StackRadar

CVE-2021-31525

Medium

Advisory

Published 24 May 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.037
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
644
of 17,781 indexed, latest versions
Container images
666
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

Carried by container images the latest versions of 644 of 17,781 indexed charts deploy, on 666 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+77 more0.0.0-20210428140749-89ef3d95e781536
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+41 more1.15.12519
OSV records
GHSA-h86h-8ppg-mxmhGO-2022-0236
Also known as
BIT-golang-2021-31525

Charts affected

644 by stars
ChartLatestAffected imagesRadar Score
postgres-backuppostgres-backup0.3.01 of 2See more

postgres-backup postgres-backup 0.3.0

1 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
nerzhul/mc-arm64:2020.10.034215df511f31
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.2
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

5,462
rethinkdbpozetron1.1.91 of 1See more

rethinkdb pozetron 1.1.9

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

2,912
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.15.12
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.15.12
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.0.0-20210428140749-89ef3d95e781
1.15.12
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.0.0-20210428140749-89ef3d95e781
1.15.12
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

9,939
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.14.2
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

23,964
rke2-canalrke2-charts3.13.32 of 2See more

rke2-canal rke2-charts 3.13.3

2 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.36d2cd61a338b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.0.0-20210428140749-89ef3d95e781
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

6,996
hcloud-fip-controllerrlex0.2.51 of 1See more

hcloud-fip-controller rlex 0.2.5

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.15.3
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,962
prometheus-webhook-dingtalkrlex0.0.31 of 1See more

prometheus-webhook-dingtalk rlex 0.0.3

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.15.12

Open the chart page →

1,852
scienceboxsciencebox0.0.71 of 17See more

sciencebox sciencebox 0.0.7

1 of the 17 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

6,587
external-secrets-operatorslamdev0.0.151 of 1See more

external-secrets-operator slamdev 0.0.15

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
slamdev/external-secrets-operator:0.0.8855f6625dda4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,301
gcp-quota-exportersoftonic2.0.21 of 1See more

gcp-quota-exporter softonic 2.0.2

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.13.12
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,637
go-ratelimitsoftonic1.0.72 of 3See more

go-ratelimit softonic 1.0.7

2 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14
0.0.0-20210428140749-89ef3d95e781
1.15.12
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.15.12

Open the chart page →

5,098
node-policy-webhooksoftonic0.1.101 of 1See more

node-policy-webhook softonic 0.1.10

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
softonic/node-policy-webhook:0.1.2ab6098c04a53
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.6
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,591
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.15.12

Open the chart page →

2,307
gitwebhookproxystakaterVerified publisher0.2.791 of 1See more

gitwebhookproxy stakater 0.2.79

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
stakater/gitwebhookproxy:v0.2.79c1226e5270cd
stdlib@go1.13.1
1.15.12

Open the chart page →

1,503
statpingstatping0.1.141 of 1See more

statping statping 0.1.14

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.13
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

3,371
hlf-k8ssubstraVerified publisher10.2.43 of 7See more

hlf-k8s substra 10.2.4

3 of the 7 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.0f270dfeee91d
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.7
0.0.0-20210428140749-89ef3d95e781
1.15.12
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.15.7
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

12,006
Grafanasurajwarbhe-grafana0.1.01 of 1See more

Grafana surajwarbhe-grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
surajwarbhe/grafana:v185248611e9f1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,597
terraform-controllerterraform-controller0.0.201 of 1See more

terraform-controller terraform-controller 0.0.20

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
absaoss/terraform-controller:v0.0.20ad538a1285a0
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.14.8
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

3,538
spa-reloadertoucanVerified publisher0.1.01 of 1See more

spa-reloader toucan 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,245
atlantistrozz3.12.111 of 1See more

atlantis trozz 3.12.11

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.16.145fbaf7e207c
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.14.7
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

5,280
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,303
vearchvearch3.3.41 of 4See more

vearch vearch 3.3.4

1 of the 4 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

5,008
vultr-ccmvultrVerified publisher1.3.01 of 1See more

vultr-ccm vultr 1.3.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

3,034
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

8,079
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,871
waardepapieren-registerwaardepapieren-register1.1.01 of 4See more

waardepapieren-register waardepapieren-register 1.1.0

1 of the 4 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,429
frpswenerme1.0.11 of 1See more

frps wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
wener/frps:v0.37.05c92cc9e8597
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

3,359
kubemodwiremindVerified publisher0.1.51 of 2See more

kubemod wiremind 0.1.5

1 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.13.0cadca39288ad
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.14.7
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

3,030
pi-hole-exporterwyrihaximusnetVerified publisher0.1.31 of 1See more

pi-hole-exporter wyrihaximusnet 0.1.3

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ekofr/pihole-exporter:0.0.109fdad6f352e0
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.7
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

1,809
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,447
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,209
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.15
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,115
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.15.12

Open the chart page →

2,239
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,488
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,730
capi-ops-managerappscodeVerified publisher2024.8.141 of 2See more

capi-ops-manager appscode 2024.8.14

1 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

3,416
grafanaappscodeVerified publisher2026.9.111 of 1See more

grafana appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

2,333
statefulsetappscodeVerified publisher0.0.11 of 3See more

statefulset appscode 0.0.1

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

2,732
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.14.15
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

5,202
dltkvassist-iot-data-integrity-verification0.2.04 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

4 of the 9 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.0.0-20210428140749-89ef3d95e781
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.04 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

4 of the 9 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.0.0-20210428140749-89ef3d95e781
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

77,706
performanceandusagediagnosisassist-iot-pud1.0.01 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

1 of the 7 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.15.12

Open the chart page →

8,556
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.13
1.15.12
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.15.12

Open the chart page →

45,363
sequencerastria4.0.01 of 3See more

sequencer astria 4.0.0

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
0.0.0-20210428140749-89ef3d95e781

Open the chart page →

6,298
hcloud-csi-driveratem181.5.12 of 6See more

hcloud-csi-driver atem18 1.5.1

2 of the 6 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.3
0.0.0-20210428140749-89ef3d95e781
1.15.12
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

6,491
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

7,561
okd-webhookav1o-chartsVerified publisher0.1.01 of 1See more

okd-webhook av1o-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

1,727
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,939
aws-sigv4-proxy-admission-controlleraws0.1.21 of 1See more

aws-sigv4-proxy-admission-controller aws 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.3
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

2,139
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2021-31525.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.0.0-20210428140749-89ef3d95e781
1.15.12

Open the chart page →

5,521

Container images carrying it

666 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.15.8
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
dnsforge/xteve:latest4d9a685c8c28
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.16.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
dollarshaveclub/furan2:master14a257836529
golang.org/x/net@v0.0.0-20201002202402-0a1ea396d57c
0.0.0-20210428140749-89ef3d95e781
1
douz/overlord:latestf2bc7fc068c1
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.5
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.0.0-20210428140749-89ef3d95e781
1
drone/kubernetes-secrets:latest206df2280ecf
golang.org/x/net@v0.0.0-20180811021610-c39426892332
stdlib@go1.13.15
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.15.12
1
duyetdev/applause-btn:latest25e59d223eaa
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.14.9
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
golang.org/x/net@v0.0.0-20200822124328-c89045814202
0.0.0-20210428140749-89ef3d95e781
1
ekofr/pihole-exporter:0.0.109fdad6f352e0
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.7
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.15.12
1
engrmth/bnkr:2.1.06d8464e6f0e8
stdlib@go1.15.8
1.15.12
1
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.13
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
envoyproxy/ratelimit:4d2efd61ede09a75a84c
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.15
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.0.0-20210428140749-89ef3d95e781
1
etejeda/butlerci:0.1.0737d58183abc
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
factly/dega-api:0.15.166fafc7b0a17
stdlib@go1.16.2
1.15.12
1
factly/dega-server:0.15.194d21479382e
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
factly/kavach-server:0.22.3be85ff1b9bd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
factly/vidcheck-server:0.12.087064eb0463c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.14.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
0.0.0-20210428140749-89ef3d95e781
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.16.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gabekangas/owncast:0.0.797461aedb580
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.15.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
garugaru/presto-exporter:cb666560e9e82d5ae36aef1e663c3d7f51cca9fc5201314c28f3
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.13
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
garugaru/presto-loadbalancer:v0.1.589d66d117029
stdlib@go1.15.2
1.15.12
1
gesellix/couchdb-prometheus-exporter:v27.2.05b891f1fc2b9
stdlib@go1.13.10
1.15.12
1
gitea/gitea:1.12.485416d6f65fe
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.8
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gitea/gitea:1.13.0d5ab14cd29af
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.15.5
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
golang.org/x/net@v0.0.0-20200222125558-5a598a2470a0
stdlib@go1.13.8
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gkarthics/container-resource-exporter:latest6799af333e8a
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.7
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gogs/gogs:0.12.30195b095d0b2
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.7
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gogs/gogs:0.12.1420d53bb7277
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.7
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.7
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.13.4
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gomods/athens:v0.11.0efb811df7844
golang.org/x/net@v0.0.0-20200222125558-5a598a2470a0
stdlib@go1.13.10
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gophish/gophish:0.12.18a57cd171999
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.15.2
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
grafana/agent:v0.20.0825c09373d27
stdlib@go1.16
1.15.12
1
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
grafana/grafana:7.5.609bb407e26ab
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.1
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
grafana/grafana:7.3.315b977f5207d
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
grafana/grafana:8.0.3696823fbc561
stdlib@go1.16.1
1.15.12
1
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.5
0.0.0-20210428140749-89ef3d95e781
1.15.12
1
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.0.0-20210428140749-89ef3d95e781
1.15.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.