VDB
GO-2026-4559
GO-2026-4559
PUBLISHED
Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chainguard | kube-logging-operator | 0, 0, 0 |
| chainguard | datadog-agent-7.74 | 0, 0 |
| chainguard | crossplane-provider-aws-kms | 0, 0 |
| chainguard | victoriametrics-cluster-fips | *, * |
| chainguard | tekton-pipelines-fips-1.10 | 0, 0 |
| chainguard | crossplane-provider-aws-cloudwatchlogs | 0, 0 |
| chainguard | crossplane-provider-aws-firehose-fips | 0, 0 |
| chainguard | nova | 0, 0 |
| wolfi | crossplane-provider-aws-eks | 0, 0, 0 |
| chainguard | flux-operator | 0, 0 |
| chainguard | goose-fips | 0, 0 |
| chainguard | buildkite-agent | 0, 0 |
| chainguard | dockerize | *, * |
| wolfi | tekton-pipelines-1.10 | 0, 0, 0 |
| chainguard | harbor-2.12 | 0, 0 |
| chainguard | apm-server-9.2 | 0, 0 |
| wolfi | pluto | 0, 0, 0 |
| chainguard | victoriametrics-fips | *, * |
| chainguard | descheduler-fips | 0, 0 |
| chainguard | crossplane-provider-aws-dynamodb | 0, 0 |
…and 368 more
Timeline
- Feb 26, 2026 CVE Published
- May 1, 2026 Security Advisory
- May 15, 2026 CVE Updated