StackRadar

CVE-2020-26160

High

Advisory

Published 14 Apr 2021In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.022
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
175
of 17,781 indexed, latest versions
Container images
163
deployed by those charts
Fix available
None
affected package

Authorization bypass in github.com/dgrijalva/jwt-go

Carried by container images the latest versions of 175 of 17,781 indexed charts deploy, on 163 images.

Affected packageAffected versionsFixed inImages
github.com/dgrijalva/jwt-gogolangv0.0.0-20160705203006-01aeca54ebda, v3.0.1-0.20170104182250-a601269ab70c+incompatible, v3.2.0+incompatible, v3.2.1-0.20190620180102-5e25c22bd5d6+incompatible+1 moreno fix listed163
OSV records
GHSA-w73w-5m7g-f7qcGO-2020-0017
Also known as
SNYK-GOLANG-GITHUBCOMDGRIJALVAJWTGO-596515

Charts affected

175 by stars
ChartLatestAffected imagesRadar Score
spinnakerspinnakerVerified publisher2.2.132 of 4See more

spinnaker spinnaker 2.2.13

2 of the 4 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

6,836
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

3,096
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

2,081
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

16,506
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

6,596
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

2,869
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

2,821
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,480
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

8,484
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,510
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

3,109
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
stakkato95/twitter-service-users:0.1.1456049efee9a
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

6,132
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,429
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

13,459
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

7,552
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

4,086
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

3,174
harborwenerme1.19.22 of 8See more

harbor wenerme 1.19.2

2 of the 8 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
goharbor/registry-photon:v2.15.2c4ebef61ceb5
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

1,650
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

6,915
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
prom/prometheus:v2.16.0e4ca62c0d62f
github.com/dgrijalva/jwt-go@v0.0.0-20160705203006-01aeca54ebda
no fix listed

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

3,369
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-26160.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed

Open the chart page →

3,023

Container images carrying it

163 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/kubectl:latest2ad610626658
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
6
prom/prometheus:v2.13.10a8caa2e9f19
github.com/dgrijalva/jwt-go@v0.0.0-20160705203006-01aeca54ebda
no fix listed
5
alfhou/hammond:v0.0.24c85dc0293aa1
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
3
argoproj/argocd:v1.8.1830e86cacefd
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
3
dgraph/dgraph:v21.12.03b55ea83fffe
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
3
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
3
goharbor/registry-photon:v2.15.2c4ebef61ceb5
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
3
prom/prometheus:v2.19.0bfad037f95e5
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
3
datawire/aes:1.14.48588eafe6862
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
2
grafana/loki:1.5.0922b3f412fdd
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
2
grafana/promtail:1.5.046e88d390cd6
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
2
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
2
prom/prometheus:v2.17.242d2395cd719
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
2
prom/prometheus:v2.21.0d43417c260e5
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
2
statping/statping:v0.90.74e874da513a5c
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
2
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
2
alex6021710/ai-scale-auth:latest6c7a47e470c3
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
alpine/k8s:1.18.16a41efe02a041
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
apache/apisix-dashboard:2.9.0c010ea7d1694
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
github.com/dgrijalva/jwt-go@v3.2.1-0.20200107013213-dc14462fd587+incompatible
no fix listed
1
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
github.com/dgrijalva/jwt-go@v3.2.1-0.20200107013213-dc14462fd587+incompatible
no fix listed
1
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
github.com/dgrijalva/jwt-go@v3.2.1-0.20200107013213-dc14462fd587+incompatible
no fix listed
1
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
github.com/dgrijalva/jwt-go@v3.2.1-0.20200107013213-dc14462fd587+incompatible
no fix listed
1
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
github.com/dgrijalva/jwt-go@v3.2.1-0.20200107013213-dc14462fd587+incompatible
no fix listed
1
conduction/agendaservice-php:latest9cfeeb6c7c20
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
conduction/balance-registration-php:devc36094a41369
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
conduction/betaalservice-php:latestece1ab544c57
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
conduction/cgrc-php:dev25415534d245
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
conduction/checkin-component-php:dev3423845692c1
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
conduction/conduction-ui-php:dev2744565516e8
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
conduction/docparser-php:devb6f95c8ead7d
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
conduction/kvk-php:dev8f177f9f8a7b
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
conduction/pan-php:dev24f03c57568f
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
containous/maesh:v1.3.2587162516502
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
coredns/coredns:1.7.073ca82b4ce82
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
craftypath/sops-operator:v0.8.0402a0024c732
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
datadog/operator:0.3.117f08a860090
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
datamate/seafile-professional:11.0.202dd66b722464
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
datawire/aes:1.13.62beb65062c8b
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
devspacecloud/manager:0.3.349c397413f7b
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1
drumsergio/duplicacy-container:0.1.0dd3ee9703969
github.com/dgrijalva/jwt-go@v3.2.0+incompatible
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.