StackRadar

CVE-2021-31525

Medium

Advisory

Published 24 May 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.037
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
646
of 17,787 indexed, latest versions
Container images
668
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

Carried by container images the latest versions of 646 of 17,787 indexed charts deploy, on 668 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+77 more0.0.0-20210428140749-89ef3d95e781538
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+41 more1.15.12520
OSV records
GHSA-h86h-8ppg-mxmhGO-2022-0236
Also known as
BIT-golang-2021-31525

Charts affected

646 by stars
ChartLatestAffected imagesRadar Score
helm-controllerazureorkestra0.1.12 of 2See more

helm-controller azureorkestra 0.1.1

2 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.0.0-20210428140749-89ef3d95e781
1.15.12
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,705
keptn-addonsazureorkestra0.1.04 of 4See more

keptn-addons azureorkestra 0.1.0

4 of the 4 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
keptn/distributor:0.8.472e17527a4f9
stdlib@go1.16.2
1.15.12
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.13.7
0.0.0-20210428140749-89ef3d95e781
1.15.12
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
stdlib@go1.16.2
1.15.12

Open the chart page →

10,621
prometheusazureorkestra14.8.05 of 6See more

prometheus azureorkestra 14.8.0

5 of the 6 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.15.12
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.15.12
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.0.0-20210428140749-89ef3d95e781
1.15.12
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.8
0.0.0-20210428140749-89ef3d95e781
1.15.12
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.2
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

9,661
webserverazureorkestra1.0.01 of 1See more

webserver azureorkestra 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
nmalhotr/webserver:v1.0.03419361fb0dd
stdlib@go1.13.10
1.15.12

Open the chart page →

3,037
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

8,408
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,342
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.15.12

Open the chart page →

15,299
nfs-subdir-external-provisionerbook-k8sinfra-v24.0.181 of 1See more

nfs-subdir-external-provisioner book-k8sinfra-v2 4.0.18

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,745
butlercibutlerciVerified publisher0.1.01 of 1See more

butlerci butlerci 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,374
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

4,518
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

6,389
openldapccowleyVerified publisher2.0.41 of 3See more

openldap ccowley 2.0.4

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

6,219
openldap_exporterccowleyVerified publisher0.1.01 of 1See more

openldap_exporter ccowley 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
stdlib@go1.15.7
1.15.12

Open the chart page →

2,143
cert-manager-webhook-infoblox-wapicert-manager-webhook-infoblox-wapiVerified publisher1.5.21 of 1See more

cert-manager-webhook-infoblox-wapi cert-manager-webhook-infoblox-wapi 1.5.2

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

2,345
cert-utils-operatorcert-utils-operator1.3.121 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

1 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

7,776
clechaosnative0.2.71 of 6See more

cle chaosnative 0.2.7

1 of the 6 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

16,395
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

8,408
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,869
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.11
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,821
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

2,290
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

3,595
vcloud-csiclastixVerified publisher1.6.03 of 5See more

vcloud-csi clastix 1.6.0

3 of the 5 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.0.0-20210428140749-89ef3d95e781
1.15.12
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.0.0-20210428140749-89ef3d95e781
1.15.12
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,386
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

20,936
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.0.0-20210428140749-89ef3d95e781
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.0.0-20210428140749-89ef3d95e781
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.0.0-20210428140749-89ef3d95e781
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

18,040
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.3
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

25,152
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.15.1
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

6,696
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.15.1
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

6,921
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.15.12

Open the chart page →

2,814
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
robotshop/rs-mongodb:latest119b545823cd
stdlib@go1.16.3
1.15.12

Open the chart page →

29,594
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/net@v0.0.0-20201029055024-942e2f445f3c
stdlib@go1.15.8
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

3,136
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

16,117
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

14,285
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,853
d2-prometheus-exportercmacraeVerified publisher0.1.01 of 1See more

d2-prometheus-exporter cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
stdlib@go1.15
1.15.12

Open the chart page →

1,299
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

2,089
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,203
lgtmcmacraeVerified publisher0.1.01 of 1See more

lgtm cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
cmacrae/lgtm:0.1.0dec8d490fe40
golang.org/x/net@v0.0.0-20181108082009-03003ca0c849
stdlib@go1.14.1
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

1,909
door-agentcnoVerified publisher3.0.151 of 15See more

door-agent cno 3.0.15

1 of the 15 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.13
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

19,380
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,234
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,572
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

12,906
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,209
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

8,408
katibcowboysysopVerified publisher2.4.23 of 4See more

katib cowboysysop 2.4.2

3 of the 4 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
stdlib@go1.13.3
0.0.0-20210428140749-89ef3d95e781
1.15.12
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

6,542
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.14
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

3,830
mpi-operatorcowboysysopVerified publisher1.2.21 of 1See more

mpi-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

2,577
notebook-controllercowboysysopVerified publisher1.1.21 of 1See more

notebook-controller cowboysysop 1.1.2

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

2,582
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
stdlib@go1.13.1
1.15.12

Open the chart page →

5,489
training-operatorcowboysysopVerified publisher1.2.21 of 1See more

training-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.9
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,275
crossplane-controllerscrossplane0.12.01 of 1See more

crossplane-controllers crossplane 0.12.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
crossplane/crossplane:v0.12.066666e6963af
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,312

Container images carrying it

668 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.0.0-20210428140749-89ef3d95e781
1
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.15.7
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.4
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
mcr.microsoft.com/oss/kubernetes-csi/csi-node-driver-registrar:v2.0.1fc5d14e9f26f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.15.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
mcr.microsoft.com/oss/kubernetes-csi/livenessprobe:v2.2.0b7d82802cca8
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.6
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.0.0-20210428140749-89ef3d95e781
1
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r1-10-g1942553-2021.06.04.00.07-linux-amd64b32c99e7bc45
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.8
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.0.0-20210428140749-89ef3d95e781
1
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.9
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.0.0-20210428140749-89ef3d95e781
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.0.0-20210428140749-89ef3d95e781
1
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
stdlib@go1.15.7
1.15.12
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.15.1
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.3
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.16.3
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.0.0-20210428140749-89ef3d95e781
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
1
quay.io/evl.ms/pgbouncer-exporter:0.4.074f919b78494
stdlib@go1.14.4
1.15.12
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.15.1
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.6
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
1
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
1
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
1
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
1
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
1
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.1
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/kube-ops/loki:2.2.14fbd63194674
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.3
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/kube-ops/promtail:2.2.134de6387233b
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.3
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.3
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781
1
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.10
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.14.4
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781
1
quay.io/openshift/origin-cli:4.66722d5041b47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.0.0-20210428140749-89ef3d95e781
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.1
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
quay.io/opstree/druid-exporter:v0.83f6d9885cfe2
stdlib@go1.14.6
1.15.12
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.