StackRadar

CVE-2022-29526

Medium

Advisory

Published 24 Jun 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.030
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,076
of 17,781 indexed, latest versions
Container images
1,173
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/sys/unix has Incorrect privilege reporting in syscall

Carried by container images the latest versions of 1,076 of 17,781 indexed charts deploy, on 1,173 images.

Affected packageAffected versionsFixed inImages
golang.org/x/sysgolangv0.0.0-20180302081741-dd2ff4accc09, v0.0.0-20180810173357-98c5dad5d1a0, v0.0.0-20190209173611-3b5209105503, v0.0.0-20190215142949-d0b11bdaac8a+192 more0.0.0-20220412211240-33da011f77ad1,033
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+69 more1.17.101,019
OSV records
GHSA-p782-xgp4-8hr8GO-2022-0493
Also known as
BIT-golang-2022-29526

Charts affected

1,076 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/sys@v0.0.0-20200812155832-6a926be9bd1d
stdlib@go1.15.1
0.0.0-20220412211240-33da011f77ad
1.17.10
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
stdlib@go1.15.3
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/sys@v0.0.0-20201015000850-e3ed0017c211
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/sys@v0.0.0-20200602225109-6fdc65e7d980
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

12,125
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/sys@v0.0.0-20190801041406-cbf593c0f2f3
stdlib@go1.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,730
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
stdlib@go1.18.1
1.17.10

Open the chart page →

3,427
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/sys@v0.0.0-20200331124033-c3d80250170d
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/sys@v0.0.0-20200327173247-9dae0f8f5775
stdlib@go1.14.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

12,502
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/sys@v0.0.0-20220207234003-57398862261d
0.0.0-20220412211240-33da011f77ad

Open the chart page →

15,477
maeshtraefikOfficialVerified publisher2.1.21 of 7See more

maesh traefik 2.1.2

1 of the 7 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
containous/maesh:v1.3.2587162516502
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,136
traefik-meshtraefikOfficialVerified publisher4.1.12 of 7See more

traefik-mesh traefik 4.1.1

2 of the 7 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/sys@v0.0.0-20200217220822-9197077df867
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10
library/traefik:v2.57d5a6ae66572
golang.org/x/sys@v0.0.0-20210817190340-bfb29a6856f2
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

9,257
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
stdlib@go1.18.1
1.17.10

Open the chart page →

10,315
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.17.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,085
wharf-helmwharf-helmOfficialVerified publisher3.2.61 of 5See more

wharf-helm wharf-helm 3.2.6

1 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/sys@v0.0.0-20220330033206-e17cdc41300f
stdlib@go1.18.1
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

10,032
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd
stdlib@go1.13.8
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,714
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.17.10

Open the chart page →

12,046
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,995
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

8,341
soft-servealphani-helm-chartsVerified publisher0.4.01 of 1See more

soft-serve alphani-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
charmcli/soft-serve:v0.4.039523c1a6ba8
golang.org/x/sys@v0.0.0-20220209214540-3681064d5158
0.0.0-20220412211240-33da011f77ad

Open the chart page →

3,119
smockerandrcunsVerified publisher0.0.41 of 1See more

smocker andrcuns 0.0.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/sys@v0.0.0-20220307203707-22a9840ba4d7
0.0.0-20220412211240-33da011f77ad

Open the chart page →

2,173
upcloud-csiankra-chartsVerified publisher0.4.06 of 8See more

upcloud-csi ankra-charts 0.4.0

6 of the 8 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

14,917
anteonanteonVerified publisher2.6.41 of 13See more

anteon anteon 2.6.4

1 of the 13 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ddosify/selfhosted_hammer:2.0.0181965edb12e
stdlib@go1.18.1
1.17.10

Open the chart page →

22,202
stash-enterpriseappscodeVerified publisher0.42.01 of 4See more

stash-enterprise appscode 0.42.0

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
stdlib@go1.16.9
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,620
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/sys@v0.0.0-20211029165221-6e7872819dc8
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

5,222
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/sys@v0.0.0-20201214210602-f9fddec55a1e
stdlib@go1.14.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,819
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/sys@v0.0.0-20200625212154-ddb9806d33ae
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

10,730
dltbrokerassist-iot-distributed-broker0.2.04 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

4 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.04 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

4 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/sys@v0.0.0-20210420205809-ac73e9fd8988
0.0.0-20220412211240-33da011f77ad

Open the chart page →

77,687
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,292
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,391
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.18.1
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,723
prismav1o-chartsVerified publisher0.3.11 of 1See more

prism av1o-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

1,276
generic-appb3oVerified publisher0.1.61 of 1See more

generic-app b3o 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.17.10

Open the chart page →

1,279
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/sys@v0.0.0-20191210023423-ac6580df4449
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,814
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.17.5
0.0.0-20220412211240-33da011f77ad
1.17.10
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,807
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,830
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/sys@v0.0.0-20201009025420-dfb3f7c4e634
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,663
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/sys@v0.0.0-20200814200057-3d37ad5750ed
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,509
passbolt-hachristianhuthVerified publisher6.0.11 of 4See more

passbolt-ha christianhuth 6.0.1

1 of the 4 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
golang.org/x/sys@v0.0.0-20200413165638-669c56c373c4
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

10,817
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
0.0.0-20220412211240-33da011f77ad
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4
0.0.0-20220412211240-33da011f77ad

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
golang.org/x/sys@v0.0.0-20200620081246-981b61492c35
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/sys@v0.0.0-20200821140526-fda516888d29
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,256
cnpg-sandboxcloudnative-pgVerified publisher0.6.12 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

2 of the 6 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/sys@v0.0.0-20210908233432-aa78b53d3365
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,583
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,713
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.17.10

Open the chart page →

1,579
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/sys@v0.0.0-20191022100944-742c48ecaeb7
stdlib@go1.13.10
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,303
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/sys@v0.0.0-20210220050731-9a76102bfb43
stdlib@go1.16.5
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

6,473
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
golang.org/x/sys@v0.0.0-20200323222414-85ca7c5b95cd
stdlib@go1.14.4
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

3,026
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/sys@v0.0.0-20191010194322-b09406accb47
stdlib@go1.13.1
0.0.0-20220412211240-33da011f77ad
1.17.10
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
0.0.0-20220412211240-33da011f77ad
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/sys@v0.0.0-20210831042530-f4d43177bf5e
stdlib@go1.17.3
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22
stdlib@go1.16.2
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

15,891
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
stdlib@go1.15.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/sys@v0.0.0-20200824131525-c12d262b63d8
stdlib@go1.13.11
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

4,568
gripmockdeliveryheroVerified publisher1.1.31 of 1See more

gripmock deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.14.6
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,793
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/sys@v0.0.0-20190826190057-c7b8b68b1456
stdlib@go1.13.15
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/sys@v0.0.0-20190531175056-4c3a928424d2
stdlib@go1.13.5
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

7,984
kube-bench-metricsdevopstalesVerified publisher0.1.01 of 1See more

kube-bench-metrics devopstales 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29526.

Container imageDigestPackageFixed in
elastisys/kube-bench-metrics:0.1.6509b94f1da55
golang.org/x/sys@v0.0.0-20190621203818-d432491b9138
stdlib@go1.15.7
0.0.0-20220412211240-33da011f77ad
1.17.10

Open the chart page →

2,111

Container images carrying it

1,173 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
alex6021710/ai-scale-saver:latestf73e8d60fd03
golang.org/x/sys@v0.0.0-20211107104306-e0b2ad06fe42
stdlib@go1.17
0.0.0-20220412211240-33da011f77ad
1.17.10
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
stdlib@go1.18.1
1.17.10
1
almir/webhook:2.8.01698346f6077
golang.org/x/sys@v0.0.0-20191228213918-04cbcbbfeed8
stdlib@go1.14.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
stdlib@go1.14.15
1.17.10
1
alpine/git:2.36.366b210a97bc0
golang.org/x/sys@v0.0.0-20210615035016-665e8c7367d1
0.0.0-20220412211240-33da011f77ad
1
alpine/k8s:1.22.600ac10bcb759
golang.org/x/sys@v0.0.0-20211101204403-39c9dd37992c
stdlib@go1.17.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
alpine/k8s:1.27.321b24e6bf801
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
1
alpine/k8s:1.18.16a41efe02a041
golang.org/x/sys@v0.0.0-20210331175145-43e1dd70ce54
stdlib@go1.15.2
0.0.0-20220412211240-33da011f77ad
1.17.10
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
0.0.0-20220412211240-33da011f77ad
1
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/sys@v0.0.0-20210809222454-d867a43fc93e
stdlib@go1.13.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/sys@v0.0.0-20210809222454-d867a43fc93e
stdlib@go1.13.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
golang.org/x/sys@v0.0.0-20190616124812-15dcb6c0061f
stdlib@go1.13.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
amazon/aws-fsx-csi-driver:latestc9b14856fd22
golang.org/x/sys@v0.0.0-20210423082822-04245dca01da
stdlib@go1.16.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
golang.org/x/sys@v0.0.0-20200316230553-a7d97aace0b0
stdlib@go1.15.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
anchore/anchore-engine:v0.10.0bde9eedf639d
golang.org/x/sys@v0.0.0-20200602225109-6fdc65e7d980
stdlib@go1.16.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
andrcuns/smocker:0.18.5b4a8eb20581a
golang.org/x/sys@v0.0.0-20220307203707-22a9840ba4d7
0.0.0-20220412211240-33da011f77ad
1
anonaddy/anonaddy:0.12.3957a95565166
golang.org/x/sys@v0.0.0-20211116061358-0a5406a5449c
0.0.0-20220412211240-33da011f77ad
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/sys@v0.0.0-20190922100055-0a153f010e69
stdlib@go1.13.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.16.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
apache/apisix-dashboard:2.9.0c010ea7d1694
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.14.15
0.0.0-20220412211240-33da011f77ad
1.17.10
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/sys@v0.0.0-20210819072135-bce67f096156
stdlib@go1.13.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
stdlib@go1.16.9
0.0.0-20220412211240-33da011f77ad
1.17.10
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/sys@v0.0.0-20200116001909-b77594299b42
stdlib@go1.13.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/sys@v0.0.0-20210225134936-a50acf3fe073
stdlib@go1.16.9
0.0.0-20220412211240-33da011f77ad
1.17.10
1
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/sys@v0.0.0-20200116001909-b77594299b42
stdlib@go1.13.3
0.0.0-20220412211240-33da011f77ad
1.17.10
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/sys@v0.0.0-20200122134326-e047566fdf82
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/sys@v0.0.0-20200625212154-ddb9806d33ae
stdlib@go1.14.12
0.0.0-20220412211240-33da011f77ad
1.17.10
1
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.0.0-20220412211240-33da011f77ad
1
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.0.0-20220412211240-33da011f77ad
1
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/sys@v0.0.0-20210124154548-22da62e12c0c
0.0.0-20220412211240-33da011f77ad
1
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/sys@v0.0.0-20211216021012-1d35b9e2eb4e
0.0.0-20220412211240-33da011f77ad
1
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.13
1.17.10
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/sys@v0.0.0-20200323222414-85ca7c5b95cd
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
beanbag/reviewboard:latest6b840f546e1c
stdlib@go1.18.1
1.17.10
1
bedag/goblackhole:0.2.0447a88598f4c
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.16.6
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
stdlib@go1.17.6
1.17.10
1
bicarus/mx-notifier:1.1.8bed688d16762
stdlib@go1.17.6
1.17.10
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.17.10
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c
stdlib@go1.17
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bitnamilegacy/mongodb:5.0.103bb1deeaf9d0
golang.org/x/sys@v0.0.0-20210510120138-977fb7262007
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bitnamilegacy/mongodb:3.6.213e51da56fc54
golang.org/x/sys@v0.0.0-20200905004654-be1d3432aa8f
stdlib@go1.15.1
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bitnamilegacy/mongodb:4.4.5e3c9d6b4bc92
golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527
stdlib@go1.15.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
golang.org/x/sys@v0.0.0-20220114195835-da31bd327af9
stdlib@go1.17.8
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/sys@v0.0.0-20210309074719-68d13333faf2
stdlib@go1.16.4
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/sys@v0.0.0-20220319134239-a9b59b0215f8
stdlib@go1.17
0.0.0-20220412211240-33da011f77ad
1.17.10
1
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
golang.org/x/sys@v0.0.0-20210817142637-7d9622a276b7
stdlib@go1.16.7
0.0.0-20220412211240-33da011f77ad
1.17.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.