StackRadar

CVE-2022-29526

Medium

Advisory

Published 24 Jun 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.030
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,076
of 17,781 indexed, latest versions
Container images
1,173
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

Carried by container images the latest versions of 1,076 of 17,781 indexed charts deploy, on 1,173 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+192 more0.0.0-20220412211240-33da011f77ad1,033
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+69 more1.17.101,019
OSV records
GHSA-p782-xgp4-8hr8GO-2022-0493
Also known as
BIT-golang-2022-29526

Charts affected

1,076 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/sys@v0.0.0-20200812155832-6a926be9bd1d
stdlib@go1.15.1
0.0.0-20220412211240-33da011f77ad
1.17.10
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
stdlib@go1.15.3
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/sys@v0.0.0-20201015000850-e3ed0017c211
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/sys@v0.0.0-20200602225109-6fdc65e7d980
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

12,125
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/sys@v0.0.0-20190801041406-cbf593c0f2f3
stdlib@go1.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,730
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
stdlib@go1.18.1
1.17.10

Open the chart page →

3,427
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/sys@v0.0.0-20200331124033-c3d80250170d
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

12,502
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/sys@v0.0.0-20220207234003-57398862261d
0.0.0-20220412211240-33da011f77ad

Open the chart page →

15,477
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,136
traefik-meshtraefikOfficialVerified publisher4.1.12 of 7See more

traefik-mesh traefik 4.1.1

2 of the 7 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/sys@v0.0.0-20200217220822-9197077df867
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10
library/traefik:v2.57d5a6ae66572
golang.org/x/sys@v0.0.0-20210817190340-bfb29a6856f2
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

9,257
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
stdlib@go1.18.1
1.17.10

Open the chart page →

10,315
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.17.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,085
wharf-helmwharf-helmOfficialVerified publisher3.2.61 of 5See more

wharf-helm wharf-helm 3.2.6

1 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/sys@v0.0.0-20220330033206-e17cdc41300f
stdlib@go1.18.1
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

10,032
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.13.8
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,714
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.17.10

Open the chart page →

12,046
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,995
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

8,341
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.0.0-20220412211240-33da011f77ad

Open the chart page →

3,119
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/sys@v0.0.0-20220307203707-22a9840ba4d7
0.0.0-20220412211240-33da011f77ad

Open the chart page →

2,173
upcloud-csiankra-chartsVerified publisher0.4.06 of 8See more

upcloud-csi ankra-charts 0.4.0

6 of the 8 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

14,917
anteonanteonVerified publisher2.6.41 of 13See more

anteon anteon 2.6.4

1 of the 13 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ddosify/selfhosted_hammer:2.0.0181965edb12e
stdlib@go1.18.1
1.17.10

Open the chart page →

22,202
stash-enterpriseappscodeVerified publisher0.42.01 of 4See more

stash-enterprise appscode 0.42.0

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.16.9
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,620
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

5,222
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
stdlib@go1.14.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,819
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/sys@v0.0.0-20200625212154-ddb9806d33ae
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

10,730
dltbrokerassist-iot-distributed-broker0.2.04 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

4 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.04 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

4 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad

Open the chart page →

77,687
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,292
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,391
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.18.1
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,723
prismav1o-chartsVerified publisher0.3.11 of 1See more

prism av1o-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

1,276
generic-appb3oVerified publisher0.1.61 of 1See more

generic-app b3o 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.17.10

Open the chart page →

1,279
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/sys@v0.0.0-20191210023423-ac6580df4449
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,814
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,807
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,830
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/sys@v0.0.0-20201009025420-dfb3f7c4e634
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,663
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/sys@v0.0.0-20200814200057-3d37ad5750ed
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,509
passbolt-hachristianhuthVerified publisher6.0.11 of 4See more

passbolt-ha christianhuth 6.0.1

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

10,817
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
0.0.0-20220412211240-33da011f77ad
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
0.0.0-20220412211240-33da011f77ad

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
golang.org/x/sys@v0.0.0-20200620081246-981b61492c35
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/sys@v0.0.0-20200821140526-fda516888d29
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,256
cnpg-sandboxcloudnative-pgVerified publisher0.6.12 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

2 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/sys@v0.0.0-20210908233432-aa78b53d3365
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,583
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,713
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.17.10

Open the chart page →

1,579
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,303
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/sys@v0.0.0-20210220050731-9a76102bfb43
stdlib@go1.16.5
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,473
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
golang.org/x/sys@v0.0.0-20200323222414-85ca7c5b95cd
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,026
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/sys@v0.0.0-20191010194322-b09406accb47
stdlib@go1.13.1
0.0.0-20220412211240-33da011f77ad
1.17.10
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.0.0-20220412211240-33da011f77ad
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

15,891
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.15.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/sys@v0.0.0-20200824131525-c12d262b63d8
stdlib@go1.13.11
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,568
gripmockdeliveryheroVerified publisher1.1.31 of 1See more

gripmock deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.14.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,793
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/sys@v0.0.0-20190826190057-c7b8b68b1456
stdlib@go1.13.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/sys@v0.0.0-20190531175056-4c3a928424d2
stdlib@go1.13.5
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,984
kube-bench-metricsdevopstalesVerified publisher0.1.01 of 1See more

kube-bench-metrics devopstales 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
elastisys/kube-bench-metrics:0.1.6509b94f1da55
golang.org/x/sys@v0.0.0-20190621203818-d432491b9138
stdlib@go1.15.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,111

Container images carrying it

1,173 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
inbucket/inbucket:3.0.01f10a0efea69
stdlib@go1.17.1
1.17.10
1
inseefrlab/shelly:cloudshell31f04ca7436b
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
stdlib@go1.15.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
intel/intel-gpu-plugin:0.20.0143f0a45e174
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.15.10
0.0.0-20220412211240-33da011f77ad
1.17.10
1
intel/multimodal-data-visualization:3.03426deb77337
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
invisibl/gravity-init:v1.0.91a970f84178b
golang.org/x/sys@v0.0.0-20220408201424-a24fb2fb8a0f
0.0.0-20220412211240-33da011f77ad
1
invisibl/identity-manager:1.0.01029f4fe20eb
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
1
invisibl/identity-manager-demo:v1.0.0cf5400cb935a
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
1
iofog/router:2.0.17260cf861479
stdlib@go1.15
1.17.10
1
iomesh/csi-driver:v2.7.25d3f9bf9240b
golang.org/x/sys@v0.0.0-20220111092808-5a964db01320
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
iomesh/node-disk-manager:1.8.0002c4b92fd34
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
iomesh/node-disk-manager:1.8.0-2292ad270082e
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
iomesh/node-disk-operator:1.8.0f6c76380db34
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
golang.org/x/sys@v0.0.0-20200625212154-ddb9806d33ae
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10
1
iotaledger/goshimmer:v0.8.6b02a8f77474f
golang.org/x/sys@v0.0.0-20210909193231-528a39cd75f3
stdlib@go1.17.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
istio/install-cni:1.10.32232f365aed6
golang.org/x/sys@v0.0.0-20210320140829-1e4c9ba3b0c4
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
istio/operator:1.10.3655eefa11c84
golang.org/x/sys@v0.0.0-20210320140829-1e4c9ba3b0c4
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
istio/operator:1.12.06cfce8a071b9
golang.org/x/sys@v0.0.0-20211020174200-9d6173849985
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/sys@v0.0.0-20210320140829-1e4c9ba3b0c4
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
istio/pilot:1.10.3e7e110a421c2
golang.org/x/sys@v0.0.0-20210320140829-1e4c9ba3b0c4
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
stdlib@go1.15.13
0.0.0-20220412211240-33da011f77ad
1.17.10
1
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/sys@v0.0.0-20210320140829-1e4c9ba3b0c4
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/sys@v0.0.0-20210426230700-d19ff857e887
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.17.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
jacobalberty/unifi:v7.1.664a3616625dda
stdlib@go1.18
1.17.10
1
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/sys@v0.0.0-20210823070655-63515b42dcdf
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
jaegertracing/all-in-one:1.22.0ca6b73330616
golang.org/x/sys@v0.0.0-20210119212857-b64e53b001e4
stdlib@go1.15.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/sys@v0.0.0-20200217220822-9197077df867
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
jfwenisch/alpine-tor:latest9e6c229f953c
golang.org/x/sys@v0.0.0-20190329044733-9eb1bfa1ce65
stdlib@go1.14.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
jkremser/log2rbac:v0.0.5e35cf56ef183
stdlib@go1.17.6
1.17.10
1
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/sys@v0.0.0-20191028164358-195ce5e7f934
stdlib@go1.13.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
stdlib@go1.14.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.0.0-20220412211240-33da011f77ad
1
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/sys@v0.0.0-20200420163511-1957bb5e6d1f
stdlib@go1.13.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
keptn/distributor:0.8.472e17527a4f9
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/sys@v0.0.0-20210603125802-9665404d3644
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
golang.org/x/sys@v0.0.0-20190312061237-fead79001313
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
kfirfer/scripts:0.0.2481e5c4e5d70e
golang.org/x/sys@v0.0.0-20210809222454-d867a43fc93e
0.0.0-20220412211240-33da011f77ad
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/sys@v0.0.0-20200905004654-be1d3432aa8f
stdlib@go1.14.14
0.0.0-20220412211240-33da011f77ad
1.17.10
1
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.15.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/sys@v0.0.0-20220328115105-d36c6a25d886
stdlib@go1.18
0.0.0-20220412211240-33da011f77ad
1.17.10
1
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
golang.org/x/sys@v0.0.0-20211210111614-af8b64212486
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.0.0-20220412211240-33da011f77ad
1
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/sys@v0.0.0-20211124211545-fe61309f8881
stdlib@go1.17.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
kubebb/cert-manager-controller:v1.8.020509de4b399
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.18
0.0.0-20220412211240-33da011f77ad
1.17.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.