StackRadar

CVE-2026-97032

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5,564
of 18,087 indexed, latest versions
Container images
6,417
deployed by those charts
Fix available
6 of 9
affected packages

HTTP/2 server crash due to HPACK encoder race in net/http

Carried by container images the latest versions of 5,564 of 18,087 indexed charts deploy, on 6,417 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+212 more1.26.9, 1.27.26,392
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+227 more0.60.05,161
golang-1.19deb1.19.8-2no fix listed1
helm-4apk4.3.0-r04.3.0-r21
ingress-nginx-controller-1.15apk1.15.10-r3no fix listed1
kineapk0.17.1-r10.17.2-r21
kubernetes-1.37apk1.37.1-r01.37.1-r21
runcapk1.5.2-r0no fix listed1
tetragonapk1.7.1-r41.7.1-r61
OSV records
CGA-387c-5f4p-4rh4CGA-4653-rw6m-872gCGA-4h9w-grf4-6jppCGA-8xvx-5mh6-vrc3CGA-f937-jwj2-rj5jCGA-fjhw-67fq-pm89DEBIAN-CVE-2026-97032GO-2026-6617
Also known as
CGA-3qgw-9846-f468, CGA-499x-7xc5-927w, CGA-4qpc-rjrp-f4h4, CGA-5pv4-5xjw-qg97, CGA-5rcr-cqmr-f8hp, CGA-5vh8-jrpp-m4r3, CGA-8g7x-r6mw-97j8, CGA-8mf9-xfh8-jx3h, CGA-923f-66wm-xfq4, CGA-9hgh-r65w-7q99, CGA-fjfp-jwwq-vjp3, CGA-gg5j-j7wm-wf6w, CGA-jrgf-gwq3-rf5w, CGA-m46j-x3g6-mqj4, CGA-mq7q-c763-9cvx, CGA-p4p3-mvmj-v95v, CGA-qpfw-4v8x-3667, CGA-qpqr-hw3x-7qxj, CGA-qqxw-hjpg-6rhv, CGA-r654-5gg7-p6xf, CGA-rggh-6rrq-mfp4, CGA-rwc6-gqq6-4p7r, CGA-vh2x-9247-h576, CGA-w2j8-94m3-rxc6, CGA-w2rp-6hc9-f8qw, CGA-w39g-2gpg-cfqr
Trending
Rank 6 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

5,564 by stars
ChartLatestAffected imagesRadar Score
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
golang.org/x/net@v0.49.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

2,028
rabbitmq-cluster-operatoralexmorbo-rabbitmq-cluster-operatorVerified publisher1.0.01 of 1See more

rabbitmq-cluster-operator alexmorbo-rabbitmq-cluster-operator 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/rabbitmqoperator/cluster-operator:2.22.52727b84b835a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

166
rabbitmq-messaging-topology-operatoralexmorbo-rabbitmq-messaging-topology-operatorVerified publisher1.0.11 of 1See more

rabbitmq-messaging-topology-operator alexmorbo-rabbitmq-messaging-topology-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
quay.io/rabbitmqoperator/messaging-topology-operator:1.20.229174b668012
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

166
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.26.9

Open the chart page →

2,322
wireguardalexpressoVerified publisher0.1.71 of 2See more

wireguard alexpresso 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
linuxserver/wireguard:latest216ca1ce9da7
golang.org/x/net@v0.47.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

670
gotifyalexvanderberkelVerified publisher0.7.11 of 1See more

gotify alexvanderberkel 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/gotify/server:3.1.144fc5bbd1c06
golang.org/x/net@v0.55.0
stdlib@go1.26.0
0.60.0
1.26.9

Open the chart page →

651
alibaba-rsocket-brokeralibaba-rsocket-brokerVerified publisher0.1.31 of 1See more

alibaba-rsocket-broker alibaba-rsocket-broker 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17.7
0.60.0
1.26.9

Open the chart page →

94,430
alluredeckalluredeckVerified publisher0.24.01 of 2See more

alluredeck alluredeck 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
golang.org/x/net@v0.56.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,907
book-serveral-masood-helm-charts0.1.01 of 1See more

book-server al-masood-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
almasood/book-server:latest6ffac9b63cdf
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9

Open the chart page →

888
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.15
0.60.0
1.26.9

Open the chart page →

3,266
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

1,013
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.60.0
1.26.9

Open the chart page →

1,013
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

1,653
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
golang.org/x/net@v0.34.0
stdlib@go1.24.2
0.60.0
1.26.9

Open the chart page →

978
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.60.0
1.26.9

Open the chart page →

5,753
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.60.0
1.26.9

Open the chart page →

1,041
versitygwalpineworks0.1.21 of 1See more

versitygw alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
versity/versitygw:v1.0.145192635d0353
golang.org/x/net@v0.40.0
stdlib@go1.24.3
0.60.0
1.26.9

Open the chart page →

1,777
versitygw-webhook-pulsar-proxyalpineworks0.1.11 of 1See more

versitygw-webhook-pulsar-proxy alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/versitygw-webhook-pulsar-proxy:v1.0.06e9ced773732
golang.org/x/net@v0.40.0
stdlib@go1.24.4
0.60.0
1.26.9

Open the chart page →

1,379
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
alustan-helmalustan-helm1.0.01 of 1See more

alustan-helm alustan-helm 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
alustan/install-argocd:1.0.0c16c34f46ad3
golang.org/x/net@v0.19.0
stdlib@go1.22.5
0.60.0
1.26.9

Open the chart page →

2,449
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.60.0
1.26.9
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
stdlib@go1.19.13
0.60.0
1.26.9
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.60.0
1.26.9
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9

Open the chart page →

34,526
ampsamps0.1.95 of 10See more

amps amps 0.1.9

5 of the 10 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
hashicorp/vault:1.9.2ff9b17b0cefe
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.5
0.60.0
1.26.9
library/nats:2.7.2-alpine8b3fb2423a8c
stdlib@go1.17.6
1.26.9
natsio/nats-box:0.8.1b7f9328145f4
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.6
0.60.0
1.26.9
natsio/nats-server-config-reloader:0.6.2ad0374303b13
stdlib@go1.15.14
1.26.9
natsio/prometheus-nats-exporter:0.9.14665cdc7e749
stdlib@go1.16.13
1.26.9

Open the chart page →

15,571
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

2,199
anchore-admission-controlleranchore-charts0.9.02 of 2See more

anchore-admission-controller anchore-charts 0.9.0

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
anchore/kubernetes-admission-controller:v0.8.51a1a374658c8
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
cfssl/cfssl:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.60.0
1.26.9

Open the chart page →

8,723
ecs-inventoryanchore-charts0.1.01 of 1See more

ecs-inventory anchore-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
anchore/ecs-inventory:v1.5.12b424b3b9a03
stdlib@go1.26.8
1.26.9

Open the chart page →

93
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.60.0
1.26.9

Open the chart page →

2,041
cert-manager-webhook-inwxandibraeuVerified publisher0.9.01 of 1See more

cert-manager-webhook-inwx andibraeu 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/andibraeu/cert-manager-webhook-inwx:v0.9.0f015e745983e
golang.org/x/net@v0.48.0
stdlib@go1.25.7
0.60.0
1.26.9

Open the chart page →

933
music-assistant-serverandibraeuVerified publisher2.1.31 of 1See more

music-assistant-server andibraeu 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.528023f8c0d96
golang.org/x/net@v0.48.0
stdlib@go1.25.5
0.60.0
1.26.9

Open the chart page →

4,664
opencloudandibraeuVerified publisher1.0.01 of 1See more

opencloud andibraeu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:8.1.08fc64ca86173
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

200
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9

Open the chart page →

1,764
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
stdlib@go1.24.6
1.26.9

Open the chart page →

21,257
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.16.4
0.60.0
1.26.9

Open the chart page →

3,078
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.26.9

Open the chart page →

3,244
dnsmadeeasy-webhookangelnu6.0.71 of 1See more

dnsmadeeasy-webhook angelnu 6.0.7

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/angelnu/dnsmadeeasy-webhook:v1.9.0a5ca158b1f02
golang.org/x/net@v0.36.0
stdlib@go1.24.1
0.60.0
1.26.9

Open the chart page →

1,278
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.26.9

Open the chart page →

122,605
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.6e1074e92a452
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

141
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.60.0
1.26.9

Open the chart page →

3,637
ddosifyanteonVerified publisher1.7.55 of 13See more

ddosify anteon 1.7.5

5 of the 13 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.60.0
1.26.9
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.60.0
1.26.9
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.60.0
1.26.9
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.26.9
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
stdlib@go1.19.11
0.60.0
1.26.9

Open the chart page →

31,303
antmediaantmediaVerified publisher3.1.03 of 4See more

antmedia antmedia 3.1.0

3 of the 4 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mongo:8.0d0d926f94df0
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

6,115
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.60.0
1.26.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.60.0
1.26.9

Open the chart page →

4,871
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
grafana/grafana:latestb28bae15e219
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9

Open the chart page →

2,246
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
antrea/antrea-ui-backend:v0.8.019f3c0113330
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

3,923
flow-aggregatorantreaVerified publisher2.7.01 of 1See more

flow-aggregator antrea 2.7.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
antrea/flow-aggregator:v2.7.0065193e7572f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

1,079
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.60.0
1.26.9

Open the chart page →

3,890
devenvanza-labsVerified publisher0.1.21 of 3See more

devenv anza-labs 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
tailscale/tailscale:stablec507f3a2a6ab
golang.org/x/net@v0.56.0
stdlib@go1.26.6
0.60.0
1.26.9

Open the chart page →

249
glauthanza-labsVerified publisher1.0.21 of 1See more

glauth anza-labs 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
ghcr.io/glauth/glauth:v2.5.4905b5db533fc
golang.org/x/net@v0.58.0
stdlib@go1.25.0
0.60.0
1.26.9

Open the chart page →

1,093
imagepullerapache-pulsar-helm-chart-repo1.0.11 of 2See more

imagepuller apache-pulsar-helm-chart-repo 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/docker:latest0b6d18a4a222
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9

Open the chart page →

222
kesque-dashboardapache-pulsar-helm-chart-repo0.0.51 of 5See more

kesque-dashboard apache-pulsar-helm-chart-repo 0.0.5

1 of the 5 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
library/mariadb:latestf1bba652ba57
stdlib@go1.26.7
1.26.9

Open the chart page →

4,322
pulsar-monitorapache-pulsar-helm-chart-repo0.1.61 of 1See more

pulsar-monitor apache-pulsar-helm-chart-repo 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
kesque/pulsar-monitor:1.0.8ce85c1e7d613
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.4
0.60.0
1.26.9

Open the chart page →

4,242
apipingapiping1.5.01 of 1See more

apiping apiping 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-97032.

Container imageDigestPackageFixed in
udhos/apiping:1.5.041ab9bae6f3b
golang.org/x/net@v0.47.0
stdlib@go1.25.4
0.60.0
1.26.9

Open the chart page →

1,531

Container images carrying it

6,417 by charts deploying them

A fixed version is listed for 6 of the 9 affected packages.

Container imageDigestPackageFixed inUsed by
mikefarah/yq:2.4.16fc625c402de
stdlib@go1.13.3
1.26.9
3
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.17.4
0.60.0
1.26.9
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.60.0
1.26.9
3
natsio/nats-account-server:1.0.0a3381560aab6
stdlib@go1.16.6
1.26.9
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
stdlib@go1.20.5
1.26.9
3
natsio/prometheus-nats-exporter:0.17.326c826662ac8
stdlib@go1.24.2
1.26.9
3
oamdev/kube-webhook-certgen:v2.4.1231c423c2b17
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.11
0.60.0
1.26.9
3
oliver006/redis_exporter:v1.93.06ca518a72f30
stdlib@go1.27.1
1.27.2
3
opencsghq/postgres:15.19b98600564e07
stdlib@go1.24.6
1.26.9
3
opencsghq/stakater-reloader:v1.4.190491782f7bac
golang.org/x/net@v0.55.0
stdlib@go1.26.4
0.60.0
1.26.9
3
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
3
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.60.0
1.26.9
3
openebs/provisioner-localpv:3.5.0aea39e49bb97
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.60.0
1.26.9
3
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.60.0
1.26.9
3
otel/opentelemetry-collector:latest310a800ad69e
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
pgsty/silo:RELEASE.2026-09-03T13-18-01Zb616a0cf8cb2
golang.org/x/net@v0.58.0
stdlib@go1.27.1
0.60.0
1.27.2
3
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.60.0
1.26.9
3
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.60.0
1.26.9
3
prom/prometheus:v3.0.1565ee8650122
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.60.0
1.26.9
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.60.0
1.26.9
3
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.26.9
3
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.26.9
3
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.26.9
3
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.26.9
3
qingcloud/cloud-controller-manager:v1.4.1210f66b5df886
stdlib@go1.18.2
1.26.9
3
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.60.0
1.26.9
3
rancher/kubectl:v1.34.1090bef429ed1
golang.org/x/net@v0.38.0
stdlib@go1.24.6
0.60.0
1.26.9
3
rancher/system-upgrade-controller:v0.20.261b68d4372ba
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
stdlib@go1.19.4
1.26.9
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.60.0
1.26.9
3
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.26.9
3
solace/solace-pubsub-standard:latest3c8a8b7fdcae
golang.org/x/net@v0.58.0
stdlib@go1.26.8
0.60.0
1.26.9
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.60.0
1.26.9
3
tykio/tyk-dashboard:v5.13.21161bd297135
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
tykio/tyk-gateway-ee:v5.13.250b3e4f5398a
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
3
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.60.0
1.26.9
3
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.26.9
3
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/net@v0.27.0
stdlib@go1.23.4
0.60.0
1.26.9
3
wallabag/wallabag:2.6.144a527e027e0d
stdlib@go1.25.1
1.26.9
3
yugabytedb/yugabyte:2026.1.2.0-b137b6dba322c734
golang.org/x/net@v0.58.0
stdlib@go1.26.7
0.60.0
1.26.9
3
gcr.io/trillian-opensource-ci/db_server2a685a38dd01
stdlib@go1.18.2
1.26.9
3
ghcr.io/appscode/petset:v0.1.093fa0daf603c
golang.org/x/net@v0.47.0
stdlib@go1.25.10
0.60.0
1.26.9
3
ghcr.io/appscode/sidekick:v0.0.15d1036b07e348
golang.org/x/net@v0.47.0
stdlib@go1.25.11
0.60.0
1.26.9
3
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.60.0
1.26.9
3
ghcr.io/coder/coder:v2.38.038a4cfc548b0
golang.org/x/net@v0.58.0
stdlib@go1.26.4
0.60.0
1.26.9
3
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.60.0
1.26.9
3
ghcr.io/external-secrets/external-secrets:v2.12.07a3c4f7e038f
golang.org/x/net@v0.58.0
stdlib@go1.26.6
0.60.0
1.26.9
3
ghcr.io/hatchet-dev/hatchet/hatchet-admin:v0.110.57c233e606095
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3
ghcr.io/hatchet-dev/hatchet/hatchet-api:v0.110.5be06a6b88299
golang.org/x/net@v0.59.0
stdlib@go1.26.8
0.60.0
1.26.9
3

syft 1.42.1 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.