StackRadar

CVE-2022-41717

Medium

Advisory

Published 8 Dec 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.056
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,425
of 17,787 indexed, latest versions
Container images
1,580
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/net/http2 vulnerable to possible excessive memory growth

Carried by container images the latest versions of 1,425 of 17,787 indexed charts deploy, on 1,580 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+172 more0.4.01,132
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+85 more1.18.91,485
OSV records
GHSA-xrjj-mj9h-534mGO-2022-1144
Also known as
BIT-golang-2022-41717

Charts affected

1,425 by stars
ChartLatestAffected imagesRadar Score
upcloud-csiankra-chartsVerified publisher0.4.06 of 8See more

upcloud-csi ankra-charts 0.4.0

6 of the 8 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.4.0
1.18.9
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.4.0
1.18.9

Open the chart page →

14,920
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.4.0
1.18.9

Open the chart page →

1,149
anteonanteonVerified publisher2.6.43 of 13See more

anteon anteon 2.6.4

3 of the 13 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ddosify/selfhosted_hammer:2.0.0181965edb12e
stdlib@go1.18.1
1.18.9
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.4.0
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.18.9

Open the chart page →

22,233
stash-enterpriseappscodeVerified publisher0.42.01 of 4See more

stash-enterprise appscode 0.42.0

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.4.0
1.18.9

Open the chart page →

3,620
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.4.0
1.18.9

Open the chart page →

5,231
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.15
0.4.0
1.18.9

Open the chart page →

2,819
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
stdlib@go1.18.2
1.18.9

Open the chart page →

17,946
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.4.0
1.18.9

Open the chart page →

10,731
dltbrokerassist-iot-distributed-broker0.2.04 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

4 of the 9 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.4.0
1.18.9
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.4.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.4.0
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.4.0

Open the chart page →

77,821
dltloggingassist-iot-logging-auditing0.2.04 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

4 of the 9 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.13
0.4.0
1.18.9
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.4.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.4.0
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.4.0

Open the chart page →

77,802
deployautoml0.1.01 of 3See more

deploy automl 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
amd64/mysql:5.7e20a653e0f51
stdlib@go1.18.2
1.18.9

Open the chart page →

2,947
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
stdlib@go1.17.5
0.4.0
1.18.9

Open the chart page →

4,298
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.16.2
0.4.0
1.18.9

Open the chart page →

3,391
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.18.1
0.4.0
1.18.9

Open the chart page →

3,729
prismav1o-chartsVerified publisher0.3.11 of 1See more

prism av1o-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.18.9

Open the chart page →

1,276
generic-appb3oVerified publisher0.1.61 of 1See more

generic-app b3o 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.18.9

Open the chart page →

1,279
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

4,814
chirpstackbeeinventor0.1.103 of 5See more

chirpstack beeinventor 0.1.10

3 of the 5 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.17.8
0.4.0
1.18.9
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.17.5
0.4.0
1.18.9
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.17.8
0.4.0
1.18.9

Open the chart page →

7,807
livekit-serverbeeinventor1.0.01 of 2See more

livekit-server beeinventor 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.10
0.4.0
1.18.9

Open the chart page →

2,602
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.4.0
1.18.9

Open the chart page →

1,595
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

7,830
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.4.0
1.18.9

Open the chart page →

2,663
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.2
0.4.0
1.18.9

Open the chart page →

3,509
passbolt-hachristianhuthVerified publisher6.0.11 of 4See more

passbolt-ha christianhuth 6.0.1

1 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.18.9

Open the chart page →

10,873
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
0.4.0
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
0.4.0

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.18.9
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.2
0.4.0
1.18.9

Open the chart page →

4,256
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.6
0.4.0
1.18.9
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.18.6
0.4.0
1.18.9
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.4.0
1.18.9

Open the chart page →

7,583
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.18.9

Open the chart page →

2,713
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.18.9

Open the chart page →

1,579
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.18.9

Open the chart page →

10,076
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

7,303
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.4.0
1.18.9

Open the chart page →

6,473
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.18.9

Open the chart page →

3,026
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.4.0
1.18.9
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.4
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.4.0
1.18.9
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.4.0
1.18.9

Open the chart page →

15,891
CubeUniversecubeuniverseVerified publisher0.1.01 of 1See more

CubeUniverse cubeuniverse 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.4.0

Open the chart page →

1,837
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.15
0.4.0
1.18.9

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.11
0.4.0
1.18.9

Open the chart page →

4,570
dregsydeliveryheroVerified publisher0.1.51 of 1See more

dregsy deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.4.0
1.18.9

Open the chart page →

2,969
gripmockdeliveryheroVerified publisher1.1.31 of 1See more

gripmock deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
stdlib@go1.14.6
1.18.9

Open the chart page →

2,793
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.4.0
1.18.9

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.4.0
1.18.9

Open the chart page →

7,987
kube-bench-metricsdevopstalesVerified publisher0.1.01 of 1See more

kube-bench-metrics devopstales 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.18.9

Open the chart page →

2,111
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.22.48be660470961
stdlib@go1.17.3
1.18.9

Open the chart page →

9,239
permission-managerdevopstalesVerified publisher1.8.01 of 1See more

permission-manager devopstales 1.8.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.4.0
1.18.9

Open the chart page →

2,266
dnsmasqdevplayer0Verified publisher0.1.51 of 2See more

dnsmasq devplayer0 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.5
0.4.0
1.18.9

Open the chart page →

3,392
whoamidevplayer0Verified publisher0.1.21 of 1See more

whoami devplayer0 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
traefik/whoami:v1.6.12c52bb2c8480
stdlib@go1.15.6
1.18.9

Open the chart page →

1,216
calicodevtron0.1.14 of 4See more

calico devtron 0.1.1

4 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.4.0
1.18.9
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.4.0
1.18.9
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.4.0
1.18.9
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.18.9

Open the chart page →

10,073
clairdevtron0.1.141 of 2See more

clair devtron 0.1.14

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.6
0.4.0
1.18.9

Open the chart page →

6,237
discord-alertmanagerdevtron-labs0.10.01 of 1See more

discord-alertmanager devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.18.9

Open the chart page →

951
digispoof-interfacedigispoof-interface1.0.01 of 3See more

digispoof-interface digispoof-interface 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.4.0
1.18.9

Open the chart page →

7,779

Container images carrying it

1,580 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.4.0
1.18.9
1
voltha/bbsim-sadis-server:0.4.0762b272d439e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.4.0
1.18.9
1
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.4.0
1.18.9
1
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.7
0.4.0
1.18.9
1
vultr/vultr-csi:v0.3.041d26735d437
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16.8
0.4.0
1.18.9
1
wallarm/ingress-python:4.6.0-15cb2ae08b40f
stdlib@go1.18.2
1.18.9
1
wallarm/ingress-ruby:4.2.1-195ea2632326c
stdlib@go1.18.3
1.18.9
1
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
stdlib@go1.18.3
1.18.9
1
wavefronthq/prometheus-storage-adapter:latestded77b38c7c6
stdlib@go1.18
1.18.9
1
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
stdlib@go1.18
1.18.9
1
wazuh/wazuh-manager:4.11.11da5c38c6a78
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.4.0
1.18.9
1
wazuh/wazuh-manager:4.4.121994f40e0da
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.4.0
1.18.9
1
wazuh/wazuh-manager:4.14.45a065930682d
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.4.0
1.18.9
1
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.4.0
1.18.9
1
weaveworks/flagger:1.0.0-rc.5174307de1b36
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.2
0.4.0
1.18.9
1
weaveworks/flagger:0.19.0a9c2e9df4227
golang.org/x/net@v0.0.0-20190206173232-65e2d4e15006
stdlib@go1.13.1
0.4.0
1.18.9
1
weaveworks/flagger-loadtester:0.9.03cdac6928a63
golang.org/x/net@v0.0.0-20190206173232-65e2d4e15006
stdlib@go1.13.1
0.4.0
1.18.9
1
weblate/weblate:3.11.3-182848df56ecd
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.4.0
1.18.9
1
wener/frpc:v0.37.0cc9fd4da44c0
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.4.0
1.18.9
1
wener/frps:v0.37.05c92cc9e8597
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.4.0
1.18.9
1
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.4.0
1.18.9
1
wistefan/vcbackend:0.0.13bd436164b51
stdlib@go1.18.3
1.18.9
1
wolveix/satisfactory-server:v1.9.1199be1064b18
stdlib@go1.18.1
1.18.9
1
wolveix/satisfactory-server:v1.9.9464d11e36e10
stdlib@go1.18.1
1.18.9
1
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.13
0.4.0
1.18.9
1
yandex/clickhouse-server:latest1cbf75aabe1e
stdlib@go1.16.7
1.18.9
1
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.18.9
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.1
0.4.0
1.18.9
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
stdlib@go1.18.1
1.18.9
1
zeetdev/tailscale-relay:v1.24.21967aa2840b6
golang.org/x/net@v0.0.0-20220407224826-aac1ed45d8e3
stdlib@go1.18.1-ts710a0d8610
0.4.0
1.18.9
1
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.4.0
1.18.9
1
zufardhiyaulhaq/devopsweekly:v2.1.046625567fb60
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.13
0.4.0
1.18.9
1
zufardhiyaulhaq/goweekly:v2.0.008dcc130fbea
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.17.12
0.4.0
1.18.9
1
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.4.0
1.18.9
1
zufardhiyaulhaq/kubernetesweekly:v2.1.0a287ada277c6
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.16.15
0.4.0
1.18.9
1
zufardhiyaulhaq/ngrok-operator:v1.3.07cf2ae3fb1fb
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.15
0.4.0
1.18.9
1
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.16.15
0.4.0
1.18.9
1
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.13.15
0.4.0
1.18.9
1
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.5
0.4.0
1.18.9
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.13.14
0.4.0
1.18.9
1
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.19.3
0.4.0
1.18.9
1
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.4.0
1.18.9
1
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.4.0
1.18.9
1
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.10
0.4.0
1.18.9
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.4.0
1.18.9
1
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.4.0
1.18.9
1
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.4.0
1.18.9
1
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
stdlib@go1.15.10
0.4.0
1.18.9
1
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.4.0
1.18.9
1
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.6
0.4.0
1.18.9
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.