StackRadar

CVE-2022-41717

Medium

Advisory

Published 8 Dec 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.056
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,423
of 17,792 indexed, latest versions
Container images
1,578
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/net/http2 vulnerable to possible excessive memory growth

Carried by container images the latest versions of 1,423 of 17,792 indexed charts deploy, on 1,578 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+172 more0.4.01,131
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+85 more1.18.91,483
OSV records
GHSA-xrjj-mj9h-534mGO-2022-1144
Also known as
BIT-golang-2022-41717

Charts affected

1,423 by stars
ChartLatestAffected imagesRadar Score
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
stdlib@go1.19.3
1.18.9

Open the chart page →

6,005
vaultintelVerified publisher0.8.12 of 2See more

vault intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.2
0.4.0
1.18.9
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/net@v0.0.0-20221004154528-8021a29435af
stdlib@go1.19.3
0.4.0
1.18.9

Open the chart page →

4,487
gravity-initinvisiblVerified publisher1.0.91 of 1See more

gravity-init invisibl 1.0.9

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
invisibl/gravity-init:v1.0.91a970f84178b
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.12
0.4.0
1.18.9

Open the chart page →

2,006
identity-managerinvisiblVerified publisher1.0.01 of 1See more

identity-manager invisibl 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
invisibl/identity-manager:1.0.01029f4fe20eb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.11
0.4.0
1.18.9

Open the chart page →

2,162
identity-manager-demoinvisiblVerified publisher0.1.11 of 1See more

identity-manager-demo invisibl 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
invisibl/identity-manager-demo:v1.0.0cf5400cb935a
stdlib@go1.19.2
1.18.9

Open the chart page →

1,006
karpenteriometeVerified publisher0.19.31 of 1See more

karpenter iomete 0.19.3

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.4.0
1.18.9

Open the chart page →

1,555
inlets-clientjacobcolvinVerified publisher0.1.21 of 1See more

inlets-client jacobcolvin 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.15
0.4.0
1.18.9

Open the chart page →

1,753
inlets-serverjacobcolvinVerified publisher0.1.11 of 1See more

inlets-server jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.15
0.4.0
1.18.9

Open the chart page →

1,753
twitch-predictions-recorderjacobcolvinVerified publisher0.1.01 of 1See more

twitch-predictions-recorder jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.4.0
1.18.9

Open the chart page →

2,670
wakatime-exporterjacobcolvinVerified publisher0.1.11 of 1See more

wakatime-exporter jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
macropower/wakatime-exporter:0.1.0dbb05debb785
stdlib@go1.14.6
1.18.9

Open the chart page →

1,313
koptimizejaconiVerified publisher0.5.41 of 2See more

koptimize jaconi 0.5.4

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
alpine/k8s:1.27.321b24e6bf801
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19
0.4.0
1.18.9

Open the chart page →

5,731
javascriptweeklyjavascriptweekly2.1.01 of 1See more

javascriptweekly javascriptweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.4.0
1.18.9

Open the chart page →

1,237
jx-app-athensjenkins-x0.0.181 of 1See more

jx-app-athens jenkins-x 0.0.18

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.13.4
0.4.0
1.18.9

Open the chart page →

4,232
jx-app-flaggerjenkins-x0.0.52 of 2See more

jx-app-flagger jenkins-x 0.0.5

2 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
grafana/grafana:6.5.1befcd84da2c1
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.4.0
1.18.9
weaveworks/flagger:1.0.0-rc.5174307de1b36
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.2
0.4.0
1.18.9

Open the chart page →

6,035
knative-servingjenkins-x0.19.124 of 4See more

knative-serving jenkins-x 0.19.12

4 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned1e3db4f2eeed
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.4.0
1.18.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinneddb6ceff2aab4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.4.0
1.18.9
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedb2cd45b8a8a4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.4.0
1.18.9
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedd27b4495ccc3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.10
0.4.0
1.18.9

Open the chart page →

9,724
ingress-nginxjfrog4.5.21 of 2See more

ingress-nginx jfrog 4.5.2

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.4.0
1.18.9

Open the chart page →

3,798
alpine-torjfwenischVerified publisher1.1.01 of 1See more

alpine-tor jfwenisch 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
jfwenisch/alpine-tor:latest9e6c229f953c
golang.org/x/net@v0.0.0-20190328230028-74de082e2cca
stdlib@go1.14.6
0.4.0
1.18.9

Open the chart page →

4,461
kafka-offset-lag-for-prometheusjhidalgo3-githubVerified publisher2.3.01 of 1See more

kafka-offset-lag-for-prometheus jhidalgo3-github 2.3.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/net@v0.1.0
stdlib@go1.17.13
0.4.0
1.18.9

Open the chart page →

1,471
missing-container-metricsjimdo-missing-container-metrics0.5.01 of 1See more

missing-container-metrics jimdo-missing-container-metrics 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.4.0
1.18.9

Open the chart page →

2,418
haven-complinacy-dashboardjolle-devVerified publisher1.0.01 of 2See more

haven-complinacy-dashboard jolle-dev 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.17.2
0.4.0
1.18.9

Open the chart page →

3,842
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.18.2
0.4.0
1.18.9

Open the chart page →

16,686
firstchartjuanjmerono0.2.01 of 1See more

firstchart juanjmerono 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17
0.4.0
1.18.9

Open the chart page →

1,443
alertmanager-irc-relayjuppi880.0.11 of 1See more

alertmanager-irc-relay juppi88 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
maldridge/alertmanager-irc-relay:v0.4.1391de2b76128
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.4
0.4.0
1.18.9

Open the chart page →

1,615
k10appk10app0.2.11 of 11See more

k10app k10app 0.2.1

1 of the 11 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/k10app/businit:latest94c9a3e799c2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.4.0
1.18.9

Open the chart page →

10,588
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
stdlib@go1.18.1
1.18.9

Open the chart page →

6,218
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
alpine/k8s:1.22.600ac10bcb759
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.17.6
0.4.0
1.18.9

Open the chart page →

14,912
k8s-pausek8s-pause0.1.41 of 1See more

k8s-pause k8s-pause 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.8
0.4.0
1.18.9

Open the chart page →

1,846
k8svault-controllerk8svault-controller0.1.21 of 1See more

k8svault-controller k8svault-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.16.15
0.4.0
1.18.9

Open the chart page →

1,885
postgresqlkagiso-me0.4.01 of 1See more

postgresql kagiso-me 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.18.9

Open the chart page →

1,488
rediskagiso-me0.1.61 of 1See more

redis kagiso-me 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.18.9

Open the chart page →

1,288
kestra-starterkestraOfficialVerified publisher2.0.21 of 5See more

kestra-starter kestra 2.0.2

1 of the 5 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.18.9

Open the chart page →

5,473
keycloak-operator-legacykeycloak-operator-legacy1.0.01 of 1See more

keycloak-operator-legacy keycloak-operator-legacy 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.4.0
1.18.9

Open the chart page →

5,067
csi-driver-nfskeyporttech0.1.41 of 2See more

csi-driver-nfs keyporttech 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
golang.org/x/net@v0.0.0-20190415100556-4a65cf94b679
stdlib@go1.14.2
0.4.0
1.18.9

Open the chart page →

3,364
gogskeyporttech0.1.31 of 3See more

gogs keyporttech 0.1.3

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
gogs/gogs:0.12.30195b095d0b2
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.7
0.4.0
1.18.9

Open the chart page →

3,524
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.4.0
1.18.9

Open the chart page →

8,829
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.4.0
1.18.9

Open the chart page →

2,792
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
stdlib@go1.17.1
1.18.9

Open the chart page →

6,458
scriptskfirfer0.1.361 of 1See more

scripts kfirfer 0.1.36

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kfirfer/scripts:0.0.2481e5c4e5d70e
stdlib@go1.17.10
1.18.9

Open the chart page →

2,320
kiaekiae0.1.66 of 9See more

kiae kiae 0.1.6

6 of the 9 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.4.0
1.18.9
grafana/promtail:2.6.1072527b12cdf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.4.0
1.18.9
istio/pilot:1.15.2db08d6963975
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.19.2
0.4.0
1.18.9
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.4.0
1.18.9
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.2
0.4.0
1.18.9
ghcr.io/kiaedev/kiae:latestebd03028ff6a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
0.4.0

Open the chart page →

19,267
kimai-helmchartkimai2tet0.1.01 of 2See more

kimai-helmchart kimai2tet 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.18.9

Open the chart page →

1,518
cadvisorkrakazyabraVerified publisher1.0.11 of 1See more

cadvisor krakazyabra 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.13.15
0.4.0
1.18.9

Open the chart page →

3,185
krakenkraken0.2.01 of 7See more

kraken kraken 0.2.0

1 of the 7 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/redis:5.0fc5ecd863862
stdlib@go1.16.7
1.18.9

Open the chart page →

1,731
kubeflowkromanow94-kubeflow0.5.14 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

4 of the 30 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
kubeflownotebookswg/kfam:v1.9.22060a2ede788
stdlib@go1.17.13
1.18.9
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.4.0
1.18.9
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.4.0
1.18.9
kubeflownotebookswg/tensorboard-controller:v1.9.26536a9f61193
stdlib@go1.17.13
1.18.9

Open the chart page →

71,075
kron-aapm-sidecarkron-aapm-sidecar1.1.01 of 1See more

kron-aapm-sidecar kron-aapm-sidecar 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.10
0.4.0
1.18.9

Open the chart page →

2,111
lndkronkltdVerified publisher0.3.93 of 4See more

lnd kronkltd 0.3.9

3 of the 4 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.1
0.4.0
1.18.9
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.4.0
1.18.9
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.4.0
1.18.9

Open the chart page →

8,472
casdoorkrzwiatrzyk1.0.01 of 1See more

casdoor krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
casbin/casdoor:v1.224.066f836ef778b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.5
0.4.0
1.18.9

Open the chart page →

3,649
nocodbkrzwiatrzyk0.0.11 of 1See more

nocodb krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
nocodb/nocodb:0.100.2b0b91ec2a2dd
golang.org/x/net@v0.0.0-20220805013720-a33c5aa5df48
stdlib@go1.18.2
0.4.0
1.18.9

Open the chart page →

2,320
pipecdkrzwiatrzyk0.39.01 of 3See more

pipecd krzwiatrzyk 0.39.0

1 of the 3 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.6
0.4.0
1.18.9

Open the chart page →

3,819
postgresql-backup-to-miniokrzwiatrzyk0.0.11 of 2See more

postgresql-backup-to-minio krzwiatrzyk 0.0.1

1 of the 2 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.18.9

Open the chart page →

2,199
traggokrzwiatrzyk1.0.01 of 1See more

traggo krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-41717.

Container imageDigestPackageFixed in
traggo/server:0.2.3f1ced637510e
stdlib@go1.13.1
1.18.9

Open the chart page →

1,885

Container images carrying it

1,578 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.2
0.4.0
1.18.9
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.4.0
1.18.9
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.4.0
1.18.9
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.4.0
1.18.9
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.4.0
1.18.9
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.4.0
1.18.9
1
registry.k8s.io/kube-scheduler:v1.23.143e149d206076
stdlib@go1.17.13
1.18.9
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
stdlib@go1.19
1.18.9
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
stdlib@go1.18
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
stdlib@go1.19
1.18.9
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.18.9
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.18.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
stdlib@go1.18
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.18.9
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.4.0
1.18.9
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.18.9
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.4.0
1.18.9
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.