StackRadar

CVE-2026-97032

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,553
of 18,090 indexed, latest versions
Container images
6,402
deployed by those charts
Fix available
8 of 9
affected packages

HTTP/2 server crash due to HPACK encoder race in net/http

Carried by container images the latest versions of 5,553 of 18,090 indexed charts deploy, on 6,402 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,378
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,149
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r31.15.10-r81
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r01.5.2-r31
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-4653-rw6m-872gCGA-4h9w-grf4-6jppCGA-8xvx-5mh6-vrc3CGA-9hgh-r65w-7q99CGA-f937-jwj2-rj5jCGA-fjhw-67fq-pm89DEBIAN-CVE-2026-97032GO-2026-6617
Also known as
CGA-387c-5f4p-4rh4, CGA-3qgw-9846-f468, CGA-499x-7xc5-927w, CGA-4qpc-rjrp-f4h4, CGA-5pv4-5xjw-qg97, CGA-5rcr-cqmr-f8hp, CGA-5vh8-jrpp-m4r3, CGA-8g7x-r6mw-97j8, CGA-8mf9-xfh8-jx3h, CGA-923f-66wm-xfq4, CGA-fjfp-jwwq-vjp3, CGA-gg5j-j7wm-wf6w, CGA-jrgf-gwq3-rf5w, CGA-m46j-x3g6-mqj4, CGA-mq7q-c763-9cvx, CGA-p4p3-mvmj-v95v, CGA-qpfw-4v8x-3667, CGA-qpqr-hw3x-7qxj, CGA-qqxw-hjpg-6rhv, CGA-r654-5gg7-p6xf, CGA-rggh-6rrq-mfp4, CGA-rwc6-gqq6-4p7r, CGA-vh2x-9247-h576, CGA-w2j8-94m3-rxc6, CGA-w2rp-6hc9-f8qw, CGA-w39g-2gpg-cfqr
Trending
Rank 11 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,553 by stars
ChartLatestAffected imagesRadar Score
pgoutboxappscodeVerified publisher2026.7.101 of 1See more

pgoutbox appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/pgoutbox:v0.0.4a96e06ec5e9f
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

1,267
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1149b706354a6f
golang.org/x/net@v0.57.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

44,043
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
golang.org/x/net@v0.26.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

1,253
prom-label-proxyappscodeVerified publisher2026.9.221 of 1See more

prom-label-proxy appscode 2026.9.22

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/prom-label-proxy:v2026.9.2247afd6372838
golang.org/x/net@v0.52.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

344
prom-proxyappscodeVerified publisher2023.3.231 of 1See more

prom-proxy appscode 2023.3.23

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2023.03.235f5a40fc1702
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.60.0
1.26.9

Open the chart page →

3,515
regcacheappscodeVerified publisher2026.9.111 of 1See more

regcache appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
golang.org/x/net@v0.52.0
stdlib@go1.25.9
0.60.0
1.26.9

Open the chart page →

1,061
secrets-store-csi-driver-provider-virtual-secretsappscodeVerified publisher2026.8.141 of 1See more

secrets-store-csi-driver-provider-virtual-secrets appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/secrets-store-csi-driver-provider-virtual-secrets:v0.2.07afb394f9f97
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

1,050
service-backendappscodeVerified publisher2026.9.111 of 1See more

service-backend appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,844
service-gatewayappscodeVerified publisher2026.9.113 of 3See more

service-gateway appscode 2026.9.11

3 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.60.0
1.26.9
ghcr.io/voyagermesh/echoserver:v20221109fa56a9251de6
stdlib@go1.19
1.26.9
ghcr.io/voyagermesh/gateway:v1.8.24237fd16a3cb
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

3,653
service-presetsappscodeVerified publisher2024.2.111 of 1See more

service-presets appscode 2024.2.11

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.26.9

Open the chart page →

1,565
service-providerappscodeVerified publisher2026.9.112 of 2See more

service-provider appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.60.0
1.26.9
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

3,307
service-vaultappscodeVerified publisher2026.9.112 of 2See more

service-vault appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
stdlib@go1.24.13
0.60.0
1.26.9
ghcr.io/kubevault/vault-operator:v0.25.0c8e042b5cee8
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

1,607
sidekickappscodeVerified publisher2026.7.101 of 1See more

sidekick appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/sidekick:v0.0.16d8d2a3c22ee7
golang.org/x/net@v0.55.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

635
stash-communityappscodeVerified publisher0.42.04 of 4See more

stash-community appscode 0.42.0

4 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.60.0
1.26.9
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
stdlib@go1.24.9
0.60.0
1.26.9
ghcr.io/stashed/stash:v0.42.03a98245a7667
golang.org/x/net@v0.26.0
stdlib@go1.25.3
0.60.0
1.26.9
ghcr.io/stashed/stash-crd-installer:v0.42.076f0a650e44b
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

6,227
stash-opscenterappscodeVerified publisher2025.10.171 of 1See more

stash-opscenter appscode 2025.10.17

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

1,145
stash-ui-serverappscodeVerified publisher0.23.01 of 1See more

stash-ui-server appscode 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
golang.org/x/net@v0.38.0
stdlib@go1.25.3
0.60.0
1.26.9

Open the chart page →

1,145
statefulsetappscodeVerified publisher0.0.12 of 3See more

statefulset appscode 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.60.0
1.26.9
ghcr.io/appscode/kubectl-nonroot:v1.248ee5bdd68977
stdlib@go1.20.7
1.26.9

Open the chart page →

4,423
storage-metrics-serverappscodeVerified publisher2026.7.81 of 1See more

storage-metrics-server appscode 2026.7.8

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/storage-metrics-server:v0.1.09cb4acb742a9
golang.org/x/net@v0.48.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

957
supervisorappscodeVerified publisher2026.2.161 of 1See more

supervisor appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/supervisor:v0.0.1223affde10a92
golang.org/x/net@v0.47.0
stdlib@go1.25.12
0.60.0
1.26.9

Open the chart page →

522
taskqueueappscodeVerified publisher2026.2.161 of 1See more

taskqueue appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,531
tenant-operatorappscodeVerified publisher2026.9.221 of 1See more

tenant-operator appscode 2026.9.22

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/tenant-operator:v0.0.38fe9b4157ed2
golang.org/x/net@v0.54.0
stdlib@go1.25.14
0.60.0
1.26.9

Open the chart page →

425
thanos-operatorappscodeVerified publisher2026.6.21 of 1See more

thanos-operator appscode 2026.6.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/opnpulse/thanos-operator:v2026.4.24e05a3e701291
golang.org/x/net@v0.49.0
stdlib@go1.26.2
0.60.0
1.26.9

Open the chart page →

744
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
golang.org/x/net@v0.47.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

1,685
vcd-lb-gcappscodeVerified publisher2026.6.251 of 1See more

vcd-lb-gc appscode 2026.6.25

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/net@v0.23.0
stdlib@go1.25.11
0.60.0
1.26.9

Open the chart page →

491
voyagerappscodeVerified publisher2026.3.231 of 1See more

voyager appscode 2026.3.23

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/voyager:v17.5.04964ceaf9d35
golang.org/x/net@v0.52.0
stdlib@go1.25.8
0.60.0
1.26.9

Open the chart page →

1,133
voyager-gatewayappscodeVerified publisher2026.10.102 of 2See more

voyager-gateway appscode 2026.10.10

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.4.04466bb77dc78
golang.org/x/net@v0.47.0
stdlib@go1.25.13
0.60.0
1.26.9
ghcr.io/voyagermesh/gateway:v1.8.24237fd16a3cb
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,994
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
golang.org/x/net@v0.11.0
stdlib@go1.21.1
0.60.0
1.26.9

Open the chart page →

6,771
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/net@v0.19.0
stdlib@go1.22.2
0.60.0
1.26.9

Open the chart page →

1,805
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mongo:latestbac22ea7710d
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

9,085
appwriteappwrite-helmVerified publisher1.3.24 of 8See more

appwrite appwrite-helm 1.3.2

4 of the 8 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
golang.org/x/net@v0.40.0
stdlib@go1.25.7
0.60.0
1.26.9
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.26.9
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.26.9
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.26.9

Open the chart page →

13,291
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

6,468
arcadearcadeVerified publisher1.11.11 of 10See more

arcade arcade 1.11.1

1 of the 10 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/postgres:17-alpineb0f9560a2de0
stdlib@go1.24.6
1.26.9

Open the chart page →

1,037
argocd-ecr-updaterargocd-aws-ecr-updater0.3.391 of 1See more

argocd-ecr-updater argocd-aws-ecr-updater 0.3.39

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/karlderkaefer/argocd-ecr-updater:1.4.6ed5d4b74792c
golang.org/x/net@v0.55.0
stdlib@go1.26.5
0.60.0
1.26.9

Open the chart page →

350
argocd-bitbucket-proxyargocd-bitbucket-proxy1.1.11 of 1See more

argocd-bitbucket-proxy argocd-bitbucket-proxy 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/salemgolemugoo/argocd-bitbucket-proxy:latesta72df069095b
stdlib@go1.26.1
1.26.9

Open the chart page →

478
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.60.0
1.26.9
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.26.9
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/net@v0.34.0
stdlib@go1.22.2
0.60.0
1.26.9

Open the chart page →

10,191
argo-workflowsargo-helm-charts1.0.02 of 2See more

argo-workflows argo-helm-charts 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
golang.org/x/net@v0.40.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

2,843
clickhouseargonaut-charts0.6.82 of 3See more

clickhouse argonaut-charts 0.6.8

2 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.13.15
0.60.0
1.26.9
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

11,768
istio-discoveryargonaut-charts0.3.31 of 1See more

istio-discovery argonaut-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

76,174
istio-ingressargonaut-charts0.3.31 of 1See more

istio-ingress argonaut-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

76,119
argonix-apiargonix0.6.51 of 4See more

argonix-api argonix 0.6.5

1 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:0.6.5431abcce7c1e
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9

Open the chart page →

6,079
argo-zombiesargo-zombies0.1.521 of 1See more

argo-zombies argo-zombies 0.1.52

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/henrywhitaker3/argo-zombies:v0.4.4316c397906c9
golang.org/x/net@v0.47.0
stdlib@go1.26.1
0.60.0
1.26.9

Open the chart page →

645
otel-collectorarieotechVerified publisher0.1.01 of 1See more

otel-collector arieotech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.154.0b3079f45e19b
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

751
arlas-aiasarlas-stackVerified publisher28.9.06 of 22See more

arlas-aias arlas-stack 28.9.0

6 of the 22 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
golang.org/x/net@v0.39.0
stdlib@go1.23.9
0.60.0
1.26.9
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
stdlib@go1.25.0
1.26.9
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.60.0
1.26.9
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
golang.org/x/net@v0.39.0
stdlib@go1.24.2
0.60.0
1.26.9
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
golang.org/x/net@v0.33.0
stdlib@go1.23.8
0.60.0
1.26.9
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
stdlib@go1.24.4
1.26.9

Open the chart page →

47,472
arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.60.0
1.26.9
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.60.0
1.26.9
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
stdlib@go1.19.5
1.26.9
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.60.0
1.26.9
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.60.0
1.26.9

Open the chart page →

30,609
articom-k8s-crdarticomio-helm-charts1.2.32 of 2See more

articom-k8s-crd articomio-helm-charts 1.2.3

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
articomio/articom-cx-operator:v1.2.389efda334136
golang.org/x/net@v0.47.0
stdlib@go1.25.14
0.60.0
1.26.9
hashicorp/vault:1.18750bb37c1638
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.60.0
1.26.9

Open the chart page →

2,965
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.60.0
1.26.9

Open the chart page →

2,627
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.11
0.60.0
1.26.9
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.10
0.60.0
1.26.9
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.60.0
1.26.9
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.60.0
1.26.9

Open the chart page →

12,740
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.26.9

Open the chart page →

7,015
dltkvassist-iot-data-integrity-verification0.2.05 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.60.0
1.26.9
hyperledger/fabric-ca:latesta70b6ba64a08
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

196,685
dltflassist-iot-dlt-based-fl0.2.05 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

5 of the 9 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.60.0
1.26.9
hyperledger/fabric-ca:latesta70b6ba64a08
golang.org/x/net@v0.57.0
stdlib@go1.26.4
0.60.0
1.26.9
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.60.0
1.26.9

Open the chart page →

196,685

Container images carrying it

6,402 by charts deploying them

A fixed version is listed for 8 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.17.5
0.60.0
1.26.9
1
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
golang.org/x/net@v0.8.0
stdlib@go1.19.3
0.60.0
1.26.9
1
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.17.8
0.60.0
1.26.9
1
chocobozzz/peertube:v8.1.5052712130691
stdlib@go1.24.4
1.26.9
1
chriseaton/adventureworks:latest54c3384ce701
stdlib@go1.23.1
1.26.9
1
chrislusf/seaweedfs:3.64634b094b2183
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.60.0
1.26.9
1
chrislusf/seaweedfs:4.346620371e8af8
golang.org/x/net@v0.54.0
stdlib@go1.25.11
0.60.0
1.26.9
1
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9
1
chrislusf/seaweedfs-csi-driver:v1.4.341fca534c9001
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
chrislusf/seaweedfs-mount:v1.4.347c6250e96001
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
1
chriswells0/first-mate:1.0.5f3918ec8471c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.60.0
1.26.9
1
circleci/container-agent:34d8d0ae5efc3
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.60.0
1.26.9
1
circleci/runner:launch-agent9bdc62f02162
stdlib@go1.21.5
1.26.9
1
ciscolabs/msm-nc:0710202336d02faad958
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.60.0
1.26.9
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
stdlib@go1.18.1
1.26.9
1
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/net@v0.4.0
stdlib@go1.19.2
0.60.0
1.26.9
1
clastix/kamaji:latestbb4bd5e1d9eb
golang.org/x/net@v0.58.0
stdlib@go1.26.5
0.60.0
1.26.9
1
cleanstart/minio:latestf1156f7fd14a
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
1
clickhouse/clickhouse-server:23.8512bb8a21483
stdlib@go1.19.10
1.26.9
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
stdlib@go1.19.5
1.26.9
1
cloud37io/s3-encryption-gateway:0.12.310e791e98b62
golang.org/x/net@v0.59.0
stdlib@go1.27.1
0.60.0
1.27.2
1
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.60.0
1.26.9
1
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.60.0
1.26.9
1
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.26.9
1
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.16.6
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
1
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.60.0
1.26.9
1
cloudflare/cloudflared:2024.8.314d9c6b01b29
golang.org/x/net@v0.25.0
stdlib@go1.22.2-devel-cf
0.60.0
1.26.9
1
cloudflare/cloudflared:2024.5.05d5f70a59d5e
golang.org/x/net@v0.25.0
stdlib@go1.22.2-devel-cf
0.60.0
1.26.9
1
cloudflare/cloudflared:2024.11.1665dda65335e
golang.org/x/net@v0.25.0
stdlib@go1.22.5-devel-cf
0.60.0
1.26.9
1
cloudflare/cloudflared:2023.10.0c18744ae1767
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
1
cloudflare/cloudflared:2025.8.0eb5c9324efe3
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9
1
cloudflare/origin-ca-issuer:v0.15.09ee05675fa9c
golang.org/x/net@v0.56.0
stdlib@go1.27.1
0.60.0
1.27.2
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.60.0
1.26.9
1
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.26.9
1
cloudreve/cloudreve:3.8.009093aec5a20
golang.org/x/net@v0.0.0-20220630215102-69896b714898
stdlib@go1.20
0.60.0
1.26.9
1
cloudreve/cloudreve:4.18.0f7a464100bf6
golang.org/x/net@v0.55.0
stdlib@go1.25.5
0.60.0
1.26.9
1
cloudtooling/moodle:5.3.0.2d3e3607acf56
stdlib@go1.26.4
1.26.9
1
cloudtooling/wordpress:7.1.3fb4863035a05
stdlib@go1.26.4
1.26.9
1
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
stdlib@go1.15
1.26.9
1
cmacrae/lgtm:0.1.0dec8d490fe40
golang.org/x/net@v0.0.0-20181108082009-03003ca0c849
stdlib@go1.14.1
0.60.0
1.26.9
1
cockroachdb/cockroach-operator:v2.1.0983312754620
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.60.0
1.26.9
1
codecov/self-hosted-gateway:24.4.1de483faad6e5
golang.org/x/net@v0.21.0
stdlib@go1.22.0
0.60.0
1.26.9
1
codenotary/immudb:1.9.77c85d7cc4f22
golang.org/x/net@v0.17.0
stdlib@go1.18.10
0.60.0
1.26.9
1
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.26.9
1
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.26.9
1
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.60.0
1.26.9
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.