StackRadar

CVE-2022-41721

High

Advisory

Published 13 Jan 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
158
of 17,781 indexed, latest versions
Container images
157
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/net/http2/h2c vulnerable to request smuggling attack

Carried by container images the latest versions of 158 of 17,781 indexed charts deploy, on 157 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20220524220425-1d687d428aca, v0.0.0-20220526153639-5463443f8c37, v0.0.0-20220531201128-c960675eff93, v0.0.0-20220607020251-c690dde0001d+30 more0.1.1-0.20221104162952-702349b0e862157
OSV records
GHSA-fxg5-wq6x-vr4w
Also known as
GO-2023-1495

Charts affected

158 by stars
ChartLatestAffected imagesRadar Score
consulintelVerified publisher0.8.11 of 2See more

consul intel 0.8.1

1 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

5,389
evi-consulintelVerified publisher3.0.31 of 2See more

evi-consul intel 3.0.3

1 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

5,389
evi-vaultintelVerified publisher3.0.32 of 2See more

evi-vault intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.1.1-0.20221104162952-702349b0e862
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/net@v0.0.0-20221004154528-8021a29435af
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

4,478
kesintelVerified publisher0.8.31 of 1See more

kes intel 0.8.3

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
minio/kes:v0.22.255f3aef5803e
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

3,570
vaultintelVerified publisher0.8.12 of 2See more

vault intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.1.1-0.20221104162952-702349b0e862
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/net@v0.0.0-20221004154528-8021a29435af
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

4,478
karpenteriometeVerified publisher0.19.31 of 1See more

karpenter iomete 0.19.3

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
golang.org/x/net@v0.1.0
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

1,548
twitch-predictions-recorderjacobcolvinVerified publisher0.1.01 of 1See more

twitch-predictions-recorder jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
golang.org/x/net@v0.1.0
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

2,669
javascriptweeklyjavascriptweekly2.1.01 of 1See more

javascriptweekly javascriptweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

1,237
kafka-offset-lag-for-prometheusjhidalgo3-githubVerified publisher2.3.01 of 1See more

kafka-offset-lag-for-prometheus jhidalgo3-github 2.3.0

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/net@v0.1.0
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

1,470
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

16,600
k10appk10app0.2.11 of 11See more

k10app k10app 0.2.1

1 of the 11 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ghcr.io/k10app/businit:latest94c9a3e799c2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

10,546
kiaekiae0.1.64 of 9See more

kiae kiae 0.1.6

4 of the 9 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
istio/pilot:1.15.2db08d6963975
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.1.1-0.20221104162952-702349b0e862
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
golang.org/x/net@v0.1.0
0.1.1-0.20221104162952-702349b0e862
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.1.1-0.20221104162952-702349b0e862
ghcr.io/kiaedev/kiae:latestebd03028ff6a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

19,168
nocodbkrzwiatrzyk0.0.11 of 1See more

nocodb krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
nocodb/nocodb:0.100.2b0b91ec2a2dd
golang.org/x/net@v0.0.0-20220805013720-a33c5aa5df48
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

2,313
openebskubeblocksVerified publisher3.10.02 of 3See more

openebs kubeblocks 3.10.0

2 of the 3 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

10,489
prometheuskubeblocksVerified publisher15.16.11 of 6See more

prometheus kubeblocks 15.16.1

1 of the 6 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.39.14748e26f9369
golang.org/x/net@v0.0.0-20220920203100-d0c6ba3f52d9
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

10,302
apm-serverkube-opsVerified publisher0.1.21 of 1See more

apm-server kube-ops 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
elastic/apm-server:7.17.6c7a1c63257d0
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

7,157
kusk-gatewaykubeshop0.0.651 of 2See more

kusk-gateway kubeshop 0.0.65

1 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
kubeshop/kusk-gateway:v1.5.48b5bfd57a3ce
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

1,615
kusk-gateway-apikubeshop0.1.282 of 2See more

kusk-gateway-api kubeshop 0.1.28

2 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
kubeshop/kusk-gateway-api:v1.5.4126c713cf7d8
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862
kubeshop/kusk-gateway-api-websocket:v1.5.43b4f8345ca5c
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

2,308
chaos-meshkubesphere-stable2.5.13 of 3See more

chaos-mesh kubesphere-stable 2.5.1

3 of the 3 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

8,555
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

18,316
iomeshkubesphere-stable1.1.01 of 25See more

iomesh kubesphere-stable 1.1.0

1 of the 25 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
iomesh/livenessprobe:v2.8.0560f01510f99
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

48,665
IOMeshkubesphere-stable1.2.01 of 25See more

IOMesh kubesphere-stable 1.2.0

1 of the 25 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
iomesh/livenessprobe:v2.8.0560f01510f99
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

46,341
prometheuslectures-k8sinfra15.8.51 of 6See more

prometheus lectures-k8sinfra 15.8.5

1 of the 6 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

9,092
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

4,271
vcluster-proloftVerified publisher0.0.0-ci-run.101 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

1 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

5,085
cameramedia-streaming-meshVerified publisher0.2.51 of 3See more

camera media-streaming-mesh 0.2.5

1 of the 3 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

18,608
msm-rtspmedia-streaming-meshVerified publisher0.0.21 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

1 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

18,608
rtspmedia-streaming-meshVerified publisher0.0.141 of 2See more

rtsp media-streaming-mesh 0.0.14

1 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

18,608
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

11,643
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

8,556
mqtt-loggermoreillonVerified publisher0.3.12 of 5See more

mqtt-logger moreillon 0.3.1

2 of the 5 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.1.1-0.20221104162952-702349b0e862
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

10,959
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3fb7667fe037f
golang.org/x/net@v0.0.0-20220726230323-06994584191e
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

25,933
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

8,928
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

6,455
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

4,674
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

4,642
npre-essentialsphntom0.1.606 of 22See more

npre-essentials phntom 0.1.60

6 of the 22 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
grafana/promtail:2.7.0c16c710f7333
golang.org/x/net@v0.0.0-20220920203100-d0c6ba3f52d9
0.1.1-0.20221104162952-702349b0e862
phntom/chartmuseum:v0.15.29242b4df9e65
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.1.1-0.20221104162952-702349b0e862
phntom/oauth2-proxy:v7.3.48ea656a2a895
golang.org/x/net@v0.0.0-20221012135044-0b7e1fb9d458
0.1.1-0.20221104162952-702349b0e862
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
0.1.1-0.20221104162952-702349b0e862
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
0.1.1-0.20221104162952-702349b0e862
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

26,840
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

3,488
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

7,062
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

4,889
prometheus-freebox-exporterportefaix-hub0.1.11 of 1See more

prometheus-freebox-exporter portefaix-hub 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
ghcr.io/nlamirault/freebox-exporter:1.0.02d522b664e12
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

1,755
trino-loadbalancerpresto-loadbalancer0.3.11 of 1See more

trino-loadbalancer presto-loadbalancer 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

2,356
ingress-controllerqumine0.8.5001 of 1See more

ingress-controller qumine 0.8.500

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
qumine/ingress-controller:v0.8.5f2c8a2148381
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

1,533
zentaorock8sVerified publisher0.0.11 of 1See more

zentao rock8s 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
easysoft/quickon-zentao:18.5592ad5df1f8b
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

1,534
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

68,240
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

32,902
zincromholdings0.1.21 of 1See more

zinc romholdings 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

1,507
tusdsagikazarmarkVerified publisher0.1.21 of 1See more

tusd sagikazarmark 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
tusproject/tusd:v1.10.01e457b59fd5b
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

1,545
knative-helm-operatorsalaboy1.9.02 of 2See more

knative-helm-operator salaboy 1.9.0

2 of the 2 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/operator/cmd/webhookdigest-pinned6c5c90cdf707
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862
gcr.io/knative-releases/knative.dev/serving/cmd/default-domaindigest-pinned5e0429b70299
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

2,339
secret-syncsecret-syncVerified publisher0.1.111 of 1See more

secret-sync secret-sync 0.1.11

1 of the 1 container images this version deploys carry CVE-2022-41721.

Container imageDigestPackageFixed in
csepulvedab/secret-sync:0.5227a6f2b0ff8
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862

Open the chart page →

1,442

Container images carrying it

157 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
0.1.1-0.20221104162952-702349b0e862
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.1.1-0.20221104162952-702349b0e862
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.1.1-0.20221104162952-702349b0e862
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.1.1-0.20221104162952-702349b0e862
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.