbufio/registry:v0.4.177a36c035b4b
golang.org/x/net@v0.45.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,869
pdf-editor-helmpdf-editor-web1.0.02 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
stdlib@go1.18.7
1.26.9
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
stdlib@go1.18.7
1.26.9

Open the chart page →

5,605
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
stdlib@go1.24.4
1.26.9

Open the chart page →

8,640
pg-operatorpercona3.1.01 of 1See more

pg-operator percona 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
percona/percona-postgresql-operator:3.1.0a7c50ef1545e
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

220
periscopeperiscopeVerified publisher1.1.61 of 1See more

periscope periscope 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,266
perspectivegraphperspectivegraphOfficialVerified publisher1.37.01See more

perspectivegraph perspectivegraph 1.37.0

1 container image this version deploys carries CVE-2026-97032.

Container imageDigestPackageFixed in
library/nats:2.15.0-scratchc0d27f305460
stdlib@go1.27.1
1.27.2

Open the chart page →

—
pgbouncerpgbouncer-helm0.6.01 of 2See more

pgbouncer pgbouncer-helm 0.6.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
stdlib@go1.23.7
1.26.9

Open the chart page →

818
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.60.0
1.26.9

Open the chart page →

10,966
full-housephilmtd1.3.21 of 1See more

full-house philmtd 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
philmtd/full-house:1.10.0224d602420ba
golang.org/x/net@v0.59.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

290
chadbotphntom0.2.31 of 1See more

chadbot phntom 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
phntom/chadbot:0.2.397c28e4178ad
golang.org/x/net@v0.11.0
stdlib@go1.21.5
0.60.0
1.26.9

Open the chart page →

1,683
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
golang.org/x/net@v0.10.0
stdlib@go1.19.3
0.60.0
1.26.9

Open the chart page →

3,747
matterircdphntom0.1.71 of 2See more

matterircd phntom 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
42wim/matterircd:latest23c951580801
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

166
phonebook-chartphonebook-chart0.1.01 of 3See more

phonebook-chart phonebook-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.26.9

Open the chart page →

3,831
phpipamphpipam-helmVerified publisher1.0.121 of 3See more

phpipam phpipam-helm 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.26.9

Open the chart page →

4,663
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.15.8
0.60.0
1.26.9

Open the chart page →

3,253
piraeuspiraeus-operatorVerified publisher2.12.01 of 1See more

piraeus piraeus-operator 2.12.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/piraeusdatastore/piraeus-operator:v2.12.02fee47e187c1
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

138
pocket-id-operatorpocket-id-operatorVerified publisher0.15.01 of 1See more

pocket-id-operator pocket-id-operator 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/aclerici38/pocket-id-operator:v0.15.0e1f94e349df1
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

124
matomopockostVerified publisher1.4.01 of 3See more

matomo pockost 1.4.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mariadb:12.3.3dd9b303aed4f
stdlib@go1.24.6
1.26.9

Open the chart page →

6,224
podtracepodtraceOfficialVerified publisher0.14.82 of 2See more

podtrace podtrace 0.14.8

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
alpine/k8s:1.37.0b421c2e9419e
golang.org/x/net@v0.57.0
stdlib@go1.26.7
0.60.0
1.26.9
ghcr.io/gma1k/podtrace:0.14.89a59d6301d74
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

1,302
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.60.0
1.26.9

Open the chart page →

3,325
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.26.9
treskon/portrait:DEV-latest88e813f22347
stdlib@go1.26.5
1.26.9

Open the chart page →

36,867
postfix-exporterpostfix-exporterVerified publisher0.2.11 of 1See more

postfix-exporter postfix-exporter 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/hsn723/postfix_exporter:0.21.28b0994de44a9
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

128
postgres-backuppostgres-backup0.3.02 of 2See more

postgres-backup postgres-backup 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.26.9
nerzhul/mc-arm64:2020.10.034215df511f31
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

5,471
postgresqlpostgresqlVerified publisher0.3.172 of 2See more

postgresql postgresql 0.3.17

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18.6-alpine77f585114c32
stdlib@go1.24.6
1.26.9
pgautoupgrade/pgautoupgrade:18-alpine2245aabc5b80
stdlib@go1.24.6
1.26.9

Open the chart page →

1,306
postgresqlpostgresql-helm0.1.21 of 1See more

postgresql postgresql-helm 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:161a6ab3f5345e
stdlib@go1.24.6
1.26.9

Open the chart page →

1,853
rethinkdbpozetron1.1.91 of 1See more

rethinkdb pozetron 1.1.9

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.9
0.60.0
1.26.9

Open the chart page →

4,442
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
golang.org/x/net@v0.57.0
stdlib@go1.27.0
0.60.0
1.27.2

Open the chart page →

2,038
preparrpreparr0.19.81 of 6See more

preparr preparr 0.19.8

1 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:18-alpine77f585114c32
stdlib@go1.24.6
1.26.9

Open the chart page →

1,204
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.26.9

Open the chart page →

6,773
projectionprojectionVerified publisher0.3.21 of 1See more

projection projection 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/projection-operator/projection:0.3.2d06374430a17
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9

Open the chart page →

450
prometheus-druid-exporterprometheus-communityVerified publisher1.2.01 of 1See more

prometheus-druid-exporter prometheus-community 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/opstree/druid-exporter:v0.119f01c9c5c2e3
stdlib@go1.15.15
1.26.9

Open the chart page →

2,091
prometheus-operator-admission-webhookprometheus-communityVerified publisher0.44.22 of 2See more

prometheus-operator-admission-webhook prometheus-community 0.44.2

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/jkroepke/kube-webhook-certgen:1.8.958e4ac2e15bf
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/prometheus-operator/admission-webhook:v0.94.1691ecb7e05ce
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

248
prometheus-pingmesh-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-pingmesh-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:v1.2.2c82de0272da0
golang.org/x/net@v0.29.0
stdlib@go1.22.9
0.60.0
1.26.9

Open the chart page →

1,322
prometheus-sql-exporterprometheus-communityVerified publisher0.5.01 of 1See more

prometheus-sql-exporter prometheus-community 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/justwatchcom/sql_exporter:v0.8c4b1d3d0f052
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,867
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.26.9
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.26.9
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.60.0
1.26.9

Open the chart page →

15,536
dockerhub-exporterpromhippieVerified publisher2.16.01 of 1See more

dockerhub-exporter promhippie 2.16.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/promhippie/dockerhub-exporter:2.17.0cbf4ef61e675
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

141
hcloud-exporterpromhippieVerified publisher4.30.01 of 1See more

hcloud-exporter promhippie 4.30.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/promhippie/hcloud-exporter:3.30.0f1dba83dfd23
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

141
prowlerprowler-appVerified publisher0.0.92 of 5See more

prowler prowler-app 0.0.9

2 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bitnami/valkey:latest3ab4091a7e3c
stdlib@go1.26.8
1.26.9
prowlercloud/prowler-api:5.31.14f252d579be2
golang.org/x/net@v0.54.0
stdlib@go1.26.3-X:jsonv2
0.60.0
1.26.9

Open the chart page →

10,168
pulumi-kubernetes-operatorpulumi-kubernetes-operator2.9.31 of 1See more

pulumi-kubernetes-operator pulumi-kubernetes-operator 2.9.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
pulumi/pulumi-kubernetes-operator:v2.9.30a0f20eeb071
golang.org/x/net@v0.59.0
0.60.0

Open the chart page →

56
operatorpunchplatform8.1.131 of 1See more

operator punchplatform 8.1.13

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
golang.org/x/net@v0.20.0
stdlib@go1.22.0
0.60.0
1.26.9

Open the chart page →

1,295

Container images carrying it

6,374 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/net@v0.23.0
stdlib@go1.23.10
0.60.0
1.26.9
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.60.0
1.26.9
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
stdlib@go1.19.3
0.60.0
1.26.9
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.60.0
1.26.9
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.60.0
1.26.9
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0db384bf43222
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.60.0
1.26.9
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.60.0
1.26.9
2
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9
2
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
golang.org/x/net@v0.56.0
stdlib@go1.26.3
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-attacher:v4.9.05aaefc24f315
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-attacher:v4.10.0be59d0556508
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.0cd21e19cd8bb
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/csi-snapshotter:v8.3.0bc7be893ecc3
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/livenessprobe:v2.12.05baeb4a6d7d5
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
stdlib@go1.18
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9
2
registry.k8s.io/sig-storage/snapshot-controller:v8.3.012c2da094b02
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
2
0xpolygon/bor:1.3.7396d3de26d8b
golang.org/x/net@v0.26.0
stdlib@go1.22.1
0.60.0
1.26.9
1
0xpolygon/heimdall:1.0.134ddf259993c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
1
1dev/server:11.9.0cd5b12fe5471
golang.org/x/net@v0.38.0
stdlib@go1.23.8
0.60.0
1.26.9
1
1password/connect-api:1.8.3656e4b10df83
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
1password/connect-api:1.7.26aa94cf713f9
golang.org/x/net@v0.14.0
stdlib@go1.20.6
0.60.0
1.26.9
1
1password/connect-sync:1.8.3a760350c941a
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
1
1password/connect-sync:1.7.2fe527ed9d81f
golang.org/x/net@v0.14.0
stdlib@go1.20.6
0.60.0
1.26.9
1
1password/kubernetes-secrets-injector:1.0.25884757f7879
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
1
42wim/matterircd:latest23c951580801
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
1
aavishay/right-sizer:0.6.23d7c4d79595c
golang.org/x/net@v0.48.0
stdlib@go1.25.8
0.60.0
1.26.9
1
abiondevelopment/cert-manager-webhook-abion:latestc741988fbd23
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9
1
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.60.0
1.26.9
1
aboogie/login_test_backend:new9c41a4483ac8
stdlib@go1.22.5
1.26.9
1
absaoss/terraform-controller:v0.0.20ad538a1285a0
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.14.8
0.60.0
1.26.9
1
activepieces/activepieces:0.92.287295caa32a1
stdlib@go1.23.5
1.26.9
1
adeptiainc/adeptia-connect-rabbitmq-cluster-operator:4.823d259e0c93e
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.60.0
1.26.9
1
adeptiainc/adeptia-connect-rabbitmq-cluster-operator:5.2cf610f8c614c
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
1
adeptiainc/adeptia-connect-rabbitmq-messaging-topology-operator:5.27cdf6ac2e738
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
1
adeptiainc/adeptia-connect-rabbitmq-messaging-topology-operator:4.8d13e3304bda8
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.513a143e6c071c
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.3843ec119419a9
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.595d5e3aef39a8
golang.org/x/net@v0.37.0
stdlib@go1.24.1
0.60.0
1.26.9
1
adguard/adguardhome:v0.107.767157eb1dc3b2
golang.org/x/net@v0.53.0
stdlib@go1.26.3
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.