StackRadar

CVE-2020-26160

High

Advisory

Published 14 Apr 2021In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.022
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
175
of 17,781 indexed, latest versions
Container images
163
deployed by those charts
Fix available
None
affected package

Authorization bypass in github.com/dgrijalva/jwt-go

Carried by container images the latest versions of 175 of 17,781 indexed charts deploy, on 163 images.

Affected packageAffected versionsFixed inImages
github.com/dgrijalva/jwt-gogolangv0.0.0-20160705203006-01aeca54ebda, v3.0.1-0.20170104182250-a601269ab70c+incompatible, v3.2.0+incompatible, v3.2.1-0.20190620180102-5e25c22bd5d6+incompatible+1 moreno fix listed163
OSV records
GHSA-w73w-5m7g-f7qcGO-2020-0017
Also known as
SNYK-GOLANG-GITHUBCOMDGRIJALVAJWTGO-596515

Charts affected

175 by stars
ChartLatestAffected imagesRadar Score
spinnakerspinnakerVerified publisher2.2.132 of 4See more

spinnaker spinnaker 2.2.13

2 of the 4 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

6,836
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

3,096
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

2,081
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

16,506
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

6,596
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

2,869
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

2,821
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,480
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

8,484
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,510
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

3,109
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
stakkato95/twitter-service-users:0.1.1456049efee9a
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

6,132
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,429
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

13,459
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,552
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

4,086
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

3,174
harborwenerme1.19.22 of 8See more

harbor wenerme 1.19.2

2 of the 8 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
goharbor/registry-photon:v2.15.2c4ebef61ceb5
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

1,650
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

6,915
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
prom/prometheus:v2.16.0e4ca62c0d62f
github.com/dgrijalva/jwt-go@v0.0.0-20160705203006-01aeca54ebda
no fix listed

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

3,369
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

3,023

Container images carrying it

163 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
etejeda/butlerci:0.1.0737d58183abc
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
filebrowser/filebrowser:v2.18.04fcd47af573c
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
flashcatcloud/nightingale:8.5.1421acb36181b
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
gitea/gitea:1.12.485416d6f65fe
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
gitea/gitea:1.13.0d5ab14cd29af
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
grafana/loki:2.0.077e138f81a8e
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
grafana/promtail:2.0.05fd12edcc694
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
iotaledger/goshimmer:v0.8.6b02a8f77474f
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
jmferrer/azure-devops-agent:latest030f68ec6998
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
keptncontrib/prometheus-service:0.6.029969dd547de
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
library/influxdb:2.0.8ba10ac9ba17a
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
library/traefik:2.2.8f5af5a5ce17f
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
logiqai/flash-discovery:v2.0.3f5b551bca98e
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
mesosphere/kubefed:proxyurl4fd8889195fe
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
minio/mc:RELEASE.2020-04-25T00-43-23Z1806872732e1
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
minio/operator:v4.1.02adc5be088f5
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
github.com/dgrijalva/jwt-go@v3.0.1-0.20170104182250-a601269ab70c+incompatible
no fix listed
1
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
monitoror/monitoror:44b88edcf51ff
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
nerzhul/mc-arm64:2020.10.034215df511f31
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
owncloud/ocis:1.7.0d2efcae92c84
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
prom/prometheus:v2.18.15880ec936055
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
prom/prometheus:v2.19.2cd134bd4fca0
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
prom/prometheus:v2.16.0e4ca62c0d62f
github.com/dgrijalva/jwt-go@v0.0.0-20160705203006-01aeca54ebda
no fix listed
1
rancher/hardened-calico:v3.13.36d2cd61a338b
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
reportportal/service-index:5.0.112b27a2d7a87d
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
rookout/k8s-operator:latest0d083f3ef1a7
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
runatlantis/atlantis:v0.16.145fbaf7e207c
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
sstarcher/helm-exporter:0.5.011769d01ba35
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
stakkato95/twitter-service-users:0.1.1456049efee9a
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
subspacecommunity/subspace:1.5.0e2042b63fb35
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.