StackRadar

CVE-2022-41717

Medium

Advisory

Published 8 Dec 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.056
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,423
of 17,792 indexed, latest versions
Container images
1,578
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/net/http2 vulnerable to possible excessive memory growth

Carried by container images the latest versions of 1,423 of 17,792 indexed charts deploy, on 1,578 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+172 more0.4.01,131
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+85 more1.18.91,483
OSV records
GHSA-xrjj-mj9h-534mGO-2022-1144
Also known as
BIT-golang-2022-41717

Charts affected

1,423 by stars
ChartLatestAffected imagesRadar Score
ccm-qingcloudkubesphere-testVerified publisher0.1.01 of 1See more

ccm-qingcloud kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
qingcloud/cloud-controller-manager:v1.4.1210f66b5df886
stdlib@go1.18.2
1.18.9

Open the chart page →

1,540
cni-hostnickubesphere-testVerified publisher0.1.01 of 1See more

cni-hostnic kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.3
0.4.0
1.18.9

Open the chart page →

2,443
csi-neonsankubesphere-testVerified publisher1.3.06 of 6See more

csi-neonsan kubesphere-test 1.3.0

6 of the 6 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.4.0
1.18.9
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.4
0.4.0
1.18.9
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.4.0
1.18.9
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.4.0
1.18.9
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.4.0
1.18.9

Open the chart page →

18,526
csi-qingcloudkubesphere-testVerified publisher1.4.06 of 6See more

csi-qingcloud kubesphere-test 1.4.0

6 of the 6 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.16
0.4.0
1.18.9
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.4.0
1.18.9
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.4.0
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.4.0
1.18.9
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.4.0
1.18.9

Open the chart page →

12,444
curvefs-csikubesphere-testVerified publisher0.1.01 of 3See more

curvefs-csi kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.4.0
1.18.9

Open the chart page →

2,831
mongodbkubesphere-testVerified publisher0.3.21 of 2See more

mongodb kubesphere-test 0.3.2

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
mikefarah/yq:2.4.16fc625c402de
stdlib@go1.13.3
1.18.9

Open the chart page →

9,631
online-boutiquekubesphere-testVerified publisher0.1.08 of 11See more

online-boutique kubesphere-test 0.1.0

8 of the 11 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.4.0
1.18.9
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.10
0.4.0
1.18.9
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.4.0
1.18.9
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.4.0
1.18.9
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.4.0
1.18.9
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.4.0
1.18.9
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.4.0
1.18.9
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.4.0
1.18.9

Open the chart page →

26,075
openelbkubesphere-testVerified publisher0.2.42 of 2See more

openelb kubesphere-test 0.2.4

2 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.4.0
1.18.9
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.4.0
1.18.9

Open the chart page →

4,336
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.15.15
0.4.0
1.18.9

Open the chart page →

2,791
snapshot-controllerkubesphere-testVerified publisher0.2.01 of 1See more

snapshot-controller kubesphere-test 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.15
0.4.0
1.18.9

Open the chart page →

2,220
kubestellar-uikubestellaruiVerified publisher0.1.11 of 4See more

kubestellar-ui kubestellarui 0.1.1

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/redis:7.0-alpinec9d92d840fd0
stdlib@go1.18.2
1.18.9

Open the chart page →

4,773
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.18.9

Open the chart page →

8,767
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.1
0.4.0
1.18.9

Open the chart page →

16,539
metadockvalitetsitVerified publisher0.0.72 of 2See more

metadoc kvalitetsit 0.0.7

2 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-app:maine89e351733ad
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.4.0
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.4.0
1.18.9

Open the chart page →

4,033
nsp-prometheus-exporterkvalitetsitVerified publisher1.0.191 of 2See more

nsp-prometheus-exporter kvalitetsit 1.0.19

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kvalitetsit/nsp-prometheus-exporter:1.0.190b397ff954ec
stdlib@go1.15.3
1.18.9

Open the chart page →

2,063
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
golang.org/x/net@v0.0.0-20180906233101-161cd47e91fd
stdlib@go1.19.3
0.4.0
1.18.9

Open the chart page →

7,848
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

8,543
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
golang.org/x/net@v0.0.0-20200519113804-d87ec0cfa476
stdlib@go1.14
0.4.0
1.18.9

Open the chart page →

26,377
metallblectures-k8sinfra0.10.22 of 2See more

metallb lectures-k8sinfra 0.10.2

2 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.5
0.4.0
1.18.9
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.5
0.4.0
1.18.9

Open the chart page →

5,406
prometheuslectures-k8sinfra15.8.55 of 6See more

prometheus lectures-k8sinfra 15.8.5

5 of the 6 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.18.9
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.4.0
1.18.9
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.4.0
1.18.9
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.4.0
1.18.9
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.4
0.4.0
1.18.9

Open the chart page →

9,100
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.4.0
1.18.9

Open the chart page →

3,198
prometheusleechistest11.6.04 of 6See more

prometheus leechistest 11.6.0

4 of the 6 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.4.0
1.18.9
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.4.0
1.18.9
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.18.9
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.4.0
1.18.9

Open the chart page →

8,491
kube-benchlemontechVerified publisher0.1.01 of 1See more

kube-bench lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.6.9c329d73fea58
stdlib@go1.19
1.18.9

Open the chart page →

1,632
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.4.0
1.18.9

Open the chart page →

4,280
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.13.8
0.4.0
1.18.9

Open the chart page →

4,459
op-scim-bridgelifen1.0.31 of 2See more

op-scim-bridge lifen 1.0.3

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.16.8
0.4.0
1.18.9

Open the chart page →

2,777
op-scim-bridgelifen-chartsVerified publisher1.0.31 of 2See more

op-scim-bridge lifen-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.16.8
0.4.0
1.18.9

Open the chart page →

2,777
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
stdlib@go1.17.8
1.18.9

Open the chart page →

3,133
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/net@v0.0.0-20211004195052-b30845b58a23
stdlib@go1.16.2
0.4.0
1.18.9

Open the chart page →

2,135
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.4.0
1.18.9

Open the chart page →

4,911
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

7,519
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
sky5367/locust-plugins-timescale:latestd3150f201471
stdlib@go1.18.7
1.18.9

Open the chart page →

7,534
devspace-cloudloftVerified publisher0.3.32 of 8See more

devspace-cloud loft 0.3.3

2 of the 8 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.4.0
1.18.9
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.18.9

Open the chart page →

9,888
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.7
0.4.0
1.18.9

Open the chart page →

3,094
loft-direct-cluster-endpointloftVerified publisher1.14.01 of 1See more

loft-direct-cluster-endpoint loft 1.14.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.6
0.4.0
1.18.9

Open the chart page →

3,119
vcluster-proloftVerified publisher0.0.0-ci-run.101 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
0.4.0

Open the chart page →

5,101
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.101 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.4.0
1.18.9

Open the chart page →

5,951
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.103 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

3 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.4.0
1.18.9
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.4.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.4.0

Open the chart page →

8,235
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.4.0
1.18.9

Open the chart page →

2,993
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

7,501
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.18.9

Open the chart page →

9,062
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

7,508
apica-ascentlogiqai2.0.46 of 19See more

apica-ascent logiqai 2.0.4

6 of the 19 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.4.0
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.13.7
0.4.0
1.18.9
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.4.0
1.18.9
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.4.0
1.18.9
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.8
0.4.0
1.18.9
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.9
0.4.0
1.18.9

Open the chart page →

23,689
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.4.0
1.18.9

Open the chart page →

2,349
fireflylsst-sqre0.3.71 of 2See more

firefly lsst-sqre 0.3.7

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/redis:5fc5ecd863862
stdlib@go1.16.7
1.18.9

Open the chart page →

1,731
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
stdlib@go1.17.2
0.4.0
1.18.9
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.4.0
1.18.9

Open the chart page →

9,347
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.5
0.4.0
1.18.9

Open the chart page →

6,642
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.6
0.4.0
1.18.9

Open the chart page →

3,773
xteveluiscajl0.1.61 of 1See more

xteve luiscajl 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
dnsforge/xteve:latest4d9a685c8c28
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.16.2
0.4.0
1.18.9

Open the chart page →

4,315
magistralamagistrala-devopsVerified publisher0.16.22 of 42See more

magistrala magistrala-devops 0.16.2

2 of the 42 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
stdlib@go1.18.2
1.18.9
timescale/timescaledb:latest-pg12645fd9e92d76
stdlib@go1.18.7
1.18.9

Open the chart page →

24,537

Container images carrying it

1,578 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
simonschneider/traefik-jwt-decode:latestd674ac370f80
stdlib@go1.17.13
1.18.9
1
simpleidserver/faasprometheus:0.0.425e378d57d78
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.1
0.4.0
1.18.9
1
sky5367/locust-plugins-timescale:latestd3150f201471
stdlib@go1.18.7
1.18.9
1
skylenet/ethereum-genesis-generator:latest210353ce7c89
stdlib@go1.17.13
1.18.9
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.2
0.4.0
1.18.9
1
slagattollas/weatherservice-practica:latest68e7f56393fc
stdlib@go1.15.6
1.18.9
1
slamdev/config-connector-templater:0.0.3a234541c9fa8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.4.0
1.18.9
1
slamdev/external-secrets-operator:0.0.8855f6625dda4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.4.0
1.18.9
1
slamdev/flux-notifier:v0.0.8b173d809132d
stdlib@go1.13.11
1.18.9
1
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
golang.org/x/net@v0.0.0-20200501053045-e0ff5e5a1de5
stdlib@go1.13.11
0.4.0
1.18.9
1
smailkoz/torrserver:1.0.1117b52d15de8f0
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.5
0.4.0
1.18.9
1
softonic/node-policy-webhook:0.1.2ab6098c04a53
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.6
0.4.0
1.18.9
1
softonic/pod-defaulter:0.1.072017aed5902
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.9
0.4.0
1.18.9
1
softonic/preemptible-killer:1.2.6-294b87f1fb362
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.10
0.4.0
1.18.9
1
softonic/rate-limit-operator:0.1.1910f6de37763
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.4.0
1.18.9
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18.2
0.4.0
1.18.9
1
sophos/nginx-vts-exporter:latestf1073556b29b
stdlib@go1.13.6
1.18.9
1
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.4.0
1.18.9
1
splunk/splunk-operator:2.0.0c4e0d3146226
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.12
0.4.0
1.18.9
1
springhack/frpc_ingress:latest4aceb821da88
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.2
0.4.0
1.18.9
1
sstarcher/ecr-cleaner:0.1.12d43c390cb19
stdlib@go1.14.2
1.18.9
1
sstarcher/helm-exporter:0.5.011769d01ba35
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.6
0.4.0
1.18.9
1
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.9
0.4.0
1.18.9
1
stakater/gitwebhookproxy:v0.2.79c1226e5270cd
stdlib@go1.13.1
1.18.9
1
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.4.0
1.18.9
1
stakater/konfigurator:v0.1.393409565b1ef5
stdlib@go1.17.13
1.18.9
1
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.4.0
1.18.9
1
stakater/whitelister:v0.0.1639107924063e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.1
0.4.0
1.18.9
1
stakater/workshop-operator:v0.0.3897bf456cc97c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.13
0.4.0
1.18.9
1
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.4.0
1.18.9
1
stakkato95/twitter-service-graphql:0.1.13cbe857234f2
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.4.0
1.18.9
1
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
stdlib@go1.18.3
1.18.9
1
stakkato95/twitter-service-users:0.1.1456049efee9a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.4.0
1.18.9
1
stashapp/stash:latest24dbd7607174
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.13.15
0.4.0
1.18.9
1
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.4.0
1
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.4.0
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.6
0.4.0
1.18.9
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.4.0
1.18.9
1
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.11
0.4.0
1.18.9
1
stubin87/tiny-api:v1.1.02e5c42e92ec8
stdlib@go1.19.1
1.18.9
1
subspacecommunity/subspace:1.5.0e2042b63fb35
golang.org/x/net@v0.0.0-20200519113804-d87ec0cfa476
stdlib@go1.14.6
0.4.0
1.18.9
1
superorbital/cludod:0.0.2-alphad59732f61d6e
golang.org/x/net@v0.0.0-20220111093109-d55c255bac03
stdlib@go1.17.6
0.4.0
1.18.9
1
surajwarbhe/grafana:v185248611e9f1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.4.0
1.18.9
1
syncthing/syncthing:1.18.2966433161272
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
stdlib@go1.17
0.4.0
1.18.9
1
sysintelligent/hello-app:2.0.177fb30df847d
stdlib@go1.19.3
1.18.9
1
t3nde/tideways:1.7.2777e008f764db
stdlib@go1.16.4
1.18.9
1
tdengine/tdengine:3.0.2.24140a4021ddb
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.6
0.4.0
1.18.9
1
tdeutsch/podsync:v2.4.2b67186f4c9a5
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.19.3
0.4.0
1.18.9
1
temporalio/admin-tools:1.15.135034611d981
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.4.0
1.18.9
1
temporalio/server:1.15.1e26758f5a1bf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.4.0
1.18.9
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.