StackRadar

CVE-2022-29526

Medium

Advisory

Published 24 Jun 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.030
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,083
of 17,787 indexed, latest versions
Container images
1,187
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

Carried by container images the latest versions of 1,083 of 17,787 indexed charts deploy, on 1,187 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+192 more0.0.0-20220412211240-33da011f77ad1,047
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+69 more1.17.101,023
OSV records
GHSA-p782-xgp4-8hr8GO-2022-0493
Also known as
BIT-golang-2022-29526

Charts affected

1,083 by stars
ChartLatestAffected imagesRadar Score
nfs-subdir-external-provisionernfs-subdir-external-provisioner4.0.181 of 1See more

nfs-subdir-external-provisioner nfs-subdir-external-provisioner 4.0.18

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
stdlib@go1.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,745
nfs-server-provisionerkvaps1.8.01 of 1See more

nfs-server-provisioner kvaps 1.8.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/sys@v0.0.0-20190924154521-2837fb4f24fe
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,315
terraformhashicorpVerified publisher1.1.21 of 1See more

terraform hashicorp 1.1.2

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/sys@v0.0.0-20211025201205-69cdffdb9359
0.0.0-20220412211240-33da011f77ad

Open the chart page →

2,059
chaos-meshchaos-meshVerified publisher2.8.41 of 4See more

chaos-mesh chaos-mesh 2.8.4

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/sys@v0.0.0-20210917161153-d61c044b1678
0.0.0-20220412211240-33da011f77ad

Open the chart page →

6,362
vclusterloftVerified publisher0.0.0-ci.31 of 2See more

vcluster loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/sys@v0.0.0-20211116061358-0a5406a5449c
0.0.0-20220412211240-33da011f77ad

Open the chart page →

2,453
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.16.15
0.0.0-20220412211240-33da011f77ad
1.17.10
milvusdb/milvus-config-tool:v0.1.12212dfb61401
stdlib@go1.16.15
1.17.10

Open the chart page →

32,353
nacosygqygq2Verified publisher2.1.101 of 4See more

nacos ygqygq2 2.1.10

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.17.10

Open the chart page →

4,984
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,086
oktetooktetoOfficialVerified publisher0.0.0-2026-08-171 of 10See more

okteto okteto 0.0.0-2026-08-17

1 of the 10 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/okteto/buildkit:0.0.0-2026-08-1714527ca5d2a9
golang.org/x/sys@v0.0.0-20190916202348-b4ddaad3f8a3
0.0.0-20220412211240-33da011f77ad

Open the chart page →

5,491
volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
golang.org/x/sys@v0.0.0-20220310020820-b874c991c1a5
0.0.0-20220412211240-33da011f77ad

Open the chart page →

1,364
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/sys@v0.0.0-20210611083646-a4fc73990273
stdlib@go1.16.8
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,159
oncallgrafana1.16.55 of 12See more

oncall grafana 1.16.5

5 of the 12 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.9
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

16,251
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/sys@v0.0.0-20200625212154-ddb9806d33ae
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

11,402
zabbixcetic3.1.32 of 5See more

zabbix cetic 3.1.3

2 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/sys@v0.0.0-20220310020820-b874c991c1a5
stdlib@go1.18.1
0.0.0-20220412211240-33da011f77ad
1.17.10
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
golang.org/x/sys@v0.0.0-20220310020820-b874c991c1a5
stdlib@go1.18.1
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

33,907
chatwootchatwootVerified publisher2.0.242 of 3See more

chatwoot chatwoot 2.0.24

2 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

9,204
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,918
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.17.10

Open the chart page →

7,706
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,039
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
stdlib@go1.13.4
1.17.10

Open the chart page →

6,219
linkerd-jaegerlinkerd2Verified publisher30.12.111 of 4See more

linkerd-jaeger linkerd2 30.12.11

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,405
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
stdlib@go1.17.1
1.17.10

Open the chart page →

6,040
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.15.12
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,853
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

5,173
zookeepercloudpirates-zookeeperVerified publisher0.13.111 of 1See more

zookeeper cloudpirates-zookeeper 0.13.11

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5cab8944a33a1
stdlib@go1.18.1
1.17.10

Open the chart page →

2,963
loki-simple-scalablegrafana1.8.112 of 3See more

loki-simple-scalable grafana 1.8.11

2 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
stdlib@go1.18
1.17.10
grafana/loki:2.6.11ee60f980950
golang.org/x/sys@v0.0.0-20220222172238-00053529121e
stdlib@go1.17.9
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,470
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
stdlib@go1.17.1
1.17.10

Open the chart page →

3,004
kube-prometheuschoerodon9.3.14 of 7See more

kube-prometheus choerodon 9.3.1

4 of the 7 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/sys@v0.0.0-20200223170610-d5e6a3e2c0ae
stdlib@go1.14.3
0.0.0-20220412211240-33da011f77ad
1.17.10
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/sys@v0.0.0-20190422165155-953cdadca894
stdlib@go1.13.11
0.0.0-20220412211240-33da011f77ad
1.17.10
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/sys@v0.0.0-20191010194322-b09406accb47
stdlib@go1.13.4
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/sys@v0.0.0-20200523222454-059865788121
stdlib@go1.14.3
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

12,237
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.9
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,896
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/sys@v0.0.0-20210426230700-d19ff857e887
stdlib@go1.15.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,412
dex-k8s-authenticatorsagikazarmarkVerified publisher0.0.31 of 1See more

dex-k8s-authenticator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/sys@v0.0.0-20190215142949-d0b11bdaac8a
stdlib@go1.13.11
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,791
kubeviewcowboysysopVerified publisher6.0.01 of 1See more

kubeview cowboysysop 6.0.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
stdlib@go1.17.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

1,513
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
golang.org/x/sys@v0.0.0-20200223170610-d5e6a3e2c0ae
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,577
devtron-operatordevtron0.23.34 of 11See more

devtron-operator devtron 0.23.3

4 of the 11 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.0.0-20220412211240-33da011f77ad
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/sys@v0.0.0-20210220050731-9a76102bfb43
0.0.0-20220412211240-33da011f77ad
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

31,447
drone-runner-kubedroneVerified publisher0.1.101 of 1See more

drone-runner-kube drone 0.1.10

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/sys@v0.0.0-20210426230700-d19ff857e887
stdlib@go1.16.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,067
temporallemontechVerified publisher0.37.05 of 13See more

temporal lemontech 0.37.0

5 of the 13 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/sys@v0.0.0-20200223170610-d5e6a3e2c0ae
stdlib@go1.13.4
0.0.0-20220412211240-33da011f77ad
1.17.10
jimmidyson/configmap-reload:v0.5.0904d08e9f701
golang.org/x/sys@v0.0.0-20200620081246-981b61492c35
stdlib@go1.15.7
0.0.0-20220412211240-33da011f77ad
1.17.10
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.16.9
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/sys@v0.0.0-20211020174200-9d6173849985
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

14,893
netris-controllernetrisai2.8.23 of 14See more

netris-controller netrisai 2.8.2

3 of the 14 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/sys@v0.0.0-20200519105757-fe76b779f299
stdlib@go1.13.11
0.0.0-20220412211240-33da011f77ad
1.17.10
netrisai/controller-web-session-generator:0.2.0a030a31289f4
golang.org/x/sys@v0.0.0-20220227234510-4e6760a101f9
stdlib@go1.14.15
0.0.0-20220412211240-33da011f77ad
1.17.10
netrisai/mongodb:4.4.4-debian-10-r095abfb776bb4
golang.org/x/sys@v0.0.0-20200905004654-be1d3432aa8f
stdlib@go1.15.1
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

30,481
nfs-server-provisionernfs-ganesha-server-and-external-provisioner1.8.01 of 1See more

nfs-server-provisioner nfs-ganesha-server-and-external-provisioner 1.8.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/sys@v0.0.0-20190924154521-2837fb4f24fe
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,315
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/sys@v0.0.0-20200523222454-059865788121
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
platform9community/api-gateway:latest40a4970de568
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
platform9community/customers-service:latest2089811e5cc6
golang.org/x/sys@v0.0.0-20210603125802-9665404d3644
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/sys@v0.0.0-20210603125802-9665404d3644
stdlib@go1.15.11
0.0.0-20220412211240-33da011f77ad
1.17.10
platform9community/visits-service:latest8d11b50368c6
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

41,902
helm-exportersstarcher0.5.01 of 1See more

helm-exporter sstarcher 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
sstarcher/helm-exporter:0.5.011769d01ba35
golang.org/x/sys@v0.0.0-20191028164358-195ce5e7f934
stdlib@go1.13.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,154
passboltcnieg1.1.171 of 2See more

passbolt cnieg 1.1.17

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,544
dronecommunity-chartsVerified publisher0.1.51 of 2See more

drone community-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/sys@v0.0.0-20210426230700-d19ff857e887
stdlib@go1.16.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,728
missing-container-metricsmissing-container-metrics0.1.11 of 1See more

missing-container-metrics missing-container-metrics 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/sys@v0.0.0-20210305230114-8fe3ee5dd75b
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,409
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
golang.org/x/sys@v0.0.0-20200625212154-ddb9806d33ae
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,168
cert-manager-webhook-hetznercert-manager-webhook-hetznerVerified publisher0.2.11 of 1See more

cert-manager-webhook-hetzner cert-manager-webhook-hetzner 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,080
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/sys@v0.0.0-20201022201747-fb209a7c41cd
stdlib@go1.15.5
0.0.0-20220412211240-33da011f77ad
1.17.10
library/traefik:2.5.47d0228d19042
golang.org/x/sys@v0.0.0-20210817190340-bfb29a6856f2
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

53,012
csi-wekafsplugincsi-wekafsOfficialVerified publisher0.6.2-01 of 6See more

csi-wekafsplugin csi-wekafs 0.6.2-0

1 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/sys@v0.0.0-20180302081741-dd2ff4accc09
stdlib@go1.13.3
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,824
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/sys@v0.0.0-20211019181941-9d821ace8654
0.0.0-20220412211240-33da011f77ad

Open the chart page →

27,358
drone-runner-dockerdroneVerified publisher0.7.01 of 3See more

drone-runner-docker drone 0.7.0

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/sys@v0.0.0-20190422165155-953cdadca894
stdlib@go1.16.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

5,674
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
stdlib@go1.15.1
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,282
lndfold0.3.152 of 4See more

lnd fold 0.3.15

2 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/sys@v0.0.0-20200202164722-d101bd2416d5
stdlib@go1.13.12
0.0.0-20220412211240-33da011f77ad
1.17.10
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/sys@v0.0.0-20200202164722-d101bd2416d5
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

8,834

Container images carrying it

1,187 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
golang.org/x/sys@v0.0.0-20191026070338-33540a1f6037
stdlib@go1.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.17.10
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
stdlib@go1.18
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
golang.org/x/sys@v0.0.0-20210809222454-d867a43fc93e
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/kube-logging/log-generator:v0.4.105aa441b20aa
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.15.14
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
golang.org/x/sys@v0.0.0-20191113165036-4c7a9d0fe056
stdlib@go1.15.14
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
stdlib@go1.15.14
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
golang.org/x/sys@v0.0.0-20210301091718-77cc2087c03b
stdlib@go1.15.14
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
stdlib@go1.17.9
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
stdlib@go1.17.9
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
golang.org/x/sys@v0.0.0-20200116001909-b77594299b42
stdlib@go1.17.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.17.10
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.16.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/sys@v0.0.0-20191112214154-59a1497f0cea
stdlib@go1.13.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
golang.org/x/sys@v0.0.0-20191026070338-33540a1f6037
stdlib@go1.15.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/sys@v0.0.0-20210823070655-63515b42dcdf
stdlib@go1.17
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.16.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
golang.org/x/sys@v0.0.0-20210917161153-d61c044b1678
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/nlamirault/bbox_exporter:1.0.0f5dd1f7794c6
golang.org/x/sys@v0.0.0-20210917161153-d61c044b1678
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/nousefreak/clusterfan:v0.1.04ea05e2a7b57
golang.org/x/sys@v0.0.0-20211210111614-af8b64212486
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/okteto/buildkit:0.0.0-2026-08-03:0.0.0-2026-08-1714527ca5d2a9
golang.org/x/sys@v0.0.0-20190916202348-b4ddaad3f8a3
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/paganuzzi/ngrokoperator:latest5a10cd095699
golang.org/x/sys@v0.0.0-20200202164722-d101bd2416d5
stdlib@go1.15.12
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
golang.org/x/sys@v0.0.0-20200116001909-b77594299b42
stdlib@go1.14.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/podtato-head/entry:latestc3d9d9c98be7
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/podtato-head/hat:latestde37ff39a4c0
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/podtato-head/left-arm:latest97596c95276a
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/podtato-head/left-leg:latest00bb31622b1e
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/podtato-head/right-arm:latest5f8f97a60558
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/podtato-head/right-leg:latest03e125b9279e
golang.org/x/sys@v0.0.0-20210603081109-ebe580a85c40
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/prymitive/karma:v0.85d06892218680
golang.org/x/sys@v0.0.0-20210503173754-0981d6026fa6
stdlib@go1.16.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ghcr.io/puckpuck/seashell:1.2ef5e31333821
golang.org/x/sys@v0.0.0-20210119212857-b64e53b001e4
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
golang.org/x/sys@v0.0.0-20220330033206-e17cdc41300f
0.0.0-20220412211240-33da011f77ad
1
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
golang.org/x/sys@v0.0.0-20220412071739-889880a91fd5
0.0.0-20220412211240-33da011f77ad
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.