StackRadar

CVE-2022-29526

Medium

Advisory

Published 24 Jun 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.030
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,076
of 17,787 indexed, latest versions
Container images
1,173
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

Carried by container images the latest versions of 1,076 of 17,787 indexed charts deploy, on 1,173 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+192 more0.0.0-20220412211240-33da011f77ad1,033
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+69 more1.17.101,019
OSV records
GHSA-p782-xgp4-8hr8GO-2022-0493
Also known as
BIT-golang-2022-29526

Charts affected

1,076 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/sys@v0.0.0-20200812155832-6a926be9bd1d
stdlib@go1.15.1
0.0.0-20220412211240-33da011f77ad
1.17.10
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
stdlib@go1.15.3
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/sys@v0.0.0-20201015000850-e3ed0017c211
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/sys@v0.0.0-20200602225109-6fdc65e7d980
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

12,125
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/sys@v0.0.0-20190801041406-cbf593c0f2f3
stdlib@go1.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,730
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
stdlib@go1.18.1
1.17.10

Open the chart page →

3,427
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/sys@v0.0.0-20200331124033-c3d80250170d
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

12,502
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/sys@v0.0.0-20220207234003-57398862261d
0.0.0-20220412211240-33da011f77ad

Open the chart page →

15,477
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,136
traefik-meshtraefikOfficialVerified publisher4.1.12 of 7See more

traefik-mesh traefik 4.1.1

2 of the 7 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/sys@v0.0.0-20200217220822-9197077df867
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10
library/traefik:v2.57d5a6ae66572
golang.org/x/sys@v0.0.0-20210817190340-bfb29a6856f2
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

9,257
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
stdlib@go1.18.1
1.17.10

Open the chart page →

10,315
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.17.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,085
wharf-helmwharf-helmOfficialVerified publisher3.2.61 of 5See more

wharf-helm wharf-helm 3.2.6

1 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/sys@v0.0.0-20220330033206-e17cdc41300f
stdlib@go1.18.1
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

10,032
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.13.8
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,714
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.17.10

Open the chart page →

12,046
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,995
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

8,341
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.0.0-20220412211240-33da011f77ad

Open the chart page →

3,119
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/sys@v0.0.0-20220307203707-22a9840ba4d7
0.0.0-20220412211240-33da011f77ad

Open the chart page →

2,173
upcloud-csiankra-chartsVerified publisher0.4.06 of 8See more

upcloud-csi ankra-charts 0.4.0

6 of the 8 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

14,917
anteonanteonVerified publisher2.6.41 of 13See more

anteon anteon 2.6.4

1 of the 13 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ddosify/selfhosted_hammer:2.0.0181965edb12e
stdlib@go1.18.1
1.17.10

Open the chart page →

22,202
stash-enterpriseappscodeVerified publisher0.42.01 of 4See more

stash-enterprise appscode 0.42.0

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.16.9
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,620
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

5,222
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
stdlib@go1.14.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,819
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/sys@v0.0.0-20200625212154-ddb9806d33ae
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

10,730
dltbrokerassist-iot-distributed-broker0.2.04 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

4 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.04 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

4 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad

Open the chart page →

77,687
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,292
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,391
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.18.1
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,723
prismav1o-chartsVerified publisher0.3.11 of 1See more

prism av1o-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

1,276
generic-appb3oVerified publisher0.1.61 of 1See more

generic-app b3o 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.17.10

Open the chart page →

1,279
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/sys@v0.0.0-20191210023423-ac6580df4449
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,814
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,807
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,830
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/sys@v0.0.0-20201009025420-dfb3f7c4e634
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,663
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/sys@v0.0.0-20200814200057-3d37ad5750ed
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,509
passbolt-hachristianhuthVerified publisher6.0.11 of 4See more

passbolt-ha christianhuth 6.0.1

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

10,817
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
0.0.0-20220412211240-33da011f77ad
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
0.0.0-20220412211240-33da011f77ad

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
golang.org/x/sys@v0.0.0-20200620081246-981b61492c35
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/sys@v0.0.0-20200821140526-fda516888d29
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,256
cnpg-sandboxcloudnative-pgVerified publisher0.6.12 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

2 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/sys@v0.0.0-20210908233432-aa78b53d3365
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,583
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,713
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.17.10

Open the chart page →

1,579
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,303
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/sys@v0.0.0-20210220050731-9a76102bfb43
stdlib@go1.16.5
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,473
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
golang.org/x/sys@v0.0.0-20200323222414-85ca7c5b95cd
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,026
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/sys@v0.0.0-20191010194322-b09406accb47
stdlib@go1.13.1
0.0.0-20220412211240-33da011f77ad
1.17.10
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.0.0-20220412211240-33da011f77ad
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

15,891
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.15.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/sys@v0.0.0-20200824131525-c12d262b63d8
stdlib@go1.13.11
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,568
gripmockdeliveryheroVerified publisher1.1.31 of 1See more

gripmock deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.14.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,793
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/sys@v0.0.0-20190826190057-c7b8b68b1456
stdlib@go1.13.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/sys@v0.0.0-20190531175056-4c3a928424d2
stdlib@go1.13.5
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,984
kube-bench-metricsdevopstalesVerified publisher0.1.01 of 1See more

kube-bench-metrics devopstales 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
elastisys/kube-bench-metrics:0.1.6509b94f1da55
golang.org/x/sys@v0.0.0-20190621203818-d432491b9138
stdlib@go1.15.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,111

Container images carrying it

1,173 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
0.0.0-20220412211240-33da011f77ad
1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
0.0.0-20220412211240-33da011f77ad
1
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
0.0.0-20220412211240-33da011f77ad
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/sys@v0.0.0-20211116061358-0a5406a5449c
0.0.0-20220412211240-33da011f77ad
1
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
stdlib@go1.16.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
golang.org/x/sys@v0.0.0-20210309074719-68d13333faf2
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
golang.org/x/sys@v0.0.0-20210309074719-68d13333faf2
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/sys@v0.0.0-20210820121016-41cdb8703e55
stdlib@go1.17.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/sys@v0.0.0-20210423185535-09eb48e85fd7
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
redislabs/redisearch:2.4.1433561794c5c8
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
reportportal/migrations:5.7.0da5d8e1395fe
golang.org/x/sys@v0.0.0-20190426135247-a129542de9ae
stdlib@go1.13.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
reportportal/service-index:5.0.112b27a2d7a87d
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
stdlib@go1.17.1
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ribbybibby/s3-exporter:v0.5.0998184c51a00
golang.org/x/sys@v0.0.0-20201018121011-98379d014ca7
stdlib@go1.15.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
rimusz/security-sample-app:0.2.0b9a178ca76ef
stdlib@go1.14.4
1.17.10
1
robjuz/postgresql-nominatim:latest805c7bab76df
golang.org/x/sys@v0.0.0-20210426230700-d19ff857e887
stdlib@go1.16.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
robotshop/rs-dispatch:latestde81f1d07b02
stdlib@go1.17
1.17.10
1
robotshop/rs-mongodb:latest119b545823cd
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
stdlib@go1.16.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
rogerrum/alertmanager-discord:1.0.3827593369625
stdlib@go1.17.4
1.17.10
1
rookout/k8s-operator:latest0d083f3ef1a7
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
stdlib@go1.15.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
runatlantis/atlantis:v0.16.145fbaf7e207c
golang.org/x/sys@v0.0.0-20200202164722-d101bd2416d5
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
samarthya/spinnaker:v1.0ef06d81036af
golang.org/x/sys@v0.0.0-20211103235746-7861aae1554b
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
seafileltd/seafile-mc:10.0.170628f29c663
golang.org/x/sys@v0.0.0-20200323222414-85ca7c5b95cd
0.0.0-20220412211240-33da011f77ad
1
seafileltd/seafile-mc:9.0.97ac833196f60
golang.org/x/sys@v0.0.0-20200323222414-85ca7c5b95cd
0.0.0-20220412211240-33da011f77ad
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
golang.org/x/sys@v0.0.0-20211019181941-9d821ace8654
0.0.0-20220412211240-33da011f77ad
1
sentriz/gonic:v0.13.1a74012a6adf3
stdlib@go1.16.4
1.17.10
1
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
golang.org/x/sys@v0.0.0-20210330210617-4fbd30eecc44
stdlib@go1.15.12
0.0.0-20220412211240-33da011f77ad
1.17.10
1
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.17.10
1
signoz/alertmanager:0.5.07bc7de2e33c2
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.14
0.0.0-20220412211240-33da011f77ad
1.17.10
1
sikalabs/slu:v0.34.0fdc0c6711add
golang.org/x/sys@v0.0.0-20220207234003-57398862261d
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
simonschneider/traefik-jwt-decode:latestd674ac370f80
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.0.0-20220412211240-33da011f77ad
1
simpleidserver/faasprometheus:0.0.425e378d57d78
golang.org/x/sys@v0.0.0-20210906170528-6f6e22806c34
stdlib@go1.17.1
0.0.0-20220412211240-33da011f77ad
1.17.10
1
skylenet/ethereum-genesis-generator:latest210353ce7c89
golang.org/x/sys@v0.0.0-20210927094055-39ccf1dd6fa6
0.0.0-20220412211240-33da011f77ad
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/sys@v0.0.0-20210908233432-aa78b53d3365
stdlib@go1.17.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
slagattollas/weatherservice-practica:latest68e7f56393fc
golang.org/x/sys@v0.0.0-20200523222454-059865788121
stdlib@go1.15.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
slamdev/config-connector-templater:0.0.3a234541c9fa8
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.16.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
slamdev/external-secrets-operator:0.0.8855f6625dda4
golang.org/x/sys@v0.0.0-20200124204421-9fbb57f87de9
stdlib@go1.13.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
slamdev/flux-notifier:v0.0.8b173d809132d
golang.org/x/sys@v0.0.0-20200420163511-1957bb5e6d1f
stdlib@go1.13.11
0.0.0-20220412211240-33da011f77ad
1.17.10
1
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
golang.org/x/sys@v0.0.0-20200501052902-10377860bb8e
stdlib@go1.13.11
0.0.0-20220412211240-33da011f77ad
1.17.10
1
smailkoz/torrserver:1.0.1117b52d15de8f0
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
softonic/node-policy-webhook:0.1.2ab6098c04a53
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.14.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
softonic/pod-defaulter:0.1.072017aed5902
golang.org/x/sys@v0.0.0-20200802091954-4b90ce9b60b3
stdlib@go1.14.9
0.0.0-20220412211240-33da011f77ad
1.17.10
1
softonic/preemptible-killer:1.2.6-294b87f1fb362
golang.org/x/sys@v0.0.0-20190222072716-a9d3bda3a223
stdlib@go1.14.10
0.0.0-20220412211240-33da011f77ad
1.17.10
1
softonic/rate-limit-operator:0.1.1910f6de37763
golang.org/x/sys@v0.0.0-20200323222414-85ca7c5b95cd
stdlib@go1.13.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
sophos/nginx-vts-exporter:latestf1073556b29b
stdlib@go1.13.6
1.17.10
1
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
golang.org/x/sys@v0.0.0-20200124204421-9fbb57f87de9
stdlib@go1.13.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
springhack/frpc_ingress:latest4aceb821da88
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.17.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
sstarcher/ecr-cleaner:0.1.12d43c390cb19
golang.org/x/sys@v0.0.0-20190412213103-97732733099d
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
sstarcher/helm-exporter:0.5.011769d01ba35
golang.org/x/sys@v0.0.0-20191028164358-195ce5e7f934
stdlib@go1.13.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.