StackRadar

CVE-2022-27664

High

Advisory

Published 7 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.033
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,336
of 17,787 indexed, latest versions
Container images
1,465
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/net/http2 Denial of Service vulnerability

Carried by container images the latest versions of 1,336 of 17,787 indexed charts deploy, on 1,465 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+156 more0.0.0-20220906165146-f3363e06e74c1,043
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+78 more1.18.61,362
OSV records
GHSA-69cg-p879-7622GO-2022-0969
Also known as
BIT-golang-2022-27664

Charts affected

1,336 by stars
ChartLatestAffected imagesRadar Score
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
stdlib@go1.18.2
1.18.6

Open the chart page →

17,946
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

10,731
dltbrokerassist-iot-distributed-broker0.2.04 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

4 of the 9 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20220906165146-f3363e06e74c
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20220906165146-f3363e06e74c
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20220906165146-f3363e06e74c

Open the chart page →

77,821
dltloggingassist-iot-logging-auditing0.2.04 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

4 of the 9 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20220906165146-f3363e06e74c
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20220906165146-f3363e06e74c
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.0.0-20220906165146-f3363e06e74c

Open the chart page →

77,802
deployautoml0.1.01 of 3See more

deploy automl 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.18.6

Open the chart page →

2,947
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
stdlib@go1.17.5
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,298
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.16.2
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

3,391
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.18.1
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

3,729
prismav1o-chartsVerified publisher0.3.11 of 1See more

prism av1o-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.18.6

Open the chart page →

1,276
generic-appb3oVerified publisher0.1.61 of 1See more

generic-app b3o 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.18.6

Open the chart page →

1,279
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
stdlib@go1.13.10
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,814
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.8
0.0.0-20220906165146-f3363e06e74c
1.18.6
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.17.5
0.0.0-20220906165146-f3363e06e74c
1.18.6
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.17.8
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

7,807
livekit-serverbeeinventor1.0.01 of 2See more

livekit-server beeinventor 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.10
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,602
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

1,595
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

7,830
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,663
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.2
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

3,509
passbolt-hachristianhuthVerified publisher6.0.11 of 4See more

passbolt-ha christianhuth 6.0.1

1 of the 4 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.18.6

Open the chart page →

10,873
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
0.0.0-20220906165146-f3363e06e74c
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
0.0.0-20220906165146-f3363e06e74c

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.18.6
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.2
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,256
cnpg-sandboxcloudnative-pgVerified publisher0.6.12 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

2 of the 6 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.6
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

7,583
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.18.6

Open the chart page →

2,713
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.18.6

Open the chart page →

1,579
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.18.6

Open the chart page →

10,076
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

7,303
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

6,473
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.18.6

Open the chart page →

3,026
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.0.0-20220906165146-f3363e06e74c
1.18.6
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.4
0.0.0-20220906165146-f3363e06e74c
1.18.6
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.0.0-20220906165146-f3363e06e74c
1.18.6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.0.0-20220906165146-f3363e06e74c
1.18.6
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.0.0-20220906165146-f3363e06e74c
1.18.6
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

15,891
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.15
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.11
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,570
dregsydeliveryheroVerified publisher0.1.51 of 1See more

dregsy deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,969
gripmockdeliveryheroVerified publisher1.1.31 of 1See more

gripmock deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
stdlib@go1.14.6
1.18.6

Open the chart page →

2,793
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

7,987
kube-bench-metricsdevopstalesVerified publisher0.1.01 of 1See more

kube-bench-metrics devopstales 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.18.6

Open the chart page →

2,111
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.22.48be660470961
stdlib@go1.17.3
1.18.6

Open the chart page →

9,239
permission-managerdevopstalesVerified publisher1.8.01 of 1See more

permission-manager devopstales 1.8.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,266
dnsmasqdevplayer0Verified publisher0.1.51 of 2See more

dnsmasq devplayer0 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

3,392
whoamidevplayer0Verified publisher0.1.21 of 1See more

whoami devplayer0 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
traefik/whoami:v1.6.12c52bb2c8480
stdlib@go1.15.6
1.18.6

Open the chart page →

1,216
calicodevtron0.1.14 of 4See more

calico devtron 0.1.1

4 of the 4 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.18.6

Open the chart page →

10,073
clairdevtron0.1.141 of 2See more

clair devtron 0.1.14

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.6
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

6,237
discord-alertmanagerdevtron-labs0.10.01 of 1See more

discord-alertmanager devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.18.6

Open the chart page →

951
digispoof-interfacedigispoof-interface1.0.01 of 3See more

digispoof-interface digispoof-interface 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

7,779
matomodigitalist-open-cloud-matomo12.0.201 of 3See more

matomo digitalist-open-cloud-matomo 12.0.20

1 of the 3 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
hipages/php-fpm_exporter:2.2.09b5be9d3d955
stdlib@go1.17.10
1.18.6

Open the chart page →

3,539
dnation-pingdnationcloud0.1.94 of 5See more

dnation-ping dnationcloud 0.1.9

4 of the 5 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.5
0.0.0-20220906165146-f3363e06e74c
1.18.6
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.18.6
prom/blackbox-exporter:v0.18.01ffc3f109eb3
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.15.2
0.0.0-20220906165146-f3363e06e74c
1.18.6
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.2
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

10,454
thermitedollarshaveclubOfficialVerified publisher0.1.171 of 1See more

thermite dollarshaveclub 0.1.17

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
dollarshaveclub/thermite:0.0.31663cbf25fcfe
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.1
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,732
archerydoubanVerified publisher0.4.31 of 6See more

archery douban 0.4.3

1 of the 6 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
hhyo/archery:v1.9.11aa41843419e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.6
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

5,854
karmadoubanVerified publisher1.9.21 of 1See more

karma douban 1.9.2

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/prymitive/karma:v0.85d06892218680
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.3
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,017
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.0.0-20220906165146-f3363e06e74c

Open the chart page →

18,402
nydus-snapshotterdragonflyVerified publisher0.0.101 of 2See more

nydus-snapshotter dragonfly 0.0.10

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.0.0-20220906165146-f3363e06e74c

Open the chart page →

3,658

Container images carrying it

1,465 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
stdlib@go1.19
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
stdlib@go1.18.3
1.18.6
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.18.1
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.18.3
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/net@v0.0.0-20220121210141-e204ce36a2ba
stdlib@go1.17.6
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
stdlib@go1.17.8
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.18.6
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
stdlib@go1.17.1
1.18.6
1
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.0.0-20220906165146-f3363e06e74c
1
ghcr.io/jlclx/runtimeclass-controller:latestb3a87f92a963
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/k10app/businit:latest94c9a3e799c2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.0.0-20220906165146-f3363e06e74c
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
stdlib@go1.18.4
1.18.6
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
stdlib@go1.16.8
1.18.6
1
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.18.6
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
stdlib@go1.15
1.18.6
1
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.4
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/k8s-at-home/gateway-admision-controller:v3.5.0175512bb3f61
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.3
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
stdlib@go1.15
1.18.6
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
stdlib@go1.18.3
1.18.6
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
stdlib@go1.16.7
1.18.6
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.18.6
1
ghcr.io/k8s-at-home/nullserv:v1.3.00792c7e6d814
stdlib@go1.16.5
1.18.6
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
stdlib@go1.18.4
1.18.6
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
stdlib@go1.15
1.18.6
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
stdlib@go1.18.4
1.18.6
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.18.6
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.18.6
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
stdlib@go1.18.4
1.18.6
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.18.6
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.18.6
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.18.6
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.18.6
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
stdlib@go1.18.4
1.18.6
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.18.6
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.18.6
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.18.6
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.13.10
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
stdlib@go1.15.2
1.18.6
1
ghcr.io/kiaedev/kiae:latestebd03028ff6a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
0.0.0-20220906165146-f3363e06e74c
1
ghcr.io/kore3lab/kore-board.backend:v0.5.5455f6e7a26fd
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.0.0-20220906165146-f3363e06e74c
1
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.0.0-20220906165146-f3363e06e74c
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.0.0-20220906165146-f3363e06e74c
1
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.0.0-20220906165146-f3363e06e74c
1
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15.14
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.15.14
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.14
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.9
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.9
0.0.0-20220906165146-f3363e06e74c
1.18.6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.