StackRadar

CVE-2026-97032

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 server crash due to HPACK encoder race in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4653-rw6m-872gCGA-4h9w-grf4-6jppCGA-8xvx-5mh6-vrc3CGA-9hgh-r65w-7q99CGA-f937-jwj2-rj5jCGA-fjhw-67fq-pm89DEBIAN-CVE-2026-97032GO-2026-6617
Also known as
CGA-387c-5f4p-4rh4, CGA-3qgw-9846-f468, CGA-499x-7xc5-927w, CGA-4qpc-rjrp-f4h4, CGA-5pv4-5xjw-qg97, CGA-5rcr-cqmr-f8hp, CGA-5vh8-jrpp-m4r3, CGA-8g7x-r6mw-97j8, CGA-8mf9-xfh8-jx3h, CGA-923f-66wm-xfq4, CGA-fjfp-jwwq-vjp3, CGA-gg5j-j7wm-wf6w, CGA-jrgf-gwq3-rf5w, CGA-m46j-x3g6-mqj4, CGA-mq7q-c763-9cvx, CGA-p4p3-mvmj-v95v, CGA-qpfw-4v8x-3667, CGA-qpqr-hw3x-7qxj, CGA-qqxw-hjpg-6rhv, CGA-r654-5gg7-p6xf, CGA-rggh-6rrq-mfp4, CGA-rwc6-gqq6-4p7r, CGA-vh2x-9247-h576, CGA-w2j8-94m3-rxc6, CGA-w2rp-6hc9-f8qw, CGA-w39g-2gpg-cfqr
Trending
Rank 11 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.60.0
1.26.9

Open the chart page →

11,003
aws-ecr-tokencheveo-charts0.1.01 of 1See more

aws-ecr-token cheveo-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
huzafach/aws-cli-k8:1.0.06e271d43ea48
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.60.0
1.26.9

Open the chart page →

1,668
pathling-serverchglVerified publisher0.10.141 of 3See more

pathling-server chgl 0.10.14

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
golang.org/x/net@v0.47.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

1,767
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.60.0
1.26.9

Open the chart page →

4,115
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.60.0
1.26.9

Open the chart page →

4,287
supersetchoerodon1.0.01 of 3See more

superset choerodon 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.60.0
1.26.9

Open the chart page →

2,145
argocd-metrics-serverchristianhuthVerified publisher1.1.11 of 1See more

argocd-metrics-server christianhuth 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
golang.org/x/net@v0.10.0
stdlib@go1.21.11
0.60.0
1.26.9

Open the chart page →

1,616
cluster-api-visualizerchristianhuthVerified publisher0.6.01 of 1See more

cluster-api-visualizer christianhuth 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/jont828/cluster-api-visualizer:v1.5.0678ba6833297
golang.org/x/net@v0.42.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

994
countlychristianhuthVerified publisher5.3.33 of 3See more

countly christianhuth 5.3.3

3 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bitnami/mongodb:latestad05bb9a19fa
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
countly/api:25.05.4f4cc7447c4f5
stdlib@go1.19.4
1.26.9
countly/frontend:25.05.42acbc11499b6
stdlib@go1.19.4
1.26.9

Open the chart page →

10,637
dnsbl-exporterchristianhuthVerified publisher1.4.01 of 2See more

dnsbl-exporter christianhuth 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/luzilla/dnsbl_exporter:v0.7.0-rc3d9767232a55e
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

2,099
github-exporterchristianhuthVerified publisher2.6.01 of 1See more

github-exporter christianhuth 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
githubexporter/github-exporter:v2.3.1a36fbedeedf8
stdlib@go1.26.4
1.26.9

Open the chart page →

267
goldpingerchristianhuthVerified publisher1.4.21 of 1See more

goldpinger christianhuth 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.11.5f7c60d319150
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

201
kubedoomchristianhuthVerified publisher1.1.21 of 1See more

kubedoom christianhuth 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/storax/kubedoom:0.6.0851ba8c80b93
stdlib@go1.17.6
1.26.9

Open the chart page →

1,933
kubevirt-cloud-controller-managerchristianhuthVerified publisher0.0.21 of 1See more

kubevirt-cloud-controller-manager christianhuth 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
golang.org/x/net@v0.49.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,086
kubevirt-managerchristianhuthVerified publisher0.7.01 of 1See more

kubevirt-manager christianhuth 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
golang.org/x/net@v0.49.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,511
mailcow-exporterchristianhuthVerified publisher1.5.01 of 1See more

mailcow-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
stdlib@go1.23.12
1.26.9

Open the chart page →

1,194
netbird-reverse-proxychristianhuthVerified publisher0.1.01 of 1See more

netbird-reverse-proxy christianhuth 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
netbirdio/reverse-proxy:0.72.43104d5ca3a76
golang.org/x/net@v0.53.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

1,404
netcupscp-exporterchristianhuthVerified publisher2.1.01 of 1See more

netcupscp-exporter christianhuth 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/mrueg/netcupscp-exporter:v0.5.25b86c2c0b0e0
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

350
nextcloud-exporterchristianhuthVerified publisher1.5.01 of 1See more

nextcloud-exporter christianhuth 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
xperimental/nextcloud-exporter:0.9.13e90a3897651
stdlib@go1.26.1
1.26.9

Open the chart page →

482
ntp-exporterchristianhuthVerified publisher1.4.01 of 1See more

ntp-exporter christianhuth 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/sapcc/ntp_exporter:v2.9.079c40c65f5d4
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

847
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.26.9

Open the chart page →

6,720
promlenschristianhuthVerified publisher1.6.01 of 1See more

promlens christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
prom/promlens:v0.4.04a377d1a0eaa
golang.org/x/net@v0.56.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

415
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.16.15
0.60.0
1.26.9

Open the chart page →

3,429
arbitrumchronicleVerified publisher0.3.51 of 1See more

arbitrum chronicle 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
golang.org/x/net@v0.38.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

8,105
basechronicleVerified publisher0.0.91 of 1See more

base chronicle 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/net@v0.30.0
stdlib@go1.22.10
0.60.0
1.26.9

Open the chart page →

5,778
ethereumchronicleVerified publisher0.3.21 of 1See more

ethereum chronicle 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ethereum/client-go:v1.16.532b878e4144a
golang.org/x/net@v0.38.0
stdlib@go1.24.9
0.60.0
1.26.9

Open the chart page →

1,820
ethereum-metrics-exporterchronicleVerified publisher0.1.51 of 1See more

ethereum-metrics-exporter chronicle 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
samcm/ethereum-metrics-exporter:0.29.291a2d9a015c1
golang.org/x/net@v0.43.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,068
goferchronicleVerified publisher0.4.51 of 1See more

gofer chronicle 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/gofer:0.613915d2e41e04
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

1,377
mantlechronicleVerified publisher0.1.41 of 1See more

mantle chronicle 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9

Open the chart page →

2,833
sith-exporterschronicleVerified publisher0.2.61 of 1See more

sith-exporters chronicle 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/oracles-updates-exporter:0.0.4992d0e793af6
stdlib@go1.19.13
1.26.9

Open the chart page →

1,549
spirechronicleVerified publisher0.3.71 of 1See more

spire chronicle 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

2,087
zksyncchronicleVerified publisher0.1.21 of 2See more

zksync chronicle 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:143e7dd0bfd7bf
stdlib@go1.24.6
1.26.9

Open the chart page →

7,198
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9

Open the chart page →

4,909
ciliumcilium21.20.23 of 3See more

cilium cilium2 1.20.2

3 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.22939231d0d3e
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82af7382699576
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/cilium/operator-generic:v1.20.264d8798350e8
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

2,070
tetragoncilium21.7.12 of 3See more

tetragon cilium2 1.7.1

2 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
quay.io/cilium/tetragon-operator:v1.7.1cd8b71f6860e
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

666
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/chekrdigest-pinnedf299baf467b5
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

4,644
vulnerability-operatorckotzbauerVerified publisher0.31.151 of 1See more

vulnerability-operator ckotzbauer 0.31.15

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/vulnerability-operator:0.28.167008df32715c
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

518
clairclair-helmVerified publisher0.12.02 of 3See more

clair clair-helm 0.12.0

2 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9
quay.io/projectquay/clair:4.9.023329c3368e4
golang.org/x/net@v0.47.0
stdlib@go1.24.11
0.60.0
1.26.9

Open the chart page →

2,463
calico-cniclastixVerified publisher3.28.13 of 3See more

calico-cni clastix 3.28.1

3 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
calico/cni:v3.28.1e486870cfde8
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

4,814
capi-kamaji-vsphere-fullclastixVerified publisher1.0.19 of 9See more

capi-kamaji-vsphere-full clastix 1.0.1

9 of the 9 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/net@v0.32.0
stdlib@go1.23.0
0.60.0
1.26.9
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
registry.k8s.io/csi-vsphere/syncer:v3.4.0179ebf195595
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.60.0
1.26.9
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

10,823
capsule-rancher-addonclastixVerified publisher0.1.15 of 5See more

capsule-rancher-addon clastix 0.1.1

5 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/net@v0.4.0
stdlib@go1.19.2
0.60.0
1.26.9
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.60.0
1.26.9

Open the chart page →

11,315
kamajiclastixVerified publisher0.0.0+latest3 of 4See more

kamaji clastix 0.0.0+latest

3 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
clastix/kamaji:latestbb4bd5e1d9eb
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.60.0
1.26.9

Open the chart page →

6,678
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
golang.org/x/net@v0.23.0
stdlib@go1.23.7
0.60.0
1.26.9

Open the chart page →

3,424
kamaji-etcdclastixVerified publisher0.18.13 of 4See more

kamaji-etcd clastix 0.18.1

3 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
cfssl/cfssl:latesta32a90480788
golang.org/x/net@v0.22.0
stdlib@go1.27.1
0.60.0
1.27.2
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.60.0
1.26.9
quay.io/coreos/etcd:v3.6.12702d7b4881c6
golang.org/x/net@v0.52.0
stdlib@go1.25.10
0.60.0
1.26.9

Open the chart page →

9,523
local-path-provisionerclastixVerified publisher0.0.301 of 1See more

local-path-provisioner clastix 0.0.30

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.309b9148811700
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

1,748
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.60.0
1.26.9
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.60.0
1.26.9
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.60.0
1.26.9

Open the chart page →

12,050
cloudflare-ddnsclouddrove0.1.51 of 1See more

cloudflare-ddns clouddrove 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
favonia/cloudflare-ddns:15e61736b982b
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

201
cloudflared-tunnelclouddrove0.1.41 of 1See more

cloudflared-tunnel clouddrove 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

2,426
cronjobclouddrove1.0.11 of 1See more

cronjob clouddrove 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/ubuntu:latestf144425ff09b
stdlib@go1.26.7
1.26.9

Open the chart page →

662
kube-acp-stackcloudentity2.29.13 of 7See more

kube-acp-stack cloudentity 2.29.1

3 of the 7 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
stdlib@go1.23.8
1.26.9
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/net@v0.33.0
stdlib@go1.21.13
0.60.0
1.26.9
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.60.0
1.26.9

Open the chart page →

24,824

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
ambassador/ambassador-agent:1.0.227a1ea0d934fb
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.60.0
1.26.9
1
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.26.9
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
stdlib@go1.20.12
1.26.9
1
anchore/anchore-engine:v0.10.0bde9eedf639d
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.16.3
0.60.0
1.26.9
1
anchore/ecs-inventory:v1.5.12b424b3b9a03
stdlib@go1.26.8
1.26.9
1
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.60.0
1.26.9
1
anchore/kubernetes-admission-controller:v0.8.51a1a374658c8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
golang.org/x/net@v0.38.0
stdlib@go1.26.5
0.60.0
1.26.9
1
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.10
0.60.0
1.26.9
1
andreacioni/kube-workload-restarter:0.0.242938b310090a
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.60.0
1.26.9
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.26.9
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
stdlib@go1.18.2
1.26.9
1
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.26.9
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.26.9
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
golang.org/x/net@v0.58.0
stdlib@go1.25.7
0.60.0
1.26.9
1
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
antrea/antrea-ui-backend:v0.8.019f3c0113330
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
1
antrea/flow-aggregator:v2.7.0065193e7572f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
1
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.26.9
1
anujdatar/cups:25.07.01685df04a643b
stdlib@go1.19.8
1.26.9
1
apache/airflow:2.8.4-python3.964e58748b6b9
stdlib@go1.21.8
1.26.9
1
apache/airflow:airflow-pgbouncer-exporter-2025.03.05-0.18.0adf7260c2c5f
stdlib@go1.23.7
1.26.9
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
stdlib@go1.22.7
1.26.9
1
apache/airflow:2.8.1e5560ad0b86e
stdlib@go1.19.8
1.26.9
1
apache/answer:2.0.2a0d71b0e30a5
golang.org/x/net@v0.56.0
stdlib@go1.25.12
0.60.0
1.26.9
1
apache/apisix-dashboard:2.9.0c010ea7d1694
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.15
0.60.0
1.26.9
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.13.8
0.60.0
1.26.9
1
apache/camel-k:1.10.43bb13d14f64a
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.13
0.60.0
1.26.9
1
apache/camel-k:2.11.0d173e7efe258
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
1
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
golang.org/x/net@v0.10.0
stdlib@go1.19.10
0.60.0
1.26.9
1
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.60.0
1.26.9
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.60.0
1.26.9
1
apache/solr-operator:v0.9.14db34508137f
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.60.0
1.26.9
1
apache/tika:3.3.1.090b7fa1dc018
golang.org/x/net@v0.40.0
stdlib@go1.26.2
0.60.0
1.26.9
1
apache/tika:latest-fullab9cc988828c
stdlib@go1.26.7
1.26.9
1
apache/yunikorn:scheduler-1.10.049fc54894fdf
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
apache/yunikorn:web-1.10.090e6a62a578a
stdlib@go1.26.7
1.26.9
1
apache/yunikorn:admission-1.10.095c6b951f38a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
1
apecloud/dt-platform:0.1.1d48bcbd38066
golang.org/x/net@v0.8.0
stdlib@go1.19.11
0.60.0
1.26.9
1
apecloud/gemini-scheduler:0.1.15832d1a9097a
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.60.0
1.26.9
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.60.0
1.26.9
1
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.13
0.60.0
1.26.9
1
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.60.0
1.26.9
1
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
stdlib@go1.19.6
0.60.0
1.26.9
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/net@v0.5.0
stdlib@go1.19.13
0.60.0
1.26.9
1
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/net@v0.40.0
stdlib@go1.25.7
0.60.0
1.26.9
1
appwrite/appwrite:2.3.034ef77fb6e87
golang.org/x/net@v0.51.0
stdlib@go1.26.8
0.60.0
1.26.9
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.60.0
1.26.9
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.