StackRadar

CVE-2022-29526

Medium

Advisory

Published 24 Jun 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.030
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,083
of 17,790 indexed, latest versions
Container images
1,187
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

Carried by container images the latest versions of 1,083 of 17,790 indexed charts deploy, on 1,187 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+192 more0.0.0-20220412211240-33da011f77ad1,047
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+69 more1.17.101,023
OSV records
GHSA-p782-xgp4-8hr8GO-2022-0493
Also known as
BIT-golang-2022-29526

Charts affected

1,083 by stars
ChartLatestAffected imagesRadar Score
prometheus-blackbox-exporterprometheus-worawutchan4.10.11 of 1See more

prometheus-blackbox-exporter prometheus-worawutchan 4.10.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.18.01ffc3f109eb3
golang.org/x/sys@v0.0.0-20200420163511-1957bb5e6d1f
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,250
prometheus-druid-exporterprometheus-worawutchan0.9.01 of 1See more

prometheus-druid-exporter prometheus-worawutchan 0.9.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/opstree/druid-exporter:v0.83f6d9885cfe2
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
stdlib@go1.14.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,090
prometheus-node-exporterprometheus-worawutchan1.12.01 of 1See more

prometheus-node-exporter prometheus-worawutchan 1.12.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/sys@v0.0.0-20200602225109-6fdc65e7d980
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,188
prometheus-pushgatewayprometheus-worawutchan1.5.01 of 1See more

prometheus-pushgateway prometheus-worawutchan 1.5.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
prom/pushgateway:v1.3.0c0d39b8d4cfe
golang.org/x/sys@v0.0.0-20200625212154-ddb9806d33ae
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

1,285
prometheus-redis-exporterprometheus-worawutchan4.0.01 of 1See more

prometheus-redis-exporter prometheus-worawutchan 4.0.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.11.104d958d209ab
golang.org/x/sys@v0.0.0-20200615200032-f1bc736245b1
stdlib@go1.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

1,315
prometheus-statsd-exporterprometheus-worawutchan0.1.01 of 1See more

prometheus-statsd-exporter prometheus-worawutchan 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
golang.org/x/sys@v0.0.0-20200523222454-059865788121
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

1,315
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

8,724
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,510
seashellpuckpuck1.2.01 of 1See more

seashell puckpuck 1.2.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/puckpuck/seashell:1.2ef5e31333821
golang.org/x/sys@v0.0.0-20210119212857-b64e53b001e4
0.0.0-20220412211240-33da011f77ad

Open the chart page →

4,214
loki-stackpyalive-cdmswebappVerified publisher2.6.52 of 4See more

loki-stack pyalive-cdmswebapp 2.6.5

2 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/loki:2.5.0f9ef133793af
golang.org/x/sys@v0.0.0-20220222172238-00053529121e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
grafana/promtail:2.4.2626900031c4e
golang.org/x/sys@v0.0.0-20210917161153-d61c044b1678
stdlib@go1.17.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,526
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/sys@v0.0.0-20191120155948-bd437916bb0e
stdlib@go1.13.3
0.0.0-20220412211240-33da011f77ad
1.17.10
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/sys@v0.0.0-20190813064441-fde4db37ae7a
stdlib@go1.13.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

11,942
quarksquarks7.0.1+0.g5396b114 of 5See more

quarks quarks 7.0.1+0.g5396b11

4 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
golang.org/x/sys@v0.0.0-20200323222414-85ca7c5b95cd
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
stdlib@go1.13.15
0.0.0-20220412211240-33da011f77ad
1.17.10
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
golang.org/x/sys@v0.0.0-20200519105757-fe76b779f299
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
golang.org/x/sys@v0.0.0-20200519105757-fe76b779f299
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

18,197
quarks-statefulsetquarks0.0.1304-g4b4f2ac51 of 1See more

quarks-statefulset quarks 0.0.1304-g4b4f2ac5

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
golang.org/x/sys@v0.0.0-20200519105757-fe76b779f299
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,010
saleorrc-helm-charts0.1.11 of 5See more

saleor rc-helm-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.22.0ca6b73330616
golang.org/x/sys@v0.0.0-20210119212857-b64e53b001e4
stdlib@go1.15.8
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,738
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.15.14
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

15,290
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.15.14
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

15,290
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
stdlib@go1.15.14
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

11,437
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.16
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

29,226
reporting-chartreporting-application0.1.01 of 1See more

reporting-chart reporting-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ibarreche/cloud-reporting-ci:latest1f45af91da6a
stdlib@go1.16.15
1.17.10

Open the chart page →

1,584
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
reportportal/migrations:5.7.0da5d8e1395fe
golang.org/x/sys@v0.0.0-20190426135247-a129542de9ae
stdlib@go1.13.6
0.0.0-20220412211240-33da011f77ad
1.17.10
reportportal/service-index:5.0.112b27a2d7a87d
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
stdlib@go1.17.1
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

25,739
resource-manager-operatorresource-manager-operator0.1.01 of 1See more

resource-manager-operator resource-manager-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/tikalk/resource-manager:latest7f21d50e69cb
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.0.0-20220412211240-33da011f77ad

Open the chart page →

1,623
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,490
whoamirgnu1.0.01 of 1See more

whoami rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
traefik/whoami:v1.6.0d38496bf0900
stdlib@go1.15.2
1.17.10

Open the chart page →

1,229
security-sample-chartrimusz0.2.11 of 3See more

security-sample-chart rimusz 0.2.1

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
rimusz/security-sample-app:0.2.0b9a178ca76ef
stdlib@go1.14.4
1.17.10

Open the chart page →

1,348
rke2-calicorke2-charts3.18.1-1011 of 1See more

rke2-calico rke2-charts 3.18.1-101

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.15.1c6591da87aa8
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,250
rke2-canal-1.19-1.20rke2-charts3.13.3-build20211022022 of 2See more

rke2-canal-1.19-1.20 rke2-charts 3.13.3-build2021102202

2 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
0.0.0-20220412211240-33da011f77ad
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
0.0.0-20220412211240-33da011f77ad

Open the chart page →

5,942
kubernetes-diff-loggerrlex0.1.21 of 1See more

kubernetes-diff-logger rlex 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/kubernetes-diff-logger:0.0.598f6d1cd1e25
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.5
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,454
runtimeclass-controllerrlex0.1.01 of 1See more

runtimeclass-controller rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/jlclx/runtimeclass-controller:latestb3a87f92a963
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.0.0-20220412211240-33da011f77ad

Open the chart page →

2,141
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad

Open the chart page →

3,051
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
golang.org/x/sys@v0.0.0-20210817190340-bfb29a6856f2
stdlib@go1.16.14
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

5,422
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
stdlib@go1.18.1
1.17.10

Open the chart page →

6,154
argocdromholdings1.8.12 of 3See more

argocd romholdings 1.8.1

2 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
stdlib@go1.14.9
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

10,468
calertromholdings0.0.11 of 1See more

calert romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
stdlib@go1.18
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,688
calicoromholdings0.1.14 of 4See more

calico romholdings 0.1.1

4 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.17.10

Open the chart page →

10,073
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/sys@v0.0.0-20210809222454-d867a43fc93e
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.07 of 28See more

devtron-enterprise romholdings 48.0.0

7 of the 28 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.0.0-20220412211240-33da011f77ad
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.14.15
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/sys@v0.0.0-20210220050731-9a76102bfb43
0.0.0-20220412211240-33da011f77ad
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
golang.org/x/sys@v0.0.0-20200918174421-af09f7315aff
stdlib@go1.15.14
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/sys@v0.0.0-20210218155724-8ebf48af031b
stdlib@go1.16.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

66,542
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/sys@v0.0.0-20201119102817-f84b799fce68
stdlib@go1.15.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

5,041
devtron-operatorromholdings0.23.34 of 11See more

devtron-operator romholdings 0.23.3

4 of the 11 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
0.0.0-20220412211240-33da011f77ad
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/sys@v0.0.0-20210220050731-9a76102bfb43
0.0.0-20220412211240-33da011f77ad
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

31,447
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/sys@v0.0.0-20210511113859-b0526f3d8744
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

11,957
discord-alertmanagerromholdings0.10.01 of 1See more

discord-alertmanager romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.17.10

Open the chart page →

951
kube-prometheus-stackromholdings19.3.03 of 6See more

kube-prometheus-stack romholdings 19.3.0

3 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/sys@v0.0.0-20210806184541-e5e7981a1069
stdlib@go1.17
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

8,645
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
stdlib@go1.16.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,435
winter-soldierromholdings0.10.61 of 1See more

winter-soldier romholdings 0.10.6

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.0.0-20220412211240-33da011f77ad

Open the chart page →

1,176
operatorrookout0.0.201 of 2See more

operator rookout 0.0.20

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
rookout/k8s-operator:latest0d083f3ef1a7
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
stdlib@go1.15.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,209
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,940
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
stdlib@go1.17.8
1.17.10

Open the chart page →

2,300
caddysagikazarmarkVerified publisher0.0.141 of 1See more

caddy sagikazarmark 0.0.14

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
library/caddy:2.4.5874405536b3e
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
stdlib@go1.17
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,960
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-email-service:v0.1.0-nativecf28472bc460
golang.org/x/sys@v0.0.0-20220412071739-889880a91fd5
0.0.0-20220412211240-33da011f77ad

Open the chart page →

16,159
fmtok8s-email-servicesalaboy0.2.01 of 1See more

fmtok8s-email-service salaboy 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
golang.org/x/sys@v0.0.0-20220412071739-889880a91fd5
0.0.0-20220412211240-33da011f77ad

Open the chart page →

2,896
hellowsamarthya2.0.01 of 1See more

hellow samarthya 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
samarthya/spinnaker:v1.0ef06d81036af
golang.org/x/sys@v0.0.0-20211103235746-7861aae1554b
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,121

Container images carrying it

1,187 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
golang.org/x/sys@v0.0.0-20200116001909-b77594299b42
0.0.0-20220412211240-33da011f77ad
1
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.1
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/giantswarm/helloworld:0.2.07a07ee730305
stdlib@go1.16.7
1.17.10
1
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
stdlib@go1.18
1.17.10
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/sys@v0.0.0-20210403161142-5e06dd20ab57
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/sys@v0.0.0-20210503080704-8803ae5d1324
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/sys@v0.0.0-20210503080704-8803ae5d1324
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.15.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
1
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
1
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
1
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
1
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
golang.org/x/sys@v0.0.0-20200113162924-86b910548bc1
stdlib@go1.14.1
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.13.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.13.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.13.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
1
quay.io/kube-ops/loki:2.2.14fbd63194674
golang.org/x/sys@v0.0.0-20201223074533-0d417f636930
stdlib@go1.15.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/kube-ops/promtail:2.2.134de6387233b
golang.org/x/sys@v0.0.0-20201223074533-0d417f636930
stdlib@go1.15.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.15.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
golang.org/x/sys@v0.0.0-20210817190340-bfb29a6856f2
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/lunarway/snyk_exporter:v1.11.155e5cc5aaa0a
golang.org/x/sys@v0.0.0-20201204225414-ed752295db88
stdlib@go1.17.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/sys@v0.0.0-20210314195730-07df6a141424
stdlib@go1.16.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/sys@v0.0.0-20210314195730-07df6a141424
stdlib@go1.16.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/sys@v0.0.0-20200323222414-85ca7c5b95cd
stdlib@go1.13.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
stdlib@go1.14.10
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
golang.org/x/sys@v0.0.0-20200519105757-fe76b779f299
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
stdlib@go1.16
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/sys@v0.0.0-20220222160653-b146bcec3beb
0.0.0-20220412211240-33da011f77ad
1
quay.io/openshift/origin-cli:4.66722d5041b47
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
stdlib@go1.15.14
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
stdlib@go1.16.9
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
golang.org/x/sys@v0.0.0-20210809222454-d867a43fc93e
stdlib@go1.17.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e
stdlib@go1.16.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/sys@v0.0.0-20190910064555-bbd175535a8b
stdlib@go1.13.1
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/opstree/druid-exporter:v0.83f6d9885cfe2
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
stdlib@go1.14.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/opstree/druid-exporter:v0.119f01c9c5c2e3
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
stdlib@go1.15.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/opstree/logging-operator:v0.4.0fd8bb57ef3cf
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
0.0.0-20220412211240-33da011f77ad
1
quay.io/opstree/mongodb-operator:v0.3.0879b9bead838
golang.org/x/sys@v0.0.0-20210817190340-bfb29a6856f2
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/prometheus/alertmanager:v0.24.0088464f949de
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/prometheuscommunity/elasticsearch-exporter:v1.5.013a41e8ac836
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.0.0-20220412211240-33da011f77ad
1
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/sys@v0.0.0-20220222172238-00053529121e
0.0.0-20220412211240-33da011f77ad
1
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/prometheus/prometheus:v2.33.591100b06e86d
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
golang.org/x/sys@v0.0.0-20220222172238-00053529121e
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.