StackRadar

CVE-2022-27664

High

Advisory

Published 7 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.033
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,325
of 17,781 indexed, latest versions
Container images
1,447
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/net/http2 Denial of Service vulnerability

Carried by container images the latest versions of 1,325 of 17,781 indexed charts deploy, on 1,447 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+155 more0.0.0-20220906165146-f3363e06e74c1,028
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+78 more1.18.61,346
OSV records
GHSA-69cg-p879-7622GO-2022-0969
Also known as
BIT-golang-2022-27664

Charts affected

1,325 by stars
ChartLatestAffected imagesRadar Score
nfs-subdir-external-provisionernfs-subdir-external-provisioner4.0.181 of 1See more

nfs-subdir-external-provisioner nfs-subdir-external-provisioner 4.0.18

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,743
nfs-server-provisionerkvaps1.8.01 of 1See more

nfs-server-provisioner kvaps 1.8.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,315
open-webuiopen-webui16.5.01 of 4See more

open-webui open-webui 16.5.0

1 of the 4 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.18.6

Open the chart page →

1,288
terraformhashicorpVerified publisher1.1.21 of 1See more

terraform hashicorp 1.1.2

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.0.0-20220906165146-f3363e06e74c

Open the chart page →

2,059
dagsterdagsterVerified publisher1.13.221 of 5See more

dagster dagster 1.13.22

1 of the 5 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.18.6

Open the chart page →

3,455
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.18.6

Open the chart page →

5,552
chaos-meshchaos-meshVerified publisher2.8.41 of 4See more

chaos-mesh chaos-mesh 2.8.4

1 of the 4 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.0.0-20220906165146-f3363e06e74c

Open the chart page →

6,342
vclusterloftVerified publisher0.0.0-ci.31 of 2See more

vcluster loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.0.0-20220906165146-f3363e06e74c

Open the chart page →

2,453
milvusmilvus4.0.313 of 5See more

milvus milvus 4.0.31

3 of the 5 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.2
0.0.0-20220906165146-f3363e06e74c
1.18.6
milvusdb/milvus:v2.2.13a3a55e1c1497
stdlib@go1.18.3
1.18.6
milvusdb/milvus-config-tool:v0.1.12212dfb61401
golang.org/x/net@v0.0.0-20220706163947-c90051bbdb60
stdlib@go1.16.15
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

32,259
nacosygqygq2Verified publisher2.1.102 of 4See more

nacos ygqygq2 2.1.10

2 of the 4 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.18.6
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.18.6

Open the chart page →

4,983
pulsarapache4.7.01 of 10See more

pulsar apache 4.7.0

1 of the 10 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

9,864
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,086
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,154
oncallgrafana1.16.56 of 12See more

oncall grafana 1.16.5

6 of the 12 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.0.0-20220906165146-f3363e06e74c
1.18.6
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.0.0-20220906165146-f3363e06e74c
1.18.6
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

16,251
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

11,384
zabbixcetic3.1.32 of 5See more

zabbix cetic 3.1.3

2 of the 5 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.1
0.0.0-20220906165146-f3363e06e74c
1.18.6
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
stdlib@go1.18.1
1.18.6

Open the chart page →

33,725
chatwootchatwootVerified publisher2.0.242 of 3See more

chatwoot chatwoot 2.0.24

2 of the 3 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.18.6
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
stdlib@go1.16.7
1.18.6

Open the chart page →

9,203
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,918
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.18.6

Open the chart page →

7,705
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.18.6

Open the chart page →

5,240
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.7
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,039
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

6,219
linkerd-jaegerlinkerd2Verified publisher30.12.112 of 4See more

linkerd-jaeger linkerd2 30.12.11

2 of the 4 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.6
0.0.0-20220906165146-f3363e06e74c
1.18.6
otel/opentelemetry-collector:0.59.0ee9da0b08d83
golang.org/x/net@v0.0.0-20220809184613-07c6da5e1ced
stdlib@go1.18.5
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,405
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
stdlib@go1.17.1
1.18.6

Open the chart page →

6,041
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

6,854
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

5,173
plane-cemakeplaneOfficialVerified publisher1.8.11 of 11See more

plane-ce makeplane 1.8.1

1 of the 11 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.18.6

Open the chart page →

4,854
zookeepercloudpirates-zookeeperVerified publisher0.13.111 of 1See more

zookeeper cloudpirates-zookeeper 0.13.11

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5cab8944a33a1
stdlib@go1.18.1
1.18.6

Open the chart page →

2,924
loki-simple-scalablegrafana1.8.112 of 3See more

loki-simple-scalable grafana 1.8.11

2 of the 3 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18
0.0.0-20220906165146-f3363e06e74c
1.18.6
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

6,470
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
stdlib@go1.17.1
1.18.6

Open the chart page →

3,004
kube-prometheuschoerodon9.3.14 of 7See more

kube-prometheus choerodon 9.3.1

4 of the 7 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.0.0-20220906165146-f3363e06e74c
1.18.6
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
stdlib@go1.13.11
0.0.0-20220906165146-f3363e06e74c
1.18.6
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
stdlib@go1.13.4
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.3
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

12,237
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

7,857
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.15
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,413
dex-k8s-authenticatorsagikazarmarkVerified publisher0.0.31 of 1See more

dex-k8s-authenticator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,791
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
stdlib@go1.18.2
1.18.6

Open the chart page →

3,012
kubeviewcowboysysopVerified publisher6.0.01 of 1See more

kubeview cowboysysop 6.0.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.2
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

1,513
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
stdlib@go1.18.3
1.18.6

Open the chart page →

4,556
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.18.6

Open the chart page →

4,577
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.18.6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

32,902
drone-runner-kubedroneVerified publisher0.1.101 of 1See more

drone-runner-kube drone 0.1.10

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,067
temporallemontechVerified publisher0.37.05 of 13See more

temporal lemontech 0.37.0

5 of the 13 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.0.0-20220906165146-f3363e06e74c
1.18.6
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.18.6
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.0.0-20220906165146-f3363e06e74c
1.18.6
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

14,893
netris-controllernetrisai2.8.23 of 14See more

netris-controller netrisai 2.8.2

3 of the 14 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.11
0.0.0-20220906165146-f3363e06e74c
1.18.6
netrisai/controller-web-session-generator:0.2.0a030a31289f4
stdlib@go1.14.15
1.18.6
netrisai/mongodb:4.4.4-debian-10-r095abfb776bb4
stdlib@go1.15.1
1.18.6

Open the chart page →

30,326
nfs-server-provisionernfs-ganesha-server-and-external-provisioner1.8.01 of 1See more

nfs-server-provisioner nfs-ganesha-server-and-external-provisioner 1.8.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,315
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.18.6

Open the chart page →

17,245
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.0.0-20220906165146-f3363e06e74c
1.18.6
platform9community/api-gateway:latest40a4970de568
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.0.0-20220906165146-f3363e06e74c
1.18.6
platform9community/customers-service:latest2089811e5cc6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.0.0-20220906165146-f3363e06e74c
1.18.6
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.11
0.0.0-20220906165146-f3363e06e74c
1.18.6
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

41,872
helm-exportersstarcher0.5.01 of 1See more

helm-exporter sstarcher 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
sstarcher/helm-exporter:0.5.011769d01ba35
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.6
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,154
passboltcnieg1.1.171 of 2See more

passbolt cnieg 1.1.17

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.18.6

Open the chart page →

3,543
dronecommunity-chartsVerified publisher0.1.51 of 2See more

drone community-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,728
uptime-kumaduyet0.1.71 of 1See more

uptime-kuma duyet 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

4,515
missing-container-metricsmissing-container-metrics0.1.11 of 1See more

missing-container-metrics missing-container-metrics 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-27664.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.0.0-20220906165146-f3363e06e74c
1.18.6

Open the chart page →

2,409

Container images carrying it

1,447 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
alex6021710/ai-scale-saver:latestf73e8d60fd03
golang.org/x/net@v0.0.0-20211105192438-b53810dc28af
stdlib@go1.17
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.18.6
1
almir/webhook:2.8.01698346f6077
stdlib@go1.14.7
1.18.6
1
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.15
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
alpine/git:2.36.366b210a97bc0
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.0.0-20220906165146-f3363e06e74c
1
alpine/k8s:1.22.600ac10bcb759
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.17.6
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
alpine/k8s:1.27.321b24e6bf801
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
alpine/k8s:1.18.16a41efe02a041
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.2
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.13.15
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
altinity/metrics-exporter:0.20.01a46d104406d
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.13.15
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.4
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
amazon/aws-fsx-csi-driver:latestc9b14856fd22
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.15.15
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.18.6
1
anchore/anchore-engine:v0.10.0bde9eedf639d
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.16.3
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
stdlib@go1.18.3
1.18.6
1
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.0.0-20220906165146-f3363e06e74c
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.18.6
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
stdlib@go1.18.2
1.18.6
1
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.18.6
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
stdlib@go1.16.3
1.18.6
1
anujarosha/hello-go:v1.0.1ed60e46870b6
stdlib@go1.18.3
1.18.6
1
apache/apisix-dashboard:2.9.0c010ea7d1694
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.15
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.13.8
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
apache/camel-k:1.10.43bb13d14f64a
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.9
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.3
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.0.0-20220906165146-f3363e06e74c
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
aquasec/kube-bench:v0.6.9c329d73fea58
stdlib@go1.19
1.18.6
1
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
aquasec/trivy:0.32.0973d0df16189
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.18.6
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
stdlib@go1.18.2
1.18.6
1
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.18.6
1
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.18.6
1
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.13
0.0.0-20220906165146-f3363e06e74c
1.18.6
1
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.0.0-20220906165146-f3363e06e74c
1
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.13
1.18.6
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.17.8
0.0.0-20220906165146-f3363e06e74c
1.18.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.