StackRadar

CVE-2022-41717

Medium

Advisory

Published 8 Dec 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.056
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,425
of 17,787 indexed, latest versions
Container images
1,580
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/net/http2 vulnerable to possible excessive memory growth

Carried by container images the latest versions of 1,425 of 17,787 indexed charts deploy, on 1,580 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+172 more0.4.01,132
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+85 more1.18.91,485
OSV records
GHSA-xrjj-mj9h-534mGO-2022-1144
Also known as
BIT-golang-2022-41717

Charts affected

1,425 by stars
ChartLatestAffected imagesRadar Score
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.4.0
1.18.9
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.4.0
1.18.9

Open the chart page →

7,386
kube-acp-stackcloudentity2.28.02 of 7See more

kube-acp-stack cloudentity 2.28.0

2 of the 7 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
stdlib@go1.18.1
1.18.9
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.4.0
1.18.9

Open the chart page →

20,936
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.4.0
1.18.9
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.14
0.4.0
1.18.9
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.4.0
1.18.9
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.16.6
0.4.0
1.18.9
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.4.0
1.18.9
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
stdlib@go1.15.2
0.4.0
1.18.9

Open the chart page →

18,040
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.16.3
0.4.0
1.18.9

Open the chart page →

25,152
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.5
0.4.0
1.18.9

Open the chart page →

6,696
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18.1
0.4.0
1.18.9

Open the chart page →

6,921
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.18.9

Open the chart page →

2,814
robot-shopcloud-native-toolkit1.1.12 of 12See more

robot-shop cloud-native-toolkit 1.1.1

2 of the 12 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
robotshop/rs-dispatch:latestde81f1d07b02
stdlib@go1.17
1.18.9
robotshop/rs-mongodb:latest119b545823cd
stdlib@go1.16.3
1.18.9

Open the chart page →

29,594
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad1 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

1 of the 6 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.1
0.4.0
1.18.9

Open the chart page →

18,256
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.16.13
0.4.0
1.18.9

Open the chart page →

3,136
galaxy-depscloudve1.1.12 of 7See more

galaxy-deps cloudve 1.1.1

2 of the 7 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17
0.4.0
1.18.9
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/net@v0.0.0-20220614195744-fb05da6f9022
stdlib@go1.17
0.4.0
1.18.9

Open the chart page →

10,543
galaxykubemancloudve2.10.12 of 7See more

galaxykubeman cloudve 2.10.1

2 of the 7 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.13
0.4.0
1.18.9
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.4.0
1.18.9

Open the chart page →

16,117
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.4.0
1.18.9

Open the chart page →

14,285
openstack-cinder-csicloudve1.2.01 of 5See more

openstack-cinder-csi cloudve 1.2.0

1 of the 5 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.10
0.4.0
1.18.9

Open the chart page →

2,061
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.13.1
0.4.0
1.18.9

Open the chart page →

2,853
d2-prometheus-exportercmacraeVerified publisher0.1.01 of 1See more

d2-prometheus-exporter cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
stdlib@go1.15
1.18.9

Open the chart page →

1,299
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.17
0.4.0
1.18.9

Open the chart page →

2,089
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16
0.4.0
1.18.9

Open the chart page →

2,203
lgtmcmacraeVerified publisher0.1.01 of 1See more

lgtm cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
cmacrae/lgtm:0.1.0dec8d490fe40
golang.org/x/net@v0.0.0-20181108082009-03003ca0c849
stdlib@go1.14.1
0.4.0
1.18.9

Open the chart page →

1,909
door-agentcnoVerified publisher3.0.152 of 15See more

door-agent cno 3.0.15

2 of the 15 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.13
0.4.0
1.18.9
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.1
0.4.0
1.18.9

Open the chart page →

19,380
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.4.0
1.18.9

Open the chart page →

2,234
mysqlcomet-mysql-helmVerified publisher1.0.71 of 1See more

mysql comet-mysql-helm 1.0.7

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.18.9

Open the chart page →

1,055
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

7,572
community-operator-v2community-operator-v21.0.01 of 2See more

community-operator-v2 community-operator-v2 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.4.0
1.18.9

Open the chart page →

1,544
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

12,906
consentbbconsentbbVerified publisher2023.12.41 of 5See more

consentbb consentbb 2023.12.4

1 of the 5 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
stdlib@go1.18.8
1.18.9

Open the chart page →

3,181
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

7,209
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

8,408
containers-security-chartscontainers-security0.1.03 of 7See more

containers-security-charts containers-security 0.1.0

3 of the 7 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.18.9
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.18.9
falcosecurity/falcosidekick:2.27.0828ee36cb13a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.18.1
0.4.0
1.18.9

Open the chart page →

9,146
falcocontainers-security2.4.62 of 2See more

falco containers-security 2.4.6

2 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.33.11fe583eee4af
stdlib@go1.18.6
1.18.9
falcosecurity/falco-no-driver:0.33.10d427b8d5fc6
stdlib@go1.18.6
1.18.9

Open the chart page →

2,540
katibcowboysysopVerified publisher2.4.23 of 4See more

katib cowboysysop 2.4.2

3 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.1
0.4.0
1.18.9
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
stdlib@go1.13.3
0.4.0
1.18.9
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.1
0.4.0
1.18.9

Open the chart page →

6,542
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kfserving/kfserving-controller:v0.6.163d79d04c2e3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.14
0.4.0
1.18.9

Open the chart page →

3,830
metacontrollercowboysysopVerified publisher1.2.21 of 1See more

metacontroller cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
metacontrollerio/metacontroller:v2.1.10336993b88e4
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.6
0.4.0
1.18.9

Open the chart page →

2,092
mpi-operatorcowboysysopVerified publisher1.2.21 of 1See more

mpi-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.15.13
0.4.0
1.18.9

Open the chart page →

2,577
notebook-controllercowboysysopVerified publisher1.1.21 of 1See more

notebook-controller cowboysysop 1.1.2

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.15.15
0.4.0
1.18.9

Open the chart page →

2,582
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
stdlib@go1.13.1
1.18.9

Open the chart page →

5,489
training-operatorcowboysysopVerified publisher1.2.21 of 1See more

training-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.14.9
0.4.0
1.18.9

Open the chart page →

2,275
crossplane-controllerscrossplane0.12.01 of 1See more

crossplane-controllers crossplane 0.12.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
crossplane/crossplane:v0.12.066666e6963af
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.4
0.4.0
1.18.9

Open the chart page →

2,312
oam-kubernetes-runtimecrossplane0.0.3-71.g0f235901 of 2See more

oam-kubernetes-runtime crossplane 0.0.3-71.g0f23590

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.14
0.4.0
1.18.9

Open the chart page →

2,248
oam-kubernetes-runtime-legacycrossplane0.3.1-5.g11e18941 of 1See more

oam-kubernetes-runtime-legacy crossplane 0.3.1-5.g11e1894

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.4.0
1.18.9

Open the chart page →

2,231
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.2
0.4.0
1.18.9

Open the chart page →

4,625
electric-mailcryptexlabsVerified publisher0.0.12 of 5See more

electric-mail cryptexlabs 0.0.1

2 of the 5 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.4.0
1.18.9
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.4.0
1.18.9

Open the chart page →

5,973
purple-piecryptexlabsVerified publisher0.0.12 of 4See more

purple-pie cryptexlabs 0.0.1

2 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.7
0.4.0
1.18.9
hashicorp/vault-k8s:0.13.1bebb03e8e800
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.4.0
1.18.9

Open the chart page →

5,973
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.4.0
1.18.9

Open the chart page →

5,293
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/postgres:13.11-bullseye5c265bf1fd30
stdlib@go1.18.2
1.18.9

Open the chart page →

14,206
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.4.0
1.18.9

Open the chart page →

13,937
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.8
0.4.0
1.18.9

Open the chart page →

1,232
irods-csi-drivercyverse0.12.01 of 4See more

irods-csi-driver cyverse 0.12.0

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.4.0
1.18.9

Open the chart page →

5,257
domain-exporterd0main-exp0rter0.1.01 of 1See more

domain-exporter d0main-exp0rter 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.2
0.4.0
1.18.9

Open the chart page →

1,832
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
stdlib@go1.17.1
1.18.9

Open the chart page →

6,178

Container images carrying it

1,580 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
nvidia/dcgm-exporter:2.2.9-2.4.1-ubuntu20.0491b20b66d1cd
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.2
0.4.0
1.18.9
1
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.4.0
1.18.9
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
stdlib@go1.18.2
1.18.9
1
ofekmeister/csi-gcs:v0.9.030d70fa9211b
golang.org/x/net@v0.0.0-20220513224357-95641704303c
stdlib@go1.18.2
0.4.0
1.18.9
1
okgolove/asprom:1.10.1974d2e5eb150
stdlib@go1.14.11
1.18.9
1
oliver006/redis_exporter:v1.11.104d958d209ab
stdlib@go1.15
1.18.9
1
oliver006/redis_exporter:v1.14.0d55e056987af
stdlib@go1.15.6
1.18.9
1
olliai/exposecontroller:1.0.5a470d96525e4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.3
0.4.0
1.18.9
1
olliai/k8s-replicator:1.3.05716f2a8bd4c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.17.2
0.4.0
1.18.9
1
openbas/caldera-server:5.1.0a277796d9724
stdlib@go1.18
1.18.9
1
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.5
0.4.0
1.18.9
1
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.18.9
1
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/net@v0.0.0-20200520182314-0ba52f642ac2
stdlib@go1.14.7
0.4.0
1.18.9
1
otel/opentelemetry-collector:0.59.0ee9da0b08d83
golang.org/x/net@v0.0.0-20220809184613-07c6da5e1ced
stdlib@go1.18.5
0.4.0
1.18.9
1
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.7
0.4.0
1.18.9
1
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.4.0
1.18.9
1
ovhplatform/what-is-my-pod:1.0.16d4d455e9aba
stdlib@go1.16.14
1.18.9
1
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.5
0.4.0
1.18.9
1
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17
0.4.0
1.18.9
1
oxynozeta/prometheus-cachethq:1.1.131f11669d597
stdlib@go1.15.1
1.18.9
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
stdlib@go1.14.4
1.18.9
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.18.9
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
stdlib@go1.14.4
1.18.9
1
phntom/chartmuseum:v0.16.053883b65d9b7
stdlib@go1.19.3
1.18.9
1
phntom/chartmuseum:v0.15.29242b4df9e65
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.18.5
0.4.0
1.18.9
1
phntom/codimd:2.4.31b9aafbb62e6
stdlib@go1.16
1.18.9
1
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.4.0
1.18.9
1
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.16.2
0.4.0
1.18.9
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
golang.org/x/net@v0.0.0-20221012135044-0b7e1fb9d458
stdlib@go1.19.2
0.4.0
1.18.9
1
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.3
0.4.0
1.18.9
1
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.4.0
1.18.9
1
platform9community/api-gateway:latest40a4970de568
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.4.0
1.18.9
1
platform9community/customers-service:latest2089811e5cc6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.4.0
1.18.9
1
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.11
0.4.0
1.18.9
1
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.4.0
1.18.9
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.12
0.4.0
1.18.9
1
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
stdlib@go1.13.10
1.18.9
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
stdlib@go1.18.7
1.18.9
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
stdlib@go1.18.2
1.18.9
1
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.18.9
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
stdlib@go1.13.12
0.4.0
1.18.9
1
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.9
0.4.0
1.18.9
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
stdlib@go1.16
1.18.9
1
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
stdlib@go1.19.3
0.4.0
1.18.9
1
prom/blackbox-exporter:v0.22.0608acee5704a
golang.org/x/net@v0.0.0-20220728211354-c7608f3a8462
stdlib@go1.18.5
0.4.0
1.18.9
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.4.0
1.18.9
1
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.18.9
1
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.18.9
1
prom/memcached-exporter:v0.9.001267317c95d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.16.2
0.4.0
1.18.9
1
prom/prometheus:v2.18.15880ec936055
golang.org/x/net@v0.0.0-20200421231249-e086a090c8fd
stdlib@go1.14.2
0.4.0
1.18.9
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.