StackRadar

CVE-2026-97032

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 server crash due to HPACK encoder race in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4653-rw6m-872gCGA-4h9w-grf4-6jppCGA-8xvx-5mh6-vrc3CGA-9hgh-r65w-7q99CGA-f937-jwj2-rj5jCGA-fjhw-67fq-pm89DEBIAN-CVE-2026-97032GO-2026-6617
Also known as
CGA-387c-5f4p-4rh4, CGA-3qgw-9846-f468, CGA-499x-7xc5-927w, CGA-4qpc-rjrp-f4h4, CGA-5pv4-5xjw-qg97, CGA-5rcr-cqmr-f8hp, CGA-5vh8-jrpp-m4r3, CGA-8g7x-r6mw-97j8, CGA-8mf9-xfh8-jx3h, CGA-923f-66wm-xfq4, CGA-fjfp-jwwq-vjp3, CGA-gg5j-j7wm-wf6w, CGA-jrgf-gwq3-rf5w, CGA-m46j-x3g6-mqj4, CGA-mq7q-c763-9cvx, CGA-p4p3-mvmj-v95v, CGA-qpfw-4v8x-3667, CGA-qpqr-hw3x-7qxj, CGA-qqxw-hjpg-6rhv, CGA-r654-5gg7-p6xf, CGA-rggh-6rrq-mfp4, CGA-rwc6-gqq6-4p7r, CGA-vh2x-9247-h576, CGA-w2j8-94m3-rxc6, CGA-w2rp-6hc9-f8qw, CGA-w39g-2gpg-cfqr
Trending
Rank 11 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
pod-gateway-settergeek-cookbookVerified publisher1.0.01 of 1See more

pod-gateway-setter geek-cookbook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

2,813
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.26.9

Open the chart page →

13,377
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
stdlib@go1.18.4
1.26.9

Open the chart page →

11,591
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.26.9

Open the chart page →

9,108
rtsp-to-webgeek-cookbookVerified publisher2.2.21 of 1See more

rtsp-to-web geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.60.0

Open the chart page →

1,625
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:latestac252dba4165
stdlib@go1.18.1
1.26.9

Open the chart page →

3,449
searxgeek-cookbookVerified publisher5.6.23 of 4See more

searx geek-cookbook 5.6.2

3 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.26.9
dalf/morty:latest248a4849c350
golang.org/x/net@v0.0.0-20220421235706-1d1ef9303861
stdlib@go1.18.2
0.60.0
1.26.9
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.60.0
1.26.9

Open the chart page →

10,638
skypilotgeek-cookbookVerified publisher0.0.13 of 3See more

skypilot geek-cookbook 0.0.1

3 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
golang.org/x/net@v0.38.0
stdlib@go1.23.5
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0c9f76a75fd00
golang.org/x/net@v0.41.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

11,421
torrservergeek-cookbookVerified publisher1.2.21 of 1See more

torrserver geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
smailkoz/torrserver:1.0.1117b52d15de8f0
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.5
0.60.0
1.26.9

Open the chart page →

4,232
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
stdlib@go1.18.4
1.26.9

Open the chart page →

13,227
vikunjageek-cookbookVerified publisher6.2.02 of 4See more

vikunja geek-cookbook 6.2.0

2 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.5
0.60.0
1.26.9
vikunja/api:0.17.18cba0520bf8c
golang.org/x/net@v0.0.0-20210505024714-0287a6fb4125
stdlib@go1.16.5
0.60.0
1.26.9

Open the chart page →

9,931
webhook-receivergeek-cookbookVerified publisher0.0.11 of 1See more

webhook-receiver geek-cookbook 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

2,082
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.26.9

Open the chart page →

19,747
asynqmongeneral-helm-chartsVerified publisher0.0.11 of 1See more

asynqmon general-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hibiken/asynqmon:latestac80bcffd2f9
stdlib@go1.18.10
1.26.9

Open the chart page →

1,427
cbtgeneral-helm-chartsVerified publisher0.0.51 of 1See more

cbt general-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ethpandaops/cbt:latest99f52ce7bad8
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

343
chproxygeneral-helm-chartsVerified publisher0.0.21 of 1See more

chproxy general-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
contentsquareplatform/chproxy:v1.26.524555f22d4be
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9

Open the chart page →

4,555
clickhouse-movoorgeneral-helm-chartsVerified publisher0.0.11 of 1See more

clickhouse-movoor general-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ethpandaops/clickhouse-movoor:latestc0e6cc6542c1
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

422
cloudflare-tunnelgeneral-helm-chartsVerified publisher0.2.01 of 1See more

cloudflare-tunnel general-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
cloudflare/cloudflared:latest9b49eed8f628
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

625
dispatchoor-apigeneral-helm-chartsVerified publisher0.1.11 of 1See more

dispatchoor-api general-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
golang.org/x/net@v0.47.0
stdlib@go1.24.13
0.60.0
1.26.9

Open the chart page →

1,264
panda-pulsegeneral-helm-chartsVerified publisher1.0.61 of 1See more

panda-pulse general-helm-charts 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ethpandaops/panda-pulse:latestad6fc3b3e6b8
stdlib@go1.26.1
1.26.9

Open the chart page →

979
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.10
0.60.0
1.26.9

Open the chart page →

6,066
mongogengxiankun-charts0.1.01 of 1See more

mongo gengxiankun-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
golang.org/x/net@v0.47.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

4,694
mysqlgengxiankun-charts0.2.01 of 1See more

mysql gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

880
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.82 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

2 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
golang.org/x/net@v0.11.0
stdlib@go1.19.11
0.60.0
1.26.9
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.26.9

Open the chart page →

38,042
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.60.0
1.26.9
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.60.0
1.26.9

Open the chart page →

19,569
ghostghostVerified publisher0.1.03 of 4See more

ghost ghost 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
cloudflare/cloudflared:latest9b49eed8f628
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
library/ghost:5.79.083f7bf209844
stdlib@go1.18.2
1.26.9
litestream/litestream:0.3c5a1e1b01916
golang.org/x/net@v0.14.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

11,240
rabbitmqginger-society0.1.02 of 2See more

rabbitmq ginger-society 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
kbudde/rabbitmq-exporter:latest12f27d6d84e6
stdlib@go1.21.8
1.26.9
library/rabbitmq:4-management8dd6e3570dda
stdlib@go1.22.2
1.26.9

Open the chart page →

2,282
gitanagitana1.4.01 of 1See more

gitana gitana 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ntakashi/gitana:1.4.04171ec641120
golang.org/x/net@v0.0.0-20210929161516-d455829e376d
stdlib@go1.17.7
0.60.0
1.26.9

Open the chart page →

5,795
github-rate-limits-prometheus-exportergithub-rate-limit-prometheus-exporterVerified publisher0.2.151 of 1See more

github-rate-limits-prometheus-exporter github-rate-limit-prometheus-exporter 0.2.15

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/kalgurn/grl-exporter:v3.2.0bd109b2bda38
stdlib@go1.23.5
1.26.9

Open the chart page →

1,329
gitlab-goproxygitlab-goproxy0.2.21 of 1See more

gitlab-goproxy gitlab-goproxy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/net@v0.10.0
stdlib@go1.21.0
0.60.0
1.26.9

Open the chart page →

2,053
gitlab-mr-conformgitlab-mr-conform0.6.01 of 1See more

gitlab-mr-conform gitlab-mr-conform 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/chrxmvtik/gitlab-mr-conform:0.6.0facdb9bf0394
golang.org/x/net@v0.51.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

790
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
golang.org/x/net@v0.11.0
stdlib@go1.19.12
0.60.0
1.26.9

Open the chart page →

3,341
prometheus-container-resource-exportergkarthiks0.3.11 of 1See more

prometheus-container-resource-exporter gkarthiks 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
gkarthics/container-resource-exporter:latest6799af333e8a
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.7
0.60.0
1.26.9

Open the chart page →

3,454
prometheus-couchdb-exportergkarthiks0.1.31 of 1See more

prometheus-couchdb-exporter gkarthiks 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
gesellix/couchdb-prometheus-exporter:v27.2.05b891f1fc2b9
stdlib@go1.13.10
1.26.9

Open the chart page →

2,355
glassflow-etlglassflowVerified publisher0.5.2111 of 16See more

glassflow-etl glassflow 0.5.21

11 of the 16 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
library/nats:2.12.3-alpine88fe8e0e09d6
stdlib@go1.25.5
1.26.9
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.21.110ff229eaf52
stdlib@go1.25.5
1.26.9
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.26.9
otel/opentelemetry-collector-contrib:0.108.0923eb1cfae32
golang.org/x/net@v0.28.0
stdlib@go1.23.0
0.60.0
1.26.9
ghcr.io/glassflow/glassflow-etl-be:v3.2.020f066d0f631
golang.org/x/net@v0.52.0
stdlib@go1.25.0
0.60.0
1.26.9
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9
ghcr.io/glassflow/kafka-kerberos-gateway:latest2ae01c524a6e
stdlib@go1.21.13
1.26.9

Open the chart page →

17,301
pgbouncerglassflowVerified publisher0.1.01 of 1See more

pgbouncer glassflow 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bitnamilegacy/pgbouncer:1.23.192356da09704
stdlib@go1.22.10
1.26.9

Open the chart page →

4,000
postgresqlglassflowVerified publisher0.1.91 of 1See more

postgresql glassflow 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9

Open the chart page →

696
glassflow-operatorglassflow-operatorVerified publisher0.8.52 of 3See more

glassflow-operator glassflow-operator 0.8.5

2 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bitnami/kubectl:latestf7f9e4f64d9e
golang.org/x/net@v0.57.0
stdlib@go1.26.8
0.60.0
1.26.9
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
golang.org/x/net@v0.43.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

1,486
glauthglauthVerified publisher0.3.171 of 2See more

glauth glauth 0.3.17

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
golang.org/x/net@v0.41.0
stdlib@go1.24.5
0.60.0
1.26.9

Open the chart page →

3,449
glidergliderVerified publisher0.1.51 of 1See more

glider glider 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
nadoo/glider:0.1638aadefbd607
golang.org/x/net@v0.28.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

1,526
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mariadb:latestf1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

13,056
gnp-stackgnp-stack0.0.511 of 14See more

gnp-stack gnp-stack 0.0.5

11 of the 14 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
grafana/grafana:12.2.135c41e0fd029
golang.org/x/net@v0.45.0
stdlib@go1.25.3
0.60.0
1.26.9
library/nats:2.12.1-alpineb3f2bd84176a
stdlib@go1.25.3
1.26.9
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/net@v0.44.0
stdlib@go1.25.2
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.20.147094fcae2f4
stdlib@go1.24.8
1.26.9
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.26.9
rancher/local-path-provisioner:v0.0.329289da488b07
golang.org/x/net@v0.38.0
stdlib@go1.24.4
0.60.0
1.26.9
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
golang.org/x/net@v0.50.0
stdlib@go1.24.12
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.85.0890b3bb05cf4
golang.org/x/net@v0.43.0
stdlib@go1.24.6
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.33d671cf20a35
golang.org/x/net@v0.44.0
stdlib@go1.25.1
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
golang.org/x/net@v0.41.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

18,570
go-app-helmgo-app-helm0.1.01 of 1See more

go-app-helm go-app-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
manojchaulagain/go-k8s:0.1.0f237b5f637ae
stdlib@go1.20.1
1.26.9

Open the chart page →

2,866
go-file-servergo-file-server1.0.01 of 2See more

go-file-server go-file-server 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
goccx/go-file-server:latestf4b3ebea0303
golang.org/x/net@v0.27.0
stdlib@go1.21.10
0.60.0
1.26.9

Open the chart page →

2,864
gofitgofit0.0.11 of 1See more

gofit gofit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/bamaas/gofit:0.0.132b6a174b419
stdlib@go1.22.11
1.26.9

Open the chart page →

1,058
goldpingergoldpinger1.2.01 of 1See more

goldpinger goldpinger 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.11.5f7c60d319150
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2

Open the chart page →

201
googly-logingoogly-login0.1.01 of 2See more

googly-login googly-login 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:1665b16a8b326e
stdlib@go1.24.6
1.26.9

Open the chart page →

1,802
gorsegorse-io0.4.23 of 4See more

gorse gorse-io 0.4.2

3 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9

Open the chart page →

6,804
gosmee-clientgosmee-clientVerified publisher0.1.31 of 1See more

gosmee-client gosmee-client 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/chmouel/gosmee:v0.32.060b8db1f68cc
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

623
gotwaygotwayVerified publisher0.8.01 of 1See more

gotway gotway 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.18.3
0.60.0
1.26.9

Open the chart page →

2,799

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.60.0
1.26.9
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0:v2.8.1f6717ce72a26
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
stdlib@go1.24.2
0.60.0
1.26.9
6
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
golang.org/x/net@v0.54.0
stdlib@go1.26.3
0.60.0
1.26.9
6
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
5
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.60.0
1.26.9
5
containous/whoami:latest:v1.5.07d6a3c8f9147
stdlib@go1.14
1.26.9
5
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.60.0
1.26.9
5
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.60.0
1.26.9
5
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.60.0
1.26.9
5
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.60.0
1.26.9
5
grafana/tempo:2.9.065a578975943
golang.org/x/net@v0.43.0
stdlib@go1.25.1
0.60.0
1.26.9
5
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
5
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.26.9
5
library/mysql:26.7.0:latestade067ae2fb1
stdlib@go1.24.6
1.26.9
5
library/postgres:172d2b8998d310
stdlib@go1.24.6
1.26.9
5
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.26.9
5
library/redis:7.4.2-alpine:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.26.9
5
library/redis:5:5.0fc5ecd863862
stdlib@go1.16.7
1.26.9
5
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
stdlib@go1.21.3
0.60.0
1.26.9
5
outcoldsolutions/collectorforkubernetes:26.04.5b2577b85aa71
stdlib@go1.26.8
1.26.9
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.60.0
1.26.9
5
rancher/rancher:v2.15.20c3d8e570255
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9
5
rancher/shell:v0.8.21eeed72d4eda
golang.org/x/net@v0.56.0
stdlib@go1.26.8
0.60.0
1.26.9
5
sigma2as/goidc-proxy:next656ac798963a
golang.org/x/net@v0.51.0
stdlib@go1.25.7
0.60.0
1.26.9
5
ghcr.io/dexidp/dex:v2.46.0933fcd3f5233
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
5
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.26.9
5
ghcr.io/paperless-ngx/paperless-ngx:3.3.06b94799bc769
stdlib@go1.24.4
1.26.9
5
ghcr.io/quenchworks/images/prometheusa9dc21133c23
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.60.0
1.26.9
5
quay.io/prometheus/mysqld-exporter:latest:v0.20.0abed8dac117b
golang.org/x/net@v0.57.0
stdlib@go1.26.5
0.60.0
1.26.9
5
quay.io/prometheus/node-exporter:v1.9.1d00a542e409e
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
5
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.60.0
1.26.9
5
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
stdlib@go1.23.7
0.60.0
1.26.9
5
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.4.0a4838319e55b
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
stdlib@go1.21.3
0.60.0
1.26.9
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
stdlib@go1.22.8
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9
5
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.60.0
1.26.9
5
adguard/adguardhome:v0.107.79aba9e3bf0613
golang.org/x/net@v0.57.0
stdlib@go1.26.6
0.60.0
1.26.9
4
artifacthub/postgres:latest4fd34fa635cc
stdlib@go1.24.6
1.26.9
4
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
stdlib@go1.25.0
1.26.9
4
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
stdlib@go1.24.6
1.26.9
4

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.