StackRadar

CVE-2022-41723

High

Advisory

Published 16 Feb 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.046
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,515
of 17,792 indexed, latest versions
Container images
1,696
deployed by those charts
Fix available
2 of 2
affected packages

golang.org/x/net vulnerable to Uncontrolled Resource Consumption

Carried by container images the latest versions of 1,515 of 17,792 indexed charts deploy, on 1,696 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+175 more0.7.01,205
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+90 more1.19.61,632
OSV records
GHSA-vvpx-j8f3-3w6hGO-2023-1571
Also known as
BIT-golang-2022-41723

Charts affected

1,515 by stars
ChartLatestAffected imagesRadar Score
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.7.0
1.19.6

Open the chart page →

2,792
prometheus-openstack-exporterwiremindVerified publisher0.5.01 of 1See more

prometheus-openstack-exporter wiremind 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
ghcr.io/openstack-exporter/openstack-exporter:1.7.0e5146a7dd515
stdlib@go1.18.10
1.19.6

Open the chart page →

1,480
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.10
0.7.0
1.19.6

Open the chart page →

2,512
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.5
0.7.0
1.19.6

Open the chart page →

2,623
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
stdlib@go1.17.13
1.19.6
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
stdlib@go1.19.3
1.19.6

Open the chart page →

16,091
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.15
0.7.0
1.19.6

Open the chart page →

1,960
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
golang.org/x/net@v0.5.0
stdlib@go1.18.10
0.7.0
1.19.6

Open the chart page →

13,813
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
stdlib@go1.18.6
1.19.6

Open the chart page →

1,152
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18.1
0.7.0
1.19.6

Open the chart page →

1,965
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.7.0
1.19.6
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.9
0.7.0
1.19.6
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.7.0
1.19.6
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16
0.7.0
1.19.6

Open the chart page →

8,000
nginx-vts-exporterymrs0.1.21 of 1See more

nginx-vts-exporter ymrs 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
sophos/nginx-vts-exporter:latestf1073556b29b
stdlib@go1.13.6
1.19.6

Open the chart page →

1,337
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.7.0
1.19.6

Open the chart page →

3,024
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.19.2
0.7.0
1.19.6

Open the chart page →

5,047
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.13
0.7.0
1.19.6

Open the chart page →

3,697
zookeeper-exporterzookeeper-exporter0.1.01 of 1See more

zookeeper-exporter zookeeper-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41723.

Container imageDigestPackageFixed in
dabealu/zookeeper-exporter:latest86106fec315f
stdlib@go1.14.15
1.19.6

Open the chart page →

1,248

Container images carrying it

1,696 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
stdlib@go1.17.1
1.19.6
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
stdlib@go1.18.10
1.19.6
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
stdlib@go1.16.3
1.19.6
1
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.2
0.7.0
1.19.6
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
stdlib@go1.16.2
1.19.6
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.7.0
1.19.6
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
stdlib@go1.16.2
1.19.6
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.7.0
1.19.6
1
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.7.0
1.19.6
1
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
stdlib@go1.16.7
1.19.6
1
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
stdlib@go1.18
1.19.6
1
ghcr.io/ckotzbauer/chekrf299baf467b5
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.7.0
1.19.6
1
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.7
0.7.0
1.19.6
1
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.13.15
0.7.0
1.19.6
1
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.14.7
0.7.0
1.19.6
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.7
0.7.0
1.19.6
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.14.7
0.7.0
1.19.6
1
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.18.6
0.7.0
1.19.6
1
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.19.6
1
ghcr.io/clusterpedia-io/clusterpedia/apiserver:v0.6.03d089d9078f8
stdlib@go1.19.4
1.19.6
1
ghcr.io/clusterpedia-io/clusterpedia/clustersynchro-manager:v0.6.082cc9a77f6d6
stdlib@go1.19.4
1.19.6
1
ghcr.io/clusterpedia-io/clusterpedia/controller-manager:v0.6.081669df338e0
stdlib@go1.19.4
1.19.6
1
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.17
0.7.0
1.19.6
1
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16
0.7.0
1.19.6
1
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/review-component-php:latestafe623824b82
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.7.0
1.19.6
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.